<?xml version="1.0" encoding="UTF-8"?>
<nvd nvd_xml_version="1.2" pub_date="2008-09-05" xmlns="http://nvd.nist.gov/feeds/cve/1.2" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:schemaLocation="http://nvd.nist.gov/feeds/cve/1.2 http://nvd.nist.gov/schema/nvdcve.xsd"><!--This XML file has been upgraded to support CVSS version 2.  The following new attributes have been added to CVS entries:
* CVSS_version - Indicates the version of the CVSS data
* CVSS_base_score - The CVSSv2 base score
* CVSS_impact_subscore - The CVSSv2 impact sub-score
* CVSS_exploit_subscore - the CVSSv2 exploit sub-score

The following attributes have been mapped to new content in CVS entries:
* CVSS_score - This attribute is the same as the CVSS_base_score and is now deprecated.
* CVSS_vector - Contains the new CVSSv2 vector string--><entry CVSS_base_score="4.7" CVSS_exploit_subscore="3.4" CVSS_impact_subscore="6.9" CVSS_score="4.7" CVSS_vector="(AV:L/AC:M/Au:N/C:N/I:N/A:C)" CVSS_version="2.0" modified="2007-07-05" name="CVE-2007-0001" published="2007-03-02" seq="2007-0001" severity="Medium" type="CVE"><desc><descript source="cve">The file watch implementation in the audit subsystem (auditctl -w) in the Red Hat Enterprise Linux (RHEL) 4 kernel 2.6.9 allows local users to cause a denial of service (kernel panic) by replacing a watched file, which does not cause the watch on the old inode to be dropped.</descript></desc><impacts><impact source="nvd">Successful exploitation requires that the attacker previously created a watch for a file.</impact></impacts><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><local/></range><refs><ref patch="1" source="" url="http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=223129"></ref><ref adv="1" patch="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2007-0085.html">RHSA-2007:0085</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24300">24300</ref><ref source="BID" url="http://www.securityfocus.com/bid/22737">22737</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017705">1017705</ref></refs><vuln_soft><prod name="Enterprise Linux" vendor="Red Hat"><vers edition="Linux Kernel 2.6.9" num="4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" CVSS_score="9.3" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2008-06-25" name="CVE-2007-0002" published="2007-03-16" seq="2007-0002" severity="High" type="CVE"><desc><descript source="cve">Multiple heap-based buffer overflows in WordPerfect Document importer/exporter (libwpd) before 0.8.9 allow user-assisted remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted WordPerfect file in which values to loop counters are not properly handled in the (1) WP3TablesGroup::_readContents and (2) WP5DefinitionGroup_DefineTablesSubGroup::WP5DefinitionGroup_DefineTablesSubGroup functions.  NOTE: the integer overflow has been split into CVE-2007-1466.</descript></desc><sols><sol source="nvd">This vulnerability has been addressed by the vendor through a product update: http://sourceforge.net/projects/libwpd/ </sol></sols><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><exception/></vuln_types><range><network/><user_init/></range><refs><ref source="" url="http://sourceforge.net/project/shownotes.php?release_id=494122"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0976">ADV-2007-0976</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24507">24507</ref><ref source="IDEFENSE" url="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=490">20070316 Multiple Vendor libwpd Multiple Buffer Overflow Vulnerabilities</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/463033/100/0/threaded">20070316 rPSA-2007-0057-1 libwpd</ref><ref source="DEBIAN" url="http://www.debian.org/security/2007/dsa-1268">DSA-1268</ref><ref source="DEBIAN" url="http://www.debian.org/security/2007/dsa-1270">DSA-1270</ref><ref source="FEDORA" url="http://fedoranews.org/cms/node/2805">FEDORA-2007-350</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2007:063">MDKSA-2007:063</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2007:064">MDKSA-2007:064</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2007-0055.html">RHSA-2007:0055</ref><ref source="SUSE" url="http://lists.suse.com/archive/suse-security-announce/2007-Mar/0007.html">SUSE-SA:2007:023</ref><ref source="UBUNTU" url="http://www.ubuntu.com/usn/usn-437-1">USN-437-1</ref><ref source="BID" url="http://www.securityfocus.com/bid/23006">23006</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1032">ADV-2007-1032</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017789">1017789</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24557">24557</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24572">24572</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24580">24580</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24573">24573</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24581">24581</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24593">24593</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24465">24465</ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200704-07.xml">GLSA-200704-07</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24794">24794</ref><ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102863-1">102863</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1339">ADV-2007-1339</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24856">24856</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200704-12.xml">GLSA-200704-12</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24906">24906</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:063">MDKSA-2007:063</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:064">MDKSA-2007:064</ref><ref source="SLACKWARE" url="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2007&amp;m=slackware-security.399659">SSA-2007-085-02</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24588">24588</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24613">24613</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24591">24591</ref></refs><vuln_soft><prod name="libwpd library" vendor="libwpd"><vers num="0.8.2"/><vers num="0.8.6"/><vers num="0.8.7"/><vers num="0.8.8"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-01-23" name="CVE-2007-0003" published="2007-01-23" seq="2007-0003" severity="High" type="CVE"><desc><descript source="cve">pam_unix.so in Linux-PAM 0.99.7.0 allows context-dependent attackers to log into accounts whose password hash, as stored in /etc/passwd or /etc/shadow, has only two characters.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><access/><design/></vuln_types><range><local/></range><refs><ref adv="1" source="MLIST" url="http://www.redhat.com/archives/fedora-devel-list/2007-January/msg01271.html">[fedora-devel-list] 20070122 Re: rawhide report: 20070120 changes</ref><ref adv="1" source="MLIST" url="http://www.redhat.com/archives/fedora-devel-list/2007-January/msg01277.html">[fedora-devel-list] 20070122 Re: rawhide report: 20070120 changes</ref><ref adv="1" source="MLIST" url="https://www.redhat.com/archives/pam-list/2007-January/msg00017.html">[pam-list] 20070123 Linux-PAM 0.99.7.1 released</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2007_3_sr.html">
SUSE-SR:2007:003</ref><ref source="BID" url="http://www.securityfocus.com/bid/22204">
22204</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0323">
ADV-2007-0323</ref><ref source="SECUNIA" url="http://secunia.com/advisories/23858">
23858</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31739">
linuxpam-pamunix-security-bypass(31739)</ref></refs><vuln_soft><prod name="Linux_PAM" vendor="Andrew Morgan"><vers num="0.99.7.0"/></prod></vuln_soft></entry><entry CVSS_base_score="1.9" CVSS_exploit_subscore="3.4" CVSS_impact_subscore="2.9" CVSS_score="1.9" CVSS_vector="(AV:L/AC:M/Au:N/C:P/I:N/A:N)" CVSS_version="2.0" modified="2007-10-04" name="CVE-2007-0004" published="2007-09-18" seq="2007-0004" severity="Low" type="CVE"><desc><descript source="cve">The NFS client implementation in the kernel in Red Hat Enterprise Linux (RHEL) 3, when a filesystem is mounted with the noacl option, checks permissions for the open system call via vfs_permission (mode bits) data rather than an NFS ACCESS call to the server, which allows local client processes to obtain a false success status from open calls that the server would deny, and possibly obtain sensitive information about file permissions on the server, as demonstrated in a root_squash environment.  NOTE: it is uncertain whether any scenarios involving this issue cross privilege boundaries.</descript></desc><loss_types><conf/></loss_types><range><local/></range><refs><ref source="" url="https://bugzilla.redhat.com/show_bug.cgi?id=199715"></ref></refs><vuln_soft><prod name="enterprise_linux" vendor="redhat"><vers num="3"/></prod></vuln_soft></entry><entry CVSS_base_score="6.9" CVSS_exploit_subscore="3.4" CVSS_impact_subscore="10.0" CVSS_score="6.9" CVSS_vector="(AV:L/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-04-05" name="CVE-2007-0005" published="2007-03-09" seq="2007-0005" severity="Medium" type="CVE"><desc><descript source="cve">Multiple buffer overflows in the (1) read and (2) write handlers in the Omnikey CardMan 4040 driver in the Linux kernel before 2.6.21-rc3 allow local users to gain privileges.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="" url="http://kernel.org/pub/linux/kernel/v2.6/testing/ChangeLog-2.6.21-rc3"></ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/462300/100/0/threaded">20070309 Buffer Overflow in Linux Drivers for Omnikey CardMan 4040 (CVE-2007-0005)</ref><ref source="FEDORA" url="http://fedoranews.org/cms/node/2787">FEDORA-2007-335</ref><ref source="FEDORA" url="http://fedoranews.org/cms/node/2788">FEDORA-2007-336</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2007-0099.html">RHSA-2007:0099</ref><ref source="BID" url="http://www.securityfocus.com/bid/22870">22870</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0872">ADV-2007-0872</ref><ref source="OSVDB" url="http://www.osvdb.org/33023">33023</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24436">24436</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24518">24518</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32880">kernel-cardman4040drivers-bo(32880)</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2007:078">
MDKSA-2007:078</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24777">
24777</ref><ref source="" url="https://issues.rpath.com/browse/RPL-1035"></ref><ref source="SECUNIA" url="http://secunia.com/advisories/24901">
24901</ref><ref source="DEBIAN" url="http://www.debian.org/security/2007/dsa-1286">
DSA-1286</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25078">
25078</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/471457">20070615 rPSA-2007-0124-1 kernel xen</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:078">MDKSA-2007:078</ref><ref source="UBUNTU" url="http://www.ubuntu.com/usn/usn-486-1">USN-486-1</ref><ref source="UBUNTU" url="http://www.ubuntu.com/usn/usn-489-1">USN-489-1</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25691">25691</ref><ref source="SECUNIA" url="http://secunia.com/advisories/26133">26133</ref><ref source="SECUNIA" url="http://secunia.com/advisories/26139">26139</ref></refs><vuln_soft><prod name="Omnikey Cardman" vendor="Linux"><vers num="4040"/></prod></vuln_soft></entry><entry CVSS_base_score="1.9" CVSS_exploit_subscore="3.4" CVSS_impact_subscore="2.9" CVSS_score="1.9" CVSS_vector="(AV:L/AC:M/Au:N/C:N/I:N/A:P)" CVSS_version="2.0" modified="2007-07-05" name="CVE-2007-0006" published="2007-02-06" seq="2007-0006" severity="Low" type="CVE"><desc><descript source="cve">The key serial number collision avoidance code in the key_alloc_serial function in Linux kernel 2.6.9 up to 2.6.20 allows local users to cause a denial of service (crash) via vectors that trigger a null dereference, as originally reported as &quot;spinlock CPU recursion.&quot;</descript></desc><impacts><impact source="nvd">The scheme for selecting serial numbers was changed from incrementing a counter to random number selection, increasing the likelihood of a serial number collision.</impact></impacts><loss_types><avail/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2007:060">MDKSA-2007:060</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2007-0085.html">RHSA-2007:0085</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2007-0099.html">RHSA-2007:0099</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2007_21_kernel.html">SUSE-SA:2007:021</ref><ref source="BID" url="http://www.securityfocus.com/bid/22539">22539</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24109">24109</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24259">24259</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24300">24300</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24429">24429</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24482">24482</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24547">24547</ref><ref source="UBUNTU" url="http://www.ubuntu.com/usn/usn-451-1">USN-451-1</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24752">24752</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/471457">20070615 rPSA-2007-0124-1 kernel xen</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:047">MDKSA-2007:047</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:060">MDKSA-2007:060</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25691">25691</ref><ref source="" url="http://bugzilla.kernel.org/show_bug.cgi?id=7727"></ref><ref source="" url="https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=227495"></ref><ref source="" url="https://issues.rpath.com/browse/RPL-1097"></ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2007:047">MDKSA-2007:047</ref></refs><vuln_soft><prod name="Kernel" vendor="Linux"><vers num="2.6.20" prev="1"/><vers num="2.6.9"/></prod></vuln_soft></entry><entry CVSS_base_score="3.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="4.9" CVSS_score="3.6" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:P)" CVSS_version="2.0" modified="2007-02-20" name="CVE-2007-0007" published="2007-02-19" seq="2007-0007" severity="Low" type="CVE"><desc><descript source="cve">gnucash 2.0.4 and earlier allows local users to overwrite arbitrary files via a symlink attack on the (1) gnucash.trace, (2) qof.trace, and (3) qof.trace.[PID] temporary files.</descript></desc><loss_types><avail/><int/></loss_types><vuln_types><other/></vuln_types><range><local/></range><refs><ref adv="1" source="" url="https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=223233"></ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/24225">24225</ref><ref source="" url="http://sourceforge.net/project/shownotes.php?group_id=192&amp;release_id=487446"></ref><ref source="FEDORA" url="http://fedoranews.org/cms/node/2725">
FEDORA-2007-256</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:046">
MDKSA-2007:046</ref><ref source="BID" url="http://www.securityfocus.com/bid/22610">
22610</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0653">
ADV-2007-0653</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24226">
24226</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24317">
24317</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32558">
gnucash-symlink(32558)</ref></refs><vuln_soft><prod name="GNUCash" vendor="GNUCash"><vers num="2.0.4" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2008-01-02" name="CVE-2007-0008" published="2007-02-26" seq="2007-0008" severity="Medium" type="CVE"><desc><descript source="cve">Integer underflow in the SSLv2 support in Mozilla Network Security Services (NSS) before 3.11.5, as used by Firefox before 1.5.0.10 and 2.x before 2.0.0.2, SeaMonkey before 1.0.8, Thunderbird before 1.5.0.10, and certain Sun Java System server products before 20070611, allows remote attackers to execute arbitrary code via a crafted SSLv2 server message containing a public key that is too short to encrypt the &quot;Master Secret&quot;, which results in a heap-based overflow.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref source="SLACKWARE" url="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2007&amp;m=slackware-security.374851">SSA:2007-066-03</ref><ref source="SLACKWARE" url="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2007&amp;m=slackware-security.363947">SSA:2007-066-04</ref><ref source="SLACKWARE" url="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2007&amp;m=slackware-security.338131">SSA:2007-066-05</ref><ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102945-1">102945</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2007_22_mozilla.html">SUSE-SA:2007:022</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/2141">ADV-2007-2141</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25597">25597</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24406">24406</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24455">24455</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24456">24456</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24457">24457</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24342">24342</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25588">25588</ref><ref adv="1" patch="1" source="" url="http://www.mozilla.org/security/announce/2007/mfsa2007-06.html"></ref><ref adv="1" source="IDEFENSE" url="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=482">20070223 Mozilla Network Security Services SSLv2 Client Integer Underflow Vulnerability</ref><ref adv="1" source="" url="https://bugzilla.mozilla.org/show_bug.cgi?id=364319"></ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/461336/100/0/threaded">20070226 rPSA-2007-0040-1 firefox</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/461809/100/0/threaded">20070303 rPSA-2007-0040-3 firefox thunderbird</ref><ref source="" url="https://issues.rpath.com/browse/RPL-1081"></ref><ref source="" url="https://issues.rpath.com/browse/RPL-1103"></ref><ref source="FEDORA" url="http://fedoranews.org/cms/node/2709">FEDORA-2007-278</ref><ref source="FEDORA" url="http://fedoranews.org/cms/node/2711">FEDORA-2007-279</ref><ref source="FEDORA" url="http://fedoranews.org/cms/node/2713">FEDORA-2007-281</ref><ref source="FEDORA" url="http://fedoranews.org/cms/node/2728">FEDORA-2007-293</ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200703-18.xml">GLSA-200703-18</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200703-22.xml">GLSA-200703-22</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2007:050">MDKSA-2007:050</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:052">MDKSA-2007:052</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2007-0079.html">RHSA-2007:0079</ref><ref source="REDHAT" url="http://rhn.redhat.com/errata/RHSA-2007-0077.html">RHSA-2007:0077</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2007-0078.html">RHSA-2007:0078</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2007-0097.html">RHSA-2007:0097</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2007-0108.html">RHSA-2007:0108</ref><ref source="SUSE" url="http://lists.suse.com/archive/suse-security-announce/2007-Mar/0001.html">SUSE-SA:2007:019</ref><ref source="UBUNTU" url="http://www.ubuntu.com/usn/usn-428-1">USN-428-1</ref><ref source="UBUNTU" url="http://www.ubuntu.com/usn/usn-431-1">USN-431-1</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/377812">VU#377812</ref><ref source="BID" url="http://www.securityfocus.com/bid/22694">22694</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0719">ADV-2007-0719</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0718">ADV-2007-0718</ref><ref source="OSVDB" url="http://www.osvdb.org/32105">32105</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017696">1017696</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24238">24238</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24252">24252</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24253">24253</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24277">24277</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24287">24287</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24290">24290</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24205">24205</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24328">24328</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24333">24333</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24343">24343</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24320">24320</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24293">24293</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24395">24395</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24384">24384</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24389">24389</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24410">24410</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24522">24522</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24562">24562</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32666">nss-mastersecret-bo(32666)</ref><ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102856-1">102856</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1165">ADV-2007-1165</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24703">
24703</ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20070301-01-P.asc">
20070301-01-P</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24650">
24650</ref><ref source="DEBIAN" url="http://www.debian.org/security/2007/dsa-1336">DSA-1336</ref><ref source="FEDORA" url="http://fedoranews.org/cms/node/2747">FEDORA-2007-308</ref><ref source="FEDORA" url="http://fedoranews.org/cms/node/2749">FEDORA-2007-309</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:050">MDKSA-2007:050</ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20070202-01-P.asc">20070202-01-P</ref><ref source="HP" url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00771742">HPSBUX02153</ref></refs><vuln_soft><prod name="Thunderbird" vendor="Mozilla"><vers num="1.5.0.10" prev="1"/></prod><prod name="SeaMonkey" vendor="Mozilla"><vers num="1.0.7" prev="1"/></prod><prod name="Network Security Services" vendor="Mozilla"><vers num="3.11.4" prev="1"/></prod><prod name="Firefox" vendor="Mozilla"><vers num="1.5.0.9" prev="1"/><vers num="2.0"/><vers num="2.0.0.1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2008-01-02" name="CVE-2007-0009" published="2007-02-26" seq="2007-0009" severity="Medium" type="CVE"><desc><descript source="cve">Stack-based buffer overflow in the SSLv2 support in Mozilla Network Security Services (NSS) before 3.11.5, as used by Firefox before 1.5.0.10 and 2.x before 2.0.0.2, Thunderbird before 1.5.0.10, SeaMonkey before 1.0.8, and certain Sun Java System server products before 20070611, allows remote attackers to execute arbitrary code via invalid &quot;Client Master Key&quot; length values.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref source="SLACKWARE" url="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2007&amp;m=slackware-security.374851">SSA:2007-066-03</ref><ref source="SLACKWARE" url="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2007&amp;m=slackware-security.363947">SSA:2007-066-04</ref><ref source="SLACKWARE" url="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2007&amp;m=slackware-security.338131">SSA:2007-066-05</ref><ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102945-1">102945</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2007_22_mozilla.html">SUSE-SA:2007:022</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/2141">ADV-2007-2141</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25597">25597</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24406">24406</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24455">24455</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24456">24456</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24457">24457</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24342">24342</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25588">25588</ref><ref source="" url="http://www.mozilla.org/security/announce/2007/mfsa2007-06.html"></ref><ref source="IDEFENSE" url="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=483">20070223 Mozilla Network Security Services SSLv2 Server Stack Overflow Vulnerability</ref><ref source="" url="https://bugzilla.mozilla.org/show_bug.cgi?id=364323"></ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/461336/100/0/threaded">20070226 rPSA-2007-0040-1 firefox</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/461809/100/0/threaded">20070303 rPSA-2007-0040-3 firefox thunderbird</ref><ref source="" url="https://issues.rpath.com/browse/RPL-1081"></ref><ref source="" url="https://issues.rpath.com/browse/RPL-1103"></ref><ref source="FEDORA" url="http://fedoranews.org/cms/node/2709">FEDORA-2007-278</ref><ref source="FEDORA" url="http://fedoranews.org/cms/node/2711">FEDORA-2007-279</ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200703-18.xml">GLSA-200703-18</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200703-22.xml">GLSA-200703-22</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2007:050">MDKSA-2007:050</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:052">MDKSA-2007:052</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2007-0079.html">RHSA-2007:0079</ref><ref source="REDHAT" url="http://rhn.redhat.com/errata/RHSA-2007-0077.html">RHSA-2007:0077</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2007-0078.html">RHSA-2007:0078</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2007-0097.html">RHSA-2007:0097</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2007-0108.html">RHSA-2007:0108</ref><ref source="SUSE" url="http://lists.suse.com/archive/suse-security-announce/2007-Mar/0001.html">SUSE-SA:2007:019</ref><ref source="UBUNTU" url="http://www.ubuntu.com/usn/usn-428-1">USN-428-1</ref><ref source="UBUNTU" url="http://www.ubuntu.com/usn/usn-431-1">USN-431-1</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/592796">VU#592796</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0719">ADV-2007-0719</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0718">ADV-2007-0718</ref><ref source="OSVDB" url="http://www.osvdb.org/32106">32106</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017696">1017696</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24253">24253</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24277">24277</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24287">24287</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24290">24290</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24333">24333</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24343">24343</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24293">24293</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24395">24395</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24384">24384</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24389">24389</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24410">24410</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24522">24522</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24562">24562</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32663">nss-clientmasterkey-bo(32663)</ref><ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102856-1">102856</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1165">ADV-2007-1165</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24703">24703</ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20070301-01-P.asc">20070301-01-P</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24650">24650</ref><ref source="DEBIAN" url="http://www.debian.org/security/2007/dsa-1336">DSA-1336</ref><ref source="FEDORA" url="http://fedoranews.org/cms/node/2747">FEDORA-2007-308</ref><ref source="FEDORA" url="http://fedoranews.org/cms/node/2749">FEDORA-2007-309</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:050">MDKSA-2007:050</ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20070202-01-P.asc">20070202-01-P</ref><ref source="HP" url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00771742">HPSBUX02153</ref></refs><vuln_soft><prod name="Thunderbird" vendor="Mozilla"><vers num="1.5.0.9" prev="1"/></prod><prod name="SeaMonkey" vendor="Mozilla"><vers num="1.0.7" prev="1"/></prod><prod name="Network Security Services" vendor="Mozilla"><vers num="3.11.4" prev="1"/></prod><prod name="Firefox" vendor="Mozilla"><vers num="2.0.0.1" prev="1"/><vers num="1.5.0.9" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0" modified="2007-01-24" name="CVE-2007-0010" published="2007-01-24" seq="2007-0010" severity="Low" type="CVE"><desc><descript source="cve">The GdkPixbufLoader function in GIMP ToolKit (GTK+) in GTK 2 (gtk2) before 2.4.13 allows context-dependent attackers to cause a denial of service (crash) via a malformed image file.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><local/></range><refs><ref adv="1" source="" url="https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=218932"></ref><ref adv="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2007-0019.html">RHSA-2007:0019</ref><ref source="" url="https://issues.rpath.com/browse/RPL-984"></ref><ref source="DEBIAN" url="http://lists.debian.org/debian-security-announce/debian-security-announce-2007/msg00011.html">
DSA-1256</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2007:039">
MDKSA-2007:039</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2007_02_sr.html">
SUSE-SR:2007:002</ref><ref source="UBUNTU" url="http://www.ubuntu.com/usn/usn-415-1">
USN-415-1</ref><ref source="BID" url="http://www.securityfocus.com/bid/22209">
22209</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0331">
ADV-2007-0331</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1017552">
1017552</ref><ref source="SECUNIA" url="http://secunia.com/advisories/23884">
23884</ref><ref source="SECUNIA" url="http://secunia.com/advisories/23933">
23933</ref><ref source="SECUNIA" url="http://secunia.com/advisories/23935">
23935</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24010">
24010</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24006">
24006</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24095">
24095</ref><ref source="SECUNIA" url="http://secunia.com/advisories/23984">
23984</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:039">MDKSA-2007:039</ref></refs><vuln_soft><prod name="GIMP ToolKit" vendor="The GIMP Team"><vers num="2.4.12"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0" modified="2007-11-06" name="CVE-2007-0011" published="2007-11-05" seq="2007-0011" severity="Medium" type="CVE"><desc><descript source="cve">The web portal interface in Citrix Access Gateway (aka Citrix Advanced Access Control) before Advanced Edition 4.5 HF1 places a session ID in the URL, which allows context-dependent attackers to hijack sessions by reading &quot;residual information&quot;, including the a referer log, browser history, or browser cache.</descript></desc><loss_types><conf/></loss_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/482626/100/100/threaded">20071022 Corsaire Security Advisory - Citrix Access Gateway session ID disclosure issue</ref><ref source="" url="http://support.citrix.com/article/CTX112803"></ref><ref source="" url="http://support.citrix.com/article/CTX113814"></ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/24975">24975</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/2583">ADV-2007-2583</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1018435">1018435</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/26143">26143</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/35510">citrix-access-unspeci-information-disclosure(35510)</ref></refs><vuln_soft><prod name="Access Gateway" vendor="Citrix"><vers edition="Advanced" num="4.5"/><vers edition="Standard" num="4.5"/></prod><prod name="Advanced Access Control" vendor="Citrix"><vers num="4.0"/><vers num="4.2"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:P)" CVSS_version="2.0" modified="2008-02-05" name="CVE-2007-0012" published="2008-01-09" seq="2007-0012" severity="Medium" type="CVE"><desc><descript source="cve">Sun JRE 5.0 before update 14 allows remote attackers to cause a denial of service (Internet Explorer crash) via an object tag with an encoded applet and an undefined name attribute, which triggers a NULL pointer dereference in jpiexp32.dll when the applet is decoded and passed to the JVM.</descript></desc><loss_types><avail/></loss_types><range><network/><user_init/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/485942/100/0/threaded">20080108 Corsaire Security Advisory: Sun J2RE DoS issue</ref><ref source="BID" url="http://www.securityfocus.com/bid/27185">27185</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/39549">sun-java-jpiexp32-dos(39549)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/3527">3527</ref></refs><vuln_soft><prod name="JRE" vendor="Sun"><vers num="5.0 Update 7" prev="1"/><vers num="5.0 Update 8" prev="1"/><vers num="5.0 Update 9" prev="1"/><vers num="5.0 Update10" prev="1"/><vers num="5.0 Update11" prev="1"/><vers num="5.0 Update12" prev="1"/><vers num="5.0 Update13" prev="1"/></prod></vuln_soft></entry><entry modified="2007-01-17" name="CVE-2007-0014" published="2007-01-16" reject="1" seq="2007-0014" type="CVE"><desc><descript source="cve">ChainKey Java Code Protection allows attackers to decompile Java class files via a Java class loader with a modified defineClass method that saves the bytecode to a file before it is passed to the JVM.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/456712/100/0/threaded">20070112 Corsaire Security Advisory: ChainKey Java Code Protection Bypass issue</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/456734/100/0/threaded">20070112 Re: Corsaire Security Advisory: ChainKey Java Code Protection Bypass issue</ref></refs><vuln_soft><prod name="ChainKey Java Code Protection" vendor="Sun"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-01-25" name="CVE-2007-0015" published="2007-01-01" seq="2007-0015" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in Apple QuickTime 7.1.3 allows remote attackers to execute arbitrary code via a long rtsp:// URI.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/><user_init/></range><refs><ref source="" url="http://projects.info-pull.com/moab/MOAB-01-01-2007.html"></ref><ref source="Milw0rm" url="http://www.milw0rm.com/exploits/3064">Exploit 3064</ref><ref source="BID" url="http://www.securityfocus.com/bid/21829">21829</ref><ref source="" url="http://landonf.bikemonkey.org/code/macosx/MOAB_Day_1.20070102060815.15950.zadder.local.html"></ref><ref source="SECTRACK" url="http://securitytracker.com/id?1017461">1017461</ref><ref patch="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/442497">VU#442497</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0001">ADV-2007-0001</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/23540">23540</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/31203">quicktime-rtsp-url-bo(31203)</ref><ref source="MILW0RM" url="http://milw0rm.com/exploits/3064">
3064</ref><ref source="" url="http://isc.sans.org/diary.html?storyid=2094"></ref><ref source="" url="http://secunia.com/blog/7/"></ref><ref source="" url="http://docs.info.apple.com/article.html?artnum=304989"></ref><ref source="APPLE" url="http://lists.apple.com/archives/Security-announce/2007/Jan/msg00000.html">
APPLE-SA-2007-01-23</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA07-005A.html">
TA07-005A</ref><ref source="OSVDB" url="http://www.osvdb.org/31023">
31023</ref></refs><vuln_soft><prod name="Quicktime" vendor="Apple"><vers num="7.1.3"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2008-01-02" name="CVE-2007-0016" published="2007-01-02" seq="2007-0016" severity="High" type="CVE"><desc><descript source="cve">Stack-based buffer overflow in MoviePlay 4.76 allows remote attackers to execute arbitrary code via a long filename in a LST file.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref source="BID" url="http://www.securityfocus.com/bid/21840">21840</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/22959">22959</ref><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/4051">4051</ref></refs><vuln_soft><prod name="MoviePlay" vendor="Netfarer.com"><vers num="4.76"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-01-15" name="CVE-2007-0017" published="2007-01-02" seq="2007-0017" severity="Medium" type="CVE"><desc><descript source="cve">Multiple format string vulnerabilities in (1) the cdio_log_handler function in modules/access/cdda/access.c in the CDDA (libcdda_plugin) plugin, and the (2) cdio_log_handler and (3) vcd_log_handler functions in modules/access/vcdx/access.c in the VCDX (libvcdx_plugin) plugin, in VideoLAN VLC 0.7.0 through 0.8.6 allow user-assisted remote attackers to execute arbitrary code via format string specifiers in an invalid URI, as demonstrated by a udp://-- URI in an M3U file.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" source="" url="http://projects.info-pull.com/moab/MOAB-02-01-2007.html"></ref><ref source="SECUNIA" url="http://secunia.com/advisories/23592">23592</ref><ref source="MLIST" url="http://www.via.ecp.fr/via/ml/vlc-devel/2007-01/msg00005.html">[vlc-devel] 20070102 Security hole in VLC media player for Mac...</ref><ref source="" url="http://applefun.blogspot.com/2007/01/moab-02-01-2007-vlc-media-player-udp.html"></ref><ref source="" url="http://landonf.bikemonkey.org/code/macosx/MOAB_Day_2.20070103045559.6753.timor.html"></ref><ref source="" url="http://trac.videolan.org/vlc/changeset/18481"></ref><ref source="" url="http://www.videolan.org/patches/vlc-0.8.6-MOAB-02-01-2007.patch"></ref><ref source="" url="http://www.videolan.org/sa0701.html"></ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0026">ADV-2007-0026</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1017464">1017464</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31226">vlcmediaplayer-udp-format-string(31226)</ref><ref source="BID" url="http://www.securityfocus.com/bid/21852">21852</ref><ref source="DEBIAN" url="http://www.debian.org/security/2007/dsa-1252">
DSA-1252</ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200701-24.xml">
GLSA-200701-24</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2007_13_xine.html">
SUSE-SA:2007:013</ref><ref source="SECUNIA" url="http://secunia.com/advisories/23829">
23829</ref><ref source="SECUNIA" url="http://secunia.com/advisories/23910">
23910</ref><ref source="SECUNIA" url="http://secunia.com/advisories/23971">
23971</ref></refs><vuln_soft><prod name="VLC" vendor="VideoLAN"><vers num="0.8.6"/></prod></vuln_soft></entry><entry CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" CVSS_score="9.3" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2008-01-21" name="CVE-2007-0018" published="2007-01-24" seq="2007-0018" severity="High" type="CVE"><desc><descript source="cve">Stack-based buffer overflow in the NCTAudioFile2.AudioFile ActiveX control (NCTAudioFile2.dll), as used by multiple products, allows remote attackers to execute arbitrary code via a long argument to the SetFormatLikeSample function. NOTE: the products include (1) NCTsoft NCTAudioStudio, NCTAudioEditor, and NCTDialogicVoice; (2) Magic Audio Recorder, Music Editor, and Audio Converter; (3) Aurora Media Workshop; DB Audio Mixer And Editor; (4) J. Hepple Products including Fx Audio Editor and others; (5) EXPStudio Audio Editor; (6) iMesh; (7) Quikscribe; (8) RMBSoft AudioConvert and SoundEdit Pro 2.1; (9) CDBurnerXP; (10) Code-it Software Wave MP3 Editor and aBasic Editor; (11) Movavi VideoMessage, DVD to iPod, and others; (12) SoftDiv Software Dexster, iVideoMAX, and others; (13) Sienzo Digital Music Mentor (DMM); (14) MP3 Normalizer; (15) Roemer Software FREE and Easy Hi-Q Recorder, and Easy Hi-Q Converter; (16) Audio Edit Magic; (17) Joshua Video and Audio Converter; (18) Virtual CD; (19) Cheetah CD and DVD Burner; (20) Mystik Media AudioEdit Deluxe, Blaze Media, and others; (21) Power Audio Editor; (22) DanDans Digital Media Full Audio Converter, Music Editing Master, and others; (23) Xrlly Software Text to Speech Makerand Arial Sound Recorder / Audio Converter; (24) Absolute Sound Recorder, Video to Audio Converter, and MP3 Splitter; (25) Easy Ringtone Maker; (26) RecordNRip; (27) McFunSoft iPod Audio Studio, Audio Recorder for Free, and others; (28) MP3 WAV Converter; (29) BearShare 6.0.2.26789; and (30) Oracle Siebel SimBuilder and CRM 7.x.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" other="1" user="1"/></loss_types><vuln_types><input bound="1" buffer="1"/></vuln_types><range><network/><user_init/></range><refs><ref source="SECUNIA" url="http://secunia.com/advisories/23534">
23534</ref><ref source="SECUNIA" url="http://secunia.com/advisories/23535">
23535</ref><ref source="SECUNIA" url="http://secunia.com/advisories/23536">
23536</ref><ref source="SECUNIA" url="http://secunia.com/advisories/23541">
23541</ref><ref source="SECUNIA" url="http://secunia.com/advisories/23542">
23542</ref><ref source="SECUNIA" url="http://secunia.com/advisories/23544">
23544</ref><ref source="SECUNIA" url="http://secunia.com/advisories/23546">
23546</ref><ref source="SECUNIA" url="http://secunia.com/advisories/23548">
23548</ref><ref source="SECUNIA" url="http://secunia.com/advisories/23550">
23550</ref><ref source="SECUNIA" url="http://secunia.com/advisories/23554">
23554</ref><ref source="SECUNIA" url="http://secunia.com/advisories/23558">
23558</ref><ref source="SECUNIA" url="http://secunia.com/advisories/23560">
23560</ref><ref source="SECUNIA" url="http://secunia.com/advisories/23561">
23561</ref><ref source="SECUNIA" url="http://secunia.com/advisories/23562">
23562</ref><ref source="SECUNIA" url="http://secunia.com/advisories/23565">
23565</ref><ref source="SECUNIA" url="http://secunia.com/advisories/23745">
23745</ref><ref source="SECUNIA" url="http://secunia.com/advisories/23753">
23753</ref><ref source="SECUNIA" url="http://secunia.com/advisories/23795">
23795</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31707">
nctaudiofile2-multiple-bo(31707)</ref><ref source="" url="http://secunia.com/secunia_research/2007-50/advisory/"></ref><ref source="BID" url="http://www.securityfocus.com/bid/22196">
22196</ref><ref source="BID" url="http://www.securityfocus.com/bid/23892">
23892</ref><ref source="SECUNIA" url="http://secunia.com/advisories/22922">
22922</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/457965/100/200/threaded">20070124 Re: Secunia Research: NCTsoft Products NCTAudioFile2 ActiveXControl Buffer Overflow</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/457936/100/200/threaded">20070124 Secunia Research: NCTsoft Products NCTAudioFile2 ActiveX ControlBuffer Overflow</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/457940/100/200/threaded">20070124 Secunia Research: Sienzo Digital Music Mentor NCTAudioFile2ActiveX Control Buffer Overflow</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25993">25993</ref><ref source="SECUNIA" url="http://secunia.com/advisories/26046">26046</ref><ref source="SECUNIA" url="http://secunia.com/advisories/26100">26100</ref><ref source="SECUNIA" url="http://secunia.com/advisories/26101">26101</ref><ref source="SECUNIA" url="http://secunia.com/advisories/28407">28407</ref><ref adv="1" source="" url="http://secunia.com/secunia_research/2007-2/advisory/"></ref><ref adv="1" source="" url="http://secunia.com/secunia_research/2007-3/advisory/"></ref><ref adv="1" source="" url="http://secunia.com/secunia_research/2007-4/advisory/"></ref><ref adv="1" source="" url="http://secunia.com/secunia_research/2007-5/advisory/"></ref><ref adv="1" source="" url="http://secunia.com/secunia_research/2007-6/advisory/"></ref><ref adv="1" source="" url="http://secunia.com/secunia_research/2007-7/advisory/"></ref><ref adv="1" source="" url="http://secunia.com/secunia_research/2007-8/advisory/"></ref><ref adv="1" source="" url="http://secunia.com/secunia_research/2007-9/advisory/"></ref><ref source="" url="http://secunia.com/secunia_research/2007-10/advisory/"></ref><ref adv="1" source="" url="http://secunia.com/secunia_research/2007-11/advisory/"></ref><ref adv="1" source="" url="http://secunia.com/secunia_research/2007-12/advisory/"></ref><ref adv="1" source="" url="http://secunia.com/secunia_research/2007-13/advisory/"></ref><ref adv="1" source="" url="http://secunia.com/secunia_research/2007-14/advisory/"></ref><ref adv="1" source="" url="http://secunia.com/secunia_research/2007-15/advisory/"></ref><ref adv="1" source="" url="http://secunia.com/secunia_research/2007-16/advisory/"></ref><ref adv="1" source="" url="http://secunia.com/secunia_research/2007-17/advisory/"></ref><ref adv="1" source="" url="http://secunia.com/secunia_research/2007-18/advisory/"></ref><ref adv="1" source="" url="http://secunia.com/secunia_research/2007-19/advisory/"></ref><ref adv="1" source="" url="http://secunia.com/secunia_research/2007-20/advisory/"></ref><ref adv="1" source="" url="http://secunia.com/secunia_research/2007-21/advisory/"></ref><ref adv="1" source="" url="http://secunia.com/secunia_research/2007-22/advisory/"></ref><ref adv="1" source="" url="http://secunia.com/secunia_research/2007-23/advisory/"></ref><ref adv="1" source="" url="http://secunia.com/secunia_research/2007-24/advisory/"></ref><ref adv="1" source="" url="http://secunia.com/secunia_research/2007-25/advisory/"></ref><ref adv="1" source="" url="http://secunia.com/secunia_research/2007-26/advisory/"></ref><ref adv="1" source="" url="http://secunia.com/secunia_research/2007-27/advisory/"></ref><ref adv="1" source="" url="http://secunia.com/secunia_research/2007-28/advisory/"></ref><ref adv="1" source="" url="http://secunia.com/secunia_research/2007-29/advisory/"></ref><ref adv="1" source="" url="http://secunia.com/secunia_research/2007-30/advisory/"></ref><ref adv="1" source="" url="http://secunia.com/secunia_research/2007-31/advisory/"></ref><ref adv="1" source="" url="http://secunia.com/secunia_research/2007-32/advisory/"></ref><ref adv="1" source="" url="http://secunia.com/secunia_research/2007-33/advisory/"></ref><ref adv="1" source="" url="http://secunia.com/secunia_research/2007-34/advisory/"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0310">ADV-2007-0310</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/23475">23475</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/23493">23493</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/23532">23532</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/23543">23543</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/23551">23551</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/23552">23552</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/23553">23553</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/23557">23557</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/23568">23568</ref><ref adv="1" source="" url="http://secunia.com/blog/6/"></ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/292713">VU#292713</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/23485">23485</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/23495">23495</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/23511">23511</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/23516">23516</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/23530">23530</ref></refs><vuln_soft><prod name="Fx Audio ConCat" vendor="J Hepple Products"><vers num="1.2.0 Beta"/></prod><prod name="Arial Audio Converter" vendor="Xrlly Software"><vers num="2.3.40"/></prod><prod name="AudioConvert" vendor="RMBSoft"><vers num="3.1.0.125"/></prod><prod name="iMesh" vendor="iMesh.com"><vers num="7.0.2.26789"/></prod><prod name="NCTAudioFile2" vendor="NCTsoft Products"><vers num=""/></prod><prod name="Quikscribe Recorder" vendor="Quikscribe"><vers num="5.021.29"/></prod><prod name="RecordNRip" vendor="RecordNRip"><vers num="1.0"/></prod><prod name="Recording to iPod Solution" vendor="McFunSoft"><vers num="5.1"/></prod><prod name="Visual Video Converter" vendor="Dandans Digital Media Products"><vers num="4.4"/></prod><prod name="Absolute MP3 Splitter" vendor="iAudioSoft.com"><vers num="2.5.4"/></prod><prod name="Audio Recorder for Free" vendor="McFunSoft"><vers num="6.1"/></prod><prod name="iPod Audio Studio" vendor="McFunSoft"><vers num="6.2.4"/></prod><prod name="Digital Music Mentor" vendor="Sienzo"><vers num="2.6.0.3"/></prod><prod name="CDBurnerXP Pro" vendor="CDBurnerXP"><vers num="3.0.116"/></prod><prod name="ChiliBurner" vendor="Movavi"><vers num="2.3"/></prod><prod name="iVideoMAX" vendor="SoftDiv Softare"><vers num="3.9"/></prod><prod name="VideoMessage" vendor="Movavi"><vers num="1.0"/></prod><prod name="Magic Audio Converter" vendor="MagicVideoSoftare"><vers num="8.2.6 build 719"/></prod><prod name="Magic Audio Editor Pro" vendor="XWaver.com"><vers num="10.3.1 Build 476"/></prod><prod name="Fx Movie Splitter" vendor="J Hepple Products"><vers num="6.4.7"/></prod><prod name="ConvertMovie" vendor="Movavi"><vers num="4.4"/></prod><prod name="Audio Editor" vendor="McFunSoft"><vers num="6.3.3 Build 489"/></prod><prod name="Blaze MediaConvert" vendor="Mystik Media Products"><vers num="3.4"/></prod><prod name="ContextConvert Pro" vendor="Mystik Media Products"><vers num="3.1"/></prod><prod name="Quikscribe Player" vendor="Quikscribe"><vers num="5.022.05"/></prod><prod name="Easy Audio Editor" vendor="Dandans Digital Media Products"><vers num="7.4"/></prod><prod name="Audio Edit Magic" vendor="Audio Edit Magic"><vers num="9.2.3_389"/></prod><prod name="SoundEdit Pro" vendor="RMBSoft"><vers num="2.1"/></prod><prod name="Fx New Sound" vendor="J Hepple Products"><vers num="5.1.1"/></prod><prod name="Virtual CD" vendor="Virtual CD"><vers num="6.0.0.7"/><vers num="7.1.0.2"/><vers num="8.0.0.6"/></prod><prod name="Music Editing Master" vendor="Dandans Digital Media Products"><vers num="5.2"/></prod><prod name="Cheetah DVD Burner" vendor="CheetahBurner"><vers num="1.79"/></prod><prod name="Audio Studio Gold" vendor="NextLevel Systems"><vers num="7.0.1.1 Build 500"/></prod><prod name="Magic Music Editor" vendor="MagicVideoSoftare"><vers num="5.2.2"/></prod><prod name="Suite" vendor="Movavi"><vers num="3.5"/></prod><prod name="MP3 Record&amp;Edit Audio Master" vendor="Altdo"><vers num="1.2"/></prod><prod name="Audio Editor Gold" vendor="NextLevel Systems"><vers num="9.2.5 Build 424"/></prod><prod name="FREE Hi-Q Recorder" vendor="Roemer Software"><vers num="1.9"/></prod><prod name="aBasic Editor" vendor="Code-It Softare"><vers num="10.1"/></prod><prod name="Audio Editor" vendor="EXPStudio"><vers num="4.0.2"/></prod><prod name="Full Audio Converter" vendor="Dandans Digital Media Products"><vers num="4.2"/></prod><prod name="Aurora Media Workshop" vendor="Mediatox"><vers num="3.3.25"/></prod><prod name="MP3 Normalizer" vendor="MP3-Soft"><vers num="1.03"/></prod><prod name="NCTDialogicVoice" vendor="NCTsoft Products"><vers num="2.7.1"/></prod><prod name="BearShare" vendor="BearShare"><vers num="6.0.2.26789"/></prod><prod name="Virtual CD File Server" vendor="Virtual CD"><vers num="7.1.0.3"/></prod><prod name="Convert Mp3 Master" vendor="Altdo"><vers num="1.1"/></prod><prod name="Easy Hi-Q Recorder" vendor="Roemer Software"><vers num="2.0"/></prod><prod name="MP3 to WAV Converter" vendor="SoftDiv Softare"><vers num="3.0"/></prod><prod name="Fx Audio Editor" vendor="J Hepple Products"><vers num="4.7.11"/></prod><prod name="Easy Ringtone Maker" vendor="Easy Ringtone Maker"><vers num="2.0.5"/></prod><prod name="Fx Movie Joiner and Splitter" vendor="J Hepple Products"><vers num="6.2.8"/></prod><prod name="Power Audio Editor" vendor="Smart Media Systems"><vers num="11.0.1"/></prod><prod name="Dexster" vendor="SoftDiv Softare"><vers num="3.0"/></prod><prod name="Cheetah CD Burner" vendor="CheetahBurner"><vers num="3.56"/></prod><prod name="Magic Audio Recorder" vendor="MagicVideoSoftare"><vers num="5.3.7"/></prod><prod name="Video Converter Plus" vendor="Joshua Mediasoft"><vers num="3.01"/></prod><prod name="Absolute Sound Recorder" vendor="iAudioSoft.com"><vers num="3.4.5"/></prod><prod name="Fx Audio Tools" vendor="J Hepple Products"><vers num="7.3.4"/></prod><prod name="iPod Music Converter" vendor="McFunSoft"><vers num="5.1"/></prod><prod name="Easy Hi-Q Converter" vendor="Roemer Software"><vers num="1.7"/></prod><prod name="Magic Music Studio Pro" vendor="XWaver.com"><vers num="7.0.2.1 Build 500"/></prod><prod name="Text to Speech Maker" vendor="Xrlly Software"><vers num="1.3.8"/></prod><prod name="VIDEOzilla" vendor="SoftDiv Softare"><vers num="2.5"/></prod><prod name="Fx Magic Music" vendor="J Hepple Products"><vers num="5.7.7"/></prod><prod name="Audio Mixer And Editor" vendor="Digital Borneo"><vers num="1.1.0"/></prod><prod name="Arial Sound Recorder" vendor="Xrlly Software"><vers num="1.4.3"/></prod><prod name="DVD to iPod" vendor="Movavi"><vers num="1.0"/></prod><prod name="Blaze Media Pro" vendor="Mystik Media Products"><vers num="7.0"/></prod><prod name="NCTAudioEditor" vendor="NCTsoft Products"><vers num="2.7.1"/></prod><prod name="AudioEdit Deluxe" vendor="Mystik Media Products"><vers num="4.10"/></prod><prod name="NCTAudioStudio" vendor="NCTsoft Products"><vers num="2.7.1"/></prod><prod name="Absolute Video to Audio Converter" vendor="iAudioSoft.com"><vers num="2.7.9"/></prod><prod name="Fx Video Converter" vendor="J Hepple Products"><vers num="7.51.21"/></prod><prod name="Snosh" vendor="SoftDiv Softare"><vers num="1.4"/></prod><prod name="Audio Studio" vendor="McFunSoft"><vers num="6.6.3 Build 479"/></prod><prod name="MP3 WAV Converter" vendor="AmericanShareware"><vers num="3.1.8"/></prod><prod name="Fx Movie Joiner" vendor="J Hepple Products"><vers num="6.2.8"/></prod><prod name="Wave MP3 Editor" vendor="Code-It Softare"><vers num="10.1"/></prod><prod name="Audio Convertor Plus" vendor="Joshua Mediasoft"><vers num="2.2"/></prod><prod name="SplitMovie" vendor="Movavi"><vers num="1.4"/></prod></vuln_soft></entry><entry CVSS_base_score="6.5" CVSS_exploit_subscore="8.0" CVSS_impact_subscore="6.4" CVSS_score="6.5" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-01-21" name="CVE-2007-0019" published="2007-01-19" seq="2007-0019" severity="Medium" type="CVE"><desc><descript source="cve">Multiple heap-based buffer overflows in rumpusd in Rumpus 5.1 and earlier (1) allow remote authenticated users to execute arbitrary code via a long LIST command and other unspecified requests to the FTP service, and (2) allow remote attackers to execute arbitrary code via unspecified requests to the HTTP service.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="" url="http://projects.info-pull.com/moab/MOAB-18-01-2007.html"></ref><ref source="SECUNIA" url="http://secunia.com/advisories/23842">
23842</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31594">
rumpus-ftp-service-bo(31594)</ref></refs><vuln_soft><prod name="Rumpus FTP Server" vendor="Maxum Development Corporation"><vers num="5.1" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" CVSS_score="9.3" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-01-24" name="CVE-2007-0020" published="2007-01-23" seq="2007-0020" severity="High" type="CVE"><desc><descript source="cve">Heap-based buffer overflow in the SFTP protocol handler for Panic Transmit (Transmit.app) up to 3.5.5 allows remote attackers to execute arbitrary code via a long ftps:// URL.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" source="" url="http://projects.info-pull.com/moab/MOAB-19-01-2007.html"></ref><ref source="" url="http://www.milw0rm.com/exploits/3160"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0273">ADV-2007-0273</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/23861">23861</ref><ref source="MILW0RM" url="http://milw0rm.com/exploits/3160">
3160</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31673">
transmit-url-handler-bo(31673)</ref></refs><vuln_soft><prod name="Panic Transmit" vendor="Panic Transmit"><vers num="3.5.5" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-01-22" name="CVE-2007-0021" published="2007-01-22" seq="2007-0021" severity="High" type="CVE"><desc><descript source="cve">Format string vulnerability in Apple iChat 3.1.6 allows remote attackers to cause a denial of service (null pointer dereference and application crash) and possibly execute arbitrary code via format string specifiers in an aim:// URI.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="" url="http://projects.info-pull.com/moab/MOAB-20-01-2007.html"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0274">ADV-2007-0274</ref><ref source="" url="http://docs.info.apple.com/article.html?artnum=305102"></ref><ref source="APPLE" url="http://lists.apple.com/archives/Security-announce/2007/Feb/msg00000.html">
APPLE-SA-2007-02-15</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA07-047A.html">
TA07-047A</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/794752">
VU#794752</ref><ref source="BID" url="http://www.securityfocus.com/bid/22146">
22146</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017661">
1017661</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24198">
24198</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31679">
ichat-aim-format-string(31679)</ref></refs><vuln_soft><prod name="iChat" vendor="Apple"><vers num="3.1.6"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-07-05" name="CVE-2007-0022" published="2007-01-22" seq="2007-0022" severity="High" type="CVE"><desc><descript source="cve">Untrusted search path vulnerability in writeconfig in Apple Mac OS X 10.4.8 allows local users to gain privileges via a modified PATH that points to a malicious launchctl program.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input/></vuln_types><range><local/></range><refs><ref adv="1" source="" url="http://projects.info-pull.com/moab/MOAB-21-01-2007.html"></ref><ref source="OSVDB" url="http://www.osvdb.org/31605">31605</ref><ref source="SECUNIA" url="http://secunia.com/advisories/23793">23793</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31677">macos-writeconfig-privilege-escalation(31677)</ref><ref source="" url="http://docs.info.apple.com/article.html?artnum=305391"></ref><ref source="APPLE" url="http://lists.apple.com/archives/Security-announce/2007/Apr/msg00001.html">APPLE-SA-2007-04-19</ref><ref source="BID" url="http://www.securityfocus.com/bid/22148">22148</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1470">ADV-2007-1470</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017941">1017941</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24966">24966</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA07-109A.html">TA07-109A</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0074">ADV-2007-0074</ref></refs><vuln_soft><prod name="Mac OS X" vendor="Apple"><vers num="10.4.8"/></prod></vuln_soft></entry><entry CVSS_base_score="6.9" CVSS_exploit_subscore="3.4" CVSS_impact_subscore="10.0" CVSS_score="6.9" CVSS_vector="(AV:L/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-01-24" name="CVE-2007-0023" published="2007-01-23" seq="2007-0023" severity="Medium" type="CVE"><desc><descript source="cve">The CFUserNotificationSendRequest function in UserNotificationCenter.app in Apple Mac OS X 10.4.8, when used in combination with diskutil, allows local users to gain privileges via a malicious InputManager in Library/InputManagers in a user&apos;s home directory, which is executed when Cocoa applications attempt to notify the user.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input/></vuln_types><range><local/></range><refs><ref adv="1" source="" url="http://projects.info-pull.com/moab/MOAB-22-01-2007.html"></ref><ref source="" url="http://docs.info.apple.com/article.html?artnum=305102"></ref><ref source="APPLE" url="http://lists.apple.com/archives/Security-announce/2007/Feb/msg00000.html">
APPLE-SA-2007-02-15</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA07-047A.html">
TA07-047A</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/315856">
VU#315856</ref><ref source="BID" url="http://www.securityfocus.com/bid/22188">
22188</ref><ref source="OSVDB" url="http://www.osvdb.org/32695">
32695</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1017542">
1017542</ref><ref source="SECUNIA" url="http://secunia.com/advisories/23846">
23846</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24198">
24198</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31676">
macos-inputmanager-privilege-escalation(31676)</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0074">ADV-2007-0074</ref></refs><vuln_soft><prod name="Mac OS X" vendor="Apple"><vers num="10.4.8"/></prod></vuln_soft></entry><entry CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" CVSS_score="9.3" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-05-14" name="CVE-2007-0024" published="2007-01-09" seq="2007-0024" severity="High" type="CVE"><desc><descript source="cve">Integer overflow in the Vector Markup Language (VML) implementation (vgx.dll) in Microsoft Internet Explorer 5.01, 6, and 7 on Windows 2000 SP4, XP SP2, Server 2003, and Server 2003 SP1 allows remote attackers to execute arbitrary code via a crafted web page that contains unspecified integer properties that cause insufficient memory allocation and trigger a buffer overflow, aka the &quot;VML Buffer Overrun Vulnerability.&quot;</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" patch="1" source="IDEFENSE" url="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=462">20070109 Microsoft Windows VML Element Integer Overflow Vulnerability</ref><ref patch="1" source="MS" url="http://www.microsoft.com/technet/security/Bulletin/MS07-004.mspx">MS07-004</ref><ref patch="1" source="MSKB" url="http://support.microsoft.com/?kbid=929969">929969</ref><ref patch="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/122084">VU#122084</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/21930">21930</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0105">ADV-2007-0105</ref><ref patch="1" source="OSVDB" url="http://www.osvdb.org/31250">31250</ref><ref patch="1" source="SECTRACK" url="http://securitytracker.com/id?1017489">1017489</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/23677">23677</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/31287">ie-vml-record-bo(31287)</ref><ref source="" url="http://support.avaya.com/elmodocs2/security/ASA-2007-009.htm"></ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0129">ADV-2007-0129</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA07-009A.html">TA07-009A</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/457053/100/0/threaded">20070116 MS07-004 VML Integer Overflow Exploit</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/457164/100/0/threaded">20070117 Re: MS07-004 VML Integer Overflow Exploit</ref><ref source="HP" url="http://www.securityfocus.com/archive/1/archive/1/457274/100/0/threaded">HPSBST02184</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1058">oval:org.mitre.oval:def:1058</ref></refs><vuln_soft><prod name="Internet Explorer" vendor="Microsoft"><vers num="5.01 SP4"/><vers num="6.0 SP1"/><vers num="7.0"/><vers num="7.0"/></prod></vuln_soft></entry><entry CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" CVSS_score="9.3" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-07-05" name="CVE-2007-0025" published="2007-02-13" seq="2007-0025" severity="High" type="CVE"><desc><descript source="cve">The MFC component in Microsoft Windows 2000 SP4, XP SP2, and 2003 SP1 and Visual Studio .NET 2000, 2002 SP1, 2003, and 2003 SP1 allows user-assisted remote attackers to execute arbitrary code via an RTF file with a malformed OLE object that triggers memory corruption. NOTE: this might be due to a stack-based buffer overflow in the the AfxOleSetEditMenu function in MFC42u.dll.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><exception/></vuln_types><range><network/><user_init/></range><refs><ref patch="1" source="MS" url="http://www.microsoft.com/technet/security/Bulletin/MS07-012.mspx">MS07-012</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/932041">VU#932041</ref><ref source="BID" url="http://www.securityfocus.com/bid/22476">22476</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0581">ADV-2007-0581</ref><ref source="OSVDB" url="http://www.osvdb.org/31887">31887</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017638">1017638</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24150">24150</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA07-044A.html">TA07-044A</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:157">oval:org.mitre.oval:def:157</ref></refs><vuln_soft><prod name="Visual Studio .NET" vendor="Microsoft"><vers num="2000"/><vers num="2000 SP1"/><vers num="2003"/><vers num="2000 SP1"/></prod><prod name="Windows Server 2003" vendor="Microsoft"><vers edition="SP4" num="2000"/><vers num="XP SP2"/><vers edition="SP2" num="2003"/></prod></vuln_soft></entry><entry CVSS_base_score="7.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="10.0" CVSS_score="7.6" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-02-16" name="CVE-2007-0026" published="2007-02-13" seq="2007-0026" severity="High" type="CVE"><desc><descript source="cve">The OLE Dialog component in Microsoft Windows 2000 SP4, XP SP2, and 2003 SP1 allows user-assisted remote attackers to execute arbitrary code via an RTF file with a malformed OLE object that triggers memory corruption.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><exception/></vuln_types><range><network/><user_init/></range><refs><ref patch="1" source="MS" url="http://www.microsoft.com/technet/security/Bulletin/MS07-011.mspx">MS07-011</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/497756">
VU#497756</ref><ref source="BID" url="http://www.securityfocus.com/bid/22483">
22483</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0580">
ADV-2007-0580</ref><ref source="OSVDB" url="http://www.osvdb.org/31885">
31885</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017637">
1017637</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24147">
24147</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA07-044A.html">TA07-044A</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:540">oval:org.mitre.oval:def:540</ref></refs><vuln_soft><prod name="Windows XP" vendor="Microsoft"><vers edition="Tablet PC" num="SP2"/></prod><prod name="Windows 2003" vendor="Microsoft"><vers num="SP1"/></prod><prod name="Windows 2000" vendor="Microsoft"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" CVSS_score="9.3" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-07-05" name="CVE-2007-0027" published="2007-01-09" seq="2007-0027" severity="High" type="CVE"><desc><descript source="cve">Microsoft Excel 2000 SP3, 2002 SP3, 2003 SP2, 2004 for Mac, and v.X for Mac allows remote attackers to execute arbitrary code via malformed IMDATA records that trigger memory corruption.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" patch="1" source="MS" url="http://www.microsoft.com/technet/security/Bulletin/MS07-002.mspx">MS07-002</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/749964">VU#749964</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/21856">21856</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0103">ADV-2007-0103</ref><ref patch="1" source="SECTRACK" url="http://securitytracker.com/id?1017487">1017487</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA07-009A.html">TA07-009A</ref><ref source="HP" url="http://www.securityfocus.com/archive/1/archive/1/457274/100/0/threaded">HPSBST02184</ref><ref source="OSVDB" url="http://www.osvdb.org/31255">31255</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:119">oval:org.mitre.oval:def:119</ref></refs><vuln_soft><prod name="Excel Viewer" vendor="Microsoft"><vers num="2003"/></prod><prod name="Office" vendor="Microsoft"><vers num="2000 SP3"/><vers num="XP SP3"/><vers num="2003 SP2"/><vers edition="Mac" num="2004"/><vers edition="Mac" num="v. X"/></prod><prod name="Works Suite" vendor="Microsoft"><vers num="2004"/><vers num="2005"/></prod><prod name="Excel" vendor="Microsoft"><vers num="2000"/><vers num="2002"/><vers num="2003"/></prod></vuln_soft></entry><entry CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" CVSS_score="9.3" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-05-14" name="CVE-2007-0028" published="2007-01-09" seq="2007-0028" severity="High" type="CVE"><desc><descript source="cve">Microsoft Excel 2000, 2002, 2003, Viewer 2003, Office 2004 for Mac, and Office v.X for Mac does not properly handle certain opcodes, which allows user-assisted remote attackers to execute arbitrary code via a crafted XLS file, which results in an &quot;Improper Memory Access Vulnerability.&quot;  NOTE: an early disclosure of this issue used CVE-2006-3432, but only CVE-2007-0028 should be used.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" patch="1" source="MS" url="http://www.microsoft.com/technet/security/Bulletin/MS07-002.mspx">MS07-002</ref><ref patch="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/493185">VU#493185</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0103">ADV-2007-0103</ref><ref source="" url="http://www.fortinet.com/FortiGuardCenter/advisory/FG-2006-30.html"></ref><ref source="" url="http://www.fortinet.com/FortiGuardCenter/advisory/FGA-2007-01.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/21952">21952</ref><ref source="SECUNIA" url="http://secunia.com/advisories/23676">23676</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA07-009A.html">TA07-009A</ref><ref source="HP" url="http://www.securityfocus.com/archive/1/archive/1/457274/100/0/threaded">HPSBST02184</ref><ref source="OSVDB" url="http://www.osvdb.org/31249">31249</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1017485">1017485</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:768">oval:org.mitre.oval:def:768</ref></refs><vuln_soft><prod name="Excel Viewer" vendor="Microsoft"><vers num="2003"/></prod><prod name="Office" vendor="Microsoft"><vers num="2000 SP3"/><vers num="XP SP3"/><vers num="2003 SP2"/><vers edition="Mac" num="2004"/><vers edition="Mac" num="v. X"/></prod><prod name="Works Suite" vendor="Microsoft"><vers num="2004"/><vers num="2005"/></prod><prod name="Excel" vendor="Microsoft"><vers num="2000"/><vers num="2002"/><vers num="2003"/></prod></vuln_soft></entry><entry CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" CVSS_score="9.3" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-05-14" name="CVE-2007-0029" published="2007-01-09" seq="2007-0029" severity="High" type="CVE"><desc><descript source="cve">Microsoft Excel 2000 SP3, 2002 SP3, 2003 SP2, 2004 for Mac, and v.X for Mac allows user-assisted remote attackers to execute arbitrary code via a malformed string, aka &quot;Excel Malformed String Vulnerability.&quot;</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" patch="1" source="MS" url="http://www.microsoft.com/technet/security/Bulletin/MS07-002.mspx">MS07-002</ref><ref source="BID" url="http://www.securityfocus.com/bid/21877">21877</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0103">ADV-2007-0103</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1017487">1017487</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA07-009A.html">TA07-009A</ref><ref source="HP" url="http://www.securityfocus.com/archive/1/archive/1/457274/100/0/threaded">HPSBST02184</ref><ref source="OSVDB" url="http://www.osvdb.org/31256">31256</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1102">oval:org.mitre.oval:def:1102</ref></refs><vuln_soft><prod name="Excel Viewer" vendor="Microsoft"><vers num="2003"/></prod><prod name="Office" vendor="Microsoft"><vers num="2000 SP3"/><vers num="XP SP3"/><vers num="2003 SP2"/><vers edition="Mac" num="2004"/><vers edition="Mac" num="v. X"/></prod><prod name="Works Suite" vendor="Microsoft"><vers num="2004"/><vers num="2005"/></prod><prod name="Excel" vendor="Microsoft"><vers num="2000"/><vers num="2002"/><vers num="2003"/></prod></vuln_soft></entry><entry CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" CVSS_score="9.3" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-05-14" name="CVE-2007-0030" published="2007-01-09" seq="2007-0030" severity="High" type="CVE"><desc><descript source="cve">Microsoft Excel 2000 SP3, 2002 SP3, 2003 SP2, 2004 for Mac, and v.X for Mac allows user-assisted remote attackers to execute arbitrary code via an Excel file with an out-of-range Column field in certain BIFF8 record types, which references arbitrary memory.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" patch="1" source="IDEFENSE" url="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=460">20070109 Microsoft Excel Invalid Column Heap Corruption Vulnerability</ref><ref adv="1" patch="1" source="MS" url="http://www.microsoft.com/technet/security/Bulletin/MS07-002.mspx">MS07-002</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/302836">VU#302836</ref><ref source="BID" url="http://www.securityfocus.com/bid/21925">21925</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0103">ADV-2007-0103</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1017487">1017487</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA07-009A.html">TA07-009A</ref><ref source="HP" url="http://www.securityfocus.com/archive/1/archive/1/457274/100/0/threaded">HPSBST02184</ref><ref source="OSVDB" url="http://www.osvdb.org/31257">31257</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:323">oval:org.mitre.oval:def:323</ref></refs><vuln_soft><prod name="Excel Viewer" vendor="Microsoft"><vers num="2003"/></prod><prod name="Office" vendor="Microsoft"><vers num="2000 SP3"/><vers num="XP SP3"/><vers num="2003 SP2"/><vers edition="Mac" num="2004"/><vers edition="Mac" num="v. X"/></prod><prod name="Works Suite" vendor="Microsoft"><vers num="2004"/><vers num="2005"/></prod><prod name="Excel" vendor="Microsoft"><vers num="2000"/><vers num="2002"/><vers num="2003"/></prod></vuln_soft></entry><entry CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" CVSS_score="9.3" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-05-14" name="CVE-2007-0031" published="2007-01-09" seq="2007-0031" severity="High" type="CVE"><desc><descript source="cve">Heap-based buffer overflow in Microsoft Excel 2000 SP3, 2002 SP3, 2003 SP2, 2004 for Mac, and v.X for Mac allows user-assisted remote attackers to execute arbitrary code via a BIFF8 spreadsheet with a PALETTE record that contains a large number of entries.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" patch="1" source="IDEFENSE" url="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=461">20070109 Microsoft Excel Long Palette Heap Overflow Vulnerability</ref><ref adv="1" patch="1" source="MS" url="http://www.microsoft.com/technet/security/Bulletin/MS07-002.mspx">MS07-002</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/625532">VU#625532</ref><ref source="BID" url="http://www.securityfocus.com/bid/21922">21922</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0103">ADV-2007-0103</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1017487">1017487</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA07-009A.html">TA07-009A</ref><ref source="HP" url="http://www.securityfocus.com/archive/1/archive/1/457274/100/0/threaded">HPSBST02184</ref><ref source="OSVDB" url="http://www.osvdb.org/31258">31258</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:753">oval:org.mitre.oval:def:753</ref></refs><vuln_soft><prod name="Excel Viewer" vendor="Microsoft"><vers num="2003"/></prod><prod name="Office" vendor="Microsoft"><vers num="2000 SP3"/><vers num="XP SP3"/><vers num="2003 SP2"/><vers edition="Mac" num="2004"/><vers edition="Mac" num="v. X"/></prod><prod name="Works Suite" vendor="Microsoft"><vers num="2004"/><vers num="2005"/></prod><prod name="Excel" vendor="Microsoft"><vers num="2000"/><vers num="2002"/><vers num="2003"/></prod></vuln_soft></entry><entry CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" CVSS_score="9.3" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-05-14" name="CVE-2007-0033" published="2007-01-09" seq="2007-0033" severity="High" type="CVE"><desc><descript source="cve">Microsoft Outlook 2002 and 2003 allows user-assisted remote attackers to execute arbitrary code via a malformed VEVENT record in an .iCal meeting request or ICS file.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" patch="1" source="MS" url="http://www.microsoft.com/technet/security/Bulletin/MS07-003.mspx">MS07-003</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/476900">VU#476900</ref><ref source="BID" url="http://www.securityfocus.com/bid/21931">21931</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0104">ADV-2007-0104</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1017488">1017488</ref><ref source="SECUNIA" url="http://secunia.com/advisories/23674">23674</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA07-009A.html">TA07-009A</ref><ref source="HP" url="http://www.securityfocus.com/archive/1/archive/1/457274/100/0/threaded">HPSBST02184</ref><ref source="OSVDB" url="http://www.osvdb.org/31252">31252</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:516">oval:org.mitre.oval:def:516</ref></refs><vuln_soft><prod name="Office" vendor="Microsoft"><vers num="2000 SP3"/><vers num="XP SP3"/><vers num="2003 SP2"/></prod><prod name="Outlook" vendor="Microsoft"><vers num="2000"/><vers num="2002"/><vers num="2003"/></prod></vuln_soft></entry><entry CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" CVSS_score="9.3" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-05-14" name="CVE-2007-0034" published="2007-01-09" seq="2007-0034" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in the Advanced Search (Finder.exe) feature of Microsoft Outlook 2000, 2002, and 2003 allows user-assisted remote attackers to execute arbitrary code via a crafted Outlook Saved Searches (OSS) file that triggers memory corruption, aka &quot;Microsoft Outlook Advanced Find Vulnerability.&quot;</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" patch="1" source="MS" url="http://www.microsoft.com/technet/security/Bulletin/MS07-003.mspx">MS07-003</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/271860">VU#271860</ref><ref source="BID" url="http://www.securityfocus.com/bid/21936">21936</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0104">ADV-2007-0104</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1017488">1017488</ref><ref source="SECUNIA" url="http://secunia.com/advisories/23674">23674</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/456589/100/0/threaded">20070111 Computer Terrorism (UK) :: Incident Response Centre - Microsoft Outlook Vulnerability</ref><ref source="" url="http://www.computerterrorism.com/research/ct09-01-2007.htm"></ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA07-009A.html">TA07-009A</ref><ref source="HP" url="http://www.securityfocus.com/archive/1/archive/1/457274/100/0/threaded">HPSBST02184</ref><ref source="OSVDB" url="http://www.osvdb.org/31254">31254</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:153">oval:org.mitre.oval:def:153</ref></refs><vuln_soft><prod name="Office" vendor="Microsoft"><vers num="2000 SP3"/><vers num="XP SP3"/><vers num="2003 SP2"/></prod><prod name="Outlook" vendor="Microsoft"><vers num="2000"/><vers num="2002"/><vers num="2003"/></prod></vuln_soft></entry><entry CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" CVSS_score="9.3" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-06-19" name="CVE-2007-0035" published="2007-05-08" seq="2007-0035" severity="High" type="CVE"><desc><descript source="cve">Word (or Word Viewer) in Microsoft Office 2000 SP3, XP SP3, 2003 SP2, 2004 for Mac, and Works Suite 2004, 2005, and 2006 does not properly handle data in a certain array, which allows user-assisted remote attackers to execute arbitrary code, aka the &quot;Word Array Overflow Vulnerability.&quot;</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><exception/></vuln_types><range><network/><user_init/></range><refs><ref patch="1" source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms07-024.mspx">MS07-024</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/260777">VU#260777</ref><ref source="BID" url="http://www.securityfocus.com/bid/23804">23804</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1709">ADV-2007-1709</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1018013">1018013</ref><ref source="OSVDB" url="http://www.osvdb.org/34387">34387</ref><ref source="HP" url="http://www.securityfocus.com/archive/1/archive/1/468871/100/200/threaded">HPSBST02214</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA07-128A.html">TA07-128A</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1737">oval:org.mitre.oval:def:1737</ref></refs><vuln_soft><prod name="Office" vendor="Microsoft"><vers num="2000 SP3"/><vers num="2002 SP3"/><vers num="2003 SP2"/><vers num="2003 Viewer"/><vers edition="Mac" num="2004"/></prod><prod name="Works Suite" vendor="Microsoft"><vers num="2004"/><vers num="2005"/><vers num="2006"/></prod></vuln_soft></entry><entry CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" CVSS_score="9.3" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-05-14" name="CVE-2007-0038" published="2007-03-30" seq="2007-0038" severity="High" type="CVE"><desc><descript source="cve">Stack-based buffer overflow in the animated cursor code in Microsoft Windows 2000 SP4 through Vista allows remote attackers to execute arbitrary code or cause a denial of service (persistent reboot) via a large length value in the second (or later) anih block of a RIFF .ANI, cur, or .ico file, which results in memory corruption when processing cursors, animated cursors, and icons, a variant of CVE-2005-0416, as originally demonstrated using Internet Explorer 6 and 7. NOTE: this might be a duplicate of CVE-2007-1765; if so, then CVE-2007-0038 should be preferred.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/><exception/></vuln_types><range><network/><user_init/></range><refs><ref source="FULLDISC" url="http://archives.neohapsis.com/archives/fulldisclosure/2007-03/0470.html">20070330 0-day ANI vulnerability in Microsoft Windows (CVE-2007-0038)</ref><ref adv="1" source="" url="http://www.determina.com/security_center/security_advisories/securityadvisory_0day_032907.asp"></ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA07-089A.html">TA07-089A</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/191609">VU#191609</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24659">24659</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/464269/100/0/threaded">20070330 0-day ANI vulnerability in Microsoft Windows (CVE-2007-0038)</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/464339/100/0/threaded">20070330 Re: 0-day ANI vulnerability in Microsoft Windows (CVE-2007-0038)</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/464342/100/0/threaded">20070331 RE: [Full-disclosure] 0-day ANI vulnerability in Microsoft Windows(CVE-2007-0038)</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/464340/100/0/threaded">20070331 Re: 0-day ANI vulnerability in Microsoft Windows (CVE-2007-0038)</ref><ref source="MILW0RM" url="http://milw0rm.com/exploits/3634">3634</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33301">windows-ani-code-execution(33301)</ref><ref source="MS" url="http://www.microsoft.com/technet/security/Bulletin/ms07-017.mspx">MS07-017</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA07-093A.html">TA07-093A</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1215">ADV-2007-1215</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/464459/100/100/threaded">20070402 More information on ZERT patch for ANI 0day</ref><ref source="HP" url="http://www.securityfocus.com/archive/1/archive/1/466186/100/200/threaded">
HPSBST02206</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/464460/100/100/threaded">20070402 MS announces out-of-band patch for ANI 0day</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA07-100A.html">TA07-100A</ref><ref source="OSVDB" url="http://www.osvdb.org/33629">33629</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1854">oval:org.mitre.oval:def:1854</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2542">2542</ref></refs><vuln_soft><prod name="Windows Vista" vendor="Microsoft"><vers num="Gold"/><vers edition="x64" num="Gold"/></prod><prod name="Windows XP" vendor="Microsoft"><vers num="SP2"/><vers edition="Professional x64" num="Gold"/><vers edition="Professional x64" num="SP2"/></prod><prod name="Windows Server 2003" vendor="Microsoft"><vers num="Gold"/><vers num="SP1"/><vers num="SP2"/><vers edition="Itanium" num="Gold"/><vers edition="Itanium" num="SP1"/><vers edition="Itanium" num="SP2"/><vers edition="x64" num="Gold"/><vers edition="x64" num="SP2"/></prod><prod name="Windows 2000" vendor="Microsoft"><vers num="SP4"/></prod></vuln_soft></entry><entry CVSS_base_score="7.8" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.9" CVSS_score="7.8" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_version="2.0" modified="2007-07-05" name="CVE-2007-0039" published="2007-05-08" seq="2007-0039" severity="High" type="CVE"><desc><descript source="cve">The Exchange Collaboration Data Objects (EXCDO) functionality in Microsoft Exchange Server 2000 SP3, 2003 SP1 and SP2, and 2007 allows remote attackers to cause a denial of service (crash) via an Internet Calendar (iCal) file containing multiple X-MICROSOFT-CDO-MODPROPS (MODPROPS) properties in which the second MODPROPS is longer than the first, which triggers a NULL pointer dereference and an unhandled exception.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/><exception/></vuln_types><range><network/></range><refs><ref patch="1" source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms07-026.mspx">MS07-026</ref><ref source="BID" url="http://www.securityfocus.com/bid/23808">23808</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1711">ADV-2007-1711</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1018015">1018015</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25183">25183</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/468047/100/0/threaded">20070508 Exchange Calendar MODPROPS Denial of Service (CVE-2007-0039)</ref><ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2007-May/063232.html">20070509 Exchange Calendar MODPROPS Denial of Service (CVE-2007-0039)</ref><ref source="" url="http://www.determina.com/security.research/vulnerabilities/exchange-ical-modprops.html"></ref><ref source="HP" url="http://www.securityfocus.com/archive/1/archive/1/468871/100/200/threaded">HPSBST02214</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA07-128A.html">TA07-128A</ref><ref source="OSVDB" url="http://www.osvdb.org/34390">34390</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1593">oval:org.mitre.oval:def:1593</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33888">exchange-ical-dos(33888)</ref></refs><vuln_soft><prod name="exchange srv" vendor="Microsoft"><vers num="2000 SP3"/><vers num="2003 SP1"/><vers num="2003 SP2"/><vers num="2007"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-07-12" name="CVE-2007-0040" published="2007-07-10" seq="2007-0040" severity="High" type="CVE"><desc><descript source="cve">The LDAP service in Windows Active Directory in Microsoft Windows 2000 Server SP4, Server 2003 SP1 and SP2, Server 2003 x64 Edition and SP2, and Server 2003 for Itanium-based Systems SP1 and SP2 allows remote attackers to execute arbitrary code via a crafted LDAP request with an unspecified number of &quot;convertible attributes.&quot;</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref patch="1" source="MS" url="http://www.microsoft.com/technet/security/Bulletin/ms07-039.mspx">MS07-039</ref><ref source="ISS" url="http://www.iss.net/threats/267.html">20070710 Microsoft Windows Active Directory Remote Code Execution</ref><ref source="HP" url="http://archive.cert.uni-stuttgart.de/bugtraq/2007/07/msg00254.html">SSRT071446</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA07-191A.html">TA07-191A</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/487905">VU#487905</ref><ref source="BID" url="http://www.securityfocus.com/bid/24800">24800</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/2481">ADV-2007-2481</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2012">oval:org.mitre.oval:def:2012</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1018355">1018355</ref><ref source="SECUNIA" url="http://secunia.com/advisories/26002">26002</ref></refs><vuln_soft><prod name="windows" vendor="Microsoft"><vers num="2000 Server SP4"/><vers num="2003 Server SP 1"/><vers num="2003 Server SP 2"/><vers num="2003 Server x64"/><vers num="2003 Server x64 SP2"/><vers num="2003 itanium sp1"/><vers num="2003 itanium sp2"/></prod></vuln_soft></entry><entry CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" CVSS_score="9.3" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-12-20" name="CVE-2007-0041" published="2007-07-10" seq="2007-0041" severity="High" type="CVE"><desc><descript source="cve">The PE Loader service in Microsoft .NET Framework 1.0, 1.1, and 2.0 for Windows 2000, XP, Server 2003, and Vista allows remote attackers to execute arbitrary code via unspecified vectors involving an &quot;unchecked buffer&quot; and unvalidated message lengths, probably a buffer overflow.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" patch="1" source="MS" url="http://www.microsoft.com/technet/security/Bulletin/ms07-040.mspx">MS07-040</ref><ref source="HP" url="http://archive.cert.uni-stuttgart.de/bugtraq/2007/07/msg00254.html">SSRT071446</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA07-191A.html">TA07-191A</ref><ref source="BID" url="http://www.securityfocus.com/bid/24778">24778</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/2482">ADV-2007-2482</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2093">oval:org.mitre.oval:def:2093</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1018356">1018356</ref><ref source="SECUNIA" url="http://secunia.com/advisories/26003">26003</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/34637">ms-dotnet-pe-loader-bo(34637)</ref></refs><vuln_soft><prod name=".NET Framework" vendor="Microsoft"><vers num="1.0"/><vers num="1.1"/><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.8" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.9" CVSS_score="7.8" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:N/A:N)" CVSS_version="2.0" modified="2007-12-21" name="CVE-2007-0042" published="2007-07-10" seq="2007-0042" severity="High" type="CVE"><desc><descript source="cve">Interpretation conflict in ASP.NET in Microsoft .NET Framework 1.0, 1.1, and 2.0 for Windows 2000, XP, Server 2003, and Vista allows remote attackers to access configuration files and obtain sensitive information, and possibly bypass security mechanisms that try to constrain the final substring of a string, via %00 characters, related to use of %00 as a string terminator within POSIX functions but a data character within .NET strings, aka &quot;Null Byte Termination Vulnerability.&quot;</descript></desc><loss_types><conf/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref source="MS" url="http://www.microsoft.com/technet/security/Bulletin/ms07-040.mspx">MS07-040</ref><ref source="" url="http://security-assessment.com/files/advisories/2007-07-11_Multiple_.NET_Null_Byte_Injection_Vulnerabilities.pdf"></ref><ref source="HP" url="http://archive.cert.uni-stuttgart.de/bugtraq/2007/07/msg00254.html">SSRT071446</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA07-191A.html">TA07-191A</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/2482">ADV-2007-2482</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2070">oval:org.mitre.oval:def:2070</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1018356">1018356</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/26003">26003</ref></refs><vuln_soft><prod name=".NET Framework" vendor="Microsoft"><vers num="1.0"/><vers num="1.1"/><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" CVSS_score="9.3" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-12-21" name="CVE-2007-0043" published="2007-07-10" seq="2007-0043" severity="High" type="CVE"><desc><descript source="cve">The Just In Time (JIT) Compiler service in Microsoft .NET Framework 1.0, 1.1, and 2.0 for Windows 2000, XP, Server 2003, and Vista allows user-assisted remote attackers to execute arbitrary code via unspecified vectors involving an &quot;unchecked buffer,&quot; probably a buffer overflow, aka &quot;.NET JIT Compiler Vulnerability&quot;.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" patch="1" source="MS" url="http://www.microsoft.com/technet/security/Bulletin/ms07-040.mspx">MS07-040</ref><ref source="HP" url="http://archive.cert.uni-stuttgart.de/bugtraq/2007/07/msg00254.html">SSRT071446</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA07-191A.html">TA07-191A</ref><ref source="BID" url="http://www.securityfocus.com/bid/24811">24811</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/2482">ADV-2007-2482</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1873">oval:org.mitre.oval:def:1873</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1018356">1018356</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/26003">26003</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/34639">ms-dotnet-jit-bo(34639)</ref></refs><vuln_soft><prod name=".NET Framework" vendor="Microsoft"><vers num="1.0"/><vers num="1.1"/><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" modified="2008-03-03" name="CVE-2007-0044" published="2007-01-03" seq="2007-0044" severity="Medium" type="CVE"><desc><descript source="cve">Adobe Acrobat Reader Plugin before 8.0.0 for the Firefox, Internet Explorer, and Opera web browsers allows remote attackers to force the browser to make unauthorized requests to other web sites via a URL in the (1) FDF, (2) xml, and (3) xfdf AJAX request parameters, following the # (hash) character, aka &quot;Universal CSRF and session riding.&quot;</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/455801/100/0/threaded">20070103 Adobe Acrobat Reader Plugin - Multiple Vulnerabilities</ref><ref source="" url="http://events.ccc.de/congress/2006/Fahrplan/attachments/1158-Subverting_Ajax.pdf"></ref><ref patch="1" source="" url="http://www.wisec.it/vulns.php?page=9"></ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0032">ADV-2007-0032</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1017469">1017469</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31266">adobe-acrobat-pdf-csrf(31266)</ref><ref source="BID" url="http://www.securityfocus.com/bid/21858">21858</ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200701-16.xml">GLSA-200701-16</ref><ref source="SUSE" url="http://lists.suse.com/archive/suse-security-announce/2007-Jan/0012.html">SUSE-SA:2007:011</ref><ref source="SECUNIA" url="http://secunia.com/advisories/23812">23812</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/23882">23882</ref><ref adv="1" source="SREASON" url="http://securityreason.com/securityalert/2090">2090</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2008-0144.html">RHSA-2008:0144</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/29065">29065</ref></refs><vuln_soft><prod name="Acrobat" vendor="Adobe"><vers edition="Standard" num="7.0"/><vers edition="Standard" num="7.0.1"/><vers edition="Standard" num="7.0.2"/><vers edition="Standard" num="7.0.3"/><vers edition="Standard" num="7.0.4"/><vers edition="Standard" num="7.0.5"/><vers edition="Standard" num="7.0.6"/><vers edition="Standard" num="7.0.7"/><vers edition="Standard" num="7.0.8"/><vers edition="Professional" num="7.0"/><vers edition="Professional" num="7.0.1"/><vers edition="Professional" num="7.0.2"/><vers edition="Professional" num="7.0.3"/><vers edition="Professional" num="7.0.4"/><vers edition="Professional" num="7.0.5"/><vers edition="Professional" num="7.0.6"/><vers edition="Professional" num="7.0.7"/><vers edition="Professional" num="7.0.8"/></prod><prod name="Acrobat 3D" vendor="Adobe"><vers num=""/></prod><prod name="Acrobat Reader" vendor="Adobe"><vers num="6.0.5"/><vers num="6.0"/><vers num="6.0.1"/><vers num="6.0.2"/><vers num="6.0.3"/><vers num="6.0.4"/><vers num="7.0"/><vers num="7.0.1"/><vers num="7.0.2"/><vers num="7.0.3"/><vers num="7.0.4"/><vers num="7.0.5"/><vers num="7.0.6"/><vers num="7.0.7"/><vers num="7.0.8"/></prod><prod name="Acrobat Elements" vendor="Adobe"><vers num="7.0.8" prev="1"/></prod><prod name="Acrobat Reader Plugin" vendor="Adobe"><vers num="7.0.8" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" modified="2007-06-27" name="CVE-2007-0045" published="2007-01-03" seq="2007-0045" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Adobe Acrobat Reader Plugin before 8.0.0 for Mozilla Firefox, Microsoft Internet Explorer 6 SP1, Opera 8.5.4 build 770, and Opera 9.10.8679 on Windows allow remote attackers to inject arbitrary JavaScript and conduct other attacks via a .pdf URL with a javascript: or res: URI with (1) FDF, (2) XML, and (3) XFDF AJAX parameters, or (4) an arbitrarily named name=URI anchor identifier, aka &quot;Universal XSS (UXSS).&quot;</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref source="SECUNIA" url="http://secunia.com/advisories/24457">24457</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2090">2090</ref><ref source="HP" url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00771742">HPSBUX02153</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/455801/100/0/threaded">20070103 Adobe Acrobat Reader Plugin - Multiple Vulnerabilities</ref><ref patch="1" source="" url="http://www.wisec.it/vulns.php?page=9"></ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/455836/100/0/threaded">20070103 RE: [WEB SECURITY] Universal XSS with PDF files: highly dangerous</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/455800/100/0/threaded">20070103 Re: Universal XSS with PDF files: highly dangerous</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/455831/100/0/threaded">20070103 Re: [WEB SECURITY] Universal XSS with PDF files: highly dangerous</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/455790/100/0/threaded">20070103 Universal XSS with PDF files: highly dangerous</ref><ref source="" url="http://www.disenchant.ch/blog/hacking-with-browser-plugins/34"></ref><ref adv="1" source="" url="http://www.gnucitizen.org/blog/danger-danger-danger/"></ref><ref adv="1" source="" url="http://www.adobe.com/support/security/advisories/apsa07-01.html"></ref><ref adv="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/815960">VU#815960</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0032">ADV-2007-0032</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1017469">1017469</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/23483">23483</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31271">adobe-acrobat-pdf-xss(31271)</ref><ref source="" url="http://www.adobe.com/support/security/advisories/apsa07-02.html"></ref><ref source="REDHAT" url="https://rhn.redhat.com/errata/RHSA-2007-0017.html">RHSA-2007:0017</ref><ref source="BID" url="http://www.securityfocus.com/bid/21858">21858</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/23691">23691</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/455906/100/0/threaded">20070104 Universal PDF XSS After Party</ref><ref source="" url="http://www.gnucitizen.org/blog/universal-pdf-xss-after-party"></ref><ref source="" url="http://www.adobe.com/support/security/bulletins/apsb07-01.html"></ref><ref source="" url="http://www.mozilla.org/security/announce/2007/mfsa2007-02.html"></ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200701-16.xml">GLSA-200701-16</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2007-0021.html">RHSA-2007:0021</ref><ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102847-1">102847</ref><ref source="SUSE" url="http://lists.suse.com/archive/suse-security-announce/2007-Jan/0012.html">SUSE-SA:2007:011</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0957">ADV-2007-0957</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/23812">23812</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/23877">23877</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/23882">23882</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24533">24533</ref><ref source="SLACKWARE" url="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2007&amp;m=slackware-security.338131">SSA:2007-066-05</ref></refs><vuln_soft><prod name="Acrobat" vendor="Adobe"><vers edition="Standard" num="7.0"/><vers edition="Professional" num="7.0"/><vers edition="Standard" num="7.0.1"/><vers edition="Professional" num="7.0.1"/><vers edition="Standard" num="7.0.2"/><vers edition="Professional" num="7.0.2"/><vers edition="Standard" num="7.0.3"/><vers edition="Professional" num="7.0.3"/><vers edition="Standard" num="7.0.4"/><vers edition="Professional" num="7.0.4"/><vers edition="Standard" num="7.0.5"/><vers edition="Professional" num="7.0.5"/><vers edition="Standard" num="7.0.6"/><vers edition="Professional" num="7.0.6"/><vers edition="Standard" num="7.0.7"/><vers edition="Professional" num="7.0.7"/><vers edition="Standard" num="7.0.8"/><vers edition="Professional" num="7.0.8"/></prod><prod name="Acrobat 3D" vendor="Adobe"><vers num=""/></prod><prod name="Acrobat Reader" vendor="Adobe"><vers num="7.0"/><vers num="7.0.1"/><vers num="7.0.2"/><vers num="7.0.3"/><vers num="7.0.4"/><vers num="7.0.5"/><vers num="7.0.6"/><vers num="7.0.7"/><vers num="7.0.8"/><vers num="6.0"/><vers num="6.0.1"/><vers num="6.0.2"/><vers num="6.0.3"/><vers num="6.0.4"/><vers num="6.0.5"/></prod><prod name="Acrobat Elements" vendor="Adobe"><vers num="7.0.8" prev="1"/></prod><prod name="Acrobat Reader Plugin" vendor="Adobe"><vers num="7.0.8" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-01-04" name="CVE-2007-0046" published="2007-01-03" seq="2007-0046" severity="High" type="CVE"><desc><descript source="cve">Double free vulnerability in the Adobe Acrobat Reader Plugin before 8.0.0, as used in Mozilla Firefox 1.5.0.7, allows remote attackers to execute arbitrary code by causing an error via a javascript: URI call to document.write in the (1) FDF, (2) XML, or (3) XFDF AJAX request parameters.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/455801/100/0/threaded">20070103 Adobe Acrobat Reader Plugin - Multiple Vulnerabilities</ref><ref source="" url="http://events.ccc.de/congress/2006/Fahrplan/attachments/1158-Subverting_Ajax.pdf"></ref><ref patch="1" source="" url="http://www.wisec.it/vulns.php?page=9"></ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0032">ADV-2007-0032</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1017469">1017469</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31272">adobe-acrobat-msvcrt-code-execution(31272)</ref><ref source="REDHAT" url="https://rhn.redhat.com/errata/RHSA-2007-0017.html">RHSA-2007:0017</ref><ref source="SECUNIA" url="http://secunia.com/advisories/23691">23691</ref><ref source="" url="http://www.adobe.com/support/security/bulletins/apsb07-01.html"></ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200701-16.xml">
GLSA-200701-16</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2007-0021.html">
RHSA-2007:0021</ref><ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102847-1">
102847</ref><ref source="SUSE" url="http://lists.suse.com/archive/suse-security-announce/2007-Jan/0012.html">
SUSE-SA:2007:011</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0957">
ADV-2007-0957</ref><ref source="SECUNIA" url="http://secunia.com/advisories/23812">
23812</ref><ref source="SECUNIA" url="http://secunia.com/advisories/23877">
23877</ref><ref source="SECUNIA" url="http://secunia.com/advisories/23882">
23882</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24533">
24533</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2090">2090</ref></refs><vuln_soft><prod name="Acrobat Reader Plugin" vendor="Adobe"><vers num="7.0.8" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-07-05" name="CVE-2007-0047" published="2007-01-03" seq="2007-0047" severity="Medium" type="CVE"><desc><descript source="cve">CRLF injection vulnerability in Adobe Acrobat Reader Plugin before 8.0.0, when used with the Microsoft.XMLHTTP ActiveX object in Internet Explorer, allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via CRLF sequences in the javascript: URI in the (1) FDF, (2) XML, or (3) XFDF AJAX request parameters.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/><config/></vuln_types><range><network/></range><refs><ref source="" url="http://events.ccc.de/congress/2006/Fahrplan/attachments/1158-Subverting_Ajax.pdf"></ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0032">ADV-2007-0032</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1017469">1017469</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31291">adobe-acrobat-xmlhttp-response-splitting(31291)</ref><ref source="SUSE" url="http://lists.suse.com/archive/suse-security-announce/2007-Jan/0012.html">SUSE-SA:2007:011</ref><ref source="SECUNIA" url="http://secunia.com/advisories/23882">23882</ref></refs><vuln_soft><prod name="Acrobat Reader Plugin" vendor="Adobe"><vers num="7.0.8" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0" modified="2007-05-14" name="CVE-2007-0048" published="2007-01-03" seq="2007-0048" severity="Medium" type="CVE"><desc><descript source="cve">Adobe Acrobat Reader Plugin before 8.0.0, when used with Internet Explorer, allows remote attackers to cause a denial of service (memory consumption) via a long sequence of # (hash) characters appended to a PDF URL.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/455801/100/0/threaded">20070103 Adobe Acrobat Reader Plugin - Multiple Vulnerabilities</ref><ref source="" url="http://events.ccc.de/congress/2006/Fahrplan/attachments/1158-Subverting_Ajax.pdf"></ref><ref adv="1" patch="1" source="" url="http://www.wisec.it/vulns.php?page=9"></ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0032">ADV-2007-0032</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1017469">1017469</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31273">adobe-acrobat-character-dos(31273)</ref><ref source="" url="http://www.adobe.com/support/security/bulletins/apsb07-01.html"></ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200701-16.xml">GLSA-200701-16</ref><ref source="SUSE" url="http://lists.suse.com/archive/suse-security-announce/2007-Jan/0012.html">SUSE-SA:2007:011</ref><ref source="SECUNIA" url="http://secunia.com/advisories/23812">23812</ref><ref source="SECUNIA" url="http://secunia.com/advisories/23882">23882</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2090">2090</ref></refs><vuln_soft><prod name="Acrobat" vendor="Adobe"><vers edition="Standard" num="7.0"/><vers edition="Professional" num="7.0"/><vers edition="Standard" num="7.0.1"/><vers edition="Professional" num="7.0.1"/><vers edition="Standard" num="7.0.2"/><vers edition="Professional" num="7.0.2"/><vers edition="Standard" num="7.0.3"/><vers edition="Professional" num="7.0.3"/><vers edition="Standard" num="7.0.4"/><vers edition="Professional" num="7.0.4"/><vers edition="Standard" num="7.0.5"/><vers edition="Professional" num="7.0.5"/><vers edition="Standard" num="7.0.6"/><vers edition="Professional" num="7.0.6"/><vers edition="Standard" num="7.0.7"/><vers edition="Professional" num="7.0.7"/><vers edition="Standard" num="7.0.8"/><vers edition="Professional" num="7.0.8"/></prod><prod name="Acrobat 3D" vendor="Adobe"><vers num=""/></prod><prod name="Acrobat Reader" vendor="Adobe"><vers num="6.0"/><vers num="6.0.1"/><vers num="6.0.2"/><vers num="6.0.3"/><vers num="6.0.4"/><vers num="6.0.5"/><vers num="7.0"/><vers num="7.0.1"/><vers num="7.0.2"/><vers num="7.0.3"/><vers num="7.0.4"/><vers num="7.0.5"/><vers num="7.0.6"/><vers num="7.0.7"/><vers num="7.0.8"/></prod><prod name="Acrobat Elements" vendor="Adobe"><vers num="7.0.8" prev="1"/></prod><prod name="Acrobat Reader Plugin" vendor="Adobe"><vers num="7.0.8" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-07-05" name="CVE-2007-0049" published="2007-01-04" seq="2007-0049" severity="High" type="CVE"><desc><descript source="cve">Geckovich TaskTracker Pro 1.5 and earlier allows remote attackers to add administrative or other accounts via an Add action with a modified GroupID in a direct request to Customize.asp.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref source="" url="http://milw0rm.com/exploits/3068"></ref><ref source="BID" url="http://www.securityfocus.com/bid/21847">21847</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/23564">23564</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31235">tasktrackerpro-customize-auth-bypass(31235)</ref></refs><vuln_soft><prod name="TaskTracker Pro" vendor="Geckovich"><vers num="1.5" prev="1"/></prod><prod name="TaskTracker" vendor="Geckovich"><vers num="1.4"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-01-10" name="CVE-2007-0050" published="2007-01-04" seq="2007-0050" severity="High" type="CVE"><desc><descript source="cve">** DISPUTED **  PHP remote file inclusion vulnerability in index.php in OpenPinboard 2.0 allows remote attackers to execute arbitrary PHP code via a URL in the language parameter.  NOTE: this issue has been disputed by the developer and a third party, since the variable is set before use. CVE analysis suggests that there is a small time window of risk before the installation is complete.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/><design/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/455795/100/0/threaded">20070103 OpenPinboard &lt;= Remote File Include</ref><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/455818/100/0/threaded">20070103 Re: OpenPinboard &lt;= Remote File Include</ref></refs><vuln_soft><prod name="OpenPinboard" vendor="OpenPinboard"><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-08-07" name="CVE-2007-0051" published="2007-01-04" seq="2007-0051" severity="Medium" type="CVE"><desc><descript source="cve">Format string vulnerability in Apple iPhoto 6.0.5 (316), and other versions before 6.0.6, allows remote user-assisted attackers to execute arbitrary code via a crafted photocast with format string specifiers in the title of an RSS iPhoto feed.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" source="" url="http://projects.info-pull.com/moab/MOAB-04-01-2007.html"></ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/455968/100/0/threaded">20070104 DMA[2007-0104a] - &apos;iLife iPhoto Photocasing Format String Vulnerability&apos;</ref><ref source="" url="http://www.digitalmunition.com/DMA%5B2007-0104a%5D.txt"></ref><ref source="" url="http://www.milw0rm.com/exploits/3080"></ref><ref source="BID" url="http://www.securityfocus.com/bid/21871">21871</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0057">ADV-2007-0057</ref><ref source="SECUNIA" url="http://secunia.com/advisories/23615">23615</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31281">iphoto-xmltitle-format-string(31281)</ref><ref source="MILW0RM" url="http://milw0rm.com/exploits/3080">3080</ref><ref source="" url="http://docs.info.apple.com/article.html?artnum=305215"></ref><ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2007/Mar//msg00003.html">APPLE-SA-2007-03-13</ref></refs><vuln_soft><prod name="iPhoto" vendor="Apple"><vers num="6.0.5_316"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-01-05" name="CVE-2007-0052" published="2007-01-04" seq="2007-0052" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in haberdetay.asp in Vizayn Haber allows remote attackers to execute arbitrary SQL commands via the id parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://milw0rm.com/exploits/3061"></ref><ref source="BID" url="http://www.securityfocus.com/bid/21836">21836</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0015">ADV-2007-0015</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/23576">23576</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31213">vicayn-haberdetay-sql-injection(31213)</ref></refs><vuln_soft><prod name="Vizayn Haber" vendor="Vizayn Haber"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-01-05" name="CVE-2007-0053" published="2007-01-04" seq="2007-0053" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in detail.asp in ASP SiteWare autoDealer 2.0 and earlier allows remote attackers to execute arbitrary SQL commands via the iPro parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://milw0rm.com/exploits/3062"></ref><ref source="BID" url="http://www.securityfocus.com/bid/21833">21833</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0016">ADV-2007-0016</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/23572">23572</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31219">autodealer-detail-sql-injection(31219)</ref></refs><vuln_soft><prod name="autoDealer" vendor="ASP Siteware"><vers num="2.0" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-01-05" name="CVE-2007-0054" published="2007-01-04" seq="2007-0054" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in gbrowse.php in Belchior Foundry vCard PRO allows remote attackers to inject arbitrary web script or HTML via the sortby parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/455615/100/0/threaded">20070101 vBulletin vCard PRO XSS</ref><ref source="BID" url="http://www.securityfocus.com/bid/21844">21844</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31182">vcard-gbrowse-xss(31182)</ref></refs><vuln_soft><prod name="vCard PRO" vendor="Belchior Foundry"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0" modified="2007-01-05" name="CVE-2007-0055" published="2007-01-04" seq="2007-0055" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in formbankcgi.exe/AbfrageForm in Formbankserver 1.9 allows remote attackers to read arbitrary files via directory traversal sequences in the Name parameter.  NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://www.milw0rm.com/exploits/3063"></ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0012">ADV-2007-0012</ref><ref source="SECUNIA" url="http://secunia.com/advisories/23539">23539</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31214">formbankserver-name-directory-traversal(31214)</ref><ref source="MILW0RM" url="http://milw0rm.com/exploits/3063">

3063</ref></refs><vuln_soft><prod name="Formbankserver" vendor="Fersch"><vers num="1.9"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-01-05" name="CVE-2007-0056" published="2007-01-04" seq="2007-0056" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in AShop Deluxe 4.5 and AShop Administration Panel allow remote attackers to inject arbitrary web script or HTML via the (1) cat parameter to (a) ashop/catalogue.php and (b) ashop/basket.php, the (2) exp parameter to ashop/catalogue.php, the (3) searchstring parameter to (c) ashop/search.php, the (4) checkout and (5) action parameters to (d) ashop/shipping.php, the cat parameter to (f) cart-path/admin/editcatalogue.php, and the (7) resultpage parameter to (g) cart-path/admin/salesadmin.php.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/455629/100/0/threaded">20070101 AShop Shopping Cart Multiple XSS Vulnerabilities</ref><ref source="BID" url="http://www.securityfocus.com/bid/21845">21845</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0028">ADV-2007-0028</ref><ref source="SECUNIA" url="http://secunia.com/advisories/23547">23547</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31178">ashop-multiple-scripts-xss(31178)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2091">2091</ref></refs><vuln_soft><prod name="AShop Deluxe" vendor="AShopSoftware"><vers num="4.5"/></prod><prod name="AShop Administration Panel" vendor="AShopSoftware"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-01-05" name="CVE-2007-0057" published="2007-01-04" seq="2007-0057" severity="High" type="CVE"><desc><descript source="cve">Cisco Clean Access (CCA) 3.6.x through 3.6.4.2 and 4.0.x through 4.0.3.2 does not properly configure or allow modification of a shared secret authentication key, which causes all devices to have the same shared sercet and allows remote attackers to gain unauthorized access.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="CISCO" url="http://www.cisco.com/warp/public/707/cisco-sa-20070103-CleanAccess.shtml">20070103 Multiple Vulnerabilities in Cisco Clean Access</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0030">ADV-2007-0030</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1017465">1017465</ref><ref source="SECUNIA" url="http://secunia.com/advisories/23617">23617</ref></refs><vuln_soft><prod name="Clean Access" vendor="Cisco"><vers num="4.0.4.2" prev="1"/><vers num="3.6.1.1" prev="1"/><vers num="3.5.9" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.8" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.9" CVSS_score="7.8" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:N/A:N)" CVSS_version="2.0" modified="2007-07-05" name="CVE-2007-0058" published="2007-01-04" seq="2007-0058" severity="High" type="CVE"><desc><descript source="cve">Cisco Clean Access (CCA) 3.5.x through 3.5.9 and 3.6.x through 3.6.1.1 on the Clean Access Manager (CAM) allows remote attackers to bypass authentication and download arbitrary manual database backups by guessing the snapshot filename using brute force, then making a direct request for the file.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref source="CISCO" url="http://www.cisco.com/warp/public/707/cisco-sa-20070103-CleanAccess.shtml">20070103 Multiple Vulnerabilities in Cisco Clean Access</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0030">ADV-2007-0030</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1017465">1017465</ref><ref source="SECUNIA" url="http://secunia.com/advisories/23556">23556</ref><ref source="OSVDB" url="http://www.osvdb.org/32579">32579</ref></refs><vuln_soft><prod name="Clean Access" vendor="Cisco"><vers num="3.6.1.1" prev="1"/><vers num="3.5.9" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-01-15" name="CVE-2007-0059" published="2007-01-04" seq="2007-0059" severity="Medium" type="CVE"><desc><descript source="cve">Cross-zone scripting vulnerability in Apple Quicktime 3 to 7.1.3 allows remote user-assisted attackers to execute arbitrary code and list filesystem contents via a QuickTime movie (.MOV) with an HREF Track (HREFTrack) that contains an automatic action tag with a local URI, which is executed in a local zone during preview, as exploited by a MySpace worm.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref source="" url="http://projects.info-pull.com/moab/MOAB-03-01-2007.html"></ref><ref adv="1" source="" url="http://www.gnucitizen.org/blog/backdooring-quicktime-movies/"></ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/304064">VU#304064</ref><ref source="APPLE" url="http://lists.apple.com/archives/Security-announce/2007/Mar/msg00000.html">
APPLE-SA-2007-03-05</ref><ref source="" url="http://docs.info.apple.com/article.html?artnum=305149"></ref></refs><vuln_soft><prod name="Quicktime Player" vendor="Apple"><vers num="7.1.3" prev="1"/><vers num="3"/></prod></vuln_soft></entry><entry CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" CVSS_score="9.3" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-07-27" name="CVE-2007-0060" published="2007-07-25" seq="2007-0060" severity="High" type="CVE"><desc><descript source="cve">Stack-based buffer overflow in the Message Queuing Server (Cam.exe) in CA (formerly Computer Associates) Message Queuing (CAM / CAFT) software before 1.11 Build 54_4 on Windows and NetWare, as used in CA Advantage Data Transport, eTrust Admin, certain BrightStor products, certain CleverPath products, and certain Unicenter products, allows remote attackers to execute arbitrary code via a crafted message to TCP port 3104.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref source="ISS" url="http://www.iss.net/threats/272.html">20070724 CA Message Queuing Server (Cam.exe) Overflow</ref><ref source="" url="http://supportconnectw.ca.com/public/dto_transportit/infodocs/camsgquevul-secnot.asp"></ref><ref source="BID" url="http://www.securityfocus.com/bid/25051">25051</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/2638">ADV-2007-2638</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/26190">26190</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32234">systems-management-bo(32234)</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/474602/100/0/threaded">20070725 [CAID 35527]: CA Message Queuing (CAM / CAFT) Buffer Overflow Vulnerability</ref><ref source="" url="http://www.ca.com/us/securityadvisor/newsinfo/collateral.aspx?cid=149809"></ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1018449">1018449</ref></refs><vuln_soft><prod name="Unicenter Network and Systems Management" vendor="Computer Associates"><vers num="3.0"/><vers num="3.1"/></prod><prod name="Unicenter TNG JPN" vendor="Computer Associates"><vers num="2.2"/></prod><prod name="BrightStor Portal" vendor="Computer Associates"><vers num="11.1"/></prod><prod name="Unicenter Remote Control" vendor="Computer Associates"><vers num="6.0"/><vers num="6.0 SP1"/></prod><prod name="Unicenter Service Level Management" vendor="Computer Associates"><vers num="3.0"/><vers num="3.0.1"/><vers num="3.0.2"/><vers num="3.5"/></prod><prod name="eTrust Admin" vendor="Computer Associates"><vers num="2.1"/><vers num="2.4"/><vers num="2.7"/><vers num="2.9"/><vers num="8.0"/><vers num="8.1"/></prod><prod name="Unicenter Application Performance Monitor" vendor="Computer Associates"><vers num="3.0"/><vers num="3.5"/></prod><prod name="Unicenter Jasmine" vendor="Computer Associates"><vers num="3.0"/></prod><prod name="Unicenter Management Lotus Note_Domino" vendor="Computer Associates"><vers num="4.0"/></prod><prod name="Unicenter Management Web Servers" vendor="Computer Associates"><vers num="5.0"/><vers num="5.0.1"/></prod><prod name="CleverPath ECM" vendor="Computer Associates"><vers num="3.5"/></prod><prod name="Unicenter Enterprise Job Manager" vendor="Computer Associates"><vers num="1.0 SP1"/><vers num="1.0 SP2"/></prod><prod name="Unicenter NSM Wireless Network Management Option" vendor="Computer Associates"><vers num="3.0"/></prod><prod name="BrightStor SAN Manager" vendor="Computer Associates"><vers num="11.1"/><vers num="11.5"/></prod><prod name="Advantage Data Transport" vendor="Computer Associates"><vers num="3.0"/></prod><prod name="Unicenter Data Transport Option" vendor="Computer Associates"><vers num="2.0"/></prod><prod name="CleverPath Aion" vendor="Computer Associates"><vers num="10.0"/></prod><prod name="Unicenter Asset Management" vendor="Computer Associates"><vers num="3.1"/><vers num="3.2"/><vers num="3.2 SP1"/><vers num="3.2 SP2"/><vers num="4.0"/><vers num="4.0 SP1"/></prod><prod name="Unicenter Software Delivery" vendor="Computer Associates"><vers num="3.0"/><vers num="3.1"/><vers num="3.1 SP1"/><vers num="3.1 SP2"/><vers num="4.0"/><vers num="4.0 SP1"/></prod><prod name="Unicenter Management Microsoft Exchange" vendor="Computer Associates"><vers num="4.0"/><vers num="4.1"/></prod><prod name="Unicenter TNG" vendor="Computer Associates"><vers num="2.1"/><vers num="2.2"/><vers num="2.4"/><vers num="2.4.2"/></prod><prod name="CleverPath Predictive Analysis Server" vendor="Computer Associates"><vers num="2.0"/><vers num="3.0"/></prod><prod name="CleverPath OLAP" vendor="Computer Associates"><vers num="5.1"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-09-26" name="CVE-2007-0061" published="2007-09-21" seq="2007-0061" severity="High" type="CVE"><desc><descript source="cve">The DHCP server in EMC VMware Workstation before 5.5.5 Build 56455 and 6.x before 6.0.1 Build 55017, Player before 1.0.5 Build 56455 and Player 2 before 2.0.1 Build 55017, ACE before 1.0.3 Build 54075 and ACE 2 before 2.0.1 Build 55017, and Server before 1.0.4 Build 56528 allows remote attackers to execute arbitrary code via a malformed packet that triggers &quot;corrupt stack memory.&quot;</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><range><network/></range><refs><ref adv="1" source="ISS" url="http://www.iss.net/threats/275.html">20070919 VMWare DHCP Server Remote Code Execution Vulnerabilities</ref><ref patch="1" source="" url="http://www.vmware.com/support/ace/doc/releasenotes_ace.html"></ref><ref patch="1" source="" url="http://www.vmware.com/support/ace2/doc/releasenotes_ace2.html"></ref><ref patch="1" source="" url="http://www.vmware.com/support/player/doc/releasenotes_player.html"></ref><ref patch="1" source="" url="http://www.vmware.com/support/player2/doc/releasenotes_player2.html"></ref><ref patch="1" source="" url="http://www.vmware.com/support/server/doc/releasenotes_server.html"></ref><ref patch="1" source="" url="http://www.vmware.com/support/ws55/doc/releasenotes_ws55.html"></ref><ref patch="1" source="" url="http://www.vmware.com/support/ws6/doc/releasenotes_ws6.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/25729">25729</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/33101">dhcp-malformed-packet-bo(33101)</ref><ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2007-September/065902.html">20070920 VMSA-2007-0006 Critical security updates for all supported versions of VMware ESX Server, VMware Server, VMware Workstation, VMware ACE, and VMware Player</ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200711-23.xml">GLSA-200711-23</ref><ref source="UBUNTU" url="http://www.ubuntu.com/usn/usn-543-1">USN-543-1</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/3229">ADV-2007-3229</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1018717">1018717</ref><ref source="SECUNIA" url="http://secunia.com/advisories/26890">26890</ref><ref source="SECUNIA" url="http://secunia.com/advisories/27694">27694</ref><ref source="SECUNIA" url="http://secunia.com/advisories/27706">27706</ref></refs><vuln_soft><prod name="VMWare Player" vendor="VMWare"><vers num="1.0" prev="1"/><vers num="1.0.5.56455" prev="1"/></prod><prod name="VMware Server" vendor="VMWare"><vers num="1.0.4.56528" prev="1"/></prod><prod name="VMWare Workstation" vendor="VMWare"><vers num="5.5" prev="1"/><vers num="5.5.1" prev="1"/><vers num="5.5.3" prev="1"/><vers num="5.5.3.34685" prev="1"/><vers num="5.5.5.56455" prev="1"/><vers num="6.0" prev="1"/><vers num="6.0.1.55017" prev="1"/></prod><prod name="ACE" vendor="VMWare"><vers num="1.0"/><vers num="1.0.3 Build 54075" prev="1"/></prod><prod name="ACE 2" vendor="VMWare"><vers num="2.0.1.55017" prev="1"/></prod><prod name="VMWare Player 2" vendor="VMWare"><vers num="2.0.1.55017" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2008-08-18" name="CVE-2007-0062" published="2007-09-21" seq="2007-0062" severity="High" type="CVE"><desc><descript source="cve">Integer overflow in the ISC dhcpd 3.0.x before 3.0.7 and 3.1.x before 3.1.1; and the DHCP server in EMC VMware Workstation before 5.5.5 Build 56455 and 6.x before 6.0.1 Build 55017, Player before 1.0.5 Build 56455 and Player 2 before 2.0.1 Build 55017, ACE before 1.0.3 Build 54075 and ACE 2 before 2.0.1 Build 55017, and Server before 1.0.4 Build 56528; allows remote attackers to cause a denial of service (daemon crash) or execute arbitrary code via a malformed DHCP packet with a large dhcp-max-message-size that triggers a stack-based buffer overflow, related to servers configured to send many DHCP options to clients.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><range><network/></range><refs><ref patch="1" source="ISS" url="http://www.iss.net/threats/275.html">20070919 VMWare DHCP Server Remote Code Execution Vulnerabilities</ref><ref patch="1" source="" url="http://www.vmware.com/support/ace/doc/releasenotes_ace.html"></ref><ref patch="1" source="" url="http://www.vmware.com/support/ace2/doc/releasenotes_ace2.html"></ref><ref patch="1" source="" url="http://www.vmware.com/support/player/doc/releasenotes_player.html"></ref><ref patch="1" source="" url="http://www.vmware.com/support/player2/doc/releasenotes_player2.html"></ref><ref patch="1" source="" url="http://www.vmware.com/support/server/doc/releasenotes_server.html"></ref><ref patch="1" source="" url="http://www.vmware.com/support/ws55/doc/releasenotes_ws55.html"></ref><ref patch="1" source="" url="http://www.vmware.com/support/ws6/doc/releasenotes_ws6.html"></ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/25729">25729</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/33102">dhcp-param-overflow(33102)</ref><ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2007-September/065902.html">20070920 VMSA-2007-0006 Critical security updates for all supported versions of VMware ESX Server, VMware Server, VMware Workstation, VMware ACE, and VMware Player</ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200711-23.xml">GLSA-200711-23</ref><ref source="UBUNTU" url="http://www.ubuntu.com/usn/usn-543-1">USN-543-1</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/3229">ADV-2007-3229</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1018717">1018717</ref><ref source="SECUNIA" url="http://secunia.com/advisories/26890">26890</ref><ref source="SECUNIA" url="http://secunia.com/advisories/27694">27694</ref><ref source="SECUNIA" url="http://secunia.com/advisories/27706">27706</ref><ref source="" url="http://bugs.gentoo.org/show_bug.cgi?id=227135"></ref><ref source="" url="https://bugzilla.redhat.com/show_bug.cgi?id=339561"></ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200808-05.xml">GLSA-200808-05</ref><ref source="SECUNIA" url="http://secunia.com/advisories/31396">31396</ref></refs><vuln_soft><prod name="VMware Server" vendor="VMWare"><vers num="1.0.3"/></prod><prod name="ACE" vendor="VMWare"><vers num="2.0"/><vers num="1.0.3"/></prod><prod name="VMWare Workstation" vendor="VMWare"><vers num="4.5.2"/><vers num="5.5.3 build 34685"/><vers num="5.5.3 build 42958"/><vers num="5.5.4"/><vers num="5.5.4 build 44386"/><vers num="6.0"/><vers num="3.4"/><vers num="4.0"/><vers num="4.0.1"/><vers num="4.0.2"/><vers num="5.5.0 build13124"/><vers num="5.5.1"/><vers num="5.5.1 build19175"/><vers num="6.0.1"/></prod><prod name="Player" vendor="VMWare"><vers num="1.0.4"/><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-09-26" name="CVE-2007-0063" published="2007-09-21" seq="2007-0063" severity="High" type="CVE"><desc><descript source="cve">Integer underflow in the DHCP server in EMC VMware Workstation before 5.5.5 Build 56455 and 6.x before 6.0.1 Build 55017, Player before 1.0.5 Build 56455 and Player 2 before 2.0.1 Build 55017, ACE before 1.0.3 Build 54075 and ACE 2 before 2.0.1 Build 55017, and Server before 1.0.4 Build 56528 allows remote attackers to execute arbitrary code via a malformed DHCP packet that triggers a stack-based buffer overflow.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><range><network/></range><refs><ref adv="1" patch="1" source="ISS" url="http://www.iss.net/threats/275.html">20070919 VMWare DHCP Server Remote Code Execution Vulnerabilities</ref><ref patch="1" source="" url="http://www.vmware.com/support/ace/doc/releasenotes_ace.html"></ref><ref patch="1" source="" url="http://www.vmware.com/support/ace2/doc/releasenotes_ace2.html"></ref><ref patch="1" source="" url="http://www.vmware.com/support/player/doc/releasenotes_player.html"></ref><ref patch="1" source="" url="http://www.vmware.com/support/player2/doc/releasenotes_player2.html"></ref><ref patch="1" source="" url="http://www.vmware.com/support/server/doc/releasenotes_server.html"></ref><ref patch="1" source="" url="http://www.vmware.com/support/ws55/doc/releasenotes_ws55.html"></ref><ref patch="1" source="" url="http://www.vmware.com/support/ws6/doc/releasenotes_ws6.html"></ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/25729">25729</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/33103">dhcp-param-underflow(33103)</ref><ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2007-September/065902.html">20070920 VMSA-2007-0006 Critical security updates for all supported versions of VMware ESX Server, VMware Server, VMware Workstation, VMware ACE, and VMware Player</ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200711-23.xml">GLSA-200711-23</ref><ref source="UBUNTU" url="http://www.ubuntu.com/usn/usn-543-1">USN-543-1</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/3229">ADV-2007-3229</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1018717">1018717</ref><ref source="SECUNIA" url="http://secunia.com/advisories/26890">26890</ref><ref source="SECUNIA" url="http://secunia.com/advisories/27694">27694</ref><ref source="SECUNIA" url="http://secunia.com/advisories/27706">27706</ref></refs><vuln_soft><prod name="ESX Server" vendor="VMWare"><vers num="2.0.2"/><vers num="2.1.3"/><vers num="2.5.3"/><vers num="2.5.4"/><vers num="3.0.0"/><vers num="3.0.1"/></prod><prod name="VMWare Player" vendor="VMWare"><vers num="1.0" prev="1"/><vers num="1.0.5.56455" prev="1"/></prod><prod name="VMware Server" vendor="VMWare"><vers num="1.0.4.56528" prev="1"/></prod><prod name="VMWare Workstation" vendor="VMWare"><vers num="5.5" prev="1"/><vers num="5.5.1" prev="1"/><vers num="5.5.3" prev="1"/><vers num="5.5.3.34685" prev="1"/><vers num="5.5.5.56455" prev="1"/><vers num="6.0" prev="1"/><vers num="6.0.1.55017" prev="1"/></prod><prod name="ACE" vendor="VMWare"><vers num="1.0"/><vers num="1.0.3 Build 54075" prev="1"/></prod><prod name="ACE 2" vendor="VMWare"><vers num="2.0.1.55017" prev="1"/></prod><prod name="VMWare Player 2" vendor="VMWare"><vers num="2.0.1.55017" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" CVSS_score="9.3" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2008-01-11" name="CVE-2007-0064" published="2007-12-11" seq="2007-0064" severity="High" type="CVE"><desc><descript source="cve">Heap-based buffer overflow in Windows Media Format Runtime 7.1, 9, 9.5, 9.5 x64 Edition, 11, and Windows Media Services 9.1 for Microsoft Windows 2000, XP, Server 2003, and Vista allows user-assisted remote attackers to execute arbitrary code via a crafted Advanced Systems Format (ASF) file.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><range><network/><user_init/></range><refs><ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms07-068.mspx">MS07-068</ref><ref source="HP" url="http://www.securityfocus.com/archive/1/archive/1/485268/100/0/threaded">HPSBST02299</ref><ref source="BID" url="http://www.securityfocus.com/bid/26776">26776</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/4183">ADV-2007-4183</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1019074">1019074</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/28034">28034</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA07-345A.html">TA07-345A</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/319385">VU#319385</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3622">oval:org.mitre.oval:def:3622</ref></refs><vuln_soft><prod name="Media Format Runtime" vendor="Microsoft"><vers num="7.1"/></prod><prod name="windows_media_format_runtime" vendor="Microsoft"><vers num="9"/><vers num="9.5"/><vers edition="x64" num="9.5"/><vers num="11"/></prod><prod name="windows_media_services" vendor="Microsoft"><vers num="9.1"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2008-02-13" name="CVE-2007-0065" published="2008-02-12" seq="2007-0065" severity="High" type="CVE"><desc><descript source="cve">Heap-based buffer overflow in Object Linking and Embedding (OLE) Automation in Microsoft Windows 2000 SP4, XP SP2, Server 2003 SP1 and SP2, Vista, Office 2004 for Mac, and Visual basic 6.0 SP6 allows remote attackers to execute arbitrary code via a crafted script request.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><range><network/></range><refs><ref patch="1" source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms08-008.mspx">MS08-008</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA08-043C.html">TA08-043C</ref><ref source="BID" url="http://www.securityfocus.com/bid/27661">27661</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/0510/references">ADV-2008-0510</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1019373">1019373</ref><ref source="SECUNIA" url="http://secunia.com/advisories/28902">28902</ref><ref source="HP" url="http://marc.info/?l=bugtraq&amp;m=120361015026386&amp;w=2">HPSBST02314</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5388">oval:org.mitre.oval:def:5388</ref></refs><vuln_soft><prod name="office macos" vendor="Microsoft"><vers num=""/></prod><prod name="Visual Basic" vendor="Microsoft"><vers edition="SP6" num="6.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.1" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.9" CVSS_score="7.1" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:C)" CVSS_version="2.0" modified="2008-01-15" name="CVE-2007-0066" published="2008-01-08" seq="2007-0066" severity="High" type="CVE"><desc><descript source="cve">The kernel in Microsoft Windows 2000 SP4, XP SP2, and Server 2003, when ICMP Router Discovery Protocol (RDP) is enabled, allows remote attackers to cause a denial of service via fragmented router advertisement ICMP packets that trigger an out-of-bounds read, aka &quot;Windows Kernel TCP/IP/ICMP Vulnerability.&quot;</descript></desc><loss_types><avail/></loss_types><range><network/></range><refs><ref patch="1" source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms08-001.mspx">MS08-001</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/28297">28297</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA08-008A.html">TA08-008A</ref><ref source="ISS" url="http://www.iss.net/threats/282.html">20070108 Multiple (3) Microsoft Windows TCP/IP Remote Code Execution and DoS Vulnerabilities</ref><ref source="" url="http://blogs.technet.com/swi/archive/2008/01/08/ms08-001-part-2-the-case-of-the-moderate-icmp-mitigations.aspx"></ref><ref source="HP" url="http://www.securityfocus.com/archive/1/archive/1/486317/100/0/threaded">HPSBST02304</ref><ref source="BID" url="http://www.securityfocus.com/bid/27139">27139</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/0069">ADV-2008-0069</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1019166">1019166</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/39254">win-tcpip-icmp-dos(39254)</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5271">oval:org.mitre.oval:def:5271</ref></refs><vuln_soft><prod name="windows-nt" vendor="Microsoft"><vers edition="sp2" num="XP"/><vers edition="sp4" num="2000"/></prod><prod name="Windows Server 2003" vendor="Microsoft"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.8" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.9" CVSS_score="7.8" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_version="2.0" modified="2007-10-30" name="CVE-2007-0067" published="2007-06-06" seq="2007-0067" severity="High" type="CVE"><desc><descript source="cve">Unspecified vulnerability in the Lotus Domino Web Server 6.0, 6.5.x before 6.5.6, and 7.0.x before 7.0.3 allows remote attackers to cause a denial of service (daemon crash) via requests for URLs that reference certain files.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref patch="1" source="" url="http://www-1.ibm.com/support/docview.wss?uid=swg21257251"></ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/24307">24307</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/2046">ADV-2007-2046</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/25542">25542</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/34689">domino-unspecified-dos(34689)</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1018189">1018189</ref></refs><vuln_soft><prod name="Lotus Domino Web Server" vendor="IBM"><vers num="6.0"/><vers num="6.0.1"/><vers num="6.0.2"/><vers num="6.0.2 CF2"/><vers num="6.0.3"/><vers num="6.0.4"/><vers num="6.0.5"/><vers num="6.5.0"/><vers num="6.5.1"/><vers num="6.5.2"/><vers num="6.5.3"/><vers num="6.5.4"/><vers num="6.5.4 FP1"/><vers num="6.5.4 FP2"/><vers num="6.5.5"/><vers num="6.5.5 FP1"/><vers num="6.5.5 FP2"/><vers num="7.0"/><vers num="7.0.1"/><vers num="7.0.2"/><vers num="7.0.2 FP1"/></prod></vuln_soft></entry><entry CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" CVSS_score="9.3" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-06-07" name="CVE-2007-0068" published="2007-06-06" seq="2007-0068" severity="High" type="CVE"><desc><descript source="cve">IBM Lotus Domino 7.0.x before 7.0.3 does not revalidate the signature on a signed scheduled agent after the agent is modified, which allows remote authenticated users to gain privileges via a modified agent in a server database.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref source="" url="http://www-1.ibm.com/support/docview.wss?uid=swg21258784"></ref><ref source="BID" url="http://www.securityfocus.com/bid/24322">24322</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/2063">ADV-2007-2063</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/25520">25520</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/34718">domino-signature-privilege-escalation(34718)</ref></refs><vuln_soft><prod name="Lotus Domino" vendor="IBM"><vers num="7.0"/><vers num="7.0.1"/><vers num="7.0.2"/></prod></vuln_soft></entry><entry CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" CVSS_score="9.3" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2008-01-15" name="CVE-2007-0069" published="2008-01-08" seq="2007-0069" severity="High" type="CVE"><desc><descript source="cve">Unspecified vulnerability in the kernel in Microsoft Windows XP SP2, Server 2003, and Vista allows remote attackers to cause a denial of service (CPU consumption) and possibly execute arbitrary code via crafted (1) IGMPv3 and (2) MLDv2 packets that trigger memory corruption, aka &quot;Windows Kernel TCP/IP/IGMPv3 and MLDv2 Vulnerability.&quot;</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs><ref patch="1" source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms08-001.mspx">MS08-001</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/28297">28297</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA08-008A.html">TA08-008A</ref><ref source="ISS" url="http://www.iss.net/threats/282.html">20070108 Multiple (3) Microsoft Windows TCP/IP Remote Code Execution and DoS Vulnerabilities</ref><ref source="" url="http://blogs.technet.com/swi/archive/2008/01/08/ms08-001-part-3-the-case-of-the-igmp-network-critical.aspx"></ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/115083">VU#115083</ref><ref source="BID" url="http://www.securityfocus.com/bid/27100">27100</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/39452">win-ssm-igmp-bo(39452)</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/39453">win-ssm-mld-bo(39453)</ref><ref source="HP" url="http://www.securityfocus.com/archive/1/archive/1/486317/100/0/threaded">HPSBST02304</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/0069">ADV-2008-0069</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1019166">1019166</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5370">oval:org.mitre.oval:def:5370</ref></refs><vuln_soft><prod name="Windows Vista" vendor="Microsoft"><vers num=""/></prod><prod name="windows-nt" vendor="Microsoft"><vers edition="sp2" num="XP"/></prod><prod name="Windows Server 2003" vendor="Microsoft"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2008-04-25" name="CVE-2007-0071" published="2008-04-09" seq="2007-0071" severity="Medium" type="CVE"><desc><descript source="cve">Integer overflow in Adobe Flash Player 9.0.115.0 and earlier, and 8.0.39.0 and earlier, allows remote attackers to execute arbitrary code via a crafted SWF file with a negative Scene Count value, which passes a signed comparison, is used as an offset of a NULL pointer, and triggers a buffer overflow.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><range><network/><user_init/></range><refs><ref source="" url="http://www.adobe.com/support/security/bulletins/apsb08-11.html"></ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2008-0221.html">RHSA-2008:0221</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA08-100A.html">TA08-100A</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1019811">1019811</ref><ref source="SUSE" url="http://lists.opensuse.org/opensuse-security-announce/2008-04/msg00006.html">SUSE-SA:2008:022</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/29763">29763</ref><ref source="ISS" url="http://www.iss.net/threats/289.html">20080408 Adobe Flash Player Invalid Pointer Vulnerability</ref><ref source="" url="http://documents.iss.net/whitepapers/IBM_X-Force_WP_final.pdf"></ref><ref source="" url="http://www.matasano.com/log/1032/this-new-vulnerability-dowds-inhuman-flash-exploit/"></ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200804-21.xml">GLSA-200804-21</ref><ref source="OSVDB" url="http://www.osvdb.org/44282">44282</ref><ref source="XF" url="http://xforce.iss.net/getrecord.jsp?id=37277">multimedia-file-integer-overflow(37277)</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/159523">VU#159523</ref><ref source="BID" url="http://www.securityfocus.com/bid/28695">28695</ref><ref source="SECUNIA" url="http://secunia.com/advisories/29865">29865</ref><ref source="" url="http://blogs.adobe.com/psirt/2008/05/potential_flash_player_issue.html"></ref><ref source="" url="http://isc.sans.org/diary.html?storyid=4465"></ref><ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2008//May/msg00001.html">APPLE-SA-2008-05-28</ref><ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-238305-1">238305</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA08-150A.html">TA08-150A</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA08-149A.html">TA08-149A</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/395473">VU#395473</ref><ref source="BID" url="http://www.securityfocus.com/bid/29386">29386</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/1662/references">ADV-2008-1662</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/1697">ADV-2008-1697</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/1724/references">ADV-2008-1724</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1020114">1020114</ref><ref source="SECUNIA" url="http://secunia.com/advisories/30404">30404</ref><ref source="SECUNIA" url="http://secunia.com/advisories/30430">30430</ref><ref source="SECUNIA" url="http://secunia.com/advisories/30507">30507</ref></refs><vuln_soft><prod name="AIR" vendor="Adobe"><vers num="1.0"/></prod><prod name="Flex" vendor="Adobe"><vers num="3.0"/></prod><prod name="Flash Player" vendor="Adobe"><vers num="9.0.115.0" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-01-15" name="CVE-2007-0075" published="2007-01-05" seq="2007-0075" severity="High" type="CVE"><desc><descript source="cve">AspBB stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing user passwords via a direct request for db/aspbb.mdb.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1" user="1"/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/455683/100/0/threaded">20070102 AspBB Remote Password Disclosure</ref><ref source="" url="http://www.aria-security.com/forum/showthread.php?t=82"></ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31230">aspbb-aspbb-info-disclosure(31230)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2100">2100</ref></refs><vuln_soft><prod name="ASPBB" vendor="ASPBB"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-07-05" name="CVE-2007-0076" published="2007-01-05" seq="2007-0076" severity="High" type="CVE"><desc><descript source="cve">Openforum stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing user passwords via a direct request for openforum.mdb.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/455684/100/0/threaded">20070102 Openforum Remote password Disclosure</ref><ref source="" url="http://www.aria-security.com/forum/showthread.php?t=80"></ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31209">openforum-openforum-password-disclosure(31209)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2099">2099</ref></refs><vuln_soft><prod name="OpenForum" vendor="2enetworx"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0" modified="2007-01-15" name="CVE-2007-0077" published="2007-01-05" seq="2007-0077" severity="Medium" type="CVE"><desc><descript source="cve">lblog stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for a certain file in admin/db/newFolder/.</descript></desc><loss_types><conf/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/455681/100/0/threaded">20070102 lblog Remote Password Disclosure</ref><ref source="" url="http://www.aria-security.com/forum/showthread.php?t=79"></ref><ref source="SECTRACK" url="http://securitytracker.com/id?1017462">1017462</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31229">lblog-newfolder-information-disclosure(31229)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2098">2098</ref></refs><vuln_soft><prod name="LBlog" vendor="LBlog"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0" modified="2007-01-15" name="CVE-2007-0078" published="2007-01-05" seq="2007-0078" severity="Medium" type="CVE"><desc><descript source="cve">BattleBlog stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for database/blankmaster.mdb.</descript></desc><loss_types><conf/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/455614/100/0/threaded">20070101 BattleBlog Database Download Vulnerability</ref><ref source="" url="http://www.aria-security.com/forum/showthread.php?t=76"></ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31224">battleblog-blankmaster-info-disclosure(31224)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2097">2097</ref></refs><vuln_soft><prod name="BattleBlog" vendor="BattleBlog"><vers num="1.0d"/></prod></vuln_soft></entry><entry CVSS_base_score="7.8" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.9" CVSS_score="7.8" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:N/A:N)" CVSS_version="2.0" modified="2007-07-05" name="CVE-2007-0079" published="2007-01-05" seq="2007-0079" severity="High" type="CVE"><desc><descript source="cve">rblog stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for (1) data/admin.mdb or (2) data/rblog.mdb.</descript></desc><loss_types><conf/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/455626/100/0/threaded">20070101 rblog Database Download Vulnerability</ref><ref source="" url="http://www.aria-security.com/forum/showthread.php?t=77"></ref><ref source="SECUNIA" url="http://secunia.com/advisories/23538">23538</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31200">rblog-database-info-disclosure(31200)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2102">2102</ref></refs><vuln_soft><prod name="Rblog" vendor="Rblog"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="6.6" CVSS_exploit_subscore="2.7" CVSS_impact_subscore="10.0" CVSS_score="6.6" CVSS_vector="(AV:L/AC:M/Au:S/C:C/I:C/A:C)" CVSS_version="2.0" modified="2008-03-03" name="CVE-2007-0080" published="2007-01-05" seq="2007-0080" severity="Medium" type="CVE"><desc><descript source="cve">** DISPUTED **  Buffer overflow in the SMB_Connect_Server function in FreeRadius 1.1.3 and earlier allows attackers to execute arbitrary code related to the server desthost field of an SMB_Handle_Type instance.  NOTE: the impact of this issue has been disputed by a reliable third party and the vendor, who states that exploitation is limited &quot;only to local administrators who have write access to the server configuration files.&quot;  CVE concurs with the dispute.</descript></desc><impacts><impact source="nvd">-- Official Vendor Statement from the FreeRADIUS Server project

This issue is not a security vulnerability.  The exploit is available only to local administrators who have write access to the server configuration files.  As such, this issue has no security impact on any system running FreeRADIUS.

-- Official Vendor Statement from the FreeRADIUS Server project
</impact></impacts><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/455678/100/0/threaded">20070102 FreeRadius 1.1.3 SMB_Handle_Type SMB_Connect_Server arbitrary code execution</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/455812/100/0/threaded">20070103 Re: FreeRadius 1.1.3 SMB_Handle_Type SMB_Connect_Server arbitrary code execution</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1017463">1017463</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31248">freeradius-smbconnectserver-bo(31248)</ref><ref source="" url="http://www.freeradius.org/security.html"></ref><ref source="VIM" url="http://www.attrition.org/pipermail/vim/2007-February/001304.html">20070211 FreeRADIUS dispute of CVE-2007-0080</ref></refs><vuln_soft><prod name="FreeRADIUS" vendor="FreeRadius"><vers num="1.1.3" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="3.1" CVSS_impact_subscore="10.0" CVSS_score="6.8" CVSS_vector="(AV:L/AC:L/Au:S/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-01-15" name="CVE-2007-0081" published="2007-01-05" seq="2007-0081" severity="Medium" type="CVE"><desc><descript source="cve">Sunbelt Kerio Personal Firewall (SKPF) 4.3.268 and 4.3.246, and possibly other versions allows local users to provide a Trojan horse iphlpapi.dll to SKPF by placing it in the installation directory.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input/><design/></vuln_types><range><local/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/455624/100/0/threaded">20070101 Kerio Fake &apos;iphlpapi&apos; DLL injection Vulnerability</ref><ref adv="1" source="" url="http://www.matousec.com/info/advisories/Kerio-Fake-iphlpapi-DLL-injection.php"></ref><ref source="BID" url="http://www.securityfocus.com/bid/21828">21828</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31232">kerio-directory-code-execution(31232)</ref><ref source="OSVDB" url="http://www.osvdb.org/33356">33356</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2095">2095</ref></refs><vuln_soft><prod name="Sunbelt Kerio Personal Firewall" vendor="Sunbelt"><vers num="4.3.268"/><vers num="4.3.246"/></prod></vuln_soft></entry><entry CVSS_base_score="6.5" CVSS_exploit_subscore="8.0" CVSS_impact_subscore="6.4" CVSS_score="6.5" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-01-15" name="CVE-2007-0082" published="2007-01-05" seq="2007-0082" severity="Medium" type="CVE"><desc><descript source="cve">users_adm/start1.php in IMGallery 2.5 and earlier does not properly handle files with multiple extensions, which allows remote authenticated users to upload and execute arbitrary PHP scripts.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="" url="http://www.milw0rm.com/exploits/3049"></ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/21827">21827</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0010">ADV-2007-0010</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/31237">imgallery-start1-file-upload(31237)</ref><ref source="MILW0RM" url="http://milw0rm.com/exploits/3049">

3049</ref></refs><vuln_soft><prod name="IMGallery" vendor="IMGallery"><vers num="2.5"/><vers num="2.4"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-01-15" name="CVE-2007-0083" published="2007-01-05" seq="2007-0083" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in Nuked Klan 1.7 and earlier allows remote attackers to inject arbitrary web script or HTML via a javascript: URI in a getURL statement in a .swf file, as demonstrated by &quot;Remote Cookie Disclosure.&quot;  NOTE: it could be argued that this is an issue in Shockwave instead of Nuked Klan.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/455726/100/0/threaded">20070102 Nuked Klan &lt;= 1.7 Remote Cookie Disclosure Exploit</ref><ref source="BID" url="http://www.securityfocus.com/bid/21850">21850</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2101">2101</ref></refs><vuln_soft><prod name="Nuked-Klan" vendor="Nuked-Klan"><vers num="1.7"/><vers num="1.5 SP2"/><vers num="1.5"/><vers num="1.4"/><vers num="1.3 Beta"/><vers num="1.3"/><vers num="1.2 Beta"/><vers num="1.2"/></prod></vuln_soft></entry><entry CVSS_base_score="6.6" CVSS_exploit_subscore="2.7" CVSS_impact_subscore="10.0" CVSS_score="6.6" CVSS_vector="(AV:L/AC:M/Au:S/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-01-15" name="CVE-2007-0084" published="2007-01-05" seq="2007-0084" severity="Medium" type="CVE"><desc><descript source="cve">** DISPUTED **  Buffer overflow in the Windows NT Message Compiler (MC) 1.00.5239 on Microsoft Windows XP allows local users to gain privileges via a long MC-filename.  NOTE: this issue has been disputed by a reliable third party who states that the compiler is not a privileged program, so privilege boundaries cannot be crossed.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input/></vuln_types><range><local/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/455729/100/0/threaded">20070102 Windows NT Message Compiler 1.00.5239 arbitrary code execution</ref><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/455789/100/0/threaded">20070103 Re: Windows NT Message Compiler 1.00.5239 arbitrary code execution</ref></refs><vuln_soft><prod name="Message Compiler" vendor="Microsoft"><vers num="1.00.5239"/></prod></vuln_soft></entry><entry CVSS_base_score="6.0" CVSS_exploit_subscore="1.5" CVSS_impact_subscore="10.0" CVSS_score="6.0" CVSS_vector="(AV:L/AC:H/Au:S/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-01-15" name="CVE-2007-0085" published="2007-01-05" seq="2007-0085" severity="Medium" type="CVE"><desc><descript source="cve">Unspecified vulnerability in sys/dev/pci/vga_pci.c in the VGA graphics driver for wscons in OpenBSD 3.9 and 4.0, when the kernel is compiled with the PCIAGP option and a non-AGP device is being used, allows local users to gain privileges via unspecified vectors, possibly related to agp_ioctl NULL pointer reference.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><range><local/></range><refs><ref source="MLIST" url="http://marc.theaimsgroup.com/?l=openbsd-cvs&amp;m=116781980706409&amp;w=2">[openbsd-cvs] 20070103 Re: CVS: cvs.openbsd.org: src</ref><ref adv="1" source="" url="http://ilja.netric.org/files/Unusual%20bugs%2023c3.pdf"></ref><ref adv="1" patch="1" source="OPENBSD" url="http://www.openbsd.org/errata39.html#agp">[3.9] 017: SECURITY FIX: January 3, 2007</ref><ref adv="1" patch="1" source="OPENBSD" url="http://www.openbsd.org/errata.html#agp">[4.0] 007: SECURITY FIX: January 3, 2007</ref><ref adv="1" patch="1" source="SECTRACK" url="http://securitytracker.com/id?1017468">1017468</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/23608">23608</ref><ref source="MLIST" url="http://marc.theaimsgroup.com/?l=openbsd-cvs&amp;m=116785923301416&amp;w=2">[openbsd-cvs] 20070103 CVS: cvs.openbsd.org: www</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0043">ADV-2007-0043</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31276">openbsd-vga-privilege-escalation(31276)</ref><ref source="OSVDB" url="http://www.osvdb.org/32574">32574</ref></refs><vuln_soft><prod name="OpenBSD" vendor="OpenBSD"><vers num="4.0"/><vers num="3.9"/></prod></vuln_soft></entry><entry CVSS_base_score="7.8" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.9" CVSS_score="7.8" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_version="2.0" modified="2007-02-08" name="CVE-2007-0086" published="2007-01-05" seq="2007-0086" severity="High" type="CVE"><desc><descript source="cve">** DISPUTED **  The Apache HTTP Server, when accessed through a TCP connection with a large window size, allows remote attackers to cause a denial of service (network bandwidth consumption) via a Range header that specifies multiple copies of the same fragment.  NOTE: the severity of this issue has been disputed by third parties, who state that the large window size required by the attack is not normally supported or configured by the server, or that a DDoS-style attack would accomplish the same goal.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/455833/100/0/threaded">20070103 a cheesy Apache / IIS DoS vuln (+a question)</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/455879/100/0/threaded">20070104 Re: a cheesy Apache / IIS DoS vuln (+a question)</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/455920/100/0/threaded">20070104 Re: a cheesy Apache / IIS DoS vuln (+a question)</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/455882/100/0/threaded">20070104 Re: a cheesy Apache / IIS DoS vuln (+a question)</ref></refs><vuln_soft><prod name="Apache HTTP Server" vendor="Apache Software Foundation"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.8" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.9" CVSS_score="7.8" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_version="2.0" modified="2007-07-05" name="CVE-2007-0087" published="2007-01-05" seq="2007-0087" severity="High" type="CVE"><desc><descript source="cve">** DISPUTED **  Microsoft Internet Information Services (IIS), when accessed through a TCP connection with a large window size, allows remote attackers to cause a denial of service (network bandwidth consumption) via a Range header that specifies multiple copies of the same fragment.  NOTE: the severity of this issue has been disputed by third parties, who state that the large window size required by the attack is not normally supported or configured by the server, or that a DDoS-style attack would accomplish the same goal.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/455833/100/0/threaded">20070103 a cheesy Apache / IIS DoS vuln (+a question)</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/455879/100/0/threaded">20070104 Re: a cheesy Apache / IIS DoS vuln (+a question)</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/455920/100/0/threaded">20070104 Re: a cheesy Apache / IIS DoS vuln (+a question)</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/455882/100/0/threaded">20070104 Re: a cheesy Apache / IIS DoS vuln (+a question)</ref></refs><vuln_soft><prod name="IIS" vendor="Microsoft"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0" modified="2007-01-15" name="CVE-2007-0088" published="2007-01-05" seq="2007-0088" severity="Medium" type="CVE"><desc><descript source="cve">Multiple directory traversal vulnerabilities in openmedia allow remote attackers to read arbitrary files via a .. (dot dot) in the (1) src parameter to page.php or the (2) format parameter to search_form.php.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/455786/100/0/threaded">20070102 openmedia local read file</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31258">openmedia-page-directory-traversal(31258)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2103">2103</ref></refs><vuln_soft><prod name="OpenMedia" vendor="OpenMedia"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-01-08" name="CVE-2007-0089" published="2007-01-05" seq="2007-0089" severity="High" type="CVE"><desc><descript source="cve">jgbbs stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing passwords via a direct request for db/bbs.mdb.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/><design/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/455832/100/0/threaded">20070103 jgbbs</ref><ref source="" url="http://aria-security.com/forum/showthread.php?t=87"></ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31274">jgbbs-bbs-information-disclosure(31274)</ref></refs><vuln_soft><prod name="JGBBS" vendor="JGBBS"><vers edition="Beta 1" num="3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-01-08" name="CVE-2007-0090" published="2007-01-05" seq="2007-0090" severity="High" type="CVE"><desc><descript source="cve">WineGlass stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing passwords via a direct request for db/data.mdb.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/><design/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/455807/100/0/threaded">20070103 WineGlass </ref><ref source="" url="http://aria-security.com/forum/showthread.php?p=112"></ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0037">ADV-2007-0037</ref><ref source="SECUNIA" url="http://secunia.com/advisories/23594">23594</ref></refs><vuln_soft><prod name="WineGlass" vendor="Fermentigrafici"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-01-08" name="CVE-2007-0091" published="2007-01-05" seq="2007-0091" severity="High" type="CVE"><desc><descript source="cve">newsCMSlite stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing passwords via a direct request for newsCMS.mdb.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/><design/></vuln_types><range><network/></range><refs><ref source="" url="http://www.milw0rm.com/exploits/3066"></ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31222">newscmslite-newscms-info-disclosure(31222)</ref><ref source="MILW0RM" url="http://milw0rm.com/exploits/3066">

3066</ref></refs><vuln_soft><prod name="newsCMSlite" vendor="Katy Whitton Web Development"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-01-08" name="CVE-2007-0092" published="2007-01-05" seq="2007-0092" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in productdetail.asp in E-SMARTCART 1.0 allows remote attackers to execute arbitrary SQL commands via the product_id parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://www.milw0rm.com/exploits/3074"></ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/23610">23610</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0036">ADV-2007-0036</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31243">esmartcart-productdetail-sql-injection(31243)</ref><ref source="MILW0RM" url="http://milw0rm.com/exploits/3074">

3074</ref></refs><vuln_soft><prod name="E-Smart Cart" vendor="E-Smart Cart"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-07-05" name="CVE-2007-0093" published="2007-01-05" seq="2007-0093" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in page.php in Simple Web Content Management System allows remote attackers to execute arbitrary SQL commands via the id parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/455814/100/0/threaded">20070103 Simple Web Content Management System SQL Injection Exploit</ref><ref source="" url="http://acid-root.new.fr/poc/18070102.txt"></ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0040">ADV-2007-0040</ref><ref source="SECUNIA" url="http://secunia.com/advisories/23590">23590</ref><ref source="" url="http://www.milw0rm.com/exploits/3076"></ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31261">swcms-page-sql-injection(31261)</ref><ref source="MILW0RM" url="http://milw0rm.com/exploits/3076">3076</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2106">2106</ref></refs><vuln_soft><prod name="Simple Web CMS" vendor="CMS-Center"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-01-08" name="CVE-2007-0094" published="2007-01-05" seq="2007-0094" severity="High" type="CVE"><desc><descript source="cve">Sven Moderow GuestBook 0.3a stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing passwords via a direct request for (1) gbook97.mdb or (2) gbook.mdb in ~db/.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/><design/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/455788/100/0/threaded">20070103 GuestBook v0.3a Remote Password Disclosure</ref><ref source="" url="http://aria-security.com/forum/showthread.php?p=114"></ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31245">guestbook-gbook-information-disclosure(31245)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2105">2105</ref></refs><vuln_soft><prod name="Sven Moderow GuestBook" vendor="Sven Moderow"><vers num="0.3a"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0" modified="2007-01-08" name="CVE-2007-0095" published="2007-01-05" seq="2007-0095" severity="Medium" type="CVE"><desc><descript source="cve">phpMyAdmin 2.9.1.1 allows remote attackers to obtain sensitive information via a direct request for themes/darkblue_orange/layout.inc.php, which reveals the path in an error message.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2007-January/051544.html">20070102 Inforamtion Discloser Vulnerabilities in  phpMyAdmin</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31223">phpmyadmin-darkblueorange-path-disclosure(31223)</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:199">MDKSA-2007:199</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2104">2104</ref></refs><vuln_soft><prod name="phpMyAdmin" vendor="phpMyAdmin"><vers num="2.9.1.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-07-05" name="CVE-2007-0096" published="2007-01-05" seq="2007-0096" severity="High" type="CVE"><desc><descript source="cve">CarbonCommunities stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing passwords via a direct request for DataBase/Carbon2.4d.mdb.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref source="" url="http://aria-security.com/forum/showthread.php?t=85"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0038">ADV-2007-0038</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31253">carboncommunities-carbon2-info-disclosure(31253)</ref></refs><vuln_soft><prod name="Carbon Communities" vendor="Carbon Communities"><vers num="2.4d" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" CVSS_score="9.3" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-01-08" name="CVE-2007-0097" published="2007-01-05" seq="2007-0097" severity="High" type="CVE"><desc><descript source="cve">Multiple stack-based buffer overflows in the (1) LoadTree and (2) ReadHeader functions in PAISO.DLL 1.7.3.0 (1.7.3 beta) in ConeXware PowerArchiver 2006 9.64.02 allow user-assisted attackers to execute arbitrary code via a crafted ISO file containing a file within several nested directories.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" source="FULLDISC" url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=116791509125050&amp;w=2">20070104 PowerArchiver PAISO.DLL Buffer Overflow</ref><ref adv="1" patch="1" source="" url="http://vuln.sg/powarc964-en.html"></ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0041">ADV-2007-0041</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/23559">23559</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/455892/100/0/threaded">20070104 [vuln.sg] PowerArchiver PAISO.DLL Buffer Overflow Vulnerability</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31263">powerarchiver-loadtree-readheader-bo(31263)</ref></refs><vuln_soft><prod name="PowerArchiver 2006" vendor="ConeXware"><vers num="9.64.02"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-01-08" name="CVE-2007-0098" published="2007-01-05" seq="2007-0098" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in language.php in VerliAdmin 0.3 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the lang cookie, as demonstrated by injecting PHP sequences into an Apache HTTP Server log file, which is then included by language.php.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><config/></vuln_types><range><network/></range><refs><ref source="" url="http://www.milw0rm.com/exploits/3075"></ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0035">ADV-2007-0035</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31241">verliadmin-language-file-include(31241)</ref><ref source="MILW0RM" url="http://milw0rm.com/exploits/3075">

3075</ref></refs><vuln_soft><prod name="VerliAdmin" vendor="VerliAdmin"><vers num="0.3" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.1" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.9" CVSS_score="7.1" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:C)" CVSS_version="2.0" modified="2007-01-15" name="CVE-2007-0099" published="2007-01-08" seq="2007-0099" severity="High" type="CVE"><desc><descript source="cve">Race condition in the msxml3 module in Microsoft Internet Explorer 6 allows remote attackers to cause a denial of service (application crash) via many nested tags in an XML document in an IFRAME, when synchronous document rendering is frequently disrupted with asynchronous events, as demonstrated using a JavaScript timer, which can trigger null pointer dereferences or memory corruption.</descript></desc><loss_types><avail/></loss_types><vuln_types><race/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/455965/100/0/threaded">20070104 Concurrency strikes MSIE (potentially exploitable msxml3 flaws)</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/455986/100/0/threaded">20070104 RE: [Full-disclosure] Concurrency strikes MSIE (potentially exploitablemsxml3 flaws)</ref><ref source="" url="http://isc.sans.org/diary.php?storyid=2004"></ref><ref source="FULLDISC" url="http://seclists.org/fulldisclosure/2007/Jan/0110.html">20070104 Concurrency strikes MSIE (potentially exploitable msxml3 flaws)</ref><ref source="BID" url="http://www.securityfocus.com/bid/21872">21872</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/23655">23655</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/456343/100/0/threaded">20070104 Re: RE: [Full-disclosure] Concurrency strikes MSIE (potentially exploitablemsxml3 flaws)</ref></refs><vuln_soft><prod name="Internet Explorer" vendor="Microsoft"><vers edition="Windows Server 2003 SP1" num="6"/><vers edition="Vista" num="7.0"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-01-15" name="CVE-2007-0100" published="2007-01-08" seq="2007-0100" severity="High" type="CVE"><desc><descript source="cve">The Perforce client does not restrict the set of files that it overwrites upon receiving a request from the server, which allows remote attackers to overwrite arbitrary files by modifying the client config file on the server, or by operating a malicious server.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/455977/100/0/threaded">20070104 Perforce client: security hole by design</ref></refs><vuln_soft><prod name="Perforce Client" vendor="Perforce"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-01-15" name="CVE-2007-0101" published="2007-01-08" seq="2007-0101" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site request forgery (CSRF) vulnerability in SPINE allows remote attackers to perform unauthorized actions as administrators via unspecified vectors.  NOTE: some of these details are obtained from third party information.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref patch="1" source="" url="http://spine.sourceforge.net/changelog.html"></ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0042">ADV-2007-0042</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/23537">23537</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31283">spine-unspecified-csrf(31283)</ref></refs><vuln_soft><prod name="SPINE" vendor="SPINE"><vers num="1.1" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2008-02-11" name="CVE-2007-0102" published="2007-01-08" seq="2007-0102" severity="Medium" type="CVE"><desc><descript source="cve">The Adobe PDF specification 1.3, as implemented by Apple Mac OS X Preview, allows remote attackers to have an unknown impact, possibly including denial of service (infinite loop), arbitrary code execution, or memory corruption, via a PDF file with a (1) crafted catalog dictionary or (2) a crafted Pages attribute that references an invalid page tree node.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://projects.info-pull.com/moab/MOAB-06-01-2007.html"></ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/21910">21910</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31364">multiple-vendor-pdf-code-execution(31364)</ref><ref source="" url="http://docs.info.apple.com/article.html?artnum=305214"></ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0930">ADV-2007-0930</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017749">1017749</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24479">24479</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA07-072A.html">TA07-072A</ref></refs><vuln_soft><prod name="Preview" vendor="Apple"><vers num="3.0.8"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2008-02-11" name="CVE-2007-0103" published="2007-01-08" seq="2007-0103" severity="Medium" type="CVE"><desc><descript source="cve">The Adobe PDF specification 1.3, as implemented by Adobe Acrobat before 8.0.0, allows remote attackers to have an unknown impact, possibly including denial of service (infinite loop), arbitrary code execution, or memory corruption, via a PDF file with a (1) crafted catalog dictionary or (2) a crafted Pages attribute that references an invalid page tree node.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref source="BID" url="http://www.securityfocus.com/bid/21910">21910</ref><ref source="" url="http://projects.info-pull.com/moab/MOAB-06-01-2007.html"></ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31364">multiple-vendor-pdf-code-execution(31364)</ref><ref source="" url="http://docs.info.apple.com/article.html?artnum=305214"></ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0930">ADV-2007-0930</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017749">1017749</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24479">24479</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA07-072A.html">TA07-072A</ref></refs><vuln_soft><prod name="Acrobat Reader" vendor="Adobe"><vers num="7.0.8" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2008-02-11" name="CVE-2007-0104" published="2007-01-08" seq="2007-0104" severity="Medium" type="CVE"><desc><descript source="cve">The Adobe PDF specification 1.3, as implemented by (a) xpdf 3.0.1 patch 2, (b) kpdf in KDE before 3.5.5, (c) poppler before 0.5.4, and other products, allows remote attackers to have an unknown impact, possibly including denial of service (infinite loop), arbitrary code execution, or memory corruption, via a PDF file with a (1) crafted catalog dictionary or (2) a crafted Pages attribute that references an invalid page tree node.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref source="BID" url="http://www.securityfocus.com/bid/21910">21910</ref><ref source="" url="http://projects.info-pull.com/moab/MOAB-06-01-2007.html"></ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31364">multiple-vendor-pdf-code-execution(31364)</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/457055/100/0/threaded">20070116 [KDE Security Advisory] kpdf/kword/xpdf denial of service vulnerability</ref><ref source="" url="http://www.kde.org/info/security/advisory-20070115-1.txt"></ref><ref source="" url="https://issues.rpath.com/browse/RPL-964"></ref><ref source="" url="http://support.novell.com/techcenter/psdb/44d7cb9b669d58e0ce5aa5d7ab2c7c53.html"></ref><ref source="" url="http://docs.info.apple.com/article.html?artnum=305214"></ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:018">MDKSA-2007:018</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:020">MDKSA-2007:020</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:022">MDKSA-2007:022</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2007:019">MDKSA-2007:019</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2007:021">MDKSA-2007:021</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2007:024">MDKSA-2007:024</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2007_3_sr.html">SUSE-SR:2007:003</ref><ref source="UBUNTU" url="http://www.ubuntu.com/usn/usn-410-1">USN-410-1</ref><ref source="UBUNTU" url="http://www.ubuntu.com/usn/usn-410-2">USN-410-2</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0203">ADV-2007-0203</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0212">ADV-2007-0212</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0244">ADV-2007-0244</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0930">ADV-2007-0930</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1017514">1017514</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017749">1017749</ref><ref source="SECUNIA" url="http://secunia.com/advisories/23799">23799</ref><ref source="SECUNIA" url="http://secunia.com/advisories/23791">23791</ref><ref source="SECUNIA" url="http://secunia.com/advisories/23808">23808</ref><ref source="SECUNIA" url="http://secunia.com/advisories/23813">23813</ref><ref source="SECUNIA" url="http://secunia.com/advisories/23815">23815</ref><ref source="SECUNIA" url="http://secunia.com/advisories/23844">23844</ref><ref source="SECUNIA" url="http://secunia.com/advisories/23839">23839</ref><ref source="SECUNIA" url="http://secunia.com/advisories/23876">23876</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24204">24204</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24479">24479</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:019">MDKSA-2007:019</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:021">MDKSA-2007:021</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:024">MDKSA-2007:024</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA07-072A.html">TA07-072A</ref></refs><vuln_soft><prod name="Xpdf" vendor="Xpdf"><vers num="3.0.1 pl2"/><vers num="3.0 pl2"/><vers num="3.0.1 pl1"/><vers num="3.0.1"/><vers num="3.0"/></prod><prod name="KDE" vendor="KDE"><vers num="3.5"/><vers num="3.4.3"/><vers num="3.4.2"/><vers num="3.4.1"/><vers num="3.4"/><vers num="3.3.2"/><vers num="3.3.1"/><vers num="3.3"/><vers num="3.2.3"/><vers num="3.2.2"/><vers num="3.2.1"/><vers num="3.2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-01-15" name="CVE-2007-0105" published="2007-01-08" seq="2007-0105" severity="High" type="CVE"><desc><descript source="cve">Stack-based buffer overflow in the CSAdmin service in Cisco Secure Access Control Server (ACS) for Windows before 4.1 and ACS Solution Engine before 4.1 allows remote attackers to execute arbitrary code via a crafted HTTP GET request.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="CISCO" url="http://www.cisco.com/warp/public/707/cisco-sa-20070105-csacs.shtml">20070105 Multiple Vulnerabilities in Cisco Secure Access Control Server</ref><ref source="BID" url="http://www.securityfocus.com/bid/21900">21900</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0068">ADV-2007-0068</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1017475">1017475</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/23629">23629</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31323">cisco-acs-csadmin-bo(31323)</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/744249">VU#744249</ref><ref source="OSVDB" url="http://www.osvdb.org/32642">32642</ref></refs><vuln_soft><prod name="Secure Access Control Server" vendor="Cisco"><vers num="4.0.1" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-01-15" name="CVE-2007-0106" published="2007-01-08" seq="2007-0106" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in the CSRF protection scheme in WordPress before 2.0.6 allows remote attackers to inject arbitrary web script or HTML via a CSRF attack with an invalid token and quote characters or HTML tags in URL variable names, which are not properly handled when WordPress generates a new link to verify the request.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/456048/100/0/threaded">20070105 Advisory 01/2007: WordPress CSRF Protection XSS Vulnerability</ref><ref adv="1" source="" url="http://www.hardened-php.net/advisory_012007.140.html"></ref><ref adv="1" patch="1" source="" url="http://wordpress.org/development/2007/01/wordpress-206/"></ref><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/21893">21893</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0061">ADV-2007-0061</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/23595">23595</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2114">2114</ref></refs><vuln_soft><prod name="WordPress" vendor="WordPress"><vers num="2.0.5"/><vers num="2.0.4"/><vers num="2.0.3"/><vers num="2.0.2"/><vers num="2.0.1"/><vers num="2.0"/><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-01-12" name="CVE-2007-0107" published="2007-01-08" seq="2007-0107" severity="Medium" type="CVE"><desc><descript source="cve">WordPress before 2.0.6, when mbstring is enabled for PHP, decodes alternate character sets after escaping the SQL query, which allows remote attackers to bypass SQL injection protection schemes and execute arbitrary SQL commands via multibyte charsets, as demonstrated using UTF-7.</descript></desc><sols><sol source="nvd">Successful exploitation requires that the &quot;mbstring&quot; extension be enabled.
This vulnerability is addressed in the following product release:
WordPress, WordPress, 2.0.6</sol></sols><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/456049/100/0/threaded">20070105 Advisory 02/2007: WordPress Trackback Charset Decoding SQL Injection Vulnerability</ref><ref adv="1" patch="1" source="" url="http://www.hardened-php.net/advisory_022007.141.html"></ref><ref patch="1" source="" url="http://wordpress.org/development/2007/01/wordpress-206/"></ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/21907">21907</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0061">ADV-2007-0061</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/23595">23595</ref><ref adv="1" patch="1" source="OPENPKG" url="http://www.openpkg.com/security/advisories/OpenPKG-SA-2007.005.html">OpenPKG-SA-2007.005</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/31297">wordpress-mbstring-security-bypass(31297)</ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200701-10.xml">GLSA-200701-10</ref><ref source="SECUNIA" url="http://secunia.com/advisories/23741">23741</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2112">2112</ref></refs><vuln_soft><prod name="WordPress" vendor="WordPress"><vers num="2.0.5" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.0" CVSS_exploit_subscore="6.8" CVSS_impact_subscore="6.4" CVSS_score="6.0" CVSS_vector="(AV:N/AC:M/Au:S/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-01-15" name="CVE-2007-0108" published="2007-01-08" seq="2007-0108" severity="Medium" type="CVE"><desc><descript source="cve">nwgina.dll in Novell Client 4.91 SP3 for Windows 2000/XP/2003 does not delete user profiles during a Terminal Service or Citrix session, which allows remote authenticated users to invoke alternate user profiles.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="" url="http://support.novell.com/cgi-bin/search/searchtid.cgi?/2974970.htm"></ref><ref source="BID" url="http://www.securityfocus.com/bid/21886">21886</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0064">ADV-2007-0064</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1017471">1017471</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/23619">23619</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31343">novell-profile-security-bypass(31343)</ref></refs><vuln_soft><prod name="Novell Client" vendor="Novell"><vers num="4.91 SP3"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0" modified="2007-01-15" name="CVE-2007-0109" published="2007-01-08" seq="2007-0109" severity="Medium" type="CVE"><desc><descript source="cve">wp-login.php in WordPress 2.0.5 and earlier displays different error messages if a user exists or not, which allows remote attackers to obtain sensitive information and facilitates brute force attacks.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/455927/100/0/threaded">20070103 Wordpress &lt;= 2.x dictionnary &amp; Bruteforce attack</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0062">ADV-2007-0062</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/23621">23621</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/31262">wordpress-account-enumeration(31262)</ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200701-10.xml">GLSA-200701-10</ref><ref source="SECUNIA" url="http://secunia.com/advisories/23741">23741</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2113">2113</ref></refs><vuln_soft><prod name="WordPress" vendor="WordPress"><vers num="2.0.5"/><vers num="2.0.4"/><vers num="2.0.3"/><vers num="2.0.2"/><vers num="2.0.1"/><vers num="2.0"/><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-01-15" name="CVE-2007-0110" published="2007-01-08" seq="2007-0110" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in nidp/idff/sso in Novell Access Manager Identity Server before 3.0.0-1013 allows remote attackers to inject arbitrary web script or HTML via the IssueInstant parameter, which is not properly handled in the resulting error message.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="" url="https://secure-support.novell.com/KanisaPlatform/Publishing/143/3615264_f.SAL_Public.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/21921">21921</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0073">ADV-2007-0073</ref><ref source="SECUNIA" url="http://secunia.com/advisories/23654">23654</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1017483">1017483</ref></refs><vuln_soft><prod name="Novell Access Manager Identity Server" vendor="Novell"><vers num="3" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-01-15" name="CVE-2007-0111" published="2007-01-08" seq="2007-0111" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in Resco Photo Viewer for PocketPC 4.11 and 6.01, as used in mobile devices running Windows Mobile 5.0, 2003, and 2003SE, allows remote attackers to execute arbitrary code via a crafted PNG image.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" source="" url="http://blog.trendmicro.com/flaw-in-3rd-party-app-weakens-windows-mobile/"></ref><ref adv="1" source="" url="http://www.trendmicro.com/vinfo/secadvisories/default6.asp?VName=Vulnerability+in+Resco+Photo+Viewer+6%2E01+Enabling+Code+Injection+and+Arbitrary+Code+Execution"></ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/21920">21920</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0072">ADV-2007-0072</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/23658">23658</ref></refs><vuln_soft><prod name="Photo Viewer" vendor="Resco"><vers num="6.11"/><vers num="4.11"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-01-15" name="CVE-2007-0112" published="2007-01-08" seq="2007-0112" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in cats.asp in createauction allows remote attackers to execute arbitrary SQL commands via the catid parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/456272/100/0/threaded">20070107 createauction (cats.asp) Remote SQL Injection Vulnerability</ref><ref source="BID" url="http://www.securityfocus.com/bid/21929">21929</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31356">createauction-cats-sql-injection(31356)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2111">2111</ref></refs><vuln_soft><prod name="CreateAuction" vendor="CreateAuction"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.0" CVSS_impact_subscore="6.9" CVSS_score="6.8" CVSS_vector="(AV:N/AC:L/Au:S/C:N/I:N/A:C)" CVSS_version="2.0" modified="2007-01-15" name="CVE-2007-0113" published="2007-01-08" seq="2007-0113" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in Packeteer PacketShaper PacketWise 8.x allows remote authenticated users to cause a denial of service (reset or reboot) via (1) a long traffic class argument to the &quot;class show&quot; command or (2) a long POLICY parameter value in clastree.htm.</descript></desc><loss_types><avail/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/456267/100/0/threaded">20070108 Packeteer PacketWise CLI overflow DoS</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/21933">21933</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0098">ADV-2007-0098</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/23685">23685</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31357">packetshaper-argument-dos(31357)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2110">2110</ref></refs><vuln_soft><prod name="PacketWise" vendor="Packeteer"><vers num="8.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0" modified="2007-01-14" name="CVE-2007-0114" published="2007-01-08" seq="2007-0114" severity="Medium" type="CVE"><desc><descript source="cve">Sun Java System Content Delivery Server 5.0 and 5.0 PU1 allows remote attackers to obtain sensitive information regarding &quot;content details&quot; via unspecified vectors.</descript></desc><loss_types><conf/></loss_types><range><network/></range><refs><ref patch="1" source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102764-1">102764</ref><ref source="BID" url="http://www.securityfocus.com/bid/21908">21908</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0076">ADV-2007-0076</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/23630">23630</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31345">sun-java-cds-info-disclosure(31345)</ref></refs><vuln_soft><prod name="Java System Content Delivery Server" vendor="Sun"><vers edition="Solaris" num="5.0 PU1"/><vers edition="Solaris" num="5.0"/></prod></vuln_soft></entry><entry CVSS_base_score="6.0" CVSS_exploit_subscore="6.8" CVSS_impact_subscore="6.4" CVSS_score="6.0" CVSS_vector="(AV:N/AC:M/Au:S/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-01-11" name="CVE-2007-0115" published="2007-01-08" seq="2007-0115" severity="Medium" type="CVE"><desc><descript source="cve">Static code injection vulnerability in Coppermine Photo Gallery 1.4.10 and earlier allows remote authenticated administrators to execute arbitrary PHP code via the Username to login.php, which is injected into an error message in security.log.php, which can then be accessed using viewlog.php.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/456051/100/0/threaded">20070105 Coppermine Photo Gallery &lt;= 1.4.10 SQL Injection Exploit</ref><ref source="VIM" url="http://www.attrition.org/pipermail/vim/2007-January/001218.html">20070108 Source verify - Coppermine Photo Gallery &lt;= 1.4.10 code injection</ref><ref source="" url="http://acid-root.new.fr/poc/19070104.txt"></ref><ref source="SREASON" url="http://securityreason.com/securityalert/2107">2107</ref></refs><vuln_soft><prod name="Coppermine Photo Gallery" vendor="Coppermine"><vers num="1.4.10" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-01-11" name="CVE-2007-0116" published="2007-01-08" seq="2007-0116" severity="High" type="CVE"><desc><descript source="cve">Digger Solutions Intranet Open Source (IOS) stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing passwords via a direct request for data/intranet.mdb.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/><design/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/456047/100/0/threaded">20070105 Intranet Open Source Remote Password Disclosure </ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31308">intranet-intranet-info-disclosure(31308)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2109">2109</ref></refs><vuln_soft><prod name="Intranet Open Source" vendor="Digger Solutions"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-01-11" name="CVE-2007-0117" published="2007-01-08" seq="2007-0117" severity="High" type="CVE"><desc><descript source="cve">DiskManagementTool in the DiskManagement.framework 92.29 on Mac OS X 10.4.8 does not properly validate Bill of Materials (BOM) files, which allows attackers to gain privileges via a BOM file under /Library/Receipts/, which triggers arbitrary file permission changes upon execution of a diskutil permission repair operation.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref source="" url="http://projects.info-pull.com/moab/MOAB-05-01-2007.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/21899">21899</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0074">ADV-2007-0074</ref><ref source="SECUNIA" url="http://secunia.com/advisories/23653">23653</ref></refs><vuln_soft><prod name="Mac OS X Server" vendor="Apple"><vers num="10.4.8"/></prod><prod name="Mac OS X" vendor="Apple"><vers num="10.4.8"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)" CVSS_version="2.0" modified="2007-01-11" name="CVE-2007-0118" published="2007-01-08" seq="2007-0118" severity="Medium" type="CVE"><desc><descript source="cve">Multiple absolute path traversal vulnerabilities in EditTag 1.2 allow remote attackers to read arbitrary files via an absolute pathname in the file parameter to (1) edittag.cgi, (2) edittag.pl, (3) edittag_mp.cgi, or (4) edittag_mp.pl.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/456055/100/0/threaded">20070105 Multiple bugs in EditTag</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/21890">21890</ref><ref source="SECUNIA" url="http://secunia.com/advisories/7950">7950</ref></refs><vuln_soft><prod name="EditTag" vendor="EditTag"><vers num="1.2"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-01-11" name="CVE-2007-0119" published="2007-01-08" seq="2007-0119" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in EditTag 1.2 allow remote attackers to inject arbitrary web script or HTML via the plain parameter to (1) mkpw_mp.cgi, (2) mkpw.pl, or (3) mkpw.cgi.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/456055/100/0/threaded">20070105 Multiple bugs in EditTag</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/21891">21891</ref><ref source="SECUNIA" url="http://secunia.com/advisories/7950">7950</ref></refs><vuln_soft><prod name="EditTag" vendor="EditTag"><vers num="1.2"/></prod></vuln_soft></entry><entry CVSS_base_score="1.9" CVSS_exploit_subscore="3.4" CVSS_impact_subscore="2.9" CVSS_score="1.9" CVSS_vector="(AV:L/AC:M/Au:N/C:N/I:N/A:P)" CVSS_version="2.0" modified="2007-01-31" name="CVE-2007-0120" published="2007-01-08" seq="2007-0120" severity="Low" type="CVE"><desc><descript source="cve">Acunetix Web Vulnerability Scanner (WVS) 4.0 Build 20060717 and earlier allows remote attackers to cause a denial of service (application crash) via multiple HTTP requests containing invalid Content-Length values.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><local/></range><refs><ref adv="1" source="" url="http://www.milw0rm.com/exploits/3078"></ref><ref source="BID" url="http://www.securityfocus.com/bid/21898">21898</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/31279">acunetix-content-length-dos(31279)</ref><ref source="MILW0RM" url="http://milw0rm.com/exploits/3078">

3078</ref></refs><vuln_soft><prod name="Web Vulnerability Scanner" vendor="Acunetix"><vers num="4.0 Build 2006-07-17" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-01-11" name="CVE-2007-0121" published="2007-01-08" seq="2007-0121" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in search.asp in RI Blog 1.3 allows remote attackers to inject arbitrary web script or HTML via the q parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/456052/100/0/threaded">20070105 RI Blog 1.3 XSS Vuln.</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/21880">21880</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0083">ADV-2007-0083</ref><ref source="SECUNIA" url="http://secunia.com/advisories/23657">23657</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31317">riblog-search-xss(31317)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2108">2108</ref></refs><vuln_soft><prod name="RI Blog" vendor="Michael Romedahl"><vers num="1.3"/></prod></vuln_soft></entry><entry CVSS_base_score="6.5" CVSS_exploit_subscore="8.0" CVSS_impact_subscore="6.4" CVSS_score="6.5" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-01-11" name="CVE-2007-0122" published="2007-01-08" seq="2007-0122" severity="Medium" type="CVE"><desc><descript source="cve">Multiple SQL injection vulnerabilities in Coppermine Photo Gallery 1.4.10 and earlier allow remote authenticated administrators to execute arbitrary SQL commands via (1) the cat parameter to albmgr.php, and possibly (2) the gid parameter to usermgr.php; (3) the start parameter to db_ecard.php; and the albumid parameter to unspecified files, related to the (4) filename_to_title and (5) del_titles functions.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/456051/100/0/threaded">20070105 Coppermine Photo Gallery &lt;= 1.4.10 SQL Injection Exploit</ref><ref source="" url="http://acid-root.new.fr/poc/19070104.txt"></ref><ref source="BID" url="http://www.securityfocus.com/bid/21894">21894</ref><ref source="MILW0RM" url="http://milw0rm.com/exploits/3085">3085</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25846">25846</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2123">2123</ref></refs><vuln_soft><prod name="Coppermine Photo Gallery" vendor="Coppermine"><vers num="1.4.10" prev="1"/><vers num="1.4.9"/><vers num="1.4.4"/><vers num="1.3.4"/><vers num="1.3.3"/><vers num="1.3.2"/><vers num="1.3"/><vers num="1.2.2 b-Nuke"/><vers num="1.2.2 b"/><vers num="1.2.1"/><vers num="1.2"/><vers num="1.1 Beta 2"/><vers num="1.1"/><vers num="1.0 RC3"/><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-01-11" name="CVE-2007-0123" published="2007-01-08" seq="2007-0123" severity="Medium" type="CVE"><desc><descript source="cve">Unrestricted file upload vulnerability in Uber Uploader 4.2 allows remote attackers to upload and execute arbitrary PHP scripts by naming them with a .phtml extension, which bypasses the .php extension check but is still executable on some server configurations.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/456045/100/0/threaded">20070105 Uber Uploader 4.2 Arbitrary File Upload Vulnerability</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31303">uber-uploader-phtml-file-upload(31303)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2116">2116</ref></refs><vuln_soft><prod name="Uber Uploader" vendor="Uber Uploader"><vers num="4.2"/></prod></vuln_soft></entry><entry CVSS_base_score="3.5" CVSS_exploit_subscore="6.8" CVSS_impact_subscore="2.9" CVSS_score="3.5" CVSS_vector="(AV:N/AC:M/Au:S/C:N/I:N/A:P)" CVSS_version="2.0" modified="2007-01-11" name="CVE-2007-0124" published="2007-01-08" seq="2007-0124" severity="Low" type="CVE"><desc><descript source="cve">Unspecified vulnerability in Drupal before 4.6.11, and 4.7 before 4.7.5, when MySQL is used, allows remote authenticated users to cause a denial of service by poisoning the page cache via unspecified vectors, which triggers erroneous 404 HTTP errors for pages that exist.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/456056/100/0/threaded">20070105 [DRUPAL-SA-2007-002] Drupal 4.6.11 / 4.7.5 fixes DoS issue</ref><ref adv="1" patch="1" source="" url="http://drupal.org/node/104238"></ref><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/21895">21895</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0051">ADV-2007-0051</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/23586">23586</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2115">2115</ref></refs><vuln_soft><prod name="Drupal" vendor="Drupal"><vers num="4.7.4"/><vers num="4.7.3"/><vers num="4.7.2"/><vers num="4.7.1"/><vers num="4.7.0"/><vers num="4.7"/><vers num="4.6.10"/><vers num="4.6.9"/><vers num="4.6.8"/><vers num="4.6.7"/><vers num="4.6.6"/><vers num="4.6.5"/><vers num="4.6.4"/><vers num="4.6.3"/><vers num="4.6.2"/><vers num="4.6.1"/><vers num="4.6.0"/><vers num="4.6"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0" modified="2007-01-15" name="CVE-2007-0125" published="2007-01-08" seq="2007-0125" severity="Medium" type="CVE"><desc><descript source="cve">Kaspersky Labs Antivirus Engine 6.0 for Windows and 5.5-10 for Linux before 20070102 enter an infinite loop upon encountering an invalid NumberOfRvaAndSizes value in the Optional Windows Header of a portable executable (PE) file, which allows remote attackers to cause a denial of service (CPU consumption) by scanning a crafted PE file.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="IDEFENSE" url="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=459">20070105 Kaspersky Antivirus Scan Engine PE File Denial of Service Vulnerability</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/23575">23575</ref><ref source="BID" url="http://www.securityfocus.com/bid/21901">21901</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0067">ADV-2007-0067</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1017476">1017476</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31315">kaspersky-antivirus-pe-dos(31315)</ref></refs><vuln_soft><prod name="Kaspersky Antivirus Engine" vendor="Kaspersky Lab"><vers edition="Windows" num="6.0"/><vers edition="Linux" num="5.5.10"/></prod></vuln_soft></entry><entry CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" CVSS_score="9.3" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-11-26" name="CVE-2007-0126" published="2007-01-08" seq="2007-0126" severity="High" type="CVE"><desc><descript source="cve">Heap-based buffer overflow in Opera 9.02 allows remote attackers to execute arbitrary code via a JPEG file with an invalid number of index bytes in the Define Huffman Table (DHT) marker.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" source="IDEFENSE" url="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=457">20070105 Opera Software Opera Web Browser JPG Image DHT Marker Heap Corruption Vulnerability</ref><ref adv="1" patch="1" source="" url="http://www.opera.com/support/search/supsearch.dml?index=852"></ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0060">ADV-2007-0060</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/23613">23613</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1017473">1017473</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31305">opera-jpeg-dht-bo(31305)</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200701-08.xml">GLSA-200701-08</ref><ref source="SUSE" url="http://lists.suse.com/archive/suse-security-announce/2007-Jan/0009.html">SUSE-SA:2007:009</ref><ref source="SECUNIA" url="http://secunia.com/advisories/23739">23739</ref><ref source="SECUNIA" url="http://secunia.com/advisories/23771">23771</ref></refs><vuln_soft><prod name="Opera" vendor="Opera Software"><vers num="9.02"/></prod></vuln_soft></entry><entry CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" CVSS_score="9.3" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" discovered="2006-11-16" modified="2007-11-26" name="CVE-2007-0127" published="2007-01-08" seq="2007-0127" severity="High" type="CVE"><desc><descript source="cve">The Javascript SVG support in Opera before 9.10 does not properly validate object types in a createSVGTransformFromMatrix request, which allows remote attackers to execute arbitrary code via JavaScript code that uses an invalid object in this request that causes a controlled pointer to be referenced during the virtual function call.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input/><design/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" patch="1" source="IDEFENSE" url="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=458">20070105 Opera Software Opera Web Browser createSVGTransformFromMatrix Object Typecasting Vulnerability</ref><ref source="" url="http://www.opera.com/support/search/supsearch.dml?index=851"></ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0060">ADV-2007-0060</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/23613">23613</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1017473">1017473</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200701-08.xml">GLSA-200701-08</ref><ref source="SUSE" url="http://lists.suse.com/archive/suse-security-announce/2007-Jan/0009.html">SUSE-SA:2007:009</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/23739">23739</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/23771">23771</ref></refs><vuln_soft><prod name="Opera" vendor="Opera Software"><vers num="9.02"/><vers num="9.01"/><vers num="9.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-01-10" name="CVE-2007-0128" published="2007-01-09" seq="2007-0128" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in info_book.asp in Digirez 3.4 and earlier allows remote attackers to execute arbitrary SQL commands via the book_id parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://milw0rm.com/exploits/3081"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0053">ADV-2007-0053</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/23606">23606</ref></refs><vuln_soft><prod name="DigiRez" vendor="DigiAppz"><vers num="3.4" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-01-10" name="CVE-2007-0129" published="2007-01-09" seq="2007-0129" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in main.asp in LocazoList 2.01a beta5 and earlier allows remote attackers to execute arbitrary SQL commands via the subcatID parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://www.milw0rm.com/exploits/3073"></ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31242">locazolist-main-sql-injection(31242)</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0052">ADV-2007-0052</ref><ref source="MILW0RM" url="http://milw0rm.com/exploits/3073">

3073</ref></refs><vuln_soft><prod name="LocazoList Classifieds" vendor="Locazo"><vers num="2.01a Beta5" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-01-10" name="CVE-2007-0130" published="2007-01-09" seq="2007-0130" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in user.php in iGeneric iG Calendar 1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://www.milw0rm.com/exploits/3082"></ref><ref source="BID" url="http://www.securityfocus.com/bid/21873">21873</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0055">ADV-2007-0055</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/23602">23602</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/456044/100/0/threaded">20070105 IG Calendar SQL Injection</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31300">igcalendar-user-sql-injection(31300)</ref><ref source="MILW0RM" url="http://milw0rm.com/exploits/3082">
3082</ref></refs><vuln_soft><prod name="iG Calendar" vendor="iGeneric"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-01-10" name="CVE-2007-0131" published="2007-01-09" seq="2007-0131" severity="High" type="CVE"><desc><descript source="cve">JAMWiki before 0.5.0 does not properly check permissions during moves of &quot;read-only or admin-only topics,&quot; which allows remote attackers to make unauthorized changes to the wiki.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref patch="1" source="" url="http://sourceforge.net/project/shownotes.php?group_id=171441&amp;release_id=475663"></ref><ref source="SECUNIA" url="http://secunia.com/advisories/23634">23634</ref><ref source="BID" url="http://www.securityfocus.com/bid/21879">21879</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31296">jamwiki-permission-security-bypass(31296)</ref></refs><vuln_soft><prod name="JAMWiki" vendor="JAMWiki"><vers num="0.4.3" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-01-10" name="CVE-2007-0132" published="2007-01-09" seq="2007-0132" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in compare_product.php in iGeneric iG Shop 1.4 allows remote attackers to execute arbitrary SQL commands via the id parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://www.milw0rm.com/exploits/3083"></ref><ref source="" url="http://packetstormsecurity.nl/0701-exploits/igshop10-multiple.txt"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0056">ADV-2007-0056</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/23604">23604</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/456043/100/0/threaded">20070105 IG Shop remote code execution</ref><ref source="BID" url="http://www.securityfocus.com/bid/21874">21874</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31299">igshop-compareproduct-sql-injection(31299)</ref><ref source="MILW0RM" url="http://milw0rm.com/exploits/3083">
3083</ref></refs><vuln_soft><prod name="iG Shop" vendor="iGeneric"><vers num="1.4"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-01-10" name="CVE-2007-0133" published="2007-01-09" seq="2007-0133" severity="High" type="CVE"><desc><descript source="cve">Multiple SQL injection vulnerabilities in display_review.php in iGeneric iG Shop 1.4 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) id or (2) user_login_cookie parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0056">ADV-2007-0056</ref></refs><vuln_soft><prod name="iG Shop" vendor="iGeneric"><vers num="1.4" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2008-01-02" name="CVE-2007-0134" published="2007-01-09" seq="2007-0134" severity="High" type="CVE"><desc><descript source="cve">Multiple eval injection vulnerabilities in iGeneric iG Shop 1.0 allow remote attackers to execute arbitrary code via the action parameter, which is supplied to an eval function call in (1) cart.php and (2) page.php.  NOTE: a later report and CVE analysis indicate that the vulnerability is present in 1.4.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://packetstormsecurity.nl/0701-exploits/igshop10-multiple.txt"></ref><ref source="" url="http://www.milw0rm.com/exploits/3083"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0056">ADV-2007-0056</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/23604">23604</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/456043/100/0/threaded">20070105 IG Shop remote code execution</ref><ref source="BID" url="http://www.securityfocus.com/bid/21875">21875</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31301">igshop-cartpage-code-execution(31301)</ref><ref source="MILW0RM" url="http://milw0rm.com/exploits/3083">3083</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/471722/100/0/threaded">20070619 iG Shop 1.4 eval Inclusion Vulnerability</ref><ref source="VIM" url="http://www.attrition.org/pipermail/vim/2007-June/001664.html">20070618 Dup: iG Shop 1.4 (page.php) Remote Code Execution Exploit</ref></refs><vuln_soft><prod name="iG Shop" vendor="iGeneric"><vers num="1.0"/><vers num="1.4"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-01-10" name="CVE-2007-0135" published="2007-01-09" seq="2007-0135" severity="Medium" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in inc/init.inc.php in Aratix 0.2.2 beta 11 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the current_path parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="VIM" url="http://www.attrition.org/pipermail/vim/2007-January/001219.html">20070108 Source verify of Aratix RFI</ref><ref source="" url="http://securityreason.com/exploitalert/1698"></ref><ref source="" url="http://www.milw0rm.com/exploits/3079"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0054">ADV-2007-0054</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31282">aratix-init-file-include(31282)</ref><ref source="MILW0RM" url="http://milw0rm.com/exploits/3079">
3079</ref></refs><vuln_soft><prod name="Aratix" vendor="Aratix"><vers num="0.2.2 Beta 11" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-01-10" name="CVE-2007-0136" published="2007-01-09" seq="2007-0136" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Drupal before 4.6.11, and 4.7 before 4.7.5, allow remote attackers to inject arbitrary web script or HTML via unspecified parameters in the (1) filter and (2) system modules.  NOTE: some of these details are obtained from third party information.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="FULLDISC" url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=116799778408115&amp;w=2">20070105 [DRUPAL-SA-2007-001] Drupal 4.6.11 / 4.7.5 fixes</ref><ref patch="1" source="" url="http://drupal.org/node/104233"></ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0050">ADV-2007-0050</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/456054/100/100/threaded">20070105 [DRUPAL-SA-2007-001] Drupal 4.6.11 / 4.7.5 fixes XSS issue</ref><ref source="" url="http://drupal.org/files/sa-2007-001/advisory.txt"></ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31311">drupal-core-unspecified-xss(31311)</ref></refs><vuln_soft><prod name="Drupal" vendor="Drupal"><vers num="4.6.10" prev="1"/><vers num="4.7.4" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-01-10" name="CVE-2007-0137" published="2007-01-09" seq="2007-0137" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in SimpleBoxes/SerendipityNZ Serene Bach 2.05R and earlier, and 2.08D and earlier in the 2.08 series; and (2) sb 1.13D and earlier, and 1.18R and earlier in the 1.18 series; allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://jvn.jp/jp/JVN%2365500885/index.html"></ref><ref source="" url="http://serenebach.net/log/sb119R.html"></ref><ref source="" url="http://serenebach.net/log/sb209R.html"></ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/23623">23623</ref><ref source="BID" url="http://www.securityfocus.com/bid/21884">21884</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0065">ADV-2007-0065</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1017470">1017470</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31302">serene-bach-unspecified-xss(31302)</ref></refs><vuln_soft><prod name="Serene Bach 1.18R" vendor="SerendipityNZ"><vers num="and previous"/></prod><prod name="Serene Bach 2.08D" vendor="SerendipityNZ"><vers num="and previous"/></prod><prod name="Serene Bach sb 1.13D" vendor="SerendipityNZ"><vers num="and previous"/></prod><prod name="Serene Bach 2.05R" vendor="SerendipityNZ"><vers num="and previous"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0" modified="2007-01-10" name="CVE-2007-0138" published="2007-01-09" seq="2007-0138" severity="Medium" type="CVE"><desc><descript source="cve">formbankcgi.exe in Fersch Formbankserver 1.9, when the PATH_INFO begins with (1) AbfrageForm or (2) EingabeForm, allows remote attackers to cause a denial of service (daemon crash) via multiple requests containing many /../ sequences in the Name parameter.  NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/23539">23539</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31216">formbankserver-formbank-dos(31216)</ref></refs><vuln_soft><prod name="Formbankserver" vendor="Fersch"><vers num="1.9"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-01-10" name="CVE-2007-0139" published="2007-01-09" seq="2007-0139" severity="High" type="CVE"><desc><descript source="cve">Unspecified vulnerability in the DECnet-Plus 7.3-2 feature in DECnet/OSI 7.3-2 for OpenVMS ALPHA, and the DECnet-Plus 7.3 feature in DECnet/OSI 7.3 for OpenVMS VAX, allows attackers to obtain &quot;unintended privileged access to data and system resources&quot; via unspecified vectors, related to (1) [SYSEXE]CTF$UI.EXE, (2) [SYSMSG]CTF$MESSAGES.EXE, (3) [SYSHLP]CTF$HELP.HLB, and (4) [SYSMGR]CTF$STARTUP.COM.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><range><network/></range><refs><ref patch="1" source="" url="ftp://ftp.itrc.hp.com/openvms_patches/alpha/V7.3-2/AXP_DNVOSIMUP01-V0703-2.txt"></ref><ref patch="1" source="" url="ftp://ftp.itrc.hp.com/openvms_patches/vax/V7.3/VAX_DNVOSIMUP01-V0703.txt"></ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/23636">23636</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0063">ADV-2007-0063</ref></refs><vuln_soft><prod name="DECnet/OSI" vendor="HP"><vers edition="OpenVMS VAX" num="7.3_2"/><vers edition="OpenVMS VAX" num="7.3"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-01-10" name="CVE-2007-0140" published="2007-01-09" seq="2007-0140" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in down.asp in Kolayindir Download (Yenionline) allows remote attackers to execute arbitrary SQL commands via the id parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/456068/100/0/threaded">20070105 Kolayindir Download (Yenionline) (tr) SqL Injection Vuln.</ref><ref source="BID" url="http://www.securityfocus.com/bid/21889">21889</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0079">ADV-2007-0079</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/23645">23645</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31320">kolayindirdownload-down-sql-injection(31320)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2122">2122</ref></refs><vuln_soft><prod name="Kolayindir Download" vendor="Kolayindir Download"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-01-10" name="CVE-2007-0141" published="2007-01-09" seq="2007-0141" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in yald.php in Yet Another Link Directory 1.0 allows remote attackers to inject arbitrary web script or HTML via the search parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/456122/100/0/threaded">20070106 Yet Another Link Directory v1.0</ref><ref source="BID" url="http://www.securityfocus.com/bid/21904">21904</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0082">ADV-2007-0082</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/23646">23646</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31322">yald-yald-xss(31322)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2121">2121</ref></refs><vuln_soft><prod name="Yet Another Link Directory" vendor="Yet Another Link Directory"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-01-10" name="CVE-2007-0142" published="2007-01-09" seq="2007-0142" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in orange.asp in ShopStoreNow E-commerce Shopping Cart allows remote attackers to execute arbitrary SQL commands via the CatID parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/456127/100/0/threaded">20070106 shopstorenow (orange.asp) sql injection</ref><ref source="BID" url="http://www.securityfocus.com/bid/21905">21905</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0080">ADV-2007-0080</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/23642">23642</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31313">shopstorenow-orange-sql-injection(31313)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2120">2120</ref></refs><vuln_soft><prod name="E-commerce Shopping Cart" vendor="Shopstorenow"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-01-10" name="CVE-2007-0143" published="2007-01-09" seq="2007-0143" severity="Medium" type="CVE"><desc><descript source="cve">Multiple PHP remote file inclusion vulnerabilities in NUNE News Script 2.0pre2 allow remote attackers to execute arbitrary PHP code via a URL in the custom_admin_path parameter to (1) index.php or (2) archives.php.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://milw0rm.com/exploits/3090"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0078">ADV-2007-0078</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/23635">23635</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/456242/100/0/threaded">20070107 NUNE News Script (custom_admin_path) Remote File Include Vulnerablity</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31312">nune-index-archives-file-include(31312)</ref></refs><vuln_soft><prod name="News Script" vendor="NUNE"><vers num="2.0 pre2"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-01-10" name="CVE-2007-0144" published="2007-01-09" seq="2007-0144" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in search.asp in Digitizing Quote And Ordering System 1.0 allows remote authenticated attackers to inject arbitrary web script or HTML via the ordernum parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://www.milw0rm.com/exploits/3089"></ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/23652">23652</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31321">qos-search-xss(31321)</ref><ref source="MILW0RM" url="http://milw0rm.com/exploits/3089">

3089</ref></refs><vuln_soft><prod name="Digitizing Quote And Ordering System" vendor="Digitizing Quote And Ordering System"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-01-10" name="CVE-2007-0145" published="2007-01-09" seq="2007-0145" severity="High" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in bn_smrep1.php in BinGoPHP News (BP News) 3.01 allows remote attackers to execute arbitrary PHP code via a URL in the bnrep parameter, a different vector than CVE-2006-4648 and CVE-2006-4649.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="SECTRACK" url="http://securitytracker.com/id?1017477">1017477</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31328">bingo-bnsmrep1-file-include(31328)</ref></refs><vuln_soft><prod name="BinGo News" vendor="BinGo News"><vers num="3.01"/></prod></vuln_soft></entry><entry CVSS_base_score="6.0" CVSS_exploit_subscore="6.8" CVSS_impact_subscore="6.4" CVSS_score="6.0" CVSS_vector="(AV:N/AC:M/Au:S/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-01-10" name="CVE-2007-0146" published="2007-01-09" seq="2007-0146" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Fix and Chips CMS 1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) id parameter in (a) delete-announce.php; the (2) Announcement form field in (b) staff.php; the (3) Client Name, (4) Business Name, (5) Street, (6) Address 2, (7) Town/City, (8) Postcode, (9) Phone Number, (10) Email Address and (11) Website Address form fields in (c) new_customer.php; and unspecified fields in (d) search.php and (e) client-results.php.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/456121/100/0/threaded">20070106 Fix &amp; Chips CMS v1.0</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0081">ADV-2007-0081</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/23625">23625</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31319">fixandchips-multiple-scripts-xss(31319)</ref><ref source="OSVDB" url="http://www.osvdb.org/32646">32646</ref><ref source="OSVDB" url="http://www.osvdb.org/32647">32647</ref><ref source="OSVDB" url="http://www.osvdb.org/32648">32648</ref><ref source="OSVDB" url="http://www.osvdb.org/32649">32649</ref><ref source="OSVDB" url="http://www.osvdb.org/32650">32650</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2119">2119</ref></refs><vuln_soft><prod name="Fix and Chips CMS" vendor="Fix and Chips Computer Services"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" modified="2007-01-10" name="CVE-2007-0147" published="2007-01-09" seq="2007-0147" severity="Medium" type="CVE"><desc><descript source="cve">Cuyahoga before 1.0.1 installs the FCKEditor component with an incorrect deny statement in a Web.config file, which allows remote attackers to upload files when these privileges were intended only for the Administrator and Editor roles.</descript></desc><loss_types><int/></loss_types><vuln_types><access/><design/></vuln_types><range><network/></range><refs><ref patch="1" source="" url="http://www.cuyahoga-project.org/10/section.aspx/61"></ref><ref patch="1" source="" url="http://cuyahoga.svn.sourceforge.net/viewvc/cuyahoga?view=rev&amp;revision=551"></ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/23662">23662</ref><ref source="BID" url="http://www.securityfocus.com/bid/21927">21927</ref></refs><vuln_soft><prod name="Cuyahoga" vendor="Cuyahoga"><vers num="1.0.0" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-01-10" name="CVE-2007-0148" published="2007-01-09" seq="2007-0148" severity="Medium" type="CVE"><desc><descript source="cve">Format string vulnerability in OmniGroup OmniWeb 5.5.1 allows remote attackers to cause a denial of service (application crash) or execute arbitrary code via format string specifiers in the Javascript alert function.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" source="" url="http://projects.info-pull.com/moab/MOAB-07-01-2007.html"></ref><ref patch="1" source="" url="http://www.omnigroup.com/applications/omniweb/releasenotes/"></ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0075">ADV-2007-0075</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/23624">23624</ref><ref source="" url="http://www.milw0rm.com/exploits/3098"></ref><ref source="BID" url="http://www.securityfocus.com/bid/21911">21911</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31324">omniweb-alert-format-string(31324)</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/456578/100/0/threaded">20070111 DMA[2007-0107a] OmniWeb Javascript Alert Format String Vulnerabiity and DMA[2007-0109a] Apple Finder Disk Image Volume Label Overflow / DoS</ref><ref source="" url="http://www.digitalmunition.com/DMA%5B2007-0107a%5D.txt"></ref><ref source="" url="http://blog.omnigroup.com/2007/01/07/omniweb-552-now-available-and-more-secure/"></ref><ref source="MILW0RM" url="http://milw0rm.com/exploits/3098">
3098</ref></refs><vuln_soft><prod name="OmniWeb" vendor="OmniGroup"><vers num="5.5.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-01-10" name="CVE-2007-0149" published="2007-01-09" seq="2007-0149" severity="High" type="CVE"><desc><descript source="cve">EMembersPro 1.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing passwords via a direct request for users.mdb.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/><design/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/456228/100/0/threaded">20070107 EMembersPro 1.0 Remote Password Disclosure Vulnerability</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31329">ememberspro-users-info-disclosure(31329)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2118">2118</ref></refs><vuln_soft><prod name="EMembersPro" vendor="EMembersPro"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-01-10" name="CVE-2007-0150" published="2007-01-09" seq="2007-0150" severity="High" type="CVE"><desc><descript source="cve">Multiple PHP remote file inclusion vulnerabilities in index.php in Dayfox Blog allow remote attackers to execute arbitrary PHP code via a URL in the (1) page, (2) subject, and (3) q parameters.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/456212/100/0/threaded">20070107 Dayfox Blog Remote File Include Vuln.</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0099">ADV-2007-0099</ref><ref source="SECUNIA" url="http://secunia.com/advisories/23661">23661</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31336">dayfoxblog-index-file-include(31336)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2117">2117</ref></refs><vuln_soft><prod name="Dayfox Blog" vendor="Dayfox Designs"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-01-10" name="CVE-2007-0151" published="2007-01-09" seq="2007-0151" severity="High" type="CVE"><desc><descript source="cve">MitiSoft stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing passwords via a direct request for access_MS/MitiSoft.mdb.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/456230/100/0/threaded">20070107 MitiSoft Remote Password Disclosure Vulnerability</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31341">mitisoft-mitisoft-info-disclosure(31341)</ref></refs><vuln_soft><prod name="MitiSoft" vendor="MitiSoft"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-01-10" name="CVE-2007-0152" published="2007-01-09" seq="2007-0152" severity="High" type="CVE"><desc><descript source="cve">OhhASP stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing passwords via a direct request for db/OhhASP.mdb.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/><design/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/456117/100/0/threaded">20070106 ohhASP Remote Password Disclosure</ref><ref source="" url="http://64.38.62.221/ariasecucom/forum/showthread.php?t=89"></ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31342">ohhasp-ohhasp-info-disclosure(31342)</ref></refs><vuln_soft><prod name="OhhASP" vendor="OhhASP"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-01-10" name="CVE-2007-0153" published="2007-01-09" seq="2007-0153" severity="High" type="CVE"><desc><descript source="cve">AJLogin 3.5 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing passwords via a direct request for ajlogin.mdb.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/><design/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/456226/100/0/threaded">20070107 AJLogin v3.5 Remote Password Disclosure Vulnerability</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31331">ajlogin-ajlogin-info-disclosure(31331)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2127">2127</ref></refs><vuln_soft><prod name="AJLogin" vendor="Adam Jarret"><vers num="3.5"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-01-10" name="CVE-2007-0154" published="2007-01-09" seq="2007-0154" severity="High" type="CVE"><desc><descript source="cve">Webulas stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing passwords via a direct request for db/db.mdb.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/><design/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/456239/100/0/threaded">20070107 Webulas Remote Password Disclosure Vulnerability</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31338">webulas-db-info-disclosure(31338)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2126">2126</ref></refs><vuln_soft><prod name="Webulas" vendor="Webulas"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-01-10" name="CVE-2007-0155" published="2007-01-09" seq="2007-0155" severity="High" type="CVE"><desc><descript source="cve">HarikaOnline 2.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing passwords via a direct request for harikaonline.mdb.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/><design/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/456238/100/0/threaded">20070107 HarikaOnline v2.0 Remote Password Disclosure Vulnerability</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31339">harikaonline-harikaonline-info-disclosure(31339)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2125">2125</ref></refs><vuln_soft><prod name="HarikaOnline" vendor="HarikaOnline"><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-01-10" name="CVE-2007-0156" published="2007-01-09" seq="2007-0156" severity="High" type="CVE"><desc><descript source="cve">M-Core stores the database under the web document root, which allows remote attackers to obtain sensitive information via a direct request to db/uyelik.mdb.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/><design/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/456235/100/0/threaded">20070107 M-Core Remote Password Disclosure Vulnerability</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31340">mcore-uyelik-info-disclosure(31340)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2124">2124</ref></refs><vuln_soft><prod name="M-Core" vendor="M-Core"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.8" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.9" CVSS_score="7.8" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_version="2.0" modified="2007-01-10" name="CVE-2007-0157" published="2007-01-09" seq="2007-0157" severity="High" type="CVE"><desc><descript source="cve">Array index error in the uri_lookup function in the URI parser for neon 0.26.0 to 0.26.2, possibly only on 64-bit platforms, allows remote malicious servers to cause a denial of service (crash) via a URI with non-ASCII characters, which triggers a buffer under-read due to a type conversion error that generates a negative index.</descript></desc><loss_types><avail/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref source="MLIST" url="http://mailman.webdav.org/pipermail/neon/2007-January/002362.html">[neon] 20070107 invalid chars cause sigserv in neon</ref><ref source="" url="http://bugs.debian.org/cgi-bin/bugreport.cgi/neon26_0.26.2-3_to_mdx1.diff?bug=404723;msg=5;att=2"></ref><ref source="" url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=404723"></ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:013">MDKSA-2007:013</ref><ref source="BID" url="http://www.securityfocus.com/bid/22035">22035</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0172">ADV-2007-0172</ref><ref source="SECUNIA" url="http://secunia.com/advisories/23763">23763</ref><ref source="SECUNIA" url="http://secunia.com/advisories/23751">23751</ref><ref source="MLIST" url="http://mailman.webdav.org/pipermail/cadaver/2007-January/001015.html">
[cadaver] 20070123 release 0.22.5</ref><ref source="" url="http://www.webdav.org/cadaver/"></ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2007_02_sr.html">
SUSE-SR:2007:002</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0362">
ADV-2007-0362</ref><ref source="SECUNIA" url="http://secunia.com/advisories/23984">
23984</ref></refs><vuln_soft><prod name="neon" vendor="neon"><vers num="0.26.0"/><vers num="0.26.1"/><vers num="0.26.2"/></prod></vuln_soft></entry><entry CVSS_base_score="6.4" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="4.9" CVSS_score="6.4" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:P)" CVSS_version="2.0" modified="2007-01-10" name="CVE-2007-0159" published="2007-01-09" seq="2007-0159" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in the GeoIP_update_database_general function in libGeoIP/GeoIPUpdate.c in GeoIP 1.4.0 allows remote malicious update servers (possibly only update.maxmind.com) to overwrite arbitrary files via a .. (dot dot) in the database filename, which is returned by a request to app/update_getfilename.</descript></desc><loss_types><avail/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref patch="1" source="" url="http://arctic.org/~dean/patches/GeoIP-1.4.0-update-vulnerability.patch"></ref><ref patch="1" source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2007:004">MDKSA-2007:004</ref><ref source="BID" url="http://www.securityfocus.com/bid/21959">21959</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0117">ADV-2007-0117</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0118">ADV-2007-0118</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31383">geoip-geoipupdate-directory-traversal(31383)</ref><ref source="UBUNTU" url="http://www.ubuntu.com/usn/usn-412-1">
USN-412-1</ref><ref source="SECUNIA" url="http://secunia.com/advisories/23880">
23880</ref><ref source="SECUNIA" url="http://secunia.com/advisories/23906">
23906</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:004">MDKSA-2007:004</ref></refs><vuln_soft><prod name="GeoIP" vendor="GeoIP"><vers num="1.4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-08-07" name="CVE-2007-0160" published="2007-01-09" seq="2007-0160" severity="High" type="CVE"><desc><descript source="cve">Stack-based buffer overflow in the LiveJournal support (hooks/ljhook.cc) in CenterICQ 4.9.11 through 4.21.0, when using unofficial LiveJournal servers, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code by adding the victim as a friend and using long (1) username and (2) real name strings.</descript></desc><sols><sol source="nvd">Failed exploitation attempts will likely result in a denial-of-service condition.</sol></sols><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/456255/100/0/threaded">20070107 TK53 Advisory #1: CenterICQ remote DoS buffer overflow in LiveJournal handling</ref><ref source="BID" url="http://www.securityfocus.com/bid/21932">21932</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31330">centericq-username-bo(31330)</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200701-20.xml">GLSA-200701-20</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0306">ADV-2007-0306</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1017545">1017545</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2129">2129</ref></refs><vuln_soft><prod name="CenterICQ" vendor="CenterICQ"><vers num="4.21"/><vers num="4.20"/><vers num="4.14"/><vers num="4.13"/><vers num="4.12"/><vers num="4.9.12"/><vers num="4.9.11"/></prod></vuln_soft></entry><entry CVSS_base_score="4.1" CVSS_exploit_subscore="2.7" CVSS_impact_subscore="6.4" CVSS_score="4.1" CVSS_vector="(AV:L/AC:M/Au:S/C:P/I:P/A:P)" CVSS_version="2.0" discovered="2006-05-29" modified="2007-01-10" name="CVE-2007-0161" published="2007-01-09" seq="2007-0161" severity="Medium" type="CVE"><desc><descript source="cve">The PML Driver HPZ12 (HPZipm12.exe) in the HP all-in-one drivers, as used by multiple HP products, uses insecure SERVICE_CHANGE_CONFIG DACL permissions, which allows local users to gain privileges and execute arbitrary programs, as demonstrated by modifying the binpath argument, a related issue to CVE-2006-0023.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/456259/100/0/threaded">20070108 HP Multiple Products PML Driver Local Privilege Escalation</ref><ref adv="1" source="" url="http://secway.org/advisory/AD20070108.txt"></ref><ref source="BID" url="http://www.securityfocus.com/bid/21935">21935</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0094">ADV-2007-0094</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/23663">23663</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31361">pml-driver-config-privilege-escalation(31361)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2128">2128</ref></refs><vuln_soft><prod name="PSC 2510 Photosmart Printer" vendor="HP"><vers num=""/></prod><prod name="PSC 1210 All-in-One" vendor="HP"><vers num=""/></prod><prod name="Officejet D" vendor="HP"><vers num=""/></prod><prod name="PSC 2100" vendor="HP"><vers num=""/></prod><prod name="Officejet 7100" vendor="HP"><vers num=""/></prod><prod name="PSC 1300" vendor="HP"><vers num=""/></prod><prod name="Officejet K" vendor="HP"><vers num=""/></prod><prod name="Officejet 4100" vendor="HP"><vers num=""/></prod><prod name="PSC 700" vendor="HP"><vers num=""/></prod><prod name="PSC 1200" vendor="HP"><vers num=""/></prod><prod name="Officejet 6100" vendor="HP"><vers num=""/></prod><prod name="Color LaserJet 4650" vendor="HP"><vers num=""/></prod><prod name="Officejet G" vendor="HP"><vers num=""/></prod><prod name="PSC 2400 Photosmart All-in-one" vendor="HP"><vers num=""/></prod><prod name="PSC 1100" vendor="HP"><vers num=""/></prod><prod name="PSC 2200" vendor="HP"><vers num=""/></prod><prod name="Officejet 5500" vendor="HP"><vers num=""/></prod><prod name="PSC 2500 Photosmart All-in-one" vendor="HP"><vers num=""/></prod><prod name="PML Driver HPZ12" vendor="HP"><vers num=""/></prod><prod name="PSC 900" vendor="HP"><vers num=""/></prod><prod name="Officejet 5100" vendor="HP"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="3.1" CVSS_impact_subscore="10.0" CVSS_score="6.8" CVSS_vector="(AV:L/AC:L/Au:S/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-01-10" name="CVE-2007-0162" published="2007-01-09" seq="2007-0162" severity="Medium" type="CVE"><desc><descript source="cve">Unsanity Application Enhancer (APE) 2.0.2 installs with insecure permissions for the (1) ApplicationEnhancer binary and the (2) /Library/Frameworks/ApplicationEnhancer.framework directory, which allows local users to gain privileges by modifying or replacing the binary or library files.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref adv="1" source="" url="http://landonf.bikemonkey.org/code/macosx/MOAB_Day_8.20070109002959.18582.timor.html"></ref><ref source="" url="http://projects.info-pull.com/moab/MOAB-08-01-2007.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/21951">21951</ref><ref source="SECUNIA" url="http://secunia.com/advisories/23649">23649</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31349">ape-appenhancer-privilege-escalation(31349)</ref></refs><vuln_soft><prod name="Application Enhancer" vendor="Unsanity"><vers num="2.0.2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.8" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.9" CVSS_score="7.8" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:N/A:N)" CVSS_version="2.0" modified="2007-01-10" name="CVE-2007-0163" published="2007-01-09" seq="2007-0163" severity="High" type="CVE"><desc><descript source="cve">SecureKit Steganography 1.7.1 and 1.8 embeds password information in the carrier file, which allows remote attackers to bypass authentication requirements and decrypt embedded steganography by replacing the last 20 bytes of the JPEG image with alternate password information.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/456283/100/0/threaded">20070106 Cracking Steganography Application in less than ONE minute</ref><ref adv="1" source="" url="http://homepage.mac.com/adonismac/Advisory/steg/steganography.html"></ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/23639">23639</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/456519/100/0/threaded">20070107 A Major design Bug in Steganography 1.7.x, 1.8 (latest) (Updated Version)</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31378">steganography-password-security-bypass(31378)</ref></refs><vuln_soft><prod name="SecureKit Steganography" vendor="SecureKit"><vers num="1.7.1"/><vers num="1.8"/></prod></vuln_soft></entry><entry CVSS_base_score="7.8" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.9" CVSS_score="7.8" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:N/A:N)" CVSS_version="2.0" modified="2007-01-10" name="CVE-2007-0164" published="2007-01-09" seq="2007-0164" severity="High" type="CVE"><desc><descript source="cve">Camouflage 1.2.1 embeds password information in the carrier file, which allows remote attackers to bypass authentication requirements and decrypt embedded steganography by replacing certain bytes of the JPEG image with alternate password information.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="" url="http://homepage.mac.com/adonismac/Advisory/steg/camouflage.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/21939">21939</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/23578">23578</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/456541/100/0/threaded">20070107 A Major design Bug in Camouflage 1.2.1 (latest)</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31375">camouflage-password-security-bypass(31375)</ref></refs><vuln_soft><prod name="Camouflage" vendor="Camouflage"><vers num="1.2.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.8" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.9" CVSS_score="7.8" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_version="2.0" modified="2007-01-10" name="CVE-2007-0165" published="2007-01-09" seq="2007-0165" severity="High" type="CVE"><desc><descript source="cve">Unspecified vulnerability in libnsl in Sun Solaris 8 and 9 allows remote attackers to cause a denial of service (crash) via malformed RPC requests that trigger a crash in rpcbind.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102713-1">102713</ref><ref source="BID" url="http://www.securityfocus.com/bid/21964">21964</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0110">ADV-2007-0110</ref><ref source="SECUNIA" url="http://secunia.com/advisories/23700">23700</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31366">solaris-rpcbind-dos(31366)</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1017492">1017492</ref><ref source="" url="http://support.avaya.com/elmodocs2/security/ASA-2007-036.htm"></ref><ref source="SECUNIA" url="http://secunia.com/advisories/24056">
24056</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2210">oval:org.mitre.oval:def:2210</ref></refs><vuln_soft><prod name="Solaris" vendor="Sun"><vers num="8.0"/><vers edition="SPARC" num="9.0"/></prod></vuln_soft></entry><entry CVSS_base_score="6.6" CVSS_exploit_subscore="2.7" CVSS_impact_subscore="10.0" CVSS_score="6.6" CVSS_vector="(AV:L/AC:M/Au:S/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-01-14" name="CVE-2007-0166" published="2007-01-11" seq="2007-0166" severity="Medium" type="CVE"><desc><descript source="cve">The jail rc.d script in FreeBSD 5.3 up to 6.2 does not verify pathnames when writing to /var/log/console.log during a jail start-up, or when file systems are mounted or unmounted, which allows local root users to overwrite arbitrary files, or mount/unmount files, outside of the jail via a symlink attack.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" source="FREEBSD" url="http://security.freebsd.org/advisories/FreeBSD-SA-07:01.jail.asc">FreeBSD-SA-07:01</ref><ref source="BID" url="http://www.securityfocus.com/bid/22011">22011</ref><ref source="SECUNIA" url="http://secunia.com/advisories/23730">23730</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1017505">1017505</ref></refs><vuln_soft><prod name="FreeBSD" vendor="FreeBSD"><vers num="6.2" prev="1"/><vers num="5.3"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-01-10" name="CVE-2007-0167" published="2007-01-09" seq="2007-0167" severity="High" type="CVE"><desc><descript source="cve">Multiple PHP file inclusion vulnerabilities in WGS-PPC (aka PPC Search Engine), as distributed with other aliases, allow remote attackers to execute arbitrary PHP code via a URL in the INC parameter in (1) config_admin.php, (2) config_main.php, (3) config_member.php, and (4) mysql_config.php in config/; (5) admin.php and (6) index.php in admini/; (7) paypalipn/ipnprocess.php; (8) index.php and (9) registration.php in members/; and (10) ppcbannerclick.php and (11) ppcclick.php in main/.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/456386/100/0/threaded">20070109 ppc engine Multiple file inclusion</ref><ref source="VIM" url="http://www.attrition.org/pipermail/vim/2007-January/001221.html">20070109 </ref><ref source="BID" url="http://www.securityfocus.com/bid/21961">21961</ref><ref source="" url="http://www.milw0rm.com/exploits/3104"></ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31355">demoppc-inc-file-include(31355)</ref><ref source="MILW0RM" url="http://milw0rm.com/exploits/3104">
3104</ref><ref source="OSVDB" url="http://www.osvdb.org/33444">
33444</ref><ref source="OSVDB" url="http://www.osvdb.org/33445">
33445</ref><ref source="OSVDB" url="http://www.osvdb.org/33446">
33446</ref><ref source="OSVDB" url="http://www.osvdb.org/33447">
33447</ref><ref source="OSVDB" url="http://www.osvdb.org/33448">
33448</ref><ref source="OSVDB" url="http://www.osvdb.org/33449">
33449</ref><ref source="OSVDB" url="http://www.osvdb.org/33450">
33450</ref><ref source="OSVDB" url="http://www.osvdb.org/33451">
33451</ref><ref source="OSVDB" url="http://www.osvdb.org/33452">
33452</ref><ref source="OSVDB" url="http://www.osvdb.org/33453">
33453</ref><ref source="OSVDB" url="http://www.osvdb.org/33454">
33454</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2134">2134</ref></refs><vuln_soft><prod name="WGS-PPC" vendor="WGS-PPC"><vers num=""/></prod><prod name="PPC Search Engine" vendor="PPC Search Engine"><vers num="1.61"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-01-14" name="CVE-2007-0168" published="2007-01-11" seq="2007-0168" severity="High" type="CVE"><desc><descript source="cve">The Tape Engine service in Computer Associates (CA) BrightStor ARCserve Backup 9.01 through 11.5, Enterprise Backup 10.5, and CA Server/Business Protection Suite r2 allows remote attackers to execute arbitrary code via certain data in opnum 0xBF in an RPC request, which is directly executed.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://www.zerodayinitiative.com/advisories/ZDI-07-002.html"></ref><ref patch="1" source="" url="http://supportconnectw.ca.com/public/storage/infodocs/babimpsec-notice.asp"></ref><ref source="" url="http://livesploit.com/advisories/LS-20061002.pdf"></ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/662400">VU#662400</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0154">ADV-2007-0154</ref><ref source="SECUNIA" url="http://secunia.com/advisories/23648">23648</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31442">brightstor-tapeengine-code-execution(31442)</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/456616/100/0/threaded">20070111 ZDI-07-002: CA BrightStor ARCserve Backup Tape Engine Code Execution Vulnerability</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1017506">1017506</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/456637">20070111 LS-20061002 - Computer Associates BrightStor ARCserve Backup Remote Code Execution Vulnerability</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/456711">20070111 [CAID 34955, 34956, 34957, 34958, 34959, 34817]: CA BrightStor ARCserve Backup Multiple Overflow Vulnerabilities</ref><ref source="" url="http://www.lssec.com/advisories/LS-20061002.pdf"></ref><ref source="BID" url="http://www.securityfocus.com/bid/22010">22010</ref></refs><vuln_soft><prod name="BrightStor ARCserve Backup" vendor="Computer Associates"><vers num="11.5" prev="1"/><vers num="9.01"/></prod><prod name="Server/Business Protection Suite" vendor="Computer Associates"><vers num="R2"/></prod><prod name="Enterprise Backup" vendor="Computer Associates"><vers num="10.5"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-01-18" name="CVE-2007-0169" published="2007-01-11" seq="2007-0169" severity="High" type="CVE"><desc><descript source="cve">Multiple buffer overflows in Computer Associates (CA) BrightStor ARCserve Backup 9.01 through 11.5, Enterprise Backup 10.5, and CA Server/Business Protection Suite r2 allow remote attackers to execute arbitrary code via RPC requests with crafted data for opnums (1) 0x2F and (2) 0x75 in the (a) Message Engine RPC service, or opnum (3) 0xCF in the Tape Engine service.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref source="" url="http://www.zerodayinitiative.com/advisories/ZDI-07-003.html"></ref><ref source="" url="http://www.zerodayinitiative.com/advisories/ZDI-07-004.html"></ref><ref patch="1" source="" url="http://supportconnectw.ca.com/public/storage/infodocs/babimpsec-notice.asp"></ref><ref source="IDEFENSE" url="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=467">20070111 Computer Associates BrightStor ARCserve Backup RPC Engine PFC Request Buffer Overflow Vulnerability</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/456619/100/0/threaded">20070111 ZDI-07-003: CA BrightStor ARCserve Backup Message Engine Buffer Overflow Vulnerability</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/180336">VU#180336</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0154">ADV-2007-0154</ref><ref source="SECUNIA" url="http://secunia.com/advisories/23648">23648</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/456618/100/0/threaded">20070111 ZDI-07-004: CA BrightStor ARCserve Backup Tape Engine Buffer Overflow Vulnerability</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/151032">VU#151032</ref><ref source="BID" url="http://www.securityfocus.com/bid/22005">22005</ref><ref source="BID" url="http://www.securityfocus.com/bid/22006">22006</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1017506">1017506</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31443">brightstor-messageengine-rpc-bo(31443)</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31433">brightstor-tapeengine-rpc-bo(31433)</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/456711">20070111 [CAID 34955, 34956, 34957, 34958, 34959, 34817]: CA BrightStor ARCserve Backup Multiple Overflow Vulnerabilities</ref></refs><vuln_soft><prod name="BrightStor ARCserve Backup" vendor="Computer Associates"><vers num="11.5" prev="1"/><vers num="9.01"/></prod><prod name="Server/Business Protection Suite" vendor="Computer Associates"><vers num="R2"/></prod><prod name="Enterprise Backup" vendor="Computer Associates"><vers num="10.5"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-01-11" name="CVE-2007-0170" published="2007-01-10" seq="2007-0170" severity="High" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in index.php in AllMyVisitors 0.4.0 allows remote attackers to execute arbitrary PHP code via a URL in the AMV_serverpath parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://www.milw0rm.com/exploits/3097"></ref><ref source="BID" url="http://www.securityfocus.com/bid/21917">21917</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31316">allmyvisitors-index-file-include(31316)</ref><ref source="MILW0RM" url="http://milw0rm.com/exploits/3097">

3097</ref></refs><vuln_soft><prod name="AllMyVisitors" vendor="AllMyPHP"><vers num="0.4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-01-11" name="CVE-2007-0171" published="2007-01-10" seq="2007-0171" severity="High" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in index.php in AllMyLinks 0.5.0 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the AML_opensite parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://www.milw0rm.com/exploits/3096"></ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/21916">21916</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/31314">allmylinks-index-file-include(31314)</ref><ref source="MILW0RM" url="http://milw0rm.com/exploits/3096">

3096</ref></refs><vuln_soft><prod name="AllMyLinks" vendor="Voice Of Web"><vers num="0.5"/><vers num="0.4.9"/><vers num="0.4.4"/><vers num="0.4.3"/><vers num="0.4.1"/><vers num="0.4"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-01-11" name="CVE-2007-0172" published="2007-01-10" seq="2007-0172" severity="High" type="CVE"><desc><descript source="cve">Multiple PHP remote file inclusion vulnerabilities in AllMyGuests 0.3.0 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the AMG_serverpath parameter to (1) comments.php and (2) signin.php; and possibly via a URL in unspecified parameters to (3) include/submit.inc.php, (4) admin/index.php, (5) include/cm_submit.inc.php, and (6) index.php.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://www.milw0rm.com/exploits/3093"></ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/21918">21918</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/31310">allmyguests-multiple-file-include(31310)</ref><ref source="MILW0RM" url="http://milw0rm.com/exploits/3093">

3093</ref></refs><vuln_soft><prod name="AllMyGuests" vendor="Voice Of Web"><vers num="0.3" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-01-11" name="CVE-2007-0173" published="2007-01-10" seq="2007-0173" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in index.php in L2J Statistik Script 0.09 and earlier, when register_globals is enabled and magic_quotes is disabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the page parameter, as demonstrated by injecting PHP sequences into an Apache HTTP Server log file, which is then included by index.php.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://www.milw0rm.com/exploits/3091"></ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/21914">21914</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/31309">l2j-statistik-index-file-include(31309)</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0097">ADV-2007-0097</ref><ref source="MILW0RM" url="http://milw0rm.com/exploits/3091">

3091</ref></refs><vuln_soft><prod name="Statistik Script" vendor="L2J"><vers num="0.09"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-01-11" name="CVE-2007-0174" published="2007-01-10" seq="2007-0174" severity="High" type="CVE"><desc><descript source="cve">Multiple stack-based multiple buffer overflows in the BRWOSSRE2UC.dll ActiveX Control in Sina UC2006 and earlier allow remote attackers to execute arbitrary code via a long string in the (1) astrVerion parameter to the SendChatRoomOpt function or (2) the astrDownDir parameter to the SendDownLoadFile function.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref source="FULLDISC" url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=116832852700467&amp;w=2">20070109 Sina UC ActiveX Multiple Remote Stack Overflow</ref><ref adv="1" source="" url="http://secway.org/advisory/ad20070109EN.txt"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0093">ADV-2007-0093</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/23638">23638</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/456378/100/0/threaded">20070109 Sina UC ActiveX Multiple Remote Stack Overflow</ref><ref source="BID" url="http://www.securityfocus.com/bid/21958">21958</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31348">sinauc-sendchatroomopt-bo(31348)</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31350">sinauc-senddownloadfile-bo(31350)</ref></refs><vuln_soft><prod name="Sina" vendor="Sina"><vers num="UC2006"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" modified="2008-06-05" name="CVE-2007-0175" published="2007-01-10" seq="2007-0175" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in htsrv/login.php in b2evolution 1.8.6 allows remote attackers to inject arbitrary web script or HTML via scriptable attributes in the redirect_to parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/23656">23656</ref><ref source="BID" url="http://www.securityfocus.com/bid/21953">21953</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31368">b2evolution-login-xss(31368)</ref><ref source="" url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=410568"></ref><ref source="DEBIAN" url="http://www.debian.org/security/2008/dsa-1568">DSA-1568</ref><ref source="SECUNIA" url="http://secunia.com/advisories/30093">30093</ref></refs><vuln_soft><prod name="b2evolution" vendor="b2evolution"><vers num="1.8.6"/><vers num="1.8.5"/><vers num="1.8.2"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-01-11" name="CVE-2007-0176" published="2007-01-10" seq="2007-0176" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in search/advanced_search.php in GForge 4.5.11 allows remote attackers to inject arbitrary web script or HTML via the words parameter.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/456296/100/0/threaded">20070108 GForge Cross Site Scripting vulnerability</ref><ref adv="1" source="" url="http://www.eazel.es/advisory006-gforge-cross-site-scripting-vulnerability.html"></ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/21946">21946</ref><ref adv="1" source="SECTRACK" url="http://securitytracker.com/id?1017482">1017482</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/23675">23675</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31346">gforge-words-xss(31346)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2133">2133</ref><ref source="DEBIAN" url="http://www.debian.org/security/2008/dsa-1475">DSA-1475</ref><ref source="SECUNIA" url="http://secunia.com/advisories/28598">28598</ref></refs><vuln_soft><prod name="GForge" vendor="GForge"><vers num="4.5.11"/></prod></vuln_soft></entry><entry CVSS_base_score="5.1" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="6.4" CVSS_score="5.1" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-01-11" name="CVE-2007-0177" published="2007-01-10" seq="2007-0177" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in the AJAX module in MediaWiki before 1.6.9, 1.7 before 1.7.2, 1.8 before 1.8.3, and 1.9 before 1.9.0rc2, when wgUseAjax is enabled, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="" url="http://sourceforge.net/forum/forum.php?forum_id=652721"></ref><ref adv="1" patch="1" source="" url="http://svn.wikimedia.org/svnroot/mediawiki/tags/REL1_6_9/phase3/RELEASE-NOTES"></ref><ref adv="1" patch="1" source="" url="http://svn.wikimedia.org/svnroot/mediawiki/tags/REL1_7_2/phase3/RELEASE-NOTES"></ref><ref adv="1" patch="1" source="" url="http://svn.wikimedia.org/svnroot/mediawiki/tags/REL1_8_3/phase3/RELEASE-NOTES"></ref><ref adv="1" patch="1" source="" url="http://svn.wikimedia.org/svnroot/mediawiki/tags/REL1_9_0RC2/phase3/RELEASE-NOTES"></ref><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/21956">21956</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0096">ADV-2007-0096</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/23647">23647</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31359">mediawiki-ajax-unspecified-xss(31359)</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2007_6_sr.html">
SUSE-SR:2007:006</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24889">
24889</ref></refs><vuln_soft><prod name="MediaWiki" vendor="MediaWiki"><vers num="1.6.6"/><vers num="1.6.5 r14348"/><vers num="1.6.5"/><vers num="1.6.4"/><vers num="1.6.3"/><vers num="1.6.2"/><vers num="1.6.1"/><vers num="1.6.0"/><vers num="1.7.1"/><vers num="1.7.0"/><vers num="1.8.2"/><vers num="1.8.1"/><vers num="1.8.0"/><vers num="1.9.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-01-11" name="CVE-2007-0178" published="2007-01-10" seq="2007-0178" severity="High" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in info.php in Easy Banner Pro 2.8 allows remote attackers to execute arbitrary PHP code via a URL in the s[phppath] parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/456404/100/0/threaded">20070108 Easy Banner Pro Version 2.8 &lt;= Remote File Inclusion</ref><ref source="BID" url="http://www.securityfocus.com/bid/21967">21967</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31374">easybannerpro-info-file-include(31374)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2132">2132</ref></refs><vuln_soft><prod name="Easy Banner Pro" vendor="PHP Web Scripts"><vers num="2.8"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-01-11" name="CVE-2007-0179" published="2007-01-10" seq="2007-0179" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in comment.php in PHPKIT 1.6.1 R2 allows remote attackers to execute arbitrary SQL commands via the subid parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/456384/100/0/threaded">20070109 Re: PHPKit 1.6.1 RC2 (faq/faq.php) Remote SQL Injection Exploit</ref><ref source="BID" url="http://www.securityfocus.com/bid/21962">21962</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2131">2131</ref></refs><vuln_soft><prod name="PHPKIT" vendor="PHPKIT"><vers edition="RC2" num="1.6.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="10.0" CVSS_score="7.6" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-01-11" name="CVE-2007-0180" published="2007-01-10" seq="2007-0180" severity="High" type="CVE"><desc><descript source="cve">Stack-based buffer overflow in EF Commander 5.75 allows user-assisted attackers to execute arbitrary code via a crafted ISO file containing a file within several nested directories, which produces a large filename that triggers the overflow.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" patch="1" source="" url="http://vuln.sg/efcommander575-en.html"></ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/23659">23659</ref><ref source="BID" url="http://www.securityfocus.com/bid/21969">21969</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31365">efcommander-iso-pathname-bo(31365)</ref></refs><vuln_soft><prod name="EF Commander" vendor="EF Software"><vers num="5.75"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-01-11" name="CVE-2007-0181" published="2007-01-10" seq="2007-0181" severity="High" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in include/common_function.php in magic photo storage website allows remote attackers to execute arbitrary PHP code via a URL in the _config[site_path] parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/456264/100/0/threaded">20070108 magic photo storage website Remote File Inclusion</ref><ref source="" url="http://milw0rm.com/exploits/3100"></ref><ref source="BID" url="http://www.securityfocus.com/bid/21965">21965</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0136">ADV-2007-0136</ref><ref source="SECUNIA" url="http://secunia.com/advisories/23687">23687</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31347">magicphotostorage-config-file-include(31347)</ref></refs><vuln_soft><prod name="Magic Photo Storage Website" vendor="Scriptaty"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-01-14" name="CVE-2007-0182" published="2007-01-12" seq="2007-0182" severity="High" type="CVE"><desc><descript source="cve">Multiple PHP remote file inclusion vulnerabilities in magic photo storage website allow remote attackers to execute arbitrary PHP code via a URL in the _config[site_path] parameter to (1) admin_password.php, (2) add_welcome_text.php, (3) admin_email.php, (4) add_templates.php, (5) admin_paypal_email.php, (6) approve_member.php, (7) delete_member.php, (8) index.php, (9) list_members.php, (10) membership_pricing.php, or (11) send_email.php in admin/; (12) config.php or (13) db_config.php in include/; or (14) add_category.php, (15) add_news.php, (16) change_catalog_template.php, (17) couple_milestone.php, (18) couple_profile.php, (19) delete_category.php, (20) index.php, (21) login.php, (22) logout.php, (23) register.php, (24) upload_photo.php, (25) user_catelog_password.php, (26) user_email.php, (27) user_extend.php, or (28) user_membership_password.php in user/.  NOTE: the include/common_function.php vector is already covered by another candidate from the same date.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/456389/100/0/threaded">20070108 magic photo storage website Multiple Remote File Inclusion</ref><ref source="BID" url="http://www.securityfocus.com/bid/21965">21965</ref><ref source="OSVDB" url="http://www.osvdb.org/32668">
32668</ref><ref source="OSVDB" url="http://www.osvdb.org/33411">
33411</ref><ref source="OSVDB" url="http://www.osvdb.org/33412">
33412</ref><ref source="OSVDB" url="http://www.osvdb.org/33413">
33413</ref><ref source="OSVDB" url="http://www.osvdb.org/33414">
33414</ref><ref source="OSVDB" url="http://www.osvdb.org/33415">
33415</ref><ref source="OSVDB" url="http://www.osvdb.org/33416">
33416</ref><ref source="OSVDB" url="http://www.osvdb.org/33417">
33417</ref><ref source="OSVDB" url="http://www.osvdb.org/33418">
33418</ref><ref source="OSVDB" url="http://www.osvdb.org/33419">
33419</ref><ref source="OSVDB" url="http://www.osvdb.org/33420">
33420</ref><ref source="OSVDB" url="http://www.osvdb.org/33421">
33421</ref><ref source="OSVDB" url="http://www.osvdb.org/33422">
33422</ref><ref source="OSVDB" url="http://www.osvdb.org/33423">
33423</ref><ref source="OSVDB" url="http://www.osvdb.org/33425">
33425</ref><ref source="OSVDB" url="http://www.osvdb.org/33426">
33426</ref><ref source="OSVDB" url="http://www.osvdb.org/33427">
33427</ref><ref source="OSVDB" url="http://www.osvdb.org/33428">
33428</ref><ref source="OSVDB" url="http://www.osvdb.org/33429">
33429</ref><ref source="OSVDB" url="http://www.osvdb.org/33430">
33430</ref><ref source="OSVDB" url="http://www.osvdb.org/33431">
33431</ref><ref source="OSVDB" url="http://www.osvdb.org/33433">
33433</ref><ref source="OSVDB" url="http://www.osvdb.org/33435">
33435</ref><ref source="OSVDB" url="http://www.osvdb.org/33436">
33436</ref><ref source="OSVDB" url="http://www.osvdb.org/33437">
33437</ref><ref source="OSVDB" url="http://www.osvdb.org/33438">
33438</ref><ref source="OSVDB" url="http://www.osvdb.org/33439">
33439</ref><ref source="OSVDB" url="http://www.osvdb.org/33432">
33432</ref><ref source="OSVDB" url="http://www.osvdb.org/33434">
33434</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2136">2136</ref></refs><vuln_soft><prod name="Magic Photo Storage Website" vendor="Scriptaty"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-01-14" name="CVE-2007-0183" published="2007-01-12" seq="2007-0183" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in /search in iPlanet Web Server 4.x allows remote attackers to inject arbitrary web script or HTML via the NS-max-records parameter.  NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/21977">21977</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/23605">23605</ref></refs><vuln_soft><prod name="iPlanet Web Server" vendor="Sun"><vers edition="Enterprise" num="4.1 SP9"/><vers num="4.1 SP9"/><vers edition="Enterprise" num="4.1 SP8"/><vers num="4.1 SP8"/><vers edition="Enterprise" num="4.1 SP7"/><vers num="4.1 SP7"/><vers edition="Enterprise" num="4.1 SP6"/><vers num="4.1 SP6"/><vers edition="Enterprise" num="4.1 SP5"/><vers num="4.1 SP5"/><vers edition="Enterprise" num="4.1 SP4"/><vers num="4.1 SP4"/><vers edition="Enterprise" num="4.1 SP3"/><vers num="4.1 SP3"/><vers edition="Enterprise" num="4.1 SP2"/><vers num="4.1 SP2"/><vers edition="Enterprise" num="4.1 SP10"/><vers num="4.1 SP10"/><vers edition="Enterprise" num="4.1 SP1"/><vers num="4.1 SP1"/><vers num="4.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-01-14" name="CVE-2007-0184" published="2007-01-12" seq="2007-0184" severity="High" type="CVE"><desc><descript source="cve">Getahead Direct Web Remoting (DWR) before 1.1.4 allows attackers to obtain unauthorized access to public methods via a crafted request that bypasses the include/exclude checks.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref source="" url="http://getahead.ltd.uk/dwr/changelog"></ref><ref source="BID" url="http://www.securityfocus.com/bid/21955">21955</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0095">ADV-2007-0095</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/23641">23641</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31377">dwr-include-exclude-security-bypass(31377)</ref></refs><vuln_soft><prod name="Direct Web Remoting" vendor="Getahead"><vers num="1.1.3" prev="1"/><vers num="1.1.2"/><vers num="1.1.1"/><vers num="1.1.0"/><vers num="1.0"/><vers num="0.9"/><vers num="0.8"/><vers num="0.7"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0" modified="2007-01-14" name="CVE-2007-0185" published="2007-01-12" seq="2007-0185" severity="Medium" type="CVE"><desc><descript source="cve">Getahead Direct Web Remoting (DWR) before 1.1.4 allows attackers to cause a denial of service (memory exhaustion and servlet outage) via unknown vectors related to a large number of calls in a batch.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref source="" url="http://getahead.ltd.uk/dwr/changelog"></ref><ref source="BID" url="http://www.securityfocus.com/bid/21955">21955</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0095">ADV-2007-0095</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/23641">23641</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31382">dwr-servlet-engine-dos(31382)</ref></refs><vuln_soft><prod name="Direct Web Remoting" vendor="Getahead"><vers num="1.1.3" prev="1"/><vers num="1.1.2"/><vers num="1.1.1"/><vers num="1.1.0"/><vers num="1.0"/><vers num="0.9"/><vers num="0.8"/><vers num="0.7"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-08-07" name="CVE-2007-0186" published="2007-01-12" seq="2007-0186" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in F5 FirePass SSL VPN allow remote attackers to inject arbitrary web script or HTML via (1) the xcho parameter to my.logon.php3; the (2) topblue, (3) midblue, (4) wtopblue, and certain other Custom color parameters in a per action to vdesk/admincon/index.php; the (5) h321, (6) h311, (7) h312, and certain other Front Door custom text color parameters in a per action to vdesk/admincon/index.php; the (8) ua parameter in a bro action to vdesk/admincon/index.php; the (9) app_param and (10) app_name parameters to webyfiers.php; (11) double eval functions; (12) JavaScript contained in an &lt;FP_DO_NOT_TOUCH&gt; element; and (13) the vhost parameter to my.activation.php.  NOTE: it is possible that this candidate overlaps CVE-2006-3550.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://www.mnin.org/advisories/2007_firepass.pdf"></ref><ref source="" url="https://tech.f5.com/home/solutions/sol6919.html"></ref><ref source="" url="https://tech.f5.com/home/solutions/sol6920.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/21957">21957</ref><ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2007-January/051651.html">20070106 NNL-Labs &amp; MNIN - F5 FirePass Security Advisory</ref><ref source="SECUNIA" url="http://secunia.com/advisories/23627">23627</ref><ref source="SECUNIA" url="http://secunia.com/advisories/23643">23643</ref><ref source="OSVDB" url="http://www.osvdb.org/32740">32740</ref><ref source="OSVDB" url="http://www.osvdb.org/32741">32741</ref><ref source="OSVDB" url="http://www.osvdb.org/32742">32742</ref><ref source="OSVDB" url="http://www.osvdb.org/32743">32743</ref><ref source="OSVDB" url="http://www.osvdb.org/32739">32739</ref><ref source="OSVDB" url="http://www.osvdb.org/32737">32737</ref><ref source="OSVDB" url="http://www.osvdb.org/32738">32738</ref></refs><vuln_soft><prod name="FirePass SSL VPN" vendor="F5"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-01-14" name="CVE-2007-0187" published="2007-01-12" seq="2007-0187" severity="High" type="CVE"><desc><descript source="cve">F5 FirePass 5.4 through 5.5.2 and 6.0 allows remote attackers to access restricted URLs via (1) a trailing null byte, (2) multiple leading slashes, (3) Unicode encoding, (4) URL-encoded directory traversal or same-directory characters, or (5) upper case letters in the domain name.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://www.mnin.org/advisories/2007_firepass.pdf"></ref><ref source="" url="https://tech.f5.com/home/solutions/sol6924.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/21957">21957</ref><ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2007-January/051651.html">20070106 NNL-Labs &amp; MNIN - F5 FirePass Security Advisory</ref><ref source="" url="https://tech.f5.com/home/solutions/sol6916.html"></ref><ref source="SECUNIA" url="http://secunia.com/advisories/23626">23626</ref><ref source="SECUNIA" url="http://secunia.com/advisories/23640">23640</ref></refs><vuln_soft><prod name="Firepass" vendor="F5"><vers num="5.4"/><vers num="5.4.1"/><vers num="5.4.2"/><vers num="5.4.3"/><vers num="5.4.4"/><vers num="5.4.5"/><vers num="5.4.6"/><vers num="5.4.7"/><vers num="5.4.8"/><vers num="5.4.9"/><vers num="5.5"/><vers num="5.5.1"/><vers num="5.5.2"/><vers num="6.0"/></prod></vuln_soft></entry><entry CVSS_base_score="6.5" CVSS_exploit_subscore="8.0" CVSS_impact_subscore="6.4" CVSS_score="6.5" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-01-14" name="CVE-2007-0188" published="2007-01-12" seq="2007-0188" severity="Medium" type="CVE"><desc><descript source="cve">F5 FirePass 5.4 through 5.5.1 does not properly enforce host access restrictions when a client uses a single integer (dword) representation of an IP address (&quot;dotless IP address&quot;), which allows remote authenticated users to connect to the FirePass administrator console and certain other network resources.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref source="" url="http://www.mnin.org/advisories/2007_firepass.pdf"></ref><ref source="" url="https://tech.f5.com/home/solutions/sol6922.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/21957">21957</ref><ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2007-January/051651.html">20070106 NNL-Labs &amp; MNIN - F5 FirePass Security Advisory</ref><ref source="SECUNIA" url="http://secunia.com/advisories/23640">23640</ref><ref source="OSVDB" url="http://www.osvdb.org/32734">32734</ref></refs><vuln_soft><prod name="Firepass" vendor="F5"><vers num="5.4"/><vers num="5.4.1"/><vers num="5.4.2"/><vers num="5.4.3"/><vers num="5.4.4"/><vers num="5.4.5"/><vers num="5.4.6"/><vers num="5.4.7"/><vers num="5.4.8"/><vers num="5.4.9"/><vers num="5.5"/><vers num="5.5.1"/><vers num="5.5.2"/><vers num="6.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-01-14" name="CVE-2007-0189" published="2007-01-12" seq="2007-0189" severity="High" type="CVE"><desc><descript source="cve">** DISPUTED **  PHP remote file inclusion vulnerability in index.php in GeoBB Georgian Bulletin Board allows remote attackers to execute arbitrary PHP code via a URL in the action parameter.  NOTE: CVE disputes this issue, since GeoBB 1.0 sets $action to a whitelisted value.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/456251/100/0/threaded">20070107 GeoBB Georgian Bulletin Board Remote File Include Vuln.</ref><ref source="VIM" url="http://www.attrition.org/pipermail/vim/2007-January/001230.html">20070110 Dispute of GeoBB RFI</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31335">geobb-index-file-include(31335)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2141">2141</ref></refs><vuln_soft><prod name="Georgian Bulletin Board" vendor="GeoBB"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-01-14" name="CVE-2007-0190" published="2007-01-12" seq="2007-0190" severity="High" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in edit_address.php in edit-x ecommerce allows remote attackers to execute arbitrary PHP code via a URL in the include_dir parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/456439/100/0/threaded">20070109 edit-x ecommerce (include_dir) Remote File include</ref><ref source="BID" url="http://www.securityfocus.com/bid/21974">21974</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0158">ADV-2007-0158</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31384">editx-editaddress-file-include(31384)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2139">2139</ref></refs><vuln_soft><prod name="eCommerce" vendor="Edit-X"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-01-14" name="CVE-2007-0191" published="2007-01-12" seq="2007-0191" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in admin.php in MKPortal allows remote attackers to inject arbitrary web script or HTML via two certain fields in a contents_new operation in the ad_contents section.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/456042/100/100/threaded">20070105 MkPortal Admin XSS</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31304">mkportal-admin-xss(31304)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2138">2138</ref></refs><vuln_soft><prod name="MKPortal" vendor="MKPortal"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-01-14" name="CVE-2007-0192" published="2007-01-12" seq="2007-0192" severity="High" type="CVE"><desc><descript source="cve">Cross-site request forgery (CSRF) vulnerability in the save_main operation in the ad_perms section in admin.php in MKPortal allows remote attackers to modify privilege settings, as demonstrated using a getURL of admin.php within a .swf file contained in an IFRAME element, aka the &quot;All Guests are Admin&quot; attack.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/455894/100/100/threaded">20070104 MkPortal </ref><ref source="SREASON" url="http://securityreason.com/securityalert/2137">2137</ref></refs><vuln_soft><prod name="MKPortal" vendor="MKPortal"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-01-14" name="CVE-2007-0193" published="2007-01-12" seq="2007-0193" severity="High" type="CVE"><desc><descript source="cve">FON La Fonera routers do not properly limit DNS service access by unauthenticated clients, which allows remote attackers to tunnel traffic via DNS requests for hosts that should not be accessible before authentication.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/><design/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/456128/100/0/threaded">20070106 FON Router allows anonymous web access</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/456344/100/0/threaded">20070107 Re: FON Router allows anonymous web access</ref></refs><vuln_soft><prod name="La Fonera" vendor="FON"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.8" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.9" CVSS_score="7.8" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:N/A:N)" CVSS_version="2.0" modified="2007-01-13" name="CVE-2007-0194" published="2007-01-12" seq="2007-0194" severity="High" type="CVE"><desc><descript source="cve">admin.php in MKPortal M1.1 RC1 allows remote attackers to obtain sensitive information via a direct request with an MK_PATH=1 query string, which reveals the path in an error message.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/456257/100/0/threaded">20070108 MKPortal Full Path Disclosure</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31333">mkportal-admin-path-disclosure(31333)</ref></refs><vuln_soft><prod name="MKPortal" vendor="MKPortal"><vers num="1.1 RC1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0" modified="2007-01-13" name="CVE-2007-0195" published="2007-01-12" seq="2007-0195" severity="Medium" type="CVE"><desc><descript source="cve">my.activation.php3 in F5 FirePass 5.4 through 5.5.1 and 6.0 displays different error messages for failed login attempts with a valid username than for those with an invalid username, which allows remote attackers to confirm the validity of an LDAP account.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref source="" url="http://www.mnin.org/advisories/2007_firepass.pdf"></ref><ref source="" url="https://tech.f5.com/home/solutions/sol6923.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/21957">21957</ref><ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2007-January/051651.html">20070106 NNL-Labs &amp; MNIN - F5 FirePass Security Advisory</ref><ref source="SECUNIA" url="http://secunia.com/advisories/23627">23627</ref><ref source="OSVDB" url="http://www.osvdb.org/32736">32736</ref></refs><vuln_soft><prod name="Firepass" vendor="F5"><vers num="5.4"/><vers num="5.4.1"/><vers num="5.4.2"/><vers num="5.4.3"/><vers num="5.4.4"/><vers num="5.4.5"/><vers num="5.4.6"/><vers num="5.4.7"/><vers num="5.4.8"/><vers num="5.4.9"/><vers num="5.5"/><vers num="5.5.1"/><vers num="6.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-01-15" name="CVE-2007-0196" published="2007-01-11" seq="2007-0196" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in admin_check_user.asp in Motionborg Web Real Estate 2.1 and earlier allows remote attackers to execute arbitrary SQL commands via the username field (txtUserName parameter) and possibly other parameters.  NOTE: some details were obtained from third party information.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://www.milw0rm.com/exploits/3105"></ref><ref source="BID" url="http://www.securityfocus.com/bid/21963">21963</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31360">motionborg-admincheckuser-sql-injection(31360)</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0143">ADV-2007-0143</ref><ref source="SECUNIA" url="http://secunia.com/advisories/23531">23531</ref><ref source="MILW0RM" url="http://milw0rm.com/exploits/3105">

3105</ref></refs><vuln_soft><prod name="Motionborg Web Real Estate" vendor="Motionborg"><vers num="2.1" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2008-04-01" name="CVE-2007-0197" published="2007-01-11" seq="2007-0197" severity="Medium" type="CVE"><desc><descript source="cve">Finder 10.4.6 on Apple Mac OS X 10.4.8 allows user-assisted remote attackers to cause a denial of service and possibly execute arbitrary code via a long volume name in a DMG disk image, which results in memory corruption.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><exception/></vuln_types><range><network/><user_init/></range><refs><ref source="" url="http://projects.info-pull.com/moab/MOAB-09-01-2007.html"></ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/456578/100/0/threaded">20070111 DMA[2007-0107a] OmniWeb Javascript Alert Format String Vulnerabiity and DMA[2007-0109a] Apple Finder Disk Image Volume Label Overflow / DoS</ref><ref source="" url="http://www.digitalmunition.com/DMA%5B2007-0109a%5D.txt"></ref><ref source="BID" url="http://www.securityfocus.com/bid/21980">21980</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0140">ADV-2007-0140</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31410">macos-finder-dos(31410)</ref><ref source="" url="http://docs.info.apple.com/article.html?artnum=305102"></ref><ref source="APPLE" url="http://lists.apple.com/archives/Security-announce/2007/Feb/msg00000.html">APPLE-SA-2007-02-15</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA07-047A.html">TA07-047A</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/240880">VU#240880</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017662">1017662</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24198">24198</ref><ref source="OSVDB" url="http://www.osvdb.org/32714">32714</ref></refs><vuln_soft><prod name="Finder" vendor="Apple"><vers num="10.4.6"/></prod><prod name="Mac OS X" vendor="Apple"><vers num="10.4.8"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0" modified="2007-01-14" name="CVE-2007-0198" published="2007-01-11" seq="2007-0198" severity="Medium" type="CVE"><desc><descript source="cve">The JTapi Gateway process in Cisco Unified Contact Center Enterprise, Unified Contact Center Hosted, IP Contact Center Enterprise, and Cisco IP Contact Center Hosted 5.0 through 7.1 allows remote attackers to cause a denial of service (repeated process restart) via a certain TCP session on the JTapi server port.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="CISCO" url="http://www.cisco.com/warp/public/707/cisco-sa-20070110-jtapi.shtml">20070110 Cisco Unified Contact Center and IP Contact Center JTapi Gateway Vulnerability</ref><ref source="BID" url="http://www.securityfocus.com/bid/21988">21988</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0138">ADV-2007-0138</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1017499">1017499</ref><ref source="SECUNIA" url="http://secunia.com/advisories/23710">23710</ref></refs><vuln_soft><prod name="IP Contact Center Hosted" vendor="Cisco"><vers num="7.1" prev="1"/><vers num="5.0"/></prod><prod name="Unified Contact Center Enterprise" vendor="Cisco"><vers num="7.1" prev="1"/><vers num="5.0"/></prod><prod name="IP Contact Center Enterprise" vendor="Cisco"><vers num="7.1" prev="1"/><vers num="5.0"/></prod><prod name="Unified Contact Center Hosted" vendor="Cisco"><vers num="7.1" prev="1"/><vers num="5.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0" modified="2007-01-11" name="CVE-2007-0199" published="2007-01-11" seq="2007-0199" severity="Medium" type="CVE"><desc><descript source="cve">The Data-link Switching (DLSw) feature in Cisco IOS 11.0 through 12.4 allows remote attackers to cause a denial of service (device reload) via &quot;an invalid value in a DLSw message... during the capabilities exchange.&quot;</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="CISCO" url="http://www.cisco.com/warp/public/707/cisco-sa-20070110-dlsw.shtml">20070110 DLSw Vulnerability</ref><ref source="BID" url="http://www.securityfocus.com/bid/21990">21990</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0139">ADV-2007-0139</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1017498">1017498</ref><ref source="SECUNIA" url="http://secunia.com/advisories/23697">23697</ref></refs><vuln_soft><prod name="IOS" vendor="Cisco"><vers num="12.4" prev="1"/><vers num="11.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-01-11" name="CVE-2007-0200" published="2007-01-11" seq="2007-0200" severity="High" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in template.php in Geoffrey Golliher Axiom Photo/News Gallery (axiompng) 0.8.6 allows remote attackers to execute arbitrary PHP code via a URL in the baseAxiomPath parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://www.milw0rm.com/exploits/3108"></ref><ref source="VIM" url="http://www.attrition.org/pipermail/vim/2007-January/001233.html">20070110 source verify - Axiom RFI</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0107">ADV-2007-0107</ref><ref source="BID" url="http://www.securityfocus.com/bid/21972">21972</ref><ref source="SECUNIA" url="http://secunia.com/advisories/23715">23715</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31372">axiom-template-file-include(31372)</ref><ref source="MILW0RM" url="http://milw0rm.com/exploits/3108">

3108</ref></refs><vuln_soft><prod name="Axiom Photo_News Gallery" vendor="Geoffrey Golliher"><vers num="0.8.6"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-01-14" name="CVE-2007-0201" published="2007-01-11" seq="2007-0201" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in the cmd_usr function in ftp-gw in TIS Internet Firewall Toolkit (FWTK) allows remote attackers to execute arbitrary code via a long destination hostname (dest).</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="" url="http://www.ranum.com/security/computer_security/editorials/codetools/"></ref><ref source="BID" url="http://www.securityfocus.com/bid/21960">21960</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1017481">1017481</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31363">tisfwtk-ftpgw-bo(31363)</ref></refs><vuln_soft><prod name="Internet Firewall Toolkit" vendor="TIS"><vers num="2.1" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-01-14" name="CVE-2007-0202" published="2007-01-11" seq="2007-0202" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in index.php in @lex Guestbook 4.0.2 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the lang parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/456218/100/0/threaded">20070107 @lex Guestbook &lt;= 4.0.2 Remote Command Execution Exploit</ref><ref source="" url="http://acid-root.new.fr/poc/20070107.txt"></ref><ref source="" url="http://www.milw0rm.com/exploits/3103"></ref><ref source="BID" url="http://www.securityfocus.com/bid/21926">21926</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/23637">23637</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0137">ADV-2007-0137</ref><ref source="MILW0RM" url="http://milw0rm.com/exploits/3103">
3103</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2135">2135</ref></refs><vuln_soft><prod name="alex guestbook" vendor="alexPHPTeam"><vers num="4.0.2"/><vers num="4.0.1"/><vers num="3.13"/><vers num="3.12"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-01-14" name="CVE-2007-0203" published="2007-01-11" seq="2007-0203" severity="High" type="CVE"><desc><descript source="cve">Multiple unspecified vulnerabilities in phpMyAdmin before 2.9.2-rc1 have unknown impact and attack vectors.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs><ref adv="1" patch="1" source="" url="http://www.phpmyadmin.net/home_page/downloads.php?relnotes=0"></ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/23702">23702</ref><ref source="BID" url="http://www.securityfocus.com/bid/21987">21987</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:199">MDKSA-2007:199</ref></refs><vuln_soft><prod name="phpMyAdmin" vendor="phpMyAdmin"><vers num="2.9.1.1" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-01-14" name="CVE-2007-0204" published="2007-01-11" seq="2007-0204" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin before 2.9.2-rc1 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.  NOTE: some of these details are obtained from third party information,</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="" url="http://www.phpmyadmin.net/home_page/downloads.php?relnotes=0"></ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0125">ADV-2007-0125</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/23702">23702</ref><ref source="BID" url="http://www.securityfocus.com/bid/21987">21987</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31387">phpmyadmin-unspecified-xss(31387)</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:199">MDKSA-2007:199</ref></refs><vuln_soft><prod name="phpMyAdmin" vendor="phpMyAdmin"><vers num="2.9.1.1" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2008-04-25" name="CVE-2007-0205" published="2007-01-11" seq="2007-0205" severity="High" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in admin/skins.php for @lex Guestbook 4.0.2 and earlier allows remote attackers to create files in arbitrary directories via &quot;..&quot; sequences in the (1) aj_skin and (2) skin_edit parameters.  NOTE: this can be leveraged for file inclusion by creating a skin file in the lang directory, then referencing that file via the lang parameter to index.php, which passes a sanity check in livre_include.php.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/456218/100/0/threaded">20070107 @lex Guestbook &lt;= 4.0.2 Remote Command Execution Exploit</ref><ref source="" url="http://acid-root.new.fr/poc/20070107.txt"></ref><ref source="" url="http://www.milw0rm.com/exploits/3103"></ref><ref source="BID" url="http://www.securityfocus.com/bid/21926">21926</ref><ref source="MILW0RM" url="http://milw0rm.com/exploits/3103">3103</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2135">2135</ref></refs><vuln_soft><prod name="alex guestbook" vendor="alexPHPTeam"><vers num="4.0.2"/><vers num="4.0.1"/><vers num="3.13"/><vers num="3.12"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0" modified="2007-01-14" name="CVE-2007-0206" published="2007-01-11" seq="2007-0206" severity="Medium" type="CVE"><desc><descript source="cve">Unspecified vulnerability in HP OpenView Network Node Manager (OV NNM) 6.20, 6.4x, 7.01, and 7.50 allows remote attackers to read arbitrary files via unknown vectors.</descript></desc><loss_types><conf/></loss_types><range><network/></range><refs><ref source="HP" url="http://www.securityfocus.com/archive/1/archive/1/456615/100/0/threaded">HPSBMA02175</ref><ref source="BID" url="http://www.securityfocus.com/bid/22009">22009</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1017503">1017503</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0153">
ADV-2007-0153</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2140">2140</ref></refs><vuln_soft><prod name="OpenView Network Node Manager" vendor="HP"><vers num="7.50"/><vers num="7.0.1"/><vers num="6.41"/><vers num="6.4"/><vers num="6.2"/><vers edition="Windows 2000 XP" num="7.50"/><vers edition="Solaris" num="7.50"/><vers edition="Linux" num="7.50"/><vers edition="HP_UX 11.X" num="7.50"/><vers edition="Windows 2000 XP" num="7.0.1"/><vers edition="Solaris" num="7.0.1"/><vers edition="Linux" num="7.0.1"/><vers edition="HP_UX 11.X" num="7.0.1"/><vers edition="Solaris" num="6.41"/><vers edition="Solaris" num="6.4"/><vers edition="NT 4.X Windows 2000" num="6.4"/><vers edition="HP_UX 11.X" num="6.4"/><vers edition="Solaris" num="6.2"/><vers edition="NT 4.X Windows 2000" num="6.2"/><vers edition="HP_UX 11.X" num="6.2"/><vers edition="HP_UX 10.X" num="6.2"/></prod></vuln_soft></entry><entry CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" CVSS_score="9.3" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-05-16" name="CVE-2007-0208" published="2007-02-13" seq="2007-0208" severity="High" type="CVE"><desc><descript source="cve">Microsoft Word in Office 2000 SP3, XP SP3, Office 2003 SP2, Works Suite 2004 to 2006, and Office 2004 for Mac does not correctly check the properties of certain documents and warn the user of macro content, which allows user-assisted remote attackers to execute arbitrary code.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><design/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" patch="1" source="MS" url="http://www.microsoft.com/technet/security/Bulletin/MS07-014.mspx">MS07-014</ref><ref source="BID" url="http://www.securityfocus.com/bid/22477">22477</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0583">ADV-2007-0583</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017639">1017639</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA07-044A.html">TA07-044A</ref><ref source="OSVDB" url="http://www.osvdb.org/34385">34385</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:700">oval:org.mitre.oval:def:700</ref></refs><vuln_soft><prod name="Office" vendor="Microsoft"><vers num="2000 SP3"/><vers num="2003 SP2"/><vers num="XP SP3"/><vers edition="Mac" num="2004"/></prod><prod name="Works Suite" vendor="Microsoft"><vers num="2004"/><vers num="2005"/><vers num="2006"/></prod><prod name="Word" vendor="Microsoft"><vers num="2000"/><vers num="2002"/><vers num="2003"/><vers num="2003 Viewer"/></prod></vuln_soft></entry><entry CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" CVSS_score="9.3" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-05-16" name="CVE-2007-0209" published="2007-02-13" seq="2007-0209" severity="High" type="CVE"><desc><descript source="cve">Microsoft Word in Office 2000 SP3, XP SP3, Office 2003 SP2, Works Suite 2004 to 2006, and Office 2004 for Mac allows user-assisted remote attackers to execute arbitrary code via a Word file with a malformed drawing object, which leads to memory corruption.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref source="MS" url="http://www.microsoft.com/technet/security/Bulletin/MS07-014.mspx">MS07-014</ref><ref source="BID" url="http://www.securityfocus.com/bid/22482">22482</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0583">ADV-2007-0583</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017639">1017639</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA07-044A.html">TA07-044A</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:187">oval:org.mitre.oval:def:187</ref></refs><vuln_soft><prod name="Office" vendor="Microsoft"><vers num="2000 SP3"/><vers num="2003 SP2"/><vers num="XP SP3"/><vers edition="Mac" num="2004"/></prod><prod name="Works Suite" vendor="Microsoft"><vers num="2004"/><vers num="2005"/><vers num="2006"/></prod><prod name="Word" vendor="Microsoft"><vers num="2000"/><vers num="2002"/><vers num="2003"/><vers num="2003 Viewer"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-02-16" name="CVE-2007-0210" published="2007-02-13" seq="2007-0210" severity="High" type="CVE"><desc><descript source="cve">The Window Image Acquisition (WIA) Service in Microsoft Windows XP SP2 allows local users to gain privileges via unspecified vectors involving an &quot;unchecked buffer,&quot; probably a buffer overflow.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref patch="1" source="MS" url="http://www.microsoft.com/technet/security/Bulletin/MS07-007.mspx">MS07-007</ref><ref source="BID" url="http://www.securityfocus.com/bid/22499">
22499</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0576">
ADV-2007-0576</ref><ref source="OSVDB" url="http://www.osvdb.org/31889">
31889</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017634">
1017634</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24132">
24132</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA07-044A.html">TA07-044A</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:186">oval:org.mitre.oval:def:186</ref></refs><vuln_soft><prod name="Windows XP" vendor="Microsoft"><vers edition="Tablet PC" num="SP2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-02-16" name="CVE-2007-0211" published="2007-02-13" seq="2007-0211" severity="High" type="CVE"><desc><descript source="cve">The hardware detection functionality in the Windows Shell in Microsoft Windows XP SP2 and Professional, and Server 2003 SP1 allows local users to gain privileges via an unvalidated parameter to a function related to the &quot;detection and registration of new hardware.&quot;</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input/></vuln_types><range><local/></range><refs><ref patch="1" source="MS" url="http://www.microsoft.com/technet/security/Bulletin/MS07-006.mspx">MS07-006</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/240796">
VU#240796</ref><ref source="BID" url="http://www.securityfocus.com/bid/22481">
22481</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0575">
ADV-2007-0575</ref><ref source="OSVDB" url="http://www.osvdb.org/31890">
31890</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017633">
1017633</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24126">
24126</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA07-044A.html">TA07-044A</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:224">oval:org.mitre.oval:def:224</ref></refs><vuln_soft><prod name="Windows XP" vendor="Microsoft"><vers edition="Tablet PC" num="SP2"/><vers edition="Gold" num="Professional"/></prod><prod name="Windows Server 2003" vendor="Microsoft"><vers num="SP1"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-05-09" name="CVE-2007-0213" published="2007-05-08" seq="2007-0213" severity="High" type="CVE"><desc><descript source="cve">Microsoft Exchange Server 2000 SP3, 2003 SP1 and SP2, and 2007 does not properly decode certain MIME encoded e-mails, which allows remote attackers to execute arbitrary code via a crafted base64-encoded MIME e-mail message.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input/><exception/></vuln_types><range><network/></range><refs><ref patch="1" source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms07-026.mspx">MS07-026</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/343145">
VU#343145</ref><ref source="BID" url="http://www.securityfocus.com/bid/23809">
23809</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1711">
ADV-2007-1711</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1018015">
1018015</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25183">
25183</ref><ref source="HP" url="http://www.securityfocus.com/archive/1/archive/1/468871/100/200/threaded">HPSBST02214</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA07-128A.html">TA07-128A</ref><ref source="OSVDB" url="http://www.osvdb.org/34391">34391</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1890">oval:org.mitre.oval:def:1890</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33889">exchange-mime-base64-code-execution(33889)</ref></refs><vuln_soft><prod name="exchange srv" vendor="Microsoft"><vers num="2000 SP3"/><vers num="2003 SP1"/><vers num="2003 SP2"/><vers num="2007"/></prod></vuln_soft></entry><entry CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" CVSS_score="9.3" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-05-16" name="CVE-2007-0214" published="2007-02-13" seq="2007-0214" severity="High" type="CVE"><desc><descript source="cve">The HTML Help ActiveX control (Hhctrl.ocx) in Microsoft Windows 2000 SP3, XP SP2 and Professional, 2003 SP1 allows remote attackers to execute arbitrary code via unspecified functions, related to uninitialized parameters.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><range><network/><user_init/></range><refs><ref patch="1" source="MS" url="http://www.microsoft.com/technet/security/Bulletin/MS07-008.mspx">MS07-008</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/563756">VU#563756</ref><ref source="BID" url="http://www.securityfocus.com/bid/22478">22478</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0577">ADV-2007-0577</ref><ref source="OSVDB" url="http://www.osvdb.org/31884">31884</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017635">1017635</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24136">24136</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA07-044A.html">TA07-044A</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:125">oval:org.mitre.oval:def:125</ref></refs><vuln_soft><prod name="Windows XP" vendor="Microsoft"><vers num="SP2"/><vers edition="64-bit" num="Professional"/></prod><prod name="Windows Server 2003" vendor="Microsoft"><vers num=""/><vers num="SP1"/><vers num="Itanium"/><vers edition="Itanium" num="SP1"/><vers num="64-bit"/></prod><prod name="Windows 2000" vendor="Microsoft"><vers num="SP4"/></prod></vuln_soft></entry><entry CVSS_base_score="7.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="10.0" CVSS_score="7.6" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-05-09" name="CVE-2007-0215" published="2007-05-08" seq="2007-0215" severity="High" type="CVE"><desc><descript source="cve">Stack-based buffer overflow in Microsoft Excel 2000 SP3, 2002 SP3, 2003 SP2, and 2003 Viewer allows user-assisted remote attackers to execute arbitrary code via a .XLS BIFF file with a malformed Named Graph record, which results in memory corruption.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/><user_init/></range><refs><ref patch="1" source="" url="http://www.zerodayinitiative.com/advisories/ZDI-07-026.html"></ref><ref patch="1" source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms07-023.mspx">MS07-023</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/467988/100/0/threaded">

20070508 ZDI-07-026: Microsoft Excel BIFF File Format Named Graph Record Parsing Stack Overflow Vulnerability</ref><ref source="BID" url="http://www.securityfocus.com/bid/23760">
23760</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1708">
ADV-2007-1708</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1018012">
1018012</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25150">
25150</ref><ref source="HP" url="http://www.securityfocus.com/archive/1/archive/1/468871/100/200/threaded">HPSBST02214</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA07-128A.html">TA07-128A</ref><ref source="OSVDB" url="http://www.osvdb.org/34393">34393</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1971">oval:org.mitre.oval:def:1971</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33913">excel-biff-file-bo(33913)</ref></refs><vuln_soft><prod name="Excel Viewer" vendor="Microsoft"><vers num="2003"/></prod><prod name="Office" vendor="Microsoft"><vers num="2000 SP3"/><vers num="XP SP3"/><vers num="2003 SP2"/><vers num="2007"/><vers edition="Mac" num="2004"/></prod><prod name="Excel" vendor="Microsoft"><vers num="2000"/><vers num="2002"/><vers num="2003"/><vers num="2007"/></prod></vuln_soft></entry><entry CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" CVSS_score="9.3" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2008-02-19" name="CVE-2007-0216" published="2008-02-12" seq="2007-0216" severity="High" type="CVE"><desc><descript source="cve">wkcvqd01.dll in Microsoft Works 6 File Converter, as used in Office 2003 SP2, Works 8.0, and Works Suite 2005, allows remote attackers to execute arbitrary code via a .wps file with crafted section length headers, aka &quot;Microsoft Works File Converter Input Validation Vulnerability.&quot;</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><range><network/><user_init/></range><refs><ref patch="1" source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms08-011.mspx">MS08-011</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA08-043C.html">TA08-043C</ref><ref source="BID" url="http://www.securityfocus.com/bid/27657">27657</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/0513/references">ADV-2008-0513</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1019386">1019386</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/28904">28904</ref><ref source="IDEFENSE" url="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=659">20080208 Microsoft Office Works Converter Heap Overflow Vulnerability</ref><ref source="HP" url="http://marc.info/?l=bugtraq&amp;m=120361015026386&amp;w=2">HPSBST02314</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5309">oval:org.mitre.oval:def:5309</ref></refs><vuln_soft><prod name="Office" vendor="Microsoft"><vers edition="sp2" num="2003"/><vers edition="sp3" num="2003"/></prod><prod name="Works Suite" vendor="Microsoft"><vers num="2005"/></prod><prod name="Works" vendor="Microsoft"><vers num="8.0"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-05-16" name="CVE-2007-0217" published="2007-02-13" seq="2007-0217" severity="High" type="CVE"><desc><descript source="cve">The wininet.dll FTP client code in Microsoft Internet Explorer 5.01 and 6 might allow remote attackers to execute arbitrary code via an FTP server response of a specific length that causes a terminating null byte to be written outside of a buffer, which causes heap corruption.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref patch="1" source="MS" url="http://www.microsoft.com/technet/security/Bulletin/MS07-016.mspx">MS07-016</ref><ref source="IDEFENSE" url="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=473">20070213 Microsoft &apos;wininet.dll&apos; FTP Reply Null Termination Heap Corruption Vulnerability</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/613564">VU#613564</ref><ref source="BID" url="http://www.securityfocus.com/bid/22489">22489</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0584">ADV-2007-0584</ref><ref source="OSVDB" url="http://www.osvdb.org/31892">31892</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017642">1017642</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24156">24156</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/462303/100/0/threaded">20070309 MS07-016 FTP Response DOS PoC</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA07-044A.html">TA07-044A</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1141">oval:org.mitre.oval:def:1141</ref></refs><vuln_soft><prod name="Internet Explorer" vendor="Microsoft"><vers num="5.01 SP4"/><vers num="6.0 SP1"/><vers num="6.0"/></prod></vuln_soft></entry><entry CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" CVSS_score="9.3" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-12-27" name="CVE-2007-0218" published="2007-06-12" seq="2007-0218" severity="High" type="CVE"><desc><descript source="cve">Microsoft Internet Explorer 5.01 and 6 allows remote attackers to execute arbitrary code by instantiating certain COM objects from Urlmon.dll, which triggers memory corruption during a call to the IObjectSafety function.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input bound="1"/><exception/></vuln_types><range><network/><user_init/></range><refs><ref patch="1" source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms07-033.mspx">MS07-033</ref><ref source="IDEFENSE" url="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=542">20070612 Microsoft License Manager and urlmon.dll COM Object Interaction Invalid Memory Access Vulnerability</ref><ref source="HP" url="http://www.securityfocus.com/archive/1/archive/1/471947/100/0/threaded">HPSBST02231</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA07-163A.html">TA07-163A</ref><ref source="BID" url="http://www.securityfocus.com/bid/24372">24372</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/2153">ADV-2007-2153</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1084">oval:org.mitre.oval:def:1084</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1018235">1018235</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/25627">25627</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32106">webbrowser-object-code-execution(32106)</ref></refs><vuln_soft><prod name="Internet Explorer" vendor="Microsoft"><vers num="5.01 SP4"/><vers num="6 SP1"/><vers num="6"/><vers num="7.0"/><vers num="6"/><vers num="7.0"/><vers num="7.0"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-05-16" name="CVE-2007-0219" published="2007-02-13" seq="2007-0219" severity="High" type="CVE"><desc><descript source="cve">Microsoft Internet Explorer 5.01, 6, and 7 uses certain COM objects from (1) Msb1fren.dll, (2) Htmlmm.ocx, and (3) Blnmgrps.dll as ActiveX controls, which allows remote attackers to execute arbitrary code via unspecified vectors, a different issue than CVE-2006-4697.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><range><network/></range><refs><ref patch="1" source="MS" url="http://www.microsoft.com/technet/security/Bulletin/MS07-016.mspx">MS07-016</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/771788">VU#771788</ref><ref source="BID" url="http://www.securityfocus.com/bid/22504">22504</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0584">ADV-2007-0584</ref><ref source="OSVDB" url="http://www.osvdb.org/31893">31893</ref><ref source="OSVDB" url="http://www.osvdb.org/31894">31894</ref><ref source="OSVDB" url="http://www.osvdb.org/31895">31895</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017643">1017643</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24156">24156</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32427">ie-com-activex-code-execution(32427)</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA07-044A.html">TA07-044A</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:257">oval:org.mitre.oval:def:257</ref></refs><vuln_soft><prod name="Internet Explorer" vendor="Microsoft"><vers num="5.01 SP4"/><vers num="6.0 SP1"/><vers num="6.0"/><vers num="7.0"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-05-09" name="CVE-2007-0220" published="2007-05-08" seq="2007-0220" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in Outlook Web Access (OWA) in Microsoft Exchange Server 2000 SP3, and 2003 SP1 and SP2 allows remote attackers to execute arbitrary scripts, spoof content, or obtain sensitive information via certain UTF-encoded, script-based e-mail attachments, involving an &quot;incorrectly handled UTF character set label&quot;.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/><exception/></vuln_types><range><network/></range><refs><ref patch="1" source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms07-026.mspx">MS07-026</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/124113">
VU#124113</ref><ref source="BID" url="http://www.securityfocus.com/bid/23806">
23806</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1711">
ADV-2007-1711</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1018015">
1018015</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25183">
25183</ref><ref source="HP" url="http://www.securityfocus.com/archive/1/archive/1/468871/100/200/threaded">HPSBST02214</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA07-128A.html">TA07-128A</ref><ref source="OSVDB" url="http://www.osvdb.org/34389">34389</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1371">oval:org.mitre.oval:def:1371</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33887">exchange-utf-xss(33887)</ref></refs><vuln_soft><prod name="exchange srv" vendor="Microsoft"><vers num="2000 SP3"/><vers num="2003 SP1"/><vers num="2003 SP2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.8" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.9" CVSS_score="7.8" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_version="2.0" modified="2007-08-02" name="CVE-2007-0221" published="2007-05-08" seq="2007-0221" severity="High" type="CVE"><desc><descript source="cve">Integer overflow in the IMAP (IMAP4) support in Microsoft Exchange Server 2000 SP3 allows remote attackers to cause a denial of service (service hang) via crafted literals in an IMAP command, aka the &quot;IMAP Literal Processing Vulnerability.&quot;</descript></desc><loss_types><avail/></loss_types><vuln_types><input/><exception/></vuln_types><range><network/></range><refs><ref patch="1" source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms07-026.mspx">MS07-026</ref><ref source="BID" url="http://www.securityfocus.com/bid/23810">23810</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1711">ADV-2007-1711</ref><ref patch="1" source="SECTRACK" url="http://www.securitytracker.com/id?1018015">1018015</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/25183">25183</ref><ref patch="1" source="IDEFENSE" url="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=526">20070508 Microsoft Exchange Server 2000 IMAP Literal Processing DoS Vulnerability</ref><ref source="HP" url="http://www.securityfocus.com/archive/1/archive/1/468871/100/200/threaded">HPSBST02214</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA07-128A.html">TA07-128A</ref><ref source="OSVDB" url="http://www.osvdb.org/34392">34392</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2054">oval:org.mitre.oval:def:2054</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33890">exchange-imap-command-dos(33890)</ref></refs><vuln_soft><prod name="exchange srv" vendor="Microsoft"><vers num="2000 SP3"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0" modified="2007-08-07" name="CVE-2007-0222" published="2007-01-16" seq="2007-0222" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in the EmChartBean server side component for Oracle Application Server 10g allows remote attackers to read arbitrary files via unknown vectors, probably &quot;\..&quot; sequences in the beanId parameter.  NOTE: this is likely a duplicate of another CVE that Oracle addressed in CPU Jan 2007, but due to lack of details by Oracle, it is unclear which BugID this issue is associated with, so the other CVE cannot be determined.  Possibilities include EM02 (CVE-2007-0292) or EM05 (CVE-2007-0293).</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref patch="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/457105/100/0/threaded">20070115 SYMSA-2007-001: Oracle Application Server 10g - Directory Traversal</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/22027">22027</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/23794">23794</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/458657/100/0/threaded">20070131 Oracle 10g R2 Enterprise Manager Directory Traversal</ref><ref source="" url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujan2007.html"></ref><ref source="SECTRACK" url="http://securitytracker.com/id?1017522">1017522</ref><ref source="BID" url="http://www.securityfocus.com/bid/22083">22083</ref></refs><vuln_soft><prod name="Oracle10g Application Server" vendor="Oracle"><vers num="10.1.3"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-01-15" name="CVE-2007-0223" published="2007-01-12" seq="2007-0223" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in shared/code/cp_functions_downloads.php in Nicola Asuni All In One Control Panel (AIOCP) before 1.3.009 allows remote attackers to execute arbitrary SQL commands via the download_category parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref patch="1" source="" url="http://sourceforge.net/project/shownotes.php?release_id=477845"></ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/23726">23726</ref></refs><vuln_soft><prod name="All In One Control Panel" vendor="Nicola Asuni"><vers num="1.3.008"/><vers num="1.3.007"/><vers num="1.3.006"/><vers num="1.3.005"/><vers num="1.3.004"/><vers num="1.3.003"/><vers num="1.3.002"/><vers num="1.3.001"/><vers num="1.3.000"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-01-15" name="CVE-2007-0224" published="2007-01-12" seq="2007-0224" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in shopgiftregsearch.asp in VP-ASP Shopping Cart 6.09 and earlier allows remote attackers to execute arbitrary SQL commands via the LoginLastname parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="" url="http://www.milw0rm.com/exploits/3115"></ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/23699">23699</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31447">vpasp-shopgift-sql-injection(31447)</ref><ref source="MILW0RM" url="http://milw0rm.com/exploits/3115">

3115</ref></refs><vuln_soft><prod name="VP-ASP" vendor="Virtual Programming"><vers num="6.09"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-01-15" name="CVE-2007-0225" published="2007-01-12" seq="2007-0225" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in shopcustadmin.asp in VP-ASP Shopping Cart 6.09 and earlier allows remote attackers to inject arbitrary web script or HTML via the msg parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://www.milw0rm.com/exploits/3115"></ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/23699">23699</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31449">vpasp-shopcustadmin-xss(31449)</ref><ref source="MILW0RM" url="http://milw0rm.com/exploits/3115">

3115</ref></refs><vuln_soft><prod name="VP-ASP" vendor="Virtual Programming"><vers num="6.09"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-01-15" name="CVE-2007-0226" published="2007-01-12" seq="2007-0226" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in wbsearch.aspx in uniForum 4 and earlier allows remote attackers to execute arbitrary SQL commands via the &quot;by User&quot; field (aka the TXbyuser parameter).</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://www.milw0rm.com/exploits/3106"></ref><ref source="BID" url="http://www.securityfocus.com/bid/21966">21966</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31362">uniforum-wbsearch-sql-injection(31362)</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/458060/100/0/threaded">

20070125 uniForum &lt;= v4 (wbsearch.aspx) Remote SQL Injection Vulnerability</ref><ref source="MILW0RM" url="http://milw0rm.com/exploits/3106">
3106</ref><ref source="SECUNIA" url="http://secunia.com/advisories/23827">
23827</ref></refs><vuln_soft><prod name="uniForum" vendor="uniForum"><vers num="4" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0" modified="2007-01-15" name="CVE-2007-0227" published="2007-01-12" seq="2007-0227" severity="Medium" type="CVE"><desc><descript source="cve">slocate 3.1 does not properly manage database entries that specify names of files in protected directories, which allows local users to obtain the names of private files.  NOTE: another researcher reports that the issue is not present in slocate 2.7.</descript></desc><loss_types><conf/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/456530/100/0/threaded">20070110 Re: slocate leaks filenames of protected directories</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/456489/100/0/threaded">20070110 slocate leaks filenames of protected directories</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/456593/100/0/threaded">20070111 Re: slocate leaks filenames of protected directories</ref><ref source="BID" url="http://www.securityfocus.com/bid/21989">21989</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/456739/100/0/threaded">20070112 Re: slocate leaks filenames of protected directories</ref><ref source="UBUNTU" url="http://www.ubuntu.com/usn/usn-425-1">
USN-425-1</ref></refs><vuln_soft><prod name="slocate" vendor="slocate"><vers num="3.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0" modified="2007-01-15" name="CVE-2007-0228" published="2007-01-12" seq="2007-0228" severity="Medium" type="CVE"><desc><descript source="cve">The DataCollector service in EIQ Networks Network Security Analyzer allows remote attackers to cause a denial of service (service crash) via a (1) &amp;CONNECTSERVER&amp; (2) &amp;ADDENTRY&amp; (3) &amp;FIN&amp; (4) &amp;START&amp; (5) &amp;LOGPATH&amp; (6) &amp;FWADELTA&amp; (7) &amp;FWALOG&amp; (8) &amp;SETSYNCHRONOUS&amp; (9) &amp;SETPRGFILE&amp;, or (10) &amp;SETREPLYPORT&amp; string to TCP port 10618, which triggers a NULL pointer dereference.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref source="FULLDISC" url="http://archives.neohapsis.com/archives/fulldisclosure/2007-01/0209.html">20070110 EIQ Networks Network Security Analyzer DoS Vulnerability</ref><ref source="BID" url="http://www.securityfocus.com/bid/21994">21994</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0147">ADV-2007-0147</ref><ref source="SECUNIA" url="http://secunia.com/advisories/23693">23693</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31428">eiq-datacollector-dos(31428)</ref></refs><vuln_soft><prod name="Enterprise Security Analyzer" vendor="eIQnetworks"><vers num="2.5"/><vers num="2.1"/><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-01-21" name="CVE-2007-0229" published="2007-01-12" seq="2007-0229" severity="High" type="CVE"><desc><descript source="cve">Integer overflow in the ffs_mountfs function in Mac OS X 10.4.8 and FreeBSD 6.1 allows local users to cause a denial of service (panic) and possibly gain privileges via a crafted DMG image that causes &quot;allocation of a negative size buffer&quot; leading to a heap-based buffer overflow, a related issue to CVE-2006-5679.  NOTE: a third party states that this issue does not cross privilege boundaries in FreeBSD because only root may mount a filesystem.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref source="" url="http://applefun.blogspot.com/2007/01/moab-10-01-2007-apple-dmg-ufs.html"></ref><ref source="" url="http://projects.info-pull.com/moab/MOAB-10-01-2007.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/21993">21993</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0141">ADV-2007-0141</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/23703">23703</ref><ref source="MLIST" url="http://lists.freebsd.org/pipermail/freebsd-security/2007-January/004218.html">[freebsd-security] 20070114 MOAB advisories</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31409">macos-ffsmountfs-bo(31409)</ref><ref source="" url="http://docs.info.apple.com/article.html?artnum=305214"></ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0930">
ADV-2007-0930</ref><ref source="OSVDB" url="http://www.osvdb.org/32684">
32684</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017751">
1017751</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24479">
24479</ref><ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2007/Mar/msg00002.html">APPLE-SA-2007-03-13</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA07-072A.html">TA07-072A</ref></refs><vuln_soft><prod name="FreeBSD" vendor="FreeBSD"><vers num="6.1"/></prod><prod name="Mac OS X Server" vendor="Apple"><vers num="10.4.8"/></prod><prod name="Mac OS X" vendor="Apple"><vers num="10.4.8"/></prod></vuln_soft></entry><entry modified="2007-01-15" name="CVE-2007-0230" published="2007-01-12" reject="1" seq="2007-0230" type="CVE"><desc><descript source="cve">** DISPUTED ** PHP remote file inclusion vulnerability in install.php in CS-Cart 1.3.3 allows remote attackers to execute arbitrary PHP code via a URL in the install_dir parameter.  NOTE: CVE and third parties dispute this vulnerability because install_dir is defined before use.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/456527/100/0/threaded">20070109 CS-Cart 1.3.3 (install.php) Remote File Include Vulnerability</ref><ref source="VIM" url="http://www.attrition.org/pipermail/vim/2007-January/001223.html">20070110 [bogus] [ahmed_labib_hilmy at yahoo.com: CS-Cart 1.3.3 (install.php) Remote File Include Vulnerability] (fwd)</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31408">cscart-install-file-include(31408)</ref></refs><vuln_soft><prod name="CS-Cart" vendor="CS-Cart"><vers num="1.3.3"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-01-15" name="CVE-2007-0231" published="2007-01-12" seq="2007-0231" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in Movable Type (MT) 3.33, when nofollow is disabled and unmoderated comments are enabled, allows remote attackers to inject arbitrary web script or HTML via the Comments field.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/><config/></vuln_types><range><network/></range><refs><ref adv="1" source="" url="http://golem.ph.utexas.edu/~distler/blog/archives/001102.html"></ref><ref adv="1" source="" url="http://www.zackvision.com/weblog/2007/01/movabletype-security-bug.html"></ref><ref source="SECUNIA" url="http://secunia.com/advisories/23669">23669</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0142">ADV-2007-0142</ref></refs><vuln_soft><prod name="Movable Type" vendor="Six Apart"><vers num="3.33"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-01-15" name="CVE-2007-0232" published="2007-01-12" seq="2007-0232" severity="High" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in routines/fieldValidation.php in Jshop Server 1.3 allows remote attackers to execute arbitrary PHP code via a URL in the jssShopFileSystem parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://www.milw0rm.com/exploits/3113"></ref><ref source="BID" url="http://www.securityfocus.com/bid/21995">21995</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/456591/100/0/threaded">20070110 Jshop Server 1.3</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31425">jshop-fieldvalidation-file-include(31425)</ref><ref source="MILW0RM" url="http://milw0rm.com/exploits/3113">
3113</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2146">2146</ref></refs><vuln_soft><prod name="JShop Server" vendor="JShop E-Commerce"><vers num="1.3"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-01-15" name="CVE-2007-0233" published="2007-01-12" seq="2007-0233" severity="High" type="CVE"><desc><descript source="cve">wp-trackback.php in WordPress 2.0.6 and earlier does not properly unset variables when the input data includes a numeric parameter with a value matching an alphanumeric parameter&apos;s hash value, which allows remote attackers to execute arbitrary SQL commands via the tb_id parameter.  NOTE: it could be argued that this vulnerability is due to a bug in the unset PHP command (CVE-2006-3017) and the proper fix should be in PHP; if so, then this should not be treated as a vulnerability in WordPress.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/><design/></vuln_types><range><network/></range><refs><ref source="" url="http://www.milw0rm.com/exploits/3109"></ref><ref source="BID" url="http://www.securityfocus.com/bid/21983">21983</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31385">wordpress-tbid-sql-injection(31385)</ref><ref source="MILW0RM" url="http://milw0rm.com/exploits/3109">

3109</ref></refs><vuln_soft><prod name="Wordpress" vendor="WordPress"><vers num="(B2) 0.6.2.1"/><vers num="(B2) 0.6.2"/><vers num="2.0.6"/><vers num="2.0.5"/><vers num="2.0.4"/><vers num="2.0.3"/><vers num="2.0.2"/><vers num="2.0.1"/><vers num="2.0"/><vers num="1.5.2"/><vers num="1.5.1.3"/><vers num="1.5.1.2"/><vers num="1.5.1"/><vers num="1.5"/><vers num="1.2.2"/><vers num="1.2.1"/><vers num="1.2"/><vers num="0.71"/><vers num="0.7"/></prod></vuln_soft></entry><entry modified="2007-01-19" name="CVE-2007-0234" published="2007-01-16" reject="1" seq="2007-0234" type="CVE"><desc><descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2007-0243.  Reason: This candidate is a duplicate of CVE-2007-0243.  Notes: All CVE users should reference CVE-2007-0243 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/457159/100/0/threaded">20070117 ZDI-07-005: Sun Microsystems Java GIF File Parsing Memory Corruption Vulnerability</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/388289">VU#388289</ref><ref source="BID" url="http://www.securityfocus.com/bid/22085">22085</ref></refs><vuln_soft><prod name="JRE" vendor="Sun"><vers num="1.4.2_21" prev="1"/><vers num="1.3.1_18" prev="1"/></prod><prod name="JDK" vendor="Sun"><vers num="5.0 Update9" prev="1"/></prod><prod name="SDK" vendor="Sun"><vers num="1.4.2_12" prev="1"/><vers num="1.3.1_18" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="3.7" CVSS_exploit_subscore="1.9" CVSS_impact_subscore="6.4" CVSS_score="3.7" CVSS_vector="(AV:L/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-10-26" name="CVE-2007-0235" published="2007-01-16" seq="2007-0235" severity="Low" type="CVE"><desc><descript source="cve">Stack-based buffer overflow in the glibtop_get_proc_map_s function in libgtop before 2.14.6 (libgtop2) allows local users to cause a denial of service (crash) and possibly execute arbitrary code via a process with a long filename that is mapped in its address space, which triggers the overflow in gnome-system-monitor.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref source="" url="https://launchpad.net/bugs/79206"></ref><ref source="" url="http://bugzilla.gnome.org/show_bug.cgi?id=396477"></ref><ref source="" url="http://ftp.gnome.org/pub/gnome/sources/libgtop/2.14/libgtop-2.14.6.news"></ref><ref source="UBUNTU" url="http://www.ubuntu.com/usn/usn-407-1">USN-407-1</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0185">ADV-2007-0185</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0187">ADV-2007-0187</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/23736">23736</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/23777">23777</ref><ref source="" url="https://issues.rpath.com/browse/RPL-972"></ref><ref source="DEBIAN" url="http://www.debian.org/security/2007/dsa-1255">DSA-1255</ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200701-17.xml">GLSA-200701-17</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:023">MDKSA-2007:023</ref><ref source="BID" url="http://www.securityfocus.com/bid/22054">22054</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/23814">23814</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/23840">23840</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/23872">23872</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24015">24015</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31522">libgtop2-glibtopbo(31522)</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2007-0765.html">RHSA-2007:0765</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1018526">1018526</ref><ref source="SECUNIA" url="http://secunia.com/advisories/26367">26367</ref></refs><vuln_soft><prod name="libgtop" vendor="libgtop"><vers num="2.14.5" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2008-02-26" name="CVE-2007-0236" published="2007-01-16" seq="2007-0236" severity="High" type="CVE"><desc><descript source="cve">Double free vulnerability in the _ATPsndrsp function in Apple Mac OS X 10.4.8, and possibly other versions, allows remote attackers to cause a denial of service (kernel panic) and possibly execute arbitrary code via a crafted AppleTalk request that triggers a heap-based buffer overflow.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref source="" url="http://projects.info-pull.com/moab/MOAB-14-01-2007.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/22041">22041</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0191">ADV-2007-0191</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1017513">1017513</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/23708">23708</ref><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3130">3130</ref><ref source="" url="http://docs.info.apple.com/article.html?artnum=305214"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0930">ADV-2007-0930</ref><ref source="OSVDB" url="http://www.osvdb.org/32687">32687</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017751">1017751</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24479">24479</ref><ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2007/Mar/msg00002.html">APPLE-SA-2007-03-13</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA07-072A.html">TA07-072A</ref></refs><vuln_soft><prod name="Mac OS X" vendor="Apple"><vers num="10.4.8"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-03-20" name="CVE-2007-0237" published="2007-03-19" seq="2007-0237" severity="Medium" type="CVE"><desc><descript source="cve">The ndeb-binary feature in Lookup (lookup-el) allows local users to overwrite arbitrary files via a symlink attack on temporary files.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input/><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="DEBIAN" url="http://www.debian.org/security/2007/dsa-1269">DSA-1269</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24377">24377</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/24590">24590</ref><ref source="BID" url="http://www.securityfocus.com/bid/23026">
23026</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017792">
1017792</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33052">
lookup-ndebbinary-symlink(33052)</ref><ref source="" url="http://bugs.gentoo.org/show_bug.cgi?id=197306"></ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200712-07.xml">GLSA-200712-07</ref><ref source="SECUNIA" url="http://secunia.com/advisories/28023">28023</ref></refs><vuln_soft><prod name="Lookup" vendor="Lookup"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" CVSS_score="9.3" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-04-13" name="CVE-2007-0238" published="2007-03-21" seq="2007-0238" severity="High" type="CVE"><desc><descript source="cve">Stack-based buffer overflow in filter\starcalc\scflt.cxx in the StarCalc parser in OpenOffice.org (OOo) Office Suite before 2.2, and 1.x before 1.1.5 Patch, allows user-assisted remote attackers to execute arbitrary code via a document with a long Note.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" source="DEBIAN" url="http://www.debian.org/security/2007/dsa-1270">DSA-1270</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1032">ADV-2007-1032</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017799">1017799</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2007-0033.html">RHSA-2007:0033</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2007-0069.html">RHSA-2007:0069</ref><ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102794-1">102794</ref><ref source="SUSE" url="http://lists.suse.com/archive/suse-security-announce/2007-Mar/0007.html">SUSE-SA:2007:023</ref><ref source="UBUNTU" url="http://www.ubuntu.com/usn/usn-444-1">USN-444-1</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1117">ADV-2007-1117</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24465">24465</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24550">24550</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24646">24646</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24647">24647</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33112">openoffice-starcalc-bo(33112)</ref><ref source="" url="https://issues.foresightlinux.org/browse/FL-211"></ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:073">MDKSA-2007:073</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24676">24676</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/464724/100/0/threaded">20070404 High Risk Vulnerability in OpenOffice</ref><ref source="" url="http://www.ngssoftware.com/advisories/high-risk-vulnerabilities-in-the-openoffice-suite/"></ref><ref source="" url="http://www.openoffice.org/security/CVE-2007-0238"></ref><ref source="" url="https://issues.rpath.com/browse/RPL-1118"></ref><ref source="SECUNIA" url="http://secunia.com/advisories/24810">
24810</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200704-12.xml">
GLSA-200704-12</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24906">
24906</ref><ref source="BID" url="http://www.securityfocus.com/bid/23067">23067</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24588">24588</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24613">24613</ref></refs><vuln_soft><prod name="OpenOffice" vendor="OpenOffice"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" CVSS_score="9.3" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-03-22" name="CVE-2007-0239" published="2007-03-21" seq="2007-0239" severity="High" type="CVE"><desc><descript source="cve">OpenOffice.org (OOo) Office Suite allows user-assisted remote attackers to execute arbitrary commands via shell metacharacters in a prepared link in a crafted document.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" source="DEBIAN" url="http://www.debian.org/security/2007/dsa-1270">DSA-1270</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1032">ADV-2007-1032</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017799">1017799</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2007-0033.html">
RHSA-2007:0033</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2007-0069.html">
RHSA-2007:0069</ref><ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102807-1">
102807</ref><ref source="SUSE" url="http://lists.suse.com/archive/suse-security-announce/2007-Mar/0007.html">
SUSE-SA:2007:023</ref><ref source="UBUNTU" url="http://www.ubuntu.com/usn/usn-444-1">
USN-444-1</ref><ref source="BID" url="http://www.securityfocus.com/bid/22812">
22812</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1117">
ADV-2007-1117</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24465">
24465</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24550">
24550</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24646">
24646</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24647">
24647</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33113">
openoffice-shell-command-execution(33113)</ref><ref source="" url="https://issues.foresightlinux.org/browse/FL-211"></ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:073">
MDKSA-2007:073</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24676">
24676</ref><ref source="" url="https://issues.rpath.com/browse/RPL-1118"></ref><ref source="SECUNIA" url="http://secunia.com/advisories/24810">
24810</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200704-12.xml">
GLSA-200704-12</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24906">
24906</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24588">24588</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24613">24613</ref></refs><vuln_soft><prod name="OpenOffice" vendor="OpenOffice"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" modified="2007-03-27" name="CVE-2007-0240" published="2007-03-22" seq="2007-0240" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in Zope 2.10.2 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors in a HTTP GET request.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" patch="1" source="" url="http://www.zope.org/Products/Zope/Hotfix-2007-03-20/announcement/view"></ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1041">ADV-2007-1041</ref><ref source="BID" url="http://www.securityfocus.com/bid/23084">
23084</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24017">
24017</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33187">
zope-unspecifiedget-xss(33187)</ref><ref source="DEBIAN" url="http://www.debian.org/security/2007/dsa-1275">
DSA-1275</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24713">
24713</ref><ref source="SUSE" url="http://lists.suse.com/archive/suse-security-announce/2007-May/0005.html">
SUSE-SR:2007:011</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25239">
25239</ref></refs><vuln_soft><prod name="Zope" vendor="Zope"><vers num="2.10.2" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" modified="2007-04-06" name="CVE-2007-0242" published="2007-04-03" seq="2007-0242" severity="Medium" type="CVE"><desc><descript source="cve">The UTF-8 decoder in codecs/qutfcodec.cpp in Qt 3.3.8 and 4.2.3 does not reject long UTF-8 sequences as required by the standard, which allows remote attackers to conduct cross-site scripting (XSS) and directory traversal attacks via long sequences that decode to dangerous metacharacters.</descript></desc><loss_types><int/></loss_types><vuln_types><input/><exception/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" source="" url="http://www.nabble.com/Bug-417390:-CVE-2007-0242,--Qt-UTF-8-overlong-sequence-decoding-vulnerability-t3506065.html"></ref><ref patch="1" source="" url="http://www.trolltech.com/company/newsroom/announcements/press.2007-03-30.9172215350"></ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2007:074">
MDKSA-2007:074</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2007:075">
MDKSA-2007:075</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2007:076">
MDKSA-2007:076</ref><ref source="BID" url="http://www.securityfocus.com/bid/23269">
23269</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1212">
ADV-2007-1212</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24727">
24727</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24699">
24699</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24705">
24705</ref><ref source="SLACKWARE" url="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2007&amp;m=slackware-security.348591">
SSA:2007-093-03</ref><ref source="UBUNTU" url="http://www.ubuntu.com/usn/usn-452-1">
USN-452-1</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24726">
24726</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24847">
24847</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33397">
qt-utf8-xss(33397)</ref><ref source="" url="http://support.novell.com/techcenter/psdb/39ea4b325a7da742cb8b6995fa585b14.html"></ref><ref source="" url="http://support.novell.com/techcenter/psdb/fc79b7f48d739f9c803a24ddad933384.html"></ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2007_6_sr.html">
SUSE-SR:2007:006</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24797">
24797</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24889">
24889</ref><ref source="" url="https://issues.rpath.com/browse/RPL-1202"></ref><ref source="SECUNIA" url="http://secunia.com/advisories/24759">
24759</ref><ref source="DEBIAN" url="http://www.debian.org/security/2007/dsa-1292">
DSA-1292</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25263">
25263</ref><ref source="" url="http://support.avaya.com/elmodocs2/security/ASA-2007-424.htm"></ref><ref source="FEDORA" url="http://fedoranews.org/updates/FEDORA-2007-703.shtml">FEDORA-2007-703</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:074">MDKSA-2007:074</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:075">MDKSA-2007:075</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:076">MDKSA-2007:076</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2007-0909.html">RHSA-2007:0909</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2007-0883.html">RHSA-2007:0883</ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20070901-01-P.asc">20070901-01-P</ref><ref source="SECUNIA" url="http://secunia.com/advisories/26857">26857</ref><ref source="SECUNIA" url="http://secunia.com/advisories/26804">26804</ref><ref source="SECUNIA" url="http://secunia.com/advisories/27108">27108</ref><ref source="SECUNIA" url="http://secunia.com/advisories/27275">27275</ref></refs><vuln_soft><prod name="Qt" vendor="Qt"><vers num="3.3.8"/><vers num="4.2.3"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" discovered="2006-06-16" modified="2008-01-17" name="CVE-2007-0243" published="2007-01-17" seq="2007-0243" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in Sun JDK and Java Runtime Environment (JRE) 5.0 Update 9 and earlier, SDK and JRE 1.4.2_12 and earlier, and SDK and JRE 1.3.1_18 and earlier allows applets to gain privileges via a GIF image with a block with a 0 width field, which triggers memory corruption.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" patch="1" source="" url="http://www.zerodayinitiative.com/advisories/ZDI-07-005.html"></ref><ref patch="1" source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102760-1">102760</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/457159/100/0/threaded">20070117 ZDI-07-005: Sun Microsystems Java GIF File Parsing Memory Corruption Vulnerability</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/388289">VU#388289</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0211">ADV-2007-0211</ref><ref source="SECUNIA" url="http://secunia.com/advisories/23757">23757</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/457638/100/0/threaded">20070121 Sun Microsystems Java GIF File Parsing Memory Corruption Vulnerability Prove Of Concept Exploit</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200702-07.xml">GLSA-200702-07</ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200702-08.xml">GLSA-200702-08</ref><ref source="HP" url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&amp;cc=us&amp;objectID=c00876579">HPSBUX02196</ref><ref source="BID" url="http://www.securityfocus.com/bid/22085">22085</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0936">ADV-2007-0936</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1017520">1017520</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24202">24202</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24189">24189</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24468">24468</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31537">jre-gif-bo(31537)</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2007-0166.html">RHSA-2007:0166</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2007-0167.html">RHSA-2007:0167</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24993">24993</ref><ref source="BEA" url="http://dev2dev.bea.com/pub/advisory/242">BEA07-172.00</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1814">ADV-2007-1814</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25283">25283</ref><ref source="" url="http://support.novell.com/techcenter/psdb/4f850d1e2b871db609de64ec70f0089c.html"></ref><ref source="" url="http://support.novell.com/techcenter/psdb/d2f549cc040cd81ae4a268bb5edfe918.html"></ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2007-0956.html">RHSA-2007:0956</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2007_45_java.html">SUSE-SA:2007:045</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA07-022A.html">TA07-022A</ref><ref source="SECUNIA" url="http://secunia.com/advisories/26049">26049</ref><ref source="SECUNIA" url="http://secunia.com/advisories/26119">26119</ref><ref source="SECUNIA" url="http://secunia.com/advisories/27203">27203</ref><ref source="SECUNIA" url="http://secunia.com/advisories/26645">26645</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2158">2158</ref><ref source="" url="http://docs.info.apple.com/article.html?artnum=307177"></ref><ref source="APPLE" url="http://lists.apple.com/archives/Security-announce/2007/Dec/msg00001.html">APPLE-SA-2007-12-14</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/4224">ADV-2007-4224</ref><ref source="SECUNIA" url="http://secunia.com/advisories/28115">28115</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2008-0261.html">RHSA-2008:0261</ref></refs><vuln_soft><prod name="JRE" vendor="Sun"><vers num="5.0 Update 9"/><vers num="5.0 Update 8"/><vers num="5.0 Update 7"/><vers num="5.0 Update 6"/><vers num="5.0 Update 5"/><vers num="5.0 Update 4"/><vers num="5.0 Update 3"/><vers num="1.4.2_12"/><vers num="1.4.2_11"/><vers num="1.4.2_10"/><vers num="1.4.2_9"/><vers num="1.4.2_8"/><vers num="1.4.2_7"/><vers num="1.4.2_6"/><vers num="1.4.2_5"/><vers num="1.4.2_4"/><vers num="1.4.2_3"/><vers num="1.4.2_2"/><vers num="1.4.2_1"/><vers num="1.3.1_18" prev="1"/><vers num="1.3.1_16"/></prod><prod name="JDK" vendor="Sun"><vers num="5.0 Update9" prev="1"/><vers num="5.0 Update8"/><vers num="5.0 Update7"/><vers num="5.0 Update5"/><vers num="5.0 Update4"/><vers num="5.0 Update3"/></prod><prod name="SDK" vendor="Sun"><vers num="1.4.2_12"/><vers num="1.4.2_10"/><vers num="1.4.2_09"/><vers num="1.4.2_08"/><vers num="1.4.2_03"/><vers num="1.4.2"/><vers num="1.3.1_18"/><vers num="1.3.1_16"/><vers num="1.3.1_01a"/><vers num="1.3.1_01"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0" modified="2007-05-11" name="CVE-2007-0244" published="2007-05-11" seq="2007-0244" severity="Medium" type="CVE"><desc><descript source="cve">pptpgre.c in PoPToP Point to Point Tunneling Server (pptpd) before 1.3.4 allows remote attackers to cause a denial of service (PPTP connection tear-down) via (1) GRE packets with out-of-order sequence numbers or (2) certain GRE packets that are processed using a wrong pointer and improperly dequeued.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref source="" url="http://sourceforge.net/project/shownotes.php?release_id=501476&amp;group_id=44827"></ref><ref adv="1" patch="1" source="DEBIAN" url="http://www.debian.org/security/2007/dsa-1288">DSA-1288</ref><ref source="BID" url="http://www.securityfocus.com/bid/23886">23886</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1743">ADV-2007-1743</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2007_10_sr.html">
SUSE-SR:2007:010</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25220">
25220</ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200705-18.xml">
GLSA-200705-18</ref><ref source="TRUSTIX" url="http://www.trustix.org/errata/2007/0017/">
2007-0017</ref><ref source="UBUNTU" url="http://www.ubuntu.com/usn/usn-459-1">
USN-459-1</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1018064">
1018064</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25255">
25255</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2007_19_sr.html">SUSE-SR:2007:019</ref><ref source="UBUNTU" url="http://www.ubuntu.com/usn/usn-459-2">USN-459-2</ref><ref source="SECUNIA" url="http://secunia.com/advisories/26987">26987</ref></refs><vuln_soft><prod name="PPTP Server" vendor="PoPToP"><vers num="1.3.3" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" CVSS_score="9.3" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-12-27" name="CVE-2007-0245" published="2007-06-12" seq="2007-0245" severity="High" type="CVE"><desc><descript source="cve">Heap-based buffer overflow in OpenOffice.org (OOo) 2.2.1 and earlier allows remote attackers to execute arbitrary code via a RTF file with a crafted prtdata tag with a length parameter inconsistency, which causes vtable entries to be overwritten.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/><user_init/></range><refs><ref patch="1" source="DEBIAN" url="http://www.debian.org/security/2007/dsa-1307">DSA-1307</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/471274/100/0/threaded">20070613 High risk vulnerability in OpenOffice RTF parser</ref><ref source="" url="http://sw.openoffice.org/source/browse/sw/sw/source/filter/rtf/swparrtf.cxx?rev=1.67"></ref><ref source="" url="https://issues.rpath.com/browse/RPL-1570"></ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200707-02.xml">GLSA-200707-02</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:144">MDKSA-2007:144</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2007-0406.html">RHSA-2007:0406</ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20070602-01-P.asc">20070602-01-P</ref><ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102917-1">102917</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2007_37_openoffice.html">SUSE-SA:2007:037</ref><ref source="UBUNTU" url="http://www.ubuntu.com/usn/usn-482-1">USN-482-1</ref><ref source="BID" url="http://www.securityfocus.com/bid/24450">24450</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/2166">ADV-2007-2166</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/2229">ADV-2007-2229</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1018239">1018239</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/25648">25648</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/25650">25650</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/25673">25673</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/25705">25705</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/25862">25862</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/25894">25894</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/25905">25905</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/26010">26010</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/26022">26022</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/26476">26476</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/34843">openoffice-rtf-bo(34843)</ref></refs><vuln_soft><prod name="OpenOffice" vendor="OpenOffice"><vers num="2.2.1" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-06-14" name="CVE-2007-0246" published="2007-05-29" seq="2007-0246" severity="Medium" type="CVE"><desc><descript source="cve">plugins/scmcvs/www/cvsweb.php in the CVSWeb CGI in GForge 4.5.16 before 20070524, aka gforge-plugin-scmcvs, allows remote attackers to execute arbitrary commands via shell metacharacters in the PATH_INFO.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://gforge.org/scm/viewvc.php/branches/Branch_4_5/gforge/plugins/scmcvs/www/cvsweb.php?root=gforge&amp;r1=5849&amp;r2=6038&amp;pathrev=6038"></ref><ref source="DEBIAN" url="http://www.debian.org/security/2007/dsa-1297">DSA-1297</ref><ref source="BID" url="http://www.securityfocus.com/bid/24141">24141</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1942">ADV-2007-1942</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/25395">25395</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/25416">25416</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/34510">gforge-cvsweb-code-execution(34510)</ref></refs><vuln_soft><prod name="GForge" vendor="GForge"><vers num="4.5.16" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0" modified="2007-08-07" name="CVE-2007-0247" published="2007-01-16" seq="2007-0247" severity="Medium" type="CVE"><desc><descript source="cve">squid/src/ftp.c in Squid before 2.6.STABLE7 allows remote FTP servers to cause a denial of service (core dump) via crafted FTP directory listing responses, possibly related to the (1) ftpListingFinish and (2) ftpHtmlifyListEntry functions.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://www.squid-cache.org/Versions/v2/2.6/squid-2.6.STABLE7-RELEASENOTES.html#s12"></ref><ref source="" url="http://www.squid-cache.org/bugs/show_bug.cgi?id=1857"></ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/23767">23767</ref><ref source="FEDORA" url="http://fedoranews.org/cms/node/2442">FEDORA-2007-092</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200701-22.xml">GLSA-200701-22</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2007:026">MDKSA-2007:026</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2007_12_squid.html">SUSE-SA:2007:012</ref><ref source="TRUSTIX" url="http://www.trustix.org/errata/2007/0003/">2007-0003</ref><ref source="UBUNTU" url="http://www.ubuntu.com/usn/usn-414-1">USN-414-1</ref><ref source="BID" url="http://www.securityfocus.com/bid/22079">22079</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0199">ADV-2007-0199</ref><ref source="SECUNIA" url="http://secunia.com/advisories/23810">23810</ref><ref source="SECUNIA" url="http://secunia.com/advisories/23805">23805</ref><ref source="SECUNIA" url="http://secunia.com/advisories/23837">23837</ref><ref source="SECUNIA" url="http://secunia.com/advisories/23889">23889</ref><ref source="SECUNIA" url="http://secunia.com/advisories/23921">23921</ref><ref source="SECUNIA" url="http://secunia.com/advisories/23946">23946</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31523">squid-multiple-dos(31523)</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:026">MDKSA-2007:026</ref></refs><vuln_soft><prod name="Squid" vendor="Squid"><vers num="2.6.STABLE6"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0" modified="2007-03-08" name="CVE-2007-0248" published="2007-01-16" seq="2007-0248" severity="Medium" type="CVE"><desc><descript source="cve">The aclMatchExternal function in Squid before 2.6.STABLE7 allows remote attackers to cause a denial of service (crash) by causing an external_acl queue overload, which triggers an infinite loop.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref source="" url="http://www.squid-cache.org/Versions/v2/2.6/squid-2.6.STABLE7-RELEASENOTES.html#s12"></ref><ref source="" url="http://www.squid-cache.org/bugs/show_bug.cgi?id=1848"></ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/23767">23767</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200701-22.xml">
GLSA-200701-22</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2007:026">
MDKSA-2007:026</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2007_12_squid.html">
SUSE-SA:2007:012</ref><ref source="UBUNTU" url="http://www.ubuntu.com/usn/usn-414-1">
USN-414-1</ref><ref source="BID" url="http://www.securityfocus.com/bid/22203">
22203</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0199">
ADV-2007-0199</ref><ref source="SECUNIA" url="http://secunia.com/advisories/23805">
23805</ref><ref source="SECUNIA" url="http://secunia.com/advisories/23889">
23889</ref><ref source="SECUNIA" url="http://secunia.com/advisories/23921">
23921</ref><ref source="SECUNIA" url="http://secunia.com/advisories/23946">
23946</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31525">
squid-externalacl-dos(31525)</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:026">MDKSA-2007:026</ref></refs><vuln_soft><prod name="Squid" vendor="Squid"><vers num="2.6.STABLE6"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-01-17" name="CVE-2007-0249" published="2007-01-16" seq="2007-0249" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in index.php in Nwom topsites 3.0 allows remote attackers to inject arbitrary web script or HTML via the o parameter.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/456636/100/0/threaded">20070111 Nwom topsites v3.0</ref><ref source="BID" url="http://www.securityfocus.com/bid/22012">22012</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2149">2149</ref></refs><vuln_soft><prod name="NWOM Topsites" vendor="NWOM"><vers num="3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0" modified="2007-01-17" name="CVE-2007-0250" published="2007-01-16" seq="2007-0250" severity="Medium" type="CVE"><desc><descript source="cve">index.php in Nwom topsites 3.0 allows remote attackers to obtain potentially sensitive information via a &apos; (quote) character in the o parameter, which forces a SQL error.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/456636/100/0/threaded">20070111 Nwom topsites v3.0</ref><ref source="BID" url="http://www.securityfocus.com/bid/22012">22012</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2149">2149</ref></refs><vuln_soft><prod name="NWOM Topsites" vendor="NWOM"><vers num="3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.8" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.9" CVSS_score="7.8" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_version="2.0" modified="2007-01-17" name="CVE-2007-0251" published="2007-01-16" seq="2007-0251" severity="High" type="CVE"><desc><descript source="cve">Integer underflow in the DecodeGRE function in src/decode.c in Snort 2.6.1.2 allows remote attackers to trigger dereferencing of certain memory locations via crafted GRE packets, which may cause corruption of log files or writing of sensitive information into log files.</descript></desc><loss_types><avail/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/456598/100/0/threaded">20070111 Calyptix Security Advisory CX-2007-001 - Snort 2.6.1.2 Integer Underflow Vulnerability</ref><ref source="" url="http://labs.calyptix.com/advisories/CX-2007-01.txt"></ref><ref source="" url="http://www.snort.org/got_source/source.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/22004">22004</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0152">
ADV-2007-0152</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1017507">
1017507</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2165">2165</ref></refs><vuln_soft><prod name="Snort" vendor="Snort"><vers num="2.6.1.2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-01-17" name="CVE-2007-0252" published="2007-01-16" seq="2007-0252" severity="High" type="CVE"><desc><descript source="cve">Unspecified vulnerability in easy-content filemanager allows remote attackers to upload or modify arbitrary files via unspecified vectors.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/456622/100/0/threaded">20070111 easy-content filemanager</ref></refs><vuln_soft><prod name="Easy-content filemanager" vendor="Easy-content filemanager"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-01-21" name="CVE-2007-0253" published="2007-01-16" seq="2007-0253" severity="High" type="CVE"><desc><descript source="cve">** DISPUTED **  Unspecified vulnerability in the grsecurity patch has unspecified impact and remote attack vectors, a different vulnerability than the expand_stack vulnerability from the Digital Armaments 20070110 pre-advisory.  NOTE: the grsecurity developer has disputed this issue, stating that &quot;the function they claim the vulnerability to be in is a trivial function, which can, and has been, easily checked for any supposed vulnerabilities.&quot;  The developer also cites a past disclosure that was not proven.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" other="1" user="1"/></loss_types><range><local/></range><refs><ref adv="1" source="" url="http://forums.grsecurity.net/viewtopic.php?t=1646"></ref><ref adv="1" source="" url="http://www.digitalarmaments.com/news_news.shtml"></ref><ref source="" url="http://grsecurity.net/news.php#digitalfud"></ref></refs><vuln_soft><prod name="Grsecurity Kernel Patch" vendor="Grsecurity"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-01-17" name="CVE-2007-0254" published="2007-01-16" seq="2007-0254" severity="High" type="CVE"><desc><descript source="cve">Format string vulnerability in the errors_create_window function in errors.c in xine-ui allows attackers to execute arbitrary code via unknown vectors.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/456590/100/0/threaded">20070111 Xine-ui format string Vulnerabilties.</ref><ref source="BID" url="http://www.securityfocus.com/bid/22002">22002</ref><ref source="SECUNIA" url="http://secunia.com/advisories/23709">23709</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31505">xineui-errorscreatewindow-format-string(31505)</ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200701-18.xml">
GLSA-200701-18</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2007:027">
MDKSA-2007:027</ref><ref source="SECUNIA" url="http://secunia.com/advisories/23891">
23891</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:027">MDKSA-2007:027</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:154">MDKSA-2007:154</ref><ref source="SECUNIA" url="http://secunia.com/advisories/23931">23931</ref></refs><vuln_soft><prod name="xine-ui" vendor="xine"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" CVSS_score="9.3" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-01-17" name="CVE-2007-0255" published="2007-01-16" seq="2007-0255" severity="High" type="CVE"><desc><descript source="cve">XINE 0.99.4 allows user-assisted remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a certain M3U file that contains a long #EXTINF line and contains format string specifiers in an invalid udp:// URI, possibly a variant of CVE-2007-0017.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/456523/100/0/threaded">20070110 VLC Format String Vulnerability also in XINE</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2007:027">
MDKSA-2007:027</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:027">MDKSA-2007:027</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:154">MDKSA-2007:154</ref><ref source="BID" url="http://www.securityfocus.com/bid/22252">22252</ref><ref source="SECUNIA" url="http://secunia.com/advisories/23931">23931</ref></refs><vuln_soft><prod name="XINE" vendor="XINE"><vers num="0.99.4"/></prod></vuln_soft></entry><entry CVSS_base_score="7.8" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.9" CVSS_score="7.8" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_version="2.0" modified="2007-01-17" name="CVE-2007-0256" published="2007-01-16" seq="2007-0256" severity="High" type="CVE"><desc><descript source="cve">VideoLAN VLC 0.8.6a allows remote attackers to cause a denial of service (application crash) via a crafted .wmv file.</descript></desc><loss_types><avail/></loss_types><range><network/></range><refs><ref source="" url="http://downloads.securityfocus.com/vulnerabilities/exploits/22003.py"></ref><ref source="BID" url="http://www.securityfocus.com/bid/22003">22003</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31515">
vlcmediaplayer-wmv-dos(31515)</ref></refs><vuln_soft><prod name="VLC Media Player" vendor="VideoLAN"><vers num="0.8.6a"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-08-07" name="CVE-2007-0257" published="2007-01-16" seq="2007-0257" severity="High" type="CVE"><desc><descript source="cve">** DISPUTED **  Unspecified vulnerability in the expand_stack function in grsecurity PaX allows local users to gain privileges via unspecified vectors. NOTE: the grsecurity developer has disputed this issue, stating that &quot;the function they claim the vulnerability to be in is a trivial function, which can, and has been, easily checked for any supposed vulnerabilities.&quot;  The developer also cites a past disclosure that was not proven.  As of 20070120, the original researcher has released demonstration code.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" other="1" user="1"/></loss_types><range><local/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/456626/100/0/threaded">20070111 Digital Armaments Security Pre-Advisory 11.01.2007: Grsecurity Kernel PaX - Local root vulnerability</ref><ref adv="1" source="" url="http://forums.grsecurity.net/viewtopic.php?t=1646"></ref><ref adv="1" source="" url="http://www.digitalarmaments.com/news_news.shtml"></ref><ref adv="1" source="" url="http://www.digitalarmaments.com/pre2007-00018659.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/22014">22014</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0155">ADV-2007-0155</ref><ref source="SECUNIA" url="http://secunia.com/advisories/23713">23713</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/456722/100/0/threaded">20070112 Lies? [Was: Re: Digital Armaments Security Pre-Advisory11.01.2007: Grsecurity Kernel PaX - Local root vulnerability]</ref><ref source="" url="http://grsecurity.net/news.php#digitalfud"></ref><ref source="SECTRACK" url="http://securitytracker.com/id?1017509">1017509</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/457509/100/0/threaded">20070120 Digital Armaments Security Advisory 20.01.2007: Grsecurity Kernel PaX Vulnerability</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/462302/100/100/threaded">20070309 Re: Digital Armaments Security Advisory 20.01.2007: Grsecurity Kernel PaX Vulnerability</ref></refs><vuln_soft><prod name="Grsecurity Kernel Patch" vendor="Grsecurity"><vers num="2.1.8"/><vers num="2.1.7"/><vers num="2.1.6"/><vers num="2.1.5"/><vers num="2.1.4"/><vers num="2.1.3"/><vers num="2.1.2"/><vers num="2.1.1"/><vers num="2.1.0"/><vers num="2.0.2"/><vers num="2.0.1"/><vers num="1.9.4"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-01-17" name="CVE-2007-0258" published="2007-01-16" seq="2007-0258" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in index.php in (1) Fastilo 2.0 and (2) Open Solution Quick.Cart 2.0 allows remote attackers to inject arbitrary web script or HTML via the p parameter.  NOTE: some of these details are obtained from third party information.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://14house.blogspot.com/2007/01/fastilo-open-source-shopping-cart-vuln.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/22007">22007</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/23733">23733</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/23738">23738</ref><ref source="BID" url="http://www.securityfocus.com/bid/21971">
21971</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0156">
ADV-2007-0156</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0157">
ADV-2007-0157</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31475">
quickcart-p-xss(31475)</ref></refs><vuln_soft><prod name="Quick.Car" vendor="OpenSolution"><vers num="2.0"/></prod><prod name="Fastilo" vendor="Fastilo"><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.8" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.9" CVSS_score="7.8" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:N/A:N)" CVSS_version="2.0" modified="2007-01-17" name="CVE-2007-0259" published="2007-01-16" seq="2007-0259" severity="High" type="CVE"><desc><descript source="cve">Ezboxx Portal System Beta 0.7.6 and earlier allows remote attackers to obtain sensitive information via a invalid cat parameter to boxx/knowledgebase.asp, which reveals the path in an error message.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/456699/100/0/threaded">20070111 Ezboxx multiple vulnerabilities.</ref><ref source="" url="http://www.bugsec.com/articles.php?Security=20"></ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0208">ADV-2007-0208</ref></refs><vuln_soft><prod name="Ezboxx Portal System" vendor="Ezboxx"><vers num="Beta 0.7.6" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-01-17" name="CVE-2007-0260" published="2007-01-16" seq="2007-0260" severity="High" type="CVE"><desc><descript source="cve">** DISPUTED **  PHP remote file inclusion vulnerability in index.php in Naig 0.5.2 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the this_path parameter.  NOTE: a reliable third party disputes this vulnerability because this_path is defined before use.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/456744/100/0/threaded">20070112 Naig &lt;= 0.5.2 (this_path) Remote File Include Vulnerability</ref><ref source="VIM" url="http://www.attrition.org/pipermail/vim/2007-January/001239.html">20070112 Fwd: Naig &lt;= 0.5.2 (this_path) Remote File Include Vulnerability</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/456785/100/0/threaded">
20070113 Re: Naig &lt;= 0.5.2 (this_path) Remote File Include Vulnerability</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2145">2145</ref></refs><vuln_soft><prod name="Naig" vendor="Naig"><vers num="0.5.2"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-01-17" name="CVE-2007-0261" published="2007-01-16" seq="2007-0261" severity="High" type="CVE"><desc><descript source="cve">snews.php in sNews 1.5.30 and earlier does not properly exit when authentication fails, which allows remote attackers to perform unauthorized administrative actions, as demonstrated by changing an administrative password via the changeup task, and by uploading PHP code via the imagefile parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref source="" url="http://www.milw0rm.com/exploits/3116"></ref><ref source="BID" url="http://www.securityfocus.com/bid/22025">22025</ref><ref source="SECUNIA" url="http://secunia.com/advisories/23746">23746</ref><ref source="MILW0RM" url="http://milw0rm.com/exploits/3116">

3116</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31535">
snews-image-file-upload(31535)</ref></refs><vuln_soft><prod name="sNews" vendor="sNews"><vers num="1.5.30"/><vers num="1.5.29"/></prod></vuln_soft></entry><entry CVSS_base_score="7.8" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.9" CVSS_score="7.8" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:N/A:N)" CVSS_version="2.0" modified="2007-01-17" name="CVE-2007-0262" published="2007-01-16" seq="2007-0262" severity="High" type="CVE"><desc><descript source="cve">WordPress 2.0.6, and 2.1Alpha 3 (SVN:4662), does not properly verify that the m parameter value has the string data type, which allows remote attackers to obtain sensitive information via an invalid m[] parameter, as demonstrated by obtaining the path, and obtaining certain SQL information such as the table prefix.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/456731/100/0/threaded">20070112 Wordpress disclosure of Table Prefix Weakness</ref></refs><vuln_soft><prod name="WordPress" vendor="WordPress"><vers num="2.0.6"/><vers edition="Alpha 3" num="2.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.1" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="9.2" CVSS_score="7.1" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:C/A:C)" CVSS_version="2.0" modified="2007-01-17" name="CVE-2007-0263" published="2007-01-16" seq="2007-0263" severity="High" type="CVE"><desc><descript source="cve">Unspecified vulnerability in Total Commander before 6.5.6 allows user-assisted remote attackers to delete arbitrary files and corrupt a filesystem via a crafted RAR file.  NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.</descript></desc><loss_types><avail/><int/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref source="" url="http://www.ghisler.com/whatsnew.htm"></ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/22033">22033</ref></refs><vuln_soft><prod name="Total Commander" vendor="Total Commander"><vers num="6.5.5" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.6" CVSS_exploit_subscore="2.7" CVSS_impact_subscore="10.0" CVSS_score="6.6" CVSS_vector="(AV:L/AC:M/Au:S/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-06-26" name="CVE-2007-0264" published="2007-01-16" seq="2007-0264" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in Winzip32.exe in WinZip 9.0 allows local users to cause a denial of service (application crash) and possibly execute arbitrary code via a long command line argument.  NOTE: this issue may cross privilege boundaries if an application automatically invokes Winzip32.exe for untrusted input filenames, as in the case of a file upload application.  NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.</descript></desc><sols><sol source="nvd">This vulnerability is addressed in the following product release:
WinZip, WinZip, 9.0 SR1</sol></sols><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref source="BID" url="http://www.securityfocus.com/bid/22020">22020</ref></refs><vuln_soft><prod name="WinZip" vendor="WinZip"><vers num="9.0"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-01-17" name="CVE-2007-0265" published="2007-01-16" seq="2007-0265" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Ezboxx Portal System Beta 0.7.6 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the pic parameter to custom/piczoom.asp, (2) the nocatname parameter to boxx/user-upload.asp, or (3) the iid parameter to indexes/newscomments.asp.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/456699/100/0/threaded">20070111 Ezboxx multiple vulnerabilities.</ref><ref source="" url="http://www.bugsec.com/articles.php?Security=20"></ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0208">
ADV-2007-0208</ref><ref source="SECUNIA" url="http://secunia.com/advisories/23759">
23759</ref></refs><vuln_soft><prod name="Portal System Beta" vendor="Ezboxx"><vers num="0.7.6" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-01-17" name="CVE-2007-0266" published="2007-01-16" seq="2007-0266" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in boxx/ShowAppendix.asp in Ezboxx Portal System Beta 0.7.6 and earlier allows remote attackers to inject arbitrary web script or HTML via the iid parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/456699/100/0/threaded">20070111 Ezboxx multiple vulnerabilities.</ref><ref source="" url="http://www.bugsec.com/articles.php?Security=20"></ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0208">
ADV-2007-0208</ref><ref source="SECUNIA" url="http://secunia.com/advisories/23759">
23759</ref></refs><vuln_soft><prod name="Ezboxx Portal System" vendor="Ezboxx"><vers num="Beta 0.7.6" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="9.2" CVSS_score="6.6" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:C/A:C)" CVSS_version="2.0" modified="2007-08-07" name="CVE-2007-0267" published="2007-01-16" seq="2007-0267" severity="Medium" type="CVE"><desc><descript source="cve">The ufs_lookup function in the Mac OS X 10.4.8 and FreeBSD 6.1 kernels allows local users to cause a denial of service (kernel panic) and possibly corrupt other filesystems by mounting a crafted UNIX File System (UFS) DMG image that contains a corrupted directory entry (struct direct), related to the ufs_dirbad function.  NOTE: a third party states that the FreeBSD issue does not cross privilege boundaries.</descript></desc><loss_types><avail/><int/></loss_types><vuln_types><exception/></vuln_types><range><local/></range><refs><ref source="MLIST" url="http://lists.freebsd.org/pipermail/freebsd-security/2007-January/004218.html">[freebsd-security] 20070114 MOAB advisories</ref><ref source="" url="http://projects.info-pull.com/moab/MOAB-12-01-2007.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/22036">22036</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0171">ADV-2007-0171</ref><ref source="" url="http://docs.info.apple.com/article.html?artnum=305214"></ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0930">ADV-2007-0930</ref><ref source="OSVDB" url="http://www.osvdb.org/32686">32686</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017751">1017751</ref><ref source="SECUNIA" url="http://secunia.com/advisories/23721">23721</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24479">24479</ref><ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2007/Mar/msg00002.html">APPLE-SA-2007-03-13</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA07-072A.html">TA07-072A</ref></refs><vuln_soft><prod name="FreeBSD" vendor="FreeBSD"><vers num="6.1"/></prod><prod name="Mac OS X" vendor="Apple"><vers num="10.4.8"/></prod></vuln_soft></entry><entry CVSS_base_score="6.5" CVSS_exploit_subscore="8.0" CVSS_impact_subscore="6.4" CVSS_score="6.5" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-08-07" name="CVE-2007-0268" published="2007-01-16" seq="2007-0268" severity="Medium" type="CVE"><desc><descript source="cve">Multiple unspecified vulnerabilities in Oracle Database 9.0.1.5, 9.2.0.7, and 10.1.0.5 have unknown impact and attack vectors related to (1) the Advanced Queuing component and sys.dbms_aqsys.dbms_aq privileges (DB01), (2) Advanced Replication and sys.dbms_repcat_untrusted (DB07), and (3) Oracle Text and ctxload (DB15).  NOTE: Oracle has not publicly claims by reliable researchers that DB01 is for SQL injection in the SYS.DBMS_AQ_INV package, and DB07 is for a buffer overflow in the UNREGISTER_SNAPSHOT procedure in the DBMS_REPCAT_UNTRUSTED package.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs><ref adv="1" patch="1" source="" url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujan2007.html"></ref><ref source="" url="http://www.red-database-security.com/advisory/oracle_sql_injection_dbms_aq_inv.html"></ref><ref patch="1" source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA07-017A.html">TA07-017A</ref><ref patch="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/221788">VU#221788</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/23794">23794</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/458475/100/100/threaded">20070129 Re: Re: Oracle Buffer Overflows in DBMS_CAPTURE_ADM_INTERNAL</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/458005/100/0/threaded">20070124 Oracle Buffer Overflow in DBMS_REPCAT_UNTRUSTED.UNREGISTER_SNAPSHOT</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1017522">1017522</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31541">oracle-cpu-jan2007(31541)</ref><ref source="BID" url="http://www.securityfocus.com/bid/22083">22083</ref></refs><vuln_soft><prod name="Oracle" vendor="Oracle"><vers num="9.0.1.5"/><vers num="9.2.0.7"/><vers num="10.1.0.5"/></prod></vuln_soft></entry><entry CVSS_base_score="5.5" CVSS_exploit_subscore="8.0" CVSS_impact_subscore="4.9" CVSS_score="5.5" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:N)" CVSS_version="2.0" modified="2007-01-19" name="CVE-2007-0269" published="2007-01-16" seq="2007-0269" severity="Medium" type="CVE"><desc><descript source="cve">Unspecified vulnerability in Oracle Database 9.2.0.8, 10.1.0.5, and 10.2.0.3 has unknown impact and attack vectors related to the Change Data Capture and sys.dbms_cdc_subscribe privileges, aka DB02.</descript></desc><loss_types><conf/><int/></loss_types><range><network/></range><refs><ref adv="1" patch="1" source="" url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujan2007.html"></ref><ref patch="1" source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA07-017A.html">TA07-017A</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/23794">23794</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1017522">
1017522</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31541">
oracle-cpu-jan2007(31541)</ref><ref source="BID" url="http://www.securityfocus.com/bid/22083">22083</ref></refs><vuln_soft><prod name="Oracle" vendor="Oracle"><vers num="9.2.0.8"/><vers num="10.1.0.5"/><vers num="10.2.0.3"/></prod></vuln_soft></entry><entry CVSS_base_score="6.5" CVSS_exploit_subscore="8.0" CVSS_impact_subscore="6.4" CVSS_score="6.5" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:P)" CVSS_version="2.0" modified="2008-01-02" name="CVE-2007-0270" published="2007-01-16" seq="2007-0270" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in SYS.DBMS_DRS in Oracle Database 9.2.0.7 and 10.1.0.4 allows remote authenticated users to cause a denial of service (crash) or execute arbitrary code via the GET_PROPERTY function in SYS.DBMS_DRS, aka DB03.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><range><network/></range><refs><ref patch="1" source="" url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujan2007.html"></ref><ref patch="1" source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA07-017A.html">TA07-017A</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/23794">23794</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/458036/100/0/threaded">20070124 Oracle Buffer Overflow in DBMS_DRS.GET_PROPERTY</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1017522">1017522</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31541">oracle-cpu-jan2007(31541)</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/474050/100/0/threaded">20070718 Oracle Database Buffer overflow vulnerabilities in procedure DBMS_DRS.GET_PROPERTY (DB03)</ref><ref source="" url="http://www.appsecinc.com/resources/alerts/oracle/2007-04.shtml"></ref><ref source="BID" url="http://www.securityfocus.com/bid/22083">22083</ref></refs><vuln_soft><prod name="Oracle Database" vendor="Oracle"><vers num="9.2.0.7"/><vers num="10.1.0.4"/></prod></vuln_soft></entry><entry CVSS_base_score="6.5" CVSS_exploit_subscore="8.0" CVSS_impact_subscore="6.4" CVSS_score="6.5" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-08-07" name="CVE-2007-0271" published="2007-01-16" seq="2007-0271" severity="Medium" type="CVE"><desc><descript source="cve">Unspecified vulnerability in Oracle Database 9.0.1.5 and 9.2.0.7 has unknown impact and attack vectors related to the Log Miner component and sys.dbms_log_mnr privileges, aka DB04.  NOTE: Oracle has not disputed a reliable researcher claim that this is a buffer overflow in the ADD_LOGFILE procedure for the SYS.DBMS_LOGMNR package that allows code execution.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref patch="1" source="" url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujan2007.html"></ref><ref patch="1" source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA07-017A.html">TA07-017A</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/23794">23794</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/458475/100/100/threaded">20070129 Re: Re: Oracle Buffer Overflows in DBMS_CAPTURE_ADM_INTERNAL</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/458006/100/0/threaded">20070124 Oracle Buffer Overflow in DBMS_LOGMNR.ADD_LOGFILE</ref><ref source="" url="http://www.appsecinc.com/resources/alerts/oracle/2007-01.shtml"></ref><ref source="SECTRACK" url="http://securitytracker.com/id?1017522">1017522</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31541">oracle-cpu-jan2007(31541)</ref><ref source="BID" url="http://www.securityfocus.com/bid/22083">22083</ref></refs><vuln_soft><prod name="Oracle Database" vendor="Oracle"><vers num="9.0.1.5"/><vers num="9.2.0.7"/></prod></vuln_soft></entry><entry CVSS_base_score="8.5" CVSS_exploit_subscore="8.0" CVSS_impact_subscore="9.2" CVSS_score="8.5" CVSS_vector="(AV:N/AC:L/Au:S/C:N/I:C/A:C)" CVSS_version="2.0" modified="2008-01-02" name="CVE-2007-0272" published="2007-01-16" seq="2007-0272" severity="High" type="CVE"><desc><descript source="cve">Multiple buffer overflows in MDSYS.MD in Oracle Database 8.1.7.4, 9.0.1.5, 9.2.0.7, and 10.1.0.4 allows remote authenticated users to cause a denial of service (crash) or execute arbitrary code via unspecified vectors involving certain public procedures, aka DB05.</descript></desc><loss_types><avail/><int/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref patch="1" source="" url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujan2007.html"></ref><ref patch="1" source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA07-017A.html">TA07-017A</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/23794">23794</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/458038/100/0/threaded">20070124 Oracle Multiple Buffer Overflows and DoS attacks in public procedures of MDSYS.MD</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1017522">1017522</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31541">oracle-cpu-jan2007(31541)</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/474047/100/0/threaded">20070718 Oracle Database Buffer overflows and Denial of service vulnerabilities in public procedures of MDSYS.MD (DB12)</ref><ref source="" url="http://www.appsecinc.com/resources/alerts/oracle/2007-05.shtml"></ref><ref source="BID" url="http://www.securityfocus.com/bid/22083">22083</ref></refs><vuln_soft><prod name="Oracle Database" vendor="Oracle"><vers num="8.1.7.4"/><vers num="9.0.1.5"/><vers num="9.2.0.7"/><vers num="10.1.0.4"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" modified="2007-08-07" name="CVE-2007-0273" published="2007-01-16" seq="2007-0273" severity="Medium" type="CVE"><desc><descript source="cve">Unspecified vulnerability in Oracle Database 9.0.1.5, 9.2.0.8, 10.1.0.5, and 10.2.0.3 has unknown impact and attack vectors related to XMLDB, aka DB06.  NOTE: as of 20070123, Oracle has not disputed claims by a reliable researcher that DB06 is for multiple cross-site scripting (XSS) vulnerabilities.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref patch="1" source="" url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujan2007.html"></ref><ref patch="1" source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA07-017A.html">TA07-017A</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/23794">23794</ref><ref source="" url="http://www.red-database-security.com/advisory/oracle_xmldb_css2.html"></ref><ref source="SECTRACK" url="http://securitytracker.com/id?1017522">1017522</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31541">oracle-cpu-jan2007(31541)</ref><ref source="BID" url="http://www.securityfocus.com/bid/22083">22083</ref></refs><vuln_soft><prod name="Oracle Database" vendor="Oracle"><vers num="9.0.1.5"/><vers num="9.2.0.8"/><vers num="10.1.0.5"/><vers num="10.2.0.3"/></prod></vuln_soft></entry><entry CVSS_base_score="6.5" CVSS_exploit_subscore="8.0" CVSS_impact_subscore="6.4" CVSS_score="6.5" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-08-07" name="CVE-2007-0274" published="2007-01-16" seq="2007-0274" severity="Medium" type="CVE"><desc><descript source="cve">Multiple unspecified vulnerabilities in Oracle Database 9.2.0.7 and 10.1.0.5 have unknown impact and attack vectors related to (1) Export and sys.dbms_logrep_util (DB08), and (2) Oracle Streams and sys.dbms_capture_adm_internal privileges (DB09).  NOTE: Oracle has not disputed reliable researcher claims that DB08 is for a buffer overflow in the GET_OBJECT_NAME procedure in the DBMS_LOGREP_UTIL package, and DB09 is for buffer overflows in the CREATE_CAPTURE, ALTER_CAPTURE, and ABORT_TABLE_INSTANTIATION procedures in SYS.DBMS_CAPTURE_ADM_INTERNAL.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref patch="1" source="" url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujan2007.html"></ref><ref patch="1" source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA07-017A.html">TA07-017A</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/23794">23794</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/458126/100/0/threaded">20070125 Re: Oracle Buffer Overflow in DBMS_LOGREP_UTIL.GET_OBJECT_NAME</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/458112/100/100/threaded">20070125 Re: Oracle Buffer Overflows in DBMS_CAPTURE_ADM_INTERNAL</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/458475/100/100/threaded">20070129 Re: Re: Oracle Buffer Overflows in DBMS_CAPTURE_ADM_INTERNAL</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/458037/100/0/threaded">20070124 Oracle Buffer Overflow in DBMS_LOGREP_UTIL.GET_OBJECT_NAME</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/458041/100/0/threaded">20070124 Oracle Buffer Overflows in DBMS_CAPTURE_ADM_INTERNAL</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1017522">1017522</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31541">oracle-cpu-jan2007(31541)</ref><ref source="BID" url="http://www.securityfocus.com/bid/22083">22083</ref></refs><vuln_soft><prod name="Oracle Database" vendor="Oracle"><vers num="9.2.0.7"/><vers num="10.1.0.5"/></prod></vuln_soft></entry><entry CVSS_base_score="6.0" CVSS_exploit_subscore="6.8" CVSS_impact_subscore="6.4" CVSS_score="6.0" CVSS_vector="(AV:N/AC:M/Au:S/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-08-07" name="CVE-2007-0275" published="2007-01-16" seq="2007-0275" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in Oracle Reports Web Cartridge (RWCGI60) in the Workflow Cartridge component, as used in Oracle Database 9.2.0.8, 10.1.0.5, and 10.2.0.3; Application Server 9.0.4.3, 10.1.2.0.2, and 10.1.2.2; Collaboration Suite 10.1.2; and Oracle E-Business Suite and Applications 11.5.10CU2; allows remote authenticated users to inject arbitrary HTML or web script via the genuser parameter to rwcgi60, aka OWF01.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref patch="1" source="" url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujan2007.html"></ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA07-017A.html">TA07-017A</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/23794">23794</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/457193/100/0/threaded">20070117 [ISecAuditors Security Advisories] Oracle Reports Web Cartridge (RWCGI60) vulnerable to XSS</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1017522">1017522</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31541">oracle-cpu-jan2007(31541)</ref><ref source="BID" url="http://www.securityfocus.com/bid/22083">22083</ref></refs><vuln_soft><prod name="Oracle Database" vendor="Oracle"><vers num="9.2.0.8"/><vers num="10.1.0.5"/><vers num="10.2.0.3"/></prod><prod name="E-Business Suite and Applications" vendor="Oracle"><vers num="11.5.10 CU2"/></prod><prod name="Oracle Application Server" vendor="Oracle"><vers num="9.0.4.3"/><vers num="10.1.2.0.2"/><vers num="10.1.2.2"/></prod><prod name="Collaboration Suite" vendor="Oracle"><vers num="10.1.2"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="3.1" CVSS_impact_subscore="10.0" CVSS_score="6.8" CVSS_vector="(AV:L/AC:L/Au:S/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-01-19" name="CVE-2007-0276" published="2007-01-16" seq="2007-0276" severity="Medium" type="CVE"><desc><descript source="cve">Multiple unspecified vulnerabilities in Oracle Database 8.1.7.4 and 9.0.1.5 have unknown impact and attack vectors related to (1) Advanced Security Option and oklist or okdstry (DB10), (2) Oracle Net Services (DB13), and (3) Recovery Manager and oklist (DB16).</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><local/></range><refs><ref patch="1" source="" url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujan2007.html"></ref><ref patch="1" source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA07-017A.html">TA07-017A</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/23794">23794</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1017522">
1017522</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31541">
oracle-cpu-jan2007(31541)</ref><ref source="BID" url="http://www.securityfocus.com/bid/22083">22083</ref></refs><vuln_soft><prod name="Oracle Database" vendor="Oracle"><vers num="8.1.7.4"/><vers num="9.0.1.5"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="3.1" CVSS_impact_subscore="10.0" CVSS_score="6.8" CVSS_vector="(AV:L/AC:L/Au:S/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-01-19" name="CVE-2007-0277" published="2007-01-16" seq="2007-0277" severity="Medium" type="CVE"><desc><descript source="cve">Unspecified vulnerability in Oracle Database client-only 10.1.0.4 has unknown impact and attack vectors related to the Export component and expdp or impdp, aka DB11.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><local/></range><refs><ref patch="1" source="" url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujan2007.html"></ref><ref patch="1" source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA07-017A.html">TA07-017A</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/23794">23794</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1017522">
1017522</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31541">
oracle-cpu-jan2007(31541)</ref><ref source="BID" url="http://www.securityfocus.com/bid/22083">22083</ref></refs><vuln_soft><prod name="Oracle Database" vendor="Oracle"><vers num="10.1.0.4"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="3.1" CVSS_impact_subscore="10.0" CVSS_score="6.8" CVSS_vector="(AV:L/AC:L/Au:S/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-01-19" name="CVE-2007-0278" published="2007-01-16" seq="2007-0278" severity="Medium" type="CVE"><desc><descript source="cve">Multiple unspecified vulnerabilities in Oracle Database 8.1.7.4, 9.0.1.5, 9.2.0.7, and 10.1.0.5 have unknown impact and attack vectors related to (1) NLS Runtime and lmsgen (DB12), and (2) Oracle Text and ctxkbtc (DB14).</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><local/></range><refs><ref patch="1" source="" url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujan2007.html"></ref><ref patch="1" source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA07-017A.html">TA07-017A</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/23794">23794</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1017522">
1017522</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31541">
oracle-cpu-jan2007(31541)</ref><ref source="BID" url="http://www.securityfocus.com/bid/22083">22083</ref></refs><vuln_soft><prod name="Oracle Database" vendor="Oracle"><vers num="8.1.7.4"/><vers num="9.0.1.5"/><vers num="9.2.0.7"/><vers num="10.1.0.5"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-01-19" name="CVE-2007-0279" published="2007-01-16" seq="2007-0279" severity="High" type="CVE"><desc><descript source="cve">Multiple unspecified vulnerabilities in Oracle HTTP Server 9.2.0.8 and Oracle E-Business Suite and Applications 11.5.10CU2 have unknown impact and attack vectors, aka (1) OHS01, (2) OHS02, (3) OHS05, (4) OHS06, and (5) OHS07.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs><ref patch="1" source="" url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujan2007.html"></ref><ref patch="1" source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA07-017A.html">TA07-017A</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/23794">23794</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1017522">
1017522</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31541">
oracle-cpu-jan2007(31541)</ref><ref source="BID" url="http://www.securityfocus.com/bid/22083">22083</ref></refs><vuln_soft><prod name="Oracle E-Business Suite and Applications" vendor="Oracle"><vers num="11.5.10 CU2"/></prod><prod name="Oracle HTTP Server" vendor="Oracle"><vers num="9.2.0.8"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-08-07" name="CVE-2007-0280" published="2007-01-16" seq="2007-0280" severity="High" type="CVE"><desc><descript source="cve">Unspecified vulnerability in Oracle HTTP Server 9.0.1.5, Application Server 9.0.4.3, 10.1.2.0.0, 10.1.2.0.2, and 10.1.2.2; and Collaboration Suite 9.0.4.2 and 10.1.2; has unknown impact and attack vectors related to the Oracle Process Mgmt &amp; Notification component, aka OPMN01.   NOTE: as of 20070123, Oracle has not disputed claims by a reliable researcher that OPMN01 is for a buffer overflow in Oracle Notification Service (ONS).</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="" url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujan2007.html"></ref><ref patch="1" source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA07-017A.html">TA07-017A</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/23794">23794</ref><ref source="" url="http://www.red-database-security.com/advisory/oracle_buffer_overflow_ons.html"></ref><ref source="SECTRACK" url="http://securitytracker.com/id?1017522">1017522</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31541">oracle-cpu-jan2007(31541)</ref><ref source="BID" url="http://www.securityfocus.com/bid/22083">22083</ref></refs><vuln_soft><prod name="Oracle HTTP Server" vendor="Oracle"><vers num="9.0.1.5"/></prod><prod name="Oracle Application Server" vendor="Oracle"><vers num="9.0.4.3"/><vers num="10.1.2.0.2"/><vers num="10.1.2.2"/></prod><prod name="Oracle Collaboration Suite" vendor="Oracle"><vers num="9.0.4.2"/><vers num="10.1.2"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" modified="2007-01-19" name="CVE-2007-0281" published="2007-01-16" seq="2007-0281" severity="Medium" type="CVE"><desc><descript source="cve">Multiple unspecified vulnerabilities in Oracle HTTP Server 9.0.1.5, 9.2.0.8, 10.1.0.5, and 10.2.0.3; Application Server 9.0.4.3, 10.1.2.0.0, 10.1.2.0.1, 10.1.2.0.2, 10.1.2.1, and 10.1.3.0; and Collaboration Suite 9.0.4.2 and 10.1.2; have unknown impact and attack vectors related to the Oracle HTTP Server, aka (1) OHS03 and (2) OHS04.</descript></desc><loss_types><int/></loss_types><range><network/></range><refs><ref adv="1" patch="1" source="" url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujan2007.html"></ref><ref patch="1" source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA07-017A.html">TA07-017A</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/23794">23794</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1017522">
1017522</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31541">
oracle-cpu-jan2007(31541)</ref><ref source="BID" url="http://www.securityfocus.com/bid/22083">22083</ref></refs><vuln_soft><prod name="Oracle HTTP Server" vendor="Oracle"><vers num="9.0.1.5"/></prod><prod name="Oracle Application Server" vendor="Oracle"><vers num="9.0.4.3"/><vers num="10.1.2.0.2"/><vers num="10.1.2.2"/></prod><prod name="Oracle Collaboration Suite" vendor="Oracle"><vers num="9.0.4.2"/><vers num="10.1.2"/></prod></vuln_soft></entry><entry CVSS_base_score="3.2" CVSS_exploit_subscore="3.1" CVSS_impact_subscore="4.9" CVSS_score="3.2" CVSS_vector="(AV:L/AC:L/Au:S/C:P/I:P/A:N)" CVSS_version="2.0" modified="2007-01-19" name="CVE-2007-0282" published="2007-01-16" seq="2007-0282" severity="Low" type="CVE"><desc><descript source="cve">Unspecified vulnerability in Oracle HTTP Server 9.0.1.5, Application Server 9.0.4.2 and 10.1.2.0.0, and Collaboration Suite 9.0.4.2 has unknown impact and attack vectors related to the Oracle Process Mgmt &amp; Notification component, aka OPMN02.</descript></desc><loss_types><conf/><int/></loss_types><range><local/></range><refs><ref adv="1" patch="1" source="" url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujan2007.html"></ref><ref patch="1" source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA07-017A.html">TA07-017A</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/23794">23794</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1017522">
1017522</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31541">
oracle-cpu-jan2007(31541)</ref><ref source="BID" url="http://www.securityfocus.com/bid/22083">22083</ref></refs><vuln_soft><prod name="Oracle HTTP Server" vendor="Oracle"><vers num="9.0.1.5"/></prod><prod name="Oracle Application Server" vendor="Oracle"><vers num="9.0.4.3"/><vers num="10.1.2.0.0"/></prod><prod name="Oracle Collaboration Suite" vendor="Oracle"><vers num="9.0.4.2"/></prod></vuln_soft></entry><entry CVSS_base_score="4.0" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="4.9" CVSS_score="4.0" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:N)" CVSS_version="2.0" modified="2007-01-19" name="CVE-2007-0283" published="2007-01-16" seq="2007-0283" severity="Medium" type="CVE"><desc><descript source="cve">Unspecified vulnerability in Oracle Application Server 9.0.4.3 and Collaboration Suite 9.0.4.2 has unknown impact and attack vectors related to Oracle Containers for J2EE, aka OC4J02.</descript></desc><loss_types><conf/><int/></loss_types><range><network/></range><refs><ref adv="1" patch="1" source="" url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujan2007.html"></ref><ref patch="1" source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA07-017A.html">TA07-017A</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/23794">23794</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1017522">
1017522</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31541">
oracle-cpu-jan2007(31541)</ref><ref source="BID" url="http://www.securityfocus.com/bid/22083">22083</ref></refs><vuln_soft><prod name="Oracle Application Server" vendor="Oracle"><vers num="9.0.4.3"/></prod><prod name="Oracle Collaboration Suite" vendor="Oracle"><vers num="9.0.4.2"/></prod></vuln_soft></entry><entry CVSS_base_score="6.4" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="4.9" CVSS_score="6.4" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_version="2.0" modified="2007-01-19" name="CVE-2007-0284" published="2007-01-16" seq="2007-0284" severity="Medium" type="CVE"><desc><descript source="cve">Multiple unspecified vulnerabilities in Oracle Application Server 9.0.4.3 and 10.1.2.0.0, and Collaboration Suite 9.0.4.2, have unknown impact and attack vectors related to Oracle Containers for J2EE, aka (1) OC4J03 and (2) OC4J04.</descript></desc><loss_types><conf/><int/></loss_types><range><network/></range><refs><ref adv="1" patch="1" source="" url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujan2007.html"></ref><ref patch="1" source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA07-017A.html">TA07-017A</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/23794">23794</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1017522">
1017522</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31541">
oracle-cpu-jan2007(31541)</ref><ref source="BID" url="http://www.securityfocus.com/bid/22083">22083</ref></refs><vuln_soft><prod name="Oracle Application Server" vendor="Oracle"><vers num="9.0.4.3"/><vers num="10.1.2.0.0"/></prod><prod name="Oracle Collaboration Suite" vendor="Oracle"><vers num="9.0.4.2"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" modified="2007-01-19" name="CVE-2007-0285" published="2007-01-16" seq="2007-0285" severity="Medium" type="CVE"><desc><descript source="cve">Unspecified vulnerability in Oracle Application Server 9.0.4.3, 10.1.2.0.2, and 10.1.2.2; Collaboration Suite 9.0.4.2 and 10.1.2; and E-Business Suite and Applications 11.5.10CU2 has unknown impact and attack vectors related to Oracle Reports Developer, aka REP01.</descript></desc><loss_types><int/></loss_types><range><network/></range><refs><ref adv="1" patch="1" source="" url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujan2007.html"></ref><ref patch="1" source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA07-017A.html">TA07-017A</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/23794">23794</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1017522">
1017522</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31541">
oracle-cpu-jan2007(31541)</ref><ref source="BID" url="http://www.securityfocus.com/bid/22083">22083</ref></refs><vuln_soft><prod name="Oracle E-Business Suite and Applications" vendor="Oracle"><vers num="11.5.1"/></prod><prod name="Oracle Application Server" vendor="Oracle"><vers num="9.0.4.3"/><vers num="10.1.2.0.2"/><vers num="10.1.2.2"/></prod><prod name="Oracle Collaboration Suite" vendor="Oracle"><vers num="9.0.4.2"/><vers num="10.1.2"/></prod></vuln_soft></entry><entry CVSS_base_score="2.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="2.9" CVSS_score="2.6" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:N/A:N)" CVSS_version="2.0" modified="2007-01-19" name="CVE-2007-0286" published="2007-01-16" seq="2007-0286" severity="Low" type="CVE"><desc><descript source="cve">Unspecified vulnerability in Oracle Application Server 10.1.2.0.2 and 10.1.3.0, and Collaboration Suite 10.1.2, has unknown impact and attack vectors related to Containers for J2EE, aka OC4J07.</descript></desc><loss_types><conf/></loss_types><range><network/></range><refs><ref adv="1" patch="1" source="" url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujan2007.html"></ref><ref patch="1" source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA07-017A.html">TA07-017A</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/23794">23794</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1017522">
1017522</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31541">
oracle-cpu-jan2007(31541)</ref><ref source="BID" url="http://www.securityfocus.com/bid/22083">22083</ref></refs><vuln_soft><prod name="Oracle Application Server" vendor="Oracle"><vers num="10.1.2.0.2"/><vers num="10.1.3.0"/></prod><prod name="Oracle Collaboration Suite" vendor="Oracle"><vers num="10.1.2"/></prod></vuln_soft></entry><entry CVSS_base_score="1.7" CVSS_exploit_subscore="3.1" CVSS_impact_subscore="2.9" CVSS_score="1.7" CVSS_vector="(AV:L/AC:L/Au:S/C:P/I:N/A:N)" CVSS_version="2.0" modified="2007-01-19" name="CVE-2007-0287" published="2007-01-16" seq="2007-0287" severity="Low" type="CVE"><desc><descript source="cve">Unspecified vulnerability in Oracle Application Server 9.0.4.3, 10.1.2.0.0, and 10.1.2.0.2; and Collaboration Suite 9.0.4.2 and 10.1.2; has unknown impact and attack vectors related to Containers for J2EE, aka OC4J08.</descript></desc><loss_types><conf/></loss_types><range><local/></range><refs><ref adv="1" patch="1" source="" url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujan2007.html"></ref><ref patch="1" source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA07-017A.html">TA07-017A</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/23794">23794</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1017522">
1017522</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31541">
oracle-cpu-jan2007(31541)</ref><ref source="BID" url="http://www.securityfocus.com/bid/22083">22083</ref></refs><vuln_soft><prod name="Oracle Application Server" vendor="Oracle"><vers num="9.0.4.3"/><vers num="10.1.2.0.2"/><vers num="10.1.2.0.0"/></prod><prod name="Oracle Collaboration Suite" vendor="Oracle"><vers num="9.0.4.2"/><vers num="10.1.2"/></prod></vuln_soft></entry><entry CVSS_base_score="1.7" CVSS_exploit_subscore="3.1" CVSS_impact_subscore="2.9" CVSS_score="1.7" CVSS_vector="(AV:L/AC:L/Au:S/C:P/I:N/A:N)" CVSS_version="2.0" modified="2007-01-19" name="CVE-2007-0288" published="2007-01-16" seq="2007-0288" severity="Low" type="CVE"><desc><descript source="cve">Unspecified vulnerability in Oracle Application Server 10.1.4.0 has unknown impact and attack vectors related to Oracle Internet Directory, aka OID01.</descript></desc><loss_types><conf/></loss_types><range><local/></range><refs><ref adv="1" patch="1" source="" url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujan2007.html"></ref><ref patch="1" source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA07-017A.html">TA07-017A</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/23794">23794</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1017522">
1017522</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31541">
oracle-cpu-jan2007(31541)</ref><ref source="BID" url="http://www.securityfocus.com/bid/22083">22083</ref></refs><vuln_soft><prod name="Oracle Application Server" vendor="Oracle"><vers num="10.1.4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="6.4" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="4.9" CVSS_score="6.4" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_version="2.0" modified="2007-01-19" name="CVE-2007-0289" published="2007-01-16" seq="2007-0289" severity="Medium" type="CVE"><desc><descript source="cve">Multiple unspecified vulnerabilities in Oracle Collaboration Suite 9.0.4.2 have unknown impact and attack vectors related to Oracle Containers for J2EE, aka (1) OC4J01, (2) OC4J05, and (3) OC4J06.</descript></desc><loss_types><conf/><int/></loss_types><range><network/></range><refs><ref adv="1" patch="1" source="" url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujan2007.html"></ref><ref patch="1" source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA07-017A.html">TA07-017A</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/23794">23794</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1017522">
1017522</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31541">
oracle-cpu-jan2007(31541)</ref><ref source="BID" url="http://www.securityfocus.com/bid/22083">22083</ref></refs><vuln_soft><prod name="Oracle Application Server" vendor="Oracle"><vers num="9.0.4.2"/></prod></vuln_soft></entry><entry CVSS_base_score="5.5" CVSS_exploit_subscore="8.0" CVSS_impact_subscore="4.9" CVSS_score="5.5" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:N)" CVSS_version="2.0" modified="2007-01-19" name="CVE-2007-0290" published="2007-01-16" seq="2007-0290" severity="Medium" type="CVE"><desc><descript source="cve">Multiple unspecified vulnerabilities in Oracle E-Business Suite and Applications 11.5.10CU2 have unknown impact and attack vectors related to (1) Application Object Library (APPS01), (2) Human Resources (APPS03), (3) Payables (APPS04), (4) Trading Community Architecture (APPS05), and (5) Web Applications Desktop Integrator (APPS06).</descript></desc><loss_types><conf/><int/></loss_types><range><network/></range><refs><ref adv="1" patch="1" source="" url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujan2007.html"></ref><ref patch="1" source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA07-017A.html">TA07-017A</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/23794">23794</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1017522">
1017522</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31541">
oracle-cpu-jan2007(31541)</ref><ref source="BID" url="http://www.securityfocus.com/bid/22083">22083</ref></refs><vuln_soft><prod name="Oracle E-Business Suite and Application" vendor="Oracle"><vers num="11.5.10 CU 2"/></prod></vuln_soft></entry><entry CVSS_base_score="4.0" CVSS_exploit_subscore="8.0" CVSS_impact_subscore="2.9" CVSS_score="4.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:N/A:N)" CVSS_version="2.0" modified="2007-01-19" name="CVE-2007-0291" published="2007-01-16" seq="2007-0291" severity="Medium" type="CVE"><desc><descript source="cve">Unspecified vulnerability in Oracle E-Business Suite and Applications 6.2.3 has unknown impact and attack vectors related to Oracle Exchange, aka APPS02.</descript></desc><loss_types><conf/></loss_types><range><network/></range><refs><ref adv="1" patch="1" source="" url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujan2007.html"></ref><ref patch="1" source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA07-017A.html">TA07-017A</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/23794">23794</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1017522">
1017522</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31541">
oracle-cpu-jan2007(31541)</ref><ref source="BID" url="http://www.securityfocus.com/bid/22083">22083</ref></refs><vuln_soft><prod name="Oracle E-Business Suite and Applications" vendor="Oracle"><vers num="6.2.3"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-08-07" name="CVE-2007-0292" published="2007-01-16" seq="2007-0292" severity="High" type="CVE"><desc><descript source="cve">Multiple unspecified vulnerabilities in Oracle Enterprise Manager 10.1.0.5 have unknown impact and attack vectors related to Oracle Agent, aka (1) EM01 and (2) EM02.  NOTE: EM05 might be related to CVE-2007-0222.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs><ref adv="1" patch="1" source="" url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujan2007.html"></ref><ref patch="1" source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA07-017A.html">TA07-017A</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/23794">23794</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1017522">1017522</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31541">oracle-cpu-jan2007(31541)</ref><ref source="BID" url="http://www.securityfocus.com/bid/22083">22083</ref></refs><vuln_soft><prod name="Oracle Enterprise Manager" vendor="Oracle"><vers num="10.1.0.5"/></prod></vuln_soft></entry><entry CVSS_base_score="6.4" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="4.9" CVSS_score="6.4" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_version="2.0" modified="2007-08-07" name="CVE-2007-0293" published="2007-01-16" seq="2007-0293" severity="Medium" type="CVE"><desc><descript source="cve">Multiple unspecified vulnerabilities in Oracle Enterprise Manager 10.1.0.5 and 10.2.0.1 have unknown impact and attack vectors related to (1) Oracle Agent (EM03) and (2) EM04 and (3) EM05 in Enterprise Manager Console.  NOTE: EM05 might be related to CVE-2007-0222.</descript></desc><loss_types><conf/><int/></loss_types><range><network/></range><refs><ref adv="1" patch="1" source="" url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujan2007.html"></ref><ref patch="1" source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA07-017A.html">TA07-017A</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/23794">23794</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1017522">1017522</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31541">oracle-cpu-jan2007(31541)</ref><ref source="BID" url="http://www.securityfocus.com/bid/22083">22083</ref></refs><vuln_soft><prod name="Oracle Enterprise Manager" vendor="Oracle"><vers num="10.1.0.5"/><vers num="10.2.0.1"/></prod></vuln_soft></entry><entry CVSS_base_score="1.7" CVSS_exploit_subscore="3.1" CVSS_impact_subscore="2.9" CVSS_score="1.7" CVSS_vector="(AV:L/AC:L/Au:S/C:P/I:N/A:N)" CVSS_version="2.0" modified="2007-01-19" name="CVE-2007-0294" published="2007-01-16" seq="2007-0294" severity="Low" type="CVE"><desc><descript source="cve">Unspecified vulnerability in Oracle Enterprise Manager 10.2.0.1 has unknown impact and attack vectors related to Database Cloning &amp; Data Guard Management, aka EM06.</descript></desc><loss_types><conf/></loss_types><range><local/></range><refs><ref adv="1" patch="1" source="" url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujan2007.html"></ref><ref patch="1" source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA07-017A.html">TA07-017A</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/23794">23794</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1017522">
1017522</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31541">
oracle-cpu-jan2007(31541)</ref><ref source="BID" url="http://www.securityfocus.com/bid/22083">22083</ref></refs><vuln_soft><prod name="Oracle Enterprise Manager" vendor="Oracle"><vers num="10.2.0.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.8" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.9" CVSS_score="7.8" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_version="2.0" modified="2007-01-19" name="CVE-2007-0295" published="2007-01-16" seq="2007-0295" severity="High" type="CVE"><desc><descript source="cve">Unspecified vulnerability in Oracle PeopleSoft Enterprise and JD Edwards EnterpriseOne 8.22.13 and 8.47.11 has unknown impact and attack vectors in PeopleTools, aka PSE01.</descript></desc><loss_types><avail/></loss_types><range><network/></range><refs><ref patch="1" source="" url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujan2007.html"></ref><ref patch="1" source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA07-017A.html">TA07-017A</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/23794">23794</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1017522">
1017522</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31541">
oracle-cpu-jan2007(31541)</ref><ref source="BID" url="http://www.securityfocus.com/bid/22083">22083</ref></refs><vuln_soft><prod name="JD Edwards EnterpriseOne" vendor="Oracle"><vers num="8.22.13"/><vers num="8.47.11"/></prod><prod name="PeopleSoft Enterprise" vendor="Oracle"><vers num="8.22.13"/><vers num="8.47.11"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0" modified="2007-01-19" name="CVE-2007-0296" published="2007-01-16" seq="2007-0296" severity="Low" type="CVE"><desc><descript source="cve">Unspecified vulnerability in Oracle PeopleSoft Enterprise and JD Edwards EnterpriseOne 8.22.13, 8.47.11, and 8.48.06 has unknown impact and attack vectors in PeopleTools, aka PSE02.</descript></desc><loss_types><conf/></loss_types><range><local/></range><refs><ref adv="1" patch="1" source="" url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujan2007.html"></ref><ref patch="1" source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA07-017A.html">TA07-017A</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/23794">23794</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1017522">
1017522</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31541">
oracle-cpu-jan2007(31541)</ref><ref source="BID" url="http://www.securityfocus.com/bid/22083">22083</ref></refs><vuln_soft><prod name="JD Edwards EnterpriseOne" vendor="Oracle"><vers num="8.22.13"/><vers num="8.47.11"/><vers num="8.48.06"/></prod><prod name="PeopleSoft Enterprise" vendor="Oracle"><vers num="8.22.13"/><vers num="8.47.11"/><vers num="8.48.06"/></prod></vuln_soft></entry><entry CVSS_base_score="4.0" CVSS_exploit_subscore="8.0" CVSS_impact_subscore="2.9" CVSS_score="4.0" CVSS_vector="(AV:N/AC:L/Au:S/C:N/I:P/A:N)" CVSS_version="2.0" modified="2007-01-19" name="CVE-2007-0297" published="2007-01-16" seq="2007-0297" severity="Medium" type="CVE"><desc><descript source="cve">Unspecified vulnerability in Oracle PeopleSoft Enterprise and JD Edwards EnterpriseOne 8.47.11 and 8.48.06 has unknown impact and attack vectors in PeopleTools, aka PSE03.</descript></desc><loss_types><int/></loss_types><range><network/></range><refs><ref adv="1" patch="1" source="" url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujan2007.html"></ref><ref patch="1" source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA07-017A.html">TA07-017A</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/23794">23794</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1017522">
1017522</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31541">
oracle-cpu-jan2007(31541)</ref><ref source="BID" url="http://www.securityfocus.com/bid/22083">22083</ref></refs><vuln_soft><prod name="JD Edwards EnterpriseOne" vendor="Oracle"><vers num="8.47.11"/><vers num="8.48.06"/></prod><prod name="PeopleSoft Enterprise" vendor="Oracle"><vers num="8.47.11"/><vers num="8.48.06"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-01-17" name="CVE-2007-0298" published="2007-01-17" seq="2007-0298" severity="Medium" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in show.php in LunarPoll, when register_globals is enabled, allows remote attackers execute arbitrary PHP code via a URL in the PollDir parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/456697/100/0/threaded">20070112 LunarPoll (PollDir) Remote File Include Vulnerabilities</ref><ref source="VIM" url="http://attrition.org/pipermail/vim/2007-January/001236.html">20070112 Source Verify of LunarPoll PollDir RFI</ref><ref source="BID" url="http://www.securityfocus.com/bid/22024">22024</ref><ref source="MILW0RM" url="http://milw0rm.com/exploits/3117">
3117</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0177">
ADV-2007-0177</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1017510">
1017510</ref><ref source="SECUNIA" url="http://secunia.com/advisories/23760">
23760</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31472">
lunarpoll-show-file-include(31472)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2152">2152</ref></refs><vuln_soft><prod name="LunarPoll" vendor="Dexxaboy"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.1" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.9" CVSS_score="7.1" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:C)" CVSS_version="2.0" modified="2007-06-26" name="CVE-2007-0299" published="2007-01-17" seq="2007-0299" severity="High" type="CVE"><desc><descript source="cve">Integer overflow in the byte_swap_sbin function in bsd/ufs/ufs/ufs_byte_order.c in Mac OS X 10.4.8 allows user-assisted remote attackers to cause a denial of service (kernel panic) by mounting a crafted Unix File System (UFS) DMG image, which triggers an invalid pointer dereference.</descript></desc><loss_types><avail/></loss_types><vuln_types><design/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" source="" url="http://projects.info-pull.com/moab/MOAB-11-01-2007.html"></ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/23725">23725</ref><ref source="" url="http://docs.info.apple.com/article.html?artnum=305214"></ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/515792">VU#515792</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0930">ADV-2007-0930</ref><ref source="OSVDB" url="http://www.osvdb.org/31653">31653</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017751">1017751</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24479">24479</ref><ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2007/Mar/msg00002.html">APPLE-SA-2007-03-13</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA07-072A.html">TA07-072A</ref></refs><vuln_soft><prod name="Mac OS X" vendor="Apple"><vers num="10.4.8"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-01-18" name="CVE-2007-0300" published="2007-01-17" seq="2007-0300" severity="Medium" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in i-accueil.php in TLM CMS 1.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the chemin parameter.</descript></desc><sols><sol source="nvd">Successful exploitation requires that &quot;register_globals&quot; is enabled.</sol></sols><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="Milw0rm" url="http://milw0rm.com/exploits/3118">Exploit 3118</ref><ref source="BID" url="http://www.securityfocus.com/bid/22021">22021</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0176">ADV-2007-0176</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/23722">23722</ref></refs><vuln_soft><prod name="TLM CMS" vendor="TLM CMS"><vers num="1.1" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-01-18" name="CVE-2007-0301" published="2007-01-17" seq="2007-0301" severity="Medium" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in _admin/admin_menu.php in FdWeB Espace Membre 2.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the path parameter.</descript></desc><sols><sol source="nvd">Successful exploitation requires that &quot;register_globals&quot; is enabled.</sol></sols><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="Milw0rm" url="http://milw0rm.com/exploits/3123">Exploit 3123</ref><ref source="BID" url="http://www.securityfocus.com/bid/22040">22040</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0178">ADV-2007-0178</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/23743">23743</ref></refs><vuln_soft><prod name="Espace Membre" vendor="FdWeB"><vers num="2.1" prev="1"/><vers num="2.01"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-01-18" name="CVE-2007-0302" published="2007-01-17" seq="2007-0302" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in InstantASP 4.1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) SessionID parameter to (a) Logon.aspx, and the (2) Username and (3) Update parameters to (b) Members1.aspx.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/456970/100/0/threaded">20070115 InstantForum.NET Multiple Cross-Site Scripting Vulnerability</ref><ref source="BID" url="http://www.securityfocus.com/bid/22052">22052</ref><ref source="SECUNIA" url="http://secunia.com/advisories/23787">23787</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0227">
ADV-2007-0227</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31521">
instantforum-multiple-scripts-xss(31521)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2164">2164</ref></refs><vuln_soft><prod name="InstantASP" vendor="InstantASP"><vers num="4.1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-01-18" name="CVE-2007-0303" published="2007-01-17" seq="2007-0303" severity="High" type="CVE"><desc><descript source="cve">Multiple unspecified vulnerabilities in Zina 1.0rc1 and earlier have unknown impact and attack vectors related to &quot;Potential security bugs.&quot;</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs><ref adv="1" source="" url="http://www.pancake.org/zina-changelog-12"></ref><ref source="BID" url="http://www.securityfocus.com/bid/22049">22049</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0181">ADV-2007-0181</ref></refs><vuln_soft><prod name="Zina" vendor="Pancake.org"><vers num="1.0 RC1" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-07-03" name="CVE-2007-0304" published="2007-01-17" seq="2007-0304" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in duyuru.asp in MiNT Haber Sistemi 2.7 allows remote attackers to execute arbitrary SQL commands via the id parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://www.milw0rm.com/exploits/3120"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0175">ADV-2007-0175</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/23756">23756</ref><ref source="MILW0RM" url="http://milw0rm.com/exploits/3120">3120</ref></refs><vuln_soft><prod name="Haber Sistemi" vendor="MiNT"><vers num="2.7" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-01-18" name="CVE-2007-0305" published="2007-01-17" seq="2007-0305" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in etkinlikbak.asp in Okul Web Otomasyon Sistemi 4.0.1 allows remote attackers to execute arbitrary SQL commands via the id parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/456894/100/0/threaded">20070115 Okul Web Otomasyon Sistemi (etkinlikbak.asp) SQL Injection Vulnerability</ref><ref source="" url="http://www.milw0rm.com/exploits/3135"></ref><ref source="BID" url="http://www.securityfocus.com/bid/22060">22060</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/23755">23755</ref><ref source="MILW0RM" url="http://milw0rm.com/exploits/3135">
3135</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0206">
ADV-2007-0206</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2151">2151</ref></refs><vuln_soft><prod name="Otomasyon Sistemi" vendor="Okulsistem Okul Web"><vers num="4.0.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-01-18" name="CVE-2007-0306" published="2007-01-17" seq="2007-0306" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in visu_user.asp in Digiappz DigiAffiliate 1.4 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://milw0rm.com/exploits/3122"></ref><ref source="BID" url="http://www.securityfocus.com/bid/22039">22039</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0179">ADV-2007-0179</ref><ref source="SECUNIA" url="http://secunia.com/advisories/23744">23744</ref></refs><vuln_soft><prod name="DigiAffiliate" vendor="Digiappz"><vers num="1.4" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-01-18" name="CVE-2007-0307" published="2007-01-17" seq="2007-0307" severity="High" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in include/common.php in Poplar Gedcom Viewer 2.0 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the env[rootPath] parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://milw0rm.com/exploits/3121"></ref><ref source="BID" url="http://www.securityfocus.com/bid/22038">22038</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0174">ADV-2007-0174</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/23761">23761</ref></refs><vuln_soft><prod name="Poplar Gedcom Viewer" vendor="Poplar Gedcom Viewer"><vers num="2.0" prev="1"/><vers num="1.2.2"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-01-18" name="CVE-2007-0308" published="2007-01-17" seq="2007-0308" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in Plain Black WebGUI before 7.3.4 (beta) allows remote attackers to inject arbitrary web script or HTML via Wiki Page titles.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref patch="1" source="" url="http://www.plainblack.com/getwebgui/advisories/webgui-7_3_4-beta-released#BUeIjcWiQasypsJxD-YwgQ"></ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/22051">22051</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/23718">23718</ref></refs><vuln_soft><prod name="WebGUI" vendor="Plain Black"><vers num="7.2.3"/><vers num="6.8.6"/><vers num="6.8.5"/><vers num="6.8.4"/><vers num="6.8.3"/><vers num="6.8.2"/><vers num="6.8.1"/><vers num="6.7.6"/><vers num="6.7.5"/><vers num="6.7.4"/><vers num="6.7.3"/><vers num="6.7.2"/><vers num="6.7.1"/><vers num="6.7.0"/><vers num="6.6.5"/><vers num="6.6.4"/><vers num="6.6.3"/><vers num="6.6.2"/><vers num="6.6.1"/><vers num="6.6.0"/><vers num="6.5.6"/><vers num="6.5.5"/><vers num="6.5.4"/><vers num="6.5.3"/><vers num="6.5.2"/><vers num="6.5.1"/><vers num="6.5.0"/><vers num="6.4.0"/><vers num="6.3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-01-18" name="CVE-2007-0309" published="2007-01-17" seq="2007-0309" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in blocks/block-Old_Articles.php in Francisco Burzi PHP-Nuke 7.9 and earlier, when register_globals is enabled and magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the cat parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/456787/100/0/threaded">20070113 PHP-Nuke &lt;= 7.9 Old-Articles Block </ref><ref source="" url="http://www.neosecurityteam.net/advisories/PHP-Nuke--7.9-Old-Articles-Block-cat-SQL-Injection-vulnerability-31.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/22037">22037</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1017511">1017511</ref><ref source="SECUNIA" url="http://secunia.com/advisories/23748">
23748</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31482">
phpnuke-blockoldarticles-sql-injection(31482)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2153">2153</ref></refs><vuln_soft><prod name="PHP-Nuke" vendor="Francisco Burzi"><vers num="7.9" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0" modified="2007-01-18" name="CVE-2007-0310" published="2007-01-17" seq="2007-0310" severity="Medium" type="CVE"><desc><descript source="cve">BMC Remedy Action Request System 5.01.02 Patch 1267 generates different error messages for failed login attempts with a valid username than for those with an invalid username, which allows remote attackers to determine valid account names.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/456949/100/0/threaded">20070115 Remedy Action Request System 5.01.02 - User Enumeration</ref><ref adv="1" source="" url="http://www.alighieri.org/advisories/advisory-remedy50102.txt"></ref><ref source="BID" url="http://www.securityfocus.com/bid/22066">22066</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/23775">23775</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/457078/100/0/threaded">
20070116 Re: Remedy Action Request System 5.01.02 - User Enumeration</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0204">
ADV-2007-0204</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1017515">
1017515</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31527">
rars-login-information-disclosure(31527)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2162">2162</ref></refs><vuln_soft><prod name="Remedy Action Request System" vendor="BMC Software"><vers num="5.01.02 Patch 1267"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0" modified="2007-01-18" name="CVE-2007-0311" published="2007-01-17" seq="2007-0311" severity="Medium" type="CVE"><desc><descript source="cve">Texas Imperial Software WFTPD and WFTPD Pro Server 3.25 and earlier allow remote attackers to cause a denial of service (application crash) via a long SITE ADMIN command.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref source="" url="http://www.milw0rm.com/exploits/3126"></ref><ref source="BID" url="http://www.securityfocus.com/bid/22046">22046</ref><ref source="MILW0RM" url="http://milw0rm.com/exploits/3126">

3126</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31517">
wftpd-admn-dos(31517)</ref></refs><vuln_soft><prod name="WFTPD Pro Server" vendor="Texas Imperial Software"><vers num="3.25" prev="1"/></prod><prod name="WFTPD" vendor="Texas Imperial Software"><vers num="3.25" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.8" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.9" CVSS_score="7.8" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:N/A:N)" CVSS_version="2.0" modified="2007-01-18" name="CVE-2007-0312" published="2007-01-17" seq="2007-0312" severity="High" type="CVE"><desc><descript source="cve">wcSimple Poll stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain password hashes via a direct request for password.txt.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/456982/100/0/threaded">20070114 wcSimple Poll (password.txt) Remote Password Disclosure Vulnerablity</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2157">2157</ref></refs><vuln_soft><prod name="wcSimple Poll" vendor="wcSimple Poll"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="9.0" CVSS_exploit_subscore="8.0" CVSS_impact_subscore="10.0" CVSS_score="9.0" CVSS_vector="(AV:N/AC:L/Au:S/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-01-18" name="CVE-2007-0313" published="2007-01-17" seq="2007-0313" severity="High" type="CVE"><desc><descript source="cve">Unspecified vulnerability in GONICUS System Administration (GOsa) before 2.5.8 allows remote authenticated users to modify certain settings, including the admin password, via crafted POST requests.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref patch="1" source="MLIST" url="http://oss.gonicus.de/pipermail/gosa/2007-January/002650.html">[gosa] 20070115 GOsa 2.5.8 released (security fixes!)</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0207">ADV-2007-0207</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/23749">23749</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31516">
gosa-unspecified-data-manipulation(31516)</ref></refs><vuln_soft><prod name="GONICUS System Administration" vendor="GONICUS"><vers num="2.5.7" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-01-18" name="CVE-2007-0314" published="2007-01-17" seq="2007-0314" severity="High" type="CVE"><desc><descript source="cve">Multiple PHP remote file inclusion vulnerabilities in Article System 1.0 allow remote attackers to execute arbitrary PHP code via a URL in the INCLUDE_DIR parameter to (1) forms.php, (2) issue_edit.php, (3) client.php, and (4) classes.php.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://www.milw0rm.com/exploits/3114"></ref><ref source="BID" url="http://www.securityfocus.com/bid/22017">22017</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31446">article-system-includedir-file-include(31446)</ref><ref source="MILW0RM" url="http://milw0rm.com/exploits/3114">

3114</ref></refs><vuln_soft><prod name="Article System" vendor="Article System"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" CVSS_score="9.3" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-02-08" name="CVE-2007-0315" published="2007-01-17" seq="2007-0315" severity="High" type="CVE"><desc><descript source="cve">Multiple buffer overflows in FileZilla before 2.2.30a allow remote attackers to execute arbitrary code or cause a denial of service (application crash) via unspecified vectors related to (1) Options.cpp when sotring settings in the registry, and (2) the transfer queue (QueueCtrl.cpp).  NOTE: some of these details are obtained from third party information.</descript></desc><sols><sol source="nvd">Failed exploit attempts may result in a application level denial-of-service condition.</sol></sols><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/><user_init/></range><refs><ref patch="1" source="" url="http://sourceforge.net/project/shownotes.php?release_id=475423&amp;group_id=21558">Release Name: 2.2.30a</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/22057">22057</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0183">ADV-2007-0183</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/31500">filezilla-options-queuectrl-bo(31500)</ref></refs><vuln_soft><prod name="FileZilla" vendor="FileZilla"><vers num="2.2.30"/><vers num="2.2.29"/><vers num="2.2.28"/><vers num="2.2.28"/><vers num="2.2.27"/><vers num="2.2.26"/><vers num="2.2.25"/><vers num="2.2.24"/><vers num="2.2.23"/><vers num="2.2.22"/><vers num="2.2.22"/><vers num="2.2.15"/><vers num="0.9.22"/><vers num="0.9.21"/><vers num="0.9.20"/><vers num="2.2.26a"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-01-18" name="CVE-2007-0316" published="2007-01-17" seq="2007-0316" severity="High" type="CVE"><desc><descript source="cve">Multiple SQL injection vulnerabilities in All In One Control Panel (AIOCP) 1.3.010 and earlier, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) xuser_name parameter to shared/code/cp_authorization.php, and the (2) did parameter to public/code/cp_downloads.php, different vectors than CVE-2007-0223.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/456742">20070112 AIOCP Login Bypass Vulnerability</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/456741">20070112 AIOCP SQL Injection Vulnerability</ref><ref source="BID" url="http://www.securityfocus.com/bid/22032">22032</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0190">ADV-2007-0190</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/23740">23740</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2166">2166</ref></refs><vuln_soft><prod name="All In One Control Panel" vendor="All In One Control Panel"><vers num="1.3.010" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-01-18" name="CVE-2007-0317" published="2007-01-17" seq="2007-0317" severity="High" type="CVE"><desc><descript source="cve">Format string vulnerability in the LogMessage function in FileZilla before 3.0.0-beta5 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via crafted arguments.  NOTE: some of these details are obtained from third party information.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref patch="1" source="" url="http://sourceforge.net/project/shownotes.php?release_id=477793&amp;group_id=21558"></ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/22063">22063</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0182">ADV-2007-0182</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/31497">filezilla-logmessage-format-string(31497)</ref></refs><vuln_soft><prod name="FileZilla" vendor="FileZilla"><vers num="3.0.0 Beta4" prev="1"/><vers num="3.0.0 Beta2"/><vers num="3.0.0 Beta1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.8" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.9" CVSS_score="7.8" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_version="2.0" modified="2007-01-18" name="CVE-2007-0318" published="2007-01-17" seq="2007-0318" severity="High" type="CVE"><desc><descript source="cve">The do_hfs_truncate function in Mac OS X 10.4.8 allows context-dependent attackers to cause a denial of service (kernel panic) via a crafted HFS+ filesystem in a DMG image, which causes an access of an invalid vnode structure during file removal.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/23742">23742</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0171">ADV-2007-0171</ref><ref source="" url="http://projects.info-pull.com/moab/MOAB-13-01-2007.html"></ref><ref source="" url="http://docs.info.apple.com/article.html?artnum=305214"></ref><ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2007/Mar/msg00002.html">
APPLE-SA-2007-03-13</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0930">
ADV-2007-0930</ref><ref source="OSVDB" url="http://www.osvdb.org/32685">
32685</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017759">
1017759</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24479">
24479</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA07-072A.html">TA07-072A</ref></refs><vuln_soft><prod name="Mac OS X" vendor="Apple"><vers num="10.4.8"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-08-16" name="CVE-2007-0319" published="2007-08-15" seq="2007-0319" severity="Medium" type="CVE"><desc><descript source="cve">Multiple stack-based buffer overflows in the Motive ActiveEmailTest.EmailData (ActiveUtils EmailData) ActiveX control in ActiveUtils.dll in Motive Service Activation Manager 5.1 and Self Service Manager 5.1 and earlier allow remote attackers to execute arbitrary code via unspecified vectors.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/><user_init/></range><refs><ref source="" url="http://www.motive.com/securitybulletin_08122007.asp"></ref><ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms07-045.mspx">MS07-045</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/747233">VU#747233</ref><ref source="BID" url="http://www.securityfocus.com/bid/25312">25312</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/2881">ADV-2007-2881</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1018571">1018571</ref><ref source="SECUNIA" url="http://secunia.com/advisories/26481">26481</ref></refs><vuln_soft><prod name="Service Activation Manager" vendor="Motive Incorporated"><vers num="5.1"/></prod><prod name="Self Service Manager" vendor="Motive Incorporated"><vers num="5.1"/></prod></vuln_soft></entry><entry CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" CVSS_score="9.3" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-09-27" name="CVE-2007-0320" published="2007-02-22" seq="2007-0320" severity="High" type="CVE"><desc><descript source="cve">Multiple buffer overflows in (a) an ActiveX control (iftw.dll) and (b) Netscape plug-in (npiftw32.dll) for Macrovision (formerly InstallShield) InstallFromTheWeb allow remote attackers to execute arbitrary code via crafted HTML documents.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><range><network/><user_init/></range><refs><ref source="" url="http://www.kb.cert.org/vuls/id/MAPG-6UQUDP"></ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/181041">VU#181041</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0705">ADV-2007-0705</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24285">24285</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32645">InstallshieldInstallfromtheweb-activex-bo(32645)</ref></refs><vuln_soft><prod name="InstallFromTheWeb" vendor="Macrovision"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" CVSS_score="9.3" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-06-04" name="CVE-2007-0321" published="2007-02-22" seq="2007-0321" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in the Update Service Agent ActiveX Control in isusweb.dll for Macrovision FLEXnet Connect (formerly InstallShield Update Service) allows remote attackers to execute arbitrary code via the Download method.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><range><network/><user_init/></range><refs><ref source="" url="http://www.kb.cert.org/vuls/id/MAPG-6UERNR"></ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/847993">VU#847993</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0706">ADV-2007-0706</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24270">24270</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32678">macrovision-updateservice-activex-bo(32678)</ref></refs><vuln_soft><prod name="FLEXnet Connect" vendor="Macrovision"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" CVSS_score="9.3" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-09-11" name="CVE-2007-0322" published="2007-09-05" seq="2007-0322" severity="High" type="CVE"><desc><descript source="cve">Multiple stack-based buffer overflows in the Intuit QuickBooks Online Edition ActiveX control before 10 allow remote attackers to execute arbitrary code via unspecified vectors.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/><user_init/></range><refs><ref adv="1" patch="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/907481">VU#907481</ref><ref source="BID" url="http://www.securityfocus.com/bid/25544">25544</ref><ref source="SECUNIA" url="http://secunia.com/advisories/26659">26659</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/36462">quickbooks-activex-bo(36462)</ref></refs><vuln_soft><prod name="Quickbooks" vendor="Intuit"><vers edition="Online" num="Unknown"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-05-09" name="CVE-2007-0323" published="2007-05-08" seq="2007-0323" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in the SetLanguage function in Research In Motion (RIM) TeamOn Import Object ActiveX control (TOImport.dll) allows remote attackers to execute arbitrary code via unspecified vectors.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref patch="1" source="MS" url="http://www.microsoft.com/technet/security/Bulletin/MS07-027.mspx">MS07-027</ref><ref patch="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/869641">VU#869641</ref><ref source="BID" url="http://www.securityfocus.com/bid/23331">
23331</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1716">
ADV-2007-1716</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25218">
25218</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/34182">
rim-toimport-activex-bo(34182)</ref><ref source="" url="http://www.blackberry.com/btsc/articles/74/KB13142_f.SAL_Public.html"></ref><ref source="HP" url="http://www.securityfocus.com/archive/1/archive/1/468871/100/200/threaded">HPSBST02214</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA07-128A.html">TA07-128A</ref></refs><vuln_soft><prod name="TeamOn Import Object ActiveX Control" vendor="RIM"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-02-18" name="CVE-2007-0324" published="2007-02-15" seq="2007-0324" severity="High" type="CVE"><desc><descript source="cve">Multiple buffer overflows in the LizardTech DjVu Browser Plug-in before 6.1.1 allow remote attackers to execute arbitrary code via unspecified vectors.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref patch="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/460197/100/0/threaded">20070215 Lizardtech DjVu Browser Plug-in - Multiple Vulnerabilities</ref><ref source="" url="http://www.lizardtech.com/products/doc/djvupluginrelease.php"></ref><ref patch="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/522393">VU#522393</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/22569">22569</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/24149">24149</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0618">
ADV-2007-0618</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32510">
djvu-browser-multiple-bo(32510)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2259">2259</ref></refs><vuln_soft><prod name="DjVu Browser Plug-in" vendor="LizardTech"><vers num="6.0.1"/><vers num="6.1"/><vers num="6.0"/></prod></vuln_soft></entry><entry CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" CVSS_score="9.3" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-02-22" name="CVE-2007-0325" published="2007-02-20" seq="2007-0325" severity="High" type="CVE"><desc><descript source="cve">Multiple buffer overflows in the Trend Micro OfficeScan Web-Deployment SetupINICtrl ActiveX control in OfficeScanSetupINI.dll, as used in OfficeScan 7.0 before Build 1344, OfficeScan 7.3 before Build 1241, and Client / Server / Messaging Security 3.0 before Build 1197, allow remote attackers to execute arbitrary code via a crafted HTML document.</descript></desc><impacts><impact source="nvd">Successful exploitation requires that OfficeScan client was installed using web deployment.</impact></impacts><sols><sol source="nvd">The vendor has issued a fix (7.0 Security Patch - Build 1344; 7.3 Security Patch - Build 1241).
</sol></sols><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref source="" url="http://esupport.trendmicro.com/support/viewxml.do?ContentID=EN-1034288"></ref><ref source="" url="http://www.trendmicro.com/ftp/documentation/readme/osce_70_win_en_securitypatch_1344_readme.txt"></ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/784369">VU#784369</ref><ref source="BID" url="http://www.securityfocus.com/bid/22585">22585</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0638">ADV-2007-0638</ref><ref adv="1" source="SECTRACK" url="http://www.securitytracker.com/id?1017664">1017664</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/24193">24193</ref></refs><vuln_soft><prod name="OfficeScan Corporate Edition" vendor="Trend Micro"><vers num="7.0"/><vers num="7.3"/></prod><prod name="Client-Server-Messaging Security" vendor="Trend Micro"><vers num="3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" CVSS_score="9.3" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-10-03" name="CVE-2007-0326" published="2007-09-18" seq="2007-0326" severity="High" type="CVE"><desc><descript source="cve">Multiple stack-based buffer overflows in the PhotoChannel Networks PNI Digital Media Photo Upload Plugin ActiveX control before 2.0.0.10, as used by multiple retailers, allow remote attackers to execute arbitrary code via unspecified vectors.</descript></desc><sols><sol source="nvd">This vulnerability is addressed in the following product release:
PhotoChannel, PNI Digital Media Photo Upload Plugin ActiveX control, 2.0.0.10</sol></sols><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><range><network/></range><refs><ref patch="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/854769">VU#854769</ref><ref source="BID" url="http://www.securityfocus.com/bid/25685">25685</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/3181">ADV-2007-3181</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1018701">1018701</ref><ref source="SECUNIA" url="http://secunia.com/advisories/26830">26830</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/36643">photochannel-photo-upload-bo(36643)</ref></refs><vuln_soft><prod name="pni digital media upload plugin activex control" vendor="photochannel"><vers num="2.0.0.9" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" CVSS_score="9.3" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-12-28" name="CVE-2007-0328" published="2007-05-31" seq="2007-0328" severity="High" type="CVE"><desc><descript source="cve">The DWUpdateService ActiveX control in the agent (agent.exe) in Macrovision FLEXnet Connect 6.0 and Update Service 3.x to 5.x allows remote attackers to execute arbitrary commands via (1) the Execute method, and obtain the exit status using (2) the GetExitCode method.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><access/></vuln_types><range><network/><user_init/></range><refs><ref patch="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/524681">VU#524681</ref><ref patch="1" source="" url="http://support.installshield.com/kb/view.asp?articleid=Q113020"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/2017">ADV-2007-2017</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/25501">25501</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/34660">macrovision-dwupdate-command-execution(34660)</ref></refs><vuln_soft><prod name="FLEXnet Connect" vendor="Macrovision"><vers num="6.0"/></prod><prod name="Update Service" vendor="Macrovision"><vers num="3.0"/><vers num="4.0"/><vers num="5.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0" modified="2007-01-18" name="CVE-2007-0329" published="2007-01-17" seq="2007-0329" severity="Medium" type="CVE"><desc><descript source="cve">download.php in Joonas Viljanen JV2 Folder Gallery allows remote attackers to read sensitive files via a relative pathname in the file parameter, as demonstrated by config/gallerysetup.php.  NOTE: this issue might be resultant from a directory traversal vulnerability.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref source="" url="http://www.milw0rm.com/exploits/3125"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0180">ADV-2007-0180</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/23724">23724</ref><ref source="MILW0RM" url="http://milw0rm.com/exploits/3125">

3125</ref></refs><vuln_soft><prod name="JV2 Folder Gallery" vendor="Joonas Viljanen"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-02-05" name="CVE-2007-0330" published="2007-01-17" seq="2007-0330" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in wsbho2k0.dll, as used by wsftpurl.exe, in Ipswitch WS_FTP 2007 Professional allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a long ftp:// URL in an HTML document, and possibly other vectors.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/456755/100/0/threaded">20070112 Ipswitch WS_FTP 2007 Professional </ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/456901/100/0/threaded">20070114 Re: Ipswitch WS_FTP 2007 Professional </ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/457097/100/0/threaded">20070116 Re: Ipswitch WS_FTP 2007 Professional </ref><ref source="BID" url="http://www.securityfocus.com/bid/22062">22062</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2160">2160</ref></refs><vuln_soft><prod name="WS_FTP Pro" vendor="Ipswitch"><vers num="2007"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-01-18" name="CVE-2007-0331" published="2007-01-17" seq="2007-0331" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in liens.php3 in liens_dynamiques 2.1 allows remote attackers to inject arbitrary web script or HTML by using the ajouter=1 query string and the add menu.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/456986/100/0/threaded">20070114 liens_dynamiques xss and admin authentification</ref><ref source="BID" url="http://www.securityfocus.com/bid/22070">22070</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31528">
liensdynamiques-liens-xss(31528)</ref></refs><vuln_soft><prod name="liens_dynamiques" vendor="Xentraz"><vers num="2.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-01-18" name="CVE-2007-0332" published="2007-01-17" seq="2007-0332" severity="High" type="CVE"><desc><descript source="cve">(1) admin/adminlien.php3 and (2) admin/modif.php3 in liens_dynamiques 2.1 do not require authentication, which allows remote attackers to perform unauthorized administrative actions using a direct request.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/456986/100/0/threaded">20070114 liens_dynamiques xss and admin authentification</ref><ref source="BID" url="http://www.securityfocus.com/bid/22068">22068</ref></refs><vuln_soft><prod name="liens_dynamiques" vendor="Xentraz"><vers num="2.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-01-19" name="CVE-2007-0333" published="2007-01-17" seq="2007-0333" severity="High" type="CVE"><desc><descript source="cve">Agnitum Outpost Firewall PRO 4.0 allows local users to bypass access restrictions and insert Trojan horse drivers into the product&apos;s installation directory by creating links using FileLinkInformation requests with the ZwSetInformationFile function, as demonstrated by modifying SandBox.sys.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/456973/100/0/threaded">20070115 Outpost Bypassing Self-Protection using file links Vulnerability</ref><ref adv="1" source="" url="http://www.matousec.com/info/advisories/Outpost-Bypassing-Self-Protection-using-file-links.php"></ref><ref source="BID" url="http://www.securityfocus.com/bid/22069">22069</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31529">
outpostfirewall-zwset-privilege-escalation(31529)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2163">2163</ref></refs><vuln_soft><prod name="Outpost Firewall" vendor="Agnitum"><vers edition="Pro" num="4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-01-21" name="CVE-2007-0334" published="2007-01-17" seq="2007-0334" severity="High" type="CVE"><desc><descript source="cve">Unspecified vulnerability in the SIP module in InGate Firewall and SIParator before 4.5.1 allows remote attackers to conduct replay attacks on the authentication mechanism via unknown vectors.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref source="" url="http://www.ingate.com/relnote-451.php"></ref><ref source="BID" url="http://www.securityfocus.com/bid/22080">22080</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/23737">23737</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0209">ADV-2007-0209</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31546">
ingate-sip-security-bypass(31546)</ref></refs><vuln_soft><prod name="Firewall and SIParator" vendor="InGate"><vers num="4.5.0" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-01-21" name="CVE-2007-0335" published="2007-01-17" seq="2007-0335" severity="Medium" type="CVE"><desc><descript source="cve">Multiple directory traversal vulnerabilities in Jax Petition Book 1.0.3.06 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the languagepack parameter to (1) jax_petitionbook.php or (2) smileys.php.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/456981/100/0/threaded">20070114 Jax Petition Book (languagepack) Remote File Include Vulnerabilities</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/456989/100/0/threaded">20070115 Re: Jax Petition Book (languagepack) Remote File Include Vulnerabilities</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/457077/100/0/threaded">20070116 Re: Jax Petition Book (languagepack) Remote File Include Vulnerabilities</ref><ref source="BID" url="http://www.securityfocus.com/bid/22072">22072</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0220">
ADV-2007-0220</ref><ref source="SECUNIA" url="http://secunia.com/advisories/23784">
23784</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31543">
petitionbook-language-file-include(31543)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2161">2161</ref></refs><vuln_soft><prod name="Jax Petition Book" vendor="Jax Scripts"><vers num="1.0.3.06"/></prod></vuln_soft></entry><entry CVSS_base_score="4.4" CVSS_exploit_subscore="3.4" CVSS_impact_subscore="6.4" CVSS_score="4.4" CVSS_vector="(AV:L/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-01-21" name="CVE-2007-0336" published="2007-01-17" seq="2007-0336" severity="Medium" type="CVE"><desc><descript source="cve">Undercover.app/Contents/Resources/uc in Rixstep Undercover allows local users to overwrite arbitrary files, probably related to a race condition.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/><race/></vuln_types><range><local/></range><refs><ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2007-January/051793.html">20070115 Rixstep aren&apos;t as leet as they thought they were</ref><ref source="BID" url="http://www.securityfocus.com/bid/22071">22071</ref></refs><vuln_soft><prod name="Undercover" vendor="Rixstep"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-01-21" name="CVE-2007-0337" published="2007-01-17" seq="2007-0337" severity="High" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in sesskglogadmin.php in KGB 1.9 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the skinnn parameter, as demonstrated by invoking kg.php with a postek parameter containing PHP code, which is injected into a file in the kg directory, and then included by sesskglogadmin.php.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://www.milw0rm.com/exploits/3134"></ref><ref source="BID" url="http://www.securityfocus.com/bid/22065">22065</ref><ref source="MILW0RM" url="http://milw0rm.com/exploits/3134">

3134</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0228">
ADV-2007-0228</ref><ref source="SECUNIA" url="http://secunia.com/advisories/23768">
23768</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31508">
kgb-sesskglogadmin-file-include(31508)</ref></refs><vuln_soft><prod name="KGB" vendor="KGB"><vers num="1.9" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-01-21" name="CVE-2007-0338" published="2007-01-17" seq="2007-0338" severity="High" type="CVE"><desc><descript source="cve">Heap-based buffer overflow in Dream FTP Server allows remote attackers to execute arbitrary code via a USER command with a large number of format string specifiers, which triggers the overflow during processing of the Server Log.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref source="" url="http://milw0rm.com/exploits/3128"></ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/23731">23731</ref></refs><vuln_soft><prod name="DreamFTP Server" vendor="BolinTech"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-01-21" name="CVE-2007-0339" published="2007-01-17" seq="2007-0339" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in index.php (aka the login form) in Scriptme SMe FileMailer 1.21 allows remote attackers to execute arbitrary SQL commands via the Password field (ps parameter).  NOTE: some of these details are obtained from third party information.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/457071/100/0/threaded">20070116 [x0n3-h4ck] SmE FileMailer 1.21 Remote Sql Injextion Exploit</ref><ref source="VIM" url="http://www.attrition.org/pipermail/vim/2007-January/001244.html">20070117 Source VERIFY of SMe FileMailer 1.21 SQL injection</ref><ref source="SECUNIA" url="http://secunia.com/advisories/23766">23766</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2154">2154</ref></refs><vuln_soft><prod name="SMe FileMailer" vendor="Scriptme"><vers num="1.21"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-01-21" name="CVE-2007-0340" published="2007-01-17" seq="2007-0340" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in inc/header.inc.php in ThWboard 3.0b2.84-php5 and earlier allows remote attackers to execute arbitrary SQL commands via the board[styleid] parameter to index.php.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://www.milw0rm.com/exploits/3124"></ref><ref source="SECUNIA" url="http://secunia.com/advisories/23735">23735</ref><ref source="MILW0RM" url="http://milw0rm.com/exploits/3124">

3124</ref></refs><vuln_soft><prod name="ThWboard" vendor="ThWboard"><vers edition="php5" num="3.0 Beta 2.84" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-01-19" name="CVE-2007-0341" published="2007-01-17" seq="2007-0341" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in phpMyAdmin 2.8.1 and earlier, when Microsoft Internet Explorer 6 is used, allows remote attackers to inject arbitrary web script or HTML via a javascript: URI in a CSS style in the convcharset parameter to the top-level URI, a different vulnerability than CVE-2005-0992.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/456726/100/0/threaded">20070112 Re: xss in phpmyadmin &lt;= 2.8.1</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/456698/100/0/threaded">20070112 xss in phpmyadmin &lt;= 2.8.1</ref><ref adv="1" patch="1" source="" url="http://www.virtuax.be/advisories/Advisory1-12012007.txt"></ref></refs><vuln_soft><prod name="phpMyAdmin" vendor="phpMyAdmin"><vers num="2.8.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0" modified="2007-01-19" name="CVE-2007-0342" published="2007-01-17" seq="2007-0342" severity="Medium" type="CVE"><desc><descript source="cve">WebCore in Apple WebKit build 18794 allows remote attackers to cause a denial of service (null dereference and application crash) via a TD element with a large number in the ROWSPAN attribute, as demonstrated by a crash of OmniWeb 5.5.3 on Mac OS X 10.4.8, a different vulnerability than CVE-2006-2019.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="" url="http://security-protocols.com/sp-x41-advisory.php"></ref><ref source="BID" url="http://www.securityfocus.com/bid/22059">22059</ref></refs><vuln_soft><prod name="OmniWeb" vendor="OmniGroup"><vers num="5.5.3"/></prod><prod name="Mac OS X" vendor="Apple"><vers num="10.4.8"/></prod><prod name="Safari" vendor="Apple"><vers num="2.0.4_419.3"/></prod><prod name="Apple WebKit" vendor="Apple"><vers num="build 18794"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0" modified="2007-01-21" name="CVE-2007-0343" published="2007-01-17" seq="2007-0343" severity="Medium" type="CVE"><desc><descript source="cve">OpenBSD before 20070116 allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via certain IPv6 ICMP (aka ICMP6) echo request packets.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="OPENBSD" url="http://www.openbsd.org/errata39.html#icmp6">[3.9] 018: RELIABILITY FIX: January 16, 2007</ref><ref source="OPENBSD" url="http://www.openbsd.org/errata.html#icmp6">[4.0] 008: RELIABILITY FIX: January 16, 2007</ref><ref source="BID" url="http://www.securityfocus.com/bid/22087">22087</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1017518">1017518</ref><ref source="SECUNIA" url="http://secunia.com/advisories/23830">
23830</ref><ref source="OSVDB" url="http://www.osvdb.org/32935">32935</ref></refs><vuln_soft><prod name="OpenBSD" vendor="OpenBSD"><vers num="4.0 2007-01-03" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-08-07" name="CVE-2007-0344" published="2007-01-17" seq="2007-0344" severity="High" type="CVE"><desc><descript source="cve">Multiple format string vulnerabilities in (1) _invitedToRoom: and (2) _invitedToDirectChat: in Colloquy 2.1 and earlier allow remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via format string specifiers in the channel name of an INVITE request, related to the implementation of AlertSheet and AlertPanel in Apple AppKit.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://projects.info-pull.com/moab/MOAB-16-01-2007.html"></ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/22086">22086</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/23801">23801</ref><ref source="MILW0RM" url="http://milw0rm.com/exploits/3139">3139</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0238">ADV-2007-0238</ref><ref source="OSVDB" url="http://www.osvdb.org/32688">32688</ref></refs><vuln_soft><prod name="Colloquy" vendor="Colloquy"><vers num="2.1_3545" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="3.1" CVSS_impact_subscore="10.0" CVSS_score="6.8" CVSS_vector="(AV:L/AC:L/Au:S/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-01-21" name="CVE-2007-0345" published="2007-01-17" seq="2007-0345" severity="Medium" type="CVE"><desc><descript source="cve">The (1) Activity Monitor.app/Contents/Resources/pmTool, (2) Keychain Access.app/Contents/Resources/kcproxy, and (3) ODBC Administrator.app/Contents/Resources/iodbcadmintool programs in /Applications/Utilities/ in Mac OS X 10.4.8 have weak permissions (writable by admin group), which allows local admin users to gain root privileges by modifying a program and then performing permissions repair via diskutil.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref source="" url="http://projects.info-pull.com/moab/MOAB-15-01-2007.html"></ref><ref source="" url="http://www.milw0rm.com/exploits/3136"></ref><ref source="MILW0RM" url="http://milw0rm.com/exploits/3136">
3136</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31530">
macosx-applications-privilege-escalation(31530)</ref><ref source="OSVDB" url="http://www.osvdb.org/32700">
32700</ref><ref source="OSVDB" url="http://www.osvdb.org/32701">
32701</ref><ref source="OSVDB" url="http://www.osvdb.org/32702">
32702</ref></refs><vuln_soft><prod name="Mac OS X" vendor="Apple"><vers num="10.4.8"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-01-21" name="CVE-2007-0346" published="2007-01-17" seq="2007-0346" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in index.php in SmE FileMailer 1.21 allows remote attackers to execute arbitrary SQL commands via the us parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="VIM" url="http://www.attrition.org/pipermail/vim/2007-January/001244.html">20070117 Source VERIFY of SMe FileMailer 1.21 SQL injection</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0221">ADV-2007-0221</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31533">
smefilemailer-login-sql-injection(31533)</ref></refs><vuln_soft><prod name="FileMailer" vendor="SmE"><vers num="1.21"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:P)" CVSS_version="2.0" modified="2007-01-30" name="CVE-2007-0347" published="2007-01-29" seq="2007-0347" severity="Medium" type="CVE"><desc><descript source="cve">The is_eow function in format.c in CVSTrac before 2.0.1 does not properly check for the &quot;&apos;&quot; (quote) character, which allows remote authenticated users to execute limited SQL injection attacks and cause a denial of service (database error) via a &apos; character in certain messages, tickets, or Wiki entries.</descript></desc><impacts><impact source="nvd">An SQL injection via this technique is somewhat limited as is_eow() bails on whitespace. So while one _can_ do an SQL injection, one is limited to SQL queries containing only characters which get past the function isspace(3). This effectively limits attacks to SQL commands like &quot;VACUUM&quot;.</impact></impacts><sols><sol source="nvd">Successful remote unauthenticated exploit requires that CVSTrac is explicitly configured to allow anonymous users to add tickets (it is not by default).</sol></sols><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/458455/100/0/threaded">20070129 CVSTrac 2.0.0 Denial of Service (DoS) vulnerability</ref><ref adv="1" patch="1" source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2007-January/052058.html">20070129 CVSTrac 2.0.0 Denial of Service (DoS) vulnerability</ref><ref adv="1" patch="1" source="" url="http://www.cvstrac.org/cvstrac/tktview?tn=683"></ref><ref adv="1" patch="1" source="" url="http://www.cvstrac.org/cvstrac/chngview?cn=850"></ref><ref adv="1" source="OPENPKG" url="http://www.openpkg.com/security/advisories/OpenPKG-SA-2007.008.html">OpenPKG-SA-2007.008</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0398">ADV-2007-0398</ref><ref source="BID" url="http://www.securityfocus.com/bid/22296">
22296</ref><ref source="SECUNIA" url="http://secunia.com/advisories/23940">
23940</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2192">2192</ref></refs><vuln_soft><prod name="CVSTrac" vendor="CVSTrac"><vers num="2.0" prev="1"/><vers num="1.1.4"/><vers num="1.1.3"/><vers num="1.1.2"/><vers num="1.1.1"/><vers num="1.1"/></prod></vuln_soft></entry><entry CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" CVSS_score="9.3" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-04-13" name="CVE-2007-0348" published="2007-03-21" seq="2007-0348" severity="High" type="CVE"><desc><descript source="cve">Stack-based buffer overflow in the IASystemInfo.dll ActiveX control in (1) InterActual Player 2.60.12.0717, (2) Roxio CinePlayer 3.2, (3) WinDVD 7.0.27.172, and possibly other products, allows remote attackers to execute arbitrary code via a long ApplicationType property.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" source="" url="http://secunia.com/secunia_research/2007-37/advisory/"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1042">ADV-2007-1042</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1043">ADV-2007-1043</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/23032">23032</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/23075">23075</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33186">interactual-iasysteminfo-bo(33186)</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/922969">VU#922969</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24556">24556</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/463405/100/0/threaded">20070321 Secunia Research: InterActual Player / CinePlayer IASystemInfo.dllActiveX Control Buffer Overflow</ref><ref source="BID" url="http://www.securityfocus.com/bid/23071">23071</ref></refs><vuln_soft><prod name="CinePlayer" vendor="Roxio"><vers num="3.2"/></prod><prod name="WinDVD" vendor="InterVideo"><vers num="7.0.27.172"/></prod><prod name="InterActual Player" vendor="InterActual Technologies"><vers num="2.60.12.0717"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0" modified="2007-01-21" name="CVE-2007-0349" published="2007-01-18" seq="2007-0349" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in upgrade.php in nicecoder.com INDEXU 5.x allows remote attackers to include arbitrary local files via a .. (dot dot) in the gateway parameter.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/457079/100/0/threaded">20070116 vulnerability script indexu all versions</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31539">
indexu-upgrade-file-include(31539)</ref></refs><vuln_soft><prod name="indexu" vendor="Nicecoder"><vers num="5.0" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-01-21" name="CVE-2007-0350" published="2007-01-18" seq="2007-0350" severity="High" type="CVE"><desc><descript source="cve">Multiple SQL injection vulnerabilities in (a) index.php and (b) dl.php in SmE FileMailer 1.21 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) ps, (2) us, (3) f, or (4) code parameter.  NOTE: the us vector in index.php is already covered by CVE-2007-0346.  NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0221">ADV-2007-0221</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31533">
smefilemailer-login-sql-injection(31533)</ref></refs><vuln_soft><prod name="FileMailer" vendor="SmE"><vers num="1.21" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.2" CVSS_exploit_subscore="1.9" CVSS_impact_subscore="10.0" CVSS_score="6.2" CVSS_vector="(AV:L/AC:H/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-08-07" name="CVE-2007-0351" published="2007-01-18" seq="2007-0351" severity="Medium" type="CVE"><desc><descript source="cve">Microsoft Windows XP and Windows Server 2003 do not properly handle user logoff, which might allow local users to gain the privileges of a previous system user, possibly related to user profile unload failure. NOTE: it is not clear whether this is an issue in Windows itself, or an interaction with another product.  The issue might involve ZoneAlarm not being able to terminate processes when it cannot prompt the user.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><design/><race/></vuln_types><range><local/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/457217/100/0/threaded">20070117 Re: Windows logoff bug possible security vulnerability and exploit.</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/457167/100/0/threaded">20070117 Windows logoff bug possible security vulnerability and exploit.</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/457340/100/0/threaded">20070118 Re: Windows logoff bug possible security vulnerability and exploit.</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/457807/100/200/threaded">20070123 Re: Windows logoff bug possible security vulnerability and exploit.</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/459838/100/0/threaded">20070211 Windows logoff bug solution possibly.</ref></refs><vuln_soft><prod name="Zone Alarm" vendor="Zone Labs"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" CVSS_score="9.3" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-01-21" name="CVE-2007-0352" published="2007-01-18" seq="2007-0352" severity="High" type="CVE"><desc><descript source="cve">Stack-based buffer overflow in Microsoft Help Workshop 4.03.0002 allows user-assisted remote attackers to execute arbitrary code via a crafted .cnt file composed of lines that begin with an integer followed by a space and a long string.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/><user_init/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/457210/100/0/threaded">20070117 Microsoft Help Workshop .CNT contents files buffer overflow vulnerability</ref><ref source="" url="http://www.anspi.pl/~porkythepig/visualization/cnt-expl1.cpp"></ref><ref source="" url="http://www.milw0rm.com/exploits/3149"></ref><ref source="MILW0RM" url="http://milw0rm.com/exploits/3149">
3149</ref><ref source="BID" url="http://www.securityfocus.com/bid/22100">
22100</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1017530">
1017530</ref><ref source="SECUNIA" url="http://secunia.com/advisories/23862">
23862</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31555">
ms-help-workshop-cnt-bo(31555)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2156">2156</ref></refs><vuln_soft><prod name="Help Workshop" vendor="Microsoft"><vers num="4.02.0002"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-01-21" name="CVE-2007-0353" published="2007-01-18" seq="2007-0353" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in (1) index.php and (2) login.php in myBloggie 2.1.5 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO string.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/457206/100/0/threaded">20070117 [x0n3-h4ck] myBloggie 2.1.5 XSS exploit</ref><ref source="" url="http://mywebland.com/forums/showtopic.php?t=1224"></ref><ref source="BID" url="http://www.securityfocus.com/bid/22097">22097</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1017531">
1017531</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31554">
mybloggie-indexlogin-xss(31554)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2155">2155</ref></refs><vuln_soft><prod name="myBloggie" vendor="myWebland"><vers num="2.1.5"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-01-21" name="CVE-2007-0354" published="2007-01-18" seq="2007-0354" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in email.php in MGB OpenSource Guestbook 0.5.4.5 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://www.milw0rm.com/exploits/3141"></ref><ref source="" url="http://www.tv-kritik.net/mgb/index.php"></ref><ref source="VIM" url="http://www.attrition.org/pipermail/vim/2007-January/001246.html">20070118 vendor ACK for MGB Guestbook issue</ref><ref source="BID" url="http://www.securityfocus.com/bid/22094">22094</ref><ref source="MILW0RM" url="http://milw0rm.com/exploits/3141">

3141</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0232">
ADV-2007-0232</ref><ref source="SECUNIA" url="http://secunia.com/advisories/23825">
23825</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31551">
mgb-email-sql-injection(31551)</ref></refs><vuln_soft><prod name="OpenSource Guestbook" vendor="MGB"><vers num="0.5.4.5" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2008-02-13" name="CVE-2007-0355" published="2007-01-18" seq="2007-0355" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in the Apple Minimal SLP v2 Service Agent (slpd) in Mac OS X 10.4.11 and earlier, including 10.4.8, allows local users, and possibly remote attackers, to gain privileges and possibly execute arbitrary code via a registration request with an invalid attr-list field.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref source="" url="http://projects.info-pull.com/moab/MOAB-17-01-2007.html"></ref><ref source="" url="http://www.milw0rm.com/exploits/3151"></ref><ref source="MILW0RM" url="http://milw0rm.com/exploits/3151">3151</ref><ref source="BID" url="http://www.securityfocus.com/bid/22101">22101</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0239">ADV-2007-0239</ref><ref source="OSVDB" url="http://www.osvdb.org/32693">32693</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1017533">1017533</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/23796">23796</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31562">macos-slpd-bo(31562)</ref><ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2008/Feb/msg00002.html">APPLE-SA-2008-02-11</ref><ref source="" url="http://docs.info.apple.com/article.html?artnum=307430"></ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA08-043B.html">TA08-043B</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1019359">1019359</ref></refs><vuln_soft><prod name="Minimal SLP Service Agent" vendor="Apple"><vers num="10.4.11"/></prod><prod name="Mac OS X" vendor="Apple"><vers num="10.4.8"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0" modified="2007-01-21" name="CVE-2007-0356" published="2007-01-18" seq="2007-0356" severity="Medium" type="CVE"><desc><descript source="cve">The Common Controls Replacement Project (CCRP) FolderTreeview (FTV) ActiveX control (ccrpftv6.ocx) allows remote attackers to cause a denial of service (Internet Explorer 7 crash) via a long CCRP.RootFolder property value.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref source="" url="http://www.milw0rm.com/exploits/3142"></ref><ref source="BID" url="http://www.securityfocus.com/bid/22092">22092</ref><ref source="MILW0RM" url="http://milw0rm.com/exploits/3142">

3142</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31549">
ie-ccrp-dos(31549)</ref></refs><vuln_soft><prod name="Internet Explorer" vendor="Microsoft"><vers edition="Vista" num="7.0"/></prod><prod name="FolderTreeview ActiveX control" vendor="Common Controls Replacement Project"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0" modified="2007-01-21" name="CVE-2007-0357" published="2007-01-18" seq="2007-0357" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in the AVM IGD CTRL Service in Fritz!DSL 02.02.29 allows remote attackers to read arbitrary files via ..%5C (URL-encoded dot dot backslash) sequences in a URI requested from the AR7 webserver.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2007-January/051844.html">20070117 Flaw in AVM UPNP service for windows</ref><ref source="BID" url="http://www.securityfocus.com/bid/22093">22093</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0236">
ADV-2007-0236</ref><ref source="SECUNIA" url="http://secunia.com/advisories/23774">
23774</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31556">
fritz-avm-directory-traversal(31556)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2159">2159</ref></refs><vuln_soft><prod name="FritzDSL" vendor="FritzDSL"><vers num="02.02.29"/></prod></vuln_soft></entry><entry CVSS_base_score="7.8" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.9" CVSS_score="7.8" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_version="2.0" modified="2007-01-21" name="CVE-2007-0358" published="2007-01-18" seq="2007-0358" severity="High" type="CVE"><desc><descript source="cve">Unspecified vulnerability in the FTP server implementation in HP Jetdirect firmware x.20.nn through x.24.nn allows remote attackers to cause a denial of service via unknown vectors.</descript></desc><loss_types><avail/></loss_types><range><network/></range><refs><ref source="HP" url="http://itrc.hp.com/service/cki/docDisplay.do?docId=c00838612">HPSBPI02185</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/23802">23802</ref><ref source="BID" url="http://www.securityfocus.com/bid/22105">
22105</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0233">
ADV-2007-0233</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1017532">
1017532</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31589">
hp-jetdirect-unspecified-dos(31589)</ref></refs><vuln_soft><prod name="Jetdirect firmware" vendor="HP"><vers num="x.20.nn"/><vers num="x.21.nn"/><vers num="x.22.nn"/><vers num="x.23.nn"/><vers num="x.24.nn"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-01-21" name="CVE-2007-0359" published="2007-01-18" seq="2007-0359" severity="High" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in frontpage.php in Uberghey CMS 0.3.1 allows remote attackers to execute arbitrary PHP code via a URL in the setup_folder parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://www.milw0rm.com/exploits/3147"></ref><ref source="VIM" url="http://www.attrition.org/pipermail/vim/2007-January/001247.html">20070118 source verify: Uberghey CMS 0.3.1 RFI</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0230">ADV-2007-0230</ref><ref source="MILW0RM" url="http://milw0rm.com/exploits/3147">

3147</ref><ref source="BID" url="http://www.securityfocus.com/bid/22098">
22098</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31553">
uberghey-frontpage-file-include(31553)</ref></refs><vuln_soft><prod name="CMS" vendor="Uberghey"><vers num="0.3.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-01-21" name="CVE-2007-0360" published="2007-01-18" seq="2007-0360" severity="High" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in lang/index.php in Oreon 1.2.3 RC4 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the file parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://www.milw0rm.com/exploits/3150"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0229">ADV-2007-0229</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/459811/100/0/threaded">

20070211 Oreon1.2.x Series Exploit Coded</ref><ref source="MILW0RM" url="http://milw0rm.com/exploits/3150">
3150</ref><ref source="BID" url="http://www.securityfocus.com/bid/22107">
22107</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31568">
oreon-index-file-include(31568)</ref></refs><vuln_soft><prod name="Oreon" vendor="Oreon Project"><vers num="1.2.3 RC4" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-01-21" name="CVE-2007-0361" published="2007-01-18" seq="2007-0361" severity="High" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in mep/frame.php in PHPMyphorum 1.5a allows remote attackers to execute arbitrary PHP code via a URL in the chem parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://www.milw0rm.com/exploits/3145"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0231">ADV-2007-0231</ref><ref source="MILW0RM" url="http://milw0rm.com/exploits/3145">

3145</ref><ref source="BID" url="http://www.securityfocus.com/bid/22099">
22099</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31552">
phpmyphorum-frame-file-include(31552)</ref></refs><vuln_soft><prod name="PHPMyphorum" vendor="ComScripts"><vers num="1.5a"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-01-21" name="CVE-2007-0362" published="2007-01-18" seq="2007-0362" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in the RSS feed component in FreshReader before 1.0.07010600 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, possibly related to tag attributes.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://jvn.jp/jp/JVN%2395249468/index.html"></ref><ref source="" url="http://manual.freshreader.com/archives/2007/01/20070118_javasc.html"></ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/23806">23806</ref><ref source="BID" url="http://www.securityfocus.com/bid/22106">
22106</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0241">
ADV-2007-0241</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31566">
freshreader-rssfeed-xss(31566)</ref></refs><vuln_soft><prod name="FreshReader" vendor="FreshReader"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-01-21" name="CVE-2007-0363" published="2007-01-18" seq="2007-0363" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in admin-search.php in (1) Openads for PostgreSQL (aka phpPgAds) before 2.0.10 and (2) Openads (aka phpAdsNew) before 2.0.10 allows remote attackers to inject arbitrary web script or HTML via unspecified parameters.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref patch="1" source="" url="http://sourceforge.net/project/shownotes.php?group_id=11386&amp;release_id=479424"></ref><ref patch="1" source="" url="http://sourceforge.net/project/shownotes.php?group_id=36679&amp;release_id=479426"></ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/23720">23720</ref><ref source="BID" url="http://www.securityfocus.com/bid/22124">
22124</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0240">
ADV-2007-0240</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31570">
openads-unspecified-xss(31570)</ref></refs><vuln_soft><prod name="Openads" vendor="Openads"><vers edition="PostgreSQL" num="2.0.9 pr1"/><vers edition="PostgreSQL" num="2.0.8 pr1"/><vers num="2.0.9 pr1"/><vers num="2.0.8 pr1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-08-07" name="CVE-2007-0364" published="2007-01-19" seq="2007-0364" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in nicecoder.com INDEXU 5.3 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) error_msg parameter to (a) suggest_category.php; the (2) u parameter to (b) user_detail.php; the (3) friend_name, (4) friend_email, (5) error_msg, (6) my_name, (7) my_email, and (8) id parameters to (c) tell_friend.php; the (9) error_msg, (10) email, (11) name, and (12) subject parameters to (d) sendmail.php; the (13) email, (14) error_msg, and (15) username parameters to (e) send_pwd.php; the (16) keyword parameter to (f) search.php; the (17) error_msg, (18) username, (19) password, (20) password2, and (21) email parameters to (g) register.php; the (22) url, (23) contact_name, and (24) email parameters to (h) power_search.php; the (25) path and (26) total parameters to (i) new.php; the (27) query parameter to (j) modify.php; the (28) error_msg parameter to (k) login.php; the (29) error_msg and (30) email parameters to (l) mailing_list.php; the (31) gateway parameter to (m) upgrade.php; and another unspecified vector.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/457079/100/0/threaded">20070116 vulnerability script indexu all versions</ref><ref source="BID" url="http://www.securityfocus.com/bid/22084">22084</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/23764">23764</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0222">ADV-2007-0222</ref><ref source="OSVDB" url="http://www.osvdb.org/32838">32838</ref><ref source="OSVDB" url="http://www.osvdb.org/32840">32840</ref><ref source="OSVDB" url="http://www.osvdb.org/32841">32841</ref><ref source="OSVDB" url="http://www.osvdb.org/32842">32842</ref><ref source="OSVDB" url="http://www.osvdb.org/32843">32843</ref><ref source="OSVDB" url="http://www.osvdb.org/32844">32844</ref><ref source="OSVDB" url="http://www.osvdb.org/32845">32845</ref><ref source="OSVDB" url="http://www.osvdb.org/32846">32846</ref><ref source="OSVDB" url="http://www.osvdb.org/32847">32847</ref><ref source="OSVDB" url="http://www.osvdb.org/32848">32848</ref><ref source="OSVDB" url="http://www.osvdb.org/32849">32849</ref><ref source="OSVDB" url="http://www.osvdb.org/32850">32850</ref><ref source="OSVDB" url="http://www.osvdb.org/32851">32851</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31538">indexu-multiple-scripts-xss(31538)</ref></refs><vuln_soft><prod name="INDEXU" vendor="nicecoder"><vers num="5.3" prev="1"/><vers num="5.0.1"/><vers num="5.0"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-01-21" name="CVE-2007-0365" published="2007-01-19" seq="2007-0365" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in All In One Control Panel (AIOCP) 1.3.009 and earlier allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.  NOTE: this is probably a different vulnerability than CVE-2006-5830.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref patch="1" source="" url="http://sourceforge.net/project/shownotes.php?release_id=478370"></ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0189">ADV-2007-0189</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/23732">23732</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/31486">aiocp-unspecified-xss(31486)</ref></refs><vuln_soft><prod name="All In One Control Panel" vendor="Nicola Asuni"><vers num="1.3.009" prev="1"/><vers num="1.3.008"/><vers num="1.3.007"/><vers num="1.3.006"/><vers num="1.3.005"/><vers num="1.3.004"/><vers num="1.3.003"/><vers num="1.3.002"/><vers num="1.3.001"/><vers num="1.3.000"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-01-21" name="CVE-2007-0366" published="2007-01-19" seq="2007-0366" severity="Medium" type="CVE"><desc><descript source="cve">Untrusted search path vulnerability in Rumpus 5.1 and earlier allows local users to gain privileges via a modified PATH that points to a malicious ipfw program.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><local/></range><refs><ref adv="1" source="" url="http://projects.info-pull.com/moab/MOAB-18-01-2007.html"></ref><ref source="SECUNIA" url="http://secunia.com/advisories/23842">
23842</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31597">
rumpus-ipfw-privilege-escalation(31597)</ref></refs><vuln_soft><prod name="Rumpus FTP Server" vendor="Maxum Development Corporation"><vers num="5.1" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-01-21" name="CVE-2007-0367" published="2007-01-19" seq="2007-0367" severity="Medium" type="CVE"><desc><descript source="cve">Rumpus 5.1 and earlier has weak permissions for certain files and directories under /usr/local/Rumpus, including the configuration file, which allows local users to have an unknown impact by creating, modifying, or deleting files.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" source="" url="http://projects.info-pull.com/moab/MOAB-18-01-2007.html"></ref><ref source="SECUNIA" url="http://secunia.com/advisories/23842">
23842</ref></refs><vuln_soft><prod name="Rumpus FTP Server" vendor="Maxum Development Corporation"><vers num="5.1" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-01-21" name="CVE-2007-0368" published="2007-01-19" seq="2007-0368" severity="High" type="CVE"><desc><descript source="cve">Stack-based buffer overflow in mbse-bbs 0.70 and earlier allows local users to execute arbitrary code via a long string in the MBSE_ROOT environment variable.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref source="" url="http://www.mbse.eu/mbse/mbsebbs/index.html"></ref><ref source="" url="http://www.milw0rm.com/exploits/3154"></ref><ref source="BID" url="http://www.securityfocus.com/bid/22112">22112</ref><ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2007-January/051859.html">

20070118 mbsebbs 0.70.0 &amp; below local root exploit</ref><ref source="MILW0RM" url="http://milw0rm.com/exploits/3154">
3154</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31639">
mbsebbs-mbuseradd-bo(31639)</ref></refs><vuln_soft><prod name="mbse-bbs" vendor="Michiel Broek"><vers num="0.70"/><vers num="0.60"/><vers num="0.38"/><vers num="0.36"/><vers num="0.35.7"/><vers num="0.33.20"/><vers num="0.33.19"/><vers num="0.33.18"/><vers num="0.33.17"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-01-22" name="CVE-2007-0369" published="2007-01-19" seq="2007-0369" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in phpBP RC3 (2.204) and earlier allows remote attackers to execute arbitrary SQL commands via the comment forum.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://www.milw0rm.com/exploits/3153"></ref><ref source="MILW0RM" url="http://milw0rm.com/exploits/3153">

3153</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31622">
phpbp-comment-sql-injection(31622)</ref></refs><vuln_soft><prod name="phpBP" vendor="phpBP"><vers num="RC3 2.204"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-01-22" name="CVE-2007-0370" published="2007-01-19" seq="2007-0370" severity="High" type="CVE"><desc><descript source="cve">Unrestricted file upload vulnerability in index.php in phpBP RC3 (2.204) and earlier allows remote administrators to inject arbitrary PHP code into an upload/banners/ file via a banners add operation that uploads the PHP code through an image_form parameter specifying a multiple-extension filename such as .jpg.vil.gif.php, which is stored in upload/banners/ under a different name, and executable via a direct request.  NOTE: a separate SQL injection issue could be leveraged to make this vulnerability reachable by remote unauthenticated attackers.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/><design/></vuln_types><range><network/></range><refs><ref source="" url="http://www.milw0rm.com/exploits/3153"></ref><ref source="MILW0RM" url="http://milw0rm.com/exploits/3153">

3153</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31619">
phpbp-banner-file-upload(31619)</ref></refs><vuln_soft><prod name="phpBP" vendor="phpBP"><vers num="RC3 2.204"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:P)" CVSS_version="2.0" modified="2007-01-22" name="CVE-2007-0371" published="2007-01-19" seq="2007-0371" severity="Medium" type="CVE"><desc><descript source="cve">A certain ActiveX control in the Common Controls Replacement Project (CCRP) CCRP BrowseDialog Server (ccrpbds6.dll) allows remote attackers to cause a denial of service (Internet Explorer 7 crash) via a long CCRP_BDc.SelectedFolder property value.</descript></desc><loss_types><avail/></loss_types><vuln_types><design/></vuln_types><range><network/><user_init/></range><refs><ref source="" url="http://www.milw0rm.com/exploits/3155"></ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/22110">22110</ref><ref source="MILW0RM" url="http://milw0rm.com/exploits/3155">

3155</ref></refs><vuln_soft><prod name="BrowseDialog Server" vendor="Common Controls Replacement Project"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-01-22" name="CVE-2007-0372" published="2007-01-19" seq="2007-0372" severity="High" type="CVE"><desc><descript source="cve">Multiple SQL injection vulnerabilities in Francisco Burzi PHP-Nuke 7.9 allow remote attackers to execute arbitrary SQL commands via (1) the active parameter in admin/modules/modules.php; the (2) ad_class, (3) imageurl, (4) clickurl, (5) ad_code, or (6) position parameter in modules/Advertising/admin/index.php; or unspecified vectors in the (7) advertising, (8) weblinks, or (9) reviews section.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="FULLDISC" url="http://archives.neohapsis.com/archives/fulldisclosure/2007-01/0355.html">20070118 The vulnerabilities festival !</ref><ref source="" url="http://www.hackers.ir/advisories/festival.txt"></ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/22116">22116</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/459174/100/0/threaded">

20070204 Sql injection bugs in PHP-Nuke</ref></refs><vuln_soft><prod name="PHP-Nuke" vendor="Francisco Burzi"><vers num="7.9"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-01-22" name="CVE-2007-0373" published="2007-01-19" seq="2007-0373" severity="Medium" type="CVE"><desc><descript source="cve">Multiple SQL injection vulnerabilities in Joomla! 1.5.0 Beta allow remote attackers to execute arbitrary SQL commands via (1) the searchword parameter in certain files; the where parameter in (2) plugins/search/content.php or (3) plugins/search/weblinks.php; the text parameter in (4) plugins/search/contacts.php, (5) plugins/search/categories.php, or (6) plugins/search/sections.php; or (7) the email parameter in database/table/user.php, which is not properly handled by the check function.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="FULLDISC" url="http://archives.neohapsis.com/archives/fulldisclosure/2007-01/0355.html">20070118 The vulnerabilities festival !</ref><ref source="" url="http://www.hackers.ir/advisories/festival.txt"></ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/22122">22122</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/459203/100/0/threaded">

20070204 Sql injection bugs in Joomla and Mambo</ref></refs><vuln_soft><prod name="Joomla" vendor="Joomla"><vers num="1.5.0 Beta"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-01-22" name="CVE-2007-0374" published="2007-01-19" seq="2007-0374" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in (1) Joomla! 1.0.11 and 1.5 Beta, and (2) Mambo 4.6.1, allows remote attackers to execute arbitrary SQL commands via the id parameter when cancelling content editing.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="FULLDISC" url="http://archives.neohapsis.com/archives/fulldisclosure/2007-01/0355.html">20070118 The vulnerabilities festival !</ref><ref adv="1" source="" url="http://www.hackers.ir/advisories/festival.txt"></ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/19734">19734</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/459203/100/0/threaded">

20070204 Sql injection bugs in Joomla and Mambo</ref></refs><vuln_soft><prod name="Mambo" vendor="Mambo"><vers num="4.6.1"/></prod><prod name="Joomla" vendor="Joomla"><vers num="1.5.0 Beta"/><vers num="1.0.11"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0" modified="2007-01-22" name="CVE-2007-0375" published="2007-01-19" seq="2007-0375" severity="Medium" type="CVE"><desc><descript source="cve">Joomla! 1.5.0 Beta allows remote attackers to obtain sensitive information via a direct request for (1) plugins/user/example.php; (2) gmail.php, (3) example.php, or (4) ldap.php in plugins/authentication/; (5) modules/mod_mainmenu/menu.php; or other unspecified PHP scripts, which reveals the path in various error messages, related to a jimport function call at the beginning of each script.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="FULLDISC" url="http://archives.neohapsis.com/archives/fulldisclosure/2007-01/0355.html">20070118 The vulnerabilities festival !</ref><ref adv="1" source="" url="http://www.hackers.ir/advisories/festival.txt"></ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/459203/100/0/threaded">

20070204 Sql injection bugs in Joomla and Mambo</ref></refs><vuln_soft><prod name="Joomla" vendor="Joomla"><vers num="1.5.0 Beta"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-01-22" name="CVE-2007-0376" published="2007-01-19" seq="2007-0376" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in Virtuemart 1.0.7 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="FULLDISC" url="http://archives.neohapsis.com/archives/fulldisclosure/2007-01/0355.html">20070118 The vulnerabilities festival !</ref><ref adv="1" patch="1" source="" url="http://virtuemart.svn.sourceforge.net/viewvc/*checkout*/virtuemart/branches/virtuemart-1_0_0/virtuemart/CHANGELOG.php?revision=607"></ref><ref adv="1" source="" url="http://www.hackers.ir/advisories/festival.txt"></ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/22123">22123</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/459195/100/0/threaded">

20070204 Sql injection bugs in Virtuemart and Letterman</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24058">
24058</ref></refs><vuln_soft><prod name="Virtuemart" vendor="Virtuemart"><vers num="1.0.7"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-01-22" name="CVE-2007-0377" published="2007-01-19" seq="2007-0377" severity="High" type="CVE"><desc><descript source="cve">Multiple SQL injection vulnerabilities in Xoops 2.0.16 allow remote attackers to execute arbitrary SQL commands via (1) the id parameter in kernel/group.php in core, (2) the lid parameter in class/table_broken.php in the Weblinks module, and other unspecified vectors.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="FULLDISC" url="http://archives.neohapsis.com/archives/fulldisclosure/2007-01/0355.html">20070118 The vulnerabilities festival !</ref><ref adv="1" source="" url="http://www.hackers.ir/advisories/festival.txt"></ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/459150/100/0/threaded">

20070204 Sql injection bugs in Xoops 2.0.16 + Weblinks module</ref><ref source="BID" url="http://www.securityfocus.com/bid/22399">
22399</ref></refs><vuln_soft><prod name="XOOPS" vendor="XOOPS"><vers num="2.0.16"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-01-22" name="CVE-2007-0378" published="2007-01-19" seq="2007-0378" severity="High" type="CVE"><desc><descript source="cve">Multiple SQL injection vulnerabilities in DocMan 1.3 RC2 allow attackers to execute arbitrary SQL commands via unspecified vectors.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="FULLDISC" url="http://archives.neohapsis.com/archives/fulldisclosure/2007-01/0355.html">20070118 The vulnerabilities festival !</ref><ref adv="1" source="" url="http://www.hackers.ir/advisories/festival.txt"></ref></refs><vuln_soft><prod name="DocMan" vendor="DocMan"><vers num="1.3 RC2"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-01-22" name="CVE-2007-0379" published="2007-01-19" seq="2007-0379" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in DocMan 1.3 RC2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="FULLDISC" url="http://archives.neohapsis.com/archives/fulldisclosure/2007-01/0355.html">20070118 The vulnerabilities festival !</ref><ref adv="1" source="" url="http://www.hackers.ir/advisories/festival.txt"></ref></refs><vuln_soft><prod name="DocMan" vendor="DocMan"><vers num="1.3 RC2"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0" modified="2007-01-22" name="CVE-2007-0380" published="2007-01-19" seq="2007-0380" severity="Medium" type="CVE"><desc><descript source="cve">DocMan 1.3 RC2 allows remote attackers to obtain sensitive information (the full path) via unspecified vectors.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="FULLDISC" url="http://archives.neohapsis.com/archives/fulldisclosure/2007-01/0355.html">20070118 The vulnerabilities festival !</ref><ref adv="1" source="" url="http://www.hackers.ir/advisories/festival.txt"></ref></refs><vuln_soft><prod name="DocMan" vendor="DocMan"><vers num="1.3 RC2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-01-22" name="CVE-2007-0381" published="2007-01-19" seq="2007-0381" severity="High" type="CVE"><desc><descript source="cve">Multiple SQL injection vulnerabilities in ATutor 1.5.3.2 allow remote attackers to execute arbitrary SQL commands via unspecified parameters.  NOTE: CVE analysis suggests that the vendor fixed these issues.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="FULLDISC" url="http://archives.neohapsis.com/archives/fulldisclosure/2007-01/0355.html">20070118 The vulnerabilities festival !</ref><ref adv="1" patch="1" source="" url="http://www.atutor.ca/atutor/mantis/changelog_page.php"></ref><ref adv="1" source="" url="http://www.hackers.ir/advisories/festival.txt"></ref></refs><vuln_soft><prod name="ATutor" vendor="Adaptive Technology Resource Centre"><vers num="1.5.3.2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-01-22" name="CVE-2007-0382" published="2007-01-19" seq="2007-0382" severity="High" type="CVE"><desc><descript source="cve">Multiple SQL injection vulnerabilities in letterman.class.php in the Letterman 1.2.3 (com_letterman) component for Joomla! before 1.0.12 allow remote attackers to execute arbitrary SQL commands via the id parameter, related to the (1) lm_sendMail, (2) saveNewsletter, and (3) cancelNewsletter functions.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="FULLDISC" url="http://archives.neohapsis.com/archives/fulldisclosure/2007-01/0355.html">20070118 The vulnerabilities festival !</ref><ref adv="1" source="" url="http://www.hackers.ir/advisories/festival.txt"></ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/22117">22117</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/459195/100/0/threaded">

20070204 Sql injection bugs in Virtuemart and Letterman</ref></refs><vuln_soft><prod name="Letterman" vendor="Letterman"><vers num="1.2.3"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0" modified="2007-01-22" name="CVE-2007-0383" published="2007-01-19" seq="2007-0383" severity="Medium" type="CVE"><desc><descript source="cve">** DISPUTED **  WDaemon 9.5.4 allows remote attackers to access the /WorldClient.dll URI on TCP port 3000, which has unknown impact.  NOTE: The researcher reports that the vendor response was &quot;this is not a security bug.&quot;</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="FULLDISC" url="http://archives.neohapsis.com/archives/fulldisclosure/2007-01/0355.html">20070118 The vulnerabilities festival !</ref><ref adv="1" source="" url="http://www.hackers.ir/advisories/festival.txt"></ref></refs><vuln_soft><prod name="WDaemon" vendor="WDaemon"><vers num="9.5.4"/><vers num="9.0.4"/><vers num="7.2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.1" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="6.4" CVSS_score="5.1" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-01-22" name="CVE-2007-0384" published="2007-01-19" seq="2007-0384" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in preview in the reviews section in PostNuke 0.764 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/><user_init/></range><refs><ref source="FULLDISC" url="http://archives.neohapsis.com/archives/fulldisclosure/2007-01/0355.html">20070118 The vulnerabilities festival !</ref><ref source="" url="http://www.hackers.ir/advisories/festival.txt"></ref><ref source="" url="http://noc.postnuke.com/plugins/scmsvn/viewcvs.php/trunk/Historic/PostNuke7x/html/modules/?root=postnuke"></ref><ref source="BID" url="http://www.securityfocus.com/bid/22119">22119</ref></refs><vuln_soft><prod name="PostNuke" vendor="PostNuke Software Foundation"><vers num="0.764"/></prod></vuln_soft></entry><entry CVSS_base_score="7.8" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.9" CVSS_score="7.8" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:N/A:N)" CVSS_version="2.0" modified="2007-01-22" name="CVE-2007-0385" published="2007-01-19" seq="2007-0385" severity="High" type="CVE"><desc><descript source="cve">The faq section in PostNuke 0.764 allows remote attackers to obtain sensitive information (the full path) via &quot;unvalidated output&quot; in FAQ/index.php, possibly involving an undefined id_cat variable.</descript></desc><loss_types><conf/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref source="FULLDISC" url="http://archives.neohapsis.com/archives/fulldisclosure/2007-01/0355.html">20070118 The vulnerabilities festival !</ref><ref source="" url="http://www.hackers.ir/advisories/festival.txt"></ref><ref source="" url="http://noc.postnuke.com/plugins/scmsvn/viewcvs.php/trunk/Historic/PostNuke7x/html/modules/?root=postnuke"></ref><ref source="" url="http://noc.postnuke.com/plugins/scmsvn/viewcvs.php/trunk/Historic/PostNuke7x/html/modules/FAQ/index.php?root=postnuke&amp;r1=20350&amp;r2=20911"></ref></refs><vuln_soft><prod name="PostNuke" vendor="PostNuke Software Foundation"><vers num="0.764"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-01-22" name="CVE-2007-0386" published="2007-01-19" seq="2007-0386" severity="High" type="CVE"><desc><descript source="cve">Unspecified vulnerability in the rating section in PostNuke 0.764 has unknown impact and attack vectors, related to &quot;an interesting bug.&quot;</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs><ref source="FULLDISC" url="http://archives.neohapsis.com/archives/fulldisclosure/2007-01/0355.html">20070118 The vulnerabilities festival !</ref><ref source="" url="http://www.hackers.ir/advisories/festival.txt"></ref></refs><vuln_soft><prod name="PostNuke" vendor="PostNuke Software Foundation"><vers num="0.764"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-01-22" name="CVE-2007-0387" published="2007-01-19" seq="2007-0387" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in models/category.php in the Weblinks component for Joomla! SVN 20070118 (com_weblinks) allows remote attackers to execute arbitrary SQL commands via the catid parameter.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="FULLDISC" url="http://archives.neohapsis.com/archives/fulldisclosure/2007-01/0355.html">20070118 The vulnerabilities festival !</ref><ref source="" url="http://www.hackers.ir/advisories/festival.txt"></ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/459203/100/0/threaded">

20070204 Sql injection bugs in Joomla and Mambo</ref></refs><vuln_soft><prod name="Joomla" vendor="Joomla"><vers num="2007-01-18"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-01-22" name="CVE-2007-0388" published="2007-01-19" seq="2007-0388" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in search.php in Woltlab Burning Board (wBB) 1.0.2 and earlier, and 2.3.6 and earlier in the 2.x series, allows remote attackers to execute arbitrary SQL commands via the boardids[1] and other board[] parameters.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://www.milw0rm.com/exploits/3143"></ref><ref source="" url="http://www.milw0rm.com/exploits/3144"></ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31550">wbb-search-sql-injection(31550)</ref><ref source="MILW0RM" url="http://milw0rm.com/exploits/3143">

3143</ref><ref source="MILW0RM" url="http://milw0rm.com/exploits/3144">
3144</ref></refs><vuln_soft><prod name="Burning Board" vendor="Woltlab"><vers num="1.0.2" prev="1"/><vers num="2.3.6" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.8" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.9" CVSS_score="7.8" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:N/A:N)" CVSS_version="2.0" modified="2007-01-22" name="CVE-2007-0389" published="2007-01-19" seq="2007-0389" severity="High" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in ArsDigita Community System (ACS) 3.4.10 and earlier, and ArsDigita Community Education Solution (ACES) 1.1, allows remote attackers to read arbitrary files via .%252e/ (double-encoded dot dot slash) sequences in the URI.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/457318/100/0/threaded">20070118 Directory Traversal in ArsDigita Community System</ref><ref source="BID" url="http://www.securityfocus.com/bid/22121">22121</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0286">
ADV-2007-0286</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31613">
acs-url-directory-traversal(31613)</ref></refs><vuln_soft><prod name="ArsDigita Community System" vendor="ArsDigita"><vers num="3.4.10" prev="1"/></prod><prod name="ArsDigita Community Education Solution" vendor="ArsDigita"><vers num="1.1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-01-22" name="CVE-2007-0390" published="2007-01-19" seq="2007-0390" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in index.php in sabros.us 1.7 allows remote attackers to inject arbitrary web script or HTML via the tag parameter.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/457331/100/0/threaded">20070118 [x0n3-h4ck] sabros.us 1.7 XSS Exploit</ref><ref source="BID" url="http://www.securityfocus.com/bid/22115">22115</ref><ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2007-January/051868.html">
20070118 [x0n3-h4ck] sabros.us 1.7 XSS Exploit</ref><ref source="SECUNIA" url="http://secunia.com/advisories/23824">
23824</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31600">
sabros-index-xss(31600)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2170">2170</ref></refs><vuln_soft><prod name="Sabros.US" vendor="Sabros.US"><vers num="1.7"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-01-22" name="CVE-2007-0391" published="2007-01-19" seq="2007-0391" severity="High" type="CVE"><desc><descript source="cve">Format string vulnerability in the log creation functionality of BitDefender Client Professional Plus 8.02 allows attackers to execute arbitrary code via certain scan job settings.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><exception/></vuln_types><range><local/></range><refs><ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2007-January/051883.html">20070119 Layered Defense Research Advisory: BitDefender Client 8.02 Format String Vulnerability</ref><ref source="" url="http://www.bitdefender.com/KB325-en--Format-string-vulnerability.html"></ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0253">ADV-2007-0253</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/457414/100/0/threaded">

20070119 Layered Defense Research Advisory: BitDefender Client 8.02 Format String Vulnerability</ref><ref source="BID" url="http://www.securityfocus.com/bid/22128">
22128</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31608">
bitdefender-scanjob-format-string(31608)</ref></refs><vuln_soft><prod name="BitDefender Client" vendor="BitDefender"><vers num="Professional Plus 8.02"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-01-22" name="CVE-2007-0392" published="2007-01-19" seq="2007-0392" severity="Medium" type="CVE"><desc><descript source="cve">IBM AIX 5.3 does not properly verify the status of file descriptors before setuid execution, which allows local users to gain privileges by closing file descriptor 0, 1, or 2 and then invoking a setuid program, a variant of CVE-2002-0572.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><exception/></vuln_types><range><local/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/457279/100/0/threaded">20070118 Multiple OS kernel insecure handling of stdio file descriptor</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/457315/100/0/threaded">20070118 Re: Multiple OS kernel insecure handling of stdio file descriptor</ref></refs><vuln_soft><prod name="AIX" vendor="IBM"><vers num="5.3"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-01-22" name="CVE-2007-0393" published="2007-01-19" seq="2007-0393" severity="Medium" type="CVE"><desc><descript source="cve">Sun Solaris 9 does not properly verify the status of file descriptors before setuid execution, which allows local users to gain privileges by closing file descriptor 0, 1, or 2 and then invoking a setuid program, a variant of CVE-2002-0572.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><exception/></vuln_types><range><local/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/457279/100/0/threaded">20070118 Multiple OS kernel insecure handling of stdio file descriptor</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/457315/100/0/threaded">20070118 Re: Multiple OS kernel insecure handling of stdio file descriptor</ref></refs><vuln_soft><prod name="Solaris" vendor="Sun"><vers edition="SPARC" num="9.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-01-22" name="CVE-2007-0394" published="2007-01-19" seq="2007-0394" severity="Medium" type="CVE"><desc><descript source="cve">HP HP-UX B11.11 does not properly verify the status of file descriptors before setuid execution, which allows local users to gain privileges by closing file descriptor 0, 1, or 2 and then invoking a setuid program, a variant of CVE-2002-0572.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><exception/></vuln_types><range><local/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/457279/100/0/threaded">20070118 Multiple OS kernel insecure handling of stdio file descriptor</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/457315/100/0/threaded">20070118 Re: Multiple OS kernel insecure handling of stdio file descriptor</ref></refs><vuln_soft><prod name="HP-UX" vendor="HP"><vers num="B.11.11"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-01-22" name="CVE-2007-0395" published="2007-01-19" seq="2007-0395" severity="High" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in libraries/grab_globals.lib.php in ComVironment 4.0 allows remote attackers to execute arbitrary PHP code via a URL in the inc_dir parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://www.milw0rm.com/exploits/3152"></ref><ref source="BID" url="http://www.securityfocus.com/bid/22108">22108</ref><ref source="MILW0RM" url="http://milw0rm.com/exploits/3152">

3152</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0266">
ADV-2007-0266</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31564">
comvironment-grabglobals-file-include(31564)</ref></refs><vuln_soft><prod name="ComVironment" vendor="ComVironment"><vers num="4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.1" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.9" CVSS_score="7.1" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:C)" CVSS_version="2.0" modified="2007-01-22" name="CVE-2007-0396" published="2007-01-19" seq="2007-0396" severity="High" type="CVE"><desc><descript source="cve">Unspecified vulnerability in HP-UX B.11.23, when running IPFilter in combination with PHNE_34474, allows remote attackers to cause a denial of service (system crash) via unspecified vectors.</descript></desc><loss_types><avail/></loss_types><range><network/></range><refs><ref source="HP" url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00837319">HPSBUX02181</ref><ref source="BID" url="http://www.securityfocus.com/bid/22103">22103</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0234">ADV-2007-0234</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1017527">1017527</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/23800">23800</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31565">
hp-ipfilter-dos(31565)</ref></refs><vuln_soft><prod name="HP-UX" vendor="HP"><vers edition="IA64 64-bit" num="B.11.23"/></prod></vuln_soft></entry><entry CVSS_base_score="6.4" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="4.9" CVSS_score="6.4" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_version="2.0" modified="2007-01-22" name="CVE-2007-0397" published="2007-01-19" seq="2007-0397" severity="Medium" type="CVE"><desc><descript source="cve">The Cisco Security Monitoring, Analysis and Response System (CS-MARS) before 4.2.3 and Adaptive Security Device Manager (ASDM) before 5.2(2.54) do not validate the SSL/TLS certificates or SSH public keys when connecting to devices, which allows remote attackers to spoof those devices to obtain sensitive information or generate incorrect information.</descript></desc><loss_types><conf/><int/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref patch="1" source="CISCO" url="http://www.cisco.com/en/US/products/products_security_advisory09186a00807c517f.shtml">20070118 SSL/TLS Certificate and SSH Public Key Validation Vulnerability</ref><ref source="BID" url="http://www.securityfocus.com/bid/22111">
22111</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0245">
ADV-2007-0245</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1017535">
1017535</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1017536">
1017536</ref><ref source="SECUNIA" url="http://secunia.com/advisories/23836">
23836</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31567">
cisco-csmars-asdm-device-spoofing(31567)</ref></refs><vuln_soft><prod name="Cisco Security Monitoring Analysis and Response System" vendor="Cisco"><vers num="4.2.3"/></prod><prod name="Adaptive Security Device Manager" vendor="Cisco"><vers num="5.2.53"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-08-07" name="CVE-2007-0398" published="2007-01-22" seq="2007-0398" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in forum.php3 in Arnaud Guyonne (aka Arnotic) a-forum allow remote attackers to inject arbitrary web script or HTML via the (1) Sujet or (2) Pseudo field.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/457503/100/0/threaded">20070119 a-forum xss</ref><ref source="VIM" url="http://www.attrition.org/pipermail/vim/2007-January/001249.html">20070122 a-forum xss - who? what? where?</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31610">aforum-unspecified-xss(31610)</ref></refs><vuln_soft><prod name="a-forum" vendor="Arnotic"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="6.0" CVSS_exploit_subscore="6.8" CVSS_impact_subscore="6.4" CVSS_score="6.0" CVSS_vector="(AV:N/AC:M/Au:S/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-01-22" name="CVE-2007-0399" published="2007-01-22" seq="2007-0399" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in index.php in Simple Machines Forum (SMF) 1.1 RC3 allow remote authenticated users to inject arbitrary web script or HTML via the (1) recipient or (2) BCC field when selecting send in a pm action.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/457508/100/0/threaded">20070120 SMF </ref><ref source="" url="http://aria-security.com/forum/showthread.php?p=128"></ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/457627/100/0/threaded">
20070121 Re: SMF &quot;index.php?action=pm&quot; Cross Site-Scripting</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/457761/100/200/threaded">
20070122 Re: Re: Re: SMF &quot;index.php?action=pm&quot; Cross Site-Scripting</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/458194/100/100/threaded">
20070126 Re: Re: Re: Re: SMF &quot;index.php?action=pm&quot; Cross Site-Scripting</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/458904/100/0/threaded">
20070202 Re: SMF &quot;index.php?action=pm&quot; Cross Site-Scripting</ref><ref source="BID" url="http://www.securityfocus.com/bid/22143">
22143</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31612">
smf-pm-xss(31612)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2169">2169</ref></refs><vuln_soft><prod name="Simple Machines Forum" vendor="Simple Machines"><vers num="1.1 RC3"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-01-22" name="CVE-2007-0400" published="2007-01-22" seq="2007-0400" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in admin/memberlist.php in Easebay Resources Login Manager 3.0 allows remote attackers to inject arbitrary web script or HTML via the keyword parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/457505/100/0/threaded">20070120 Login Manager Multiple HTML Injections</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31614">
loginmanager-memberlist-xss(31614)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2167">2167</ref></refs><vuln_soft><prod name="Login Manager" vendor="Easebay Resources"><vers num="3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-01-22" name="CVE-2007-0401" published="2007-01-22" seq="2007-0401" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in admin/memberlist.php in Easebay Resources Login Manager 3.0 allows remote attackers to execute arbitrary SQL commands via the init_row parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/457505/100/0/threaded">20070120 Login Manager Multiple HTML Injections</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2167">2167</ref></refs><vuln_soft><prod name="Login Manager" vendor="Easebay Resources"><vers num="3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-01-22" name="CVE-2007-0402" published="2007-01-22" seq="2007-0402" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in admin/edit_member.php in Easebay Resources Paypal Subscription Manager allows remote attackers to inject arbitrary web script or HTML via the username parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/457506/100/0/threaded">20070120 Paypal Subscription Manager Multiple HTML Injections</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31618">
psm-editmember-xss(31618)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2168">2168</ref></refs><vuln_soft><prod name="Paypal Subscription Manager" vendor="Easebay Resources"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-01-22" name="CVE-2007-0403" published="2007-01-22" seq="2007-0403" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in admin/memberlist.php in Easebay Resources Paypal Subscription Manager allows remote attackers to execute arbitrary SQL commands via the keyword parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/457506/100/0/threaded">20070120 Paypal Subscription Manager Multiple HTML Injections</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31616">
psm-memberlist-sql-injection(31616)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2168">2168</ref></refs><vuln_soft><prod name="Paypal Subscription Manager" vendor="Easebay Resources"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-01-22" name="CVE-2007-0404" published="2007-01-22" seq="2007-0404" severity="High" type="CVE"><desc><descript source="cve">bin/compile-messages.py in Django 0.95 does not quote argument strings before invoking the msgfmt program through the os.system function, which allows attackers to execute arbitrary commands via shell metacharacters in a (1) .po or (2) .mo file.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://code.djangoproject.com/changeset/3592"></ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/23826">23826</ref><ref source="BID" url="http://www.securityfocus.com/bid/22134">
22134</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31627">
django-po-code-execution(31627)</ref></refs><vuln_soft><prod name="Django" vendor="Django Project"><vers num="0.95"/></prod></vuln_soft></entry><entry CVSS_base_score="6.5" CVSS_exploit_subscore="8.0" CVSS_impact_subscore="6.4" CVSS_score="6.5" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-08-07" name="CVE-2007-0405" published="2007-01-22" seq="2007-0405" severity="Medium" type="CVE"><desc><descript source="cve">The LazyUser class in the AuthenticationMiddleware for Django 0.95 does not properly cache the user name across requests, which allows remote authenticated users to gain the privileges of a different user.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/><input/></vuln_types><range><network/></range><refs><ref source="" url="http://code.djangoproject.com/changeset/3754"></ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/23826">23826</ref><ref source="BID" url="http://www.securityfocus.com/bid/22138">22138</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31628">django-request-session-hijacking(31628)</ref></refs><vuln_soft><prod name="Django" vendor="Django Project"><vers num="0.95"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-01-22" name="CVE-2007-0406" published="2007-01-22" seq="2007-0406" severity="Medium" type="CVE"><desc><descript source="cve">Multiple buffer overflows in the (1) main function in (a) client.c, and the (2) server_setup and (3) server_client_connect functions in (b) server.c in gxine 0.5.9 and earlier allow local users to cause a denial of service (daemon crash) or gain privileges via a long HOME environment variable.  NOTE: some of these details are obtained from third party information.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref source="" url="http://sourceforge.net/project/shownotes.php?group_id=9655&amp;release_id=476891"></ref><ref source="" url="http://xinehq.de/index.php/news?show_category_id=1"></ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0259">ADV-2007-0259</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31604">
gxine-serversetup-serverclient-bo(31604)</ref></refs><vuln_soft><prod name="gxine" vendor="gxine"><vers num="0.5.9" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-01-22" name="CVE-2007-0407" published="2007-01-22" seq="2007-0407" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in Operation/User.pm in Plain Black WebGUI before 7.3.5 (beta) allows remote attackers to inject arbitrary web script or HTML via the username parameter during anonymous registration, a different vector than CVE-2007-0308.  NOTE: it is possible that a separate &quot;WikiPage titles&quot; issue was also fixed.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://www.plainblack.com/bugs/tracker/security-update-cross-site-scripting-vulnerability"></ref><ref source="" url="http://www.plainblack.com/downloads/builds/7.3.5-beta/WebGUI/docs/changelog/7.x.x.txt"></ref><ref source="BID" url="http://www.securityfocus.com/bid/22114">22114</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0242">ADV-2007-0242</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/23754">23754</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31573">webgui-username-xss(31573)</ref></refs><vuln_soft><prod name="WebGUI" vendor="Plain Black"><vers num="7.3.4 Beta"/><vers num="7.2.3"/><vers num="6.8.6"/><vers num="6.8.5"/><vers num="6.8.4"/><vers num="6.8.3"/><vers num="6.8.2"/><vers num="6.8.1"/><vers num="6.7.6"/><vers num="6.7.5"/><vers num="6.7.4"/><vers num="6.7.3"/><vers num="6.7.2"/><vers num="6.7.1"/><vers num="6.7.0"/><vers num="6.6.5"/><vers num="6.6.4"/><vers num="6.6.3"/><vers num="6.6.2"/><vers num="6.6.1"/><vers num="6.6.0"/><vers num="6.5.6"/><vers num="6.5.5"/><vers num="6.5.4"/><vers num="6.5.3"/><vers num="6.5.2"/><vers num="6.5.1"/><vers num="6.5.0"/><vers num="6.4.0"/><vers num="6.3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-01-23" name="CVE-2007-0408" published="2007-01-22" seq="2007-0408" severity="High" type="CVE"><desc><descript source="cve">BEA Weblogic Server 8.1 through 8.1 SP4 does not properly validate client certificates when reusing cached connections, which allows remote attackers to obtain access via an untrusted X.509 certificate.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="BEA" url="http://dev2dev.bea.com/pub/advisory/202">BEA07-135.00</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0213">ADV-2007-0213</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1017519">1017519</ref><ref source="SECUNIA" url="http://secunia.com/advisories/23750">23750</ref><ref source="BID" url="http://www.securityfocus.com/bid/22082">22082</ref></refs><vuln_soft><prod name="WebLogic Server" vendor="BEA Systems"><vers num="8.1 SP4" prev="1"/><vers num="8.1"/></prod></vuln_soft></entry><entry CVSS_base_score="1.5" CVSS_exploit_subscore="2.7" CVSS_impact_subscore="2.9" CVSS_score="1.5" CVSS_vector="(AV:L/AC:M/Au:S/C:P/I:N/A:N)" CVSS_version="2.0" modified="2007-01-23" name="CVE-2007-0409" published="2007-01-22" seq="2007-0409" severity="Low" type="CVE"><desc><descript source="cve">BEA WebLogic 7.0 through 7.0 SP6, 8.1 through 8.1 SP4, and 9.0 initial release does not encrypt passwords stored in the JDBCDataSourceFactory MBean Properties, which allows local administrative users to read the cleartext password.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="BEA" url="http://dev2dev.bea.com/pub/advisory/203">BEA07-136.00</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0213">ADV-2007-0213</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1017525">1017525</ref><ref source="SECUNIA" url="http://secunia.com/advisories/23750">23750</ref><ref source="BID" url="http://www.securityfocus.com/bid/22082">22082</ref></refs><vuln_soft><prod name="WebLogic" vendor="BEA Systems"><vers num="7.0 SP6" prev="1"/><vers num="7.0"/><vers num="8.1 SP4" prev="1"/><vers num="8.1"/><vers num="9.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0" modified="2007-01-23" name="CVE-2007-0410" published="2007-01-22" seq="2007-0410" severity="Medium" type="CVE"><desc><descript source="cve">Unspecified vulnerability in the thread management in BEA WebLogic 7.0 through 7.0 SP6, 8.1 through 8.1 SP5, 9.0, and 9.1, when T3 authentication is used, allows remote attackers to cause a denial of service (thread and system hang) via unspecified &quot;sequences of events.&quot;</descript></desc><loss_types><avail/></loss_types><range><network/></range><refs><ref adv="1" patch="1" source="BEA" url="http://dev2dev.bea.com/pub/advisory/204">BEA07-137.00</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0213">ADV-2007-0213</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1017525">1017525</ref><ref source="SECUNIA" url="http://secunia.com/advisories/23750">23750</ref><ref source="BID" url="http://www.securityfocus.com/bid/22082">22082</ref></refs><vuln_soft><prod name="WebLogic" vendor="BEA Systems"><vers num="7.0 SP6" prev="1"/><vers num="7.0"/><vers num="8.0 SP5" prev="1"/><vers num="8.1"/><vers num="9.1"/><vers num="9.0"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-01-23" name="CVE-2007-0411" published="2007-01-22" seq="2007-0411" severity="Medium" type="CVE"><desc><descript source="cve">BEA WebLogic Server 8.1 through 8.1 SP5, 9.0, 9.1, and 9.2 Gold, when WS-Security is used, does not properly validate certificates, which allows remote attackers to conduct a man-in-the-middle (MITM) attack.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><other/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="BEA" url="http://dev2dev.bea.com/pub/advisory/205">BEA07-138.00</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0213">ADV-2007-0213</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1017525">1017525</ref><ref source="SECUNIA" url="http://secunia.com/advisories/23750">23750</ref><ref source="BID" url="http://www.securityfocus.com/bid/22082">22082</ref></refs><vuln_soft><prod name="WebLogic" vendor="BEA Systems"><vers num="8.1 SP5" prev="1"/><vers num="8.1"/><vers num="9.0"/><vers num="9.1"/><vers edition="Gold" num="9.2"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0" modified="2007-01-23" name="CVE-2007-0412" published="2007-01-22" seq="2007-0412" severity="Medium" type="CVE"><desc><descript source="cve">BEA WebLogic Server 6.1 through 6.1 SP7, 7.0 through 7.0 SP7, and 8.1 through 8.1 SP5 allows remote attackers to read arbitrary files inside the class-path property via .ear or exploded .ear files that use the manifest class-path property to point to utility jar files.</descript></desc><loss_types><conf/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="BEA" url="http://dev2dev.bea.com/pub/advisory/206">BEA07-139.00</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0213">ADV-2007-0213</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1017525">1017525</ref><ref source="SECUNIA" url="http://secunia.com/advisories/23750">23750</ref><ref source="BID" url="http://www.securityfocus.com/bid/22082">22082</ref></refs><vuln_soft><prod name="WebLogic Server" vendor="BEA Systems"><vers num="6.1 SP7" prev="1"/><vers num="6.1"/><vers num="7.0 SP7" prev="1"/><vers num="7.0"/><vers num="8.1 SP5" prev="1"/><vers num="8.1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.4" CVSS_exploit_subscore="3.4" CVSS_impact_subscore="6.4" CVSS_score="4.4" CVSS_vector="(AV:L/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2008-01-02" name="CVE-2007-0413" published="2007-01-22" seq="2007-0413" severity="Medium" type="CVE"><desc><descript source="cve">BEA WebLogic Server 8.1 through 8.1 SP5 stores cleartext data in a backup of config.xml after offline editing, which allows local users to obtain sensitive information by reading this backup file.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="BEA" url="http://dev2dev.bea.com/pub/advisory/207">BEA07-140.00</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0213">ADV-2007-0213</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1017525">1017525</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/23750">23750</ref><ref source="BID" url="http://www.securityfocus.com/bid/22082">22082</ref></refs><vuln_soft><prod name="WebLogic Server" vendor="BEA Systems"><vers num="8.1 SP5" prev="1"/><vers num="8.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0" modified="2007-01-23" name="CVE-2007-0414" published="2007-01-22" seq="2007-0414" severity="Medium" type="CVE"><desc><descript source="cve">BEA WebLogic Server 6.1 through 6.1 SP7, 7.0 through 7.0 SP6, 8.1 through 8.1 SP5, and 9.0 allows remote attackers to cause a denial of service (server hang) via certain requests that cause muxer threads to block when processing error pages.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="BEA" url="http://dev2dev.bea.com/pub/advisory/208">BEA07-141.00</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0213">ADV-2007-0213</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1017525">1017525</ref><ref source="SECUNIA" url="http://secunia.com/advisories/23750">23750</ref><ref source="BID" url="http://www.securityfocus.com/bid/22082">22082</ref></refs><vuln_soft><prod name="WebLogic Server" vendor="BEA Systems"><vers num="6.1 SP7" prev="1"/><vers num="6.1"/><vers num="7.0 SP6" prev="1"/><vers num="7.0"/><vers num="8.1 SP5" prev="1"/><vers num="8.1"/><vers num="9.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0" modified="2007-01-23" name="CVE-2007-0415" published="2007-01-22" seq="2007-0415" severity="Medium" type="CVE"><desc><descript source="cve">BEA WebLogic Server 8.1 through 8.1 SP5 does not properly enforce access control after a dynamic update and dynamic redeployment of an application that is implemented through exploded jars, which allows attackers to bypass intended access restrictions.</descript></desc><loss_types><conf/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="BEA" url="http://dev2dev.bea.com/pub/advisory/209">BEA07-142.00</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0213">ADV-2007-0213</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1017525">1017525</ref><ref source="SECUNIA" url="http://secunia.com/advisories/23750">23750</ref><ref source="BID" url="http://www.securityfocus.com/bid/22082">22082</ref></refs><vuln_soft><prod name="WebLogic Server" vendor="BEA Systems"><vers num="8.1 SP5" prev="1"/><vers num="8.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-01-23" name="CVE-2007-0416" published="2007-01-22" seq="2007-0416" severity="High" type="CVE"><desc><descript source="cve">The WSEE runtime (WS-Security runtime) in BEA WebLogic Server 9.0 and 9.1 does not verify credentials when decrypting client messages, which allows remote attackers to bypass application security.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="BEA" url="http://dev2dev.bea.com/pub/advisory/210">BEA07-143.00</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0213">ADV-2007-0213</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1017525">1017525</ref><ref source="SECUNIA" url="http://secunia.com/advisories/23750">23750</ref><ref source="BID" url="http://www.securityfocus.com/bid/22082">22082</ref></refs><vuln_soft><prod name="WebLogic Server" vendor="BEA Systems"><vers num="9.0"/><vers num="9.1"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-01-23" name="CVE-2007-0417" published="2007-01-22" seq="2007-0417" severity="High" type="CVE"><desc><descript source="cve">BEA WebLogic Server 7.0 through 7.0 SP7, 8.1 through 8.1 SP5, 9.0, and 9.1, when using the WebLogic Server 6.1 compatibility realm, allows attackers to execute certain EJB container persistence operations with an administrative identity.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" other="1" user="1"/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="BEA" url="http://dev2dev.bea.com/pub/advisory/211">BEA07-144.00</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0213">ADV-2007-0213</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1017525">1017525</ref><ref source="SECUNIA" url="http://secunia.com/advisories/23750">23750</ref><ref source="BID" url="http://www.securityfocus.com/bid/22082">22082</ref></refs><vuln_soft><prod name="WebLogic Server" vendor="BEA Systems"><vers num="7.0 SP7" prev="1"/><vers num="7.0"/><vers num="8.1 SP5"/><vers num="8.1"/><vers num="9.0"/><vers num="9.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-01-23" name="CVE-2007-0418" published="2007-01-22" seq="2007-0418" severity="High" type="CVE"><desc><descript source="cve">BEA WebLogic Server 7.0 through 7.0 SP6, 8.1 through 8.1 SP5, 9.0, and 9.1 does not enforce a security policy that declares permissions for EJB methods that have array parameters, which allows remote attackers to obtain unauthorized access to these methods.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="BEA" url="http://dev2dev.bea.com/pub/advisory/212">BEA07-145.00</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0213">ADV-2007-0213</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1017525">1017525</ref><ref source="SECUNIA" url="http://secunia.com/advisories/23750">23750</ref><ref source="BID" url="http://www.securityfocus.com/bid/22082">22082</ref></refs><vuln_soft><prod name="WebLogic Server" vendor="BEA Systems"><vers num="7.0 SP6" prev="1"/><vers num="7.0"/><vers num="8.1 SP5" prev="1"/><vers num="8.1"/><vers num="9.0"/><vers num="9.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0" modified="2007-01-23" name="CVE-2007-0419" published="2007-01-22" seq="2007-0419" severity="Medium" type="CVE"><desc><descript source="cve">The BEA WebLogic Server proxy plug-in before June 2006 for the Apache HTTP Server does not properly handle protocol errors, which allows remote attackers to cause a denial of service (server outage).</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="BEA" url="http://dev2dev.bea.com/pub/advisory/213">BEA07-146.00</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0213">ADV-2007-0213</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1017525">1017525</ref><ref source="SECUNIA" url="http://secunia.com/advisories/23750">23750</ref><ref source="BID" url="http://www.securityfocus.com/bid/22082">22082</ref></refs><vuln_soft><prod name="WebLogic Server" vendor="BEA Systems"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0" modified="2007-01-23" name="CVE-2007-0420" published="2007-01-22" seq="2007-0420" severity="Medium" type="CVE"><desc><descript source="cve">BEA WebLogic Server 9.0, 9.1, and 9.2 Gold allows remote attackers to obtain sensitive information via malformed HTTP requests, which reveal data from previous requests.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="BEA" url="http://dev2dev.bea.com/pub/advisory/214">BEA07-147.00</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0213">ADV-2007-0213</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1017525">1017525</ref><ref source="SECUNIA" url="http://secunia.com/advisories/23750">23750</ref><ref source="BID" url="http://www.securityfocus.com/bid/22082">22082</ref></refs><vuln_soft><prod name="WebLogic Server" vendor="BEA Systems"><vers num="9.0"/><vers num="9.1"/><vers edition="Gold" num="9.2"/></prod></vuln_soft></entry><entry CVSS_base_score="6.4" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="4.9" CVSS_score="6.4" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:P)" CVSS_version="2.0" modified="2007-01-23" name="CVE-2007-0421" published="2007-01-22" seq="2007-0421" severity="Medium" type="CVE"><desc><descript source="cve">BEA WebLogic Server 6.1 through 6.1 SP7, and 7.0 through 7.0 SP7 allows remote attackers to cause a denial of service (disk consumption) via requests containing malformed headers, which cause a large amount of data to be written to the server log.</descript></desc><loss_types><avail/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="BEA" url="http://dev2dev.bea.com/pub/advisory/215">BEA07-148.00</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0213">ADV-2007-0213</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1017525">1017525</ref><ref source="SECUNIA" url="http://secunia.com/advisories/23750">23750</ref><ref source="BID" url="http://www.securityfocus.com/bid/22082">22082</ref></refs><vuln_soft><prod name="WebLogic Server" vendor="BEA Systems"><vers num="6.1 SP7" prev="1"/><vers num="6.1"/><vers num="7.0 SP7" prev="1"/><vers num="7.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0" modified="2007-01-23" name="CVE-2007-0422" published="2007-01-22" seq="2007-0422" severity="Medium" type="CVE"><desc><descript source="cve">BEA WebLogic Server 9.0, 9.1, and 9.2 Gold, when running on Solaris 9, allows remote attackers to cause a denial of service (server inaccessibility) via manipulated socket connections.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="BEA" url="http://dev2dev.bea.com/pub/advisory/217">BEA07-150.00</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0213">ADV-2007-0213</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1017525">1017525</ref><ref source="SECUNIA" url="http://secunia.com/advisories/23750">23750</ref><ref source="BID" url="http://www.securityfocus.com/bid/22082">22082</ref></refs><vuln_soft><prod name="WebLogic Server" vendor="BEA Systems"><vers num="9.0"/><vers num="9.1"/><vers edition="Gold" num="9.2"/></prod></vuln_soft></entry><entry CVSS_base_score="4.4" CVSS_exploit_subscore="3.4" CVSS_impact_subscore="6.4" CVSS_score="4.4" CVSS_vector="(AV:L/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-01-23" name="CVE-2007-0423" published="2007-01-22" seq="2007-0423" severity="Medium" type="CVE"><desc><descript source="cve">BEA WebLogic Portal 9.2 does not properly handle when an administrator deletes entitlements for a role, which causes other role entitlements to be &quot;inadvertently affected,&quot; which has an unknown impact.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="BEA" url="http://dev2dev.bea.com/pub/advisory/218">BEA07-151.00</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0213">ADV-2007-0213</ref><ref source="SECUNIA" url="http://secunia.com/advisories/23750">23750</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1017521">
1017521</ref><ref source="BID" url="http://www.securityfocus.com/bid/22082">22082</ref></refs><vuln_soft><prod name="WebLogic Portal" vendor="BEA Systems"><vers num="9.2"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0" modified="2007-01-23" name="CVE-2007-0424" published="2007-01-22" seq="2007-0424" severity="Medium" type="CVE"><desc><descript source="cve">Unspecified vulnerability in the BEA WebLogic Server proxy plug-in for Netscape Enterprise Server before September 2006 for Netscape Enterprise Server allow remote attackers to cause a denial of service via certain requests that trigger errors that lead to a server being marked as unavailable, hosting web server failure, or CPU consumption.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="BEA" url="http://dev2dev.bea.com/pub/advisory/219">BEA07-152.00</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0213">ADV-2007-0213</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1017525">1017525</ref><ref source="SECUNIA" url="http://secunia.com/advisories/23750">23750</ref><ref source="BID" url="http://www.securityfocus.com/bid/22082">22082</ref></refs><vuln_soft><prod name="WebLogic Server" vendor="BEA Systems"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-01-24" name="CVE-2007-0425" published="2007-01-22" seq="2007-0425" severity="High" type="CVE"><desc><descript source="cve">Unspecified vulnerability in BEA WebLogic Platform and Server 8.1 through 8.1 SP5, and JRockit 1.4.2 R4.5 and earlier, allows attackers to gain privileges via unspecified vectors, related to an &quot;overflow condition,&quot; probably a buffer overflow.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="BEA" url="http://dev2dev.bea.com/pub/advisory/222">BEA07-155.00</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0213">ADV-2007-0213</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1017525">1017525</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/23750">23750</ref></refs><vuln_soft><prod name="WebLogic Platform and Server" vendor="BEA Systems"><vers num="8.1 SP5" prev="1"/><vers num="8.1"/></prod><prod name="JRockit" vendor="BEA Systems"><vers num="1.4.2 R4.5" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-01-24" name="CVE-2007-0426" published="2007-01-22" seq="2007-0426" severity="Medium" type="CVE"><desc><descript source="cve">BEA WebLogic Portal 9.2, when running in a WebLogic Server clustered environment using WebLogic Portal entitlements, does not properly propagate entitlement policy changes if the changes are made on a managed server while the Administrative Server is unavailable, which might allow attackers to bypass intended restrictions.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="BEA" url="http://dev2dev.bea.com/pub/advisory/223">BEA07-156.00</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0213">ADV-2007-0213</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/23750">23750</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1017521">
1017521</ref><ref source="BID" url="http://www.securityfocus.com/bid/22082">22082</ref></refs><vuln_soft><prod name="WebLogic Portal" vendor="BEA Systems"><vers num="9.2"/></prod></vuln_soft></entry><entry CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" CVSS_score="9.3" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-01-24" name="CVE-2007-0427" published="2007-01-22" seq="2007-0427" severity="High" type="CVE"><desc><descript source="cve">Stack-based buffer overflow in Microsoft Help Workshop 4.03.0002 allows user-assisted remote attackers to execute arbitrary code via a help project (.HPJ) file with a long HLP field in the OPTIONS section.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/457436/100/0/threaded">20070119 Help project files (.HPJ) buffer overflow vulnerability in Microsoft Help Workshop</ref><ref source="" url="http://www.anspi.pl/~porkythepig/visualization/hpj-x01.cpp"></ref><ref source="BID" url="http://www.securityfocus.com/bid/22135">22135</ref><ref source="SECUNIA" url="http://secunia.com/advisories/23862">
23862</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2177">2177</ref></refs><vuln_soft><prod name="Help Workshop" vendor="Microsoft"><vers num="4.03.0002"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0" modified="2007-01-23" name="CVE-2007-0428" published="2007-01-22" seq="2007-0428" severity="Medium" type="CVE"><desc><descript source="cve">Unspecified vulnerability in the chtbl_lookup function in hash.c for WzdFTPD 8.0 and earlier allows remote attackers to cause a denial of service via a crafted FTP command, probably due to a NULL pointer dereference.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/457454/100/0/threaded">20070119 WzdFTPD &lt; 8.1 Denial of service</ref><ref adv="1" source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2007-January/051896.html">20070119 WzdFTPD &lt; 8.1 Denial of service</ref><ref adv="1" source="" url="http://www.s21sec.com/avisos/s21sec-033-en.txt"></ref><ref adv="1" source="SECTRACK" url="http://securitytracker.com/id?1017537">1017537</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31599">wzdftpd-ftp-dos(31599)</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0277">
ADV-2007-0277</ref><ref source="SECUNIA" url="http://secunia.com/advisories/23852">
23852</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2171">2171</ref></refs><vuln_soft><prod name="wzdftpd" vendor="wzdftpd"><vers num="8.0" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0" modified="2007-01-23" name="CVE-2007-0429" published="2007-01-22" seq="2007-0429" severity="Medium" type="CVE"><desc><descript source="cve">DivXBrowserPlugin (aka DivX Web Player) npdivx32.dll, as distributed with DivX Player 6.4.1, allows remote attackers to cause a denial of service (Internet Explorer 7 crash) by invoking the GoWindowed method for a certain instance of the ActiveX object.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref source="" url="http://www.milw0rm.com/exploits/3157"></ref><ref source="BID" url="http://www.securityfocus.com/bid/22133">22133</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31601">divx-divxbrowserplugin-dos(31601)</ref><ref source="MILW0RM" url="http://milw0rm.com/exploits/3157">

3157</ref></refs><vuln_soft><prod name="DivX Player" vendor="DivX"><vers num="6.4.1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.9" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.9" CVSS_score="4.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:C)" CVSS_version="2.0" modified="2007-01-23" name="CVE-2007-0430" published="2007-01-22" seq="2007-0430" severity="Medium" type="CVE"><desc><descript source="cve">The shared_region_map_file_np function in Apple Mac OS X 10.4.8 and earlier kernel allows local users to cause a denial of service (memory corruption) via a large mappingCount value.</descript></desc><loss_types><avail/></loss_types><vuln_types><input bound="1"/></vuln_types><range><local/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/457466/100/0/threaded">20070119 [RISE-2007001] Apple Mac OS X 10.4.x kernel shared_region_map_file_np() memory corruption vulnerability</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0275">
ADV-2007-0275</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1017538">
1017538</ref><ref source="SECUNIA" url="http://secunia.com/advisories/23823">
23823</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31645">
macos-sharedregionmapfilenp-dos(31645)</ref><ref source="" url="http://risesecurity.org/advisory.php?id=RISE-2007001.txt"></ref><ref source="OSVDB" url="http://www.osvdb.org/32942">32942</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2178">2178</ref></refs><vuln_soft><prod name="Mac OS X" vendor="Apple"><vers num="10.4.8" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.8" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.9" CVSS_score="7.8" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_version="2.0" modified="2007-01-23" name="CVE-2007-0431" published="2007-01-22" seq="2007-0431" severity="High" type="CVE"><desc><descript source="cve">AVM Fritz!Box 7050, and possibly other product models, allows remote attackers to cause a denial of service (VoIP application crash) via a zero-length UDP packet to the SIP port (port 5060).</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/457406/100/0/threaded">20070119 DoS against AVM Fritz!Box 7050 (and others)</ref><ref source="FULLDISC" url="http://archives.neohapsis.com/archives/fulldisclosure/2007-01/0387.html">20070119 DoS against AVM Fritz!Box 7050 (and others)</ref><ref source="" url="http://mazzoo.de/blog/2007/01/18#FritzBox_DoS"></ref><ref source="BID" url="http://www.securityfocus.com/bid/22130">22130</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/457829/100/0/threaded">
20070123 Re: DoS against AVM Fritz!Box 7050 (and others)</ref><ref source="" url="ftp://ftp.avm.de/fritz.box/fritzbox.fon_wlan_7050/firmware/info.txt"></ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0272">
ADV-2007-0272</ref><ref source="SECUNIA" url="http://secunia.com/advisories/23868">
23868</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31633">
fritzbox-udp-packet-dos(31633)</ref></refs><vuln_soft><prod name="FRITZBox" vendor="AVM"><vers num="7050"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-01-23" name="CVE-2007-0432" published="2007-01-22" seq="2007-0432" severity="High" type="CVE"><desc><descript source="cve">BEA AquaLogic Service Bus 2.0, 2.1, and 2.5 does not properly reject malformed request messages to a proxy service, which might allow remote attackers to bypass authorization policies and route requests to back-end services or conduct other unauthorized activities.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" source="BEA" url="http://dev2dev.bea.com/pub/advisory/224">BEA07-157.00</ref><ref adv="1" source="SECTRACK" url="http://securitytracker.com/id?1017523">1017523</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/23786">23786</ref><ref source="BID" url="http://www.securityfocus.com/bid/22082">22082</ref></refs><vuln_soft><prod name="AquaLogic Service Bus" vendor="BEA Systems"><vers num="2.0"/><vers num="2.1"/><vers num="2.5"/></prod></vuln_soft></entry><entry CVSS_base_score="6.5" CVSS_exploit_subscore="8.0" CVSS_impact_subscore="6.4" CVSS_score="6.5" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-01-23" name="CVE-2007-0433" published="2007-01-22" seq="2007-0433" severity="Medium" type="CVE"><desc><descript source="cve">Unspecified vulnerability in BEA AquaLogic Enterprise Security 2.0 through 2.0 SP2, 2.1 through 2.1 SP1, and 2.2, when using Active Directory LDAP for authentication, allows remote authenticated users to access the server even after the account has been disabled.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="BEA" url="http://dev2dev.bea.com/pub/advisory/221">BEA07-154.00</ref><ref adv="1" source="SECTRACK" url="http://securitytracker.com/id?1017524">1017524</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/23786">23786</ref><ref source="BID" url="http://www.securityfocus.com/bid/22082">22082</ref></refs><vuln_soft><prod name="AquaLogic Service Bus" vendor="BEA Systems"><vers num="2.0"/><vers num="2.0 SP1"/><vers num="2.0 SP2"/><vers num="2.1"/><vers num="2.1 SP1"/><vers num="2.2"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-01-23" name="CVE-2007-0434" published="2007-01-22" seq="2007-0434" severity="Medium" type="CVE"><desc><descript source="cve">BEA AquaLogic Enterprise Security 2.0 through 2.0 SP2, 2.1 through 2.1 SP1, and 2.2 does not properly set the severity level of audit events when the system load is high, which might make it easier for attackers to avoid detection.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/><design/></vuln_types><range><local/></range><refs><ref adv="1" source="BEA" url="http://dev2dev.bea.com/pub/advisory/220">BEA07-153.00</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/23786">23786</ref><ref source="BID" url="http://www.securityfocus.com/bid/22082">22082</ref></refs><vuln_soft><prod name="AquaLogic Enterprise Security" vendor="BEA Systems"><vers num="2.0"/><vers num="2.0 SP1"/><vers num="2.0 SP2"/><vers num="2.1"/><vers num="2.1 SP1"/><vers num="2.2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-01-23" name="CVE-2007-0435" published="2007-01-22" seq="2007-0435" severity="High" type="CVE"><desc><descript source="cve">T-Com Speedport 500V routers with firmware 1.31 allow remote attackers to bypass authentication and reconfigure the device via a LOGINKEY=TECOM cookie value.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/457453/100/0/threaded">20070119 Virginity Security Advisory 2007-001 : T-Com Speedport 500V Login bypass</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/457645/100/0/threaded">
20070121 Re: Virginity Security Advisory 2007-001 : T-Com Speedport 500V Login bypass</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/457656/100/0/threaded">
20070122 Re: Virginity Security Advisory 2007-001 : T-Com Speedport 500V Login bypass</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/460319/100/0/threaded">
20070216 Re: Virginity Security Advisory 2007-001 : T-Com Speedport 500V Login bypass</ref><ref source="BID" url="http://www.securityfocus.com/bid/22160">
22160</ref><ref source="SECUNIA" url="http://secunia.com/advisories/23853">
23853</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31621">
tcom-login-authentication-bypass(31621)</ref></refs><vuln_soft><prod name="Speedport 500V" vendor="T-Com"><vers num="firmware 1.31"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-08-03" name="CVE-2007-0436" published="2007-02-03" seq="2007-0436" severity="Medium" type="CVE"><desc><descript source="cve">Barron McCann X-Kryptor Driver BMS1446HRR (Xgntr BMS1351 Install BMS1472) in X-Kryptor Secure Client does not drop privileges when launching an Explorer window in response to a help command, which allows local users to gain LocalSystem privileges via interactive use of Explorer.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref source="" url="http://jvn.jp/niscc/NISCC-462660/index.html"></ref><ref source="" url="http://www.cpni.gov.uk/Products/advisories/default.aspx?id=al-20070129-0107.xml"></ref><ref source="" url="http://www.cpni.gov.uk/Products/vulnerabilitydisclosures/default.aspx?id=va-20070129-0107.xml"></ref><ref source="" url="http://www.barronmccann.com/ISec/s2pressrelease.asp?PRID=141&amp;S2ID=14"></ref><ref source="" url="http://www.bemacpromotions.com/files/xkpatch462660.zip"></ref><ref source="BID" url="http://www.securityfocus.com/bid/22424">22424</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0496">ADV-2007-0496</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24045">24045</ref></refs><vuln_soft><prod name="Install" vendor="Barron McCann"><vers num="BMS1472"/></prod><prod name="Xgntr" vendor="Barron McCann"><vers num="BMS1351"/></prod><prod name="X-Kryptor Driver" vendor="Barron McCann"><vers num="BMS1446HRR"/></prod><prod name="X-Kryptor Secure Client" vendor="Barron McCann"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="3.5" CVSS_exploit_subscore="6.8" CVSS_impact_subscore="2.9" CVSS_score="3.5" CVSS_vector="(AV:N/AC:M/Au:S/C:N/I:P/A:N)" CVSS_version="2.0" modified="2007-08-22" name="CVE-2007-0437" published="2007-08-20" seq="2007-0437" severity="Low" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in the sample Cache&apos; Server Page (CSP) scripts in InterSystems Cache&apos; allow remote attackers to inject arbitrary web script or HTML via (1) the TO parameter to loop.csp, (2) the VALUE parameter to cookie.csp, and (3) the PAGE parameter to showsource.csp in csp/samples/; and allow remote authenticated users to inject arbitrary web script or HTML via (4) the ERROR parameter to csp/samples/xmlclasseserror.csp, and unspecified vectors in (5) object.csp and (6) lotteryhistory.csp in csp/samples/.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref source="" url="http://www.cpni.gov.uk/Products/alerts/2928.aspx"></ref><ref source="" url="http://www.mwrinfosecurity.com/advisories/mwri_cache-sample-files-xss-advisory_2007-04-04.pdf"></ref><ref source="" url="http://www.mwrinfosecurity.com/news/1658.html"></ref></refs><vuln_soft><prod name="Cache Database" vendor="InterSystems"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.1" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="6.4" CVSS_score="5.1" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-01-23" name="CVE-2007-0441" published="2007-01-23" seq="2007-0441" severity="Medium" type="CVE"><desc><descript source="cve">Unspecified vulnerability in HP OpenView Network Node Manager (OV NNM) 6.20, 6.4x, 7.01, and 7.50 allows remote attackers to execute arbitrary commands via unknown vectors.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><range><network/></range><refs><ref adv="1" patch="1" source="HP" url="http://www.securityfocus.com/archive/1/archive/1/456623/100/100/threaded">HPSBMA02176</ref><ref adv="1" source="SECTRACK" url="http://securitytracker.com/id?1017504">1017504</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0153">
ADV-2007-0153</ref></refs><vuln_soft><prod name="OpenView Network Node Manager" vendor="HP"><vers num="7.50"/><vers num="7.0.1"/><vers num="6.41"/><vers num="6.20"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" modified="2007-01-23" name="CVE-2007-0442" published="2007-01-23" seq="2007-0442" severity="Medium" type="CVE"><desc><descript source="cve">Unspecified vulnerability in IBM OS/400 R530 and R535 has unknown impact and remote attack vectors, related to an &quot;Integrity Problem&quot; involving LIC-TCPIP and TCP reset.  NOTE: it is possible that this issue is related to CVE-2004-0230, but this is not certain.</descript></desc><loss_types><int/></loss_types><range><network/></range><refs><ref source="AIXAPAR" url="http://www-1.ibm.com/support/docview.wss?uid=nas204b3e62c8a63af708625718e0043eddc">MA33861</ref><ref source="AIXAPAR" url="http://www-1.ibm.com/support/docview.wss?uid=nas2c8623b2ed01d45d08625718e0043edc2">MA33861</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/23765">23765</ref></refs><vuln_soft><prod name="OS_400" vendor="IBM"><vers num="R530"/><vers num="R535"/></prod></vuln_soft></entry><entry CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" CVSS_score="9.3" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-04-26" name="CVE-2007-0443" published="2007-04-24" seq="2007-0443" severity="High" type="CVE"><desc><descript source="cve">Multiple buffer overflows in the CDDBControl ActiveX control in Gracenote CDDB before 20070418 allow remote attackers to execute arbitrary code via long values for certain Proxy configuration parameters.</descript></desc><sols><sol source="nvd">The vendor has address this issue with the following information: http://www.gracenote.com/corporate/FAQs.html/faqset=update/page=0</sol></sols><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" patch="1" source="" url="http://www.zerodayinitiative.com/advisories/ZDI-07-021.html"></ref><ref source="" url="http://www.gracenote.com/corporate/FAQs.html/faqset=update/page=0"></ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/23567">23567</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017937">1017937</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/22924">22924</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/466403/100/0/threaded">

20070420 ZDI-07-021: GraceNote CDDBControl ActiveX Buffer Overflow Vulnerability</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1475">
ADV-2007-1475</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33773">
cddbcontrol-activex-bo(33773)</ref></refs><vuln_soft><prod name="CDDBControl ActiveX Control" vendor="GraceNote"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-08-07" name="CVE-2007-0444" published="2007-01-24" seq="2007-0444" severity="High" type="CVE"><desc><descript source="cve">Stack-based buffer overflow in the print provider library (cpprov.dll) in Citrix Presentation Server 4.0, MetaFrame Presentation Server 3.0, and MetaFrame XP 1.0 allows local users and remote attackers to execute arbitrary code via long arguments to the (1) EnumPrintersW and (2) OpenPrinter functions.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input/></vuln_types><range><local/></range><refs><ref source="" url="http://www.zerodayinitiative.com/advisories/ZDI-07-006.html"></ref><ref source="" url="http://support.citrix.com/article/CTX111686"></ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/458002/100/0/threaded">20070124 ZDI-07-006: Citrix Metaframe Presentation Server Print Provider Buffer Overflow Vulnerability</ref><ref source="" url="http://www.securityfocus.com/data/vulnerabilities/exploits/testlpc.c"></ref><ref source="BID" url="http://www.securityfocus.com/bid/22217">22217</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0328">ADV-2007-0328</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1017553">1017553</ref><ref source="SECUNIA" url="http://secunia.com/advisories/23869">23869</ref></refs><vuln_soft><prod name="Citrix MetaFrame XP" vendor="Citrix"><vers num="1.0"/></prod><prod name="Citrix Presentation Server" vendor="Citrix"><vers num="4.0"/><vers num="3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-04-06" name="CVE-2007-0445" published="2007-04-05" seq="2007-0445" severity="High" type="CVE"><desc><descript source="cve">Heap-based buffer overflow in the arj.ppl module in the OnDemand Scanner in Kaspersky Anti-Virus, Anti-Virus for Workstations, and Anti-Virus for File Servers 6.0, and Internet Security 6.0 before Maintenance Pack 2 build 6.0.2.614 allows remote attackers to execute arbitrary code via crafted ARJ archives.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="" url="http://www.zerodayinitiative.com/advisories/ZDI-07-013.html"></ref><ref patch="1" source="" url="http://www.kaspersky.com/technews?id=203038693"></ref><ref patch="1" source="" url="http://www.kaspersky.com/technews?id=203038694"></ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1268">ADV-2007-1268</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/24778">24778</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/464878/100/0/threaded">

20070405 ZDI-07-013: Kaspersky AntiVirus Engine ARJ Archive Parsing Heap Overflow Vulnerability</ref><ref source="BID" url="http://www.securityfocus.com/bid/23346">
23346</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017882">
1017882</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017883">
1017883</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33489">
kaspersky-arj-bo(33489)</ref></refs><vuln_soft><prod name="Kaspersky Internet Security" vendor="Kaspersky Lab"><vers num="6.0" prev="1"/></prod><prod name="Kaspersky Anti-Virus" vendor="Kaspersky Lab"><vers edition="Workstations" num="6.0"/><vers edition="File Servers" num="6.0"/><vers num="6.0"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-02-13" name="CVE-2007-0446" published="2007-02-08" seq="2007-0446" severity="High" type="CVE"><desc><descript source="cve">Stack-based buffer overflow in magentproc.exe for Hewlett-Packard Mercury LoadRunner Agent 8.0 and 8.1, Performance Center Agent 8.0 and 8.1, and Monitor over Firewall 8.1 allows remote attackers to execute arbitrary code via a packet with a long server_ip_name field to TCP port 54345, which triggers the overflow in mchan.dll.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="" url="http://www.zerodayinitiative.com/advisories/ZDI-07-007.html"></ref><ref adv="1" patch="1" source="HP" url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00854250">HPSBGN02187</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/459505/100/0/threaded">

20070208 ZDI-07-007: HP Mercury LoadRunner Agent Stack Overflow Vulnerability</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/303012">
VU#303012</ref><ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/r-123.shtml">
R-123</ref><ref source="BID" url="http://www.securityfocus.com/bid/22487">
22487</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0535">
ADV-2007-0535</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1017611">
1017611</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1017612">
1017612</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1017613">
1017613</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24112">
24112</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32390">
mercury-multiple-agent-bo(32390)</ref></refs><vuln_soft><prod name="Mercury Performance Center Agent" vendor="HP"><vers num="8.0"/><vers num="8.1"/></prod><prod name="Mercury Monitor over Firewall" vendor="HP"><vers num="8.1"/></prod><prod name="Mercury LoadRunner Agent" vendor="HP"><vers num="8.0"/><vers num="8.1"/></prod></vuln_soft></entry><entry CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" CVSS_score="9.3" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-10-26" name="CVE-2007-0447" published="2007-10-05" seq="2007-0447" severity="High" type="CVE"><desc><descript source="cve">Heap-based buffer overflow in the Decomposer component in multiple Symantec products allows remote attackers to execute arbitrary code via multiple crafted CAB archives.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs><ref source="" url="http://www.zerodayinitiative.com/advisories/ZDI-07-040.html"></ref><ref patch="1" source="" url="http://securityresponse.symantec.com/avcenter/security/Content/2007.07.11f.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/24282">24282</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/2508">ADV-2007-2508</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/26053">26053</ref></refs><vuln_soft><prod name="Gateway Security 5400" vendor="Symantec"><vers num="2.0.1"/></prod><prod name="Norton Internet Security" vendor="Symantec"><vers num="2005"/><vers edition="Professional" num="2005"/><vers edition="11.0" num="2005"/><vers edition="11.0.9" num="2005"/><vers edition="11.5.6.14" num="2005"/><vers num="2004"/><vers edition="Professional" num="2004"/><vers num="2006"/><vers edition="Professional" num="2006"/><vers edition="Macintosh" num="3.0"/></prod><prod name="AntiVirus Scan Engine" vendor="Symantec"><vers num="5.0"/><vers num="4.1"/><vers num="4.1.8"/><vers num="4.3.3"/><vers num="5.0.1"/><vers num="4.0"/><vers edition="Clearswift" num="4.0"/><vers num="4.3"/><vers edition="build4.3.3" num="4.3"/><vers edition="build4.3.7.27" num="4.3"/><vers edition="build4.3.8.29" num="4.3"/><vers edition="Caching" num="4.3"/><vers edition="Clearswift" num="4.3"/><vers edition="Microsoft SharePoint" num="4.3"/><vers edition="Network Attached Storage" num="4.3"/><vers num="4.3.12"/><vers edition="Caching" num="4.3.12"/><vers edition="Clearswift" num="4.3.12"/><vers edition="Messaging" num="4.3.12"/><vers edition="Microsoft SharePoint" num="4.3.12"/><vers edition="Network Attached Storage" num="4.3.12"/></prod><prod name="Symantec AntiVirus_Filtering Domino" vendor="Symantec"><vers num="3.0.12"/></prod><prod name="Mail Security 8820 Appliance" vendor="Symantec"><vers num=""/></prod><prod name="Mail Security" vendor="Symantec"><vers edition="build456" num="4.0"/><vers edition="build463" num="4.0"/><vers edition="build465" num="4.0"/><vers edition="build736" num="4.0"/><vers edition="build741" num="4.0"/><vers edition="build743" num="4.0"/><vers edition="Microsoft Exchange" num="4.0"/><vers edition="build461" num="4.1"/><vers edition="build458" num="4.1"/><vers edition="build459" num="4.1"/><vers edition="build736" num="4.5"/><vers edition="build741" num="4.5"/><vers edition="build743" num="4.5"/><vers edition="build4.5.4.743" num="4.5"/><vers edition="build719" num="4.5"/><vers edition="Microsoft Exchange" num="4.5"/><vers edition="Microsoft Exchange" num="5.0"/><vers edition="SMTP" num="5.0"/><vers edition="build4.6.1.107" num="4.6"/><vers edition="build97" num="4.6"/><vers edition="Microsoft Exchange" num="4.6.3"/><vers edition="SMTP" num="5.0.1"/><vers edition="Microsoft Exchange" num="6.0.0"/><vers edition="Microsoft Exchange" num="5.0.0.204"/><vers edition="Domino" num="4.0"/><vers edition="Domino" num="4.0.1"/><vers edition="Domino" num="5.1.0"/></prod><prod name="Norton Personal Firewall" vendor="Symantec"><vers num="2006"/><vers num="2006 9.1.0.33"/><vers num="2006 9.1.1.7"/></prod><prod name="Norton System Works" vendor="Symantec"><vers num="2005"/><vers edition="Premier" num="2005"/><vers edition="11.0" num="2005"/><vers edition="11.0.9" num="2005"/><vers num="2006"/><vers num="2004"/><vers edition="Macintosh" num="3.0"/></prod><prod name="Client Security" vendor="Symantec"><vers num="2.0"/><vers edition="SCF_7.1" num="2.0"/><vers edition="build 9.0.0.338" num="2.0"/><vers edition="MR1_b9.0.1.1000" num="2.0.1"/><vers edition="MR2_b9.0.2.1000" num="2.0.2"/><vers edition="MR3_b9.0.3.1000" num="2.0.3"/><vers num="2.0.4"/><vers edition="MR4_build1000" num="2.0.4"/><vers edition="build1100" num="2.0.5"/><vers edition="MR6" num="2.0.6"/><vers num="3.0"/><vers num="3.0.0.359"/><vers num="3.0.1.1000"/><vers num="3.0.1.1001"/><vers num="3.0.1.1007"/><vers num="3.0.1.1008"/><vers num="3.0.2.2000"/><vers num="3.0.2.2001"/><vers num="3.0.2.2002"/><vers num="3.0.2.2010"/><vers num="3.0.2.2011"/><vers num="3.0.2.2020"/><vers num="3.0.2.2021"/><vers num="3.1"/><vers num="3.1.394"/><vers num="3.1.396"/><vers num="3.1.400"/><vers num="3.1.401"/></prod><prod name="BrightMail AntiSpam" vendor="Symantec"><vers num="4.0"/><vers num="5.5"/><vers num="6.0"/><vers num="6.0.1"/><vers num="6.0.2"/><vers num="6.0.3"/><vers num="6.0.4"/></prod><prod name="Norton Antivirus" vendor="Symantec"><vers edition="Macintosh" num="10.0.0"/><vers edition="Macintosh" num="10.0.1"/><vers edition="Macintosh" num="10.9.1"/><vers edition="Macintosh" num="9.0"/><vers edition="Macintosh" num="9.0.0"/><vers edition="Macintosh" num="9.0.1"/><vers edition="Macintosh" num="9.0.2"/><vers edition="Macintosh" num="9.0.3"/><vers num="2006"/><vers edition="Professional" num="2005"/><vers num="2005"/><vers edition="11.0.9" num="2005"/><vers edition="11.0" num="2005"/><vers num="2004"/><vers edition="Professional" num="2004"/></prod><prod name="Gateway Security 5000 Series" vendor="Symantec"><vers num="3.0.1"/></prod><prod name="Symantec Web Security" vendor="Symantec"><vers num="2.5"/><vers num="3.0"/><vers num="3.0.1"/><vers num="3.0.1 build 3.01.59"/><vers num="3.0.1 build 3.01.60"/><vers num="3.0.1 build 3.01.61"/><vers num="3.0.1 build 3.01.62"/><vers num="3.0.1 build 3.01.63"/><vers num="3.0.1 build 3.01.67"/><vers num="3.0.1 build 3.01.68"/><vers num="3.0.1 build 3.01.70"/><vers num="3.0.1 build 3.01.72"/><vers num="3.0.1 build 3.01.74"/><vers num="3.0.1.62"/><vers num="3.0.1.70"/><vers num="3.0.1.76"/><vers edition="Microsoft ISA 2004" num="5.0"/></prod><prod name="AntiVirus" vendor="Symantec"><vers edition="MR4_MP1_build4010" num="10.1.4"/><vers edition="MR4_build_1000" num="9.0.4"/><vers edition="Corporate Edition for Linux" num="unknown"/><vers edition="Macintosh" num="10.0"/><vers edition="Corporate Edition" num="10.0.0.359"/><vers edition="Corporate Edition" num="10.1.4"/><vers edition="Corporate Edition" num="9.0.6.1000"/><vers edition="Corporate Edition" num="10.0"/><vers edition="Corporate Edition" num="10.0.1.1000"/><vers edition="Corporate Edition" num="10.0.1.1007"/><vers edition="Corporate Edition" num="10.0.1.1008"/><vers edition="Corporate Edition" num="10.0.2.2000"/><vers edition="Corporate Edition" num="10.0.2.2001"/><vers edition="Corporate Edition" num="10.0.2.2002"/><vers edition="Corporate Edition" num="10.0.2.2010"/><vers edition="Corporate Edition" num="10.0.2.2011"/><vers edition="Corporate Edition" num="10.0.2.2020"/><vers edition="Corporate Edition" num="10.0.2.2021"/><vers edition="Corporate Edition" num="10.1"/><vers edition="Corporate Edition" num="10.1.394"/><vers edition="Corporate Edition" num="10.1.396"/><vers edition="Corporate Edition" num="10.1.4.4010"/><vers edition="Corporate Edition" num="10.1.400"/><vers edition="Corporate Edition" num="10.1.401"/><vers edition="Corporate Edition" num="9.0"/><vers edition="Corporate Edition" num="9.0.0.338"/><vers edition="Corporate Edition" num="9.0.1.1.1000"/><vers edition="Corporate Edition" num="9.0.2.1000"/><vers edition="Corporate Edition" num="9.0.3.1000"/><vers edition="Corporate Edition" num="9.0.4"/><vers edition="Corporate Edition" num="9.0.5"/><vers edition="Corporate Edition" num="9.0.5.1100"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-05-29" name="CVE-2007-0448" published="2007-05-24" seq="2007-0448" severity="High" type="CVE"><desc><descript source="cve">The fopen function in PHP 5.2.0 does not properly handle invalid URI handlers, which allows context-dependent attackers to bypass safe_mode restrictions and read arbitrary files via a file path specified with an invalid URI, as demonstrated via the srpath URI.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><access/><input/></vuln_types><range><network/></range><refs><ref source="FULLDISC" url="http://marc.info/?l=full-disclosure&amp;m=116977186211191&amp;w=2">20070125 PHP 5.2.0 safe_mode bypass (by Writing Mode)</ref><ref source="" url="http://securityreason.com/achievement_securityalert/44"></ref><ref source="BID" url="http://www.securityfocus.com/bid/22261">22261</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2175">2175</ref></refs><vuln_soft><prod name="PHP" vendor="PHP"><vers num="5.2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-08-07" name="CVE-2007-0449" published="2007-01-23" seq="2007-0449" severity="High" type="CVE"><desc><descript source="cve">Multiple buffer overflows in LGSERVER.EXE in CA BrightStor ARCserve Backup for Laptops and Desktops r11.0 through r11.1 SP1, Mobile Backup r4.0, Desktop and Business Protection Suite r2, and Desktop Management Suite (DMS) r11.0 and r11.1 allow remote attackers to execute arbitrary code via crafted packets to TCP port (1) 1900 or (2) 2200.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref patch="1" source="" url="http://supportconnectw.ca.com/public/sams/lifeguard/infodocs/babldimpsec-notice.asp"></ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/458644/100/0/threaded">20070131 Remote Unauthenticated Code Execution CA BrightStor ARCserve Backup</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/458648/100/0/threaded">20070131 Remote Unauthenticated Code Execution II CA BrightStor ARCserve Backup for Laptops &amp; Desktops</ref><ref source="" url="http://www3.ca.com/securityadvisor/vulninfo/Vuln.aspx?ID=34993"></ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/357308">VU#357308</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/611276">VU#611276</ref><ref source="BID" url="http://www.securityfocus.com/bid/22340">22340</ref><ref source="BID" url="http://www.securityfocus.com/bid/22342">22342</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0314">ADV-2007-0314</ref><ref source="OSVDB" url="http://www.osvdb.org/31593">31593</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/23897">23897</ref><ref source="" url="http://www3.ca.com/securityadvisor/newsinfo/collateral.aspx?cid=97696"></ref><ref source="SECTRACK" url="http://securitytracker.com/id?1017548">1017548</ref></refs><vuln_soft><prod name="Desktop Management Suite" vendor="Computer Associates"><vers num="r11.0"/><vers num="r11.1"/></prod><prod name="Business Protection Suite" vendor="Computer Associates"><vers num="r2"/></prod><prod name="Mobile Backup" vendor="Computer Associates"><vers num="r4.0"/></prod><prod name="Desktop Protection Suite" vendor="Computer Associates"><vers num="r2"/></prod><prod name="BrightStor ARCserve Backup Laptops_Desktops" vendor="Computer Associates"><vers num="r11.1 SP1"/><vers num="r11.1"/><vers num="r11.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0" modified="2007-10-03" name="CVE-2007-0450" published="2007-03-16" seq="2007-0450" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in Apache HTTP Server and Tomcat 5.x before 5.5.22 and 6.x before 6.0.10, when using certain proxy modules (mod_proxy, mod_rewrite, mod_jk), allows remote attackers to read arbitrary files via a .. (dot dot) sequence with combinations of (1) &quot;/&quot; (slash), (2) &quot;\&quot; (backslash), and (3) URL-encoded backslash (%5C) characters in the URL, which are valid separators in Tomcat but not in Apache.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BID" url="http://www.securityfocus.com/bid/22960">22960</ref><ref patch="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/462791/100/0/threaded">20070314 SEC Consult SA-20070314-0 :: Apache HTTP Server / Tomcat directory traversal</ref><ref source="" url="http://www.sec-consult.com/287.html"></ref><ref source="" url="http://www.sec-consult.com/fileadmin/Advisories/20070314-0-apache_tomcat_directory_traversal.txt"></ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0975">ADV-2007-0975</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32988">tomcat-proxy-directory-traversal(32988)</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2007_5_sr.html">SUSE-SR:2007:005</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24732">24732</ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200705-03.xml">GLSA-200705-03</ref><ref source="" url="http://tomcat.apache.org/security-4.html"></ref><ref source="" url="http://tomcat.apache.org/security-5.html"></ref><ref source="" url="http://tomcat.apache.org/security-6.html"></ref><ref source="SECUNIA" url="http://secunia.com/advisories/25106">25106</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2007-0327.html">RHSA-2007:0327</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25280">25280</ref><ref source="" url="http://docs.info.apple.com/article.html?artnum=306172"></ref><ref source="" url="http://www.fujitsu.com/global/support/software/security/products-f/interstage-200702e.html"></ref><ref source="" url="http://support.avaya.com/elmodocs2/security/ASA-2007-206.htm"></ref><ref source="APPLE" url="http://lists.apple.com/archives/security-announce//2007/Jul/msg00004.html">APPLE-SA-2007-07-31</ref><ref source="HP" url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01178795">HPSBUX02262</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2007-0360.html">RHSA-2007:0360</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2007_15_sr.html">SUSE-SR:2007:015</ref><ref source="BID" url="http://www.securityfocus.com/bid/25159">25159</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/2732">ADV-2007-2732</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/3087">ADV-2007-3087</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/3386">ADV-2007-3386</ref><ref source="SECUNIA" url="http://secunia.com/advisories/26235">26235</ref><ref source="SECUNIA" url="http://secunia.com/advisories/26660">26660</ref><ref source="SECUNIA" url="http://secunia.com/advisories/27037">27037</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2446">2446</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:241">MDKSA-2007:241</ref><ref source="MLIST" url="http://lists.vmware.com/pipermail/security-announce/2008/000003.html">[Security-announce] 20080107 VMSA-2008-0002 Low severity security update for VirtualCenter and ESX Server 3.0.2, and ESX 3.0.1</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/0065">ADV-2008-0065</ref><ref source="SECUNIA" url="http://secunia.com/advisories/28365">28365</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/485938/100/0/threaded">20080108 VMSA-2008-0002 Low severity security update for VirtualCenter and ESX Server 3.0.2, and ESX 3.0.1</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2008-0261.html">RHSA-2008:0261</ref><ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-239312-1">239312</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/1979/references">ADV-2008-1979</ref><ref source="SECUNIA" url="http://secunia.com/advisories/30908">30908</ref><ref source="SECUNIA" url="http://secunia.com/advisories/30899">30899</ref></refs><vuln_soft><prod name="Tomcat" vendor="Apache Software Foundation"><vers num="5.0.19" prev="1"/><vers num="5.0.28" prev="1"/><vers num="5.5.0" prev="1"/><vers num="5.5.1" prev="1"/><vers num="5.5.10" prev="1"/><vers num="5.5.11" prev="1"/><vers num="5.5.12" prev="1"/><vers num="5.5.13" prev="1"/><vers num="5.5.14" prev="1"/><vers num="5.5.15" prev="1"/><vers num="5.5.16" prev="1"/><vers num="5.5.17" prev="1"/><vers num="5.5.18" prev="1"/><vers num="5.5.19" prev="1"/><vers num="5.5.2" prev="1"/><vers num="5.5.20" prev="1"/><vers num="5.5.21" prev="1"/><vers num="5.5.22" prev="1"/><vers num="5.5.3" prev="1"/><vers num="5.5.4" prev="1"/><vers num="5.5.5" prev="1"/><vers num="5.5.6" prev="1"/><vers num="5.5.7" prev="1"/><vers num="5.5.8" prev="1"/><vers num="5.5.9" prev="1"/><vers num="6.0.9" prev="1"/></prod><prod name="Apache HTTP Server" vendor="Apache Software Foundation"><vers edition="Win32" num="_null_"/></prod></vuln_soft></entry><entry CVSS_base_score="7.8" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.9" CVSS_score="7.8" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_version="2.0" modified="2007-08-03" name="CVE-2007-0451" published="2007-02-16" seq="2007-0451" severity="High" type="CVE"><desc><descript source="cve">Apache SpamAssassin before 3.1.8 allows remote attackers to cause a denial of service via long URLs in malformed HTML, which triggers &quot;massive memory usage.&quot;</descript></desc><sols><sol source="nvd">Upgrade to SpamAssassin version 3.1.8</sol></sols><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2007-0075.html">RHSA-2007:0075</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017666">1017666</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24250">24250</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24256">24256</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24265">24265</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24307">24307</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32536">spamassassin-url-dos(32536)</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2007_6_sr.html">SUSE-SR:2007:006</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24889">24889</ref><ref source="" url="http://svn.apache.org/repos/asf/spamassassin/branches/3.1/build/announcements/3.1.8.txt"></ref><ref patch="1" source="FEDORA" url="http://fedoranews.org/cms/node/2657">FEDORA-2007-242</ref><ref patch="1" source="FEDORA" url="http://fedoranews.org/cms/node/2659">FEDORA-2007-241</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0628">ADV-2007-0628</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/22584">22584</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24197">24197</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24200">24200</ref><ref source="" url="http://spamassassin.apache.org/advisories/cve-2007-0451.txt"></ref><ref source="" url="https://issues.rpath.com/browse/RPL-1073"></ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200703-02.xml">GLSA-200703-02</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:049">MDKSA-2007:049</ref><ref source="REDHAT" url="http://rhn.redhat.com/errata/RHSA-2007-0074.html">RHSA-2007:0074</ref></refs><vuln_soft><prod name="SpamAssassin" vendor="Apache Software Foundation"><vers num="3.1.7" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.0" CVSS_impact_subscore="6.9" CVSS_score="6.8" CVSS_vector="(AV:N/AC:L/Au:S/C:N/I:N/A:C)" CVSS_version="2.0" modified="2007-02-06" name="CVE-2007-0452" published="2007-02-05" seq="2007-0452" severity="Medium" type="CVE"><desc><descript source="cve">smbd in Samba 3.0.6 through 3.0.23d allows remote authenticated users to cause a denial of service (memory and CPU exhaustion) by renaming a file in a way that prevents a request from being removed from the deferred open queue, which triggers an infinite loop.</descript></desc><loss_types><avail/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/459167/100/0/threaded">20070205 [SAMBA-SECURITY] CVE-2007-0452: Potential DoS against smbd in Samba 3.0.6 - 3.0.23d</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/459365/100/0/threaded">
20070207 rPSA-2007-0026-1 samba samba-swat</ref><ref source="" url="http://us1.samba.org/samba/security/CVE-2007-0452.html"></ref><ref source="" url="https://issues.rpath.com/browse/RPL-1005"></ref><ref source="DEBIAN" url="http://www.debian.org/security/2007/dsa-1257">
DSA-1257</ref><ref source="FEDORA" url="http://fedoranews.org/cms/node/2579">
FEDORA-2007-219</ref><ref source="FEDORA" url="http://fedoranews.org/cms/node/2580">
FEDORA-2007-220</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200702-01.xml">
GLSA-200702-01</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2007:034">
MDKSA-2007:034</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2007-0060.html">
RHSA-2007:0060</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2007-0061.html">
RHSA-2007:0061</ref><ref source="SLACKWARE" url="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2007&amp;m=slackware-security.476916">
SSA:2007-038-01</ref><ref source="SUSE" url="http://lists.suse.com/archive/suse-security-announce/2007-Feb/0002.html">
SUSE-SA:2007:016</ref><ref source="TRUSTIX" url="http://www.trustix.org/errata/2007/0007">
2007-0007</ref><ref source="UBUNTU" url="http://www.ubuntu.com/usn/usn-419-1">
USN-419-1</ref><ref source="BID" url="http://www.securityfocus.com/bid/22395">
22395</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0483">
ADV-2007-0483</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1017587">
1017587</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24021">
24021</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24060">
24060</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24030">
24030</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24067">
24067</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24101">
24101</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24046">
24046</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24151">
24151</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24145">
24145</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24076">
24076</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24140">
24140</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24188">
24188</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32301">
samba-smbd-filerename-dos(32301)</ref><ref source="HP" url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00943462">
HPSBUX02204</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1278">
ADV-2007-1278</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24792">
24792</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:034">MDKSA-2007:034</ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20070201-01-P.asc">20070201-01-P</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24284">24284</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2219">2219</ref><ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-66-200588-1">200588</ref></refs><vuln_soft><prod name="Samba" vendor="Samba"><vers num="3.0.23d"/><vers num="3.0.23c"/><vers num="3.0.23b"/><vers num="3.0.23a"/><vers num="3.0.23"/><vers num="3.0.22"/><vers num="3.0.21c"/><vers num="3.0.21b"/><vers num="3.0.21a"/><vers num="3.0.21"/><vers num="3.0.20b"/><vers num="3.0.20a"/><vers num="3.0.20"/><vers num="3.0.14a"/><vers num="3.0.13"/><vers num="3.0.12"/><vers num="3.0.11"/><vers num="3.0.10"/><vers num="3.0.9"/><vers num="3.0.8"/><vers num="3.0.7"/><vers num="3.0.6"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-02-06" name="CVE-2007-0453" published="2007-02-05" seq="2007-0453" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in the nss_winbind.so.1 library in Samba 3.0.21 through 3.0.23d, as used in the winbindd daemon on Solaris, allows attackers to execute arbitrary code via the (1) gethostbyname and (2) getipnodebyname functions.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input buffer="1"/><env/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/459168/100/0/threaded">20070205 [SAMBA-SECURITY] CVE-2007-0453: Buffer overrun in nss_winbind.so.1 on Solaris</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/459365/100/0/threaded">
20070207 rPSA-2007-0026-1 samba samba-swat</ref><ref source="" url="http://us1.samba.org/samba/security/CVE-2007-0453.html"></ref><ref source="" url="https://issues.rpath.com/browse/RPL-1005"></ref><ref source="SLACKWARE" url="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2007&amp;m=slackware-security.476916">
SSA:2007-038-01</ref><ref source="TRUSTIX" url="http://www.trustix.org/errata/2007/0007">
2007-0007</ref><ref source="BID" url="http://www.securityfocus.com/bid/22410">
22410</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0483">
ADV-2007-0483</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1017589">
1017589</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24043">
24043</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24101">
24101</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24151">
24151</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32231">
samba-winbind-bo(32231)</ref><ref source="OPENPKG" url="http://www.openpkg.com/security/advisories/OpenPKG-SA-2007.012.html">OpenPKG-SA-2007.012</ref></refs><vuln_soft><prod name="Samba" vendor="Samba"><vers num="3.0.23d"/><vers num="3.0.23c"/><vers num="3.0.23b"/><vers num="3.0.23a"/><vers num="3.0.23"/><vers num="3.0.22"/><vers num="3.0.21c"/><vers num="3.0.21b"/><vers num="3.0.21a"/><vers num="3.0.21"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-08-03" name="CVE-2007-0454" published="2007-02-05" seq="2007-0454" severity="High" type="CVE"><desc><descript source="cve">Format string vulnerability in the afsacl.so VFS module in Samba 3.0.6 through 3.0.23d allows context-dependent attackers to execute arbitrary code via format string specifiers in a filename on an AFS file system, which is not properly handled during Windows ACL mapping.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/459179/100/0/threaded">20070205 [SAMBA-SECURITY] CVE-2007-0454: Format string bug in afsacl.so VFS plugin</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/22403">22403</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/459365/100/0/threaded">20070207 rPSA-2007-0026-1 samba samba-swat</ref><ref source="" url="http://us1.samba.org/samba/security/CVE-2007-0454.html"></ref><ref source="" url="https://issues.rpath.com/browse/RPL-1005"></ref><ref source="DEBIAN" url="http://www.debian.org/security/2007/dsa-1257">DSA-1257</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200702-01.xml">GLSA-200702-01</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2007:034">MDKSA-2007:034</ref><ref source="SLACKWARE" url="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2007&amp;m=slackware-security.476916">SSA:2007-038-01</ref><ref source="TRUSTIX" url="http://www.trustix.org/errata/2007/0007">2007-0007</ref><ref source="UBUNTU" url="http://www.ubuntu.com/usn/usn-419-1">USN-419-1</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/649732">VU#649732</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0483">ADV-2007-0483</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1017588">1017588</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24021">24021</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24060">24060</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24067">24067</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24101">24101</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24046">24046</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24151">24151</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24145">24145</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32304">samba-afsacl-format-string(32304)</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:034">MDKSA-2007:034</ref><ref source="OPENPKG" url="http://www.openpkg.com/security/advisories/OpenPKG-SA-2007.012.html">OpenPKG-SA-2007.012</ref></refs><vuln_soft><prod name="Mandrake Corporate Server" vendor="MandrakeSoft"><vers edition="x86_64" num="4.0"/><vers edition="x86_64" num="3.0"/><vers num="3.0"/><vers num="4.0"/></prod><prod name="Samba" vendor="Samba"><vers num="3.0.22"/><vers num="3.0.21"/><vers num="3.0.20"/><vers num="3.0.14"/><vers num="3.0.13"/><vers num="3.0.12"/><vers num="3.0.11"/><vers num="3.0.10"/><vers num="3.0.9"/><vers num="3.0.8"/><vers num="3.0.7"/><vers num="3.0.6"/><vers num="3.0.23d"/><vers num="3.0.21c"/><vers num="3.0.21b"/><vers num="3.0.21a"/><vers num="3.0.20b"/><vers num="3.0.20a"/><vers num="3.0.14a"/></prod><prod name="Mandrake LinuxSoft" vendor="MandrakeSoft"><vers num="2006.0 x86_64"/><vers num="2006.0"/><vers num="2007.0 x86_64"/><vers num="2007.0"/></prod><prod name="Debian Linux" vendor="Debian"><vers num="3.1 sparc"/><vers num="3.1 s_390"/><vers num="3.1 ppc"/><vers num="3.1 mipsel"/><vers num="3.1 mips"/><vers num="3.1 m68k"/><vers num="3.1 ia-64"/><vers num="3.1 ia-32"/><vers num="3.1 hppa"/><vers num="3.1 arm"/><vers num="3.1 amd64"/><vers num="3.1 alpha"/><vers num="3.1"/><vers num="3.0 sparc"/><vers num="3.0 s_390"/><vers num="3.0 ppc"/><vers num="3.0 mipsel"/><vers num="3.0 mips"/><vers num="3.0 m68k"/><vers num="3.0 ia-64"/><vers num="3.0 ia-32"/><vers num="3.0 hppa"/><vers num="3.0 arm"/><vers num="3.0 alpha"/><vers num="3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-09-17" name="CVE-2007-0455" published="2007-01-30" seq="2007-0455" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in the gdImageStringFTEx function in gdft.c in GD Graphics Library 2.0.33 and earlier allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted string with a JIS encoded font.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="" url="http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=224607"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0400">ADV-2007-0400</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/23916">23916</ref><ref source="MLIST" url="http://lists.rpath.com/pipermail/security-announce/2007-February/000145.html">[security-announce] 20070208 rPSA-2007-0028-1 gd</ref><ref source="" url="https://issues.rpath.com/browse/RPL-1030"></ref><ref source="FEDORA" url="http://fedoranews.org/cms/node/2631">FEDORA-2007-150</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:035">MDKSA-2007:035</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:036">MDKSA-2007:036</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:038">MDKSA-2007:038</ref><ref source="TRUSTIX" url="http://www.trustix.org/errata/2007/0007">2007-0007</ref><ref source="BID" url="http://www.securityfocus.com/bid/22289">22289</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24022">24022</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24052">24052</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24053">24053</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24107">24107</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24143">24143</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24151">24151</ref><ref source="REDHAT" url="http://rhn.redhat.com/errata/RHSA-2007-0155.html">RHSA-2007:0155</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24924">24924</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/466166/100/0/threaded">20070418 rPSA-2007-0073-1 php php-mysql php-pgsql</ref><ref source="" url="https://issues.rpath.com/browse/RPL-1268"></ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2007-0153.html">RHSA-2007:0153</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2007-0162.html">RHSA-2007:0162</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24965">24965</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24945">24945</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:109">MDKSA-2007:109</ref><ref source="UBUNTU" url="http://www.ubuntu.com/usn/usn-473-1">USN-473-1</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25575">25575</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2008-0146.html">RHSA-2008:0146</ref><ref source="SECUNIA" url="http://secunia.com/advisories/29157">29157</ref></refs><vuln_soft><prod name="gdlib" vendor="GD Graphics Library"><vers num="2.0.33"/><vers num="2.0.28"/><vers num="2.0.27"/><vers num="2.0.26"/><vers num="2.0.23"/><vers num="2.0.22"/><vers num="2.0.21"/><vers num="2.0.20"/><vers num="2.0.15"/><vers num="2.0.1"/></prod></vuln_soft></entry><entry CVSS_base_score="2.9" CVSS_exploit_subscore="5.5" CVSS_impact_subscore="2.9" CVSS_score="2.9" CVSS_vector="(AV:A/AC:M/Au:N/C:N/I:N/A:P)" CVSS_version="2.0" modified="2007-06-27" name="CVE-2007-0456" published="2007-02-02" seq="2007-0456" severity="Low" type="CVE"><desc><descript source="cve">Unspecified vulnerability in the LLT dissector in Wireshark (formerly Ethereal) 0.99.3 and 0.99.4 allows remote attackers to cause a denial of service (application crash) via unspecified vectors.</descript></desc><loss_types><avail/></loss_types><range><local_network/></range><refs><ref adv="1" patch="1" source="" url="http://www.wireshark.org/security/wnpa-sec-2007-01.html"></ref><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/22352">22352</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0443">ADV-2007-0443</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/24016">24016</ref><ref source="" url="https://issues.rpath.com/browse/RPL-985"></ref><ref source="FEDORA" url="http://fedoranews.org/cms/node/2565">FEDORA-2007-207</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:033">MDKSA-2007:033</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2007-0066.html">RHSA-2007:0066</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1017581">1017581</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24011">24011</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24025">24025</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24084">24084</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24515">24515</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32056">wireshark-lltdissector-dos(32056)</ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20070301-01-P.asc">20070301-01-P</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24650">24650</ref><ref source="" url="http://support.avaya.com/elmodocs2/security/ASA-2007-166.htm"></ref><ref source="SECUNIA" url="http://secunia.com/advisories/24970">24970</ref></refs><vuln_soft><prod name="Wireshark" vendor="Wireshark"><vers num="0.99.4"/><vers num="0.99.3"/></prod></vuln_soft></entry><entry CVSS_base_score="2.9" CVSS_exploit_subscore="5.5" CVSS_impact_subscore="2.9" CVSS_score="2.9" CVSS_vector="(AV:A/AC:M/Au:N/C:N/I:N/A:P)" CVSS_version="2.0" modified="2007-06-27" name="CVE-2007-0457" published="2007-02-02" seq="2007-0457" severity="Low" type="CVE"><desc><descript source="cve">Unspecified vulnerability in the IEEE 802.11 dissector in Wireshark (formerly Ethereal) 0.10.14 through 0.99.4 allows remote attackers to cause a denial of service (application crash) via unspecified vectors.</descript></desc><loss_types><avail/></loss_types><range><local_network/></range><refs><ref adv="1" patch="1" source="" url="http://www.wireshark.org/security/wnpa-sec-2007-01.html"></ref><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/22352">22352</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0443">ADV-2007-0443</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/24016">24016</ref><ref source="" url="https://issues.rpath.com/browse/RPL-985"></ref><ref source="FEDORA" url="http://fedoranews.org/cms/node/2565">FEDORA-2007-207</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:033">MDKSA-2007:033</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2007-0066.html">RHSA-2007:0066</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1017581">1017581</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24011">24011</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24025">24025</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24084">24084</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24515">24515</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32055">wireshark-ieeedissector-dos(32055)</ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20070301-01-P.asc">20070301-01-P</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24650">24650</ref><ref source="" url="http://support.avaya.com/elmodocs2/security/ASA-2007-166.htm"></ref><ref source="SECUNIA" url="http://secunia.com/advisories/24970">24970</ref></refs><vuln_soft><prod name="Wireshark" vendor="Wireshark"><vers num="0.99.4"/><vers num="0.99.3"/><vers num="0.99.2"/><vers num="0.99.0"/><vers num="0.10.9"/><vers num="0.10.8"/><vers num="0.10.7"/><vers num="0.10.6"/><vers num="0.10.5"/><vers num="0.10.4"/><vers num="0.10.3"/><vers num="0.10.2"/><vers num="0.10.14"/></prod></vuln_soft></entry><entry CVSS_base_score="2.9" CVSS_exploit_subscore="5.5" CVSS_impact_subscore="2.9" CVSS_score="2.9" CVSS_vector="(AV:A/AC:M/Au:N/C:N/I:N/A:P)" CVSS_version="2.0" modified="2008-07-30" name="CVE-2007-0458" published="2007-02-02" seq="2007-0458" severity="Low" type="CVE"><desc><descript source="cve">Unspecified vulnerability in the HTTP dissector in Wireshark (formerly Ethereal) 0.99.3 and 0.99.4 allows remote attackers to cause a denial of service (application crash) via unspecified vectors, a different issue than CVE-2006-5468.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><local_network/></range><refs><ref adv="1" patch="1" source="" url="http://www.wireshark.org/security/wnpa-sec-2007-01.html"></ref><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/22352">22352</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0443">ADV-2007-0443</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24016">24016</ref><ref source="" url="https://issues.rpath.com/browse/RPL-985"></ref><ref source="FEDORA" url="http://fedoranews.org/cms/node/2565">FEDORA-2007-207</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:033">MDKSA-2007:033</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2007-0066.html">RHSA-2007:0066</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1017581">1017581</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24011">24011</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24025">24025</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24084">24084</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24515">24515</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32054">wireshark-httpdissector-dos(32054)</ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20070301-01-P.asc">20070301-01-P</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24650">24650</ref><ref source="" url="http://support.avaya.com/elmodocs2/security/ASA-2007-166.htm"></ref><ref source="SECUNIA" url="http://secunia.com/advisories/24970">24970</ref></refs><vuln_soft><prod name="Wireshark" vendor="Wireshark"><vers num="0.99.4"/><vers num="0.99.3"/></prod></vuln_soft></entry><entry CVSS_base_score="2.9" CVSS_exploit_subscore="5.5" CVSS_impact_subscore="2.9" CVSS_score="2.9" CVSS_vector="(AV:A/AC:M/Au:N/C:N/I:N/A:P)" CVSS_version="2.0" modified="2007-02-05" name="CVE-2007-0459" published="2007-02-02" seq="2007-0459" severity="Low" type="CVE"><desc><descript source="cve">packet-tcp.c in the TCP dissector in Wireshark (formerly Ethereal) 0.99.2 through 0.99.4 allows remote attackers to cause a denial of service (application crash or hang) via fragmented HTTP packets.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><local_network/></range><refs><ref adv="1" source="" url="http://bugs.wireshark.org/bugzilla/show_bug.cgi?id=1200"></ref><ref adv="1" patch="1" source="" url="http://www.wireshark.org/security/wnpa-sec-2007-01.html"></ref><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/22352">22352</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0443">ADV-2007-0443</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/24016">24016</ref><ref source="" url="https://issues.rpath.com/browse/RPL-985"></ref><ref source="FEDORA" url="http://fedoranews.org/cms/node/2565">
FEDORA-2007-207</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:033">
MDKSA-2007:033</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2007-0066.html">
RHSA-2007:0066</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1017581">
1017581</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24011">
24011</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24025">
24025</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24084">
24084</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24515">
24515</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32053">
wireshark-tcpdissector-dos(32053)</ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20070301-01-P.asc">
20070301-01-P</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24650">
24650</ref><ref source="" url="http://support.avaya.com/elmodocs2/security/ASA-2007-166.htm"></ref><ref source="SECUNIA" url="http://secunia.com/advisories/24970">
24970</ref></refs><vuln_soft><prod name="Wireshark" vendor="Wireshark"><vers num="0.99.4"/><vers num="0.99.3"/><vers num="0.99.2"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2008-06-25" name="CVE-2007-0460" published="2007-01-23" seq="2007-0460" severity="High" type="CVE"><desc><descript source="cve">Multiple buffer overflows in ulogd for SUSE Linux 9.3 up to 10.1, and possibly other distributions, have unknown impact and attack vectors related to &quot;improper string length calculations.&quot;</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="SUSE" url="http://www.novell.com/linux/security/advisories/2007_01_sr.html">SUSE-SR:2007:001</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/23863">23863</ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200703-17.xml">GLSA-200703-17</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2007:028">MDKSA-2007:028</ref><ref source="BID" url="http://www.securityfocus.com/bid/22139">22139</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24524">24524</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:028">MDKSA-2007:028</ref></refs><vuln_soft><prod name="SuSE Linux" vendor="SuSE"><vers num="10.1" prev="1"/><vers num="9.3"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0" modified="2007-01-24" name="CVE-2007-0461" published="2007-01-23" seq="2007-0461" severity="Medium" type="CVE"><desc><descript source="cve">Multiple memory leaks in the Dazuko anti-virus helper module before 2.3.2 allow attackers to cause a denial of service (memory consumption) via unknown vectors.</descript></desc><loss_types><avail/></loss_types><vuln_types><other/></vuln_types><range><network/></range><refs><ref adv="1" source="SUSE" url="http://www.novell.com/linux/security/advisories/2007_01_sr.html">SUSE-SR:2007:001</ref></refs><vuln_soft><prod name="Dazuko" vendor="Dazuko"><vers num="2.3.1" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-01-28" name="CVE-2007-0462" published="2007-01-25" seq="2007-0462" severity="High" type="CVE"><desc><descript source="cve">The _GetSrcBits32ARGB function in Apple QuickDraw, as used by Quicktime 7.1.3 and other applications on Mac OS X 10.4.8 and earlier, allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted PICT image with a malformed Alpha RGB (ARGB) record, which triggers memory corruption.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="" url="http://projects.info-pull.com/moab/MOAB-23-01-2007.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/22207">
22207</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0337">
ADV-2007-0337</ref><ref source="OSVDB" url="http://www.osvdb.org/32696">
32696</ref><ref source="SECUNIA" url="http://secunia.com/advisories/23859">
23859</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31698">
macos-argb-dos(31698)</ref></refs><vuln_soft><prod name="Mac OS X" vendor="Apple"><vers num="10.4.8"/></prod><prod name="Quicktime" vendor="Apple"><vers num="7.1.3"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0" modified="2007-01-30" name="CVE-2007-0463" published="2007-01-29" seq="2007-0463" severity="Medium" type="CVE"><desc><descript source="cve">Format string vulnerability in Apple Software Update 2.0.5 on Mac OS X 10.4.8 allows remote attackers to cause a denial of service (application crash) or execute arbitrary code via format string specifiers in (1) SWUTMP or (2) SUCATALOG filenames, or using the (3) application/x-apple.sucatalog+xml MIME type.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="" url="http://projects.info-pull.com/moab/MOAB-24-01-2007.html"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0337">ADV-2007-0337</ref><ref source="" url="http://docs.info.apple.com/article.html?artnum=305214"></ref><ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2007/Mar/msg00002.html">
APPLE-SA-2007-03-13</ref><ref source="BID" url="http://www.securityfocus.com/bid/22222">
22222</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0930">
ADV-2007-0930</ref><ref source="OSVDB" url="http://www.osvdb.org/32703">
32703</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017755">
1017755</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24479">
24479</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA07-072A.html">TA07-072A</ref></refs><vuln_soft><prod name="Software Update" vendor="Apple"><vers num="2.0.5"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0" modified="2008-01-02" name="CVE-2007-0464" published="2007-01-30" seq="2007-0464" severity="Medium" type="CVE"><desc><descript source="cve">The _CFNetConnectionWillEnqueueRequests function in CFNetwork 129.19 on Apple Mac OS X 10.4 through 10.4.10 allows remote attackers to cause a denial of service (application crash) via a crafted HTTP 301 response, which results in a NULL pointer dereference.</descript></desc><loss_types><avail/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="" url="http://projects.info-pull.com/moab/MOAB-25-01-2007.html"></ref><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3200">3200</ref><ref source="BID" url="http://www.securityfocus.com/bid/22249">22249</ref><ref source="OSVDB" url="http://www.osvdb.org/32704">32704</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31837">macos-cfnetwork-dos(31837)</ref><ref source="" url="http://docs.info.apple.com/article.html?artnum=307041"></ref><ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2007/Nov/msg00002.html">APPLE-SA-2007-11-14</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA07-319A.html">TA07-319A</ref><ref source="BID" url="http://www.securityfocus.com/bid/26444">26444</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/3868">ADV-2007-3868</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/27643">27643</ref></refs><vuln_soft><prod name="CFNetwork" vendor="CFNetwork"><vers num="129.19"/></prod></vuln_soft></entry><entry CVSS_base_score="7.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="10.0" CVSS_score="7.6" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-01-31" name="CVE-2007-0465" published="2007-01-30" seq="2007-0465" severity="High" type="CVE"><desc><descript source="cve">Format string vulnerability in Apple Installer 2.1.5 on Mac OS X 10.4.8 allows user-assisted remote attackers to execute arbitrary code via format string specifiers in a (1) PKG, (2) DISTZ, or (3) MPKG package filename.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref source="" url="http://projects.info-pull.com/moab/MOAB-26-01-2007.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/22272">22272</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31883">
macos-installer-format-string(31883)</ref><ref source="" url="http://docs.info.apple.com/article.html?artnum=305391"></ref><ref source="APPLE" url="http://lists.apple.com/archives/Security-announce/2007/Apr/msg00001.html">
APPLE-SA-2007-04-19</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1470">
ADV-2007-1470</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017940">
1017940</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24966">
24966</ref><ref source="OSVDB" url="http://www.osvdb.org/32705">
32705</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA07-109A.html">TA07-109A</ref></refs><vuln_soft><prod name="Mac OS X" vendor="Apple"><vers num="10.4.8"/></prod><prod name="Apple Installer" vendor="Apple"><vers num="2.1.5"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-01-31" name="CVE-2007-0466" published="2007-01-30" seq="2007-0466" severity="High" type="CVE"><desc><descript source="cve">Telestream Flip4Mac Windows Media Components for Quicktime 2.1.0.33 allows remote attackers to execute arbitrary code via a crafted ASF_File_Properties_Object size field in a WMV file, which triggers memory corruption.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref source="" url="http://projects.info-pull.com/moab/MOAB-27-01-2007.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/22286">22286</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0389">ADV-2007-0389</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/23958">23958</ref><ref source="OSVDB" url="http://www.osvdb.org/32697">
32697</ref></refs><vuln_soft><prod name="Flip4Mac Windows Media Components for Quicktime" vendor="Telestream"><vers num="2.1.0.33"/></prod></vuln_soft></entry><entry CVSS_base_score="6.2" CVSS_exploit_subscore="1.9" CVSS_impact_subscore="10.0" CVSS_score="6.2" CVSS_vector="(AV:L/AC:H/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-04-02" name="CVE-2007-0467" published="2007-01-30" seq="2007-0467" severity="Medium" type="CVE"><desc><descript source="cve">crashdump in Apple Mac OS X 10.4.8 allows local users in the admin group to modify arbitrary files or gain privileges via a symlink attack on application logs in /Library/Logs/CrashReporter/.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input/></vuln_types><range><local/></range><refs><ref adv="1" source="" url="http://projects.info-pull.com/moab/MOAB-28-01-2007.html"></ref><ref source="" url="http://docs.info.apple.com/article.html?artnum=305214"></ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0930">ADV-2007-0930</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017751">1017751</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24479">24479</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31888">macos-crashreporterd-privilege-escalation(31888)</ref><ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2007/Mar/msg00002.html">APPLE-SA-2007-03-13</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA07-072A.html">TA07-072A</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/363112">VU#363112</ref><ref source="OSVDB" url="http://www.osvdb.org/32706">32706</ref></refs><vuln_soft><prod name="Mac OS X" vendor="Apple"><vers num="10.4.8"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-01-24" name="CVE-2007-0468" published="2007-01-23" seq="2007-0468" severity="Medium" type="CVE"><desc><descript source="cve">Stack-based buffer overflow in rcdll.dll in msdev.exe in Visual C++ (MSVC) in Microsoft Visual Studio 6.0 SP6 allows user-assisted remote attackers to execute arbitrary code via a long file path in the &quot;1 TYPELIB MOVEABLE PURE&quot; option in an RC file.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/457646/100/0/threaded">20070122 Microsoft Visual C++ (.RC) resource files buffer overflow vulnerability</ref><ref source="" url="http://www.anspi.pl/~porkythepig/visualization/rc-kupiekrowe.cpp"></ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/23856">23856</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0296">
ADV-2007-0296</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31665">
visualstudio-rc-bo(31665)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2172">2172</ref></refs><vuln_soft><prod name="Visual Studio" vendor="Microsoft"><vers num="6.0 SP6"/></prod></vuln_soft></entry><entry CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" CVSS_score="9.3" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-01-24" name="CVE-2007-0469" published="2007-01-23" seq="2007-0469" severity="High" type="CVE"><desc><descript source="cve">The extract_files function in installer.rb in RubyGems before 0.9.1 does not check whether files exist before overwriting them, which allows user-assisted remote attackers to overwrite arbitrary files, cause a denial of service, or execute arbitrary code via crafted GEM packages.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><design/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" patch="1" source="" url="http://rubyforge.org/frs/shownotes.php?release_id=9074"></ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0295">ADV-2007-0295</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/458128/100/0/threaded">

20070121 RubyGems 0.9.0 and earlier installation exploit</ref><ref source="FULLDISC" url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=116939816621060&amp;w=2">
20070121 RubyGems 0.9.0 and earlier installation exploit</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31688">
rubygems-extractfiles-file-overwrite(31688)</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2007_4_sr.html">
SUSE-SR:2007:004</ref></refs><vuln_soft><prod name="RubyGems" vendor="RubyForge"><vers num="0.9.0" prev="1"/><vers num="0.8.11"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-01-24" name="CVE-2007-0470" published="2007-01-23" seq="2007-0470" severity="High" type="CVE"><desc><descript source="cve">Multiple unspecified vulnerabilities in tip in Sun Solaris 8, 9, and 10 allow local users to gain uucp account privileges via unspecified vectors.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><range><local/></range><refs><ref patch="1" source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102773-1">102773</ref><ref source="BID" url="http://www.securityfocus.com/bid/22190">
22190</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0317">
ADV-2007-0317</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1017546">
1017546</ref><ref source="SECUNIA" url="http://secunia.com/advisories/23821">
23821</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31669">
solaris-tip-privilege-escalation(31669)</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2038">oval:org.mitre.oval:def:2038</ref></refs><vuln_soft><prod name="Solaris" vendor="Sun"><vers num="8.0"/><vers edition="SPARC" num="9.0"/><vers edition="SPARC" num="10.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" discovered="2006-12-20" modified="2007-08-07" name="CVE-2007-0471" published="2007-01-23" seq="2007-0471" severity="High" type="CVE"><desc><descript source="cve">sre/params.php in the Integrity Clientless Security (ICS) component in Check Point Connectra NGX R62 3.x and earlier before Security Hotfix 5, and possibly VPN-1 NGX R62, allows remote attackers to bypass security requirements via a crafted Report parameter, which returns a valid ICSCookie authentication token.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/457683/100/0/threaded">20070122 Check Point Connectra End Point security bypass</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/457621/100/0/threaded">20070122 Re: [Full-disclosure] Check Point Connectra End Point security bypass</ref><ref adv="1" source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2007-January/051920.html">20070122 Check Point Connectra End Point security bypass</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0276">ADV-2007-0276</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/31646">checkpoint-params-security-bypass(31646)</ref><ref source="" url="http://secureknowledge.checkpoint.com/SecureKnowledge/viewSolutionDocument.do?lid=sk32472"></ref><ref source="" url="http://updates.checkpoint.com/fileserver/ID/7126/FILE/VPN-1_Hotfix1.pdf"></ref><ref source="" url="http://www.checkpoint.com/downloads/latest/hfa/vpn1_security/vpn1_R62_Windows.html"></ref><ref source="" url="http://www.checkpoint.com/downloads/latest/hfa/connectra/security_r62.html"></ref><ref source="SECTRACK" url="http://securitytracker.com/id?1017559">1017559</ref><ref source="SECUNIA" url="http://secunia.com/advisories/23847">23847</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1017560">1017560</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2179">2179</ref></refs><vuln_soft><prod name="Connectra NGX" vendor="Checkpoint"><vers num="R62" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="3.7" CVSS_exploit_subscore="1.9" CVSS_impact_subscore="6.4" CVSS_score="3.7" CVSS_vector="(AV:L/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-02-06" name="CVE-2007-0472" published="2007-02-03" seq="2007-0472" severity="Low" type="CVE"><desc><descript source="cve">Multiple race conditions in Smb4K before 0.8.0 allow local users to (1) modify arbitrary files via unspecified manipulations of Smb4K&apos;s lock file, which is not properly handled by the remove_lock_file function in core/smb4kfileio.cpp, and (2) add lines to the sudoers file via a symlink attack on temporary files, which isn&apos;t properly handled by the writeFile function in core/smb4kfileio.cpp.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><race/></vuln_types><range><local/></range><refs><ref patch="1" source="MLIST" url="https://lists.berlios.de/pipermail/smb4k-announce/2006-December/000037.html">[smb4k-announce] 20061221 Smb4K 0.8.0 and security fixes released</ref><ref source="" url="http://developer.berlios.de/bugs/?func=detailbug&amp;bug_id=9630&amp;group_id=769"></ref><ref source="" url="http://developer.berlios.de/project/shownotes.php?release_id=11706"></ref><ref source="" url="http://developer.berlios.de/project/shownotes.php?release_id=11902"></ref><ref source="" url="http://developer.berlios.de/project/shownotes.php?release_id=9777"></ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0393">ADV-2007-0393</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/23937">23937</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200703-09.xml">
GLSA-200703-09</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2007:042">
MDKSA-2007:042</ref><ref source="SUSE" url="http://lists.suse.com/archive/suse-security-announce/2007-Jan/0015.html">
SUSE-SR:2007:002</ref><ref source="BID" url="http://www.securityfocus.com/bid/22299">
22299</ref><ref source="SECUNIA" url="http://secunia.com/advisories/23984">
23984</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24111">
24111</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24469">
24469</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:042">MDKSA-2007:042</ref></refs><vuln_soft><prod name="Smb4k" vendor="Smb4k"><vers num="0.7"/><vers num="0.6"/><vers num="0.5"/><vers num="0.4"/></prod></vuln_soft></entry><entry CVSS_base_score="1.9" CVSS_exploit_subscore="3.4" CVSS_impact_subscore="2.9" CVSS_score="1.9" CVSS_vector="(AV:L/AC:M/Au:N/C:P/I:N/A:N)" CVSS_version="2.0" modified="2007-02-06" name="CVE-2007-0473" published="2007-02-03" seq="2007-0473" severity="Low" type="CVE"><desc><descript source="cve">The writeFile function in core/smb4kfileio.cpp in Smb4K before 0.8.0 does not preserve /etc/sudoers permissions across modifications, which allows local users to obtain sensitive information (/etc/sudoers contents) by reading this file.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref patch="1" source="MLIST" url="https://lists.berlios.de/pipermail/smb4k-announce/2006-December/000037.html">[smb4k-announce] 20061221 Smb4K 0.8.0 and security fixes released</ref><ref source="" url="http://developer.berlios.de/bugs/?func=detailbug&amp;bug_id=9630&amp;group_id=769"></ref><ref source="" url="http://developer.berlios.de/project/shownotes.php?release_id=11706"></ref><ref source="" url="http://developer.berlios.de/project/shownotes.php?release_id=11902"></ref><ref source="" url="http://developer.berlios.de/project/shownotes.php?release_id=9777"></ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0393">ADV-2007-0393</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/23937">23937</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200703-09.xml">
GLSA-200703-09</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2007:042">
MDKSA-2007:042</ref><ref source="SUSE" url="http://lists.suse.com/archive/suse-security-announce/2007-Jan/0015.html">
SUSE-SR:2007:002</ref><ref source="BID" url="http://www.securityfocus.com/bid/22299">
22299</ref><ref source="SECUNIA" url="http://secunia.com/advisories/23984">
23984</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24111">
24111</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24469">
24469</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:042">MDKSA-2007:042</ref></refs><vuln_soft><prod name="Smb4k" vendor="Smb4k"><vers num="0.7"/><vers num="0.6"/><vers num="0.5"/><vers num="0.4"/></prod></vuln_soft></entry><entry CVSS_base_score="3.3" CVSS_exploit_subscore="3.4" CVSS_impact_subscore="4.9" CVSS_score="3.3" CVSS_vector="(AV:L/AC:M/Au:N/C:N/I:P/A:P)" CVSS_version="2.0" modified="2007-02-06" name="CVE-2007-0474" published="2007-02-03" seq="2007-0474" severity="Low" type="CVE"><desc><descript source="cve">Smb4K before 0.8.0 allow local users, when present on the Smb4K sudoers list, to kill arbitrary processes, related to a &quot;design issue with smb4k_kill.&quot;</descript></desc><loss_types><avail/><int/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref patch="1" source="MLIST" url="https://lists.berlios.de/pipermail/smb4k-announce/2006-December/000037.html">[smb4k-announce] 20061221 Smb4K 0.8.0 and security fixes released</ref><ref source="" url="http://developer.berlios.de/bugs/?func=detailbug&amp;bug_id=9631&amp;group_id=769"></ref><ref source="" url="http://developer.berlios.de/project/shownotes.php?release_id=11706"></ref><ref source="" url="http://developer.berlios.de/project/shownotes.php?release_id=11902"></ref><ref source="" url="http://developer.berlios.de/project/shownotes.php?release_id=9777"></ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0393">ADV-2007-0393</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/23937">23937</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200703-09.xml">
GLSA-200703-09</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2007:042">
MDKSA-2007:042</ref><ref source="SUSE" url="http://lists.suse.com/archive/suse-security-announce/2007-Jan/0015.html">
SUSE-SR:2007:002</ref><ref source="BID" url="http://www.securityfocus.com/bid/22299">
22299</ref><ref source="SECUNIA" url="http://secunia.com/advisories/23984">
23984</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24111">
24111</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24469">
24469</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:042">MDKSA-2007:042</ref></refs><vuln_soft><prod name="Smb4k" vendor="Smb4k"><vers num="0.7"/><vers num="0.6"/><vers num="0.5"/><vers num="0.4"/></prod></vuln_soft></entry><entry CVSS_base_score="4.4" CVSS_exploit_subscore="3.4" CVSS_impact_subscore="6.4" CVSS_score="4.4" CVSS_vector="(AV:L/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-02-06" name="CVE-2007-0475" published="2007-02-03" seq="2007-0475" severity="Medium" type="CVE"><desc><descript source="cve">Multiple stack-based buffer overflows in utilities/smb4k_*.cpp in Smb4K before 0.8.0 allow local users, when present on the Smb4K sudoers list, to gain privileges via unspecified vectors related to the args variable and unspecified other variables, in conjunction with the sudo configuration.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref patch="1" source="MLIST" url="https://lists.berlios.de/pipermail/smb4k-announce/2006-December/000037.html">[smb4k-announce] 20061221 Smb4K 0.8.0 and security fixes released</ref><ref source="" url="http://developer.berlios.de/bugs/?func=detailbug&amp;bug_id=9631&amp;group_id=769"></ref><ref source="" url="http://developer.berlios.de/project/shownotes.php?release_id=11706"></ref><ref source="" url="http://developer.berlios.de/project/shownotes.php?release_id=11902"></ref><ref source="" url="http://developer.berlios.de/project/shownotes.php?release_id=9777"></ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0393">ADV-2007-0393</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/23937">23937</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200703-09.xml">
GLSA-200703-09</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2007:042">
MDKSA-2007:042</ref><ref source="SUSE" url="http://lists.suse.com/archive/suse-security-announce/2007-Jan/0015.html">
SUSE-SR:2007:002</ref><ref source="BID" url="http://www.securityfocus.com/bid/22299">
22299</ref><ref source="SECUNIA" url="http://secunia.com/advisories/23984">
23984</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24111">
24111</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24469">
24469</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:042">MDKSA-2007:042</ref></refs><vuln_soft><prod name="Smb4k" vendor="Smb4k"><vers num="0.7"/><vers num="0.6"/><vers num="0.5"/><vers num="0.4"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-01-25" name="CVE-2007-0476" published="2007-01-24" seq="2007-0476" severity="Medium" type="CVE"><desc><descript source="cve">The gencert.sh script, when installing OpenLDAP before 2.1.30-r10, 2.2.x before 2.2.28-r7, and 2.3.x before 2.3.30-r2 as an ebuild in Gentoo Linux, does not create temporary directories in /tmp securely during emerge, which allows local users to overwrite arbitrary files via a symlink attack.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200701-19.xml">GLSA-200701-19</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/23881">23881</ref><ref source="BID" url="http://www.securityfocus.com/bid/22195">
22195</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0305">
ADV-2007-0305</ref></refs><vuln_soft><prod name="Linux" vendor="Gentoo"><vers num="2.1.30 r9"/><vers num="2.2.28 r7"/><vers num="2.3.30 r2"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-08-07" name="CVE-2007-0477" published="2007-01-24" seq="2007-0477" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in Openads 2.0.x before 2.0.10, 2.3 before 2.3.31 (aka Max Media Manager before 0.3.31-alpha-pr2), and phpAdsNew/phpPgAds before 2.0.9-pr1 allows remote attackers to inject arbitrary web script or HTML via (1) the keyword parameter in admin-search.php and (2) affiliate-search.php. NOTE: this issue may overlap CVE-2007-0363.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs><ref source="" url="http://forum.openads.org/index.php?showtopic=503412651"></ref><ref source="" url="http://jvn.jp/jp/JVN%2307274813/index.html"></ref><ref source="" url="https://developer.openads.org/browser/branches/max/trunk/CHANGELOG.txt?format=raw"></ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0315">ADV-2007-0315</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/458197/100/100/threaded">20070126 [OPENADS-SA-2007-002] Max Media Manager v0.1.29 and v0.3.30 vulnerability fixed</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/458296/100/100/threaded">20070127 Re: [OPENADS-SA-2007-002] Max Media Manager v0.1.29 and v0.3.30 vulnerability fixed</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/457990/100/200/threaded">20070124 [OPENADS-SA-2007-001] phpAdsNew and phpPgAds 2.0.9-pr1 vulnerability fixed</ref></refs><vuln_soft><prod name="Openads" vendor="Openads"><vers num="2.3.30"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" modified="2008-01-02" name="CVE-2007-0478" published="2007-01-24" seq="2007-0478" severity="Medium" type="CVE"><desc><descript source="cve">WebCore on Apple Mac OS X 10.3.9 and 10.4.10, as used in Safari, does not properly parse HTML comments in TITLE elements, which allows remote attackers to conduct cross-site scripting (XSS) attacks and bypass some XSS protection schemes by embedding certain HTML tags within an HTML comment.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/457763/100/0/threaded">20070123 Safari Improperly Parses HTML Documents &amp; BlogSpot XSS vulnerability</ref><ref source="" url="http://www.beanfuzz.com/wordpress/?p=99"></ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31846">safari-html-xss(31846)</ref><ref source="" url="http://docs.info.apple.com/article.html?artnum=306172"></ref><ref source="APPLE" url="http://lists.apple.com/archives/security-announce//2007/Jul/msg00004.html">APPLE-SA-2007-07-31</ref><ref source="BID" url="http://www.securityfocus.com/bid/25159">25159</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/2732">ADV-2007-2732</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1018494">1018494</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/23893">23893</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/26235">26235</ref></refs><vuln_soft><prod name="Safari" vendor="Apple"><vers num=""/></prod><prod name="WebCore" vendor="Apple"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.8" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.9" CVSS_score="7.8" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_version="2.0" modified="2007-05-16" name="CVE-2007-0479" published="2007-01-24" seq="2007-0479" severity="High" type="CVE"><desc><descript source="cve">Memory leak in the TCP listener in Cisco IOS 9.x, 10.x, 11.x, and 12.x allows remote attackers to cause a denial of service by sending crafted TCP traffic to an IPv4 address on the IOS device.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref source="CISCO" url="http://www.cisco.com/en/US/products/products_security_advisory09186a00807cb0e4.shtml">20070124 Crafted TCP Packet Can Cause Denial of Service</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/217912">VU#217912</ref><ref source="BID" url="http://www.securityfocus.com/bid/22208">22208</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0329">ADV-2007-0329</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1017551">1017551</ref><ref source="SECUNIA" url="http://secunia.com/advisories/23867">23867</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31716">cisco-tcp-ipv4-dos(31716)</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA07-024A.html">TA07-024A</ref></refs><vuln_soft><prod name="IOS Transmission Control Protocol" vendor="Cisco"><vers num="12"/><vers num="12.0DA"/><vers num="12.0DB"/><vers num="12.0DC"/><vers num="12.0S"/><vers num="12.0SC"/><vers num="12.0SL"/><vers num="12.0SP"/><vers num="12.0ST"/><vers num="12.0SX"/><vers num="12.0SY"/><vers num="12.0SZ"/><vers num="12.0T"/><vers num="12.0W"/><vers num="12.0WC"/><vers num="12.0WT"/><vers num="12.0XA"/><vers num="12.0XB"/><vers num="12.0XC"/><vers num="12.0XD"/><vers num="12.0XE"/><vers num="12.0XF"/><vers num="12.0XG"/><vers num="12.0XH"/><vers num="12.0XI"/><vers num="12.0XJ"/><vers num="12.0XK"/><vers num="12.0XL"/><vers num="12.0XM"/><vers num="12.0XQ"/><vers num="12.0XR"/><vers num="12.0XS"/><vers num="12.0XV"/><vers num="12.0XW"/><vers num="12.1"/><vers num="12.1AA"/><vers num="12.1AX"/><vers num="12.1AY"/><vers num="12.1AZ"/><vers num="12.1CX"/><vers num="12.1DA"/><vers num="12.1DB"/><vers num="12.1DC"/><vers num="12.1E"/><vers num="12.1EA"/><vers num="12.1EB"/><vers num="12.1EC"/><vers num="12.1EO"/><vers num="12.1EU"/><vers num="12.1EV"/><vers num="12.1EW"/><vers num="12.1EX"/><vers num="12.1EY"/><vers num="12.1EZ"/><vers num="12.1T"/><vers num="12.1X"/><vers num="12.1XA"/><vers num="12.1XB"/><vers num="12.1XC"/><vers num="12.1XD"/><vers num="12.1XE"/><vers num="12.1XF"/><vers num="12.1XG"/><vers num="12.1XH"/><vers num="12.1XI"/><vers num="12.1XJ"/><vers num="12.1XL"/><vers num="12.1XP"/><vers num="12.1XQ"/><vers num="12.1XR"/><vers num="12.1XS"/><vers num="12.1XT"/><vers num="12.1XU"/><vers num="12.1XV"/><vers num="12.1XW"/><vers num="12.1XX"/><vers num="12.1XY"/><vers num="12.1XZ"/><vers num="12.1YA"/><vers num="12.1YB"/><vers num="12.1YC"/><vers num="12.1YD"/><vers num="12.1YE"/><vers num="12.1YF"/><vers num="12.1YH"/><vers num="12.1YI"/><vers num="12.1YJ"/><vers num="12.2"/><vers num="12.2B"/><vers num="12.2BC"/><vers num="12.2BW"/><vers num="12.2BY"/><vers num="12.2BZ"/><vers num="12.2CX"/><vers num="12.2CY"/><vers num="12.2CZ"/><vers num="12.2DA"/><vers num="12.2DD"/><vers num="12.2DX"/><vers num="12.2EU"/><vers num="12.2EW"/><vers num="12.2EWA"/><vers num="12.2EX"/><vers num="12.2EY"/><vers num="12.2EZ"/><vers num="12.2FX"/><vers num="12.2FY"/><vers num="12.2FZ"/><vers num="12.2IXA"/><vers num="12.2IXB"/><vers num="12.2IXC"/><vers num="12.2JA"/><vers num="12.2JK"/><vers num="12.2MB"/><vers num="12.2MC"/><vers num="12.2S"/><vers num="12.2SB"/><vers num="12.2SBC"/><vers num="12.2SE"/><vers num="12.2SEA"/><vers num="12.2SEB"/><vers num="12.2SEC"/><vers num="12.2SED"/><vers num="12.2SEE"/><vers num="12.2SEF"/><vers num="12.2SEG"/><vers num="12.2SG"/><vers num="12.2SGA"/><vers num="12.2SO"/><vers num="12.2SRA"/><vers num="12.2SRB"/><vers num="12.2SU"/><vers num="12.2SV"/><vers num="12.2SW"/><vers num="12.2SX"/><vers num="12.2SXA"/><vers num="12.2SXB"/><vers num="12.2SXD"/><vers num="12.2SXE"/><vers num="12.2SXF"/><vers num="12.2SY"/><vers num="12.2SZ"/><vers num="12.2T"/><vers num="12.2TPC"/><vers num="12.2XA"/><vers num="12.2XB"/><vers num="12.2XC"/><vers num="12.2XD"/><vers num="12.2XE"/><vers num="12.2XF"/><vers num="12.2XG"/><vers num="12.2XH"/><vers num="12.2XI"/><vers num="12.2XJ"/><vers num="12.2XK"/><vers num="12.2XL"/><vers num="12.2XM"/><vers num="12.2XN"/><vers num="12.2XQ"/><vers num="12.2XR"/><vers num="12.2XS"/><vers num="12.2XT"/><vers num="12.2XU"/><vers num="12.2XV"/><vers num="12.2XW"/><vers num="12.2YA"/><vers num="12.2YB"/><vers num="12.2YC"/><vers num="12.2YD"/><vers num="12.2YE"/><vers num="12.2YF"/><vers num="12.2YG"/><vers num="12.2YH"/><vers num="12.2YJ"/><vers num="12.2YK"/><vers num="12.2YL"/><vers num="12.2YM"/><vers num="12.2YN"/><vers num="12.2YO"/><vers num="12.2YP"/><vers num="12.2YQ"/><vers num="12.2YR"/><vers num="12.2YS"/><vers num="12.2YT"/><vers num="12.2YU"/><vers num="12.2YV"/><vers num="12.2YW"/><vers num="12.2YX"/><vers num="12.2YY"/><vers num="12.2YZ"/><vers num="12.2ZA"/><vers num="12.2ZB"/><vers num="12.2ZC"/><vers num="12.2ZD"/><vers num="12.2ZE"/><vers num="12.2ZF"/><vers num="12.2ZG"/><vers num="12.2ZH"/><vers num="12.2ZJ"/><vers num="12.2ZL"/><vers num="12.2ZN"/><vers num="12.2ZP"/><vers num="12.3"/><vers num="12.3B"/><vers num="12.3BC"/><vers num="12.3BW"/><vers num="12.3JA"/><vers num="12.3JEA"/><vers num="12.3JEB"/><vers num="12.3JK"/><vers num="12.3JX"/><vers num="12.3T"/><vers num="12.3TPC"/><vers num="12.3XA"/><vers num="12.3XB"/><vers num="12.3XC"/><vers num="12.3XD"/><vers num="12.3XE"/><vers num="12.3XF"/><vers num="12.3XG"/><vers num="12.3XH"/><vers num="12.3XI"/><vers num="12.3XJ"/><vers num="12.3XK"/><vers num="12.3XQ"/><vers num="12.3XR"/><vers num="12.3XS"/><vers num="12.3XU"/><vers num="12.3XW"/><vers num="12.3XX"/><vers num="12.3XY"/><vers num="12.3YA"/><vers num="12.3YD"/><vers num="12.3YF"/><vers num="12.3YG"/><vers num="12.3YH"/><vers num="12.3YI"/><vers num="12.3YJ"/><vers num="12.3YK"/><vers num="12.3YM"/><vers num="12.3YQ"/><vers num="12.3YS"/><vers num="12.3YT"/><vers num="12.3YU"/><vers num="12.3YX"/><vers num="12.3YZ"/><vers num="12.4"/><vers num="12.4MR"/><vers num="12.4SW"/><vers num="12.4T"/><vers num="12.4XA"/><vers num="12.4XB"/><vers num="12.4XB"/><vers num="12.4XC"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-05-16" name="CVE-2007-0480" published="2007-01-24" seq="2007-0480" severity="High" type="CVE"><desc><descript source="cve">Cisco IOS 9.x, 10.x, 11.x, and 12.x and IOS XR 2.0.x, 3.0.x, and 3.2.x allows remote attackers to cause a denial of service or execute arbitrary code via a crafted IP option in the IP header in a (1) ICMP, (2) PIMv2, (3) PGM, or (4) URD packet.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="CISCO" url="http://www.cisco.com/en/US/products/products_security_advisory09186a00807cb157.shtml">20070124 Crafted IP Option Vulnerability</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/341288">VU#341288</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0329">ADV-2007-0329</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1017555">1017555</ref><ref source="SECUNIA" url="http://secunia.com/advisories/23867">23867</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31725">cisco-ip-option-code-execution(31725)</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA07-024A.html">TA07-024A</ref><ref source="BID" url="http://www.securityfocus.com/bid/22211">22211</ref></refs><vuln_soft><prod name="IOS Transmission Control Protocol" vendor="Cisco"><vers num="12"/><vers num="12.0DA"/><vers num="12.0DB"/><vers num="12.0DC"/><vers num="12.0S"/><vers num="12.0SC"/><vers num="12.0SL"/><vers num="12.0SP"/><vers num="12.0ST"/><vers num="12.0SX"/><vers num="12.0SY"/><vers num="12.0SZ"/><vers num="12.0T"/><vers num="12.0W"/><vers num="12.0WC"/><vers num="12.0WT"/><vers num="12.0XA"/><vers num="12.0XB"/><vers num="12.0XC"/><vers num="12.0XD"/><vers num="12.0XE"/><vers num="12.0XF"/><vers num="12.0XG"/><vers num="12.0XH"/><vers num="12.0XI"/><vers num="12.0XJ"/><vers num="12.0XK"/><vers num="12.0XL"/><vers num="12.0XM"/><vers num="12.0XQ"/><vers num="12.0XR"/><vers num="12.0XS"/><vers num="12.0XV"/><vers num="12.0XW"/><vers num="12.1"/><vers num="12.1AA"/><vers num="12.1AX"/><vers num="12.1AY"/><vers num="12.1AZ"/><vers num="12.1CX"/><vers num="12.1DA"/><vers num="12.1DB"/><vers num="12.1DC"/><vers num="12.1E"/><vers num="12.1EA"/><vers num="12.1EB"/><vers num="12.1EC"/><vers num="12.1EO"/><vers num="12.1EU"/><vers num="12.1EV"/><vers num="12.1EW"/><vers num="12.1EX"/><vers num="12.1EY"/><vers num="12.1EZ"/><vers num="12.1T"/><vers num="12.1X"/><vers num="12.1XA"/><vers num="12.1XB"/><vers num="12.1XC"/><vers num="12.1XD"/><vers num="12.1XE"/><vers num="12.1XF"/><vers num="12.1XG"/><vers num="12.1XH"/><vers num="12.1XI"/><vers num="12.1XJ"/><vers num="12.1XL"/><vers num="12.1XP"/><vers num="12.1XQ"/><vers num="12.1XR"/><vers num="12.1XS"/><vers num="12.1XT"/><vers num="12.1XU"/><vers num="12.1XV"/><vers num="12.1XW"/><vers num="12.1XX"/><vers num="12.1XY"/><vers num="12.1XZ"/><vers num="12.1YA"/><vers num="12.1YB"/><vers num="12.1YC"/><vers num="12.1YD"/><vers num="12.1YE"/><vers num="12.1YF"/><vers num="12.1YH"/><vers num="12.1YI"/><vers num="12.1YJ"/><vers num="12.2"/><vers num="12.2B"/><vers num="12.2BC"/><vers num="12.2BW"/><vers num="12.2BY"/><vers num="12.2BZ"/><vers num="12.2CX"/><vers num="12.2CY"/><vers num="12.2CZ"/><vers num="12.2DA"/><vers num="12.2DD"/><vers num="12.2DX"/><vers num="12.2EU"/><vers num="12.2EW"/><vers num="12.2EWA"/><vers num="12.2EX"/><vers num="12.2EY"/><vers num="12.2EZ"/><vers num="12.2FX"/><vers num="12.2FY"/><vers num="12.2FZ"/><vers num="12.2IXA"/><vers num="12.2IXB"/><vers num="12.2IXC"/><vers num="12.2JA"/><vers num="12.2JK"/><vers num="12.2MB"/><vers num="12.2MC"/><vers num="12.2S"/><vers num="12.2SB"/><vers num="12.2SBC"/><vers num="12.2SE"/><vers num="12.2SEA"/><vers num="12.2SEB"/><vers num="12.2SEC"/><vers num="12.2SED"/><vers num="12.2SEE"/><vers num="12.2SEF"/><vers num="12.2SEG"/><vers num="12.2SG"/><vers num="12.2SGA"/><vers num="12.2SO"/><vers num="12.2SRA"/><vers num="12.2SRB"/><vers num="12.2SU"/><vers num="12.2SV"/><vers num="12.2SW"/><vers num="12.2SX"/><vers num="12.2SXA"/><vers num="12.2SXB"/><vers num="12.2SXD"/><vers num="12.2SXE"/><vers num="12.2SXF"/><vers num="12.2SY"/><vers num="12.2SZ"/><vers num="12.2T"/><vers num="12.2TPC"/><vers num="12.2XA"/><vers num="12.2XB"/><vers num="12.2XC"/><vers num="12.2XD"/><vers num="12.2XE"/><vers num="12.2XF"/><vers num="12.2XG"/><vers num="12.2XH"/><vers num="12.2XI"/><vers num="12.2XJ"/><vers num="12.2XK"/><vers num="12.2XL"/><vers num="12.2XM"/><vers num="12.2XN"/><vers num="12.2XQ"/><vers num="12.2XR"/><vers num="12.2XS"/><vers num="12.2XT"/><vers num="12.2XU"/><vers num="12.2XV"/><vers num="12.2XW"/><vers num="12.2YA"/><vers num="12.2YB"/><vers num="12.2YC"/><vers num="12.2YD"/><vers num="12.2YE"/><vers num="12.2YF"/><vers num="12.2YG"/><vers num="12.2YH"/><vers num="12.2YJ"/><vers num="12.2YK"/><vers num="12.2YL"/><vers num="12.2YM"/><vers num="12.2YN"/><vers num="12.2YO"/><vers num="12.2YP"/><vers num="12.2YQ"/><vers num="12.2YR"/><vers num="12.2YS"/><vers num="12.2YT"/><vers num="12.2YU"/><vers num="12.2YV"/><vers num="12.2YW"/><vers num="12.2YX"/><vers num="12.2YY"/><vers num="12.2YZ"/><vers num="12.2ZA"/><vers num="12.2ZB"/><vers num="12.2ZC"/><vers num="12.2ZD"/><vers num="12.2ZE"/><vers num="12.2ZF"/><vers num="12.2ZG"/><vers num="12.2ZH"/><vers num="12.2ZJ"/><vers num="12.2ZL"/><vers num="12.2ZN"/><vers num="12.2ZP"/><vers num="12.3"/><vers num="12.3B"/><vers num="12.3BC"/><vers num="12.3BW"/><vers num="12.3JA"/><vers num="12.3JEA"/><vers num="12.3JEB"/><vers num="12.3JK"/><vers num="12.3JX"/><vers num="12.3T"/><vers num="12.3TPC"/><vers num="12.3XA"/><vers num="12.3XB"/><vers num="12.3XC"/><vers num="12.3XD"/><vers num="12.3XE"/><vers num="12.3XF"/><vers num="12.3XG"/><vers num="12.3XH"/><vers num="12.3XI"/><vers num="12.3XJ"/><vers num="12.3XK"/><vers num="12.3XQ"/><vers num="12.3XR"/><vers num="12.3XS"/><vers num="12.3XU"/><vers num="12.3XW"/><vers num="12.3XX"/><vers num="12.3XY"/><vers num="12.3YA"/><vers num="12.3YD"/><vers num="12.3YF"/><vers num="12.3YG"/><vers num="12.3YH"/><vers num="12.3YI"/><vers num="12.3YJ"/><vers num="12.3YK"/><vers num="12.3YM"/><vers num="12.3YQ"/><vers num="12.3YS"/><vers num="12.3YT"/><vers num="12.3YU"/><vers num="12.3YX"/><vers num="12.3YZ"/><vers num="12.4"/><vers num="12.4MR"/><vers num="12.4SW"/><vers num="12.4T"/><vers num="12.4XA"/><vers num="12.4XB"/><vers num="12.4XB"/><vers num="12.4XC"/></prod></vuln_soft></entry><entry CVSS_base_score="7.8" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.9" CVSS_score="7.8" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_version="2.0" modified="2007-05-16" name="CVE-2007-0481" published="2007-01-24" seq="2007-0481" severity="High" type="CVE"><desc><descript source="cve">Cisco IOS allows remote attackers to cause a denial of service (crash) via a crafted IPv6 Type 0 Routing header.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref source="CISCO" url="http://www.cisco.com/en/US/products/products_security_advisory09186a00807cb0fd.shtml">20070124 IPv6 Routing Header Vulnerability</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/274760">VU#274760</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0329">ADV-2007-0329</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1017550">1017550</ref><ref source="SECUNIA" url="http://secunia.com/advisories/23867">23867</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31715">cisco-ios-ipv6-type0-dos(31715)</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA07-024A.html">TA07-024A</ref><ref source="BID" url="http://www.securityfocus.com/bid/22210">22210</ref></refs><vuln_soft><prod name="IOS Transmission Control Protocol" vendor="Cisco"><vers num="12"/><vers num="12.0DA"/><vers num="12.0DB"/><vers num="12.0DC"/><vers num="12.0S"/><vers num="12.0SC"/><vers num="12.0SL"/><vers num="12.0SP"/><vers num="12.0ST"/><vers num="12.0SX"/><vers num="12.0SY"/><vers num="12.0SZ"/><vers num="12.0T"/><vers num="12.0W"/><vers num="12.0WC"/><vers num="12.0WT"/><vers num="12.0XA"/><vers num="12.0XB"/><vers num="12.0XC"/><vers num="12.0XD"/><vers num="12.0XE"/><vers num="12.0XF"/><vers num="12.0XG"/><vers num="12.0XH"/><vers num="12.0XI"/><vers num="12.0XJ"/><vers num="12.0XK"/><vers num="12.0XL"/><vers num="12.0XM"/><vers num="12.0XQ"/><vers num="12.0XR"/><vers num="12.0XS"/><vers num="12.0XV"/><vers num="12.0XW"/><vers num="12.1"/><vers num="12.1AA"/><vers num="12.1AX"/><vers num="12.1AY"/><vers num="12.1AZ"/><vers num="12.1CX"/><vers num="12.1DA"/><vers num="12.1DB"/><vers num="12.1DC"/><vers num="12.1E"/><vers num="12.1EA"/><vers num="12.1EB"/><vers num="12.1EC"/><vers num="12.1EO"/><vers num="12.1EU"/><vers num="12.1EV"/><vers num="12.1EW"/><vers num="12.1EX"/><vers num="12.1EY"/><vers num="12.1EZ"/><vers num="12.1T"/><vers num="12.1X"/><vers num="12.1XA"/><vers num="12.1XB"/><vers num="12.1XC"/><vers num="12.1XD"/><vers num="12.1XE"/><vers num="12.1XF"/><vers num="12.1XG"/><vers num="12.1XH"/><vers num="12.1XI"/><vers num="12.1XJ"/><vers num="12.1XL"/><vers num="12.1XP"/><vers num="12.1XQ"/><vers num="12.1XR"/><vers num="12.1XS"/><vers num="12.1XT"/><vers num="12.1XU"/><vers num="12.1XV"/><vers num="12.1XW"/><vers num="12.1XX"/><vers num="12.1XY"/><vers num="12.1XZ"/><vers num="12.1YA"/><vers num="12.1YB"/><vers num="12.1YC"/><vers num="12.1YD"/><vers num="12.1YE"/><vers num="12.1YF"/><vers num="12.1YH"/><vers num="12.1YI"/><vers num="12.1YJ"/><vers num="12.2"/><vers num="12.2B"/><vers num="12.2BC"/><vers num="12.2BW"/><vers num="12.2BY"/><vers num="12.2BZ"/><vers num="12.2CX"/><vers num="12.2CY"/><vers num="12.2CZ"/><vers num="12.2DA"/><vers num="12.2DD"/><vers num="12.2DX"/><vers num="12.2EU"/><vers num="12.2EW"/><vers num="12.2EWA"/><vers num="12.2EX"/><vers num="12.2EY"/><vers num="12.2EZ"/><vers num="12.2FX"/><vers num="12.2FY"/><vers num="12.2FZ"/><vers num="12.2IXA"/><vers num="12.2IXB"/><vers num="12.2IXC"/><vers num="12.2JA"/><vers num="12.2JK"/><vers num="12.2MB"/><vers num="12.2MC"/><vers num="12.2S"/><vers num="12.2SB"/><vers num="12.2SBC"/><vers num="12.2SE"/><vers num="12.2SEA"/><vers num="12.2SEB"/><vers num="12.2SEC"/><vers num="12.2SED"/><vers num="12.2SEE"/><vers num="12.2SEF"/><vers num="12.2SEG"/><vers num="12.2SG"/><vers num="12.2SGA"/><vers num="12.2SO"/><vers num="12.2SRA"/><vers num="12.2SRB"/><vers num="12.2SU"/><vers num="12.2SV"/><vers num="12.2SW"/><vers num="12.2SX"/><vers num="12.2SXA"/><vers num="12.2SXB"/><vers num="12.2SXD"/><vers num="12.2SXE"/><vers num="12.2SXF"/><vers num="12.2SY"/><vers num="12.2SZ"/><vers num="12.2T"/><vers num="12.2TPC"/><vers num="12.2XA"/><vers num="12.2XB"/><vers num="12.2XC"/><vers num="12.2XD"/><vers num="12.2XE"/><vers num="12.2XF"/><vers num="12.2XG"/><vers num="12.2XH"/><vers num="12.2XI"/><vers num="12.2XJ"/><vers num="12.2XK"/><vers num="12.2XL"/><vers num="12.2XM"/><vers num="12.2XN"/><vers num="12.2XQ"/><vers num="12.2XR"/><vers num="12.2XS"/><vers num="12.2XT"/><vers num="12.2XU"/><vers num="12.2XV"/><vers num="12.2XW"/><vers num="12.2YA"/><vers num="12.2YB"/><vers num="12.2YC"/><vers num="12.2YD"/><vers num="12.2YE"/><vers num="12.2YF"/><vers num="12.2YG"/><vers num="12.2YH"/><vers num="12.2YJ"/><vers num="12.2YK"/><vers num="12.2YL"/><vers num="12.2YM"/><vers num="12.2YN"/><vers num="12.2YO"/><vers num="12.2YP"/><vers num="12.2YQ"/><vers num="12.2YR"/><vers num="12.2YS"/><vers num="12.2YT"/><vers num="12.2YU"/><vers num="12.2YV"/><vers num="12.2YW"/><vers num="12.2YX"/><vers num="12.2YY"/><vers num="12.2YZ"/><vers num="12.2ZA"/><vers num="12.2ZB"/><vers num="12.2ZC"/><vers num="12.2ZD"/><vers num="12.2ZE"/><vers num="12.2ZF"/><vers num="12.2ZG"/><vers num="12.2ZH"/><vers num="12.2ZJ"/><vers num="12.2ZL"/><vers num="12.2ZN"/><vers num="12.2ZP"/><vers num="12.3"/><vers num="12.3B"/><vers num="12.3BC"/><vers num="12.3BW"/><vers num="12.3JA"/><vers num="12.3JEA"/><vers num="12.3JEB"/><vers num="12.3JK"/><vers num="12.3JX"/><vers num="12.3T"/><vers num="12.3TPC"/><vers num="12.3XA"/><vers num="12.3XB"/><vers num="12.3XC"/><vers num="12.3XD"/><vers num="12.3XE"/><vers num="12.3XF"/><vers num="12.3XG"/><vers num="12.3XH"/><vers num="12.3XI"/><vers num="12.3XJ"/><vers num="12.3XK"/><vers num="12.3XQ"/><vers num="12.3XR"/><vers num="12.3XS"/><vers num="12.3XU"/><vers num="12.3XW"/><vers num="12.3XX"/><vers num="12.3XY"/><vers num="12.3YA"/><vers num="12.3YD"/><vers num="12.3YF"/><vers num="12.3YG"/><vers num="12.3YH"/><vers num="12.3YI"/><vers num="12.3YJ"/><vers num="12.3YK"/><vers num="12.3YM"/><vers num="12.3YQ"/><vers num="12.3YS"/><vers num="12.3YT"/><vers num="12.3YU"/><vers num="12.3YX"/><vers num="12.3YZ"/><vers num="12.4"/><vers num="12.4MR"/><vers num="12.4SW"/><vers num="12.4T"/><vers num="12.4XA"/><vers num="12.4XB"/><vers num="12.4XB"/><vers num="12.4XC"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-01-25" name="CVE-2007-0482" published="2007-01-24" seq="2007-0482" severity="Medium" type="CVE"><desc><descript source="cve">cgi-bin/main in Sun Ray Server Software 2.0 and 3.0 before 20070123 allows local users to obtain the utadmin password by reading a web server&apos;s log file, or by conducting a different, unspecified local attack.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102779-1">102779</ref><ref source="BID" url="http://www.securityfocus.com/bid/22192">
22192</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0316">
ADV-2007-0316</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1017547">
1017547</ref><ref source="SECUNIA" url="http://secunia.com/advisories/23900">
23900</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31700">
sunray-utadmin-information-disclosure(31700)</ref></refs><vuln_soft><prod name="Ray Server Software" vendor="Sun"><vers num="2.0"/><vers num="3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-01-25" name="CVE-2007-0483" published="2007-01-24" seq="2007-0483" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Enthusiast 3.1 allow remote attackers to inject arbitrary web script or HTML via the URI for (1) show_owned.php or (2) show_joined.php.  NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/23865">23865</ref><ref source="BID" url="http://www.securityfocus.com/bid/22180">

22180</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31667">
enthusiast-show-xss(31667)</ref></refs><vuln_soft><prod name="Enthusiast" vendor="Enthusiast"><vers num="3.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-01-25" name="CVE-2007-0484" published="2007-01-24" seq="2007-0484" severity="High" type="CVE"><desc><descript source="cve">Multiple SQL injection vulnerabilities in Enthusiast 3.1 allow remote attackers to execute arbitrary SQL commands via the cat parameter to (1) show_owned.php, (2) show_joined.php, and possibly other files. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/23865">23865</ref><ref source="BID" url="http://www.securityfocus.com/bid/22180">

22180</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31666">
enthusiast-show-sql-injection(31666)</ref></refs><vuln_soft><prod name="Enthusiast" vendor="Enthusiast"><vers num="3.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-01-25" name="CVE-2007-0485" published="2007-01-24" seq="2007-0485" severity="High" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in defines.php in WebChat 0.77 allows remote attackers to execute arbitrary PHP code via a URL in the WEBCHATPATH parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://www.milw0rm.com/exploits/3169"></ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31624">webchat-definesphp-file-include(31624)</ref><ref source="MILW0RM" url="http://milw0rm.com/exploits/3169">

3169</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/313610/30/25700/threaded">20030303 WebChat (PHP)</ref><ref source="BID" url="http://www.securityfocus.com/bid/7000">7000</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1006193">1006193</ref><ref source="SECUNIA" url="http://secunia.com/advisories/8206">8206</ref></refs><vuln_soft><prod name="WebChat" vendor="WebChat.org"><vers num="0.77"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-08-07" name="CVE-2007-0486" published="2007-01-24" seq="2007-0486" severity="High" type="CVE"><desc><descript source="cve">** DISPUTED **  Multiple PHP remote file inclusion vulnerabilities in Openads (aka phpAdsNew) 2.0.7 allow remote attackers to execute arbitrary PHP code via a URL in the (1) phpAds_geoPlugin parameter to libraries/lib-remotehost.inc, the (2) filename parameter to admin/report-index, or the (3) phpAds_config[my_footer] parameter to admin/lib-gui.inc.  NOTE: the vendor has disputed this issue, stating that the relevant variables are used within function definitions.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/457670/100/0/threaded">20070120 phpAdsNew 2.0.7 Remote File Include</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/457806/100/200/threaded">20070122 Re: phpAdsNew 2.0.7 Remote File Include</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/457991/100/200/threaded">20070124 Re: phpAdsNew 2.0.7 Remote File Include</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2174">2174</ref><ref source="BID" url="http://www.securityfocus.com/bid/22172">22172</ref></refs><vuln_soft><prod name="phpAdsNew" vendor="phpAdsNew"><vers num="2.0.7"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-08-07" name="CVE-2007-0487" published="2007-01-24" seq="2007-0487" severity="High" type="CVE"><desc><descript source="cve">** DISPUTED **  PHP remote file inclusion vulnerability in index.php in FreeForum 0.9.0 allows remote attackers to execute arbitrary PHP code via a URL in the fpath parameter. NOTE: this issue has been disputed by third party researchers, stating that fpath variable is initialized before being used.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/457643/100/0/threaded">20070121 FreeForum 0.9.0 &lt;=- (index.php fpath) Remote File Include Vulnerability</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/457958/100/0/threaded">20070124 Re: FreeForum 0.9.0 &lt;=- (index.php fpath) Remote File Include Vulnerability</ref></refs><vuln_soft><prod name="freeForum" vendor="ZoneO-Soft"><vers num="0.9.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0" modified="2007-01-25" name="CVE-2007-0488" published="2007-01-24" seq="2007-0488" severity="Medium" type="CVE"><desc><descript source="cve">The Huawei Versatile Routing Platform 1.43 2500E-003 firmware on the Quidway R1600 Router, and possibly other models, allows remote attackers to cause a denial of service (device crash) via a long show arp command.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2007-January/051856.html">20070118 The Quidway Router local DOS</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31641">quidway-arp-dos(31641)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2176">2176</ref></refs><vuln_soft><prod name="Versatile Routing Platform" vendor="Huawei"><vers num="1.43 2500E-003 firmware"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-01-25" name="CVE-2007-0489" published="2007-01-24" seq="2007-0489" severity="Medium" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in includes/functions.visohotlink.php in VisoHotlink 1.01 and possibly earlier allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://milw0rm.com/exploits/3175"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0285">ADV-2007-0285</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/23878">23878</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31654">visohotlink-functions-file-include(31654)</ref><ref source="BID" url="http://www.securityfocus.com/bid/22171">
22171</ref></refs><vuln_soft><prod name="VisoHotlink" vendor="VisoHotlink"><vers num="1.01" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0" modified="2007-01-25" name="CVE-2007-0490" published="2007-01-24" seq="2007-0490" severity="Medium" type="CVE"><desc><descript source="cve">index.php in Open-Realty 2.3.4 allows remote attackers to obtain sensitive information (the full path) via an invalid listingID parameter in a listingview action.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/457676/100/0/threaded">20070121 Full Path Disclosure in Open-Realty ( v2.3.4 )</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31657">
openrealty-index-path-disclosure(31657)</ref></refs><vuln_soft><prod name="Open-Realty" vendor="Open-Realty"><vers num="2.3.4"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-01-25" name="CVE-2007-0491" published="2007-01-24" seq="2007-0491" severity="Medium" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in up.php in Sky GUNNING MySpeach 3.0.6 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the my_ms[root] parameter, a different vector than CVE-2006-4630.  NOTE: Some of these details are obtained from third party information.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0269">ADV-2007-0269</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/23850">23850</ref></refs><vuln_soft><prod name="MySpeach" vendor="Sky Gunning"><vers num="3.0.6" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-01-25" name="CVE-2007-0492" published="2007-01-24" seq="2007-0492" severity="High" type="CVE"><desc><descript source="cve">Multiple SQL injection vulnerabilities in gallery.php in webSPELL 4.01.02 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) id or (2) galleryID parameter.  NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0270">ADV-2007-0270</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31632">
webspell-gallery-sql-injection(31632)</ref></refs><vuln_soft><prod name="webSPELL" vendor="webSPELL"><vers num="4.01.02" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.8" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.9" CVSS_score="7.8" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_version="2.0" modified="2007-01-26" name="CVE-2007-0493" published="2007-01-25" seq="2007-0493" severity="High" type="CVE"><desc><descript source="cve">Use-after-free vulnerability in ISC BIND 9.3.0 up to 9.3.3, 9.4.0a1 up to 9.4.0a6, 9.4.0b1 up to 9.4.0b4, 9.4.0rc1, and 9.5.0a1 (Bind Forum only) allows remote attackers to cause a denial of service (named daemon crash) via unspecified vectors that cause named to &quot;dereference a freed fetch context.&quot;</descript></desc><loss_types><avail/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2007-January/052018.html">20070125 BIND remote exploit (low severity) [Fwd: Internet Systems Consortium Security Advisory.]</ref><ref source="MLIST" url="http://marc.theaimsgroup.com/?l=bind-announce&amp;m=116968519321296&amp;w=2">[bind-announce] 20070125 Internet Systems Consortium Security Advisory.</ref><ref patch="1" source="" url="http://www.isc.org/index.pl?/sw/bind/view/?release=9.2.8"></ref><ref patch="1" source="" url="http://www.isc.org/index.pl?/sw/bind/view/?release=9.3.4"></ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0349">ADV-2007-0349</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/23904">23904</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/458066/100/0/threaded">

20070125 BIND remote exploit (low severity) [Fwd: Internet Systems Consortium Security Advisory.]</ref><ref source="" url="http://www.isc.org/index.pl?/sw/bind/bind-security.php"></ref><ref source="" url="https://issues.rpath.com/browse/RPL-989"></ref><ref source="FEDORA" url="http://fedoranews.org/cms/node/2507">
FEDORA-2007-147</ref><ref source="FEDORA" url="http://fedoranews.org/cms/node/2537">
FEDORA-2007-164</ref><ref source="FREEBSD" url="http://security.freebsd.org/advisories/FreeBSD-SA-07:02.bind.asc">
FreeBSD-SA-07:02</ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200702-06.xml">
GLSA-200702-06</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2007:030">
MDKSA-2007:030</ref><ref source="OPENPKG" url="http://www.openpkg.com/security/advisories/OpenPKG-SA-2007.007.html">
OpenPKG-SA-2007.007</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2007-0057.html">
RHSA-2007:0057</ref><ref source="SLACKWARE" url="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2007&amp;m=slackware-security.494157">
SSA:2007-026-01</ref><ref source="SUSE" url="http://lists.suse.com/archive/suse-security-announce/2007-Jan/0016.html">
SUSE-SA:2007:014</ref><ref source="TRUSTIX" url="http://www.trustix.org/errata/2007/0005">
2007-0005</ref><ref source="UBUNTU" url="http://www.ubuntu.com/usn/usn-418-1">
USN-418-1</ref><ref source="BID" url="http://www.securityfocus.com/bid/22229">
22229</ref><ref source="SECUNIA" url="http://secunia.com/advisories/23972">
23972</ref><ref source="SECUNIA" url="http://secunia.com/advisories/23924">
23924</ref><ref source="SECUNIA" url="http://secunia.com/advisories/23943">
23943</ref><ref source="SECUNIA" url="http://secunia.com/advisories/23974">
23974</ref><ref source="SECUNIA" url="http://secunia.com/advisories/23977">
23977</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24054">
24054</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24014">
24014</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24048">
24048</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24129">
24129</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24203">
24203</ref><ref source="HP" url="https://www2.itrc.hp.com/service/cki/docDisplay.do?docId=c00967144">
HPSBTU02207</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1401">
ADV-2007-1401</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24950">
24950</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24930">
24930</ref><ref source="" url="http://docs.info.apple.com/article.html?artnum=305530"></ref><ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2007/May/msg00004.html">APPLE-SA-2007-05-24</ref><ref source="HP" url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&amp;cc=us&amp;objectID=c01070495">HPSBUX02219</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:030">MDKSA-2007:030</ref><ref source="NETBSD" url="http://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2007-003.txt.asc">NetBSD-SA2007-003</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1939">ADV-2007-1939</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/2163">ADV-2007-2163</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/2315">ADV-2007-2315</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1017561">1017561</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25402">25402</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25649">25649</ref></refs><vuln_soft><prod name="BIND" vendor="ISC"><vers num="9.3.0"/><vers num="9.3.1"/><vers num="9.3.2"/><vers num="9.4.0a1"/><vers num="9.4.0a2"/><vers num="9.4.0a3"/><vers num="9.4.0a4"/><vers num="9.4.0a5"/><vers num="9.4.0b1"/><vers num="9.4.0b2"/><vers num="9.4.0b3"/><vers num="9.4.0rc1"/><vers num="9.5.0a1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:P)" CVSS_version="2.0" modified="2007-08-07" name="CVE-2007-0494" published="2007-01-25" seq="2007-0494" severity="Medium" type="CVE"><desc><descript source="cve">ISC BIND 9.0.x, 9.1.x, 9.2.0 up to 9.2.7, 9.3.0 up to 9.3.3, 9.4.0a1 up to 9.4.0a6, 9.4.0b1 up to 9.4.0b4, 9.4.0rc1, and 9.5.0a1 (Bind Forum only) allows remote attackers to cause a denial of service (exit) via a type * (ANY) DNS query response that contains multiple RRsets, which triggers an assertion error, aka the &quot;DNSSEC Validation&quot; vulnerability.</descript></desc><sols><sol source="nvd">Syccessful exploitation requires that the victim has enabled dnssec validation in named.conf by specifying trusted-keys.</sol></sols><loss_types><avail/></loss_types><range><network/></range><refs><ref patch="1" source="MLIST" url="http://marc.theaimsgroup.com/?l=bind-announce&amp;m=116968519300764&amp;w=2">[bind-announce] 20070125 Internet Systems Consortium Security Advisory.</ref><ref patch="1" source="" url="http://www.isc.org/index.pl?/sw/bind/view/?release=9.2.8"></ref><ref patch="1" source="" url="http://www.isc.org/index.pl?/sw/bind/view/?release=9.3.4"></ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/23904">23904</ref><ref source="" url="http://www.isc.org/index.pl?/sw/bind/bind-security.php"></ref><ref source="" url="https://issues.rpath.com/browse/RPL-989"></ref><ref source="DEBIAN" url="http://www.debian.org/security/2007/dsa-1254">DSA-1254</ref><ref source="FEDORA" url="http://fedoranews.org/cms/node/2507">FEDORA-2007-147</ref><ref source="FEDORA" url="http://fedoranews.org/cms/node/2537">FEDORA-2007-164</ref><ref source="FREEBSD" url="http://security.freebsd.org/advisories/FreeBSD-SA-07:02.bind.asc">FreeBSD-SA-07:02</ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200702-06.xml">GLSA-200702-06</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2007:030">MDKSA-2007:030</ref><ref source="OPENPKG" url="http://www.openpkg.com/security/advisories/OpenPKG-SA-2007.007.html">OpenPKG-SA-2007.007</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2007-0044.html">RHSA-2007:0044</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2007-0057.html">RHSA-2007:0057</ref><ref source="SLACKWARE" url="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2007&amp;m=slackware-security.494157">SSA:2007-026-01</ref><ref source="SUSE" url="http://lists.suse.com/archive/suse-security-announce/2007-Jan/0016.html">SUSE-SA:2007:014</ref><ref source="TRUSTIX" url="http://www.trustix.org/errata/2007/0005">2007-0005</ref><ref source="UBUNTU" url="http://www.ubuntu.com/usn/usn-418-1">USN-418-1</ref><ref source="BID" url="http://www.securityfocus.com/bid/22231">22231</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1017573">1017573</ref><ref source="SECUNIA" url="http://secunia.com/advisories/23972">23972</ref><ref source="SECUNIA" url="http://secunia.com/advisories/23924">23924</ref><ref source="SECUNIA" url="http://secunia.com/advisories/23944">23944</ref><ref source="SECUNIA" url="http://secunia.com/advisories/23943">23943</ref><ref source="SECUNIA" url="http://secunia.com/advisories/23974">23974</ref><ref source="SECUNIA" url="http://secunia.com/advisories/23977">23977</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24054">24054</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24014">24014</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24083">24083</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24048">24048</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24129">24129</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24203">24203</ref><ref source="" url="http://support.avaya.com/elmodocs2/security/ASA-2007-125.htm"></ref><ref source="SECUNIA" url="http://secunia.com/advisories/24648">24648</ref><ref source="HP" url="https://www2.itrc.hp.com/service/cki/docDisplay.do?docId=c00967144">HPSBTU02207</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1401">ADV-2007-1401</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24950">24950</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24930">24930</ref><ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2007-September/065902.html">20070920 VMSA-2007-0006 Critical security updates for all supported versions of VMware ESX Server, VMware Server, VMware Workstation, VMware ACE, and VMware Player</ref><ref source="" url="http://docs.info.apple.com/article.html?artnum=305530"></ref><ref source="AIXAPAR" url="http://www-1.ibm.com/support/docview.wss?uid=isg1IY95618">IY95618</ref><ref source="AIXAPAR" url="http://www-1.ibm.com/support/docview.wss?uid=isg1IY95619">IY95619</ref><ref source="AIXAPAR" url="http://www-1.ibm.com/support/docview.wss?uid=isg1IY96144">IY96144</ref><ref source="AIXAPAR" url="http://www-1.ibm.com/support/docview.wss?uid=isg1IY96324">IY96324</ref><ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2007/May/msg00004.html">APPLE-SA-2007-05-24</ref><ref source="HP" url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&amp;cc=us&amp;objectID=c01070495">HPSBUX02219</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:030">MDKSA-2007:030</ref><ref source="NETBSD" url="http://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2007-003.txt.asc">NetBSD-SA2007-003</ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20070201-01-P.asc">20070201-01-P</ref><ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102969-1">102969</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1939">ADV-2007-1939</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/2002">ADV-2007-2002</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/2163">ADV-2007-2163</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/2245">ADV-2007-2245</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/2315">ADV-2007-2315</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/3229">ADV-2007-3229</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25402">25402</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25649">25649</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25715">25715</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24284">24284</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25482">25482</ref><ref source="SECUNIA" url="http://secunia.com/advisories/26909">26909</ref><ref source="SECUNIA" url="http://secunia.com/advisories/27706">27706</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31838">bind-rrsets-dos(31838)</ref></refs><vuln_soft><prod name="BIND" vendor="ISC"><vers num="9.0.1"/><vers num="9.0"/><vers num="9.1.3"/><vers num="9.1.2"/><vers num="9.1.1"/><vers num="9.1"/><vers num="9.2.7"/><vers num="9.2.6"/><vers num="9.2.5"/><vers num="9.2.4"/><vers num="9.2.3"/><vers num="9.2.2"/><vers num="9.2.1"/><vers num="9.2"/><vers num="9.3.3"/><vers num="9.3.2"/><vers num="9.3.1"/><vers num="9.3"/><vers num="9.4.0a6"/><vers num="9.4.0a5"/><vers num="9.4.0a4"/><vers num="9.4.0a3"/><vers num="9.4.0a2"/><vers num="9.4.0a1"/><vers num="9.4.0b4"/><vers num="9.4.0b3"/><vers num="9.4.0b2"/><vers num="9.4.0b1"/><vers num="9.4.0rc1"/><vers edition="Bind Forum" num="9.5.0a1"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-01-26" name="CVE-2007-0495" published="2007-01-25" seq="2007-0495" severity="High" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in include/config.inc.php in PhpSherpa allows remote attackers to execute arbitrary PHP code via a URL in the racine parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://milw0rm.com/exploits/3161"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0263">ADV-2007-0263</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/23817">23817</ref></refs><vuln_soft><prod name="PhpSherpa" vendor="PhpSherpa"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-01-26" name="CVE-2007-0496" published="2007-01-25" seq="2007-0496" severity="High" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in lib/nl/nl.php in Neon Labs Website (nlws) 3.2 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the g_strRootDir parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://www.milw0rm.com/exploits/3163"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0268">ADV-2007-0268</ref><ref source="MILW0RM" url="http://milw0rm.com/exploits/3163">

3163</ref></refs><vuln_soft><prod name="Neon Labs Website" vendor="Neon Labs"><vers num="3.2" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-01-26" name="CVE-2007-0497" published="2007-01-25" seq="2007-0497" severity="Medium" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in upload/top.php in Upload-Service 1.0, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the maindir parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://echo.or.id/adv/adv62-y3dips-2007.txt"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0265">ADV-2007-0265</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/23845">23845</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/457800/100/100/threaded">

20070123 [ECHO_ADV_62$2007] Upload Service 1.0 remote file inclusion</ref><ref source="BID" url="http://www.securityfocus.com/bid/22189">
22189</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31634">
uploadservice-top-file-include(31634)</ref></refs><vuln_soft><prod name="Upload-Service" vendor="Upload-Service"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-01-26" name="CVE-2007-0498" published="2007-01-25" seq="2007-0498" severity="High" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in up.php in MySpeach 2.1 beta and possibly earlier allows remote attackers to execute arbitrary PHP code via a URL in the my[root] parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://www.milw0rm.com/exploits/3165"></ref><ref source="MILW0RM" url="http://milw0rm.com/exploits/3165">

3165</ref></refs><vuln_soft><prod name="MySpeach" vendor="Sky Gunning"><vers num="2.1 Beta"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2008-03-07" name="CVE-2007-0499" published="2007-01-25" seq="2007-0499" severity="Medium" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in config.php in Sangwan Kim phpIndexPage 1.0.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the env[inc_path] parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="Milw0rm" url="http://www.milw0rm.com/exploits/3164">Exploit 3164</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0267">ADV-2007-0267</ref><ref source="MILW0RM" url="http://milw0rm.com/exploits/3164">3164</ref><ref source="BID" url="http://www.securityfocus.com/bid/22161">22161</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/23992">23992</ref></refs><vuln_soft><prod name="phpIndexPage" vendor="Sangwan Kim"><vers num="1.0.1" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-01-26" name="CVE-2007-0500" published="2007-01-25" seq="2007-0500" severity="High" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in include/includes.php in Bradabra 2.0.5 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the include_path parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://milw0rm.com/exploits/3162"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0264">ADV-2007-0264</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/23851">23851</ref></refs><vuln_soft><prod name="Bradabra" vendor="Bradabra"><vers num="2.0.5" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2008-03-07" name="CVE-2007-0501" published="2007-01-25" seq="2007-0501" severity="Medium" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in index.php in Mafia Scum Tools 2.0.0 in Matthew Wardrop Advanced Random Generators (adv-random-gen) allows remote attackers to execute arbitrary PHP code via a URL in the gen parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="Milw0rm" url="http://www.milw0rm.com/exploits/3171">Exploit 3171</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0271">ADV-2007-0271</ref><ref source="MILW0RM" url="http://milw0rm.com/exploits/3171">3171</ref><ref source="BID" url="http://www.securityfocus.com/bid/22151">22151</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31637">mafiascum-index-file-include(31637)</ref></refs><vuln_soft><prod name="Mafia Scum Tools" vendor="Mafia Scum Tools"><vers num="2.0.0" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-01-26" name="CVE-2007-0502" published="2007-01-25" seq="2007-0502" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in gallery.php in webSPELL 4.01.02 allows remote attackers to execute arbitrary SQL commands via the picID parameter, a different vector than CVE-2007-0492.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://www.milw0rm.com/exploits/3172"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0270">ADV-2007-0270</ref><ref source="MILW0RM" url="http://milw0rm.com/exploits/3172">

3172</ref><ref source="BID" url="http://www.securityfocus.com/bid/22149">
22149</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31632">
webspell-gallery-sql-injection(31632)</ref></refs><vuln_soft><prod name="webSPELL" vendor="webSPELL"><vers num="4.01.02"/></prod></vuln_soft></entry><entry CVSS_base_score="6.9" CVSS_exploit_subscore="3.4" CVSS_impact_subscore="10.0" CVSS_score="6.9" CVSS_vector="(AV:L/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-01-26" name="CVE-2007-0503" published="2007-01-25" seq="2007-0503" severity="Medium" type="CVE"><desc><descript source="cve">Unspecified vulnerability in kcms_calibrate in Sun Solaris 8 and 9 before 20071122 allows local users to execute arbitrary commands via unknown vectors.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" other="1" user="1"/></loss_types><range><local/></range><refs><ref adv="1" patch="1" source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102728-1">102728</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0287">ADV-2007-0287</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1017541">1017541</ref><ref source="SECUNIA" url="http://secunia.com/advisories/23885">23885</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31668">solaris-kcmscalibrate-privilege-escalation(31668)</ref><ref source="" url="http://support.avaya.com/elmodocs2/security/ASA-2007-040.htm"></ref><ref source="BID" url="http://www.securityfocus.com/bid/22175">
22175</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1495">oval:org.mitre.oval:def:1495</ref></refs><vuln_soft><prod name="Solaris" vendor="Sun"><vers num="8.0"/><vers edition="SPARC" num="9.0"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-01-26" name="CVE-2007-0504" published="2007-01-25" seq="2007-0504" severity="High" type="CVE"><desc><descript source="cve">Eval injection vulnerability in poll_frame.php in Vote! Pro 4.0, and possibly other scripts, allows remote attackers to execute arbitrary code via the poll_id parameter, which is supplied to an eval function call, a different vulnerability type than CVE-2005-4632.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" other="1" user="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://www.milw0rm.com/exploits/3180"></ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0300">ADV-2007-0300</ref><ref source="SECUNIA" url="http://secunia.com/advisories/23834">23834</ref><ref source="MILW0RM" url="http://milw0rm.com/exploits/3180">

3180</ref></refs><vuln_soft><prod name="Vote Pro" vendor="Vote Pro"><vers num="4.0" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="8.5" CVSS_exploit_subscore="6.8" CVSS_impact_subscore="10.0" CVSS_score="8.5" CVSS_vector="(AV:N/AC:M/Au:S/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-01-26" name="CVE-2007-0505" published="2007-01-25" seq="2007-0505" severity="High" type="CVE"><desc><descript source="cve">Unrestricted file upload vulnerability in the Project issue tracking 4.7.0 through 5.x before 20070123, a module for Drupal, allows remote authenticated users to execute arbitrary code by attaching a file with executable or multiple extensions to a project issue.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" other="1" user="1"/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="" url="http://drupal.org/node/112146"></ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0312">ADV-2007-0312</ref><ref source="BID" url="http://www.securityfocus.com/bid/22224">
22224</ref><ref source="SECUNIA" url="http://secunia.com/advisories/23887">
23887</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31729">
projecttracking-extension-file-upload(31729)</ref></refs><vuln_soft><prod name="Project" vendor="Drupal"><vers edition="Dev" num="5.0"/><vers num="4.7_2.1"/><vers num="4.7_1.1"/><vers num="4.6_1.1"/><vers num="4.7"/><vers num="4.6"/></prod><prod name="Project Issue Tracking Module" vendor="Drupal"><vers edition="Dev" num="5.0"/><vers num="4.7_2.1"/><vers num="4.7_1.1"/><vers num="4.7"/></prod></vuln_soft></entry><entry CVSS_base_score="6.0" CVSS_exploit_subscore="6.8" CVSS_impact_subscore="6.4" CVSS_score="6.0" CVSS_vector="(AV:N/AC:M/Au:S/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-01-26" name="CVE-2007-0506" published="2007-01-25" seq="2007-0506" severity="Medium" type="CVE"><desc><descript source="cve">The project_issue_access function in the Project issue tracking 4.7.0 through 5.x before 20070123 module for Drupal allows remote authenticated users to bypass other access control modules and obtain attached files by guessing the filename, and obtain issue information via direct requests.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="" url="http://drupal.org/node/112146"></ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0312">ADV-2007-0312</ref><ref source="BID" url="http://www.securityfocus.com/bid/22224">
22224</ref><ref source="SECUNIA" url="http://secunia.com/advisories/23887">
23887</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31727">
projecttracking-access-weak-security(31727)</ref></refs><vuln_soft><prod name="Project" vendor="Drupal"><vers edition="Dev" num="5.0"/><vers num="4.7_2.1"/><vers num="4.7_1.1"/><vers num="4.6_1.1"/><vers num="4.7"/><vers num="4.6"/></prod><prod name="Project Issue Tracking Module" vendor="Drupal"><vers edition="Dev" num="5.0"/><vers num="4.7_2.1"/><vers num="4.7_1.1"/><vers num="4.7"/></prod></vuln_soft></entry><entry CVSS_base_score="6.0" CVSS_exploit_subscore="6.8" CVSS_impact_subscore="6.4" CVSS_score="6.0" CVSS_vector="(AV:N/AC:M/Au:S/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-01-26" name="CVE-2007-0507" published="2007-01-25" seq="2007-0507" severity="Medium" type="CVE"><desc><descript source="cve">SQL injection vulnerability in the Acidfree module for Drupal before 4.6.x-1.0, and before 4.7.x-1.0 in the 4.7 series, allows remote authenticated users with &quot;create acidfree albums&quot; privileges to execute arbitrary SQL commands via node titles.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1" user="1"/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="" url="http://drupal.org/node/112145"></ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0313">ADV-2007-0313</ref><ref source="SECUNIA" url="http://secunia.com/advisories/23895">23895</ref><ref source="BID" url="http://www.securityfocus.com/bid/22202">
22202</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31724">
acidfree-albums-sql-injection(31724)</ref></refs><vuln_soft><prod name="Acidfree" vendor="Drupal"><vers num="4.6_1.0"/><vers num="4.7_1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-01-26" name="CVE-2007-0508" published="2007-01-25" seq="2007-0508" severity="High" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in lib/selectlang.php in BBClone 0.31 allows remote attackers to execute arbitrary PHP code via a URL in the BBC_LANGUAGE_PATH parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://www.milw0rm.com/exploits/3183"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0318">ADV-2007-0318</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/23874">23874</ref><ref source="MILW0RM" url="http://milw0rm.com/exploits/3183">

3183</ref></refs><vuln_soft><prod name="BBClone" vendor="BBClone"><vers num="0.31"/></prod></vuln_soft></entry><entry CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" CVSS_score="9.3" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-01-26" name="CVE-2007-0509" published="2007-01-25" seq="2007-0509" severity="High" type="CVE"><desc><descript source="cve">Multiple unspecified vulnerabilities in MaklerPlus before 1.2 have unknown impact and attack vectors, possibly relating to cross-site scripting (XSS) in the slogan parameter in main.tpl, or information leaks in error messages.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs><ref patch="1" source="" url="http://sourceforge.net/project/shownotes.php?release_id=479940"></ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0321">ADV-2007-0321</ref><ref source="SECUNIA" url="http://secunia.com/advisories/23864">23864</ref><ref source="BID" url="http://www.securityfocus.com/bid/22206">
22206</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31734">
maklerplus-multiple-unspecified(31734)</ref></refs><vuln_soft><prod name="MaklerPlus" vendor="MaklerPlus"><vers num="1.01"/><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-01-26" name="CVE-2007-0510" published="2007-01-25" seq="2007-0510" severity="High" type="CVE"><desc><descript source="cve">Multiple buffer overflows in (1) graphs.c, (2) output.c, and (3) preserve.c in AWFFull 3.7.1 and earlier have unknown impact and attack vectors.  NOTE: some of these details are obtained from third party information.  NOTE: There may not be any attack vector that crosses privilege boundaries.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="MLIST" url="http://www.stedee.id.au/pipermail/awffull_stedee.id.au/2007-January/000309.html">[AWFFULL] 20070123 Regarding the fixes in 3.7.2</ref><ref adv="1" patch="1" source="" url="http://www.stedee.id.au/awffull#changes"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0320">ADV-2007-0320</ref><ref source="SECUNIA" url="http://secunia.com/advisories/23831">
23831</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31731">
awffull-multiple-bo(31731)</ref></refs><vuln_soft><prod name="AWFFull" vendor="AWFFull"><vers num="3.7.1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-01-26" name="CVE-2007-0511" published="2007-01-25" seq="2007-0511" severity="Medium" type="CVE"><desc><descript source="cve">Multiple PHP remote file inclusion vulnerabilities in phpXMLDOM (phpXD) 0.3 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the path parameter to (1) dom.php, (2) dtd.php, or (3) parser.php in include/.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/><config/></vuln_types><range><network/></range><refs><ref source="" url="http://www.milw0rm.com/exploits/3184"></ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/23875">23875</ref><ref source="MILW0RM" url="http://milw0rm.com/exploits/3184">

3184</ref><ref source="BID" url="http://www.securityfocus.com/bid/22201">
22201</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0309">
ADV-2007-0309</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31726">
phpxd-path-file-include(31726)</ref></refs><vuln_soft><prod name="phpXMLDOM" vendor="phpXMLDOM"><vers num="0.3"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0" modified="2007-01-26" name="CVE-2007-0512" published="2007-01-25" seq="2007-0512" severity="Medium" type="CVE"><desc><descript source="cve">Hitachi TP1/LiNK 05-00 through 05-03-/F, 03-04 through 03-06-/K, and 03-00 through 03-03-/H; and TP1/Server Base 05-00 through 05-00-/M, 03-01-E through 03-01-FD, 03-01 through 03-01-DB, and 05-03; allow attackers to cause a denial of service (process crash) via invalid data to an OpenTP1 port.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="" url="http://www.hitachi-support.com/security_e/vuls_e/HS06-021_e/01-e.html"></ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0325">ADV-2007-0325</ref><ref source="BID" url="http://www.securityfocus.com/bid/22223">
22223</ref><ref source="SECUNIA" url="http://secunia.com/advisories/23866">
23866</ref></refs><vuln_soft><prod name="TPI Link" vendor="Hitachi"><vers num="05_03_F" prev="1"/><vers num="05_00"/><vers num="03_06_K" prev="1"/><vers num="03_04"/></prod><prod name="TPI Server Base" vendor="Hitachi"><vers num="05_00_H"/><vers num="03_01_FD" prev="1"/><vers num="03_01_E"/><vers num="03_01_DB" prev="1"/><vers num="03_01"/><vers num="05_03"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0" modified="2007-01-26" name="CVE-2007-0513" published="2007-01-25" seq="2007-0513" severity="Medium" type="CVE"><desc><descript source="cve">Hitachi HiRDB Datareplicator 7HiRDB, 7(64), 6, 6(64), 5.0, and 5.0(64); and various products that bundle HiRDB Datareplicator; allows attackers to cause a denial of service (CPU consumption) via certain data.</descript></desc><loss_types><avail/></loss_types><vuln_types><other/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="" url="http://www.hitachi-support.com/security_e/vuls_e/HS06-023_e/01-e.html"></ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0327">ADV-2007-0327</ref><ref source="BID" url="http://www.securityfocus.com/bid/22244">
22244</ref><ref source="SECUNIA" url="http://secunia.com/advisories/23816">
23816</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31735">
hitachi-hirdb-request-dos(31735)</ref></refs><vuln_soft><prod name="HiRDB_Workgroup Server" vendor="Hitachi"><vers num="6"/></prod><prod name="HiRDB Datareplicator" vendor="Hitachi"><vers num="7"/><vers num="7_64"/><vers num="6"/><vers num="6_64"/><vers num="5.0"/><vers num="5.0_64"/></prod><prod name="HiRDB_Single Server Workgroup Edition" vendor="Hitachi"><vers num="5.0"/></prod><prod name="HiRDB_Parallel Server" vendor="Hitachi"><vers num="7"/><vers num="6"/><vers num="5.0"/><vers num="4.0"/></prod><prod name="HiRDB_Single Server" vendor="Hitachi"><vers num="7"/><vers num="6"/><vers num="5.0"/><vers num="4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-01-26" name="CVE-2007-0514" published="2007-01-25" seq="2007-0514" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in multiple Hitachi Web Server, uCosminexus, and Cosminexus products before 20070124 allow remote attackers to inject arbitrary web script or HTML via (1) HTTP Expect headers or (2) image maps.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="" url="http://www.hitachi-support.com/security_e/vuls_e/HS06-022_e/01-e.html"></ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0326">ADV-2007-0326</ref><ref source="SECUNIA" url="http://secunia.com/advisories/23843">
23843</ref></refs><vuln_soft><prod name="Cosminexus Server - Standard Edition Version 4" vendor="Hitachi"><vers num=""/></prod><prod name="uCosminexus Application Server Standard" vendor="Hitachi"><vers num=""/></prod><prod name="Cosminexus Application Server Version 5" vendor="Hitachi"><vers num=""/></prod><prod name="Cosminexus Server - Enterprise Edition" vendor="Hitachi"><vers num=""/></prod><prod name="uCosminexus Developer Light" vendor="Hitachi"><vers num=""/></prod><prod name="Cosminexus Developer Professional Version 6" vendor="Hitachi"><vers num=""/></prod><prod name="uCosminexus Application Server Smart Edition" vendor="Hitachi"><vers num=""/></prod><prod name="Cosminexus Application Server" vendor="Hitachi"><vers num=""/><vers edition="Enterprise" num="6"/></prod><prod name="Cosminexus Server - Web Edition" vendor="Hitachi"><vers num=""/></prod><prod name="uCosminexus Service Architect" vendor="Hitachi"><vers num=""/></prod><prod name="Cosminexus Developer Light Version 6" vendor="Hitachi"><vers num=""/></prod><prod name="Hitachi Web Server" vendor="Hitachi"><vers num=""/></prod><prod name="Cosminexus Developer Standard Version 6" vendor="Hitachi"><vers num=""/></prod><prod name="Cosminexus Developer Version 5" vendor="Hitachi"><vers num=""/></prod><prod name="uCosminexus Application Server Enterprise" vendor="Hitachi"><vers edition="Enterprise" num=""/></prod><prod name="uCosminexus Developer Standard" vendor="Hitachi"><vers num=""/></prod><prod name="uCosminexus Service Platform" vendor="Hitachi"><vers num=""/></prod><prod name="Cosminexus Server - Web Edition Version 4" vendor="Hitachi"><vers num=""/></prod><prod name="Cosminexus Server - Standard Edition" vendor="Hitachi"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" CVSS_score="9.3" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-05-16" name="CVE-2007-0515" published="2007-01-25" seq="2007-0515" severity="High" type="CVE"><desc><descript source="cve">Unspecified vulnerability in Microsoft Word allows user-assisted remote attackers to execute arbitrary code on Word 2000, and cause a denial of service on Word 2003, via unknown attack vectors that trigger memory corruption, as exploited by Trojan.Mdropper.W and later by Trojan.Mdropper.X, a different issue than CVE-2006-6456, CVE-2006-5994, and CVE-2006-6561.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" other="1" user="1"/></loss_types><range><network/><user_init/></range><refs><ref source="" url="http://www.symantec.com/enterprise/security_response/weblog/2007/01/new_microsoft_word_2000_vulner.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/22225">22225</ref><ref source="" url="http://isc.sans.org/diary.html?storyid=2133"></ref><ref source="" url="http://www.symantec.com/enterprise/security_response/weblog/2007/01/multiple_organizations_targett.html"></ref><ref source="" url="http://www.symantec.com/enterprise/security_response/writeup.jsp?docid=2007-013010-5422-99&amp;tabid=2"></ref><ref source="" url="http://www.microsoft.com/technet/security/advisory/932114.mspx"></ref><ref source="MS" url="http://www.microsoft.com/technet/security/Bulletin/MS07-014.mspx">MS07-014</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/412225">VU#412225</ref><ref source="BID" url="http://www.securityfocus.com/bid/22328">22328</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0350">ADV-2007-0350</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1017564">1017564</ref><ref source="SECUNIA" url="http://secunia.com/advisories/23950">23950</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31834">word-document-code-execution(31834)</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA07-044A.html">TA07-044A</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:528">oval:org.mitre.oval:def:528</ref></refs><vuln_soft><prod name="Office" vendor="Microsoft"><vers num="2000 SP3"/><vers num="2003 SP2"/><vers num="XP SP3"/><vers edition="Mac" num="2004"/></prod><prod name="Works Suite" vendor="Microsoft"><vers num="2004"/><vers num="2005"/><vers num="2006"/></prod><prod name="Word" vendor="Microsoft"><vers num="2000"/><vers num="2002"/><vers num="2003"/><vers num="2003 Viewer"/></prod></vuln_soft></entry><entry CVSS_base_score="3.5" CVSS_exploit_subscore="6.8" CVSS_impact_subscore="2.9" CVSS_score="3.5" CVSS_vector="(AV:N/AC:M/Au:S/C:N/I:P/A:N)" CVSS_version="2.0" modified="2007-01-26" name="CVE-2007-0516" published="2007-01-25" seq="2007-0516" severity="Low" type="CVE"><desc><descript source="cve">Yana Framework before 2.8.5a allows remote authenticated users with permissions to modify a guestbook profile to modify or delete arbitrary guestbook profiles via unspecified vectors.  NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.</descript></desc><loss_types><int/></loss_types><range><network/><user_init/></range><refs><ref adv="1" patch="1" source="" url="http://all-community.de/pub/pages/changes.php?language=en"></ref><ref adv="1" source="OSVDB" url="http://www.osvdb.org/31615">31615</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/23855">23855</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/31671">yana-unspecified-security-bypass(31671)</ref></refs><vuln_soft><prod name="Yana Framework" vendor="Yana Framework"><vers num="2.8.4a"/><vers num="2.8.3a"/><vers num="2.8.2a"/><vers num="2.8.1"/><vers num="2.8"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-01-26" name="CVE-2007-0517" published="2007-01-25" seq="2007-0517" severity="High" type="CVE"><desc><descript source="cve">Scriptsez Random PHP Quote 1.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain password information via a direct request for pwd.txt.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/><design/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/457825/100/0/threaded">20070123 RANDOM PHP QUOTE 1.0 (pwd.txt) Remote Password Disclosur</ref><ref source="SECUNIA" url="http://secunia.com/advisories/23888">
23888</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31696">
randomphpquote-pwd-information-disclosure(31696)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2184">2184</ref></refs><vuln_soft><prod name="Random PHP Quote" vendor="Scriptsez"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-01-26" name="CVE-2007-0518" published="2007-01-25" seq="2007-0518" severity="High" type="CVE"><desc><descript source="cve">Scriptsez Smart PHP Subscriber (aka subscribe) stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain encoded passwords via a direct request for pwd.txt.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/457852/100/0/threaded">20070123 subscribe (pwd.txt) Remote Password Disclosur</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/23886">23886</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31701">
subscriber-pwd-information-disclosure(31701)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2183">2183</ref></refs><vuln_soft><prod name="Smart PHP Subscriber" vendor="Scriptsez"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="3.5" CVSS_exploit_subscore="6.8" CVSS_impact_subscore="2.9" CVSS_score="3.5" CVSS_vector="(AV:N/AC:M/Au:S/C:N/I:P/A:N)" CVSS_version="2.0" modified="2007-01-26" name="CVE-2007-0519" published="2007-01-25" seq="2007-0519" severity="Low" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in memcp.php in XMB U2U Instant Messenger allows remote authenticated users to inject arbitrary web script or HTML via the recipient field.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/457630/100/0/threaded">20070120 XMB </ref><ref adv="1" source="" url="http://aria-security.com/forum/showthread.php?p=129"></ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/31661">u2u-memcp-xss(31661)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2182">2182</ref></refs><vuln_soft><prod name="U2U Instant Messenger" vendor="XMB Software"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-01-26" name="CVE-2007-0520" published="2007-01-25" seq="2007-0520" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in banner.php in Unique Ads (UDS) 1.x allows remote attackers to execute arbitrary SQL commands via the bid parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/457667/100/0/threaded">20070121 SQL Injection in Unique Ads ( UDS )</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/31660">uniqueads-banner-sql-injection(31660)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2181">2181</ref></refs><vuln_soft><prod name="Unique Ads" vendor="Unique Ads"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="2.9" CVSS_exploit_subscore="5.5" CVSS_impact_subscore="2.9" CVSS_score="2.9" CVSS_vector="(AV:A/AC:M/Au:N/C:N/I:N/A:P)" CVSS_version="2.0" modified="2007-01-26" name="CVE-2007-0521" published="2007-01-25" seq="2007-0521" severity="Low" type="CVE"><desc><descript source="cve">The Sony Ericsson K700i and W810i phones allow remote attackers to cause a denial of service (continual modal dialogs and UI unavailability) by repeatedly trying to OBEX push a file over Bluetooth, as demonstrated by ussp-push.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/><design/></vuln_types><range><local_network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/457768/100/0/threaded">20070123 Bluetooth DoS by obex push</ref><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/457797/100/0/threaded">20070123 Re: Bluetooth DoS by obex push [readable]</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2180">2180</ref></refs><vuln_soft><prod name="W810i" vendor="Sony Ericsson"><vers num=""/></prod><prod name="K700i" vendor="Sony Ericsson"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="2.9" CVSS_exploit_subscore="5.5" CVSS_impact_subscore="2.9" CVSS_score="2.9" CVSS_vector="(AV:A/AC:M/Au:N/C:N/I:N/A:P)" CVSS_version="2.0" modified="2007-01-26" name="CVE-2007-0522" published="2007-01-25" seq="2007-0522" severity="Low" type="CVE"><desc><descript source="cve">The Motorola MOTORAZR V3 phone allows remote attackers to cause a denial of service (continual modal dialogs and UI unavailability) by repeatedly trying to OBEX push a file over Bluetooth, as demonstrated by ussp-push.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/><design/></vuln_types><range><local_network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/457768/100/0/threaded">20070123 Bluetooth DoS by obex push</ref><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/457797/100/0/threaded">20070123 Re: Bluetooth DoS by obex push [readable]</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2180">2180</ref></refs><vuln_soft><prod name="MOTORAZR" vendor="Motorola"><vers num="V3"/></prod></vuln_soft></entry><entry CVSS_base_score="2.9" CVSS_exploit_subscore="5.5" CVSS_impact_subscore="2.9" CVSS_score="2.9" CVSS_vector="(AV:A/AC:M/Au:N/C:N/I:N/A:P)" CVSS_version="2.0" modified="2007-01-26" name="CVE-2007-0523" published="2007-01-25" seq="2007-0523" severity="Low" type="CVE"><desc><descript source="cve">The Nokia N70 phone allows remote attackers to cause a denial of service (continual modal dialogs and UI unavailability) by repeatedly trying to OBEX push a file over Bluetooth, as demonstrated by ussp-push.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/><design/></vuln_types><range><local_network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/457768/100/0/threaded">20070123 Bluetooth DoS by obex push</ref><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/457797/100/0/threaded">20070123 Re: Bluetooth DoS by obex push [readable]</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2180">2180</ref></refs><vuln_soft><prod name="N70" vendor="Nokia"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="2.9" CVSS_exploit_subscore="5.5" CVSS_impact_subscore="2.9" CVSS_score="2.9" CVSS_vector="(AV:A/AC:M/Au:N/C:N/I:N/A:P)" CVSS_version="2.0" modified="2007-01-26" name="CVE-2007-0524" published="2007-01-25" seq="2007-0524" severity="Low" type="CVE"><desc><descript source="cve">The LG Chocolate KG800 phone allows remote attackers to cause a denial of service (continual modal dialogs and UI unavailability) by repeatedly trying to OBEX push a file over Bluetooth, as demonstrated by ussp-push.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/><design/></vuln_types><range><local_network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/457768/100/0/threaded">20070123 Bluetooth DoS by obex push</ref><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/457797/100/0/threaded">20070123 Re: Bluetooth DoS by obex push [readable]</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2180">2180</ref></refs><vuln_soft><prod name="Chocolate KG800" vendor="LG Electronics"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-01-28" name="CVE-2007-0525" published="2007-01-25" seq="2007-0525" severity="High" type="CVE"><desc><descript source="cve">Multiple buffer overflows in Nickolas Grigoriadis Mini Web server (MiniWebsvr) before 0.05 have unknown impact and attack vectors.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref patch="1" source="" url="http://sourceforge.net/project/shownotes.php?release_id=479480&amp;group_id=187000"></ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0294">ADV-2007-0294</ref></refs><vuln_soft><prod name="Mini Web server" vendor="Grigoriadis"><vers num="0.04" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:P)" CVSS_version="2.0" modified="2007-01-28" name="CVE-2007-0526" published="2007-01-25" seq="2007-0526" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Bitweaver 1.3.1 allow remote attackers to inject arbitrary web script or HTML via the URL (PATH_INFO) to (1) articles/edit.php, (2) articles/list.php, (3) blogs/list_blogs.php, or (4) blogs/rankings.php.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/457695/100/0/threaded">20070122 [x0n3-h4ck] bitweaver 1.3.1 XSS Exploit</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31655">bitweaver-multiple-scripts-xss(31655)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2186">2186</ref></refs><vuln_soft><prod name="Bitweaver" vendor="Bitweaver"><vers num="1.3.1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-08-07" name="CVE-2007-0527" published="2007-01-25" seq="2007-0527" severity="Medium" type="CVE"><desc><descript source="cve">SQL injection vulnerability in the is_remembered function in class.login.php in Website Baker 2.6.5 and earlier allows remote attackers to execute arbitrary SQL commands via the REMEMBER_KEY cookie parameter. NOTE: some of these details are obtained from third party information.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/457684/100/0/threaded">20070122 SQL Injection by using Cookie Poisoning for Website Baker Version 2.6.5 and before</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/23828">23828</ref><ref source="BID" url="http://www.securityfocus.com/bid/22176">22176</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0311">ADV-2007-0311</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31692">websitebaker-login-sql-injection(31692)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2185">2185</ref></refs><vuln_soft><prod name="Website Baker" vendor="Website Baker"><vers num="2.6.5" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="9.0" CVSS_exploit_subscore="8.0" CVSS_impact_subscore="10.0" CVSS_score="9.0" CVSS_vector="(AV:N/AC:L/Au:S/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-01-28" name="CVE-2007-0528" published="2007-01-25" seq="2007-0528" severity="High" type="CVE"><desc><descript source="cve">The admin web console implemented by the Centrality Communications (aka Aredfox) PA168 chipset and firmware 1.54 and earlier, as provided by various IP phones, does not require passwords or authentication tokens when using HTTP, which allows remote attackers to connect to existing superuser sessions and obtain sensitive information (passwords and configuration data).</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><access/><design/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/457868/100/0/threaded">20070123 PR06-14: IP Phones based on Centrality Communications/Aredfox PA168 chipset weak session management vulnerability</ref><ref adv="1" source="" url="http://www.procheckup.com/Vulner_PR0614.php"></ref><ref source="MILW0RM" url="http://milw0rm.com/exploits/3189">
3189</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0346">
ADV-2007-0346</ref><ref source="SECUNIA" url="http://secunia.com/advisories/23919">
23919</ref><ref source="SECUNIA" url="http://secunia.com/advisories/23936">
23936</ref></refs><vuln_soft><prod name="PA168 chipset" vendor="Centrality Communications"><vers num="firmware 1.54" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" modified="2007-01-28" name="CVE-2007-0529" published="2007-01-25" seq="2007-0529" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in index.html (aka the administration page) in PHP Link Directory (phpLD) 3.0.6 and earlier allows remote attackers to inject arbitrary web script or HTML via a crafted link, which is triggered when the administrator uses the &quot;Validate Links&quot; functionality.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/457672/100/0/threaded">20070121 PHP Link Directory XSS Vulnerability version &lt;= 3.0.6</ref><ref adv="1" patch="1" source="" url="http://www.smilehouse.com/advisory/phplinkdirectory_070121.txt"></ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/31662">phpld-admin-xss(31662)</ref></refs><vuln_soft><prod name="PHP Link Directory" vendor="PHP Link Directory"><vers num="3.0.6" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-01-28" name="CVE-2007-0530" published="2007-01-25" seq="2007-0530" severity="High" type="CVE"><desc><descript source="cve">** DISPUTED **  Multiple PHP remote file inclusion vulnerabilities in Advanced Guestbook 2.4.2 allow remote attackers to execute arbitrary PHP code via a URL in the include_path parameter to (1) index.php, (2) addentry.php, or (3) picture.php, a different set of vectors than CVE-2006-5804.  NOTE: this issue has been disputed by third party researchers, stating that the include_path variable is instantiated before use.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/457870/100/0/threaded">20070123 Advanced Guestbook &lt;=- 2.4.2 (include_path) Remote File Include Vulnerability</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/457955/100/0/threaded">20070123 Re: Advanced Guestbook &lt;=- 2.4.2 (include_path) Remote File Include Vulnerability</ref></refs><vuln_soft><prod name="Advanced Guestbook" vendor="Advanced Guestbook"><vers num="2.4.2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-01-28" name="CVE-2007-0531" published="2007-01-25" seq="2007-0531" severity="High" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in includes/login.php in FreeWebShop 2.2.3 and 2.2.4 before 20070123 allows remote attackers to execute arbitrary PHP code via a URL in the lang_file parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="" url="http://14house.blogspot.com/2007/01/freewebshoporg-remote-file-inclusion.html"></ref><ref source="" url="http://www.freewebshop.org/?id=36"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0319">ADV-2007-0319</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/23898">23898</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1017549">
1017549</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31732">
freewebshop-login-file-include(31732)</ref></refs><vuln_soft><prod name="FreeWebShop" vendor="FreeWebShop"><vers num="2.2.3"/><vers num="2.2.4"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0" modified="2007-01-28" name="CVE-2007-0532" published="2007-01-25" seq="2007-0532" severity="Medium" type="CVE"><desc><descript source="cve">Tuan Do Uploader (aka php-uploader) 6 beta 1 stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain the administrator password hash via a direct request for userdata/user_1.txt.</descript></desc><loss_types><conf/></loss_types><vuln_types><access/><design/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/457698/100/0/threaded">20070122 Uploader &lt;= (userdata/user_1.txt) Password Disclosure Vulnerability</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31683">uploader-userdata-info-disclosure(31683)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2187">2187</ref></refs><vuln_soft><prod name="Uploader" vendor="Tuan Do"><vers num="6 Beta 1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0" modified="2007-01-28" name="CVE-2007-0533" published="2007-01-25" seq="2007-0533" severity="Medium" type="CVE"><desc><descript source="cve">The AToZed IntraWeb component 8.0 and earlier for Borland Delphi and Kylix, and IntraWeb 9.0 before build (9.0.12), allows remote attackers to cause a denial of service (thread hang or CPU consumption) via a crafted HTTP request, related to the OnBeforeDispatch function in the TIWServerController object.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/457758/100/0/threaded">20070123 AToZed Software Intraweb Component for Borland Delphi and Kylix DoS vulnerability</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/458121/100/0/threaded">20070125 Re: AToZed Software Intraweb Component for Borland Delphi and Kylix DoS vulnerability</ref><ref source="" url="http://blogs.atozed.com/Olaf/20070124A.en.aspx"></ref><ref source="" url="http://blogs.atozed.com/Olaf/20070124.en.aspx"></ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31685">intraweb-component-dos(31685)</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/457947/100/0/threaded">
20070124 Re: AToZed Software Intraweb Component for Borland Delphi and Kylix DoS vulnerability</ref><ref source="BID" url="http://www.securityfocus.com/bid/22185">
22185</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0355">
ADV-2007-0355</ref><ref source="SECUNIA" url="http://secunia.com/advisories/23902">
23902</ref></refs><vuln_soft><prod name="IntraWeb Component" vendor="AToZed Software"><vers num="9.0"/><vers num="8.0" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" modified="2007-02-02" name="CVE-2007-0534" published="2007-01-25" seq="2007-0534" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in the (1) Project issue tracking 4.7.0 through 5.x before 20070123 and (2) Project 4.6.0 through 5.x before 20070123 modules for Drupal allow remote authenticated users to inject arbitrary web script or HTML via (a) certain &quot;fields on project nodes&quot; or (b) &quot;certain project-specific settings regarding issue tracking.&quot;</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://drupal.org/node/112146"></ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0312">ADV-2007-0312</ref><ref source="BID" url="http://www.securityfocus.com/bid/22224">
22224</ref><ref source="SECUNIA" url="http://secunia.com/advisories/23908">
23908</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31728">
projecttracking-unspecified-xss(31728)</ref></refs><vuln_soft><prod name="Project" vendor="Drupal"><vers num="5" prev="1"/><vers num="4.6.0"/></prod><prod name="Project Issue Tracking module" vendor="Drupal"><vers num="5" prev="1"/><vers num="4.7.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-02-02" name="CVE-2007-0535" published="2007-01-25" seq="2007-0535" severity="High" type="CVE"><desc><descript source="cve">Multiple eval injection vulnerabilities in Vote! Pro 4.0, and possibly earlier, allow remote attackers to execute arbitrary code via requests to unspecified PHP scripts with the poll_id parameter, which is supplied to eval function calls, a different set of vectors than CVE-2007-0504.  NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0300">ADV-2007-0300</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/23834">23834</ref></refs><vuln_soft><prod name="Vote Pro" vendor="Vote Pro"><vers num="4.0" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-01-29" name="CVE-2007-0536" published="2007-01-26" seq="2007-0536" severity="High" type="CVE"><desc><descript source="cve">The chroot helper in rMake for rPath Linux 1 does not drop supplemental groups, which causes packages to be installed with insecure permissions and might allow local users to gain privileges.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref source="" url="https://issues.rpath.com/browse/RPL-987"></ref><ref source="" url="http://lists.rpath.com/pipermail/security-announce/2007-January/000137.html"></ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31942">
rpath-rmake-privilege-escalation(31942)</ref><ref source="SECUNIA" url="http://secunia.com/advisories/23922">23922</ref></refs><vuln_soft><prod name="rPath Linux" vendor="rPath"><vers num="1"/></prod></vuln_soft></entry><entry CVSS_base_score="2.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="2.9" CVSS_score="2.6" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" modified="2008-01-17" name="CVE-2007-0537" published="2007-01-29" seq="2007-0537" severity="Low" type="CVE"><desc><descript source="cve">The KDE HTML library (kdelibs), as used by Konqueror 3.5.5, does not properly parse HTML comments, which allows remote attackers to conduct cross-site scripting (XSS) attacks and bypass some XSS protection schemes by embedding certain HTML tags within a comment in a title tag, a related issue to CVE-2007-0478.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/457924/100/0/threaded">20070124 Re: Safari Improperly Parses HTML Documents &amp; BlogSpot XSS vulnerability</ref><ref source="" url="http://www.kde.org/info/security/advisory-20070206-1.txt"></ref><ref source="" url="https://issues.rpath.com/browse/RPL-1117"></ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200703-10.xml">GLSA-200703-10</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2007:031">MDKSA-2007:031</ref><ref source="UBUNTU" url="http://www.ubuntu.com/usn/usn-420-1">USN-420-1</ref><ref source="BID" url="http://www.securityfocus.com/bid/22428">22428</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0505">ADV-2007-0505</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1017591">1017591</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/23932">23932</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24013">24013</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24065">24065</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24442">24442</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24463">24463</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2007_6_sr.html">SUSE-SR:2007:006</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24889">24889</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:031">MDKSA-2007:031</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:157">MDKSA-2007:157</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2007-0909.html">RHSA-2007:0909</ref><ref source="SECUNIA" url="http://secunia.com/advisories/27108">27108</ref></refs><vuln_soft><prod name="Konqueror" vendor="KDE"><vers num="3.5.5"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0" modified="2007-01-30" name="CVE-2007-0538" published="2007-01-29" seq="2007-0538" severity="Medium" type="CVE"><desc><descript source="cve">Telligent Community Server 2.1 and earlier allows remote attackers to cause a denial of service (bandwidth or thread consumption) via pingback service calls with a source URI that corresponds to (1) a large file, which triggers a long download session without a timeout constraint; or (2) a file with a binary content type, which is downloaded even though it cannot contain usable pingback data.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/457999/100/0/threaded">20070124 DoS against Telligent Community Server</ref><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/457996/100/0/threaded">20070124 Weaknesses in Pingback Design</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2211">2211</ref></refs><vuln_soft><prod name="Community Server Forums" vendor="Telligent Systems"><vers num="2.1" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.8" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.9" CVSS_score="7.8" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_version="2.0" modified="2007-08-06" name="CVE-2007-0539" published="2007-01-29" seq="2007-0539" severity="High" type="CVE"><desc><descript source="cve">The wp_remote_fopen function in WordPress before 2.1 allows remote attackers to cause a denial of service (bandwidth or thread consumption) via pingback service calls with a source URI that corresponds to a large file, which triggers a long download session without a timeout constraint.</descript></desc><loss_types><avail/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/458003/100/0/threaded">20070124 Multiple Remote Vulnerabilities in Wordpress</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/457996/100/0/threaded">20070124 Weaknesses in Pingback Design</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2191">2191</ref></refs><vuln_soft><prod name="WordPress" vendor="WordPress"><vers num="2.0" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0" modified="2007-01-29" name="CVE-2007-0540" published="2007-01-29" seq="2007-0540" severity="Medium" type="CVE"><desc><descript source="cve">WordPress allows remote attackers to cause a denial of service (bandwidth or thread consumption) via pingback service calls with a source URI that corresponds to a file with a binary content type, which is downloaded even though it cannot contain usable pingback data.</descript></desc><loss_types><avail/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/458003/100/0/threaded">20070124 Multiple Remote Vulnerabilities in Wordpress</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/457996/100/0/threaded">20070124 Weaknesses in Pingback Design</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2191">2191</ref><ref source="DEBIAN" url="http://www.debian.org/security/2008/dsa-1564">DSA-1564</ref><ref source="SECUNIA" url="http://secunia.com/advisories/30013">30013</ref></refs><vuln_soft><prod name="WordPress" vendor="WordPress"><vers num="2.0" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0" modified="2007-10-29" name="CVE-2007-0541" published="2007-01-29" seq="2007-0541" severity="Medium" type="CVE"><desc><descript source="cve">WordPress allows remote attackers to determine the existence of arbitrary files, and possibly read portions of certain files, via pingback service calls with a source URI that corresponds to a local pathname, which triggers different fault codes for existing and non-existing files, and in certain configurations causes a brief file excerpt to be published as a blog comment.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/458003/100/0/threaded">20070124 Multiple Remote Vulnerabilities in Wordpress</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/457996/100/0/threaded">20070124 Weaknesses in Pingback Design</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2191">2191</ref></refs><vuln_soft><prod name="WordPress" vendor="WordPress"><vers num="2.0" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-01-29" name="CVE-2007-0542" published="2007-01-29" seq="2007-0542" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in show.php in 212cafe Guestbook 4.00 beta allows remote attackers to inject arbitrary web script or HTML via the user parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/457660/100/0/threaded">20070121 XSS in Guestbook ( v.4.00 beta )</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31663">guestbook-show-xss(31663)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2190">2190</ref></refs><vuln_soft><prod name="Guestbook" vendor="212cafe"><vers num="4.00 Beta"/></prod></vuln_soft></entry><entry CVSS_base_score="9.4" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="9.2" CVSS_score="9.4" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:N)" CVSS_version="2.0" modified="2007-08-06" name="CVE-2007-0543" published="2007-01-29" seq="2007-0543" severity="High" type="CVE"><desc><descript source="cve">ZixForum 1.14 and earlier stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing passwords via a direct request for Zixforum.mdb.  NOTE: a followup post suggests that this issue only occurs if the administrator does not properly follow installation directions.</descript></desc><loss_types><conf/><int/></loss_types><vuln_types><access/><design/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/457950/100/0/threaded">20070124 ZixForum &lt;= 1.14 (Zixforum.mdb) Remote Password Disclosure Vulnerability</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/458135/100/100/threaded">20070124 Re: ZixForum &lt;= 1.14 (Zixforum.mdb) Remote Password Disclosure Vulnerability</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2189">2189</ref></refs><vuln_soft><prod name="ZixForum" vendor="ZixForum"><vers num="1.14" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.0" CVSS_exploit_subscore="6.8" CVSS_impact_subscore="6.4" CVSS_score="6.0" CVSS_vector="(AV:N/AC:M/Au:S/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-02-02" name="CVE-2007-0544" published="2007-01-29" seq="2007-0544" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in private.php in MyBB (aka MyBulletinBoard) allows remote authenticated users to inject arbitrary web script or HTML via the Subject field, a different vector than CVE-2006-2949.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/457929/100/0/threaded">20070124 [Aria-Security Team] MyBB Cross-Site Scripting</ref><ref source="BID" url="http://www.securityfocus.com/bid/22205">
22205</ref><ref source="SECUNIA" url="http://secunia.com/advisories/23934">
23934</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31740">
mybb-subject-field-xss(31740)</ref><ref source="DEBIAN" url="http://www.debian.org/security/2008/dsa-1493">DSA-1493</ref><ref source="SECUNIA" url="http://secunia.com/advisories/28837">28837</ref></refs><vuln_soft><prod name="MyBB" vendor="MyBB"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.8" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.9" CVSS_score="7.8" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:N/A:N)" CVSS_version="2.0" modified="2007-02-02" name="CVE-2007-0545" published="2007-01-29" seq="2007-0545" severity="High" type="CVE"><desc><descript source="cve">Maxtricity Tagger 0.1 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing passwords via a direct request for tagger.mdb.</descript></desc><loss_types><conf/></loss_types><vuln_types><access/><design/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/457953/100/0/threaded">20070124 Maxtricity Tagger Password Disclosure Vulnerability</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2214">2214</ref></refs><vuln_soft><prod name="Tagger" vendor="Maxtricity"><vers num="0.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.8" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.9" CVSS_score="7.8" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:N/A:N)" CVSS_version="2.0" modified="2007-02-02" name="CVE-2007-0546" published="2007-01-29" seq="2007-0546" severity="High" type="CVE"><desc><descript source="cve">Toxiclab Shoutbox 1 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing passwords via a direct request for db.mdb.</descript></desc><loss_types><conf/></loss_types><vuln_types><access/><design/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/457931/100/0/threaded">20070124 Toxiclab Shoutbox Password Disclosure Vulnerability</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2213">2213</ref></refs><vuln_soft><prod name="Shoutbox" vendor="Toxiclab"><vers num="1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" modified="2007-02-02" name="CVE-2007-0547" published="2007-01-29" seq="2007-0547" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in CGI-RESCUE WebFORM 4.3 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://jvn.jp/jp/JVN%2305123538/index.html"></ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/23913">23913</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0344">
ADV-2007-0344</ref></refs><vuln_soft><prod name="WebFORM" vendor="CGI-RESCUE"><vers num="4.3" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0" modified="2007-01-30" name="CVE-2007-0548" published="2007-01-29" seq="2007-0548" severity="Medium" type="CVE"><desc><descript source="cve">KarjaSoft Sami HTTP Server 2.0.1 allows remote attackers to cause a denial of service (daemon hang) via a large number of requests for nonexistent objects.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref source="" url="http://www.milw0rm.com/exploits/3182"></ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/23901">23901</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/31690">sami-http-request-dos(31690)</ref><ref source="MILW0RM" url="http://milw0rm.com/exploits/3182">

3182</ref></refs><vuln_soft><prod name="Sami HTTP Server" vendor="KarjaSoft"><vers num="2.0.1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-01-30" name="CVE-2007-0549" published="2007-01-29" seq="2007-0549" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in list3.php in 212cafeBoard 6.30 Beta allows remote attackers to inject arbitrary web script or HTML via the user parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/457611/100/0/threaded">20070121 XSS in 212cafeBoard ( Verision 0.08 &amp; 6.30 Beta )</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/31650">212cafeboard-list3-xss(31650)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2212">2212</ref></refs><vuln_soft><prod name="212cafeboard" vendor="212cafe"><vers num="6.30 Beta"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-01-30" name="CVE-2007-0550" published="2007-01-29" seq="2007-0550" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in search.php in 212cafeBoard 0.08 Beta allows remote attackers to inject arbitrary web script or HTML via keyword parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/457611/100/0/threaded">20070121 XSS in 212cafeBoard ( Verision 0.08 &amp; 6.30 Beta )</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/31651">212cafeboard-search-xss(31651)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2212">2212</ref></refs><vuln_soft><prod name="212cafeBoard" vendor="212cafe"><vers num="0.08 Beta"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-01-30" name="CVE-2007-0551" published="2007-01-29" seq="2007-0551" severity="High" type="CVE"><desc><descript source="cve">Multiple PHP remote file inclusion vulnerabilities in cmsimple/cms.php in CMSimple 2.7 allow remote attackers to execute arbitrary PHP code via a URL in the (1) pth[file][config] and (2) pth[file][image] parameters.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/457668/100/0/threaded">20070120 cmsimple 2.7 Remote File Include</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/31658">cmsimple-cms-file-include(31658)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2195">2195</ref></refs><vuln_soft><prod name="CMSimple" vendor="CMSimple"><vers num="2.7"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-01-30" name="CVE-2007-0552" published="2007-01-29" seq="2007-0552" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in install/default/error404.html in Oh no! Not another CMS (Onnac) 0.0.8.4 and earlier allows remote attackers to inject arbitrary web script or HTML via the error_url parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="" url="http://onnac.svn.sourceforge.net/viewvc/onnac/trunk/install/default/error404.html?view=log"></ref><ref adv="1" source="" url="http://sourceforge.net/forum/forum.php?forum_id=655260"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0347">ADV-2007-0347</ref><ref source="BID" url="http://www.securityfocus.com/bid/22256">
22256</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31795">
onnac-error-xss(31795)</ref></refs><vuln_soft><prod name="oh no not another cms" vendor="oh no not another cms"><vers num="0.0.8.4"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-01-30" name="CVE-2007-0553" published="2007-01-29" seq="2007-0553" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in index.inc.php in PHProxy before 0.5 beta 2 allow remote attackers to inject arbitrary web script or HTML via the (1) data[realm] and (2) _url parameters, different vectors than CVE-2004-2604.  NOTE: some of these details are obtained from third party information.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref patch="1" source="" url="http://sourceforge.net/project/shownotes.php?release_id=479999&amp;group_id=110693"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0348">ADV-2007-0348</ref><ref source="BID" url="http://www.securityfocus.com/bid/22255">22255</ref></refs><vuln_soft><prod name="PHProxy" vendor="PHProxy"><vers num="0.4"/><vers num="0.3"/><vers num="0.2"/><vers num="0.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-01-30" name="CVE-2007-0554" published="2007-01-29" seq="2007-0554" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in print.asp in Guo Xu Guos Posting System (GPS) 1.2 allows remote attackers to execute arbitrary SQL commands via the id parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/458061/100/0/threaded">20070125 GPS 1.2 Content Managing System (print.asp) Remote SQL Injection Vulnerability</ref><ref source="MILW0RM" url="http://milw0rm.com/exploits/3195">
3195</ref><ref source="BID" url="http://www.securityfocus.com/bid/22232">
22232</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0353">
ADV-2007-0353</ref><ref source="SECUNIA" url="http://secunia.com/advisories/23929">
23929</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31759">
gps-print-sql-injection(31759)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2209">2209</ref></refs><vuln_soft><prod name="Guo Xu Guos Posting System" vendor="Guo Xu Guos Posting System"><vers num="1.2"/></prod></vuln_soft></entry><entry CVSS_base_score="8.5" CVSS_exploit_subscore="8.0" CVSS_impact_subscore="9.2" CVSS_score="8.5" CVSS_vector="(AV:N/AC:L/Au:S/C:C/I:N/A:C)" CVSS_version="2.0" modified="2007-02-06" name="CVE-2007-0555" published="2007-02-05" seq="2007-0555" severity="High" type="CVE"><desc><descript source="cve">PostgreSQL 7.3 before 7.3.13, 7.4 before 7.4.16, 8.0 before 8.0.11, 8.1 before 8.1.7, and 8.2 before 8.2.2 allows attackers to disable certain checks for the data types of SQL function arguments, which allows remote authenticated users to cause a denial of service (server crash) and possibly access database content.</descript></desc><loss_types><avail/><conf/></loss_types><range><network/></range><refs><ref source="" url="http://www.postgresql.org/support/security"></ref><ref source="UBUNTU" url="http://www.ubuntulinux.org/support/documentation/usn/usn-417-1">USN-417-1</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0478">ADV-2007-0478</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/24033">24033</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/459280/100/0/threaded">

20070206 rPSA-2007-0025-1 postgresql postgresql-server</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/459448/100/0/threaded">
20070208 rPSA-2007-0025-2 postgresql postgresql-server</ref><ref source="MLIST" url="http://lists.rpath.com/pipermail/security-announce/2007-February/000141.html">
[security-announce] 20070206 rPSA-2007-0025-1 postgresql postgresql-server</ref><ref source="" url="https://issues.rpath.com/browse/RPL-830"></ref><ref source="" url="https://issues.rpath.com/browse/RPL-1025"></ref><ref source="" url="http://support.avaya.com/elmodocs2/security/ASA-2007-117.htm"></ref><ref source="DEBIAN" url="http://www.debian.org/security/2007/dsa-1261">
DSA-1261</ref><ref source="FEDORA" url="http://fedoranews.org/cms/node/2554">
FEDORA-2007-198</ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200703-15.xml">
GLSA-200703-15</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:037">
MDKSA-2007:037</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2007-0064.html">
RHSA-2007:0064</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2007-0067.html">
RHSA-2007:0067</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2007-0068.html">
RHSA-2007:0068</ref><ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102825-1">
102825</ref><ref source="TRUSTIX" url="http://www.trustix.org/errata/2007/0007">
2007-0007</ref><ref source="UBUNTU" url="http://www.ubuntu.com/usn/usn-417-2">
USN-417-2</ref><ref source="BID" url="http://www.securityfocus.com/bid/22387">
22387</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0774">
ADV-2007-0774</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1017597">
1017597</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24028">
24028</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24057">
24057</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24050">
24050</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24042">
24042</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24094">
24094</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24151">
24151</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24158">
24158</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24315">
24315</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24513">
24513</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24577">
24577</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32195">
postgresql-sqlfunctions-info-disclosure(32195)</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2007_10_sr.html">
SUSE-SR:2007:010</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25220">
25220</ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20070201-01-P.asc">20070201-01-P</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24284">24284</ref></refs><vuln_soft><prod name="PostgreSQL" vendor="PostgreSQL"><vers num="8.2"/><vers num="8.1"/><vers num="8.0"/><vers num="7.4"/><vers num="7.3"/></prod></vuln_soft></entry><entry CVSS_base_score="6.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="9.2" CVSS_score="6.6" CVSS_vector="(AV:N/AC:H/Au:S/C:C/I:N/A:C)" CVSS_version="2.0" modified="2007-02-06" name="CVE-2007-0556" published="2007-02-05" seq="2007-0556" severity="Medium" type="CVE"><desc><descript source="cve">The query planner in PostgreSQL before 8.0.11, 8.1 before 8.1.7, and 8.2 before 8.2.2 does not verify that a table is compatible with a &quot;previously made query plan,&quot; which allows remote authenticated users to cause a denial of service (server crash) and possibly access database content via an &quot;ALTER COLUMN TYPE&quot; SQL statement, which can be leveraged to read arbitrary memory from the server.</descript></desc><loss_types><avail/><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://www.postgresql.org/support/security"></ref><ref source="UBUNTU" url="http://www.ubuntulinux.org/support/documentation/usn/usn-417-1">USN-417-1</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0478">ADV-2007-0478</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24033">24033</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/459280/100/0/threaded">

20070206 rPSA-2007-0025-1 postgresql postgresql-server</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/459448/100/0/threaded">
20070208 rPSA-2007-0025-2 postgresql postgresql-server</ref><ref source="MLIST" url="http://lists.rpath.com/pipermail/security-announce/2007-February/000141.html">
[security-announce] 20070206 rPSA-2007-0025-1 postgresql postgresql-server</ref><ref source="" url="https://issues.rpath.com/browse/RPL-830"></ref><ref source="" url="https://issues.rpath.com/browse/RPL-1025"></ref><ref source="" url="http://support.avaya.com/elmodocs2/security/ASA-2007-117.htm"></ref><ref source="FEDORA" url="http://fedoranews.org/cms/node/2554">
FEDORA-2007-198</ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200703-15.xml">
GLSA-200703-15</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:037">
MDKSA-2007:037</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2007-0067.html">
RHSA-2007:0067</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2007-0068.html">
RHSA-2007:0068</ref><ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102825-1">
102825</ref><ref source="TRUSTIX" url="http://www.trustix.org/errata/2007/0007">
2007-0007</ref><ref source="UBUNTU" url="http://www.ubuntu.com/usn/usn-417-2">
USN-417-2</ref><ref source="BID" url="http://www.securityfocus.com/bid/22387">
22387</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0774">
ADV-2007-0774</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1017597">
1017597</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24028">
24028</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24057">
24057</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24050">
24050</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24042">
24042</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24151">
24151</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24315">
24315</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24513">
24513</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24577">
24577</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32191">
postgresql-datatype-information-disclosure(32191)</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2007_10_sr.html">
SUSE-SR:2007:010</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25220">
25220</ref></refs><vuln_soft><prod name="PostgreSQL" vendor="PostgreSQL"><vers num="8.2.1"/><vers num="8.2"/><vers num="8.1.6"/><vers num="8.1.5"/><vers num="8.1.4"/><vers num="8.1.3"/><vers num="8.1.2"/><vers num="8.1.1"/><vers num="8.1"/><vers num="8.0.10"/><vers num="8.0.9"/><vers num="8.0.8"/><vers num="8.0.7"/><vers num="8.0.6"/><vers num="8.0.5"/><vers num="8.0.4"/><vers num="8.0.3"/><vers num="8.0.2"/><vers num="8.0.1"/><vers num="8.0"/><vers num="7.4.16"/><vers num="7.4.15"/><vers num="7.4.14"/><vers num="7.4.13"/><vers num="7.4.12"/><vers num="7.4.11"/><vers num="7.4.10"/><vers num="7.4.9"/><vers num="7.4.8"/><vers num="7.4.7"/><vers num="7.4.6"/><vers num="7.4.5"/><vers num="7.4.4"/><vers num="7.4.3"/><vers num="7.4.2"/><vers num="7.4.1"/><vers num="7.4"/><vers num="7.3.18"/><vers num="7.3.17"/><vers num="7.3.16"/><vers num="7.3.15"/><vers num="7.3.14"/><vers num="7.3.13"/><vers num="7.3.12"/><vers num="7.3.11"/><vers num="7.3.10"/><vers num="7.3.9"/><vers num="7.3.8"/><vers num="7.3.7"/><vers num="7.3.6"/><vers num="7.3.5"/><vers num="7.3.4"/><vers num="7.3.3"/><vers num="7.3.2"/><vers num="7.3.1"/><vers num="7.3"/><vers num="7.2.8"/><vers num="7.2.7"/><vers num="7.2.6"/><vers num="7.2.5"/><vers num="7.2.4"/><vers num="7.2.3"/><vers num="7.2.2"/><vers num="7.2.1"/><vers num="7.2"/><vers num="7.1.3"/><vers num="7.1.2"/><vers num="7.1.1"/><vers num="7.1"/><vers num="7.0.3"/><vers num="7.0.2"/><vers num="7.0.1"/><vers num="7.0"/><vers num="6.5.3"/><vers num="6.5.2"/><vers num="6.5.1"/><vers num="6.5"/><vers num="6.4.2"/><vers num="6.4.1"/><vers num="6.4"/><vers num="6.3.2"/><vers num="6.3.1"/><vers num="6.3"/><vers num="6.2.1"/><vers num="6.2"/><vers num="6.1.1"/><vers num="6.1"/><vers num="6.0"/><vers num="1.09"/><vers num="1.02"/><vers num="1.01"/><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-01-30" name="CVE-2007-0557" published="2007-01-29" seq="2007-0557" severity="High" type="CVE"><desc><descript source="cve">rMake before 1.0.4 drops root privileges in a way that retains the original supplemental groups, which might allow attackers to gain privileges via a crafted recipe file, a different vulnerability than CVE-2007-0536.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input/><design/></vuln_types><range><local/></range><refs><ref adv="1" source="" url="https://issues.rpath.com/browse/RPL-1002"></ref></refs><vuln_soft><prod name="rMake" vendor="rMake"><vers num="1.0.3"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-01-30" name="CVE-2007-0558" published="2007-01-30" seq="2007-0558" severity="High" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in modules/mail/main.php in Inter7 vHostAdmin 1.0 allows remote attackers to execute arbitrary PHP code via a URL in the MODULES_DIR parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://www.milw0rm.com/exploits/3191"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0339">ADV-2007-0339</ref><ref source="MILW0RM" url="http://milw0rm.com/exploits/3191">

3191</ref></refs><vuln_soft><prod name="vHostAdmin" vendor="Inter7"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-01-30" name="CVE-2007-0559" published="2007-01-30" seq="2007-0559" severity="High" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in config.php in RPW 1.0.2 allows remote attackers to execute arbitrary PHP code via a URL in the sql_language parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://www.milw0rm.com/exploits/3185"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0342">ADV-2007-0342</ref><ref source="MILW0RM" url="http://milw0rm.com/exploits/3185">

3185</ref></refs><vuln_soft><prod name="RP World" vendor="RP World"><vers num="1.0.2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-01-30" name="CVE-2007-0560" published="2007-01-30" seq="2007-0560" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in user.asp in ASP EDGE 1.2b and earlier allows remote attackers to execute arbitrary SQL commands via the user parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://www.milw0rm.com/exploits/3186"></ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/458058/100/100/threaded">

20070125 ASP EDGE &lt;= V1.2b (user.asp) Remote SQL Injection Vulnerability</ref><ref source="MILW0RM" url="http://milw0rm.com/exploits/3186">
3186</ref><ref source="BID" url="http://www.securityfocus.com/bid/22212">
22212</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0341">
ADV-2007-0341</ref><ref source="SECUNIA" url="http://secunia.com/advisories/23894">
23894</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31723">
aspedge-user-sql-injection(31723)</ref></refs><vuln_soft><prod name="ASP EDGE" vendor="ASP EDGE"><vers num="1.2b"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-01-30" name="CVE-2007-0561" published="2007-01-30" seq="2007-0561" severity="High" type="CVE"><desc><descript source="cve">Multiple PHP remote file inclusion vulnerabilities in Xero Portal 1.2 allow remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter to (1) admin_linkdb.php, (2) admin_forum_prune.php, (3) admin_extensions.php, (4) admin_board.php, (5) admin_attachments.php, or (6) admin_users.php in admin/.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://www.milw0rm.com/exploits/3192"></ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/458059/100/0/threaded">

20070125 Xero Portal v1.2 (phpbb_root_path) Remote File Include Vulnerablity</ref><ref source="MILW0RM" url="http://milw0rm.com/exploits/3192">
3192</ref><ref source="BID" url="http://www.securityfocus.com/bid/22227">
22227</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0338">
ADV-2007-0338</ref><ref source="SECUNIA" url="http://secunia.com/advisories/23952">
23952</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31767">
xero-multiple-scripts-file-include(31767)</ref></refs><vuln_soft><prod name="Xero Portal" vendor="Xero Portal"><vers num="1.2"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:P)" CVSS_version="2.0" modified="2007-01-30" name="CVE-2007-0562" published="2007-01-30" seq="2007-0562" severity="Medium" type="CVE"><desc><descript source="cve">Windows Explorer (explorer.exe) 6.0.2900.2180 in Microsoft Windows XP SP2 allows user-assisted remote attackers to cause a denial of service (application crash) via a crafted .avi file, which triggers the crash when the user right clicks on the file.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/><design/></vuln_types><range><network/><user_init/></range><refs><ref source="" url="http://www.milw0rm.com/exploits/3190"></ref><ref source="MILW0RM" url="http://milw0rm.com/exploits/3190">

3190</ref></refs><vuln_soft><prod name="Windows Explorer" vendor="Microsoft"><vers num="6.00.2900.2180"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" modified="2007-06-05" name="CVE-2007-0563" published="2007-01-30" seq="2007-0563" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Symantec Web Security (SWS) before 3.0.1.85 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors related to (1) error messages and (2) blocked page messages produced by SWS.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" patch="1" source="" url="http://securityresponse.symantec.com/avcenter/security/Content/2007.01.24c.html"></ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0330">ADV-2007-0330</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/23896">23896</ref><ref source="BID" url="http://www.securityfocus.com/bid/22184">22184</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1017558">1017558</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31750">symantec-html-xss(31750)</ref></refs><vuln_soft><prod name="Symantec Web Security" vendor="Symantec"><vers num="3.0.1.72"/><vers num="3.0.1.68"/><vers num="3.0.1.67"/><vers num="3.0.1.63"/><vers num="3.0.1.62"/><vers num="3.0.1.61"/><vers num="3.0.1.60"/><vers num="3.0.1.59"/></prod></vuln_soft></entry><entry CVSS_base_score="4.0" CVSS_exploit_subscore="8.0" CVSS_impact_subscore="2.9" CVSS_score="4.0" CVSS_vector="(AV:N/AC:L/Au:S/C:N/I:N/A:P)" CVSS_version="2.0" modified="2007-01-30" name="CVE-2007-0564" published="2007-01-30" seq="2007-0564" severity="Medium" type="CVE"><desc><descript source="cve">The license registering interface in Symantec Web Security (SWS) before 3.0.1.85 allows attackers to cause a denial of service (CPU consumption) by submitting a large file.</descript></desc><sols><sol source="nvd">This vulnerablity is addressed in the following product release:
Symantec, Symantec Web Security, 3.0.1.85</sol></sols><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref patch="1" source="" url="http://securityresponse.symantec.com/avcenter/security/Content/2007.01.24c.html"></ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0330">ADV-2007-0330</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/23896">23896</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1017558">
1017558</ref></refs><vuln_soft><prod name="Symantec Web Security" vendor="Symantec"><vers num="3.0.1.72" prev="1"/><vers num="3.0.1.68"/><vers num="3.0.1.67"/><vers num="3.0.1.63"/><vers num="3.0.1.62"/><vers num="3.0.1.61"/><vers num="3.0.1.60"/><vers num="3.0.1.59"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-08-06" name="CVE-2007-0565" published="2007-01-30" seq="2007-0565" severity="High" type="CVE"><desc><descript source="cve">CGI-Rescue Shopping Basket Professional 7.50 and earlier allows remote attackers to inject arbitrary operating system commands via unspecified vectors.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><other/></vuln_types><range><network/></range><refs><ref adv="1" source="" url="http://jvn.jp/jp/JVN%2382258242/index.html"></ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/23909">23909</ref><ref source="BID" url="http://www.securityfocus.com/bid/22245">22245</ref></refs><vuln_soft><prod name="Shopping Basket Professional" vendor="CGI-RESCUE"><vers num="7.50" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-01-30" name="CVE-2007-0566" published="2007-01-30" seq="2007-0566" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in news_detail.asp in ASP NEWS 3 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://www.milw0rm.com/exploits/3187"></ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/458057/100/100/threaded">

20070125 ASP NEWS &lt;= V3 (news_detail.asp) Remote SQL Injection Vulnerability</ref><ref source="MILW0RM" url="http://milw0rm.com/exploits/3187">
3187</ref><ref source="BID" url="http://www.securityfocus.com/bid/22214">
22214</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0340">
ADV-2007-0340</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31719">
aspnews-newsdetail-sql-injection(31719)</ref></refs><vuln_soft><prod name="ASP NEWS" vendor="ASP NEWS"><vers num="3" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-01-30" name="CVE-2007-0567" published="2007-01-30" seq="2007-0567" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in admin.php in Interactive-Scripts.Com PHP Membership Manager 1.5 allows remote attackers to inject arbitrary web script or HTML via the _p parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/458226/100/0/threaded">20070126 PHP Membership Manager Cross-Site Scripting Vulnerability</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/22263">22263</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31916">
phpmembership-admin-xss(31916)</ref></refs><vuln_soft><prod name="PHP Membership Manager" vendor="Interactive-Scripts.Com"><vers num="1.5"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-01-30" name="CVE-2007-0568" published="2007-01-30" seq="2007-0568" severity="High" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in system/lib/package.php in MyPHPCommander 2.0 allows remote attackers to execute arbitrary PHP code via a URL in the gl_root parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://www.milw0rm.com/exploits/3201"></ref><ref source="BID" url="http://www.securityfocus.com/bid/22257">22257</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0385">ADV-2007-0385</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/23890">23890</ref><ref source="MILW0RM" url="http://milw0rm.com/exploits/3201">

3201</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31906">
myphpcommander-package-file-include(31906)</ref></refs><vuln_soft><prod name="MyPHPCommander" vendor="MyPHPCommander"><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-02-01" name="CVE-2007-0569" published="2007-01-30" seq="2007-0569" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in xNews.php in xNews 1.3 allows remote attackers to execute arbitrary SQL commands via the id parameter in a shownews action.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://milw0rm.com/exploits/3216"></ref><ref source="BID" url="http://www.securityfocus.com/bid/22284">22284</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/23954">23954</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31855">
xnews-xnews-sql-injection(31855)</ref></refs><vuln_soft><prod name="xNews" vendor="X-dev"><vers num="1.3"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-01-30" name="CVE-2007-0570" published="2007-01-30" seq="2007-0570" severity="High" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in ains_main.php in Johannes Gijsbers (aka Taradino) Ad Fundum Integratable News Script (AINS) 0.02b allows remote attackers to execute arbitrary PHP code via a URL in the ains_path parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://www.milw0rm.com/exploits/3202"></ref><ref source="BID" url="http://www.securityfocus.com/bid/22259">22259</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0384">ADV-2007-0384</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31850">ains-ainsmain-file-include(31850)</ref><ref source="MILW0RM" url="http://milw0rm.com/exploits/3202">

3202</ref></refs><vuln_soft><prod name="Ad Fundum Integratable News Script" vendor="Johannes Gijsbers"><vers num="0.02b"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-01-30" name="CVE-2007-0571" published="2007-01-30" seq="2007-0571" severity="High" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in include/lib/lib_head.php in phpMyReports 3.0.11 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the cfgPathModule parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://www.milw0rm.com/exploits/3212"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0386">ADV-2007-0386</ref><ref source="MILW0RM" url="http://milw0rm.com/exploits/3212">

3212</ref><ref source="BID" url="http://www.securityfocus.com/bid/22290">
22290</ref><ref source="SECUNIA" url="http://secunia.com/advisories/23959">
23959</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31857">
phpmyreports-libhead-file-include(31857)</ref></refs><vuln_soft><prod name="phpMyReports" vendor="phpMyReports"><vers num="3.0.11"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-01-30" name="CVE-2007-0572" published="2007-01-30" seq="2007-0572" severity="High" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in include/irc/phpIRC.php in Drunken:Golem Gaming Portal 0.5.1 Alpha 2 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/><design/></vuln_types><range><network/></range><refs><ref source="" url="http://www.milw0rm.com/exploits/3207"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0390">ADV-2007-0390</ref><ref source="MILW0RM" url="http://milw0rm.com/exploits/3207">

3207</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31873">
drunkengolem-phpirc-file-include(31873)</ref></refs><vuln_soft><prod name="Gaming Portal" vendor="Drunken Golem"><vers num="0.5.1 Alpha 2" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-01-30" name="CVE-2007-0573" published="2007-01-30" seq="2007-0573" severity="High" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in includes/config.inc.php in nsGalPHP 0.41 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the racineTBS parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://milw0rm.com/exploits/3205"></ref><ref adv="1" source="MLIST" url="http://www.attrition.org/pipermail/vim/2007-January/001257.html">VIM 20070130 Source VERIFY: nsGalPHP RFI</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/22277">22277</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0392">ADV-2007-0392</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/23969">23969</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31861">
nsgalphp-config-file-include(31861)</ref></refs><vuln_soft><prod name="nsGalPHP" vendor="nsGalPHP"><vers num="0.41"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-01-30" name="CVE-2007-0574" published="2007-01-30" seq="2007-0574" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in rss/show_webfeed.php in SpoonLabs Vivvo Article Management CMS (aka phpWordPress) 3.40 allows remote attackers to execute arbitrary SQL commands via the wcHeadlines parameter, a different vector than CVE-2006-4715.  NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/22282">22282</ref></refs><vuln_soft><prod name="Vivvo Article Management CMS" vendor="SpoonLabs"><vers num="3.40"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-08-06" name="CVE-2007-0575" published="2007-01-30" seq="2007-0575" severity="High" type="CVE"><desc><descript source="cve">Multiple SQL injection vulnerabilities in the administrative login page (admin/login.asp) in ASPCode.net AdMentor allow remote attackers to execute arbitrary SQL commands via the (1) Userid and (2) Password fields.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/458303/100/0/threaded">20070127 AdMentor (banners) admin SQL injection</ref><ref source="" url="http://forums.avenir-geopolitique.net/viewtopic.php?t=2606"></ref><ref source="BID" url="http://www.securityfocus.com/bid/22281">22281</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/460632/100/100/threaded">20070220 AdMentor Script Remote SQL injection Exploit</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31908">admentor-adminlogin-sql-injection(31908)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2207">2207</ref></refs><vuln_soft><prod name="AdMentor" vendor="Stefan Holmberg"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-01-30" name="CVE-2007-0576" published="2007-01-30" seq="2007-0576" severity="High" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in xt_counter.php in Xt-Stats 2.3.x up to 2.4.0.b3 allows remote attackers to execute arbitrary PHP code via a URL in the server_base_dir parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/><design/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://seclists.org/bugtraq/2007/Jan/0643.html">20070127 Xt-Stats v.2.4.0.b3 - Remote File Include Vulnerabilities</ref><ref adv="1" source="" url="http://milw0rm.com/exploits/3209"></ref><ref source="" url="http://www.xt-scripts.com/"></ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/22276">22276</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0387">ADV-2007-0387</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/23967">23967</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/31871">xtstats-xtcounter-file-include(31871)</ref></refs><vuln_soft><prod name="Xt-Stats" vendor="Xt-Stats"><vers num="2.3.0"/><vers num="2.4.0.b3"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-01-30" name="CVE-2007-0577" published="2007-01-30" seq="2007-0577" severity="High" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in function.inc.php in ACGVclick 0.2.0 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the path parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://milw0rm.com/exploits/3206"></ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/22278">22278</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0391">ADV-2007-0391</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/23970">23970</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31859">
acgvclick-function-file-include(31859)</ref></refs><vuln_soft><prod name="ACGVclick" vendor="ACGVclick"><vers num="0.2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:P)" CVSS_version="2.0" modified="2007-06-27" name="CVE-2007-0578" published="2007-01-30" seq="2007-0578" severity="Medium" type="CVE"><desc><descript source="cve">The http_open function in httpget.c in mpg123 before 0.64 allows remote attackers to cause a denial of service (infinite loop) by closing the HTTP connection early.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" patch="1" source="" url="http://sourceforge.net/project/shownotes.php?group_id=135704&amp;release_id=478747"></ref><ref adv="1" patch="1" source="" url="http://www.mpg123.de/cgi-bin/news.cgi"></ref><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/22274">22274</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0366">ADV-2007-0366</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2007:032">MDKSA-2007:032</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:032">MDKSA-2007:032</ref></refs><vuln_soft><prod name="mpg123" vendor="mpg123"><vers num="pre0.59s"/><vers num="pre0.59s r11"/><vers num="0.63"/><vers num="0.62"/><vers num="0.59s"/><vers num="0.59r"/><vers num="0.59q"/><vers num="0.59p"/><vers num="0.59o"/><vers num="0.59n"/><vers num="0.59m"/></prod></vuln_soft></entry><entry CVSS_base_score="5.1" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="6.4" CVSS_score="5.1" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-01-30" name="CVE-2007-0579" published="2007-01-30" seq="2007-0579" severity="Medium" type="CVE"><desc><descript source="cve">Unspecified vulnerability in the calendar component in Horde Groupware Webmail Edition before 1.0, and Groupware before 1.0, allows remote attackers to include certain files via unspecified vectors.  NOTE: some of these details are obtained from third party information.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="MLIST" url="http://lists.horde.org/archives/announce/2007/000308.html">[horde-announce] 20070114 Horde Groupware 1.0 (final)</ref><ref adv="1" patch="1" source="MLIST" url="http://lists.horde.org/archives/announce/2007/000309.html">[horde-announce] 20070114 Horde Groupware Webmail Edition 1.0 (final)</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/22273">22273</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0368">ADV-2007-0368</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/31849">horde-calendar-file-include(31849)</ref></refs><vuln_soft><prod name="Groupware" vendor="Horde"><vers num="1.0 RC2"/><vers num="1.0 RC3"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-01-30" name="CVE-2007-0580" published="2007-01-30" seq="2007-0580" severity="Medium" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in menu.php in Foro Domus 2.10 allows remote attackers to execute arbitrary PHP code via a URL in the sesion_idioma parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://milw0rm.com/exploits/3215"></ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/22285">22285</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/23949">23949</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0396">
ADV-2007-0396</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31853">
forodomus-menu-file-include(31853)</ref></refs><vuln_soft><prod name="Foro Domus" vendor="Javier Suarez Sanz"><vers num="2.10"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-01-30" name="CVE-2007-0581" published="2007-01-30" seq="2007-0581" severity="High" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in functions.php in EclipseBB 0.5.0 Lite allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://www.milw0rm.com/exploits/3214"></ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/22283">22283</ref><ref source="MILW0RM" url="http://milw0rm.com/exploits/3214">

3214</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0397">
ADV-2007-0397</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31852">
eclipsebb-functions-file-include(31852)</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/466172/100/0/threaded">

20070418 EclipseBB Remote File Inclusion</ref></refs><vuln_soft><prod name="EclipseBB" vendor="EclipseBB"><vers num="0.5.0 Lite"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2008-03-07" name="CVE-2007-0582" published="2007-01-30" seq="2007-0582" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in default.asp in ChernobiLe 1.0 allows remote attackers to execute arbitrary SQL commands via the User (username) field.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="Milw0rm" url="http://www.milw0rm.com/exploits/3210">Exploit 3210</ref><ref source="BID" url="http://www.securityfocus.com/bid/22280">22280</ref><ref source="MILW0RM" url="http://milw0rm.com/exploits/3210">3210</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31939">chernobile-default-sql-injection(31939)</ref></refs><vuln_soft><prod name="ChernobiLe" vendor="ChernobiLe"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" modified="2007-01-30" name="CVE-2007-0583" published="2007-01-30" seq="2007-0583" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in HTTP Commander 6.0, and possibly earlier, allow remote attackers to inject arbitrary web script or HTML via the (1) LogoffMessage parameter to logofflast.aspx or the (2) txtUsername parameter to Default.aspx. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/23964">23964</ref><ref source="BID" url="http://www.securityfocus.com/bid/22298">

22298</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31877">
httpcommander-multiple-xss(31877)</ref></refs><vuln_soft><prod name="HTTP Commander" vendor="HTTP Commander"><vers num="6.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-01-31" name="CVE-2007-0584" published="2007-01-30" seq="2007-0584" severity="High" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in membres/membreManager.php in PhP Generic Library &amp; Framework for comm (g-neric) allows remote attackers to execute arbitrary PHP code via a URL in the include_path parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://www.milw0rm.com/exploits/3217"></ref><ref source="BID" url="http://www.securityfocus.com/bid/22287">22287</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0394">ADV-2007-0394</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/458556/100/0/threaded">

20070129 PhP Generic library &amp; framework (include_path) Remote File Include Exploit</ref><ref source="MILW0RM" url="http://milw0rm.com/exploits/3217">
3217</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31895">
phpgeneric-membremanager-file-include(31895)</ref></refs><vuln_soft><prod name="PHP Generic Library and Framework" vendor="g-neric"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" CVSS_score="9.3" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-01-31" name="CVE-2007-0585" published="2007-01-30" seq="2007-0585" severity="High" type="CVE"><desc><descript source="cve">include/debug.php in Webfwlog 0.92 and earlier, when register_globals is enabled, allows remote attackers to obtain source code of files via the conffile parameter.  NOTE: some of these details are obtained from third party information.  It is likely that this issue can be exploited to conduct directory traversal attacks.</descript></desc><impacts><impact source="nvd">Successful exploitation requires that &quot;register_globals&quot; is enabled.</impact></impacts><loss_types><avail/><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://www.milw0rm.com/exploits/3222"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0399">ADV-2007-0399</ref><ref source="MILW0RM" url="http://milw0rm.com/exploits/3222">

3222</ref><ref source="BID" url="http://www.securityfocus.com/bid/22291">
22291</ref><ref source="SECUNIA" url="http://secunia.com/advisories/23968">
23968</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31881">
webfwlog-debug-file-include(31881)</ref><ref source="" url="http://webfwlog.cvs.sourceforge.net/*checkout*/webfwlog/webfwlog/ChangeLog"></ref></refs><vuln_soft><prod name="Webfwlog" vendor="Webfwlog"><vers num="0.92" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.1" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.9" CVSS_score="7.1" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:C)" CVSS_version="2.0" modified="2007-04-10" name="CVE-2007-0588" published="2007-01-30" seq="2007-0588" severity="High" type="CVE"><desc><descript source="cve">The InternalUnpackBits function in Apple QuickDraw, as used by Quicktime 7.1.3 and other applications on Mac OS X 10.4.8 and earlier, allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted PICT file that triggers memory corruption in the _GetSrcBits32ARGB function. NOTE: this issue might overlap CVE-2007-0462.</descript></desc><loss_types><avail/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref source="" url="http://security-protocols.com/sp-x43-advisory.php"></ref><ref source="BID" url="http://www.securityfocus.com/bid/22228">22228</ref><ref source="" url="http://docs.info.apple.com/article.html?artnum=305214"></ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/396820">VU#396820</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0930">ADV-2007-0930</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017760">1017760</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24479">24479</ref><ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2007/Mar/msg00002.html">APPLE-SA-2007-03-13</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA07-072A.html">TA07-072A</ref><ref source="OSVDB" url="http://www.osvdb.org/33365">33365</ref></refs><vuln_soft><prod name="Mac OS X" vendor="Apple"><vers num="10.4.8"/></prod><prod name="Quicktime" vendor="Apple"><vers num="7.1.3"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-01-31" name="CVE-2007-0589" published="2007-01-30" seq="2007-0589" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in Forum Livre 1.0 allows remote attackers to execute arbitrary SQL commands via the user parameter to info_user.asp.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://www.milw0rm.com/exploits/3197"></ref><ref source="MILW0RM" url="http://milw0rm.com/exploits/3197">

3197</ref></refs><vuln_soft><prod name="Forum Livre" vendor="Forum Livre"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="4.9" CVSS_score="5.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:N)" CVSS_version="2.0" modified="2007-01-31" name="CVE-2007-0590" published="2007-01-30" seq="2007-0590" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in busca2.asp in Forum Livre 1.0 remote attackers to inject arbitrary web script or HTML via the palavra parameter.</descript></desc><loss_types><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://www.milw0rm.com/exploits/3197"></ref><ref source="MILW0RM" url="http://milw0rm.com/exploits/3197">

3197</ref></refs><vuln_soft><prod name="Forum Livre" vendor="Forum Livre"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-01-31" name="CVE-2007-0591" published="2007-01-30" seq="2007-0591" severity="High" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in configure.php in Vu Le An Virtual Path (VirtualPath) 1.0 allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://www.milw0rm.com/exploits/3198"></ref><ref source="MILW0RM" url="http://milw0rm.com/exploits/3198">

3198</ref><ref source="BID" url="http://www.securityfocus.com/bid/22241">
22241</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0352">
ADV-2007-0352</ref><ref source="SECUNIA" url="http://secunia.com/advisories/23918">
23918</ref></refs><vuln_soft><prod name="Virtual Path" vendor="Vu Le An"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-01-31" name="CVE-2007-0592" published="2007-01-30" seq="2007-0592" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in EzDatabase 2.1.3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors related to admin/login.php and the Admin Panel Database.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/458062/100/0/threaded">20070125 EzDatabase Multiple Cross-Site Scripting Vulnerability</ref><ref source="BID" url="http://www.securityfocus.com/bid/22235">22235</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31768">ezdatabase-adminpanel-xss(31768)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2196">2196</ref></refs><vuln_soft><prod name="EzDatabase" vendor="IndexCOR"><vers num="2.1.3"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0" modified="2007-01-31" name="CVE-2007-0593" published="2007-01-30" seq="2007-0593" severity="Medium" type="CVE"><desc><descript source="cve">Siteman 1.1.11 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing password hashes via a direct request for data/members.txt.</descript></desc><loss_types><conf/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/458092/100/0/threaded">20070125 [x0n3-h4ck] Siteman 1.1.11 Remote Md5 Hash Disclosure Vulnerability</ref><ref source="SECUNIA" url="http://secunia.com/advisories/23925">
23925</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31780">
siteman-members-information-disclosure(31780)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2205">2205</ref></refs><vuln_soft><prod name="Siteman" vendor="Siteman"><vers num="1.1.11"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0" modified="2007-01-31" name="CVE-2007-0594" published="2007-01-30" seq="2007-0594" severity="Medium" type="CVE"><desc><descript source="cve">Siteman 2.0.x2 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing password hashes via a direct request for db/siteman/users.MYD.</descript></desc><loss_types><conf/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/458081/100/0/threaded">20070125 [x0n3-h4ck] Siteman 2.0.x2 Remote Md5 Hash Disclosure Vulnerability</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2206">2206</ref></refs><vuln_soft><prod name="Siteman" vendor="Siteman"><vers num="2.0.x2"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" modified="2007-08-06" name="CVE-2007-0595" published="2007-01-30" seq="2007-0595" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in search in High 5 Review Site allows remote attackers to inject arbitrary web script or HTML via the q parameter (aka the search box).</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/458122/100/0/threaded">20070125 high5 Review script Security Risk</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0363">ADV-2007-0363</ref><ref source="SECUNIA" url="http://secunia.com/advisories/23905">23905</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31797">high5review-search-xss(31797)</ref></refs><vuln_soft><prod name="High5 Review Script" vendor="Designmind"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="6.0" CVSS_exploit_subscore="6.8" CVSS_impact_subscore="6.4" CVSS_score="6.0" CVSS_vector="(AV:N/AC:M/Au:S/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-01-31" name="CVE-2007-0596" published="2007-01-30" seq="2007-0596" severity="Medium" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in index/main.php in Aztek Forum 4.00 allows remote authenticated administrators to execute arbitrary PHP code via a URL in the PF[top_url] parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/458076/100/0/threaded">20070125 Aztek Forum 4.1 Multiple Vulnerabilities Exploit</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/458123/100/0/threaded">20070125 Re: Aztek Forum 4.1 Multiple Vulnerabilities Exploit</ref><ref source="" url="http://acid-root.new.fr/poc/21070125.txt"></ref></refs><vuln_soft><prod name="Aztek Forum" vendor="Aztek Forum"><vers num="4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0" modified="2007-01-31" name="CVE-2007-0597" published="2007-01-30" seq="2007-0597" severity="Medium" type="CVE"><desc><descript source="cve">Aztek Forum 4.00 allows remote attackers to obtain sensitive information via a direct request to forum.php with the fid=XD query string, which reveals the path in an error message.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/><exception/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/458076/100/0/threaded">20070125 Aztek Forum 4.1 Multiple Vulnerabilities Exploit</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/458123/100/0/threaded">20070125 Re: Aztek Forum 4.1 Multiple Vulnerabilities Exploit</ref><ref source="" url="http://acid-root.new.fr/poc/21070125.txt"></ref></refs><vuln_soft><prod name="Aztek Forum" vendor="Aztek Forum"><vers num="4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-01-31" name="CVE-2007-0598" published="2007-01-30" seq="2007-0598" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in forum/load.php in Aztek Forum 4.00 allows remote attackers to execute arbitrary SQL commands via the fid cookie to forum.php.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/458076/100/0/threaded">20070125 Aztek Forum 4.1 Multiple Vulnerabilities Exploit</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/458123/100/0/threaded">20070125 Re: Aztek Forum 4.1 Multiple Vulnerabilities Exploit</ref><ref source="" url="http://acid-root.new.fr/poc/21070125.txt"></ref></refs><vuln_soft><prod name="Aztek Forum" vendor="Aztek Forum"><vers num="4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-01-31" name="CVE-2007-0599" published="2007-01-30" seq="2007-0599" severity="High" type="CVE"><desc><descript source="cve">Variable overwrite vulnerability in common/config.php in Aztek Forum 4.00 allows remote attackers to overwrite arbitrary program variables and conduct other unauthorized activities, such as copying arbitrary files using index/common_actions.php, via vectors associated with extract operations on the (1) POST, (2) GET, (3) COOKIE, and (4) SERVER superglobal arrays.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/458076/100/0/threaded">20070125 Aztek Forum 4.1 Multiple Vulnerabilities Exploit</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/458123/100/0/threaded">20070125 Re: Aztek Forum 4.1 Multiple Vulnerabilities Exploit</ref><ref source="" url="http://acid-root.new.fr/poc/21070125.txt"></ref></refs><vuln_soft><prod name="Aztek Forum" vendor="Aztek Forum"><vers num="4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-01-31" name="CVE-2007-0600" published="2007-01-30" seq="2007-0600" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in news_page.asp in Martyn Kilbryde Newsposter Script (aka makit news/blog poster) 3 and earlier allows remote attackers to execute arbitrary SQL commands via the uid parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/458063/100/0/threaded">20070125 makit news/blog poster &lt;=v3(news_page.asp) Remote SQL Injection Vulnerability</ref><ref source="" url="http://www.milw0rm.com/exploits/3194"></ref><ref source="BID" url="http://www.securityfocus.com/bid/22230">22230</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31747">newsposter-newspage-sql-injection(31747)</ref><ref source="MILW0RM" url="http://milw0rm.com/exploits/3194">
3194</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2208">2208</ref></refs><vuln_soft><prod name="Newsposter Script" vendor="Martyn Kilbryde"><vers num="3" prev="1"/></prod><prod name="Newsposter Script" vendor="Makit"><vers num="0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-01-31" name="CVE-2007-0601" published="2007-01-30" seq="2007-0601" severity="High" type="CVE"><desc><descript source="cve">common/safety.php in Aztek Forum 4.00 allows remote attackers to enter certain data containing %22 sequences (URL encoded double quotes) and other potentially dangerous manipulations by sending a cookie, which bypasses the blacklist matching against the GET and PUT superglobal arrays.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/458076/100/0/threaded">20070125 Aztek Forum 4.1 Multiple Vulnerabilities Exploit</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/458123/100/0/threaded">20070125 Re: Aztek Forum 4.1 Multiple Vulnerabilities Exploit</ref><ref source="" url="http://acid-root.new.fr/poc/21070125.txt"></ref></refs><vuln_soft><prod name="Aztek Forum" vendor="Aztek Forum"><vers num="4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="6.9" CVSS_exploit_subscore="3.4" CVSS_impact_subscore="10.0" CVSS_score="6.9" CVSS_vector="(AV:L/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-01-31" name="CVE-2007-0602" published="2007-01-30" seq="2007-0602" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in libvsapi.so in the VSAPI library in Trend Micro VirusWall 3.81 for Linux, as used by IScan.BASE/vscan, allows local users to gain privileges via a long command line argument, a different vulnerability than CVE-2005-0533.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" other="1" user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/458111/100/0/threaded">20070125 Buffer overflow in VSAPI library of Trend Micro VirusWall 3.81 for Linux</ref><ref source="" url="http://www.devtarget.org/tmvwall381v3_exp.c"></ref><ref adv="1" source="" url="http://www.devtarget.org/trendmicro-advisory-01-2007.txt"></ref><ref patch="1" source="" url="http://esupport.trendmicro.com/support/viewxml.do?ContentID=EN-1034124&amp;id=EN-1034124"></ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0367">
ADV-2007-0367</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1017562">
1017562</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2204">2204</ref></refs><vuln_soft><prod name="VirusWall" vendor="Trend Micro"><vers num="3.81"/></prod></vuln_soft></entry><entry CVSS_base_score="7.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.1" CVSS_vector="(AV:N/AC:H/Au:S/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-02-02" name="CVE-2007-0603" published="2007-01-30" seq="2007-0603" severity="High" type="CVE"><desc><descript source="cve">PGP Desktop before 9.5.1 does not validate data objects received over the (1) \pipe\pgpserv named pipe for PGPServ.exe or the (2) \pipe\pgpsdkserv named pipe for PGPsdkServ.exe, which allows remote authenticated users to gain privileges by sending a data object representing an absolute pointer, which causes code execution at the corresponding address.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input/><design/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/458137/100/0/threaded">20070125 Medium Risk Vulnerability in PGP Desktop</ref><ref adv="1" source="" url="http://www.ngssoftware.com/advisories/medium-risk-vulnerability-in-pgp-desktop/"></ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/23938">23938</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/102465">
VU#102465</ref><ref source="BID" url="http://www.securityfocus.com/bid/22247">
22247</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0356">
ADV-2007-0356</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1017563">
1017563</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2203">2203</ref></refs><vuln_soft><prod name="PGP Corporate Desktop" vendor="PGP"><vers num="9.5"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-01-31" name="CVE-2007-0604" published="2007-01-30" seq="2007-0604" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in Movable Type (MT) before 3.34 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors related to the MTCommentPreviewIsStatic tag, which can open the &quot;comment entry screen,&quot; a different vulnerability than CVE-2007-0231.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs><ref source="" url="http://www.sixapart.com/movabletype/beta/distros/MT-3.34-beta-Release-Notes.html"></ref></refs><vuln_soft><prod name="Movable Type" vendor="Six Apart Ltd"><vers num="3.33" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" modified="2007-06-20" name="CVE-2007-0605" published="2007-05-09" seq="2007-0605" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in picture.php in Advanced Guestbook 2.4.2 allows remote attackers to inject arbitrary web script or HTML via the picture parameter.</descript></desc><impacts><impact source="nvd">Successful exploitation requires that &quot;register_globals&quot; is enabled.</impact></impacts><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/467937/100/0/threaded">20070507 Advanced Guestbook version 2.4.2 Multiple XSS Attack Vulnerabilities</ref><ref adv="1" source="" url="http://www.netvigilance.com/advisory0012"></ref><ref source="BID" url="http://www.securityfocus.com/bid/23873">23873</ref><ref source="OSVDB" url="http://www.osvdb.org/33877">33877</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1726">ADV-2007-1726</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/25153">25153</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/34156">advanced-picture-index-xss(34156)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2663">2663</ref></refs><vuln_soft><prod name="Advanced Guestbook" vendor="Advanced Guestbook"><vers num="2.4.2"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0" modified="2007-03-22" name="CVE-2007-0606" published="2007-03-21" seq="2007-0606" severity="Medium" type="CVE"><desc><descript source="cve">w-agora 4.2.1 allows remote attackers to obtain sensitive information by via the (1) bn[] array parameter to index.php, which expects a string, and (2) certain parameters to delete_forum.php, which displays the path name in the resulting error message.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/463213/100/0/threaded">20070319 w-agora version 4.2.1 Multiple Path Disclosure Vulnerabilities</ref><ref adv="1" source="" url="http://www.netvigilance.com/advisory0014"></ref><ref source="OSVDB" url="http://www.osvdb.org/31668">31668</ref><ref source="OSVDB" url="http://www.osvdb.org/31669">31669</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33076">wagora-deleteforumindex-path-disclosure(33076)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2461">2461</ref></refs><vuln_soft><prod name="W-Agora" vendor="W-Agora"><vers num="4.2.1"/><vers num="4.2.1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)" CVSS_version="2.0" modified="2007-03-21" name="CVE-2007-0607" published="2007-03-20" seq="2007-0607" severity="Medium" type="CVE"><desc><descript source="cve">W-Agora (Web-Agora) 4.2.1, when register_globals is enabled, stores globals.inc under the web document root with insufficient access control, which allows remote attackers to obtain application path information via a direct request.</descript></desc><loss_types><conf/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/463215/100/0/threaded">20070319 w-agora version 4.2.1 Information Disclosure Vulnerability</ref><ref adv="1" source="" url="http://www.netvigilance.com/advisory0015"></ref><ref source="OSVDB" url="http://www.osvdb.org/31670">31670</ref><ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2007-March/053054.html">
20070319 w-agora version 4.2.1 Information Disclosure Vulnerability</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33073">
wagora-globals-information-disclosure(33073)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2465">2465</ref></refs><vuln_soft><prod name="W-Agora" vendor="W-Agora"><vers num="4.2.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.1" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.9" CVSS_score="7.1" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:N/A:N)" CVSS_version="2.0" modified="2007-06-20" name="CVE-2007-0608" published="2007-05-09" seq="2007-0608" severity="High" type="CVE"><desc><descript source="cve">Advanced Guestbook 2.4.2 allows remote attackers to obtain sensitive information via an invalid (1) GB_TBL parameter to (a) lang/codes-english.php or (b) image.php, which reveal the database name; (2) an invalid GB_DB parameter to index.php, coupled with a ../index lang cookie, which reveals the installation path; or (3) a direct request to index.php with no parameters or cookies, which reveals the installation path.</descript></desc><impacts><impact source="nvd">Successful exploitation requires that &quot;register_globals&quot; is enabled.</impact></impacts><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/467940/100/0/threaded">20070507 Advanced Guestbook version 2.4.2 Multiple Error Information Leak Vulnerabilities</ref><ref adv="1" source="" url="http://www.netvigilance.com/advisory0011"></ref><ref source="OSVDB" url="http://www.osvdb.org/33876">33876</ref><ref source="OSVDB" url="http://www.osvdb.org/33878">33878</ref><ref source="OSVDB" url="http://www.osvdb.org/33879">33879</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1726">ADV-2007-1726</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/25153">25153</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/34161">advanced-multiple-script-info-disclosure(34161)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2661">2661</ref></refs><vuln_soft><prod name="Advanced Guestbook" vendor="Advanced Guestbook"><vers num="2.4.2"/></prod></vuln_soft></entry><entry CVSS_base_score="5.1" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="6.4" CVSS_score="5.1" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-06-19" name="CVE-2007-0609" published="2007-05-09" seq="2007-0609" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in Advanced Guestbook 2.4.2 allows remote attackers to bypass .htaccess settings, and execute arbitrary PHP local files or read arbitrary local templates, via a .. (dot dot) in a lang cookie, followed by a filename without its .php extension, as demonstrated via a request to index.php.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/467941/100/0/threaded">20070507 Advanced Guestbook version 2.4.2 Directory Traversal Vulnerability</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/467937/100/0/threaded">20070507 Advanced Guestbook version 2.4.2 Multiple XSS Attack Vulnerabilities</ref><ref adv="1" source="" url="http://www.netvigilance.com/advisory0012"></ref><ref adv="1" source="" url="http://www.netvigilance.com/advisory0013"></ref><ref source="BID" url="http://www.securityfocus.com/bid/23876">23876</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1726">ADV-2007-1726</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/25153">25153</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/34152">advanced-index-directory-traversal(34152)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2662">2662</ref></refs><vuln_soft><prod name="Advanced Guestbook" vendor="Advanced Guestbook"><vers num="2.4.2"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-01-31" name="CVE-2007-0610" published="2007-01-30" seq="2007-0610" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in the mailform feature in CMSimple 2.7 fix1 allows remote attackers to inject arbitrary web script or HTML via the sender parameter.  NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/23951">23951</ref><ref source="BID" url="http://www.securityfocus.com/bid/22250">

22250</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31841">
cmsimple-sender-xss(31841)</ref></refs><vuln_soft><prod name="CMSimple" vendor="CMSimple"><vers num="2.7 fix1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-01-31" name="CVE-2007-0611" published="2007-01-30" seq="2007-0611" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Free LAN In(tra|ter)net Portal (FLIP) before 1.0-RC2 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors in (1) inc.page.php and (2) inc.text.php.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs><ref source="" url="http://sourceforge.net/project/shownotes.php?release_id=480714&amp;group_id=98260"></ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0360">ADV-2007-0360</ref></refs><vuln_soft><prod name="Free LAN Intra_Internet Portal" vendor="Free LAN Intra_Internet Portal"><vers num="1.0 RC1" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.8" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.9" CVSS_score="7.8" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_version="2.0" modified="2007-01-31" name="CVE-2007-0612" published="2007-01-31" seq="2007-0612" severity="High" type="CVE"><desc><descript source="cve">Multiple ActiveX controls in Microsoft Windows 2000, XP, 2003, and Vista allows remote attackers to cause a denial of service (Internet Explorer crash) by accessing the bgColor, fgColor, linkColor, alinkColor, vlinkColor, or defaultCharset properties in the (1) giffile, (2) htmlfile, (3) jpegfile, (4) mhtmlfile, (5) ODCfile, (6) pjpegfile, (7) pngfile, (8) xbmfile, (9) xmlfile, (10) xslfile, or (11) wdfile objects in (a) mshtml.dll; or the (12) TriEditDocument.TriEditDocument or (13) TriEditDocument.TriEditDocument.1 objects in (b) triedit.dll, which cause a NULL pointer dereference.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/458443/100/0/threaded">20070129 Internet Explorer 7 ActiveX bgColor property NULL pointer dereference (DoS)</ref><ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2007-January/052057.html">20070129 Internet Explorer 7 ActiveX bgColor property NULL pointer dereference (DoS)</ref><ref source="" url="http://www.determina.com/security.research/vulnerabilities/activex-bgcolor.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/22288">22288</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31867">ie-activex-bgcolor-dos(31867)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2199">2199</ref></refs><vuln_soft><prod name="Internet Explorer" vendor="Microsoft"><vers num="6.0 SP1"/><vers num="6.0"/><vers num="5.5"/><vers num="5.0.1 SP4"/><vers num="5.0.1 SP1"/><vers num="5.0.1"/><vers num="5.0 ta3"/><vers num="7.0 Beta2"/><vers num="7.0 Beta1"/><vers edition="Vista" num="7.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0" modified="2007-02-02" name="CVE-2007-0613" published="2007-01-31" seq="2007-0613" severity="Medium" type="CVE"><desc><descript source="cve">The Bonjour functionality in mDNSResponder, iChat 3.1.6, and InstantMessage framework 428 in Apple Mac OS X 10.4.8 does not check for duplicate entries when adding newly discovered available contacts, which allows remote attackers to cause a denial of service (disrupted communication) via a flood of duplicate _presence._tcp mDNS queries.</descript></desc><loss_types><avail/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="" url="http://projects.info-pull.com/moab/MOAB-29-01-2007.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/22304">22304</ref><ref source="OSVDB" url="http://www.osvdb.org/32699">
32699</ref><ref source="OSVDB" url="http://www.osvdb.org/32698">32698</ref></refs><vuln_soft><prod name="InstantMessage framework" vendor="Apple"><vers num="428"/></prod><prod name="mDNSResponder" vendor="Apple"><vers num=""/></prod><prod name="iChat" vendor="Apple"><vers num="3.1.6"/></prod></vuln_soft></entry><entry CVSS_base_score="7.8" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.9" CVSS_score="7.8" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_version="2.0" modified="2007-01-31" name="CVE-2007-0614" published="2007-01-31" seq="2007-0614" severity="High" type="CVE"><desc><descript source="cve">The Bonjour functionality in mDNSResponder, iChat 3.1.6, and InstantMessage framework 428 in Apple Mac OS X 10.4.8 allows remote attackers to cause a denial of service (persistent application crash) via a crafted phsh hash attribute in a TXT key.</descript></desc><loss_types><avail/></loss_types><range><network/></range><refs><ref source="" url="http://projects.info-pull.com/moab/MOAB-29-01-2007.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/22304">22304</ref><ref source="" url="http://docs.info.apple.com/article.html?artnum=305102"></ref><ref source="APPLE" url="http://lists.apple.com/archives/Security-announce/2007/Feb/msg00000.html">
APPLE-SA-2007-02-15</ref><ref source="OSVDB" url="http://www.osvdb.org/32713">
32713</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017661">
1017661</ref><ref source="SECUNIA" url="http://secunia.com/advisories/23945">
23945</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24198">
24198</ref></refs><vuln_soft><prod name="Mac OS X" vendor="Apple"><vers num="10.4.8"/></prod><prod name="InstantMessage framework" vendor="Apple"><vers num="428"/></prod><prod name="iChat" vendor="Apple"><vers num="3.1.6"/></prod></vuln_soft></entry><entry CVSS_base_score="7.8" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.9" CVSS_score="7.8" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_version="2.0" modified="2007-01-31" name="CVE-2007-0615" published="2007-01-31" seq="2007-0615" severity="High" type="CVE"><desc><descript source="cve">Unspecified vulnerability in Hitachi JP1/HIBUN Advanced Edition Management Server and Log Server before 20070124 allows remote attackers to cause a denial of service (application stop) via unexpected data.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref source="" url="http://www.hitachi-support.com/security_e/vuls_e/HS06-019_e/01-e.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/22237">22237</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0324">ADV-2007-0324</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/23854">23854</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31733">hitachi-jp1-hibun-request-dos(31733)</ref></refs><vuln_soft><prod name="JPI HIBUN Advanced Edition Server" vendor="Hitachi"><vers num="R_1543H_11"/></prod><prod name="HIBUN Advanced Edition Server" vendor="Hitachi"><vers num="R-1V13-06W001F1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.8" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.9" CVSS_score="7.8" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:N/A:N)" CVSS_version="2.0" modified="2007-01-31" name="CVE-2007-0616" published="2007-01-31" seq="2007-0616" severity="High" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in zen/template-functions.php in zenphoto 1.0.4 up to 1.0.6 allows remote attackers to list arbitrary directories via &quot;..&quot; sequences in the album parameter to index.php.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://www.zenphoto.org/support/topic.php?id=1146&amp;replies=3"></ref><ref source="" url="http://www.zenphoto.org/support/topic.php?id=1148"></ref><ref source="BID" url="http://www.securityfocus.com/bid/22368">
22368</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0470">
ADV-2007-0470</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24026">
24026</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32102">
zenphoto-template-directory-traversal(32102)</ref></refs><vuln_soft><prod name="zenphoto" vendor="Zenphoto"><vers num="1.0.4"/><vers num="1.0.5"/><vers num="1.0.6"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-01-31" name="CVE-2007-0617" published="2007-01-31" seq="2007-0617" severity="Medium" type="CVE"><desc><descript source="cve">The SpamBlocker.dll ActiveX control in Earthlink TotalAccess is marked &quot;safe for scripting,&quot; which allows remote attackers to add arbitrary e-mail addresses and domains to the spam blocker whitelist via the (1) AddSenderToWhitelist and (2) AddDomainToWhitelist functions.</descript></desc><impacts><impact source="nvd">Medium complexity because phishing attack</impact></impacts><loss_types><avail/><conf/><int/></loss_types><vuln_types><access/></vuln_types><range><network/><user_init/></range><refs><ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2007-January/052021.html">20070125 Earthlink TotalAccess ActiveX Unsafe Methods Vulnerability</ref><ref source="BID" url="http://www.securityfocus.com/bid/22238">22238</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31827">earthlink-spamblocker-security-bypass(31827)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2210">2210</ref></refs><vuln_soft><prod name="Total Access" vendor="Earthlink"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-01-31" name="CVE-2007-0618" published="2007-01-31" seq="2007-0618" severity="High" type="CVE"><desc><descript source="cve">Unspecified vulnerability in (1) pop3d, (2) pop3ds, (3) imapd, and (4) imapds in IBM AIX 5.3.0 has unspecified impact and attack vectors, involving an &quot;authentication vulnerability.&quot;</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref source="AIXAPAR" url="http://www-1.ibm.com/support/search.wss?rs=0&amp;q=IY93084&amp;apar=only">IY93084</ref><ref source="" url="ftp://aix.software.ibm.com/aix/efixes/security/README"></ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/22262">22262</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0382">ADV-2007-0382</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/23957">23957</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31875">
aix-mailservices-rlogin-security-bypass(31875)</ref></refs><vuln_soft><prod name="AIX" vendor="IBM"><vers num="5.3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" CVSS_score="9.3" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-02-06" name="CVE-2007-0619" published="2007-01-31" seq="2007-0619" severity="High" type="CVE"><desc><descript source="cve">chmlib before 0.39 allows user-assisted remote attackers to execute arbitrary code via a crafted page block length in a CHM file, which triggers memory corruption.</descript></desc><sols><sol source="nvd">Update to version 0.39.</sol></sols><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/><user_init/></range><refs><ref source="IDEFENSE" url="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=468">20070126 Multiple Vendor libchm Page Block Length Memory Corruption Vulnerability</ref><ref patch="1" source="" url="http://morte.jedrea.com/~jedwin/projects/chmlib/"></ref><ref source="SECTRACK" url="http://securitytracker.com/id?1017565">1017565</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/23975">23975</ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200702-12.xml">
GLSA-200702-12</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2007_3_sr.html">
SUSE-SR:2007:003</ref><ref source="BID" url="http://www.securityfocus.com/bid/22258">
22258</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24335">
24335</ref></refs><vuln_soft><prod name="chmlib" vendor="chmlib"><vers num="0.38" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0" modified="2007-02-06" name="CVE-2007-0620" published="2007-01-31" seq="2007-0620" severity="Medium" type="CVE"><desc><descript source="cve">download.php in FD Script 1.3.2 and earlier allows remote attackers to read source of files under the web document root with certain extensions, including .php, via a relative pathname in the fname parameter, as demonstrated by downloading config.php.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/458231/100/0/threaded">20070126 FdScript &lt;= v1.3.2 Remote File Disclosure Vulnerability</ref><ref source="BID" url="http://www.securityfocus.com/bid/22265">22265</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0383">ADV-2007-0383</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/23947">23947</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31915">
fdscript-download-file-disclosure(31915)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2197">2197</ref></refs><vuln_soft><prod name="FD Script" vendor="Vlad Leont"><vers num="1.3.2"/><vers num="1.3.1"/><vers num="1.3"/></prod></vuln_soft></entry><entry modified="2007-03-30" name="CVE-2007-0621" published="2007-01-31" reject="1" seq="2007-0621" type="CVE"><desc><descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2006-6456.  Reason: This candidate is a duplicate of CVE-2006-6456.  It was assigned for a targeted zero-day attack, but further analysis revealed it was for an older issue.  Notes: All CVE users should reference CVE-2006-6456 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs/></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" modified="2007-02-06" name="CVE-2007-0622" published="2007-01-31" seq="2007-0622" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site request forgery (CSRF) vulnerability in MyBB (aka MyBulletinBoard) 1.2.2 allows remote attackers to send messages to arbitrary users.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript></desc><loss_types><int/></loss_types><range><network/></range><refs><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/23934">23934</ref></refs><vuln_soft><prod name="MyBB" vendor="MyBB"><vers num="1.2.2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-02-06" name="CVE-2007-0623" published="2007-01-31" seq="2007-0623" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in index.php in MAXdev MDPro 1.0.76 allows remote attackers to execute arbitrary SQL commands via the startrow parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/458438/100/0/threaded">20070129 MDPro 1.0.76 - Multiple Remote Vulnerabilities</ref><ref source="BID" url="http://www.securityfocus.com/bid/22293">22293</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/23948">23948</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0412">
ADV-2007-0412</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31897">
mdpro-startrow-sql-injection(31897)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2198">2198</ref></refs><vuln_soft><prod name="MDPro" vendor="MAXdev"><vers num="1.0.76"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0" modified="2007-02-06" name="CVE-2007-0624" published="2007-01-31" seq="2007-0624" severity="Medium" type="CVE"><desc><descript source="cve">user.php in MAXdev MDPro 1.0.76 allows remote attackers to obtain the full path via a &apos; (quote) character, and possibly other invalid values, in the uname parameter in a userinfo operation.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/458438/100/0/threaded">20070129 MDPro 1.0.76 - Multiple Remote Vulnerabilities</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31898">
mdpro-user-path-disclosure(31898)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2198">2198</ref></refs><vuln_soft><prod name="MDPro" vendor="MAXdev"><vers num="1.0.76"/></prod></vuln_soft></entry><entry CVSS_base_score="4.9" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.9" CVSS_score="4.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:C)" CVSS_version="2.0" modified="2007-02-05" name="CVE-2007-0625" published="2007-01-31" seq="2007-0625" severity="Medium" type="CVE"><desc><descript source="cve">nxconfigure.sh in NoMachine NX Server before 2.1.0-18 does not validate the invoking user, which allows local users to modify server configuration keys in /usr/NX/etc/server.cfg, resulting in an unspecified denial of service.</descript></desc><loss_types><avail/></loss_types><vuln_types><access/><design/></vuln_types><range><local/></range><refs><ref patch="1" source="" url="http://www.nomachine.com/news_read.php?idnews=190"></ref><ref source="" url="http://www.nomachine.com/tr/view.php?id=TR01E01622"></ref><ref source="BID" url="http://www.securityfocus.com/bid/22308">22308</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0413">ADV-2007-0413</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/23993">23993</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31941">
nxserver-nxconfigure-dos(31941)</ref></refs><vuln_soft><prod name="NX Server" vendor="NoMachine"><vers num="2.1.0_17" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.1" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="6.4" CVSS_score="5.1" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-08-06" name="CVE-2007-0626" published="2007-01-31" seq="2007-0626" severity="Medium" type="CVE"><desc><descript source="cve">The comment_form_add_preview function in comment.module in Drupal before 4.7.6, and 5.x before 5.1, and vbDrupal, allows remote attackers with &quot;post comments&quot; privileges and access to multiple input filters to execute arbitrary code by previewing comments, which are not processed by &quot;normal form validation routines.&quot;</descript></desc><sols><sol source="nvd">Successful exploitation requires &quot;post comments&quot; privileges and access to multiple input filters (not the default). </sol></sols><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="DRUPAL" url="http://drupal.org/node/113935">DRUPAL-SA-2007-005 </ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0406">ADV-2007-0406</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/23960">23960</ref><ref source="" url="http://www.vbdrupal.org/forum/showthread.php?t=786"></ref><ref source="BID" url="http://www.securityfocus.com/bid/22306">22306</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0415">ADV-2007-0415</ref><ref source="SECUNIA" url="http://secunia.com/advisories/23990">23990</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31940">drupal-commentformaddpreview-code-execution(31940)</ref></refs><vuln_soft><prod name="Drupal" vendor="Drupal"><vers num="4.7.5" prev="1"/><vers num="5.0" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.9" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.9" CVSS_score="4.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:N/A:N)" CVSS_version="2.0" modified="2007-02-02" name="CVE-2007-0627" published="2007-01-31" seq="2007-0627" severity="Medium" type="CVE"><desc><descript source="cve">Michael Still gtalkbot before 1.2 places username and password arguments on the command line, which allows local users to obtain sensitive information by listing the process.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref source="" url="http://freshmeat.net/projects/gtalkbot/?branch_id=67830&amp;release_id=245004"></ref><ref source="" url="http://www.stillhq.com/gtalkbot/"></ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0408">ADV-2007-0408</ref><ref source="BID" url="http://www.securityfocus.com/bid/22322">
22322</ref><ref source="SECUNIA" url="http://secunia.com/advisories/23942">
23942</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31923">
gtalkbot-ps-information-disclosure(31923)</ref></refs><vuln_soft><prod name="gtalkbot" vendor="Michael Still"><vers num="1.1" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" modified="2007-08-06" name="CVE-2007-0628" published="2007-01-31" seq="2007-0628" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Sun Java System Access Manager 6.1, 6.2, 6 2005Q1 (6.3), and 7 2005Q4 (7.0) before 20070129 allow remote attackers to inject arbitrary web script or HTML via the (1) goto or (2) gx-charset parameter. NOTE: some of these details are obtained from third party information.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102621-1">102621</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/22302">22302</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0411">ADV-2007-0411</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/23979">23979</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1017570">1017570</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31936">javaaccessserver-unspecified-xss(31936)</ref></refs><vuln_soft><prod name="Java System Access Manager" vendor="Sun"><vers num="6.1"/><vers num="6.2"/><vers num="6.3"/><vers num="7.0"/></prod></vuln_soft></entry><entry CVSS_base_score="6.4" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="4.9" CVSS_score="6.4" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:P)" CVSS_version="2.0" modified="2007-02-02" name="CVE-2007-0629" published="2007-01-31" seq="2007-0629" severity="Medium" type="CVE"><desc><descript source="cve">The www_purgeList method in Plain Black WebGUI before 7.3.8 does not properly check user permissions, which allows attackers to delete unauthorized assets.  NOTE: some of these details are obtained from third party information.</descript></desc><loss_types><avail/><int/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref patch="1" source="" url="http://sourceforge.net/project/shownotes.php?group_id=51417&amp;release_id=481584"></ref><ref adv="1" patch="1" source="" url="http://www.plainblack.com/getwebgui/advisories/security-defect-discovered-in-7.x-versions"></ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/22294">22294</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/23981">23981</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31905">
webgui-wwwpurgelist-data-manipulation(31905)</ref></refs><vuln_soft><prod name="WebGUI" vendor="Plain Black"><vers num="7.3.8"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-02-02" name="CVE-2007-0630" published="2007-01-31" seq="2007-0630" severity="High" type="CVE"><desc><descript source="cve">Multiple SQL injection vulnerabilities in the generate_csv function in classes/class.news.php in X-dev xNews 1.3 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) id, (2) from, and (3) q parameters, different vectors than CVE-2007-0569.  NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0395">ADV-2007-0395</ref></refs><vuln_soft><prod name="xNews" vendor="X-dev"><vers num="1.3" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-02-02" name="CVE-2007-0631" published="2007-01-31" seq="2007-0631" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in index.php in Eclectic Designs CascadianFAQ 4.1 and earlier allows remote attackers to execute arbitrary SQL commands via the catid parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="Milw0rm" url="http://www.milw0rm.com/exploits/3227">Exploit 3227</ref><ref source="BID" url="http://www.securityfocus.com/bid/22314">22314</ref><ref source="MILW0RM" url="http://milw0rm.com/exploits/3227">

3227</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0424">
ADV-2007-0424</ref><ref source="OSVDB" url="http://www.osvdb.org/31675">
31675</ref><ref source="SECUNIA" url="http://secunia.com/advisories/23965">
23965</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31968">
cascadianfaq-index-sql-injection(31968)</ref></refs><vuln_soft><prod name="CascadianFAQ" vendor="Eclectic Designs"><vers num="4.1" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-02-02" name="CVE-2007-0632" published="2007-01-31" seq="2007-0632" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in artreplydelete.asp in ASP EDGE 1.3a and earlier allows remote attackers to execute arbitrary SQL commands via a username cookie, a different vector than CVE-2007-0560.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0341">ADV-2007-0341</ref></refs><vuln_soft><prod name="ASP EDGE" vendor="ASP EDGE"><vers num="1.3a" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-02-02" name="CVE-2007-0633" published="2007-01-31" seq="2007-0633" severity="High" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in include/themes/themefunc.php in MyNews 4.2.2 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the myNewsConf[path][sys][index] parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://www.milw0rm.com/exploits/3228"></ref><ref source="BID" url="http://www.securityfocus.com/bid/22313">22313</ref><ref source="MILW0RM" url="http://milw0rm.com/exploits/3228">

3228</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0423">
ADV-2007-0423</ref><ref source="SECUNIA" url="http://secunia.com/advisories/23973">
23973</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31971">
mynews-themefunc-file-include(31971)</ref></refs><vuln_soft><prod name="MyNews" vendor="T-Systems Solutions for Research GmbH"><vers num="4.2.2" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.8" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.9" CVSS_score="7.8" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_version="2.0" modified="2008-01-11" name="CVE-2007-0634" published="2007-01-31" seq="2007-0634" severity="High" type="CVE"><desc><descript source="cve">Unspecified vulnerability in Sun Solaris 10 before 20070130 allows remote attackers to cause a denial of service (system crash) via certain ICMP packets.</descript></desc><loss_types><avail/></loss_types><range><network/></range><refs><ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102697-1">102697</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/967236">VU#967236</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/22323">22323</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0420">ADV-2007-0420</ref><ref patch="1" source="SECTRACK" url="http://securitytracker.com/id?1017574">1017574</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/23982">23982</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32010">solaris-icmp-dos(32010)</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1249">oval:org.mitre.oval:def:1249</ref></refs><vuln_soft><prod name="Solaris" vendor="Sun"><vers edition="SPARC" num="10.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-02-02" name="CVE-2007-0635" published="2007-01-31" seq="2007-0635" severity="High" type="CVE"><desc><descript source="cve">Multiple PHP remote file inclusion vulnerabilities in EncapsCMS 0.3.6 allow remote attackers to execute arbitrary PHP code via a URL in the (1) config[path] parameter to (a) common_foot.php or (b) blogs.php, or (2) the config[theme] parameter to (c) admin/gallery_head.php.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/458582/100/0/threaded">20070130 EncapsCMS 0.3.6 (common_foot.php) Remote File Include</ref><ref source="BID" url="http://www.securityfocus.com/bid/22319">22319</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31978">encapsms-config-file-include(31978)</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0430">
ADV-2007-0430</ref><ref source="SECUNIA" url="http://secunia.com/advisories/23987">
23987</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2200">2200</ref></refs><vuln_soft><prod name="EncapsCMS" vendor="EncapsCMS"><vers num="0.3.6"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0" modified="2007-02-02" name="CVE-2007-0636" published="2007-01-31" seq="2007-0636" severity="Low" type="CVE"><desc><descript source="cve">Unspecified vulnerability in inotify before 0.3.5 has unknown impact and attack vectors, related to &quot;access rights to watched files.&quot;</descript></desc><loss_types><conf/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref source="" url="http://inotify.aiken.cz/?section=incron&amp;page=changelog"></ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/22305">22305</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0405">ADV-2007-0405</ref></refs><vuln_soft><prod name="Incron" vendor="Inotify"><vers num="0.3.4"/><vers num="0.3.3"/><vers num="0.3.2"/><vers num="0.3.1"/><vers num="0.3"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-02-02" name="CVE-2007-0637" published="2007-01-31" seq="2007-0637" severity="High" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in zd_numer.php in Galeria Zdjec 3.0 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the galeria parameter, as demonstrated by injecting PHP sequences into an Apache HTTP Server log file, which is then included by zd_numer.php.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://www.milw0rm.com/exploits/3225"></ref><ref source="BID" url="http://www.securityfocus.com/bid/22324">22324</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31967">galeria-zdnumer-file-include(31967)</ref><ref source="MILW0RM" url="http://milw0rm.com/exploits/3225">

3225</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0425">
ADV-2007-0425</ref><ref source="SECUNIA" url="http://secunia.com/advisories/23956">
23956</ref></refs><vuln_soft><prod name="Galeria Zdjec" vendor="Galeria Zdjec"><vers num="3.0" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0" modified="2007-02-02" name="CVE-2007-0638" published="2007-01-31" seq="2007-0638" severity="Medium" type="CVE"><desc><descript source="cve">show.php in Vlad Alexa Mancini PHPFootball 1.6 allows remote attackers to obtain sensitive information (database contents) via a % (percent) character in the dbfieldv parameter.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://www.milw0rm.com/exploits/3226"></ref><ref source="BID" url="http://www.securityfocus.com/bid/22312">22312</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31976">phpfootball-show-information-disclosure(31976)</ref><ref source="MILW0RM" url="http://milw0rm.com/exploits/3226">

3226</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0429">
ADV-2007-0429</ref><ref source="SECUNIA" url="http://secunia.com/advisories/23962">
23962</ref></refs><vuln_soft><prod name="PHPFootball" vendor="Vlad Alexa Mancini"><vers num="1.6"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-02-02" name="CVE-2007-0639" published="2007-01-31" seq="2007-0639" severity="High" type="CVE"><desc><descript source="cve">Multiple static code injection vulnerabilities in error.php in GuppY 4.5.16 and earlier allow remote attackers to inject arbitrary PHP code into a .inc file in the data/ directory via (1) a REMOTE_ADDR cookie or (2) a cookie specifying an element of the msg array with an error number in the first dimension and 0 in the second dimension, as demonstrated by msg[999][0].</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://retrogod.altervista.org/guppy_4516_cmd.html"></ref><ref source="" url="http://www.milw0rm.com/exploits/3221"></ref><ref source="SECTRACK" url="http://securitytracker.com/id?1017569">1017569</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/23914">23914</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31882">guppy-mdp-command-execution(31882)</ref><ref source="MILW0RM" url="http://milw0rm.com/exploits/3221">
3221</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0421">
ADV-2007-0421</ref></refs><vuln_soft><prod name="GuppY" vendor="GuppY"><vers num="4.5.16" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-02-02" name="CVE-2007-0640" published="2007-01-31" seq="2007-0640" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in ZABBIX before 1.1.5 has unknown impact and attack vectors related to &quot;SNMP IP addresses.&quot;</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref patch="1" source="" url="http://www.zabbix.com/rn1.1.5.php"></ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/22321">22321</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0416">ADV-2007-0416</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24020">
24020</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32038">
zabbix-snmp-bo(32038)</ref></refs><vuln_soft><prod name="ZABBIX" vendor="ZABBIX"><vers num="1.1.4" prev="1"/><vers num="1.1.3"/><vers num="1.1.2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-02-02" name="CVE-2007-0641" published="2007-01-31" seq="2007-0641" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in the EnumPrintersA function in dapcnfsd.dll 0.6.4.0 in Shaffer Solutions (SSC) DiskAccess NFS Client allows remote attackers to execute arbitrary code via a long argument, an issue similar to CVE-2006-5854 and CVE-2007-0444.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref source="" url="http://www.securityfocus.com/data/vulnerabilities/exploits/testlpc.c"></ref><ref source="BID" url="http://www.securityfocus.com/bid/22301">22301</ref></refs><vuln_soft><prod name="dapcnfsd.dll" vendor="Shaffer Solutions Corp"><vers num="0.6.4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2008-01-02" name="CVE-2007-0642" published="2007-01-31" seq="2007-0642" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in tForum 2.00 in the Raymond BERTHOU script collection (aka RBL - ASP) allows remote attackers to execute arbitrary SQL commands via the (1) id and (2) pass to user_confirm.asp.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/458495/100/0/threaded">20070127 RBL - ASP (scripts with db) SQL injection</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/458560/100/0/threaded">20070129 RBL - ASP (scripts with db) SQL injection</ref><ref source="" url="http://forums.avenir-geopolitique.net/viewtopic.php?t=2607"></ref><ref source="VIM" url="http://www.attrition.org/pipermail/vim/2007-January/001259.html">20070131 Partial source code verify - </ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/31927">rbl-userpass-sql-injection(31927)</ref><ref source="BID" url="http://www.securityfocus.com/bid/22350">22350</ref><ref source="OSVDB" url="http://www.osvdb.org/36040">36040</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2201">2201</ref></refs><vuln_soft><prod name="tForum" vendor="RBL"><vers num="2.00"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:P)" CVSS_version="2.0" modified="2007-02-02" name="CVE-2007-0643" published="2007-01-31" seq="2007-0643" severity="Medium" type="CVE"><desc><descript source="cve">Stack-based buffer overflow in Bloodshed Dev-C++ 4.9.9.2 allows user-assisted remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a long line in a .cpp file.</descript></desc><loss_types><avail/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/><user_init/></range><refs><ref source="" url="http://www.milw0rm.com/exploits/3229"></ref><ref source="BID" url="http://www.securityfocus.com/bid/22315">22315</ref><ref source="MILW0RM" url="http://milw0rm.com/exploits/3229">

3229</ref></refs><vuln_soft><prod name="Dev-C++" vendor="Bloodshed Software"><vers num="4.9.9.2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.1" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.9" CVSS_score="7.1" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:C)" CVSS_version="2.0" modified="2007-02-02" name="CVE-2007-0644" published="2007-01-31" seq="2007-0644" severity="High" type="CVE"><desc><descript source="cve">Format string vulnerability in Apple Safari 2.0.4 (419.3) allows remote user-assisted attackers to cause a denial of service (crash) via format string specifiers in filenames that are not properly handled when calling the (1) NSLog and (2) NSBeginAlertSheet Apple AppKit functions.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/><exception/></vuln_types><range><network/><user_init/></range><refs><ref source="" url="http://www.digitalmunition.com/MOAB-30-01-2007.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/22326">
22326</ref><ref source="OSVDB" url="http://www.osvdb.org/32710">
32710</ref></refs><vuln_soft><prod name="Safari" vendor="Apple"><vers num="2.0.4_419.3"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-02-02" name="CVE-2007-0645" published="2007-01-31" seq="2007-0645" severity="Medium" type="CVE"><desc><descript source="cve">Format string vulnerability in iPhoto 6.0.5 allows remote user-assisted attackers to cause a denial of service (crash) via format string specifiers in a filename, which is not properly handled when calling certain Apple AppKit functions.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" source="" url="http://www.digitalmunition.com/MOAB-30-01-2007.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/22326">
22326</ref><ref source="" url="http://projects.info-pull.com/moab/MOAB-30-01-2007.html"></ref><ref source="OSVDB" url="http://www.osvdb.org/32711">
32711</ref></refs><vuln_soft><prod name="iPhoto" vendor="Apple"><vers num="6.0.5"/></prod></vuln_soft></entry><entry CVSS_base_score="7.1" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.9" CVSS_score="7.1" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:C)" CVSS_version="2.0" modified="2008-01-02" name="CVE-2007-0646" published="2007-01-31" seq="2007-0646" severity="High" type="CVE"><desc><descript source="cve">Format string vulnerability in iMovie HD 6.0.3, and Safari in Apple Mac OS X 10.4 through 10.4.10, allows remote user-assisted attackers to cause a denial of service (crash) via format string specifiers in a filename, which is not properly handled when calling the NSRunCriticalAlertPanel Apple AppKit function.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/><exception/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" source="" url="http://www.digitalmunition.com/MOAB-30-01-2007.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/22326">22326</ref><ref source="" url="http://docs.info.apple.com/article.html?artnum=305391"></ref><ref source="APPLE" url="http://lists.apple.com/archives/Security-announce/2007/Apr/msg00001.html">APPLE-SA-2007-04-19</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1470">ADV-2007-1470</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24966">24966</ref><ref source="" url="http://docs.info.apple.com/article.html?artnum=307041"></ref><ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2007/Nov/msg00002.html">APPLE-SA-2007-11-14</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA07-109A.html">TA07-109A</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA07-319A.html">TA07-319A</ref><ref source="BID" url="http://www.securityfocus.com/bid/26444">26444</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/3868">ADV-2007-3868</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/27643">27643</ref></refs><vuln_soft><prod name="iMovie HD" vendor="Apple"><vers num="6.0.3"/></prod><prod name="Help Viewer" vendor="Apple"><vers num="3.0.0_144.1"/></prod><prod name="Safari" vendor="Apple"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.1" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.9" CVSS_score="7.1" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:C)" CVSS_version="2.0" modified="2007-02-02" name="CVE-2007-0647" published="2007-01-31" seq="2007-0647" severity="High" type="CVE"><desc><descript source="cve">Format string vulnerability in Help Viewer 3.0.0 allows remote user-assisted attackers to cause a denial of service (crash) via format string specifiers in a filename, which is not properly handled when calling the NSBeginAlertSheet Apple AppKit function.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" source="" url="http://www.digitalmunition.com/MOAB-30-01-2007.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/22326">
22326</ref><ref source="OSVDB" url="http://www.osvdb.org/32707">
32707</ref></refs><vuln_soft><prod name="Help Viewer" vendor="Apple"><vers num="3.0.0_144.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.8" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.9" CVSS_score="7.8" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_version="2.0" modified="2007-02-02" name="CVE-2007-0648" published="2007-01-31" seq="2007-0648" severity="High" type="CVE"><desc><descript source="cve">Cisco IOS after 12.3(14)T, 12.3(8)YC1, 12.3(8)YG, and 12.4, with voice support and without Session Initiated Protocol (SIP) configured, allows remote attackers to cause a denial of service (crash) by sending a crafted packet to port 5060/UDP.</descript></desc><loss_types><avail/></loss_types><vuln_types><config/></vuln_types><range><network/></range><refs><ref adv="1" source="" url="http://www.cisco.com/warp/public/707/cisco-air-20070131-sip.shtml"></ref><ref adv="1" patch="1" source="CISCO" url="http://www.cisco.com/warp/public/707/cisco-sa-20070131-sip.shtml">20070131 SIP Packet Reloads IOS Devices Not Configured for SIP</ref><ref patch="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/438176">VU#438176</ref><ref source="BID" url="http://www.securityfocus.com/bid/22330">22330</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0428">ADV-2007-0428</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/23978">23978</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31990">cisco-sip-packet-dos(31990)</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1017575">
1017575</ref></refs><vuln_soft><prod name="IOS" vendor="Cisco"><vers num="12.4 XB"/><vers num="12.4 XA"/><vers num="12.4 T"/><vers num="12.4 MR"/><vers num="12.4 (5)"/><vers num="12.4 (4)T"/><vers num="12.4 (4)MR"/><vers num="12.4 (3b)"/><vers num="12.4 (3a)"/><vers num="12.4 (3)"/><vers num="12.4 (2)XB"/><vers num="12.4 (2)XA"/><vers num="12.4 (2)T2"/><vers num="12.4 (2)T1"/><vers num="12.4 (2)T"/><vers num="12.4 (2)MR1"/><vers num="12.4 (2)MR"/><vers num="12.4 (1c)"/><vers num="12.4 (1b)"/><vers num="12.4 (1)"/><vers num="12.4"/><vers num="12.3 YX"/><vers num="12.3 YU"/><vers num="12.3 YT"/><vers num="12.3 YQ"/><vers num="12.3 YM"/><vers num="12.3 YK"/><vers num="12.3 YG"/><vers num="12.3 (14)T5"/><vers num="12.3 (14)T4"/><vers num="12.3 (14)T2"/><vers num="12.3 (14)T"/><vers num="12.4XT"/><vers num="12.4XP"/><vers num="12.4XJ"/><vers num="12.4XG"/><vers num="12.4XE"/><vers num="12.4XD"/><vers num="12.4XC"/><vers num="12.4SW"/><vers num="12.4(9)T"/><vers num="12.4(8)"/><vers num="12.4(7a)"/><vers num="12.4(7)"/><vers num="12.4(6)T1"/><vers num="12.4(6)T"/><vers num="12.4(5b)"/><vers num="12.4(4)T2"/><vers num="12.4(4)MR"/><vers num="12.4(3d)"/><vers num="12.4(3)T2"/><vers num="12.4(2)XB2"/><vers num="12.4(2)T4"/><vers num="12.4 (2)T3"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="3.2" CVSS_impact_subscore="6.4" CVSS_score="4.3" CVSS_vector="(AV:N/AC:H/Au:M/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-08-06" name="CVE-2007-0649" published="2007-01-31" seq="2007-0649" severity="Medium" type="CVE"><desc><descript source="cve">Variable overwrite vulnerability in interface/globals.php in OpenEMR 2.8.2 and earlier allows remote attackers to overwrite arbitrary program variables and conduct other unauthorized activities, such as conduct (a) remote file inclusion attacks via the srcdir parameter in custom/import_xml.php or (b) cross-site scripting (XSS) attacks via the rootdir parameter in interface/login/login_frame.php, via vectors associated with extract operations on the (1) POST and (2) GET superglobal arrays.  NOTE: this issue was originally disputed before the extract behavior was identified in post-disclosure analysis. Also, the original report identified &quot;Open Conference Systems,&quot; but this was an error.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/458306/100/0/threaded">20070127 Open Conference Systems = 2.8.2 Remote File Inclusion</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/458426/100/0/threaded">20070127 Re: Open Conference Systems = 2.8.2 Remote File Inclusion</ref><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/458486/100/0/threaded">20070128 Re: Open Conference Systems = 2.8.2 Remote File Inclusion</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/458456/100/0/threaded">20070129 Fake: Open Conference Systems = 2.8.2 Remote File Inclusion</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/458476/100/0/threaded">20070129 Re: Fake: Open Conference Systems = 2.8.2 Remote File Inclusion</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/458565/100/0/threaded">20070130 Re: Fake: Open Conference Systems = 2.8.2 Remote File Inclusion</ref><ref adv="1" source="VIM" url="http://attrition.org/pipermail/vim/2007-January/001254.html">20070129 [still bogus] V [mike at carstein.kill-9.pl: Re: Open Conference Systems = 2.8.2 Remote File Inclusion] (fwd)</ref><ref adv="1" source="VIM" url="http://attrition.org/pipermail/vim/2007-January/001258.html">20070131 VERIFY of RFI and XSS in OpenEMR 2.8.2 (was [still bogus] V [mike at carstein.kill-9.pl: Re: Open Conference Systems = 2.8.2 Remote File Inclusion])</ref><ref source="BID" url="http://www.securityfocus.com/bid/22346">22346</ref><ref source="BID" url="http://www.securityfocus.com/bid/22348">22348</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2202">2202</ref></refs><vuln_soft><prod name="OpenEMR" vendor="OpenEMR"><vers num="2.8.2" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-08-06" name="CVE-2007-0650" published="2007-02-01" seq="2007-0650" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in the open_sty function in mkind.c for makeindex 2.14 in teTeX might allow user-assisted remote attackers to overwrite files and possibly execute arbitrary code via a long filename.  NOTE: other overflows exist but might not be exploitable, such as a heap-based overflow in the check_idx function.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/><user_init/></range><refs><ref source="" url="https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=225491"></ref><ref source="BID" url="http://www.securityfocus.com/bid/23872">23872</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1706">ADV-2007-1706</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32284">tetex-makeindex-opensty-bo(32284)</ref><ref source="" url="https://issues.rpath.com/browse/RPL-1036"></ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200709-17.xml">GLSA-200709-17</ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200711-34.xml">GLSA-200711-34</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:109">MDKSA-2007:109</ref><ref source="SECUNIA" url="http://secunia.com/advisories/26982">26982</ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200805-13.xml">GLSA-200805-13</ref><ref source="SECUNIA" url="http://secunia.com/advisories/30168">30168</ref></refs><vuln_soft><prod name="makeindex" vendor="makeindex"><vers num="2.14"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" discovered="2007-02-06" modified="2007-07-24" name="CVE-2007-0651" published="2007-02-15" seq="2007-0651" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in MailEnable Professional before 2.37 allow remote attackers to inject arbitrary Javascript script via (1) e-mail messages and (2) the ID parameter to (a) right.asp, (b) Forms/MAI/list.asp, and (c) Forms/VCF/list.asp in mewebmail/base/default/lang/EN/.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/460063/100/0/threaded">20070214 Secunia Research: MailEnable Web Mail Client MultipleVulnerabilities</ref><ref adv="1" patch="1" source="" url="http://secunia.com/secunia_research/2007-38/advisory/"></ref><ref source="" url="http://www.mailenable.com/Professional20-ReleaseNotes.txt"></ref><ref source="BID" url="http://www.securityfocus.com/bid/22554">22554</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0595">ADV-2007-0595</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/23998">23998</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32476">mailenable-email-messages-xss(32476)</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32480">mailenable-id-xss(32480)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2258">2258</ref></refs><vuln_soft><prod name="MailEnable Professional" vendor="MailEnable"><vers num="1.116"/><vers num="1.115"/><vers num="1.114"/><vers num="1.113"/><vers num="1.112"/><vers num="1.111"/><vers num="1.110"/><vers num="1.109"/><vers num="1.108"/><vers num="1.107"/><vers num="1.106"/><vers num="1.105"/><vers num="1.104"/><vers num="1.103"/><vers num="1.102"/><vers num="1.101"/><vers num="1.54"/><vers num="1.53"/><vers num="1.52"/><vers num="1.51"/><vers num="1.19"/><vers num="1.18"/><vers num="1.17"/><vers num="1.16"/><vers num="1.15"/><vers num="1.14"/><vers num="1.13"/><vers num="1.12"/><vers num="1.7"/><vers num="1.6"/><vers num="1.5"/><vers num="1.2a"/><vers num="1.2"/><vers num="1.1"/><vers num="1.0.017"/><vers num="1.0.016"/><vers num="1.0.015"/><vers num="1.0.014"/><vers num="1.0.013"/><vers num="1.0.012"/><vers num="1.0.011"/><vers num="1.0.010"/><vers num="1.0.009"/><vers num="1.0.008"/><vers num="1.0.007"/><vers num="1.0.006"/><vers num="1.0.005"/><vers num="1.0.004"/><vers num="2.351"/><vers num="2.35"/><vers num="2.34"/><vers num="2.33"/><vers num="2.32"/><vers num="2.2"/><vers num="2.1"/><vers num="2.0"/><vers num="1.84"/><vers num="1.83"/><vers num="1.82"/><vers num="1.73"/><vers num="1.72"/></prod></vuln_soft></entry><entry CVSS_base_score="5.1" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="6.4" CVSS_score="5.1" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-07-24" name="CVE-2007-0652" published="2007-02-15" seq="2007-0652" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site request forgery (CSRF) vulnerability in MailEnable Professional before 2.37 allows remote attackers to modify arbitrary configurations and perform unauthorized actions as arbitrary users via a link or IMG tag.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/460063/100/0/threaded">20070214 Secunia Research: MailEnable Web Mail Client MultipleVulnerabilities</ref><ref adv="1" patch="1" source="" url="http://secunia.com/secunia_research/2007-38/advisory/"></ref><ref source="BID" url="http://www.securityfocus.com/bid/22554">22554</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0595">ADV-2007-0595</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/23998">23998</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2258">2258</ref></refs><vuln_soft><prod name="MailEnable Professional" vendor="MailEnable"><vers num="1.116"/><vers num="1.115"/><vers num="1.114"/><vers num="1.113"/><vers num="1.112"/><vers num="1.111"/><vers num="1.110"/><vers num="1.109"/><vers num="1.108"/><vers num="1.107"/><vers num="1.106"/><vers num="1.105"/><vers num="1.104"/><vers num="1.103"/><vers num="1.102"/><vers num="1.101"/><vers num="1.54"/><vers num="1.53"/><vers num="1.52"/><vers num="1.51"/><vers num="1.19"/><vers num="1.18"/><vers num="1.17"/><vers num="1.16"/><vers num="1.15"/><vers num="1.14"/><vers num="1.13"/><vers num="1.12"/><vers num="1.7"/><vers num="1.6"/><vers num="1.5"/><vers num="1.2a"/><vers num="1.2"/><vers num="1.1"/><vers num="1.0.017"/><vers num="1.0.016"/><vers num="1.0.015"/><vers num="1.0.014"/><vers num="1.0.013"/><vers num="1.0.012"/><vers num="1.0.011"/><vers num="1.0.010"/><vers num="1.0.009"/><vers num="1.0.008"/><vers num="1.0.007"/><vers num="1.0.006"/><vers num="1.0.005"/><vers num="1.0.004"/><vers num="2.351"/><vers num="2.35"/><vers num="2.34"/><vers num="2.33"/><vers num="2.32"/><vers num="2.2"/><vers num="2.1"/><vers num="2.0"/><vers num="1.84"/><vers num="1.83"/><vers num="1.82"/><vers num="1.73"/><vers num="1.72"/></prod></vuln_soft></entry><entry CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" CVSS_score="9.3" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-03-23" name="CVE-2007-0653" published="2007-03-21" seq="2007-0653" severity="High" type="CVE"><desc><descript source="cve">Integer overflow in X MultiMedia System (xmms) 1.2.10, and possibly other versions, allows user-assisted remote attackers to execute arbitrary code via crafted header information in a skin bitmap image, which triggers memory corruption.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input/><exception/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" source="" url="http://secunia.com/secunia_research/2007-47/advisory/"></ref><ref source="BID" url="http://www.securityfocus.com/bid/23078">23078</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1057">ADV-2007-1057</ref><ref source="SECUNIA" url="http://secunia.com/advisories/23986">23986</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2007:071">
MDKSA-2007:071</ref><ref source="UBUNTU" url="http://www.ubuntu.com/usn/usn-445-1">
USN-445-1</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24645">
24645</ref><ref source="DEBIAN" url="http://www.debian.org/security/2007/dsa-1277">
DSA-1277</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24804">
24804</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2007_6_sr.html">
SUSE-SR:2007:006</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24889">
24889</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/463408/100/0/threaded">20070321 Secunia Research: XMMS Integer Overflow and UnderflowVulnerabilities</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:071">MDKSA-2007:071</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33205">xmms-skinbitmap-code-execution(33205)</ref></refs><vuln_soft><prod name="X MultiMedia System" vendor="X MultiMedia System"><vers num="1.2.10"/></prod></vuln_soft></entry><entry CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" CVSS_score="9.3" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-03-23" name="CVE-2007-0654" published="2007-03-21" seq="2007-0654" severity="High" type="CVE"><desc><descript source="cve">Integer underflow in X MultiMedia System (xmms) 1.2.10 allows user-assisted remote attackers to execute arbitrary code via crafted header information in a skin bitmap image, which results in a stack-based buffer overflow.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" source="" url="http://secunia.com/secunia_research/2007-47/advisory/"></ref><ref source="BID" url="http://www.securityfocus.com/bid/23078">23078</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1057">ADV-2007-1057</ref><ref source="SECUNIA" url="http://secunia.com/advisories/23986">23986</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2007:071">
MDKSA-2007:071</ref><ref source="UBUNTU" url="http://www.ubuntu.com/usn/usn-445-1">
USN-445-1</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24645">
24645</ref><ref source="DEBIAN" url="http://www.debian.org/security/2007/dsa-1277">
DSA-1277</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24804">
24804</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2007_6_sr.html">
SUSE-SR:2007:006</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24889">
24889</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/463408/100/0/threaded">20070321 Secunia Research: XMMS Integer Overflow and UnderflowVulnerabilities</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:071">MDKSA-2007:071</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33203">xmms-skinbitmap-bo(33203)</ref></refs><vuln_soft><prod name="X MultiMedia System" vendor="X MultiMedia System"><vers num="1.2.10"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-06-29" name="CVE-2007-0655" published="2007-05-02" seq="2007-0655" severity="High" type="CVE"><desc><descript source="cve">The MicroWorld Agent service (MWAGENT.EXE) in MicroWorld Technologies eScan 8.0.671.1, and possibly other versions, allows remote or local attackers to gain privileges and execute arbitrary commands by connecting directly to TCP port 2222.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" source="" url="http://secunia.com/secunia_research/2007-45/advisory/"></ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1609">ADV-2007-1609</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/23809">23809</ref><ref source="BID" url="http://www.securityfocus.com/bid/23759">23759</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1018007">1018007</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/34009">escan-mwagent-security-bypass(34009)</ref></refs><vuln_soft><prod name="eScan" vendor="MicroWorld Technologies"><vers num="8.0671.1" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-02-02" name="CVE-2007-0656" published="2007-02-01" seq="2007-0656" severity="High" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in includes/functions.php in phpBB2-MODificat 0.2.0 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://www.milw0rm.com/exploits/3231"></ref><ref source="BID" url="http://www.securityfocus.com/bid/22320">22320</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0422">ADV-2007-0422</ref><ref source="MILW0RM" url="http://milw0rm.com/exploits/3231">

3231</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31985">
phpbb2modificat-functions-file-include(31985)</ref></refs><vuln_soft><prod name="phpBB2-MODificat" vendor="phpBB2-MODificat"><vers num="0.2.0"/><vers num="0.1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-02-02" name="CVE-2007-0657" published="2007-02-01" seq="2007-0657" severity="High" type="CVE"><desc><descript source="cve">Unspecified vulnerability in Nexuiz 2.2.2 allows remote attackers to read and overwrite arbitrary files via the gamedir command.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref patch="1" source="" url="http://www.alientrap.org/devwiki/index.php?n=Nexuiz.Patch"></ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0427">ADV-2007-0427</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/23963">23963</ref><ref source="BID" url="http://www.securityfocus.com/bid/22332">
22332</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32040">
nexuiz-gamedir-information-disclosure(32040)</ref></refs><vuln_soft><prod name="Nexuiz" vendor="Alientrap"><vers num="2.2.2"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" modified="2007-02-02" name="CVE-2007-0658" published="2007-02-01" seq="2007-0658" severity="Medium" type="CVE"><desc><descript source="cve">The (1) Textimage 4.7.x before 4.7-1.2 and 5.x before 5.x-1.1 module for Drupal and the (2) Captcha 4.7.x before 4.7-1.2 and 5.x before 5.x-1.1 module for Drupal allow remote attackers to bypass the CAPTCHA test via an empty captcha element in $_SESSION.</descript></desc><loss_types><int/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref patch="1" source="" url="http://cvs.drupal.org/viewcvs/drupal/contributions/modules/captcha/captcha.module?r1=1.25.2.1&amp;r2=1.25.2.2"></ref><ref patch="1" source="" url="http://cvs.drupal.org/viewcvs/drupal/contributions/modules/textimage/captcha.inc?r1=1.1&amp;r2=1.1.2.1"></ref><ref adv="1" patch="1" source="" url="http://drupal.org/node/114364"></ref><ref adv="1" patch="1" source="" url="http://drupal.org/node/114519"></ref><ref source="BID" url="http://www.securityfocus.com/bid/22329">22329</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0431">ADV-2007-0431</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/23983">23983</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/23985">23985</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31994">
captcha-response-security-bypass(31994)</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31984">
textimage-captcha-security-bypass(31984)</ref></refs><vuln_soft><prod name="Drupal" vendor="Drupal"><vers num="4.7.6"/><vers num="4.7.5"/><vers num="4.7.4"/><vers num="4.7.3"/><vers num="4.7.2"/><vers num="4.7.1"/><vers num="4.7"/><vers num="5.1"/><vers num="5.0"/><vers num="4.7 rev1.15"/></prod><prod name="Textimage" vendor="Drupal"><vers num="4.7"/><vers num="5.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-02-02" name="CVE-2007-0659" published="2007-02-01" seq="2007-0659" severity="High" type="CVE"><desc><descript source="cve">download.php in the MuddyDogPaws FileDownload snippet before 2.5 for MODx allows remote attackers to download arbitrary files, as demonstrated by downloading config.inc.php to obtain database credentials.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="" url="http://modxcms.com/forums/index.php/topic,10470.0.html"></ref><ref source="" url="http://www.muddydogpaws.com/Home.html"></ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/22327">22327</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0426">ADV-2007-0426</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/23953">23953</ref></refs><vuln_soft><prod name="FileDownload" vendor="MODxCMS"><vers num="2.0"/><vers num="1.7"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-02-02" name="CVE-2007-0660" published="2007-02-01" seq="2007-0660" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in the IFrame module before 03.02.01 for DotNetNuke (DNN) allows remote attackers to inject arbitrary web script or HTML via unspecified vectors related to &quot;Pass through values.&quot;</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://www.dotnetnuke.com/Default.aspx?tabid=825&amp;EntryID=1278"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0433">ADV-2007-0433</ref><ref source="BID" url="http://www.securityfocus.com/bid/22334">
22334</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32037">
dotnetnuke-iframe-unspecified-xss(32037)</ref></refs><vuln_soft><prod name="DotNetNuke IFrame" vendor="DotNetNuke"><vers num="03.02.00"/><vers num="03.01.01" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.4" CVSS_exploit_subscore="5.5" CVSS_impact_subscore="6.4" CVSS_score="5.4" CVSS_vector="(AV:A/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-02-02" name="CVE-2007-0661" published="2007-02-01" seq="2007-0661" severity="Medium" type="CVE"><desc><descript source="cve">Intel Enterprise Southbridge 2 Baseboard Management Controller (BMC), Intel Server Boards 5000XAL, S5000PAL, S5000PSL, S5000XVN, S5000VCL, S5000VSA, SC5400RA, and OEM Firmware for Intel Enterprise Southbridge Baseboard Management Controller before 20070119, when Intelligent Platform Management Interface (IPMI) is enabled, allow remote attackers to connect and issue arbitrary IPMI commands, possibly triggering a denial of service.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><access/></vuln_types><range><local_network/></range><refs><ref adv="1" patch="1" source="" url="http://lz1.intel.com/psirt/advisory.aspx?intelid=INTEL-SA-00012&amp;languageid=en-fr"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0432">ADV-2007-0432</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/23989">23989</ref><ref source="BID" url="http://www.securityfocus.com/bid/22341">
22341</ref></refs><vuln_soft><prod name="Enterprise Southbridge 2 BMC" vendor="Intel"><vers num=""/></prod><prod name="Enterprise Southbridge BMC" vendor="Intel"><vers num="OEM"/></prod><prod name="Server Boards" vendor="Intel"><vers num="5000XAL"/><vers num="S5000PAL"/><vers num="S5000PSL"/><vers num="S5000XVN"/><vers num="S5000VCL"/><vers num="S5000VSA"/><vers num="SC5400RA"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-02-02" name="CVE-2007-0662" published="2007-02-01" seq="2007-0662" severity="High" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in includes/usercp_viewprofile.php in Hailboards 1.2.0 allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://www.milw0rm.com/exploits/3236"></ref><ref source="BID" url="http://www.securityfocus.com/bid/22333">22333</ref><ref source="MILW0RM" url="http://milw0rm.com/exploits/3236">

3236</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0450">
ADV-2007-0450</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24002">
24002</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31997">
hailboards-usercpviewprofile-file-include(31997)</ref></refs><vuln_soft><prod name="hailBoards" vendor="hailBoards"><vers num="1.2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-02-02" name="CVE-2007-0663" published="2007-02-01" seq="2007-0663" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in index.php in Eclectic Designs CascadianFAQ 4.1 and earlier allows remote attackers to execute arbitrary SQL commands via the qid parameter, a different vector than CVE-2007-0631.  NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0424">ADV-2007-0424</ref></refs><vuln_soft><prod name="CascadianFAQ" vendor="Eclectic Designs"><vers num="4.1"/><vers num="4.0" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0" modified="2007-02-05" name="CVE-2007-0664" published="2007-02-02" seq="2007-0664" severity="Medium" type="CVE"><desc><descript source="cve">thttpd before 2.25b-r6 in Gentoo Linux is started from the system root directory (/) by the Gentoo baselayout 1.12.6 package, which allows remote attackers to read arbitrary files.</descript></desc><loss_types><conf/></loss_types><vuln_types><config/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="" url="http://bugs.gentoo.org/show_bug.cgi?id=142047"></ref><ref adv="1" patch="1" source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200701-28.xml">GLSA-200701-28</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/22349">22349</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/24018">24018</ref></refs><vuln_soft><prod name="thttpd" vendor="Acme Labs"><vers num="2.24" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-02-05" name="CVE-2007-0665" published="2007-02-02" seq="2007-0665" severity="Medium" type="CVE"><desc><descript source="cve">Format string vulnerability in the SCP module in Ipswitch WS_FTP 2007 Professional might allow remote attackers to execute arbitrary commands via format string specifiers in the filename, related to the SHELL WS_FTP script command.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input/><design/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/458293/100/0/threaded">20070126 WS_FTP 2007 Professional SCP handling format string vulnerability</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/22275">22275</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/31865">wsftp-scphandler-format-string(31865)</ref></refs><vuln_soft><prod name="WS_FTP Pro" vendor="Ipswitch"><vers num="2007"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-08-06" name="CVE-2007-0666" published="2007-02-02" seq="2007-0666" severity="Medium" type="CVE"><desc><descript source="cve">Ipswitch WS_FTP Server 5.04 allows FTP site administrators to execute arbitrary code on the system via a long input string to the (1) iFTPAddU or (2) iFTPAddH file, or to a (3) edition module.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/458774/100/0/threaded">20070201 Ipswitch WS_FTP Server 5.04 multiple arbitrary code execution vulnerabilities</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/458932/100/0/threaded">20070202 Re: Ipswitch WS_FTP Server 5.04 multiple arbitrary code execution vulnerabilities</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/459023/100/0/threaded">20070202 Re: Re: Ipswitch WS_FTP Server 5.04 multiple arbitrary code execution vulnerabilities</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/458942/100/0/threaded">20070202 Re[2]: Ipswitch WS_FTP Server 5.04 multiple arbitrary code execution vulnerabilities</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32176">wsftp-iftpaddu-privilege-escalation(32176)</ref></refs><vuln_soft><prod name="WS_FTP Server" vendor="Ipswitch"><vers num="5.04"/></prod></vuln_soft></entry><entry CVSS_base_score="6.5" CVSS_exploit_subscore="8.0" CVSS_impact_subscore="6.4" CVSS_score="6.5" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-08-06" name="CVE-2007-0667" published="2007-02-02" seq="2007-0667" severity="Medium" type="CVE"><desc><descript source="cve">The redirect function in Form.pm for (1) LedgerSMB before 1.1.5 and (2) SQL-Ledger allows remote authenticated users to execute arbitrary code via redirects, related to callbacks, a different issue than CVE-2006-5872.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/458464/100/0/threaded">20070127 Arbitrary Code Execution in SQL-Ledger and LedgerSMB through redirects</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0407">ADV-2007-0407</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/459264/100/0/threaded">20070206 Unofficial SQL-Ledger patch for CVE-2007-0667</ref><ref source="BID" url="http://www.securityfocus.com/bid/22295">22295</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2217">2217</ref></refs><vuln_soft><prod name="SQL-Ledger" vendor="SQL-Ledger"><vers num="2.6.25"/><vers num="2.6.21"/><vers num="2.6.19"/><vers num="2.6.18"/><vers num="2.6.17"/><vers num="2.4.7"/></prod><prod name="LedgerSMB" vendor="LedgerSMB"><vers num="1.1.1" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.2" CVSS_exploit_subscore="3.1" CVSS_impact_subscore="9.2" CVSS_score="6.2" CVSS_vector="(AV:L/AC:L/Au:S/C:N/I:C/A:C)" CVSS_version="2.0" modified="2007-02-05" name="CVE-2007-0668" published="2007-02-02" seq="2007-0668" severity="Medium" type="CVE"><desc><descript source="cve">The Loopback Filesystem (LOFS) in Sun Solaris 10 allows local users in a non-global zone to move and rename files in a read-only filesystem, which could lead to a denial of service.</descript></desc><loss_types><avail/><int/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102699-1">102699</ref><ref source="BID" url="http://www.securityfocus.com/bid/22364">
22364</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0462">
ADV-2007-0462</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1017582">
1017582</ref><ref source="SECUNIA" url="http://secunia.com/advisories/23996">
23996</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32140">
solaris-loopbackfs-dos(32140)</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1372">oval:org.mitre.oval:def:1372</ref></refs><vuln_soft><prod name="Solaris" vendor="Sun"><vers edition="SPARC" num="10.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-02-12" name="CVE-2007-0669" published="2007-02-08" seq="2007-0669" severity="Medium" type="CVE"><desc><descript source="cve">Unspecified vulnerability in Twiki 4.0.0 through 4.1.0 allows local users to execute arbitrary Perl code via unknown vectors related to CGI session files.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><range><local/></range><refs><ref adv="1" source="" url="http://twiki.org/cgi-bin/view/Codev/SecurityAlert-CVE-2007-0669"></ref><ref patch="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/584436">VU#584436</ref><ref source="OPENPKG" url="http://www.openpkg.com/security/advisories/OpenPKG-SA-2007.009.html">
OpenPKG-SA-2007.009</ref><ref source="BID" url="http://www.securityfocus.com/bid/22378">
22378</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0544">
ADV-2007-0544</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24091">
24091</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32389">
twiki-cgisession-code-execution(32389)</ref></refs><vuln_soft><prod name="Twiki" vendor="Twiki"><vers num="4.1.0"/><vers num="4.0.5"/><vers num="4.0.4"/><vers num="4.0.3"/><vers num="4.0.2"/><vers num="4.0.1"/><vers num="4.0.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-08-03" name="CVE-2007-0670" published="2007-02-02" seq="2007-0670" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in bos.rte.libc in IBM AIX 5.2 and 5.3 allows local users to execute arbitrary code via the &quot;r-commands&quot;, possibly including (1) rdist, (2) rsh, (3) rcp, (4) rsync, and (5) rlogin.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref source="AIXAPAR" url="http://www-1.ibm.com/support/docview.wss?uid=isg1IY94301">IY94301</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/23995">23995</ref><ref source="" url="ftp://aix.software.ibm.com/aix/efixes/security/README"></ref><ref source="AIXAPAR" url="http://www-1.ibm.com/support/docview.wss?uid=isg1IY94368">IY94368</ref><ref source="BID" url="http://www.securityfocus.com/bid/22370">22370</ref><ref source="BID" url="http://www.securityfocus.com/bid/22456">22456</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0471">ADV-2007-0471</ref><ref source="OSVDB" url="http://www.osvdb.org/31696">31696</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1017583">1017583</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1017607">1017607</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32184">aix-rdist-bo(32184)</ref></refs><vuln_soft><prod name="AIX" vendor="IBM"><vers num="5.3"/></prod></vuln_soft></entry><entry CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" CVSS_score="9.3" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-05-16" name="CVE-2007-0671" published="2007-02-02" seq="2007-0671" severity="High" type="CVE"><desc><descript source="cve">Unspecified vulnerability in Microsoft Excel 2000, XP, 2003, and 2004 for Mac, and possibly other Office products, allows remote user-assisted attackers to execute arbitrary code via unknown attack vectors, as demonstrated by Exploit-MSExcel.h in targeted zero-day attacks.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><range><network/><user_init/></range><refs><ref source="" url="http://www.avertlabs.com/research/blog/?p=191"></ref><ref source="" url="http://vil.nai.com/vil/content/v_141393.htm"></ref><ref source="" url="http://www.microsoft.com/technet/security/advisory/932553.mspx"></ref><ref source="MS" url="http://www.microsoft.com/technet/security/Bulletin/MS07-015.mspx">MS07-015</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/613740">VU#613740</ref><ref source="BID" url="http://www.securityfocus.com/bid/22383">22383</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0463">ADV-2007-0463</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1017584">1017584</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24008">24008</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32178">office-unspecified-code-execution(32178)</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA07-044A.html">TA07-044A</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:301">oval:org.mitre.oval:def:301</ref></refs><vuln_soft><prod name="Excel" vendor="Microsoft"><vers num="2000"/><vers num="2002"/><vers num="2003"/><vers num="2003 Viewer"/></prod><prod name="Project" vendor="Microsoft"><vers num="2000 SR1"/><vers num="2002 SP1"/><vers num="2003"/></prod><prod name="Access" vendor="Microsoft"><vers num="2000"/><vers num="2002"/><vers num="2003"/></prod><prod name="OneNote" vendor="Microsoft"><vers num="2003"/></prod><prod name="Word" vendor="Microsoft"><vers num="2000"/><vers num="2002"/><vers num="2003"/><vers num="2003 Viewer"/></prod><prod name="Outlook" vendor="Microsoft"><vers num="2000"/><vers num="2002"/><vers num="2003"/></prod><prod name="Visio" vendor="Microsoft"><vers num="2002 SP2"/><vers num="2003"/></prod><prod name="Office" vendor="Microsoft"><vers num="2000 SP3"/><vers num="2003 SP2"/><vers num="XP SP3"/><vers edition="Mac" num="2004"/></prod><prod name="Publisher" vendor="Microsoft"><vers num="2000"/><vers num="2002"/><vers num="2003"/></prod><prod name="PowerPoint" vendor="Microsoft"><vers num="2000"/><vers num="2002"/><vers num="2003"/><vers edition="Mac" num="2004"/></prod><prod name="FrontPage" vendor="Microsoft"><vers num="2000"/><vers num="2002"/><vers num="2003"/></prod><prod name="InfoPath" vendor="Microsoft"><vers num="2003"/></prod></vuln_soft></entry><entry CVSS_base_score="7.8" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.9" CVSS_score="7.8" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_version="2.0" modified="2007-02-05" name="CVE-2007-0672" published="2007-02-02" seq="2007-0672" severity="High" type="CVE"><desc><descript source="cve">LGSERVER.EXE in BrightStor Mobile Backup 4.0 allows remote attackers to cause a denial of service (disk consumption and daemon hang) via a value of 0xFFFFFF7F at a certain point in an authentication negotiation packet, which writes a large amount of data to a .USX file in CA_BABLDdata\Server\data\transfer\.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/458653/100/0/threaded">20070131 Remote Unauthenticated Resource Exhaustion CA Mobile BackupService</ref><ref patch="1" source="" url="http://supportconnectw.ca.com/public/sams/lifeguard/infodocs/babldimpsec-notice.asp"></ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/22339">22339</ref></refs><vuln_soft><prod name="Business Protection Suite" vendor="Computer Associates"><vers edition="Microsoft SBS Standard" num="r2"/><vers edition="Microsoft SBS Premium" num="r2"/><vers num="2.0"/></prod><prod name="Desktop Protection Suite" vendor="Computer Associates"><vers num="2.0"/></prod><prod name="Desktop Management Suite" vendor="Computer Associates"><vers num="11.1"/><vers num="11.0"/></prod><prod name="BrightStor ARCserve Backup Laptops_Desktops" vendor="Computer Associates"><vers num="11.1"/><vers num="11.0"/><vers num="11.1 SP1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.8" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.9" CVSS_score="7.8" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_version="2.0" modified="2007-08-03" name="CVE-2007-0673" published="2007-02-02" seq="2007-0673" severity="High" type="CVE"><desc><descript source="cve">LGSERVER.EXE in BrightStor ARCserve Backup for Laptops &amp; Desktops r11.1 allows remote attackers to cause a denial of service (daemon crash) via a value of 0xFFFFFFFF at a certain point in an authentication negotiation packet, which results in an out-of-bounds read.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/458650/100/0/threaded">20070131 Remote DOS BrightStor ARCserve Backup for Laptops &amp; Desktops</ref><ref patch="1" source="" url="http://supportconnectw.ca.com/public/sams/lifeguard/infodocs/babldimpsec-notice.asp"></ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/22337">22337</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2218">2218</ref></refs><vuln_soft><prod name="Business Protection Suite" vendor="Computer Associates"><vers edition="Microsoft SBS Standard" num="r2"/><vers edition="Microsoft SBS Premium" num="r2"/><vers num="2.0"/></prod><prod name="Desktop Protection Suite" vendor="Computer Associates"><vers num="2.0"/></prod><prod name="Desktop Management Suite" vendor="Computer Associates"><vers num="11.1"/><vers num="11.0"/></prod><prod name="BrightStor ARCserve Backup Laptops_Desktops" vendor="Computer Associates"><vers num="11.1"/><vers num="11.0"/><vers num="11.1 SP1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.1" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.9" CVSS_score="7.1" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:C)" CVSS_version="2.0" modified="2007-02-05" name="CVE-2007-0674" published="2007-02-02" seq="2007-0674" severity="High" type="CVE"><desc><descript source="cve">Pictures and Videos on Windows Mobile 5.0 and Windows Mobile 2003 and 2003SE for Smartphones and PocketPC allows user-assisted remote attackers to cause a denial of service (device hang) via a malformed JPEG file.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/><user_init/></range><refs><ref source="" url="http://blog.trendmicro.com/trend-micro-finds-more-windows-mobile-flaws/"></ref><ref source="BID" url="http://www.securityfocus.com/bid/22343">22343</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0434">ADV-2007-0434</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32002">picturesvideos-jpeg-dos(32002)</ref></refs><vuln_soft><prod name="Windows Mobile" vendor="Microsoft"><vers num="Smartphone"/><vers num="Pocket PC Phone 2003"/><vers num="2003 SE"/><vers num="5.0"/><vers num="2003"/></prod></vuln_soft></entry><entry CVSS_base_score="7.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="10.0" CVSS_score="7.6" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2008-06-23" name="CVE-2007-0675" published="2007-02-02" seq="2007-0675" severity="High" type="CVE"><desc><descript source="cve">A certain ActiveX control in sapi.dll (aka the Speech API) in Speech Components in Microsoft Windows Vista, when the Speech Recognition feature is enabled, allows user-assisted remote attackers to delete arbitrary files, and conduct other unauthorized activities, via a web page with an embedded sound object that contains voice commands to an enabled microphone, allowing for interaction with Windows Explorer.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref source="MLIST" url="http://lists.immunitysec.com/pipermail/dailydave/2007-January/004003.html">[dailydave] 20070130 Vista speach recognition</ref><ref source="MLIST" url="http://lists.immunitysec.com/pipermail/dailydave/2007-January/004005.html">[dailydave] 20070130 Vista speach recognition</ref><ref source="MLIST" url="http://lists.immunitysec.com/pipermail/dailydave/2007-January/004007.html">[dailydave] 20070130 Vista speach recognition</ref><ref source="MLIST" url="http://lists.immunitysec.com/pipermail/dailydave/2007-January/004012.html">[dailydave] 20070131 Vista speach recognition</ref><ref source="" url="http://blogs.technet.com/msrc/archive/2007/01/31/issue-regarding-windows-vista-speech-recognition.aspx"></ref><ref source="BID" url="http://www.securityfocus.com/bid/22359">22359</ref><ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms08-032.mspx">MS08-032</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA08-162B.html">TA08-162B</ref></refs><vuln_soft><prod name="Windows Vista" vendor="Microsoft"><vers edition="32 bit" num="Ultimate"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-02-14" name="CVE-2007-0676" published="2007-02-02" seq="2007-0676" severity="Medium" type="CVE"><desc><descript source="cve">SQL injection vulnerability in faq.php in ExoPHPDesk 1.2.1 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.</descript></desc><sols><sol source="nvd">Successful exploitation requires that &quot;magic_quotes_gpc&quot; is disabled.</sol></sols><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="Milw0rm" url="http://www.milw0rm.com/exploits/3234">Exploit 3234</ref><ref source="BID" url="http://www.securityfocus.com/bid/22338">22338</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31998">exophpdesk-faq-sql-injection(31998)</ref><ref source="MILW0RM" url="http://milw0rm.com/exploits/3234">

3234</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0452">
ADV-2007-0452</ref></refs><vuln_soft><prod name="ExoPHPDesk" vendor="EXO"><vers num="1.2.1"/><vers num="1.2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-02-05" name="CVE-2007-0677" published="2007-02-02" seq="2007-0677" severity="High" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in fw/class.Quick_Config_Browser.php in Cadre PHP Framework 20020724 allows remote attackers to execute arbitrary PHP code via a URL in the GLOBALS[config][framework_path] parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/458681/100/0/threaded">20070131 [ECHO_ADV_63$2007] Cadre remote file inclusion</ref><ref source="" url="http://echo.or.id/adv/adv63-y3dips-2007.txt"></ref><ref source="" url="http://www.milw0rm.com/exploits/3237"></ref><ref source="BID" url="http://www.securityfocus.com/bid/22336">22336</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32005">cadre-classquickconfigbrowser-file-include(32005)</ref><ref source="MILW0RM" url="http://milw0rm.com/exploits/3237">
3237</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0449">
ADV-2007-0449</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2215">2215</ref></refs><vuln_soft><prod name="Cadre PHP Framework" vendor="Cronosys"><vers num="22020724"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-02-05" name="CVE-2007-0678" published="2007-02-02" seq="2007-0678" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in windows.asp in Fullaspsite Asp Hosting Sitesi allows remote attackers to execute arbitrary SQL commands via the kategori_id parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://www.milw0rm.com/exploits/3233"></ref><ref source="BID" url="http://www.securityfocus.com/bid/22347">22347</ref><ref source="MILW0RM" url="http://milw0rm.com/exploits/3233">

3233</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0453">
ADV-2007-0453</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32020">
fullaspsite-windows-sql-injection(32020)</ref></refs><vuln_soft><prod name="ASP Hosting Site" vendor="Fullaspsite"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-02-05" name="CVE-2007-0679" published="2007-02-02" seq="2007-0679" severity="High" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in lang/leslangues.php in Nicolas Grandjean PHPMyRing 4.1.3b and earlier allows remote attackers to execute arbitrary PHP code via a URL in the fichier parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://www.milw0rm.com/exploits/3238"></ref><ref source="BID" url="http://www.securityfocus.com/bid/22345">22345</ref><ref source="MILW0RM" url="http://milw0rm.com/exploits/3238">

3238</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0448">
ADV-2007-0448</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32033">
phpmyring-leslangues-file-include(32033)</ref></refs><vuln_soft><prod name="PHPMyRing" vendor="Nicolas Grandjean"><vers num="4.1.3b" prev="1"/><vers num="4.1.2b"/><vers num="4.1.1b"/><vers num="4.1.0b"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-02-05" name="CVE-2007-0680" published="2007-02-02" seq="2007-0680" severity="High" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in includes/functions.php in Phpbb Tweaked 3 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://www.milw0rm.com/exploits/3235"></ref><ref source="" url="http://www.xoron.info/bugs/phpbbtweaked.txt"></ref><ref source="BID" url="http://www.securityfocus.com/bid/22344">22344</ref><ref source="MILW0RM" url="http://milw0rm.com/exploits/3235">

3235</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0451">
ADV-2007-0451</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24001">
24001</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32024">
phpbbtweaked-functions-file-include(32024)</ref></refs><vuln_soft><prod name="Phpbb Tweaked" vendor="Phpbb Tweaked"><vers num="3" prev="1"/><vers num="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-02-05" name="CVE-2007-0681" published="2007-02-02" seq="2007-0681" severity="High" type="CVE"><desc><descript source="cve">profile.php in ExtCalendar 2 and earlier allows remote attackers to change the passwords of arbitrary users without providing the original password, and possibly perform other unauthorized actions, via modified values to register.php.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://www.milw0rm.com/exploits/3239"></ref><ref source="MILW0RM" url="http://milw0rm.com/exploits/3239">

3239</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32035">
extcalendar-profile-security-bypass(32035)</ref></refs><vuln_soft><prod name="ExtCalendar" vendor="ExtCalendar"><vers num="2" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-02-05" name="CVE-2007-0682" published="2007-02-02" seq="2007-0682" severity="High" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in theme/include_mode/template.php in JV2 Folder Gallery 3.0.2 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the galleryfilesdir parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://www.milw0rm.com/exploits/3240"></ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24012">24012</ref><ref source="MILW0RM" url="http://milw0rm.com/exploits/3240">

3240</ref><ref source="BID" url="http://www.securityfocus.com/bid/22354">
22354</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0447">
ADV-2007-0447</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32043">
jv2gallery-template-file-include(32043)</ref></refs><vuln_soft><prod name="Folder Gallery" vendor="JV2"><vers num="3.0.2" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-02-06" name="CVE-2007-0683" published="2007-02-02" seq="2007-0683" severity="High" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in includes/functions.php in Omegaboard 1.0beta4 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="Milw0rm" url="http://www.milw0rm.com/exploits/3242">Exploit 3242</ref><ref source="" url="http://www.xoron.info/bugs/omegaboard-html.txt"></ref><ref source="" url="http://www.xoron.info/bugs/omegaboard-perl.txt"></ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/458825/100/0/threaded">

20070201 Omegaboard v1.0b4 (phpbb_root_path) Remote File Include Exploit</ref><ref source="FULLDISC" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=117036933022782&amp;w=2">
20070201 Omegaboard v1.0b4 (phpbb_root_path) Remote File Include Exploit</ref><ref source="MILW0RM" url="http://milw0rm.com/exploits/3242">
3242</ref><ref source="BID" url="http://www.securityfocus.com/bid/22355">
22355</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0445">
ADV-2007-0445</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32057">
omegaboard-functions-file-include(32057)</ref></refs><vuln_soft><prod name="Omegaboard" vendor="Omegaboard"><vers num="1.0 Beta4" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-02-05" name="CVE-2007-0684" published="2007-02-02" seq="2007-0684" severity="High" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in portal.php in Cerulean Portal System 0.7b allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://www.milw0rm.com/exploits/3243"></ref><ref source="" url="http://www.xoron.info/bugs/ceruleanportalsystem-html.txt"></ref><ref source="" url="http://www.xoron.info/bugs/ceruleanportalsystem-perl.txt"></ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/458824/100/0/threaded">

20070201 Cerulean Portal System (phpbb_root_path) Remote File Include Exploit</ref><ref source="MILW0RM" url="http://milw0rm.com/exploits/3243">
3243</ref><ref source="BID" url="http://www.securityfocus.com/bid/22356">
22356</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0444">
ADV-2007-0444</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32058">
cerulean-portal-file-include(32058)</ref></refs><vuln_soft><prod name="Cerulean Portal System" vendor="Cerulean Portal System"><vers num="0.7b"/></prod></vuln_soft></entry><entry CVSS_base_score="2.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="2.9" CVSS_score="2.6" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:N/A:P)" CVSS_version="2.0" modified="2007-02-06" name="CVE-2007-0685" published="2007-02-02" seq="2007-0685" severity="Low" type="CVE"><desc><descript source="cve">Internet Explorer on Windows Mobile 5.0 and Windows Mobile 2003 and 2003SE for Smartphones and PocketPC allows attackers to cause a denial of service (application crash and device instability) via unspecified vectors, possibly related to a buffer overflow.</descript></desc><loss_types><avail/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/><user_init/></range><refs><ref source="" url="http://blog.trendmicro.com/trend-micro-finds-more-windows-mobile-flaws/"></ref><ref source="BID" url="http://www.securityfocus.com/bid/22343">22343</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0434">ADV-2007-0434</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/32001">ie-mobile-unspecified-bo(32001)</ref></refs><vuln_soft><prod name="Windows Mobile" vendor="Microsoft"><vers num="Smartphone"/><vers num="Pocket PC Phone 2003"/><vers num="2003 SE"/><vers num="5.0"/><vers num="2003"/></prod></vuln_soft></entry><entry CVSS_base_score="7.1" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.9" CVSS_score="7.1" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:C)" CVSS_version="2.0" modified="2007-02-06" name="CVE-2007-0686" published="2007-02-02" seq="2007-0686" severity="High" type="CVE"><desc><descript source="cve">The Intel 2200BG 802.11 Wireless Mini-PCI driver 9.0.3.9 (w29n51.sys) allows remote attackers to cause a denial of service (system crash) via crafted disassociation packets, which triggers memory corruption of &quot;internal kernel structures,&quot; a different vulnerability than CVE-2006-6651.  NOTE: this issue might overlap CVE-2006-3992.</descript></desc><loss_types><avail/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref source="" url="http://www.milw0rm.com/exploits/3224"></ref><ref source="MILW0RM" url="http://milw0rm.com/exploits/3224">

3224</ref></refs><vuln_soft><prod name="2200BG PROSet/Wireless" vendor="Intel"><vers num="9.0.3.9"/></prod></vuln_soft></entry><entry CVSS_base_score="6.5" CVSS_exploit_subscore="8.0" CVSS_impact_subscore="6.4" CVSS_score="6.5" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-02-06" name="CVE-2007-0687" published="2007-02-02" seq="2007-0687" severity="Medium" type="CVE"><desc><descript source="cve">SQL injection vulnerability in i-search.php in Michelle&apos;s L2J Dropcalc 4 and earlier allows remote authenticated users to execute arbitrary SQL commands via the itemid parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://www.milw0rm.com/exploits/3232"></ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/22335">22335</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32003">l2j-isearch-sql-injection(32003)</ref><ref source="MILW0RM" url="http://milw0rm.com/exploits/3232">

3232</ref></refs><vuln_soft><prod name="L2J DropCalc" vendor="Michelle"><vers num="4" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-02-06" name="CVE-2007-0688" published="2007-02-02" seq="2007-0688" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in oku.asp in Hunkaray Duyuru Scripti allows remote attackers to execute arbitrary SQL commands via the id parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://www.milw0rm.com/exploits/3241"></ref><ref source="MILW0RM" url="http://milw0rm.com/exploits/3241">

3241</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0446">
ADV-2007-0446</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32042">
hds-oku-sql-injection(32042)</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/470744/100/0/threaded">20070607 H&amp;uuml;nkaray Duyuru Script Remote SQL &amp;#304;njection</ref><ref source="BID" url="http://www.securityfocus.com/bid/24367">24367</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25581">25581</ref></refs><vuln_soft><prod name="Scripti" vendor="Hunkaray Duyuru"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0" modified="2007-05-18" name="CVE-2007-0689" published="2007-05-14" seq="2007-0689" severity="Medium" type="CVE"><desc><descript source="cve">MyBB 1.2.4 allows remote attackers to obtain sensitive information via the (1) action[] parameter to member.php, (2) imagehash[] parameter to captcha.php, and (3) a direct request to inc/datahandlers/event.php, which reveal the installation path in the resulting error message.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="FULLDISC" url="http://marc.info/?l=full-disclosure&amp;m=117909973216181&amp;w=2">20070513 MyBB version 1.2.4 Multiple Path Disclosure Vulnerabilities</ref><ref adv="1" source="" url="http://www.netvigilance.com/advisory0017"></ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/468549/100/0/threaded">

20070513 MyBB version 1.2.4 Multiple Path Disclosure Vulnerabilities</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/34336">mybb-eventmembercaptcha-info-disclosure(34336)</ref></refs><vuln_soft><prod name="MyBB" vendor="MyBB"><vers num="1.2.4" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0" modified="2007-06-04" name="CVE-2007-0690" published="2007-05-30" seq="2007-0690" severity="Medium" type="CVE"><desc><descript source="cve">myEvent 1.6 allows remote attackers to obtain sensitive information via (1) a Log In action without a password to login.php, or an invalid (2) view[] or (3) monthno[] parameter to myevent.php, which reveals the path in various error messages.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/469831/100/0/threaded">20070528 myEvent version 1.6 Multiple Path Disclosure Vulnerabilities</ref><ref source="OSVDB" url="http://www.osvdb.org/34272">34272</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2744">2744</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/34542">myevent-myevent-login-path-disclosure(34542)</ref></refs><vuln_soft><prod name="myEvent" vendor="myEvent"><vers num="1.6"/></prod></vuln_soft></entry><entry modified="2007-05-15" name="CVE-2007-0691" published="2007-05-08" reject="1" seq="2007-0691" type="CVE"><desc><descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2007-2066.  Reason: This candidate is a duplicate of CVE-2007-2066.  Notes: All CVE users should reference CVE-2007-2066 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</descript></desc><refs/></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0" modified="2007-06-04" name="CVE-2007-0692" published="2007-05-30" seq="2007-0692" severity="Medium" type="CVE"><desc><descript source="cve">DGNews 2.1 allows remote attackers to obtain sensitive information via a fullnews request to news.php with an invalid newsid parameter, and other unspecified vectors, which reveal the path in various error messages.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/469826/100/0/threaded">20070528 DGNews version 2.1 Path Disclosure Vulnerability</ref><ref adv="1" source="OSVDB" url="http://www.osvdb.org/34226">34226</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2741">2741</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/34540">dgnews-news-path-disclosure(34540)</ref></refs><vuln_soft><prod name="DGNews" vendor="DGNews"><vers num="2.1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-06-04" name="CVE-2007-0693" published="2007-05-30" seq="2007-0693" severity="Medium" type="CVE"><desc><descript source="cve">SQL injection vulnerability in news.php in DGNews 2.1 allows remote attackers to execute arbitrary SQL commands via the catid parameter in a newslist action.  NOTE: this issue can produce resultant cross-site scripting (XSS).</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/469828/100/0/threaded">20070528 DGNews version 2.1 SQL Injection Vulnerability</ref><ref source="BID" url="http://www.securityfocus.com/bid/24201">24201</ref><ref adv="1" source="OSVDB" url="http://www.osvdb.org/34227">34227</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1981">ADV-2007-1981</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25438">25438</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2740">2740</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/34539">dgnews-news-sql-injection(34539)</ref></refs><vuln_soft><prod name="DGNews" vendor="Dian Gemilang"><vers num="1.5.1"/><vers num="2.1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" modified="2007-06-04" name="CVE-2007-0694" published="2007-05-30" seq="2007-0694" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in footer.php in DGNews 2.1 allows remote attackers to inject arbitrary web script or HTML via the copyright parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/469829/100/0/threaded">20070528 DGNews version 2.1 XSS Attack Vulnerability</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/24200">24200</ref><ref adv="1" source="OSVDB" url="http://www.osvdb.org/34228">34228</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1981">ADV-2007-1981</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25438">25438</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2739">2739</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/34537">dgnews-footer-xss(34537)</ref></refs><vuln_soft><prod name="DGNews" vendor="Dian Gemilang"><vers num="2.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-08-03" name="CVE-2007-0695" published="2007-02-03" seq="2007-0695" severity="High" type="CVE"><desc><descript source="cve">Multiple SQL injection vulnerabilities in Free LAN In(tra|ter)net Portal (FLIP) before 1.0-RC3 allow remote attackers to execute arbitrary SQL commands via unspecified vectors.  NOTE: some sources mention the escape_sqlData, implode_sql, and implode_sqlIn functions, but these are protection schemes, not the vulnerable functions.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://sourceforge.net/project/shownotes.php?release_id=481131&amp;group_id=98260"></ref><ref source="VIM" url="http://www.attrition.org/pipermail/vim/2007-February/001282.html">20070203 FLIP SQL injection clarification</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0454">ADV-2007-0454</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/31902">flip-multiple-sql-injection(31902)</ref></refs><vuln_soft><prod name="Free LAN Intra_Internet Portal" vendor="Free LAN Intra_Internet Portal"><vers num="1.0 RC2"/><vers num="1.0 RC1"/><vers num="0.9.0.1029"/><vers num="0.9.0.730"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-02-06" name="CVE-2007-0696" published="2007-02-03" seq="2007-0696" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in error messages in Free LAN In(tra|ter)net Portal (FLIP) before 1.0-RC3 allows remote attackers to inject arbitrary web script or HTML via unspecified parameters, different vectors than CVE-2007-0611.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://sourceforge.net/project/shownotes.php?release_id=481131&amp;group_id=98260"></ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0454">ADV-2007-0454</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/31900">flip-triggererrortext-xss(31900)</ref></refs><vuln_soft><prod name="Free LAN Intra_Internet Portal" vendor="Free LAN Intra_Internet Portal"><vers num="1.0 RC2"/><vers num="1.0 RC1"/><vers num="0.9.0.730"/><vers num="0.9.0.1029"/></prod></vuln_soft></entry><entry CVSS_base_score="6.4" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="4.9" CVSS_score="6.4" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:P)" CVSS_version="2.0" modified="2007-02-06" name="CVE-2007-0697" published="2007-02-03" seq="2007-0697" severity="Medium" type="CVE"><desc><descript source="cve">index2.php in ACGVannu 1.3 and earlier allows remote attackers to change the password or profile of a user via a modified id parameter, related to templates/modif.html.  NOTE: some of these details are obtained from third party information.</descript></desc><loss_types><avail/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://www.milw0rm.com/exploits/3208"></ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/22279">22279</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0388">ADV-2007-0388</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/31893">acgv-multiple-security-bypass(31893)</ref><ref source="MILW0RM" url="http://milw0rm.com/exploits/3208">

3208</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24072">
24072</ref></refs><vuln_soft><prod name="ACGVannu" vendor="Mentiss ACGV"><vers num="1.3" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-02-06" name="CVE-2007-0698" published="2007-02-03" seq="2007-0698" severity="Medium" type="CVE"><desc><descript source="cve">Multiple SQL injection vulnerabilities in ACGVannu 1.3 and earlier allow remote attackers to execute arbitrary SQL commands via the id_mod parameter to templates/modif.html, and other unspecified vectors.  NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0388">ADV-2007-0388</ref><ref source="OSVDB" url="http://www.osvdb.org/34666">34666</ref></refs><vuln_soft><prod name="ACGVannu" vendor="Mentiss ACGV"><vers num="1.3" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2008-03-05" name="CVE-2007-0699" published="2007-02-03" seq="2007-0699" severity="High" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in includes/includes.php in Guernion Sylvain Portail Web Php (aka Gsylvain35 Portail Web, PwP) before 2.5.1.1 allows remote attackers to execute arbitrary PHP code via a URL in the site_path parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/458805/100/0/threaded">20070201 php web portail [remote file include &amp; local file include]</ref><ref source="VIM" url="http://www.attrition.org/pipermail/vim/2007-February/001269.html">20070201 Fwd: php web portail [remote file include &amp; local file include]</ref><ref source="BID" url="http://www.securityfocus.com/bid/22361">22361</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0457">ADV-2007-0457</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32121">portailwebphp-includes-file-include(32121)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2223">2223</ref><ref source="" url="http://sourceforge.net/project/shownotes.php?release_id=480538&amp;group_id=178400"></ref></refs><vuln_soft><prod name="Portail Web Php" vendor="Portail Web Php"><vers num="2.5.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0" modified="2008-03-05" name="CVE-2007-0700" published="2007-02-03" seq="2007-0700" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in index.php in Guernion Sylvain Portail Web Php (aka Gsylvain35 Portail Web, PwP) allows remote attackers to read arbitrary files via a .. (dot dot) in the page parameter.  NOTE: this issue was later reported for 2.5.1.1.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/><design/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/458805/100/0/threaded">20070201 php web portail [remote file include &amp; local file include]</ref><ref source="VIM" url="http://www.attrition.org/pipermail/vim/2007-February/001269.html">20070201 Fwd: php web portail [remote file include &amp; local file include]</ref><ref source="VIM" url="http://www.attrition.org/pipermail/vim/2007-February/001280.html">20070202 Local File Inclusion inconclusive in PwP (was Fwd: php web portail [remote file include &amp; local fileinclude])</ref><ref source="VIM" url="http://www.attrition.org/pipermail/vim/2007-February/001281.html">20070202 Local File Inclusion inconclusive in PwP (was Fwd: php web portail [remote file include &amp; local fileinclude])</ref><ref source="BID" url="http://www.securityfocus.com/bid/22361">22361</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32115">portailwebphp-index-file-include(32115)</ref><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/5182">5182</ref><ref source="BID" url="http://www.securityfocus.com/bid/27962">27962</ref></refs><vuln_soft><prod name="Portail Web Php" vendor="Portail Web Php"><vers num="2.5.1.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-02-06" name="CVE-2007-0701" published="2007-02-03" seq="2007-0701" severity="High" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in inc/common.inc.php in Epistemon 1.0 allows remote attackers to execute arbitrary PHP code via a URL in the inc_path parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="Milw0rm" url="http://www.milw0rm.com/exploits/3247">Exploit 3247</ref><ref source="VIM" url="http://www.attrition.org/pipermail/vim/2007-February/001266.html">20070201 true: Epistemon 1.0 &lt;= Remote File Include Vulnerability</ref><ref source="BID" url="http://www.securityfocus.com/bid/22360">22360</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0459">ADV-2007-0459</ref><ref source="MILW0RM" url="http://milw0rm.com/exploits/3247">

3247</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24003">
24003</ref></refs><vuln_soft><prod name="Epistemon" vendor="Epistemon"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-02-06" name="CVE-2007-0702" published="2007-02-03" seq="2007-0702" severity="High" type="CVE"><desc><descript source="cve">Multiple PHP remote file inclusion vulnerabilities in phpEventMan 1.0.2 allow remote attackers to execute arbitrary PHP code via a URL in the level parameter to (1) Shared/controller/text.ctrl.php or (2) UserMan/controller/common.function.php.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://www.attrition.org/exploits/3246"></ref><ref source="VIM" url="http://www.attrition.org/pipermail/vim/2007-February/001264.html">20070201 true: phpEventMan RFI Vuln.</ref><ref source="BID" url="http://www.securityfocus.com/bid/22358">22358</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0460">ADV-2007-0460</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24000">24000</ref><ref source="MILW0RM" url="http://milw0rm.com/exploits/3246">

3246</ref></refs><vuln_soft><prod name="phpEventMan" vendor="phpEventMan"><vers num="1.0.2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-02-06" name="CVE-2007-0703" published="2007-02-03" seq="2007-0703" severity="High" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in library/StageLoader.php in WebBuilder 2.0 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the GLOBALS[core][module_path] parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://www.milw0rm.com/exploits/3249"></ref><ref source="VIM" url="http://www.attrition.org/pipermail/vim/2007-February/001267.html">20070201 true: WebBuilder &lt;= 2.0 Remote File Include Vulnerability</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0458">ADV-2007-0458</ref><ref source="MILW0RM" url="http://milw0rm.com/exploits/3249">

3249</ref></refs><vuln_soft><prod name="WebBuilder" vendor="WebBuilder"><vers num="2.0" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-02-06" name="CVE-2007-0704" published="2007-02-03" seq="2007-0704" severity="High" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in install.php in Somery 0.4.6 allows remote attackers to execute arbitrary PHP code via a URL in the skindir parameter, a different vector than CVE-2006-4669.  NOTE: the documentation says to remove install.php after installation.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://www.milw0rm.com/exploits/2329"></ref><ref source="VIM" url="http://www.attrition.org/pipermail/vim/2007-February/001265.html">20070201 True: Somery 0.4.6 (skindir install.php) Remote file include</ref><ref source="MILW0RM" url="http://milw0rm.com/exploits/2329">

2329</ref></refs><vuln_soft><prod name="Somery" vendor="Somery"><vers num="0.4.6"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-02-06" name="CVE-2007-0705" published="2007-02-03" seq="2007-0705" severity="High" type="CVE"><desc><descript source="cve">Cross-zone scripting vulnerability in Sleipnir 2.49 and earlier, and Portable Sleipnir 2.45 and earlier, allows remote attackers to bypass Web content zone restrictions via certain script contained in RSS data.  NOTE: some of these details are obtained from third party information.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><env/></vuln_types><range><network/></range><refs><ref source="" url="http://jvn.jp/jp/JVN%2393700808/index.html"></ref><ref source="" url="http://www.fenrir.co.jp/press/20070126_2.html"></ref><ref source="" url="http://www.ipa.go.jp/security/vuln/documents/2006/JVN_93700808.html"></ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0364">ADV-2007-0364</ref><ref source="SECUNIA" url="http://secunia.com/advisories/23927">23927</ref></refs><vuln_soft><prod name="Sleipnir" vendor="Fenrir"><vers num="2.49" prev="1"/></prod><prod name="Portable Sleipnir" vendor="Fenrir"><vers num="2.45" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-02-06" name="CVE-2007-0706" published="2007-02-03" seq="2007-0706" severity="High" type="CVE"><desc><descript source="cve">Cross-zone scripting vulnerability in Darksky RSS bar for Internet Explorer before 1.29, RSS bar for Sleipnir before 1.29, and RSS bar for unDonut before 1.29 allows remote attackers to bypass Web content zone restrictions via certain script contained in RSS data.  NOTE: some of these details are obtained from third party information.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://jvn.jp/jp/JVN%2393700808/index.html"></ref><ref source="" url="http://www.fenrir.co.jp/press/20070126_2.html"></ref><ref source="" url="http://www.ipa.go.jp/security/vuln/documents/2006/JVN_93700808.html"></ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0365">ADV-2007-0365</ref></refs><vuln_soft><prod name="Darksky RSS bar" vendor="Fenrir"><vers edition="Internet Explorer" num="1.28 Release3" prev="1"/><vers edition="Sleipnir" num="1.28 Release3" prev="1"/><vers edition="unDonut" num="1.28 Release3" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-02-06" name="CVE-2007-0707" published="2007-02-03" seq="2007-0707" severity="Medium" type="CVE"><desc><descript source="cve">Stack-based buffer overflow in GOM Player 2.0.12.3375 allows user-assisted remote attackers to execute arbitrary code via a .ASX file with a long URI in the &quot;ref href&quot; tag.  NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/><user_init/></range><refs><ref source="" url="http://www.gomplayer.com/forum/viewtopic.html?t=221"></ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/23994">23994</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32164">
gomplayer-asx-bo(32164)</ref></refs><vuln_soft><prod name="GOM Player" vendor="GOM Player"><vers num="2.0.12.3375"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-02-06" name="CVE-2007-0708" published="2007-02-03" seq="2007-0708" severity="High" type="CVE"><desc><descript source="cve">cmdmon.sys in Comodo Firewall Pro (formerly Comodo Personal Firewall) before 2.4.16.174 does not validate arguments that originate in user mode for the (1) NtConnectPort and (2) NtCreatePort hooked SSDT functions, which allows local users to cause a denial of service (system crash) and possibly gain privileges via invalid arguments.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><local/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/458773/100/0/threaded">20070201 Comodo Multiple insufficient argument validation of hooked SSDT function Vulnerability</ref><ref source="" url="http://www.matousec.com/info/advisories/Comodo-Multiple-insufficient-argument-validation-of-hooked-SSDT-functions.php"></ref><ref source="BID" url="http://www.securityfocus.com/bid/22357">22357</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1017580">1017580</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32059">comodofirewallpro-cmdmon-dos(32059)</ref></refs><vuln_soft><prod name="Comodo Firewall Pro" vendor="Comodo"><vers num="2.4.16.174"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-02-06" name="CVE-2007-0709" published="2007-02-03" seq="2007-0709" severity="High" type="CVE"><desc><descript source="cve">cmdmon.sys in Comodo Firewall Pro (formerly Comodo Personal Firewall) 2.4.16.174 and earlier does not validate arguments that originate in user mode for the (1) NtCreateSection, (2) NtOpenProcess, (3) NtOpenSection, (4) NtOpenThread, and (5) NtSetValueKey hooked SSDT functions, which allows local users to cause a denial of service (system crash) and possibly gain privileges via invalid arguments.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><local/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/458773/100/0/threaded">20070201 Comodo Multiple insufficient argument validation of hooked SSDT function Vulnerability</ref><ref adv="1" source="" url="http://www.matousec.com/info/advisories/Comodo-Multiple-insufficient-argument-validation-of-hooked-SSDT-functions.php"></ref><ref source="BID" url="http://www.securityfocus.com/bid/22357">22357</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1017580">1017580</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32059">comodofirewallpro-cmdmon-dos(32059)</ref></refs><vuln_soft><prod name="Comodo Firewall Pro" vendor="Comodo"><vers num="2.4.16.174" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0" modified="2008-03-03" name="CVE-2007-0710" published="2007-02-16" seq="2007-0710" severity="Low" type="CVE"><desc><descript source="cve">The Bonjour functionality in iChat in Apple Mac OS X 10.3.9 allows remote attackers to cause a denial of service (persistent application crash) via unspecified vectors, possibly related to CVE-2007-0614.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><local/></range><refs><ref patch="1" source="" url="http://docs.info.apple.com/article.html?artnum=305102"></ref><ref source="APPLE" url="http://lists.apple.com/archives/Security-announce/2007/Feb/msg00000.html">APPLE-SA-2007-02-15</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/24198">24198</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/836024">VU#836024</ref><ref source="BID" url="http://www.securityfocus.com/bid/22304">22304</ref><ref source="OSVDB" url="http://www.osvdb.org/32713">32713</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017661">1017661</ref></refs><vuln_soft><prod name="iChat" vendor="Apple"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="10.0" CVSS_score="7.6" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-03-07" name="CVE-2007-0711" published="2007-03-05" seq="2007-0711" severity="High" type="CVE"><desc><descript source="cve">Integer overflow in Apple QuickTime before 7.1.5, when installed on Windows operating systems, allows remote user-assisted attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted 3GP video file.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="APPLE" url="http://lists.apple.com/archives/Security-announce/2007/Mar/msg00000.html">APPLE-SA-2007-03-05</ref><ref source="" url="http://docs.info.apple.com/article.html?artnum=305149"></ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA07-065A.html">
TA07-065A</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/568689">
VU#568689</ref><ref source="BID" url="http://www.securityfocus.com/bid/22827">
22827</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0825">
ADV-2007-0825</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017725">
1017725</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24359">
24359</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32814">
quicktime-3gpvideo-overflow(32814)</ref></refs><vuln_soft><prod name="Quicktime" vendor="Apple"><vers num="7.1.4" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="10.0" CVSS_score="7.6" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-03-07" name="CVE-2007-0712" published="2007-03-05" seq="2007-0712" severity="High" type="CVE"><desc><descript source="cve">Heap-based buffer overflow in Apple QuickTime before 7.1.5 allows remote user-assisted attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted MIDI file.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="APPLE" url="http://lists.apple.com/archives/Security-announce/2007/Mar/msg00000.html">APPLE-SA-2007-03-05</ref><ref source="" url="http://docs.info.apple.com/article.html?artnum=305149"></ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA07-065A.html">
TA07-065A</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/822481">
VU#822481</ref><ref source="BID" url="http://www.securityfocus.com/bid/22827">
22827</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0825">
ADV-2007-0825</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017725">
1017725</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24359">
24359</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32816">
quicktime-midi-files-bo(32816)</ref></refs><vuln_soft><prod name="Quicktime" vendor="Apple"><vers num="7.1.4" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="4.9" CVSS_score="5.8" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:P)" CVSS_version="2.0" modified="2007-03-07" name="CVE-2007-0713" published="2007-03-05" seq="2007-0713" severity="Medium" type="CVE"><desc><descript source="cve">Heap-based buffer overflow in Apple QuickTime before 7.1.5 allows remote user-assisted attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted QuickTime movie file.</descript></desc><loss_types><avail/><int/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" source="APPLE" url="http://lists.apple.com/archives/Security-announce/2007/Mar/msg00000.html">APPLE-SA-2007-03-05</ref><ref adv="1" patch="1" source="" url="http://docs.info.apple.com/article.html?artnum=305149"></ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/461983/100/0/threaded">

20070306 Apple QuickTime Player Remote Heap Overflow</ref><ref source="" url="http://www.piotrbania.com/all/adv/quicktime-heap-adv-7.1.txt"></ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA07-065A.html">
TA07-065A</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/880561">
VU#880561</ref><ref source="BID" url="http://www.securityfocus.com/bid/22827">
22827</ref><ref source="BID" url="http://www.securityfocus.com/bid/22843">
22843</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0825">
ADV-2007-0825</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017725">
1017725</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24359">
24359</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32817">
quicktime-quicktime-bo(32817)</ref></refs><vuln_soft><prod name="Quicktime" vendor="Apple"><vers num="7.0"/><vers num="7.0.1"/><vers num="7.0.2"/><vers num="7.0.3"/><vers num="7.0.4"/><vers num="7.1"/><vers num="7.1.1"/><vers num="7.1.2"/><vers num="7.1.3"/><vers num="7.1.4"/></prod></vuln_soft></entry><entry CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" CVSS_score="9.3" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-04-16" name="CVE-2007-0714" published="2007-03-05" seq="2007-0714" severity="High" type="CVE"><desc><descript source="cve">Integer overflow in Apple QuickTime before 7.1.5 allows remote user-assisted attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted QuickTime movie with a User Data Atom (UDTA) with an Atom size field with a large value.</descript></desc><sols><sol source="nvd">This vulnerability is addressed in latest version of Quicktime 7.1.5
</sol></sols><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/><user_init/></range><refs><ref source="APPLE" url="http://lists.apple.com/archives/Security-announce/2007/Mar/msg00000.html">APPLE-SA-2007-03-05</ref><ref source="" url="http://docs.info.apple.com/article.html?artnum=305149"></ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/461999/100/0/threaded">20070306 Apple QuickTime udta ATOM Integer Overflow</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/462153/100/0/threaded">20070307 ZDI-07-010: Apple Quicktime UDTA Parsing Heap Overflow Vulnerability</ref><ref source="" url="http://secway.org/advisory/AD20070306.txt"></ref><ref adv="1" source="" url="http://www.zerodayinitiative.com/advisories/ZDI-07-010.html"></ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA07-065A.html">TA07-065A</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/861817">VU#861817</ref><ref source="BID" url="http://www.securityfocus.com/bid/22827">22827</ref><ref source="BID" url="http://www.securityfocus.com/bid/22844">22844</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0825">ADV-2007-0825</ref><ref patch="1" source="SECTRACK" url="http://www.securitytracker.com/id?1017725">1017725</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/24359">24359</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32819">quicktime-udta-atoms-overflow(32819)</ref></refs><vuln_soft><prod name="Quicktime" vendor="Apple"><vers num="5.0"/><vers num="5.0.1"/><vers num="5.0.2"/><vers num="6.0"/><vers num="6.1"/><vers num="6.5"/><vers num="6.5.1"/><vers num="6.5.2"/><vers num="7.0"/><vers num="7.0.1"/><vers num="7.0.2"/><vers num="7.0.3"/><vers num="7.0.4"/><vers num="7.1"/><vers num="7.1.1"/><vers num="7.1.2"/><vers num="7.1.3"/><vers num="7.1.4"/></prod></vuln_soft></entry><entry CVSS_base_score="5.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="4.9" CVSS_score="5.8" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:P)" CVSS_version="2.0" modified="2007-03-07" name="CVE-2007-0715" published="2007-03-05" seq="2007-0715" severity="Medium" type="CVE"><desc><descript source="cve">Heap-based buffer overflow in Apple QuickTime before 7.1.5 allows remote user-assisted attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted PICT file.</descript></desc><loss_types><avail/><int/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" source="APPLE" url="http://lists.apple.com/archives/Security-announce/2007/Mar/msg00000.html">APPLE-SA-2007-03-05</ref><ref adv="1" patch="1" source="" url="http://docs.info.apple.com/article.html?artnum=305149"></ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA07-065A.html">
TA07-065A</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/448745">
VU#448745</ref><ref source="BID" url="http://www.securityfocus.com/bid/22827">
22827</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0825">
ADV-2007-0825</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017725">
1017725</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24359">
24359</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32821">
quicktime-pict-file-bo(32821)</ref></refs><vuln_soft><prod name="Quicktime" vendor="Apple"><vers num="7.0"/><vers num="7.0.1"/><vers num="7.0.2"/><vers num="7.0.3"/><vers num="7.0.4"/><vers num="7.1"/><vers num="7.1.1"/><vers num="7.1.2"/><vers num="7.1.3"/><vers num="7.1.4"/></prod></vuln_soft></entry><entry CVSS_base_score="5.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="4.9" CVSS_score="5.8" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:P)" CVSS_version="2.0" modified="2007-06-27" name="CVE-2007-0716" published="2007-03-05" seq="2007-0716" severity="Medium" type="CVE"><desc><descript source="cve">Stack-based buffer overflow in Apple QuickTime before 7.1.5 allows remote user-assisted attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted QTIF file.</descript></desc><loss_types><avail/><int/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" source="APPLE" url="http://lists.apple.com/archives/Security-announce/2007/Mar/msg00000.html">APPLE-SA-2007-03-05</ref><ref adv="1" patch="1" source="" url="http://docs.info.apple.com/article.html?artnum=305149"></ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA07-065A.html">TA07-065A</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/642433">VU#642433</ref><ref source="BID" url="http://www.securityfocus.com/bid/22827">22827</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0825">ADV-2007-0825</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017725">1017725</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24359">24359</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32822">quicktime-qtif-bo(32822)</ref></refs><vuln_soft><prod name="Quicktime" vendor="Apple"><vers num="7.0"/><vers num="7.0.1"/><vers num="7.0.2"/><vers num="7.0.3"/><vers num="7.0.4"/><vers num="7.1"/><vers num="7.1.1"/><vers num="7.1.2"/><vers num="7.1.3"/><vers num="7.1.4"/></prod></vuln_soft></entry><entry CVSS_base_score="5.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="4.9" CVSS_score="5.8" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:P)" CVSS_version="2.0" modified="2007-06-27" name="CVE-2007-0717" published="2007-03-05" seq="2007-0717" severity="Medium" type="CVE"><desc><descript source="cve">Integer overflow in Apple QuickTime before 7.1.5 allows remote user-assisted attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted QTIF file.</descript></desc><loss_types><avail/><int/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" source="APPLE" url="http://lists.apple.com/archives/Security-announce/2007/Mar/msg00000.html">APPLE-SA-2007-03-05</ref><ref adv="1" patch="1" source="" url="http://docs.info.apple.com/article.html?artnum=305149"></ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA07-065A.html">TA07-065A</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/410993">VU#410993</ref><ref source="BID" url="http://www.securityfocus.com/bid/22827">22827</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0825">ADV-2007-0825</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017725">1017725</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24359">24359</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32823">quicktime-qtif-overflow(32823)</ref></refs><vuln_soft><prod name="Quicktime" vendor="Apple"><vers num="7.0"/><vers num="7.0.1"/><vers num="7.0.2"/><vers num="7.0.3"/><vers num="7.0.4"/><vers num="7.1"/><vers num="7.1.1"/><vers num="7.1.2"/><vers num="7.1.3"/><vers num="7.1.4"/></prod></vuln_soft></entry><entry CVSS_base_score="5.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="4.9" CVSS_score="5.8" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:P)" CVSS_version="2.0" modified="2007-06-27" name="CVE-2007-0718" published="2007-03-05" seq="2007-0718" severity="Medium" type="CVE"><desc><descript source="cve">Heap-based buffer overflow in Apple QuickTime before 7.1.5 allows remote user-assisted attackers to cause a denial of service (crash) and possibly execute arbitrary code via a QTIF file with a Video Sample Description containing a Color table ID of 0, which triggers memory corruption when QuickTime assumes that a color table exists.</descript></desc><loss_types><avail/><int/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" source="APPLE" url="http://lists.apple.com/archives/Security-announce/2007/Mar/msg00000.html">APPLE-SA-2007-03-05</ref><ref adv="1" patch="1" source="" url="http://docs.info.apple.com/article.html?artnum=305149"></ref><ref source="IDEFENSE" url="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=486">20070305 Apple QuickTime Color Table ID Heap Corruption Vulnerability</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/462012/100/0/threaded">20070306 [Reversemode Advisory] Apple Quicktime Color ID remote heap corruption</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA07-065A.html">TA07-065A</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/313225">VU#313225</ref><ref source="BID" url="http://www.securityfocus.com/bid/22827">22827</ref><ref source="BID" url="http://www.securityfocus.com/bid/22839">22839</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0825">ADV-2007-0825</ref><ref patch="1" source="SECTRACK" url="http://www.securitytracker.com/id?1017725">1017725</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/24359">24359</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32826">quicktime-qtif-file-bo(32826)</ref></refs><vuln_soft><prod name="Quicktime" vendor="Apple"><vers num="7.0"/><vers num="7.0.1"/><vers num="7.0.2"/><vers num="7.0.3"/><vers num="7.0.4"/><vers num="7.1"/><vers num="7.1.1"/><vers num="7.1.2"/><vers num="7.1.3"/><vers num="7.1.4"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-03-14" name="CVE-2007-0719" published="2007-03-13" seq="2007-0719" severity="Medium" type="CVE"><desc><descript source="cve">Stack-based buffer overflow in Apple Mac OS X 10.3.9 and 10.4 through 10.4.8 allows remote user-assisted attackers to execute arbitrary code via an image with a crafted ColorSync profile.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" patch="1" source="APPLE" url="http://lists.apple.com/archives/security-announce/2007/Mar/msg00002.html">APPLE-SA-2007-03-13</ref><ref source="" url="http://docs.info.apple.com/article.html?artnum=305214"></ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/449440">
VU#449440</ref><ref source="BID" url="http://www.securityfocus.com/bid/22948">
22948</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0930">
ADV-2007-0930</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017751">
1017751</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24479">
24479</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA07-072A.html">TA07-072A</ref><ref source="OSVDB" url="http://www.osvdb.org/34845">34845</ref></refs><vuln_soft><prod name="Mac OS X Server" vendor="Apple"><vers num="10.3.9"/><vers num="10.4"/><vers num="10.4.1"/><vers num="10.4.2"/><vers num="10.4.3"/><vers num="10.4.4"/><vers num="10.4.5"/><vers num="10.4.6"/><vers num="10.4.7"/><vers num="10.4.8"/></prod><prod name="Mac OS X" vendor="Apple"><vers num="10.3.9"/><vers num="10.4"/><vers num="10.4.1"/><vers num="10.4.2"/><vers num="10.4.3"/><vers num="10.4.4"/><vers num="10.4.5"/><vers num="10.4.6"/><vers num="10.4.7"/><vers num="10.4.8"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0" modified="2007-04-10" name="CVE-2007-0720" published="2007-03-13" seq="2007-0720" severity="Medium" type="CVE"><desc><descript source="cve">The CUPS service on multiple platforms allows remote attackers to cause a denial of service (service hang) via a &quot;partially-negotiated&quot; SSL connection, which prevents other requests from being accepted.</descript></desc><loss_types><avail/></loss_types><vuln_types><design/><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="APPLE" url="http://lists.apple.com/archives/security-announce/2007/Mar/msg00002.html">APPLE-SA-2007-03-13</ref><ref source="" url="https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=232243"></ref><ref source="" url="http://docs.info.apple.com/article.html?artnum=305214"></ref><ref source="FEDORA" url="http://fedoranews.org/cms/node/2785">FEDORA-2007-1219</ref><ref source="BID" url="http://www.securityfocus.com/bid/22948">22948</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0930">ADV-2007-0930</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0949">ADV-2007-0949</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017750">1017750</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24479">24479</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24517">24517</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24530">24530</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/463846/100/0/threaded">20070325 FLEA-2007-0003-1: cups</ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200703-28.xml">GLSA-200703-28</ref><ref source="BID" url="http://www.securityfocus.com/bid/23127">23127</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24660">24660</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2007:086">
MDKSA-2007:086</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2007-0123.html">
RHSA-2007:0123</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24878">
24878</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24895">
24895</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2007_9_sr.html">
SUSE-SR:2007:009</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25119">
25119</ref><ref source="" url="http://support.avaya.com/elmodocs2/security/ASA-2007-194.htm"></ref><ref source="" url="https://issues.rpath.com/browse/RPL-1173"></ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:086">MDKSA-2007:086</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2007_14_sr.html">SUSE-SR:2007:014</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA07-072A.html">TA07-072A</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25497">25497</ref><ref source="SECUNIA" url="http://secunia.com/advisories/26083">26083</ref><ref source="SECUNIA" url="http://secunia.com/advisories/26413">26413</ref></refs><vuln_soft><prod name="CUPS" vendor="Easy Software Products"><vers num="1.0.4"/><vers num="1.0.4_8"/><vers num="1.1"/><vers num="1.1.1"/><vers num="1.1.10"/><vers num="1.1.10_1"/><vers num="1.1.11"/><vers num="1.1.12"/><vers num="1.1.13"/><vers num="1.1.14"/><vers num="1.1.15"/><vers num="1.1.16"/><vers num="1.1.17"/><vers num="1.1.18"/><vers num="1.1.19"/><vers num="1.1.19 rc5"/><vers num="1.1.19 rc1"/><vers num="1.1.19 rc2"/><vers num="1.1.19 rc3"/><vers num="1.1.19 rc4"/><vers num="1.1.2"/><vers num="1.1.20"/><vers num="1.1.20 rc1"/><vers num="1.1.20 rc2"/><vers num="1.1.20 rc3"/><vers num="1.1.20 rc4"/><vers num="1.1.20 rc5"/><vers num="1.1.20 rc6"/><vers num="1.1.21"/><vers num="1.1.21 rc1"/><vers num="1.1.21 rc2"/><vers num="1.1.22"/><vers num="1.1.22 rc1"/><vers num="1.1.22 rc2"/><vers num="1.1.23"/><vers num="1.1.23 rc1"/><vers num="1.1.3"/><vers num="1.1.4"/><vers num="1.1.4_2"/><vers num="1.1.4_3"/><vers num="1.1.4_5"/><vers num="1.1.5"/><vers num="1.1.5_1"/><vers num="1.1.5_2"/><vers num="1.1.6"/><vers num="1.1.6_1"/><vers num="1.1.6_2"/><vers num="1.1.6_3"/><vers num="1.1.7"/><vers num="1.1.8"/><vers num="1.1.9"/><vers num="1.1.9_1"/><vers num="1.2.10"/><vers num="1.2.9"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-03-14" name="CVE-2007-0721" published="2007-03-13" seq="2007-0721" severity="Medium" type="CVE"><desc><descript source="cve">Unspecified vulnerability in diskimages-helper in Apple Mac OS X 10.3.9 and 10.4 through 10.4.8 allows remote user-assisted attackers to execute arbitrary code via a crafted compressed disk image that triggers memory corruption.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" patch="1" source="APPLE" url="http://lists.apple.com/archives/security-announce/2007/Mar/msg00002.html">APPLE-SA-2007-03-13</ref><ref source="" url="http://docs.info.apple.com/article.html?artnum=305214"></ref><ref source="BID" url="http://www.securityfocus.com/bid/22948">
22948</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0930">
ADV-2007-0930</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017751">
1017751</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24479">
24479</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA07-072A.html">TA07-072A</ref><ref source="OSVDB" url="http://www.osvdb.org/34846">34846</ref></refs><vuln_soft><prod name="Mac OS X Server" vendor="Apple"><vers num="10.3.9"/><vers num="10.4"/><vers num="10.4.1"/><vers num="10.4.2"/><vers num="10.4.3"/><vers num="10.4.4"/><vers num="10.4.5"/><vers num="10.4.6"/><vers num="10.4.7"/><vers num="10.4.8"/></prod><prod name="Mac OS X" vendor="Apple"><vers num="10.3.9"/><vers num="10.4"/><vers num="10.4.1"/><vers num="10.4.2"/><vers num="10.4.3"/><vers num="10.4.4"/><vers num="10.4.5"/><vers num="10.4.6"/><vers num="10.4.7"/><vers num="10.4.8"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-03-14" name="CVE-2007-0722" published="2007-03-13" seq="2007-0722" severity="Medium" type="CVE"><desc><descript source="cve">Integer overflow in Apple Mac OS X 10.3.9 and 10.4 through 10.4.8 allows remote user-assisted attackers to execute arbitrary code via a crafted AppleSingleEncoding disk image.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" patch="1" source="APPLE" url="http://lists.apple.com/archives/security-announce/2007/Mar/msg00002.html">APPLE-SA-2007-03-13</ref><ref source="" url="http://docs.info.apple.com/article.html?artnum=305214"></ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/124280">
VU#124280</ref><ref source="BID" url="http://www.securityfocus.com/bid/22948">
22948</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0930">
ADV-2007-0930</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017751">
1017751</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24479">
24479</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA07-072A.html">TA07-072A</ref><ref source="OSVDB" url="http://www.osvdb.org/34847">34847</ref></refs><vuln_soft><prod name="Mac OS X Server" vendor="Apple"><vers num="10.3.9"/><vers num="10.4"/><vers num="10.4.1"/><vers num="10.4.2"/><vers num="10.4.3"/><vers num="10.4.4"/><vers num="10.4.5"/><vers num="10.4.6"/><vers num="10.4.7"/><vers num="10.4.8"/></prod><prod name="Mac OS X" vendor="Apple"><vers num="10.3.9"/><vers num="10.4"/><vers num="10.4.1"/><vers num="10.4.2"/><vers num="10.4.3"/><vers num="10.4.4"/><vers num="10.4.5"/><vers num="10.4.6"/><vers num="10.4.7"/><vers num="10.4.8"/></prod></vuln_soft></entry><entry CVSS_base_score="8.5" CVSS_exploit_subscore="6.8" CVSS_impact_subscore="10.0" CVSS_score="8.5" CVSS_vector="(AV:N/AC:M/Au:S/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-03-14" name="CVE-2007-0723" published="2007-03-13" seq="2007-0723" severity="High" type="CVE"><desc><descript source="cve">Unspecified vulnerability in the authentication feature for DirectoryService (DS Plug-Ins) for Apple Mac OS X 10.3.9 and 10.4 through 10.4.8 allows remote authenticated LDAP users to modify the root password and gain privileges via unknown vectors.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><range><network/></range><refs><ref adv="1" patch="1" source="APPLE" url="http://lists.apple.com/archives/security-announce/2007/Mar/msg00002.html">APPLE-SA-2007-03-13</ref><ref source="" url="http://docs.info.apple.com/article.html?artnum=305214"></ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/557064">
VU#557064</ref><ref source="BID" url="http://www.securityfocus.com/bid/22948">
22948</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0930">
ADV-2007-0930</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017751">
1017751</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24479">
24479</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA07-072A.html">TA07-072A</ref><ref source="OSVDB" url="http://www.osvdb.org/34848">34848</ref></refs><vuln_soft><prod name="Mac OS X Server" vendor="Apple"><vers num="10.3.9"/><vers num="10.4"/><vers num="10.4.1"/><vers num="10.4.2"/><vers num="10.4.3"/><vers num="10.4.4"/><vers num="10.4.5"/><vers num="10.4.6"/><vers num="10.4.7"/><vers num="10.4.8"/></prod><prod name="Mac OS X" vendor="Apple"><vers num="10.3.9"/><vers num="10.4"/><vers num="10.4.1"/><vers num="10.4.2"/><vers num="10.4.3"/><vers num="10.4.4"/><vers num="10.4.5"/><vers num="10.4.6"/><vers num="10.4.7"/><vers num="10.4.8"/></prod></vuln_soft></entry><entry CVSS_base_score="6.9" CVSS_exploit_subscore="3.4" CVSS_impact_subscore="10.0" CVSS_score="6.9" CVSS_vector="(AV:L/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-03-14" name="CVE-2007-0724" published="2007-03-13" seq="2007-0724" severity="Medium" type="CVE"><desc><descript source="cve">The IOKit HID interface in Apple Mac OS X 10.3.9 and 10.4 through 10.4.8 does not sufficiently limit access to certain controls, which allows local users to gain privileges by using HID device events to read keystrokes from the console.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="APPLE" url="http://lists.apple.com/archives/security-announce/2007/Mar/msg00002.html">APPLE-SA-2007-03-13</ref><ref source="" url="http://docs.info.apple.com/article.html?artnum=305214"></ref><ref source="BID" url="http://www.securityfocus.com/bid/22948">
22948</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0930">
ADV-2007-0930</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017751">
1017751</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24479">
24479</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32973">
macos-hid-privilege-escalation(32973)</ref><ref source="" url="http://docs.info.apple.com/article.html?artnum=305391"></ref><ref source="APPLE" url="http://lists.apple.com/archives/Security-announce/2007/Apr/msg00001.html">
APPLE-SA-2007-04-19</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1470">
ADV-2007-1470</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017942">
1017942</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24966">
24966</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA07-072A.html">TA07-072A</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA07-109A.html">TA07-109A</ref><ref source="OSVDB" url="http://www.osvdb.org/34855">34855</ref></refs><vuln_soft><prod name="Mac OS X Server" vendor="Apple"><vers num="10.4"/><vers num="10.4.1"/><vers num="10.4.2"/><vers num="10.4.3"/><vers num="10.4.4"/><vers num="10.4.5"/><vers num="10.4.6"/><vers num="10.4.7"/><vers num="10.4.8"/></prod><prod name="Mac OS X" vendor="Apple"><vers num="10.3.9"/><vers num="10.4"/><vers num="10.4.1"/><vers num="10.4.2"/><vers num="10.4.3"/><vers num="10.4.4"/><vers num="10.4.5"/><vers num="10.4.6"/><vers num="10.4.7"/><vers num="10.4.8"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-04-24" name="CVE-2007-0725" published="2007-04-24" seq="2007-0725" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in the AirPortDriver module for AirPort in Apple Mac OS X 10.3.9 through 10.4.9, when running on hardware with the original AirPort wireless card, allows local users to execute arbitrary code by &quot;sending malformed control commands.&quot;</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref source="" url="http://docs.info.apple.com/article.html?artnum=305391"></ref><ref source="APPLE" url="http://lists.apple.com/archives/Security-announce/2007/Apr/msg00001.html">APPLE-SA-2007-04-19</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1470">ADV-2007-1470</ref><ref source="BID" url="http://www.securityfocus.com/bid/23569">
23569</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24966">
24966</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA07-109A.html">TA07-109A</ref><ref source="OSVDB" url="http://www.osvdb.org/34857">34857</ref></refs><vuln_soft><prod name="Mac OS X Server" vendor="Apple"><vers num="10.3.9"/><vers num="10.4"/><vers num="10.4.1"/><vers num="10.4.2"/><vers num="10.4.3"/><vers num="10.4.4"/><vers num="10.4.5"/><vers num="10.4.6"/><vers num="10.4.7"/><vers num="10.4.8"/><vers num="10.4.9"/></prod><prod name="Mac OS X" vendor="Apple"><vers num="10.3.9"/><vers num="10.4"/><vers num="10.4.1"/><vers num="10.4.2"/><vers num="10.4.3"/><vers num="10.4.4"/><vers num="10.4.5"/><vers num="10.4.6"/><vers num="10.4.7"/><vers num="10.4.8"/><vers num="10.4.9"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0" modified="2007-03-14" name="CVE-2007-0726" published="2007-03-13" seq="2007-0726" severity="Medium" type="CVE"><desc><descript source="cve">The SSH key generation process in OpenSSH in Apple Mac OS X 10.3.9 and 10.4 through 10.4.8 allows remote attackers to cause a denial of service by connecting to the server before SSH has finished creating keys, which causes the keys to be regenerated and can break trust relationships that were based on the original keys.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="APPLE" url="http://lists.apple.com/archives/security-announce/2007/Mar/msg00002.html">APPLE-SA-2007-03-13</ref><ref source="" url="http://docs.info.apple.com/article.html?artnum=305214"></ref><ref source="BID" url="http://www.securityfocus.com/bid/22948">
22948</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0930">
ADV-2007-0930</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017756">
1017756</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24479">
24479</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32975">
macos-openssh-dos(32975)</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA07-072A.html">TA07-072A</ref><ref source="OSVDB" url="http://www.osvdb.org/34850">34850</ref></refs><vuln_soft><prod name="Mac OS X Server" vendor="Apple"><vers num="10.3.9"/><vers num="10.4"/><vers num="10.4.1"/><vers num="10.4.2"/><vers num="10.4.3"/><vers num="10.4.4"/><vers num="10.4.5"/><vers num="10.4.6"/><vers num="10.4.7"/><vers num="10.4.8"/></prod><prod name="Mac OS X" vendor="Apple"><vers num="10.3.9"/><vers num="10.4"/><vers num="10.4.1"/><vers num="10.4.2"/><vers num="10.4.3"/><vers num="10.4.4"/><vers num="10.4.5"/><vers num="10.4.6"/><vers num="10.4.7"/><vers num="10.4.8"/></prod></vuln_soft></entry><entry CVSS_base_score="4.4" CVSS_exploit_subscore="3.4" CVSS_impact_subscore="6.4" CVSS_score="4.4" CVSS_vector="(AV:L/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-03-14" name="CVE-2007-0728" published="2007-03-13" seq="2007-0728" severity="Medium" type="CVE"><desc><descript source="cve">Unspecified vulnerability in Apple Mac OS X 10.3.9 and 10.4 through 10.4.8 creates files insecurely while initializing a USB printer, which allows local users to create or overwrite arbitrary files.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><range><local/></range><refs><ref adv="1" patch="1" source="APPLE" url="http://lists.apple.com/archives/security-announce/2007/Mar/msg00002.html">APPLE-SA-2007-03-13</ref><ref source="" url="http://docs.info.apple.com/article.html?artnum=305214"></ref><ref source="BID" url="http://www.securityfocus.com/bid/22948">
22948</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0930">
ADV-2007-0930</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017751">
1017751</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24479">
24479</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32976">
macos-usbprinter-file-overwrite(32976)</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA07-072A.html">TA07-072A</ref><ref source="OSVDB" url="http://www.osvdb.org/34849">34849</ref></refs><vuln_soft><prod name="Mac OS X Server" vendor="Apple"><vers num="10.3.9"/><vers num="10.4"/><vers num="10.4.1"/><vers num="10.4.2"/><vers num="10.4.3"/><vers num="10.4.4"/><vers num="10.4.5"/><vers num="10.4.6"/><vers num="10.4.7"/><vers num="10.4.8"/></prod><prod name="Mac OS X" vendor="Apple"><vers num="10.3.9"/><vers num="10.4"/><vers num="10.4.1"/><vers num="10.4.2"/><vers num="10.4.3"/><vers num="10.4.4"/><vers num="10.4.5"/><vers num="10.4.6"/><vers num="10.4.7"/><vers num="10.4.8"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2008-03-03" name="CVE-2007-0729" published="2007-04-24" seq="2007-0729" severity="High" type="CVE"><desc><descript source="cve">Apple File Protocol (AFP) Client in Apple Mac OS X 10.3.9 through 10.4.9 does not properly clean the environment before executing commands, which allows local users to gain privileges by setting unspecified environment variables.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><range><local/></range><refs><ref patch="1" source="" url="http://docs.info.apple.com/article.html?artnum=305391"></ref><ref source="APPLE" url="http://lists.apple.com/archives/Security-announce/2007/Apr/msg00001.html">APPLE-SA-2007-04-19</ref><ref adv="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/312424">VU#312424</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1470">ADV-2007-1470</ref><ref source="BID" url="http://www.securityfocus.com/bid/23569">23569</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017944">1017944</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24966">24966</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA07-109A.html">TA07-109A</ref><ref source="OSVDB" url="http://www.osvdb.org/34858">34858</ref></refs><vuln_soft><prod name="Mac OS X Server" vendor="Apple"><vers num="10.3.9"/><vers num="10.4"/><vers num="10.4.1"/><vers num="10.4.2"/><vers num="10.4.3"/><vers num="10.4.4"/><vers num="10.4.5"/><vers num="10.4.6"/><vers num="10.4.7"/><vers num="10.4.8"/><vers num="10.4.9"/><vers num="10.0"/><vers num="10.1"/><vers num="10.1.1"/><vers num="10.1.2"/><vers num="10.1.3"/><vers num="10.1.4"/><vers num="10.1.5"/><vers num="10.2"/><vers num="10.2.1"/><vers num="10.2.2"/><vers num="10.2.3"/><vers num="10.2.4"/><vers num="10.2.5"/><vers num="10.2.6"/><vers num="10.2.7"/><vers num="10.2.8"/></prod><prod name="Mac OS X" vendor="Apple"><vers num="10.3.9"/><vers num="10.4"/><vers num="10.4.1"/><vers num="10.4.2"/><vers num="10.4.3"/><vers num="10.4.4"/><vers num="10.4.5"/><vers num="10.4.6"/><vers num="10.4.7"/><vers num="10.4.8"/><vers num="10.4.9"/><vers num="10.0"/><vers num="10.0.1"/><vers num="10.0.2"/><vers num="10.0.3"/><vers num="10.0.4"/><vers num="10.1"/><vers num="10.1.1"/><vers num="10.1.2"/><vers num="10.1.3"/><vers num="10.1.4"/><vers num="10.1.5"/><vers num="10.2"/><vers num="10.2.1"/><vers num="10.2.2"/><vers num="10.2.3"/><vers num="10.2.4"/><vers num="10.2.5"/><vers num="10.2.6"/><vers num="10.2.7"/><vers num="10.2.8"/><vers num="10.3"/><vers num="10.3.1"/><vers num="10.3.2"/><vers num="10.3.3"/><vers num="10.3.4"/><vers num="10.3.5"/><vers num="10.3.6"/><vers num="10.3.7"/><vers num="10.3.8"/></prod><prod name="Mac OS X Preview.app" vendor="Apple"><vers num="3.0.8"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-03-14" name="CVE-2007-0730" published="2007-03-13" seq="2007-0730" severity="Medium" type="CVE"><desc><descript source="cve">Server Manager (servermgrd) in Apple Mac OS X 10.3.9 and 10.4 through 10.4.8 does not sufficiently validate authentication credentials, which allows remote attackers to bypass authentication and modify system configuration.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="APPLE" url="http://lists.apple.com/archives/security-announce/2007/Mar/msg00002.html">APPLE-SA-2007-03-13</ref><ref source="" url="http://docs.info.apple.com/article.html?artnum=305214"></ref><ref source="BID" url="http://www.securityfocus.com/bid/22948">
22948</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0930">
ADV-2007-0930</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017751">
1017751</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24479">
24479</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32978">
macos-servermanager-authentication-bypass(32978)</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA07-072A.html">TA07-072A</ref><ref source="OSVDB" url="http://www.osvdb.org/34851">34851</ref></refs><vuln_soft><prod name="Server Manager" vendor="Apple"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" CVSS_score="9.3" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-03-14" name="CVE-2007-0731" published="2007-03-13" seq="2007-0731" severity="High" type="CVE"><desc><descript source="cve">Stack-based buffer overflow in the Apple-specific Samba module (SMB File Server) in Apple Mac OS X 10.4 through 10.4.8 allows context-dependent attackers to execute arbitrary code via a long ACL.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="APPLE" url="http://lists.apple.com/archives/security-announce/2007/Mar/msg00002.html">APPLE-SA-2007-03-13</ref><ref source="" url="http://docs.info.apple.com/article.html?artnum=305214"></ref><ref source="BID" url="http://www.securityfocus.com/bid/22948">
22948</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0930">
ADV-2007-0930</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017754">
1017754</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24479">
24479</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32979">
macos-smbfileserver-bo(32979)</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA07-072A.html">TA07-072A</ref><ref source="OSVDB" url="http://www.osvdb.org/34852">34852</ref></refs><vuln_soft><prod name="Mac OS X Server" vendor="Apple"><vers num="10.4"/><vers num="10.4.1"/><vers num="10.4.2"/><vers num="10.4.3"/><vers num="10.4.4"/><vers num="10.4.5"/><vers num="10.4.6"/><vers num="10.4.7"/><vers num="10.4.8"/></prod><prod name="Mac OS X" vendor="Apple"><vers num="10.3.9"/><vers num="10.4.1"/><vers num="10.4.2"/><vers num="10.4.3"/><vers num="10.4.4"/><vers num="10.4.5"/><vers num="10.4.6"/><vers num="10.4.7"/><vers num="10.4.8"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-04-24" name="CVE-2007-0732" published="2007-04-24" seq="2007-0732" severity="High" type="CVE"><desc><descript source="cve">Unspecified vulnerability in the CoreServices daemon in CarbonCore in Apple Mac OS X 10.4 through 10.4.9 allows local users to gain privileges via unspecified vectors involving &quot;obtaining a send right to [the] Mach task port.&quot;</descript></desc><sols><sol source="nvd">The vendor has addressed this issue through Mac OS software updates.  </sol></sols><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><range><local/></range><refs><ref source="" url="http://docs.info.apple.com/article.html?artnum=305391"></ref><ref adv="1" source="APPLE" url="http://lists.apple.com/archives/Security-announce/2007/Apr/msg00001.html">APPLE-SA-2007-04-19</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1470">ADV-2007-1470</ref><ref source="BID" url="http://www.securityfocus.com/bid/23569">
23569</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017942">
1017942</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24966">
24966</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA07-109A.html">TA07-109A</ref><ref source="OSVDB" url="http://www.osvdb.org/34859">34859</ref></refs><vuln_soft><prod name="Mac OS X Server" vendor="Apple"><vers num="10.4"/><vers num="10.4.1"/><vers num="10.4.2"/><vers num="10.4.3"/><vers num="10.4.4"/><vers num="10.4.5"/><vers num="10.4.6"/><vers num="10.4.7"/><vers num="10.4.8"/><vers num="10.4.9"/></prod><prod name="Mac OS X" vendor="Apple"><vers num="10.4"/><vers num="10.4.1"/><vers num="10.4.2"/><vers num="10.4.3"/><vers num="10.4.4"/><vers num="10.4.5"/><vers num="10.4.6"/><vers num="10.4.7"/><vers num="10.4.8"/><vers num="10.4.9"/></prod></vuln_soft></entry><entry CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" CVSS_score="9.3" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-03-14" name="CVE-2007-0733" published="2007-03-13" seq="2007-0733" severity="High" type="CVE"><desc><descript source="cve">Unspecified vulnerability in ImageIO in Apple Mac OS X 10.3.9 and 10.4 through 10.4.8 allows remote user-assisted attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted RAW image that triggers memory corruption.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" patch="1" source="APPLE" url="http://lists.apple.com/archives/security-announce/2007/Mar/msg00002.html">APPLE-SA-2007-03-13</ref><ref source="" url="http://docs.info.apple.com/article.html?artnum=305214"></ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/873868">
VU#873868</ref><ref source="BID" url="http://www.securityfocus.com/bid/22948">
22948</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0930">
ADV-2007-0930</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017758">
1017758</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24479">
24479</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32974">
macos-imageio-code-execution(32974)</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA07-072A.html">TA07-072A</ref><ref source="OSVDB" url="http://www.osvdb.org/34853">34853</ref></refs><vuln_soft><prod name="ImageIO" vendor="Apple"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.4" CVSS_exploit_subscore="5.5" CVSS_impact_subscore="6.4" CVSS_score="5.4" CVSS_vector="(AV:A/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-08-02" name="CVE-2007-0734" published="2007-04-10" seq="2007-0734" severity="Medium" type="CVE"><desc><descript source="cve">fsck, as used by the AirPort Disk feature of the AirPort Extreme Base Station with 802.11n before Firmware Update 7.1, and by Apple Mac OS X 10.3.9 through 10.4.9, does not properly enforce password protection of a USB hard drive, which allows context-dependent attackers to list arbitrary directories or execute arbitrary code, resulting from memory corruption.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><design/></vuln_types><range><local_network/></range><refs><ref adv="1" patch="1" source="" url="http://docs.info.apple.com/article.html?artnum=305366"></ref><ref adv="1" source="APPLE" url="http://lists.apple.com/archives/security-announce/2007/Apr/msg00000.html">APPLE-SA-2007-04-09</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1308">ADV-2007-1308</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24830">24830</ref><ref source="BID" url="http://www.securityfocus.com/bid/23396">23396</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017889">1017889</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33527">airportextreme-airportdisk-info-disclosure(33527)</ref><ref source="" url="http://docs.info.apple.com/article.html?artnum=305391"></ref><ref source="APPLE" url="http://lists.apple.com/archives/Security-announce/2007/Apr/msg00001.html">APPLE-SA-2007-04-19</ref><ref source="BID" url="http://www.securityfocus.com/bid/23569">23569</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1470">ADV-2007-1470</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017942">1017942</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24966">24966</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA07-109A.html">TA07-109A</ref></refs><vuln_soft><prod name="Mac OS X" vendor="Apple"><vers num="10.3.9"/><vers num="10.4"/><vers num="10.4.1"/><vers num="10.4.2"/><vers num="10.4.3"/><vers num="10.4.4"/><vers num="10.4.5"/><vers num="10.4.6"/><vers num="10.4.7"/><vers num="10.4.8"/><vers num="10.4.9"/></prod></vuln_soft></entry><entry CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" CVSS_score="9.3" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-04-24" name="CVE-2007-0735" published="2007-04-24" seq="2007-0735" severity="High" type="CVE"><desc><descript source="cve">Use-after-free vulnerability in Libinfo in Apple Mac OS X 10.3.9 through 10.4.9 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via unspecified vectors involving crafted web pages that trigger certain error conditions that are not properly reported in certain circumstances, resulting in accessing deallocated memory.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><exception/></vuln_types><range><network/><user_init/></range><refs><ref source="" url="http://docs.info.apple.com/article.html?artnum=305391"></ref><ref source="APPLE" url="http://lists.apple.com/archives/Security-announce/2007/Apr/msg00001.html">APPLE-SA-2007-04-19</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/23569">23569</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1470">ADV-2007-1470</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017942">
1017942</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24966">
24966</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA07-109A.html">TA07-109A</ref><ref source="OSVDB" url="http://www.osvdb.org/34860">34860</ref></refs><vuln_soft><prod name="Mac OS X Server" vendor="Apple"><vers num="10.3.9"/><vers num="10.4"/><vers num="10.4.1"/><vers num="10.4.2"/><vers num="10.4.3"/><vers num="10.4.4"/><vers num="10.4.5"/><vers num="10.4.6"/><vers num="10.4.7"/><vers num="10.4.8"/><vers num="10.4.9"/></prod><prod name="Mac OS X" vendor="Apple"><vers num="10.3.9"/><vers num="10.4"/><vers num="10.4.1"/><vers num="10.4.2"/><vers num="10.4.3"/><vers num="10.4.4"/><vers num="10.4.5"/><vers num="10.4.6"/><vers num="10.4.7"/><vers num="10.4.8"/><vers num="10.4.9"/></prod></vuln_soft></entry><entry CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" CVSS_score="9.3" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-04-24" name="CVE-2007-0736" published="2007-04-24" seq="2007-0736" severity="High" type="CVE"><desc><descript source="cve">Integer overflow in the RPC library in Libinfo in Apple Mac OS X 10.3.9 through 10.4.9 allows remote attackers to execute arbitrary code via crafted requests to portmap.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref source="" url="http://docs.info.apple.com/article.html?artnum=305391"></ref><ref source="APPLE" url="http://lists.apple.com/archives/Security-announce/2007/Apr/msg00001.html">APPLE-SA-2007-04-19</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/23569">23569</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1470">ADV-2007-1470</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017942">
1017942</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24966">
24966</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33782">
macos-rpc-code-execution(33782)</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA07-109A.html">TA07-109A</ref><ref source="OSVDB" url="http://www.osvdb.org/34861">34861</ref></refs><vuln_soft><prod name="Mac OS X Server" vendor="Apple"><vers num="10.3.9"/><vers num="10.4"/><vers num="10.4.1"/><vers num="10.4.2"/><vers num="10.4.3"/><vers num="10.4.4"/><vers num="10.4.5"/><vers num="10.4.6"/><vers num="10.4.7"/><vers num="10.4.8"/><vers num="10.4.9"/></prod><prod name="Mac OS X" vendor="Apple"><vers num="10.3.9"/><vers num="10.4"/><vers num="10.4.1"/><vers num="10.4.2"/><vers num="10.4.3"/><vers num="10.4.4"/><vers num="10.4.5"/><vers num="10.4.6"/><vers num="10.4.7"/><vers num="10.4.8"/><vers num="10.4.9"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-04-24" name="CVE-2007-0737" published="2007-04-24" seq="2007-0737" severity="Medium" type="CVE"><desc><descript source="cve">The Login Window in Apple Mac OS X 10.3.9 through 10.4.9 does not properly check certain environment variables, which allows local users to gain privileges via unspecified vectors.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><env/></vuln_types><range><local/></range><refs><ref source="" url="http://docs.info.apple.com/article.html?artnum=305391"></ref><ref source="APPLE" url="http://lists.apple.com/archives/Security-announce/2007/Apr/msg00001.html">APPLE-SA-2007-04-19</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/23569">23569</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1470">ADV-2007-1470</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017939">1017939</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24966">
24966</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA07-109A.html">TA07-109A</ref><ref source="OSVDB" url="http://www.osvdb.org/34862">34862</ref></refs><vuln_soft><prod name="Mac OS X" vendor="Apple"><vers num="10.3.9"/><vers num="10.4"/><vers num="10.4.1"/><vers num="10.4.2"/><vers num="10.4.3"/><vers num="10.4.4"/><vers num="10.4.5"/><vers num="10.4.6"/><vers num="10.4.7"/><vers num="10.4.8"/><vers num="10.4.9"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-04-24" name="CVE-2007-0738" published="2007-04-24" seq="2007-0738" severity="Medium" type="CVE"><desc><descript source="cve">The Login Window in Apple Mac OS X 10.4 through 10.4.9 does not display the screen saver authentication dialog in certain circumstances when waking from sleep, even though the &quot;require a password to wake the computer from sleep&quot; option is enabled, which allows local users to bypass authentication controls.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref source="" url="http://docs.info.apple.com/article.html?artnum=305391"></ref><ref source="APPLE" url="http://lists.apple.com/archives/Security-announce/2007/Apr/msg00001.html">APPLE-SA-2007-04-19</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/23569">23569</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1470">ADV-2007-1470</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017939">1017939</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24966">
24966</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA07-109A.html">TA07-109A</ref><ref source="OSVDB" url="http://www.osvdb.org/34863">34863</ref></refs><vuln_soft><prod name="Mac OS X" vendor="Apple"><vers num="10.4"/><vers num="10.4.1"/><vers num="10.4.2"/><vers num="10.4.3"/><vers num="10.4.4"/><vers num="10.4.5"/><vers num="10.4.6"/><vers num="10.4.7"/><vers num="10.4.8"/><vers num="10.4.9"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-04-24" name="CVE-2007-0739" published="2007-04-24" seq="2007-0739" severity="Medium" type="CVE"><desc><descript source="cve">The Login Window in Apple Mac OS X 10.4 through 10.4.9 displays the software update window beneath the loginwindow authentication dialog in certain circumstances related to running scheduled tasks, which allows local users to bypass authentication controls.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref source="" url="http://docs.info.apple.com/article.html?artnum=305391"></ref><ref source="APPLE" url="http://lists.apple.com/archives/Security-announce/2007/Apr/msg00001.html">APPLE-SA-2007-04-19</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/23569">23569</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1470">ADV-2007-1470</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017939">1017939</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24966">
24966</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA07-109A.html">TA07-109A</ref><ref source="OSVDB" url="http://www.osvdb.org/34864">34864</ref></refs><vuln_soft><prod name="Mac OS X" vendor="Apple"><vers num="10.4"/><vers num="10.4.1"/><vers num="10.4.2"/><vers num="10.4.3"/><vers num="10.4.4"/><vers num="10.4.5"/><vers num="10.4.6"/><vers num="10.4.7"/><vers num="10.4.8"/><vers num="10.4.9"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-05-29" name="CVE-2007-0740" published="2007-05-24" seq="2007-0740" severity="Medium" type="CVE"><desc><descript source="cve">Alias Manager in Apple Mac OS X 10.3.9 and 10.4.9 does not display files with the same name in mounted disk images that have the same name, which might allow user-assisted attackers to trick a user into executing malicious files.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><design/></vuln_types><range><network/><user_init/></range><refs><ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2007/May/msg00004.html">APPLE-SA-2007-05-24</ref><ref source="" url="http://docs.info.apple.com/article.html?artnum=305530"></ref><ref source="BID" url="http://www.securityfocus.com/bid/24144">24144</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1939">ADV-2007-1939</ref><ref source="OSVDB" url="http://www.osvdb.org/35147">35147</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1018121">1018121</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25402">25402</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/34498">macos-diskimage-code-execution(34498)</ref></refs><vuln_soft><prod name="Mac OS X" vendor="Apple"><vers num="10.3.9"/><vers num="10.4.9"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-04-24" name="CVE-2007-0741" published="2007-04-24" seq="2007-0741" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in natd in network_cmds in Apple Mac OS X 10.3.9 through 10.4.9, when Internet Sharing is enabled, allows remote attackers to execute arbitrary code via malformed RTSP packets.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref source="" url="http://docs.info.apple.com/article.html?artnum=305391"></ref><ref source="APPLE" url="http://lists.apple.com/archives/Security-announce/2007/Apr/msg00001.html">APPLE-SA-2007-04-19</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/23569">23569</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1470">ADV-2007-1470</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017942">
1017942</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24966">
24966</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA07-109A.html">TA07-109A</ref><ref source="OSVDB" url="http://www.osvdb.org/34865">34865</ref></refs><vuln_soft><prod name="Mac OS X" vendor="Apple"><vers num="10.3.9"/><vers num="10.4"/><vers num="10.4.1"/><vers num="10.4.2"/><vers num="10.4.3"/><vers num="10.4.4"/><vers num="10.4.5"/><vers num="10.4.6"/><vers num="10.4.7"/><vers num="10.4.8"/><vers num="10.4.9"/></prod></vuln_soft></entry><entry CVSS_base_score="7.8" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.9" CVSS_score="7.8" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:N/A:N)" CVSS_version="2.0" modified="2007-04-24" name="CVE-2007-0742" published="2007-04-24" seq="2007-0742" severity="High" type="CVE"><desc><descript source="cve">The WebFoundation framework in Apple Mac OS X 10.3.9 and earlier allows subdomain cookies to be accessed by the parent domain, which allows remote attackers to obtain sensitive information.</descript></desc><loss_types><conf/></loss_types><range><network/></range><refs><ref source="" url="http://docs.info.apple.com/article.html?artnum=305391"></ref><ref source="APPLE" url="http://lists.apple.com/archives/Security-announce/2007/Apr/msg00001.html">APPLE-SA-2007-04-19</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/23569">23569</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1470">ADV-2007-1470</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017942">
1017942</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24966">
24966</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA07-109A.html">TA07-109A</ref><ref source="OSVDB" url="http://www.osvdb.org/34866">34866</ref></refs><vuln_soft><prod name="Mac OS X" vendor="Apple"><vers num="10.3.9" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.9" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.9" CVSS_score="4.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:N/A:N)" CVSS_version="2.0" modified="2007-04-24" name="CVE-2007-0743" published="2007-04-24" seq="2007-0743" severity="Medium" type="CVE"><desc><descript source="cve">URLMount in Apple Mac OS X 10.3.9 through 10.4.9 passes the username and password credentials for mounting filesystems on SMB servers as command line arguments to the mount_sub command, which may allow local users to obtain sensitive information by listing the process.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref source="" url="http://docs.info.apple.com/article.html?artnum=305391"></ref><ref source="APPLE" url="http://lists.apple.com/archives/Security-announce/2007/Apr/msg00001.html">APPLE-SA-2007-04-19</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/23569">23569</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1470">ADV-2007-1470</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017942">
1017942</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24966">
24966</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA07-109A.html">TA07-109A</ref><ref source="OSVDB" url="http://www.osvdb.org/34867">34867</ref></refs><vuln_soft><prod name="Mac OS X" vendor="Apple"><vers num="10.3.9"/><vers num="10.4"/><vers num="10.4.1"/><vers num="10.4.2"/><vers num="10.4.3"/><vers num="10.4.4"/><vers num="10.4.5"/><vers num="10.4.6"/><vers num="10.4.7"/><vers num="10.4.8"/><vers num="10.4.9"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-04-25" name="CVE-2007-0744" published="2007-04-24" seq="2007-0744" severity="High" type="CVE"><desc><descript source="cve">SMB in Apple Mac OS X 10.3.9 through 10.4.9 does not properly clean the environment when executing commands, which allows local users to gain privileges by setting unspecified environment variables.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref source="" url="http://docs.info.apple.com/article.html?artnum=305391"></ref><ref source="APPLE" url="http://lists.apple.com/archives/Security-announce/2007/Apr/msg00001.html">APPLE-SA-2007-04-19</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/23569">23569</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1470">ADV-2007-1470</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24966">
24966</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA07-109A.html">TA07-109A</ref><ref source="OSVDB" url="http://www.osvdb.org/34868">34868</ref></refs><vuln_soft><prod name="Mac OS X Server" vendor="Apple"><vers num="10.3.9"/><vers num="10.4"/><vers num="10.4.1"/><vers num="10.4.2"/><vers num="10.4.3"/><vers num="10.4.4"/><vers num="10.4.5"/><vers num="10.4.6"/><vers num="10.4.7"/><vers num="10.4.8"/><vers num="10.4.9"/></prod><prod name="Mac OS X" vendor="Apple"><vers num="10.3.9"/><vers num="10.4"/><vers num="10.4.1"/><vers num="10.4.2"/><vers num="10.4.3"/><vers num="10.4.4"/><vers num="10.4.5"/><vers num="10.4.6"/><vers num="10.4.7"/><vers num="10.4.8"/><vers num="10.4.9"/></prod></vuln_soft></entry><entry CVSS_base_score="7.1" CVSS_exploit_subscore="5.1" CVSS_impact_subscore="9.2" CVSS_score="7.1" CVSS_vector="(AV:A/AC:L/Au:S/C:C/I:C/A:N)" CVSS_version="2.0" modified="2007-05-03" name="CVE-2007-0745" published="2007-05-02" seq="2007-0745" severity="High" type="CVE"><desc><descript source="cve">The Apple Security Update 2007-004 uses an incorrect configuration file for FTPServer in Apple Mac OS X Server 10.4.9, which might allow remote authenticated users to access additional directories.</descript></desc><loss_types><conf/><int/></loss_types><vuln_types><config/></vuln_types><range><local_network/></range><refs><ref patch="1" source="APPLE" url="http://lists.apple.com/archives/security-announce/2007/May/msg00000.html">APPLE-SA-2007-05-01</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017990">
1017990</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/34001">
macos-ftpserver-unauthorized-access(34001)</ref><ref source="OSVDB" url="http://www.osvdb.org/34869">34869</ref></refs><vuln_soft><prod name="Mac OS X Server" vendor="Apple"><vers num="10.4.9"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-04-25" name="CVE-2007-0746" published="2007-04-24" seq="2007-0746" severity="High" type="CVE"><desc><descript source="cve">Heap-based buffer overflow in the VideoConference framework in Apple Mac OS X 10.3.9 through 10.4.9 allows remote attackers to execute arbitrary code via a &quot;crafted SIP packet when initializing an audio/video conference&quot;.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref source="" url="http://docs.info.apple.com/article.html?artnum=305391"></ref><ref source="APPLE" url="http://lists.apple.com/archives/Security-announce/2007/Apr/msg00001.html">APPLE-SA-2007-04-19</ref><ref adv="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/969969">VU#969969</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/23569">23569</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1470">ADV-2007-1470</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017942">
1017942</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24966">
24966</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA07-109A.html">TA07-109A</ref><ref source="OSVDB" url="http://www.osvdb.org/34870">34870</ref></refs><vuln_soft><prod name="Mac OS X Server" vendor="Apple"><vers num="10.3.9"/><vers num="10.4"/><vers num="10.4.1"/><vers num="10.4.2"/><vers num="10.4.3"/><vers num="10.4.4"/><vers num="10.4.5"/><vers num="10.4.6"/><vers num="10.4.7"/><vers num="10.4.8"/><vers num="10.4.9"/></prod><prod name="Mac OS X" vendor="Apple"><vers num="10.3.9"/><vers num="10.4"/><vers num="10.4.1"/><vers num="10.4.2"/><vers num="10.4.3"/><vers num="10.4.4"/><vers num="10.4.5"/><vers num="10.4.6"/><vers num="10.4.7"/><vers num="10.4.8"/><vers num="10.4.9"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-04-25" name="CVE-2007-0747" published="2007-04-24" seq="2007-0747" severity="High" type="CVE"><desc><descript source="cve">load_webdav in Apple Mac OS X 10.3.9 through 10.4.9 does not properly clean the environment when mounting a WebDAV filesystem, which allows local users to gain privileges by setting unspecified environment variables.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref source="" url="http://docs.info.apple.com/article.html?artnum=305391"></ref><ref source="APPLE" url="http://lists.apple.com/archives/Security-announce/2007/Apr/msg00001.html">APPLE-SA-2007-04-19</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/23569">23569</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1470">ADV-2007-1470</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/474969">
VU#474969</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017942">
1017942</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24966">
24966</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA07-109A.html">TA07-109A</ref><ref source="OSVDB" url="http://www.osvdb.org/34871">34871</ref></refs><vuln_soft><prod name="Mac OS X Server" vendor="Apple"><vers num="10.3.9"/><vers num="10.4"/><vers num="10.4.1"/><vers num="10.4.2"/><vers num="10.4.3"/><vers num="10.4.4"/><vers num="10.4.5"/><vers num="10.4.6"/><vers num="10.4.7"/><vers num="10.4.8"/><vers num="10.4.9"/></prod><prod name="Mac OS X" vendor="Apple"><vers num="10.3.9"/><vers num="10.4"/><vers num="10.4.1"/><vers num="10.4.2"/><vers num="10.4.3"/><vers num="10.4.4"/><vers num="10.4.5"/><vers num="10.4.6"/><vers num="10.4.7"/><vers num="10.4.8"/><vers num="10.4.9"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-05-14" name="CVE-2007-0748" published="2007-05-13" seq="2007-0748" severity="High" type="CVE"><desc><descript source="cve">Heap-based buffer overflow in Apple Darwin Streaming Proxy, when using Darwin Streaming Server before 5.5.5, allows remote attackers to execute arbitrary code via multiple trackID values in a SETUP RTSP request.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/><exception/></vuln_types><range><network/></range><refs><ref patch="1" source="IDEFENSE" url="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=533">20070510 Apple Darwin Streaming Proxy Multiple Vulnerabilities</ref><ref patch="1" source="" url="http://docs.info.apple.com/article.html?artnum=305495"></ref><ref source="APPLE" url="http://lists.apple.com/archives/Security-announce/2007/May/msg00002.html">APPLE-SA-2007-05-10</ref><ref source="BID" url="http://www.securityfocus.com/bid/23918">23918</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1770">ADV-2007-1770</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/25193">25193</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1018047">
1018047</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/34225">
darwin-trackid-bo(34225)</ref></refs><vuln_soft><prod name="Darwin Streaming Server" vendor="Apple"><vers num="4.1.2"/><vers num="5.5.4"/><vers num="5.0.1"/><vers num="4.1.3"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-05-14" name="CVE-2007-0749" published="2007-05-13" seq="2007-0749" severity="High" type="CVE"><desc><descript source="cve">Multiple stack-based buffer overflows in the is_command function in proxy.c in Apple Darwin Streaming Proxy, when using Darwin Streaming Server before 5.5.5, allow remote attackers to execute arbitrary code via a long (1) cmd or (2) server value in an RTSP request.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/><exception/></vuln_types><range><network/></range><refs><ref patch="1" source="IDEFENSE" url="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=533">20070510 Apple Darwin Streaming Proxy Multiple Vulnerabilities</ref><ref patch="1" source="" url="http://docs.info.apple.com/article.html?artnum=305495"></ref><ref patch="1" source="APPLE" url="http://lists.apple.com/archives/Security-announce/2007/May/msg00002.html">APPLE-SA-2007-05-10</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/23918">23918</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1770">ADV-2007-1770</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/25193">25193</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1018047">
1018047</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/34222">
darwin-iscommand-bo(34222)</ref></refs><vuln_soft><prod name="Darwin Streaming Server" vendor="Apple"><vers num="4.1.2"/><vers num="5.5.4"/><vers num="5.0.1"/><vers num="4.1.3"/></prod></vuln_soft></entry><entry CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" CVSS_score="9.3" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-05-29" name="CVE-2007-0750" published="2007-05-24" seq="2007-0750" severity="High" type="CVE"><desc><descript source="cve">Integer overflow in CoreGraphics in Apple Mac OS X 10.4 up to 10.4.9 allows remote user-assisted attackers to cause a denial of service (application termination) or execute arbitrary code via a crafted PDF file.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/><user_init/></range><refs><ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2007/May/msg00004.html">APPLE-SA-2007-05-24</ref><ref source="" url="http://docs.info.apple.com/article.html?artnum=305530"></ref><ref source="BID" url="http://www.securityfocus.com/bid/24144">24144</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1939">ADV-2007-1939</ref><ref source="OSVDB" url="http://www.osvdb.org/35146">35146</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1018114">1018114</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25402">25402</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/34499">macos-pdf-bo(34499)</ref></refs><vuln_soft><prod name="Mac OS X Server" vendor="Apple"><vers num="10.4"/><vers num="10.4.1"/><vers num="10.4.2"/><vers num="10.4.3"/><vers num="10.4.4"/><vers num="10.4.5"/><vers num="10.4.6"/><vers num="10.4.7"/><vers num="10.4.8"/><vers num="10.4.9"/></prod><prod name="Mac OS X" vendor="Apple"><vers num="10.4"/><vers num="10.4.1"/><vers num="10.4.2"/><vers num="10.4.3"/><vers num="10.4.4"/><vers num="10.4.5"/><vers num="10.4.6"/><vers num="10.4.7"/><vers num="10.4.8"/><vers num="10.4.9"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0" modified="2007-05-29" name="CVE-2007-0751" published="2007-05-24" seq="2007-0751" severity="Low" type="CVE"><desc><descript source="cve">A cleanup script in crontabs in Apple Mac OS X 10.3.9 and 10.4.9 might delete filesystems that have been mounted in /tmp, which might allow local users to cause a denial of service, related to the find command.</descript></desc><loss_types><avail/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2007/May/msg00004.html">APPLE-SA-2007-05-24</ref><ref source="" url="http://docs.info.apple.com/article.html?artnum=305530"></ref><ref source="BID" url="http://www.securityfocus.com/bid/24144">24144</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1939">ADV-2007-1939</ref><ref source="OSVDB" url="http://www.osvdb.org/35145">35145</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1018117">1018117</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25402">25402</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/34500">macos-tmpfilesystem-dos(34500)</ref></refs><vuln_soft><prod name="Mac OS X Server" vendor="Apple"><vers num="10.4"/><vers num="10.4.1"/><vers num="10.4.2"/><vers num="10.4.3"/><vers num="10.4.4"/><vers num="10.4.5"/><vers num="10.4.6"/><vers num="10.4.7"/><vers num="10.4.8"/><vers num="10.4.9"/><vers num="10.3"/><vers num="10.3.1"/><vers num="10.3.2"/><vers num="10.3.3"/><vers num="10.3.4"/><vers num="10.3.5"/><vers num="10.3.6"/><vers num="10.3.7"/><vers num="10.3.8"/><vers num="10.3.9"/></prod><prod name="Mac OS X" vendor="Apple"><vers num="10.4"/><vers num="10.4.1"/><vers num="10.4.2"/><vers num="10.4.3"/><vers num="10.4.4"/><vers num="10.4.5"/><vers num="10.4.6"/><vers num="10.4.7"/><vers num="10.4.8"/><vers num="10.4.9"/><vers num="10.3"/><vers num="10.3.1"/><vers num="10.3.2"/><vers num="10.3.3"/><vers num="10.3.4"/><vers num="10.3.5"/><vers num="10.3.6"/><vers num="10.3.7"/><vers num="10.3.8"/><vers num="10.3.9"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-05-29" name="CVE-2007-0752" published="2007-05-24" seq="2007-0752" severity="High" type="CVE"><desc><descript source="cve">The PPP daemon (pppd) in Apple Mac OS X 10.4.8 checks ownership of the stdin file descriptor to determine if the invoker has sufficient privileges, which allows local users to load arbitrary plugins and gain root privileges by bypassing this check.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><access/><design/></vuln_types><range><local/></range><refs><ref adv="1" source="IDEFENSE" url="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=537">20070524 Apple Computer Mac OS X pppd Plugin Loading Privilege Escalation Vulnerability</ref><ref source="" url="http://docs.info.apple.com/article.html?artnum=305530"></ref><ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2007/May/msg00004.html">APPLE-SA-2007-05-24</ref><ref source="BID" url="http://www.securityfocus.com/bid/24144">24144</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1939">ADV-2007-1939</ref><ref source="OSVDB" url="http://www.osvdb.org/35144">35144</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1018124">1018124</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25402">25402</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/34503">macos-pppd-privilege-escalation(34503)</ref></refs><vuln_soft><prod name="Mac OS X Server" vendor="Apple"><vers num="10.4.8"/></prod><prod name="Mac OS X" vendor="Apple"><vers num="10.4.8"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-12-29" name="CVE-2007-0753" published="2007-05-24" seq="2007-0753" severity="High" type="CVE"><desc><descript source="cve">Format string vulnerability in the VPN daemon (vpnd) in Apple Mac OS X 10.3.9 and 10.4.9 allows local users to execute arbitrary code via the -i parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input/></vuln_types><range><local/></range><refs><ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2007/May/msg00004.html">APPLE-SA-2007-05-24</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/469882/100/0/threaded">20070529 Mac OS X vpnd local format string</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/469889/100/0/threaded">20070529 Re: Mac OS X vpnd local format string</ref><ref source="" url="http://docs.info.apple.com/article.html?artnum=305530"></ref><ref source="BID" url="http://www.securityfocus.com/bid/24144">24144</ref><ref source="BID" url="http://www.securityfocus.com/bid/24208">24208</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1939">ADV-2007-1939</ref><ref source="OSVDB" url="http://www.osvdb.org/35143">35143</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1018125">1018125</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/25402">25402</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/34505">macos-vpnd-format-string(34505)</ref></refs><vuln_soft><prod name="Mac OS X Server" vendor="Apple"><vers num="10.4"/><vers num="10.4.1"/><vers num="10.4.2"/><vers num="10.4.3"/><vers num="10.4.4"/><vers num="10.4.5"/><vers num="10.4.6"/><vers num="10.4.7"/><vers num="10.4.8"/><vers num="10.4.9"/><vers num="10.3"/><vers num="10.3.1"/><vers num="10.3.2"/><vers num="10.3.3"/><vers num="10.3.4"/><vers num="10.3.5"/><vers num="10.3.6"/><vers num="10.3.7"/><vers num="10.3.8"/><vers num="10.3.9"/></prod><prod name="Mac OS X" vendor="Apple"><vers num="10.4"/><vers num="10.4.1"/><vers num="10.4.2"/><vers num="10.4.3"/><vers num="10.4.4"/><vers num="10.4.5"/><vers num="10.4.6"/><vers num="10.4.7"/><vers num="10.4.8"/><vers num="10.4.9"/><vers num="10.3"/><vers num="10.3.1"/><vers num="10.3.2"/><vers num="10.3.3"/><vers num="10.3.4"/><vers num="10.3.5"/><vers num="10.3.6"/><vers num="10.3.7"/><vers num="10.3.8"/><vers num="10.3.9"/></prod></vuln_soft></entry><entry CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" CVSS_score="9.3" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-05-15" name="CVE-2007-0754" published="2007-05-14" seq="2007-0754" severity="High" type="CVE"><desc><descript source="cve">Heap-based buffer overflow in Apple QuickTime before 7.1.3 allows user-assisted remote attackers to execute arbitrary code via a crafted Sample Table Sample Descriptor (STSD) atom size in a QuickTime movie.</descript></desc><sols><sol source="nvd">This vulnerability is addressed in the following product release:
Apple, QuickTime, 7.1.3</sol></sols><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/><user_init/></range><refs><ref patch="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/468305/100/0/threaded">20070511 TPTI-07-07: Apple QuickTime STSD Parsing Heap Overflow Vulnerability</ref><ref adv="1" patch="1" source="" url="http://dvlabs.tippingpoint.com/advisory/TPTI-07-07"></ref><ref patch="1" source="" url="http://docs.info.apple.com/article.html?artnum=304357"></ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/23923">23923</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/34244">
quicktime-stsd-bo(34244)</ref><ref source="OSVDB" url="http://www.osvdb.org/35574">35574</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2703">2703</ref></refs><vuln_soft><prod name="Quicktime" vendor="Apple"><vers num="7.1.2" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.8" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.9" CVSS_score="7.8" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_version="2.0" modified="2007-02-06" name="CVE-2007-0756" published="2007-02-05" seq="2007-0756" severity="High" type="CVE"><desc><descript source="cve">Chicken of the VNC (cotv) 2.0 allows remote attackers to cause a denial of service (application crash) via a large computer-name size value in a ServerInit packet, which triggers a failed malloc and a resulting NULL dereference.</descript></desc><loss_types><avail/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/458907/100/0/threaded">20070202 Chicken of the VNC 2.0 remote DoS</ref><ref source="BID" url="http://www.securityfocus.com/bid/22372">22372</ref><ref source="MILW0RM" url="http://milw0rm.com/exploits/3257">
3257</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32166">
cotv-serverinit-dos(32166)</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/466966/100/0/threaded">
20070426 Re: Chicken of the VNC 2.0 remote DoS</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2220">2220</ref></refs><vuln_soft><prod name="Chicken of the VNC" vendor="Chicken of the VNC"><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-02-06" name="CVE-2007-0757" published="2007-02-05" seq="2007-0757" severity="High" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in index.php in Miguel Nunes Call of Duty 2 (CoD2) DreamStats System 4.2 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the rootpath parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://www.milw0rm.com/exploits/3251"></ref><ref source="VIM" url="http://www.attrition.org/pipermail/vim/2007-February/001272.html">20070202 true: DreamStats V 4.2=(index.php)=&gt;Remote File Include</ref><ref source="BID" url="http://www.securityfocus.com/bid/22371">22371</ref><ref source="MILW0RM" url="http://milw0rm.com/exploits/3251">

3251</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0479">
ADV-2007-0479</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24037">
24037</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32160">
cod2dreamstats-index-file-include(32160)</ref></refs><vuln_soft><prod name="Call of Duty 2 DreamStats System" vendor="Miguel Nunes"><vers num="4.2" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2008-02-14" name="CVE-2007-0758" published="2007-02-05" seq="2007-0758" severity="High" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in lang.php in PHPProbid 5.24 allows remote attackers to execute arbitrary PHP code via a URL in the SRC attribute of an HTML element in the lang parameter.  NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BID" url="http://www.securityfocus.com/bid/22374">22374</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32273">phpprobid-lang-file-include(32273)</ref></refs><vuln_soft><prod name="PHPProbid" vendor="PHPProbid"><vers num="5.24"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2008-02-14" name="CVE-2007-0759" published="2007-02-05" seq="2007-0759" severity="High" type="CVE"><desc><descript source="cve">Multiple SQL injection vulnerabilities in EasyMoblog 0.5.1 allow remote attackers to execute arbitrary SQL commands via the (1) i or (2) post_id parameter to add_comment.php, which triggers an injection in libraries.inc.php; or (3) the i parameter to list_comments.php, which triggers an injection in libraries.inc.php.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://www.zion-security.com/text/Sql_Vulnerability_EasymoBlog%232.txt"></ref><ref source="" url="http://www.zion-security.com/text/Sql_Vulnerability_EasymoBlog.txt"></ref><ref source="BID" url="http://www.securityfocus.com/bid/22369">22369</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19370">19370</ref></refs><vuln_soft><prod name="EasyMoblog" vendor="Umberto Caldera"><vers num="0.5.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-02-06" name="CVE-2007-0760" published="2007-02-05" seq="2007-0760" severity="High" type="CVE"><desc><descript source="cve">EQdkp 1.3.1 and earlier authenticates administrative requests by verifying that the HTTP Referer header specifies an admin/ URL, which allows remote attackers to read or modify account names and passwords via a spoofed Referer.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref source="" url="http://www.milw0rm.com/exploits/3252"></ref><ref source="BID" url="http://www.securityfocus.com/bid/20805">20805</ref><ref source="MILW0RM" url="http://milw0rm.com/exploits/3252">

3252</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24038">
24038</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32152">
eqdkp-backup-information-disclosure(32152)</ref></refs><vuln_soft><prod name="EQdkp" vendor="EQdkp"><vers num="1.3.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-02-06" name="CVE-2007-0761" published="2007-02-05" seq="2007-0761" severity="High" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in config.php in phpBB ezBoard converter (ezconvert) 0.2 allows remote attackers to execute arbitrary PHP code via a URL in the ezconvert_dir parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://www.milw0rm.com/exploits/3258"></ref><ref source="" url="http://www.xoron.info/bugs/ezconvert.txt"></ref><ref source="VIM" url="http://www.attrition.org/pipermail/vim/2007-February/001278.html">20070202 true: phpBB ezBoard converter 0.2 (ezconvert_dir) Remote File Include Exploit</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32157">ezboard-config-file-include(32157)</ref><ref source="MILW0RM" url="http://milw0rm.com/exploits/3258">

3258</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0473">
ADV-2007-0473</ref></refs><vuln_soft><prod name="ezBoard Converter" vendor="phpBB"><vers num="0.2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-02-06" name="CVE-2007-0762" published="2007-02-05" seq="2007-0762" severity="High" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in includes/functions.php in phpBB++ Build 100 allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://www.milw0rm.com/exploits/3259"></ref><ref source="VIM" url="http://www.attrition.org/pipermail/vim/2007-February/001279.html">20070202 phpBB++ Build 100 (phpbb_root_path) Remote File Include Exploit</ref><ref source="MILW0RM" url="http://milw0rm.com/exploits/3259">

3259</ref><ref source="BID" url="http://www.securityfocus.com/bid/22376">
22376</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0472">
ADV-2007-0472</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24034">
24034</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32159">
phpbbplusplus-functions-file-include(32159)</ref></refs><vuln_soft><prod name="phpBB++" vendor="phpBB++"><vers num="Build 100"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-02-06" name="CVE-2007-0763" published="2007-02-05" seq="2007-0763" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in the news comment functionality in F3Site 2.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the Autor field.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://www.milw0rm.com/exploits/3255"></ref><ref source="BID" url="http://www.securityfocus.com/bid/22379">22379</ref><ref source="MILW0RM" url="http://milw0rm.com/exploits/3255">

3255</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32188">
f3site-autor-xss(32188)</ref></refs><vuln_soft><prod name="F3Site" vendor="F3Site"><vers num="2.1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.5" CVSS_exploit_subscore="8.0" CVSS_impact_subscore="6.4" CVSS_score="6.5" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-02-06" name="CVE-2007-0764" published="2007-02-05" seq="2007-0764" severity="Medium" type="CVE"><desc><descript source="cve">Unrestricted file upload vulnerability in F3Site 2.1 and earlier allows remote authenticated administrators to upload and execute arbitrary PHP scripts via GIF86 header in a file in the uplf parameter, which can be later accessed via a relative pathname in the dir parameter in adm.php.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://www.milw0rm.com/exploits/3255"></ref><ref source="MILW0RM" url="http://milw0rm.com/exploits/3255">

3255</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32189">
f3site-adm-file-upload(32189)</ref></refs><vuln_soft><prod name="F3Site" vendor="F3Site"><vers num="2.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-02-06" name="CVE-2007-0765" published="2007-02-05" seq="2007-0765" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in news.php in dB Masters Curium CMS 1.03 and earlier allows remote attackers to execute arbitrary SQL commands via the c_id parameter.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://www.milw0rm.com/exploits/3256"></ref><ref source="BID" url="http://www.securityfocus.com/bid/22373">22373</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32148">curium-news-sql-injection(32148)</ref><ref source="MILW0RM" url="http://milw0rm.com/exploits/3256">

3256</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0474">
ADV-2007-0474</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24032">
24032</ref></refs><vuln_soft><prod name="Curium CMS" vendor="dB Masters Multimedia"><vers num="1.03" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" CVSS_score="9.3" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-06-27" name="CVE-2007-0766" published="2007-02-05" seq="2007-0766" severity="High" type="CVE"><desc><descript source="cve">Stack-based buffer overflow in Remotesoft .NET Explorer 2.0.1 allows user-assisted remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a long line in a .cpp file.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref source="" url="http://www.milw0rm.com/exploits/3254"></ref><ref source="BID" url="http://www.securityfocus.com/bid/22377">22377</ref><ref source="MILW0RM" url="http://milw0rm.com/exploits/3254">3254</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32182">netexplorer-char-bo(32182)</ref></refs><vuln_soft><prod name=".NET Explorer" vendor="Remotesoft"><vers num="2.0.1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-02-06" name="CVE-2007-0767" published="2007-02-05" seq="2007-0767" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in the core in Phorum before 5.1.18 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs><ref source="" url="http://www.phorum.org/phorum5/read.php?12,119757"></ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0410">ADV-2007-0410</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/44201">phorum-core-xss(44201)</ref></refs><vuln_soft><prod name="Phorum" vendor="Phorum"><vers num="5.1.17" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" modified="2007-06-27" name="CVE-2007-0768" published="2007-02-05" seq="2007-0768" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in the Contact Details functionality in Yahoo! Messenger 8.1.0.209 and earlier allow user-assisted remote attackers to inject arbitrary web script or HTML via a javascript: URI in the SRC attribute of an IMG element to the (1) First Name, (2) Last Name, and (3) Nickname fields.  NOTE: some of these details are obtained from third party information.</descript></desc><impacts><impact source="nvd">Access Complexity: Successful exploitation requires that the attacker is in the messenger list of the target.</impact></impacts><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/458225/100/0/threaded">20070126 Cross-site Scripting with Local Privilege Vulnerability in Yahoo Messenger</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/458305/100/0/threaded">20070127 RE: Cross-site Scripting with Local Privilege Vulnerability in Yahoo Messenger</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/458494/100/0/threaded">20070127 Re: Cross-site Scripting with Local Privilege Vulnerability in Yahoo Messenger</ref><ref source="BID" url="http://www.securityfocus.com/bid/22269">22269</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/23928">23928</ref></refs><vuln_soft><prod name="Messenger" vendor="Yahoo"><vers num="8.1.0.209" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-02-06" name="CVE-2007-0769" published="2007-02-05" seq="2007-0769" severity="Medium" type="CVE"><desc><descript source="cve">** DISPUTED **  Cross-site scripting (XSS) vulnerability in register.php in Phorum 5.1.18 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.  NOTE: the vendor disputes this vulnerability, stating that &quot;The characters are escaped properly.&quot;</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/458461/100/0/threaded">20070129 Phorum HTML Injection Vulnerability</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/458467/100/0/threaded">20070129 Re: Phorum HTML Injection Vulnerability</ref><ref source="" url="http://www.phorum.org/phorum5/read.php?12,119757"></ref><ref source="BID" url="http://www.securityfocus.com/bid/22297">22297</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0410">ADV-2007-0410</ref></refs><vuln_soft><prod name="Phorum" vendor="Phorum"><vers num="5.1.18"/></prod></vuln_soft></entry><entry CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" CVSS_score="9.3" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-02-13" name="CVE-2007-0770" published="2007-02-12" seq="2007-0770" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in GraphicsMagick and ImageMagick allows user-assisted remote attackers to cause a denial of service and possibly execute arbitrary code via a PALM image that is not properly handled by the ReadPALMImage function in coders/palm.c. NOTE: this issue is due to an incomplete patch for CVE-2006-5456.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/><user_init/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/459507/100/0/threaded">20070208 rPSA-2007-0029-1 ImageMagick</ref><ref source="" url="https://issues.rpath.com/browse/RPL-1034"></ref><ref adv="1" source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2007:041">MDKSA-2007:041</ref><ref source="DEBIAN" url="http://www.debian.org/security/2007/dsa-1260">
DSA-1260</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2007_3_sr.html">
SUSE-SR:2007:003</ref><ref source="UBUNTU" url="http://www.ubuntu.com/usn/usn-422-1">
USN-422-1</ref><ref source="OSVDB" url="http://www.osvdb.org/31911">
31911</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24167">
24167</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24196">
24196</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:041">MDKSA-2007:041</ref></refs><vuln_soft><prod name="ImageMagick" vendor="ImageMagick"><vers num="6.3.3.4"/></prod><prod name="GraphicsMagick" vendor="GraphicsMagick"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="4.9" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.9" CVSS_score="4.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:C)" CVSS_version="2.0" modified="2008-07-30" name="CVE-2007-0771" published="2007-05-02" seq="2007-0771" severity="Medium" type="CVE"><desc><descript source="cve">The utrace support in Linux kernel 2.6.18, and other versions, allows local users to cause a denial of service (system hang) related to &quot;MT exec + utrace_attach spin failure mode,&quot; as demonstrated by ptrace-thrash.c.</descript></desc><loss_types><avail/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2007-0169.html">RHSA-2007:0169</ref><ref source="BID" url="http://www.securityfocus.com/bid/23720">23720</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1017979">1017979</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/25080">25080</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/34128">kernel-utracesupport-dos(34128)</ref><ref source="" url="https://bugzilla.redhat.com/show_bug.cgi?id=227952"></ref><ref source="" url="https://bugzilla.redhat.com/show_bug.cgi?id=228816"></ref></refs><vuln_soft><prod name="Kernel" vendor="Linux"><vers num="2.6.18"/><vers num="2.6.18.1"/><vers num="2.6.18.2"/><vers num="2.6.18.3"/><vers num="2.6.18.4"/><vers edition="rc1" num="2.6.18"/><vers edition="rc2" num="2.6.18"/><vers edition="rc3" num="2.6.18"/><vers edition="rc4" num="2.6.18"/><vers edition="rc5" num="2.6.18"/><vers edition="rc6" num="2.6.18"/><vers edition="rc7" num="2.6.18"/></prod><prod name="Enterprise Linux Desktop Workstation" vendor="Red Hat"><vers edition="Desktop Workstation" num="5.0"/></prod><prod name="Enterprise Linux" vendor="Red Hat"><vers edition="Server" num="5.0"/></prod><prod name="Enterprise Linux Desktop" vendor="Red Hat"><vers edition="Desktop" num="5.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0" modified="2007-08-03" name="CVE-2007-0772" published="2007-02-20" seq="2007-0772" severity="Medium" type="CVE"><desc><descript source="cve">The Linux kernel 2.6.13 and other versions before 2.6.20.1 allows remote attackers to cause a denial of service (oops) via a crafted NFSACL 2 ACCESS request that triggers a free of an incorrect pointer.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="" url="http://kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.20.1"></ref><ref patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0660">ADV-2007-0660</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24215">24215</ref><ref source="" url="https://issues.rpath.com/browse/RPL-1063"></ref><ref source="FEDORA" url="http://fedoranews.org/cms/node/2739">FEDORA-2007-277</ref><ref source="FEDORA" url="http://fedoranews.org/cms/node/2740">FEDORA-2007-291</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2007:060">MDKSA-2007:060</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2007_18_kernel.html">SUSE-SA:2007:018</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2007_21_kernel.html">SUSE-SA:2007:021</ref><ref source="BID" url="http://www.securityfocus.com/bid/22625">22625</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24201">24201</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24400">24400</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24482">24482</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24547">24547</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32578">kernel-nfsaclsvc-dos(32578)</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2007:078">MDKSA-2007:078</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24777">24777</ref><ref source="UBUNTU" url="http://www.ubuntu.com/usn/usn-451-1">USN-451-1</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24752">24752</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/471457">20070615 rPSA-2007-0124-1 kernel xen</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:060">MDKSA-2007:060</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:078">MDKSA-2007:078</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25691">25691</ref></refs><vuln_soft><prod name="Kernel" vendor="Linux"><vers num="2.6.18"/><vers num="2.6.18.1"/><vers num="2.6.18.2"/><vers num="2.6.18.3"/><vers num="2.6.18.4"/><vers num="2.6.18.5"/><vers num="2.6.18.6"/><vers num="2.6.19.1"/><vers num="2.6.19.2"/><vers num="2.6.19.3"/><vers num="2.6.20"/><vers num="2.6.13.1"/><vers num="2.6.13.2"/><vers num="2.6.13.3"/><vers num="2.6.13.4"/><vers num="2.6.13.5"/><vers num="2.6.14"/><vers num="2.6.14.1"/><vers num="2.6.14.2"/><vers num="2.6.14.3"/><vers num="2.6.14.4"/><vers num="2.6.14.5"/><vers num="2.6.14.6"/><vers num="2.6.14.7"/><vers num="2.6.15"/><vers num="2.6.15.1"/><vers num="2.6.15.2"/><vers num="2.6.15.3"/><vers num="2.6.15.4"/><vers num="2.6.15.5"/><vers num="2.6.15.6"/><vers num="2.6.15.7"/><vers num="2.6.16"/><vers num="2.6.16.1"/><vers num="2.6.16.10"/><vers num="2.6.16.11"/><vers num="2.6.16.12"/><vers num="2.6.16.13"/><vers num="2.6.16.14"/><vers num="2.6.16.15"/><vers num="2.6.16.16"/><vers num="2.6.16.17"/><vers num="2.6.16.18"/><vers num="2.6.16.19"/><vers num="2.6.16.2"/><vers num="2.6.16.20"/><vers num="2.6.16.21"/><vers num="2.6.16.22"/><vers num="2.6.16.23"/><vers num="2.6.16.24"/><vers num="2.6.16.25"/><vers num="2.6.16.26"/><vers num="2.6.16.27"/><vers num="2.6.16.28"/><vers num="2.6.16.29"/><vers num="2.6.16.3"/><vers num="2.6.16.30"/><vers num="2.6.16.31"/><vers num="2.6.16.32"/><vers num="2.6.16.33"/><vers num="2.6.16.34"/><vers num="2.6.16.35"/><vers num="2.6.16.36"/><vers num="2.6.16.37"/><vers num="2.6.16.38"/><vers num="2.6.16.39"/><vers num="2.6.16.4"/><vers num="2.6.16.40"/><vers num="2.6.16.41"/><vers num="2.6.16.5"/><vers num="2.6.16.6"/><vers num="2.6.16.7"/><vers num="2.6.16.8"/><vers num="2.6.16.9"/><vers num="2.6.17"/><vers num="2.6.17.1"/><vers num="2.6.17.10"/><vers num="2.6.17.11"/><vers num="2.6.17.12"/><vers num="2.6.17.13"/><vers num="2.6.17.14"/><vers num="2.6.17.2"/><vers num="2.6.17.3"/><vers num="2.6.17.4"/><vers num="2.6.17.5"/><vers num="2.6.17.6"/><vers num="2.6.17.7"/><vers num="2.6.17.8"/><vers num="2.6.17.9"/><vers num="2.6.16.43"/><vers num="2.6.16.44"/><vers num="2.6.16.45"/><vers num="2.6.16.46"/><vers num="2.6.16.47"/><vers num="2.6.16.48"/><vers num="2.6.16.49"/><vers num="2.6.16.50"/><vers num="2.6.16.51"/><vers num="2.6.16.52"/><vers num="2.6.16.53"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.1" CVSS_impact_subscore="6.9" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:S/C:N/I:N/A:C)" CVSS_version="2.0" modified="2007-08-09" name="CVE-2007-0773" published="2007-06-26" seq="2007-0773" severity="Medium" type="CVE"><desc><descript source="cve">The Linux kernel before 2.6.9-42.0.8 in Red Hat 4.4 allows local users to cause a denial of service (kernel OOPS from null dereference) via fput in a 32-bit ioctl on 64-bit x86 systems, an incomplete fix of CVE-2005-3044.1.</descript></desc><loss_types><avail/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref patch="1" source="" url="http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=243252"></ref><ref patch="1" source="REDHAT" url="http://rhn.redhat.com/errata/RHSA-2007-0488.html">RHSA-2007:0488</ref><ref source="" url="http://support.avaya.com/elmodocs2/security/ASA-2007-287.htm"></ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2007_53_kernel.html">SUSE-SA:2007:053</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25838">25838</ref><ref source="SECUNIA" url="http://secunia.com/advisories/26289">26289</ref><ref source="SECUNIA" url="http://secunia.com/advisories/27227">27227</ref></refs><vuln_soft><prod name="Desktop" vendor="Red Hat"><vers num="4.4"/></prod><prod name="Enterprise Linux WS" vendor="Red Hat"><vers num="4.4"/></prod><prod name="Enterprise Linux ES" vendor="Red Hat"><vers num="4.4"/></prod><prod name="Enterprise Linux AS" vendor="Red Hat"><vers num="4.4"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-03-20" name="CVE-2007-0774" published="2007-03-04" seq="2007-0774" severity="High" type="CVE"><desc><descript source="cve">Stack-based buffer overflow in the map_uri_to_worker function (native/common/jk_uri_worker_map.c) in mod_jk.so for Apache Tomcat JK Web Server Connector 1.2.19 and 1.2.20, as used in Tomcat 4.1.34 and 5.5.20, allows remote attackers to execute arbitrary code via a long URL that triggers the overflow in a URI worker map routine.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="" url="http://www.zerodayinitiative.com/advisories/ZDI-07-008.html"></ref><ref patch="1" source="" url="http://tomcat.apache.org/connectors-doc/miscellaneous/changelog.html"></ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/461734/100/0/threaded">

20070302 ZDI-07-008: Apache Tomcat JK Web Server Connector Long URL Stack Overflow Vulnerability</ref><ref source="" url="http://tomcat.apache.org/security-jk.html"></ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200703-16.xml">
GLSA-200703-16</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2007-0096.html">
RHSA-2007:0096</ref><ref source="BID" url="http://www.securityfocus.com/bid/22791">
22791</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0809">
ADV-2007-0809</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1017719">
1017719</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24398">
24398</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24558">
24558</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32794">
tomcat-mapuritoworker-bo(32794)</ref><ref source="HP" url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01178795">HPSBUX02262</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/3386">ADV-2007-3386</ref><ref source="SECUNIA" url="http://secunia.com/advisories/27037">27037</ref><ref source="CISCO" url="http://www.cisco.com/en/US/products/products_security_advisory09186a008093f040.shtml">20080130 Cisco Wireless Control System Tomcat mod_jk.so Vulnerability</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/0331">ADV-2008-0331</ref><ref source="SECUNIA" url="http://secunia.com/advisories/28711">28711</ref></refs><vuln_soft><prod name="Tomcat JK Web Server Connector" vendor="Apache Software Foundation"><vers num="1.2.19"/><vers num="1.2.20"/></prod></vuln_soft></entry><entry CVSS_base_score="3.7" CVSS_exploit_subscore="1.9" CVSS_impact_subscore="6.4" CVSS_score="3.7" CVSS_vector="(AV:L/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2008-01-02" name="CVE-2007-0775" published="2007-02-26" seq="2007-0775" severity="Low" type="CVE"><desc><descript source="cve">Multiple unspecified vulnerabilities in the layout engine in Mozilla Firefox before 1.5.0.10 and 2.x before 2.0.0.2, Thunderbird before 1.5.0.10, and SeaMonkey before 1.0.8 allow remote attackers to cause a denial of service (crash) and potentially execute arbitrary code via certain vectors.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><exception/></vuln_types><range><local/></range><refs><ref source="SLACKWARE" url="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2007&amp;m=slackware-security.374851">SSA:2007-066-03</ref><ref source="SLACKWARE" url="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2007&amp;m=slackware-security.363947">SSA:2007-066-04</ref><ref source="SLACKWARE" url="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2007&amp;m=slackware-security.338131">SSA:2007-066-05</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2007_22_mozilla.html">SUSE-SA:2007:022</ref><ref source="OSVDB" url="http://www.osvdb.org/32114">32114</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24406">24406</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24455">24455</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24456">24456</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24457">24457</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24342">24342</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25588">25588</ref><ref adv="1" patch="1" source="" url="http://www.mozilla.org/security/announce/2007/mfsa2007-01.html"></ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/461336/100/0/threaded">20070226 rPSA-2007-0040-1 firefox</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/461809/100/0/threaded">20070303 rPSA-2007-0040-3 firefox thunderbird</ref><ref source="" url="https://issues.rpath.com/browse/RPL-1081"></ref><ref source="" url="https://issues.rpath.com/browse/RPL-1103"></ref><ref source="FEDORA" url="http://fedoranews.org/cms/node/2713">FEDORA-2007-281</ref><ref source="FEDORA" url="http://fedoranews.org/cms/node/2728">FEDORA-2007-293</ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200703-04.xml">GLSA-200703-04</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200703-08.xml">GLSA-200703-08</ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200703-18.xml">GLSA-200703-18</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2007:050">MDKSA-2007:050</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:052">MDKSA-2007:052</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2007-0079.html">RHSA-2007:0079</ref><ref source="REDHAT" url="http://rhn.redhat.com/errata/RHSA-2007-0077.html">RHSA-2007:0077</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2007-0078.html">RHSA-2007:0078</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2007-0097.html">RHSA-2007:0097</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2007-0108.html">RHSA-2007:0108</ref><ref source="SUSE" url="http://lists.suse.com/archive/suse-security-announce/2007-Mar/0001.html">SUSE-SA:2007:019</ref><ref source="UBUNTU" url="http://www.ubuntu.com/usn/usn-428-1">USN-428-1</ref><ref source="UBUNTU" url="http://www.ubuntu.com/usn/usn-431-1">USN-431-1</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/761756">VU#761756</ref><ref source="BID" url="http://www.securityfocus.com/bid/22694">22694</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0719">ADV-2007-0719</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0718">ADV-2007-0718</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017698">1017698</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24238">24238</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24252">24252</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24287">24287</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24290">24290</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24205">24205</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24328">24328</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24333">24333</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24343">24343</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24320">24320</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24293">24293</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24393">24393</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24395">24395</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24384">24384</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24389">24389</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24410">24410</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24437">24437</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24522">24522</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32704">mozilla-multiple-layout-code-execution(32704)</ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20070301-01-P.asc">20070301-01-P</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24650">24650</ref><ref source="DEBIAN" url="http://www.debian.org/security/2007/dsa-1336">DSA-1336</ref><ref source="FEDORA" url="http://fedoranews.org/cms/node/2747">FEDORA-2007-308</ref><ref source="FEDORA" url="http://fedoranews.org/cms/node/2749">FEDORA-2007-309</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:050">MDKSA-2007:050</ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20070202-01-P.asc">20070202-01-P</ref><ref source="HP" url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00771742">HPSBUX02153</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/0083">ADV-2008-0083</ref></refs><vuln_soft><prod name="Thunderbird" vendor="Mozilla"><vers num="1.0.3"/><vers num="1.0.4"/><vers num="1.0.5"/><vers num="1.0.6"/><vers num="1.0.7"/><vers num="1.0.8"/><vers num="1.5"/></prod><prod name="SeaMonkey" vendor="Mozilla"><vers edition="Alpha" num="1.0"/><vers edition="Beta" num="1.0"/><vers num="1.0"/><vers num="1.0.1"/><vers num="1.0.2"/><vers num="1.0.3"/><vers num="1.0.4"/><vers num="1.0.5"/><vers num="1.0.6"/><vers num="1.0.7"/></prod><prod name="Firefox" vendor="Mozilla"><vers num="2.0"/><vers edition="Beta 1" num="2.0"/><vers edition="RC2" num="2.0"/><vers edition="RC3" num="2.0"/><vers num="2.0.0.1"/><vers num="1.0"/><vers num="1.0.1"/><vers num="1.0.2"/><vers num="1.0.3"/><vers num="1.0.4"/><vers num="1.0.5"/><vers num="1.0.6"/><vers edition="Linux" num="1.0.6"/><vers num="1.0.7"/><vers num="1.0.8"/><vers num="1.5"/><vers edition="Beta 2" num="1.5"/><vers edition="Beta 1" num="1.5"/><vers num="1.5.0.1"/><vers num="1.5.0.2"/><vers num="1.5.0.3"/><vers num="1.5.0.4"/><vers num="1.5.0.5"/><vers num="1.5.0.6"/><vers num="1.5.0.7"/><vers num="1.5.0.8"/><vers num="1.5.0.9"/></prod></vuln_soft></entry><entry CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" CVSS_score="9.3" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2008-05-22" name="CVE-2007-0776" published="2007-02-26" seq="2007-0776" severity="High" type="CVE"><desc><descript source="cve">Heap-based buffer overflow in the _cairo_pen_init function in Mozilla Firefox 2.x before 2.0.0.2, Thunderbird before 1.5.0.10, and SeaMonkey before 1.0.8 allows remote attackers to execute arbitrary code via a large stroke-width attribute in the clipPath element in an SVG file.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="" url="http://www.mozilla.org/security/announce/2007/mfsa2007-01.html"></ref><ref adv="1" source="" url="https://bugzilla.mozilla.org/show_bug.cgi?id=360645"></ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/461336/100/0/threaded">20070226 rPSA-2007-0040-1 firefox</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/461809/100/0/threaded">20070303 rPSA-2007-0040-3 firefox thunderbird</ref><ref source="" url="https://issues.rpath.com/browse/RPL-1081"></ref><ref source="FEDORA" url="http://fedoranews.org/cms/node/2713">FEDORA-2007-281</ref><ref source="FEDORA" url="http://fedoranews.org/cms/node/2728">FEDORA-2007-293</ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200703-04.xml">GLSA-200703-04</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200703-08.xml">GLSA-200703-08</ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200703-18.xml">GLSA-200703-18</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:052">MDKSA-2007:052</ref><ref source="SUSE" url="http://lists.suse.com/archive/suse-security-announce/2007-Mar/0001.html">SUSE-SA:2007:019</ref><ref source="UBUNTU" url="http://www.ubuntu.com/usn/usn-428-1">USN-428-1</ref><ref source="UBUNTU" url="http://www.ubuntu.com/usn/usn-431-1">USN-431-1</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/551436">VU#551436</ref><ref source="BID" url="http://www.securityfocus.com/bid/22694">22694</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0719">ADV-2007-0719</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0718">ADV-2007-0718</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017698">1017698</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24238">24238</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24252">24252</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24205">24205</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24328">24328</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24333">24333</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24320">24320</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24293">24293</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24393">24393</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24384">24384</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24389">24389</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24410">24410</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24437">24437</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24522">24522</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32698">firefox-strokewidth-bo(32698)</ref><ref source="FEDORA" url="http://fedoranews.org/cms/node/2747">FEDORA-2007-308</ref><ref source="FEDORA" url="http://fedoranews.org/cms/node/2749">FEDORA-2007-309</ref><ref source="SLACKWARE" url="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2007&amp;m=slackware-security.374851">SSA:2007-066-03</ref><ref source="SLACKWARE" url="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2007&amp;m=slackware-security.363947">SSA:2007-066-04</ref><ref source="SLACKWARE" url="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2007&amp;m=slackware-security.338131">SSA:2007-066-05</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2007_22_mozilla.html">SUSE-SA:2007:022</ref><ref source="OSVDB" url="http://www.osvdb.org/32113">32113</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24406">24406</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24455">24455</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24456">24456</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24457">24457</ref><ref source="HP" url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00771742">HPSBUX02153</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/0083">ADV-2008-0083</ref></refs><vuln_soft><prod name="Thunderbird" vendor="Mozilla"><vers num="1.5.0.9" prev="1"/></prod><prod name="SeaMonkey" vendor="Mozilla"><vers num="1.0.7" prev="1"/></prod><prod name="Firefox" vendor="Mozilla"><vers num="2.0.0.1" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" CVSS_score="9.3" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-04-26" name="CVE-2007-0777" published="2007-02-26" seq="2007-0777" severity="High" type="CVE"><desc><descript source="cve">The JavaScript engine in Mozilla Firefox before 1.5.0.10 and 2.x before 2.0.0.2, Thunderbird before 1.5.0.10, and SeaMonkey before 1.0.8 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via certain vectors that trigger memory corruption.</descript></desc><impacts><impact source="nvd">Successful exploitation in Thunderbird requires that JavaScript be enabled in mail which is not the default setting. </impact></impacts><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/><user_init/></range><refs><ref patch="1" source="" url="http://www.mozilla.org/security/announce/2007/mfsa2007-01.html"></ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/461336/100/0/threaded">20070226 rPSA-2007-0040-1 firefox</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/461809/100/0/threaded">20070303 rPSA-2007-0040-3 firefox thunderbird</ref><ref source="" url="https://issues.rpath.com/browse/RPL-1081"></ref><ref source="" url="https://issues.rpath.com/browse/RPL-1103"></ref><ref source="FEDORA" url="http://fedoranews.org/cms/node/2713">FEDORA-2007-281</ref><ref source="FEDORA" url="http://fedoranews.org/cms/node/2728">FEDORA-2007-293</ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200703-04.xml">GLSA-200703-04</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200703-08.xml">GLSA-200703-08</ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200703-18.xml">GLSA-200703-18</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2007:050">MDKSA-2007:050</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:052">MDKSA-2007:052</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2007-0079.html">RHSA-2007:0079</ref><ref source="REDHAT" url="http://rhn.redhat.com/errata/RHSA-2007-0077.html">RHSA-2007:0077</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2007-0078.html">RHSA-2007:0078</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2007-0097.html">RHSA-2007:0097</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2007-0108.html">RHSA-2007:0108</ref><ref source="SUSE" url="http://lists.suse.com/archive/suse-security-announce/2007-Mar/0001.html">SUSE-SA:2007:019</ref><ref source="UBUNTU" url="http://www.ubuntu.com/usn/usn-428-1">USN-428-1</ref><ref source="UBUNTU" url="http://www.ubuntu.com/usn/usn-431-1">USN-431-1</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/269484">VU#269484</ref><ref source="BID" url="http://www.securityfocus.com/bid/22694">22694</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0719">ADV-2007-0719</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0718">ADV-2007-0718</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017698">1017698</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/24238">24238</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24252">24252</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24287">24287</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24290">24290</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24205">24205</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24328">24328</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24333">24333</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24343">24343</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24320">24320</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24293">24293</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24393">24393</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24395">24395</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24384">24384</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24389">24389</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24410">24410</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24437">24437</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24522">24522</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32699">mozilla-multiple-javascript-code-execution(32699)</ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20070301-01-P.asc">20070301-01-P</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24650">24650</ref><ref source="FEDORA" url="http://fedoranews.org/cms/node/2747">FEDORA-2007-308</ref><ref source="FEDORA" url="http://fedoranews.org/cms/node/2749">FEDORA-2007-309</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:050">MDKSA-2007:050</ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20070202-01-P.asc">20070202-01-P</ref><ref source="SLACKWARE" url="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2007&amp;m=slackware-security.374851">SSA:2007-066-03</ref><ref source="SLACKWARE" url="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2007&amp;m=slackware-security.363947">SSA:2007-066-04</ref><ref source="SLACKWARE" url="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2007&amp;m=slackware-security.338131">SSA:2007-066-05</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2007_22_mozilla.html">SUSE-SA:2007:022</ref><ref source="OSVDB" url="http://www.osvdb.org/32115">32115</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24406">24406</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24455">24455</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24456">24456</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24457">24457</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24342">24342</ref><ref source="HP" url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00771742">HPSBUX02153</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/0083">ADV-2008-0083</ref></refs><vuln_soft><prod name="Thunderbird" vendor="Mozilla"><vers num="1.5.0.9" prev="1"/></prod><prod name="SeaMonkey" vendor="Mozilla"><vers num="1.0.7" prev="1"/></prod><prod name="Firefox" vendor="Mozilla"><vers num="1.5.0.9" prev="1"/><vers num="2.0.0.1" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.4" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="6.9" CVSS_score="5.4" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:N/A:N)" CVSS_version="2.0" modified="2007-06-27" name="CVE-2007-0778" published="2007-02-26" seq="2007-0778" severity="Medium" type="CVE"><desc><descript source="cve">The page cache feature in Mozilla Firefox before 1.5.0.10 and 2.x before 2.0.0.2, and SeaMonkey before 1.0.8 can generate hash collisions that cause page data to be appended to the wrong page cache, which allows remote attackers to obtain sensitive information or enable further attack vectors when the target page is reloaded from the cache.</descript></desc><loss_types><conf/></loss_types><vuln_types><race/></vuln_types><range><network/></range><refs><ref patch="1" source="" url="http://www.mozilla.org/security/announce/2007/mfsa2007-03.html"></ref><ref source="" url="https://bugzilla.mozilla.org/show_bug.cgi?id=347852"></ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/461336/100/0/threaded">20070226 rPSA-2007-0040-1 firefox</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/461809/100/0/threaded">20070303 rPSA-2007-0040-3 firefox thunderbird</ref><ref source="" url="https://issues.rpath.com/browse/RPL-1081"></ref><ref source="" url="https://issues.rpath.com/browse/RPL-1103"></ref><ref source="FEDORA" url="http://fedoranews.org/cms/node/2713">FEDORA-2007-281</ref><ref source="FEDORA" url="http://fedoranews.org/cms/node/2728">FEDORA-2007-293</ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200703-04.xml">GLSA-200703-04</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200703-08.xml">GLSA-200703-08</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2007:050">MDKSA-2007:050</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2007-0079.html">RHSA-2007:0079</ref><ref source="REDHAT" url="http://rhn.redhat.com/errata/RHSA-2007-0077.html">RHSA-2007:0077</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2007-0078.html">RHSA-2007:0078</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2007-0097.html">RHSA-2007:0097</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2007-0108.html">RHSA-2007:0108</ref><ref source="SUSE" url="http://lists.suse.com/archive/suse-security-announce/2007-Mar/0001.html">SUSE-SA:2007:019</ref><ref source="UBUNTU" url="http://www.ubuntu.com/usn/usn-428-1">USN-428-1</ref><ref source="BID" url="http://www.securityfocus.com/bid/22694">22694</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0718">ADV-2007-0718</ref><ref source="OSVDB" url="http://www.osvdb.org/32110">32110</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1017699">1017699</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24238">24238</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24287">24287</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24290">24290</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24205">24205</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24328">24328</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24333">24333</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24343">24343</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24320">24320</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24293">24293</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24393">24393</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24395">24395</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24384">24384</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24437">24437</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32671">mozilla-diskcache-information-disclosure(32671)</ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20070301-01-P.asc">20070301-01-P</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24650">24650</ref><ref source="DEBIAN" url="http://www.debian.org/security/2007/dsa-1336">DSA-1336</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:050">MDKSA-2007:050</ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20070202-01-P.asc">20070202-01-P</ref><ref source="SLACKWARE" url="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2007&amp;m=slackware-security.374851">SSA:2007-066-03</ref><ref source="SLACKWARE" url="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2007&amp;m=slackware-security.338131">SSA:2007-066-05</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2007_22_mozilla.html">SUSE-SA:2007:022</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24455">24455</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24457">24457</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24342">24342</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25588">25588</ref><ref source="HP" url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00771742">HPSBUX02153</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/0083">ADV-2008-0083</ref></refs><vuln_soft><prod name="SeaMonkey" vendor="Mozilla"><vers num="1.0.7" prev="1"/></prod><prod name="Firefox" vendor="Mozilla"><vers num="1.5.0.9" prev="1"/><vers num="2.0.0.1" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.4" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="4.9" CVSS_score="6.4" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_version="2.0" modified="2008-03-03" name="CVE-2007-0779" published="2007-02-26" seq="2007-0779" severity="Medium" type="CVE"><desc><descript source="cve">GUI overlay vulnerability in Mozilla Firefox 1.5.x before 1.5.0.10 and 2.x before 2.0.0.2, and SeaMonkey before 1.0.8 allows remote attackers to spoof certain user interface elements, such as the host name or security indicators, via the CSS3 hotspot property with a large, transparent, custom cursor.</descript></desc><loss_types><conf/><int/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="" url="http://www.mozilla.org/security/announce/2007/mfsa2007-04.html"></ref><ref source="" url="https://bugzilla.mozilla.org/show_bug.cgi?id=361298"></ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/461336/100/0/threaded">20070226 rPSA-2007-0040-1 firefox</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/461809/100/0/threaded">20070303 rPSA-2007-0040-3 firefox thunderbird</ref><ref source="" url="https://issues.rpath.com/browse/RPL-1081"></ref><ref source="" url="https://issues.rpath.com/browse/RPL-1103"></ref><ref source="FEDORA" url="http://fedoranews.org/cms/node/2713">FEDORA-2007-281</ref><ref source="FEDORA" url="http://fedoranews.org/cms/node/2728">FEDORA-2007-293</ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200703-04.xml">GLSA-200703-04</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200703-08.xml">GLSA-200703-08</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2007:050">MDKSA-2007:050</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2007-0079.html">RHSA-2007:0079</ref><ref source="REDHAT" url="http://rhn.redhat.com/errata/RHSA-2007-0077.html">RHSA-2007:0077</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2007-0078.html">RHSA-2007:0078</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2007-0097.html">RHSA-2007:0097</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2007-0108.html">RHSA-2007:0108</ref><ref source="SUSE" url="http://lists.suse.com/archive/suse-security-announce/2007-Mar/0001.html">SUSE-SA:2007:019</ref><ref source="UBUNTU" url="http://www.ubuntu.com/usn/usn-428-1">USN-428-1</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/22694">22694</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0718">ADV-2007-0718</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017700">1017700</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24238">24238</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24287">24287</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24290">24290</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24205">24205</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24328">24328</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24333">24333</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24343">24343</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24320">24320</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24293">24293</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24393">24393</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24395">24395</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24384">24384</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24437">24437</ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20070301-01-P.asc">20070301-01-P</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24650">24650</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:050">MDKSA-2007:050</ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20070202-01-P.asc">20070202-01-P</ref><ref source="SLACKWARE" url="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2007&amp;m=slackware-security.374851">SSA:2007-066-03</ref><ref source="SLACKWARE" url="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2007&amp;m=slackware-security.338131">SSA:2007-066-05</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2007_22_mozilla.html">SUSE-SA:2007:022</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24455">24455</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24457">24457</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24342">24342</ref><ref source="HP" url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00771742">HPSBUX02153</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/0083">ADV-2008-0083</ref></refs><vuln_soft><prod name="SeaMonkey" vendor="Mozilla"><vers edition="Alpha" num="1.0"/><vers edition="Beta" num="1.0"/><vers edition="dev" num="1.0"/><vers num="1.0"/><vers num="1.0.1"/><vers num="1.0.2"/><vers num="1.0.3"/><vers num="1.0.4"/><vers num="1.0.5"/><vers num="1.0.6"/><vers num="1.0.7"/><vers num="1.0.99"/></prod><prod name="Firefox" vendor="Mozilla"><vers edition="Beta 1" num="1.5"/><vers num="1.5"/><vers edition="Beta 2" num="1.5"/><vers num="1.5.0.1"/><vers num="1.5.0.2"/><vers num="1.5.0.3"/><vers num="1.5.0.4"/><vers num="1.5.0.5"/><vers num="1.5.0.6"/><vers num="1.5.0.7"/><vers num="1.5.0.8"/><vers num="1.5.0.9"/><vers edition="RC2" num="2.0"/><vers num="2.0"/><vers edition="Beta 1" num="2.0"/><vers edition="RC3" num="2.0"/><vers num="2.0.0.1"/><vers num="0.10"/><vers num="0.10.1"/><vers num="0.9.1"/><vers num="0.9.2"/><vers num="0.9.3"/><vers num="1.0"/><vers num="1.0.1"/><vers num="1.0.2"/><vers num="1.0.3"/><vers num="1.0.4"/><vers num="1.0.5"/><vers num="1.0.6"/><vers num="1.0.7"/><vers num="1.0.8"/><vers num="1.5.6"/><vers num="1.5.8"/><vers num="0.8"/><vers num="0.9 rc"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-02-27" name="CVE-2007-0780" published="2007-02-26" seq="2007-0780" severity="Medium" type="CVE"><desc><descript source="cve">browser.js in Mozilla Firefox 1.5.x before 1.5.0.10 and 2.x before 2.0.0.2, and SeaMonkey before 1.0.8 uses the requesting URI to identify child windows, which allows remote attackers to conduct cross-site scripting (XSS) attacks by opening a blocked popup originating from a javascript: URI in combination with multiple frames having the same data: URI.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><range><network/><user_init/></range><refs><ref patch="1" source="" url="http://www.mozilla.org/security/announce/2007/mfsa2007-05.html"></ref><ref source="" url="https://bugzilla.mozilla.org/show_bug.cgi?id=354973"></ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/461336/100/0/threaded">

20070226 rPSA-2007-0040-1 firefox</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/461809/100/0/threaded">
20070303 rPSA-2007-0040-3 firefox thunderbird</ref><ref source="" url="https://issues.rpath.com/browse/RPL-1081"></ref><ref source="" url="https://issues.rpath.com/browse/RPL-1103"></ref><ref source="FEDORA" url="http://fedoranews.org/cms/node/2713">
FEDORA-2007-281</ref><ref source="FEDORA" url="http://fedoranews.org/cms/node/2728">
FEDORA-2007-293</ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200703-04.xml">
GLSA-200703-04</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200703-08.xml">
GLSA-200703-08</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2007:050">
MDKSA-2007:050</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2007-0079.html">
RHSA-2007:0079</ref><ref source="REDHAT" url="http://rhn.redhat.com/errata/RHSA-2007-0077.html">
RHSA-2007:0077</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2007-0078.html">
RHSA-2007:0078</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2007-0097.html">
RHSA-2007:0097</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2007-0108.html">
RHSA-2007:0108</ref><ref source="SUSE" url="http://lists.suse.com/archive/suse-security-announce/2007-Mar/0001.html">
SUSE-SA:2007:019</ref><ref source="UBUNTU" url="http://www.ubuntu.com/usn/usn-428-1">
USN-428-1</ref><ref source="BID" url="http://www.securityfocus.com/bid/22694">
22694</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0718">
ADV-2007-0718</ref><ref source="OSVDB" url="http://www.osvdb.org/32107">
32107</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017702">
1017702</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24238">
24238</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24287">
24287</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24290">
24290</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24205">
24205</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24328">
24328</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24333">
24333</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24343">
24343</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24320">
24320</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24293">
24293</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24393">
24393</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24395">
24395</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24384">
24384</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24437">
24437</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32667">
mozilla-dataurl-xss(32667)</ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20070301-01-P.asc">
20070301-01-P</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24650">
24650</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:050">MDKSA-2007:050</ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20070202-01-P.asc">20070202-01-P</ref><ref source="SLACKWARE" url="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2007&amp;m=slackware-security.374851">SSA:2007-066-03</ref><ref source="SLACKWARE" url="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2007&amp;m=slackware-security.338131">SSA:2007-066-05</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2007_22_mozilla.html">SUSE-SA:2007:022</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24455">24455</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24457">24457</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24342">24342</ref><ref source="HP" url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00771742">HPSBUX02153</ref></refs><vuln_soft><prod name="SeaMonkey" vendor="Mozilla"><vers num="1.0.7" prev="1"/></prod><prod name="Firefox" vendor="Mozilla"><vers num="1.5.0.9" prev="1"/><vers num="2.0.0.1" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-02-07" name="CVE-2007-0784" published="2007-02-06" seq="2007-0784" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in login.asp for tPassword in the Raymond BERTHOU script collection (aka RBL - ASP) allows remote attackers to execute arbitrary SQL commands via the (1) User and (2) Password parameters.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/458495/100/0/threaded">20070127 RBL - ASP (scripts with db) SQL injection</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/458560/100/0/threaded">20070129 RBL - ASP (scripts with db) SQL injection</ref><ref source="" url="http://forums.avenir-geopolitique.net/viewtopic.php?t=2607"></ref><ref source="VIM" url="http://www.attrition.org/pipermail/vim/2007-January/001259.html">20070131 Partial source code verify - </ref><ref source="SREASON" url="http://securityreason.com/securityalert/2225">2225</ref></refs><vuln_soft><prod name="tPassword" vendor="RBL"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-02-06" name="CVE-2007-0785" published="2007-02-06" seq="2007-0785" severity="High" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in previewtheme.php in Flipsource Flip 2.01-final 1.0 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the inc_path parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://www.milw0rm.com/exploits/3266"></ref><ref source="BID" url="http://www.securityfocus.com/bid/22385">22385</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0476">ADV-2007-0476</ref><ref source="MILW0RM" url="http://milw0rm.com/exploits/3266">

3266</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32174">
flip-previewtheme-file-include(32174)</ref></refs><vuln_soft><prod name="Flip" vendor="Flipsource"><vers num="2.01-final 1.0" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-02-06" name="CVE-2007-0786" published="2007-02-06" seq="2007-0786" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in view.php in Noname Media Photo Galerie Standard 1.1.1 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://www.milw0rm.com/exploits/3261"></ref><ref source="BID" url="http://www.securityfocus.com/bid/22384">22384</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0475">ADV-2007-0475</ref><ref source="MILW0RM" url="http://milw0rm.com/exploits/3261">

3261</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24029">24029</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32171">photogalerie-view-sql-injection(32171)</ref></refs><vuln_soft><prod name="Photo Galerie Standard" vendor="Noname Media"><vers num="1.1.1" prev="1"/><vers num="1.1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-02-08" name="CVE-2007-0787" published="2007-02-06" seq="2007-0787" severity="Medium" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in controller.php in Simple Invoices before 20070202 allows remote attackers to execute arbitrary PHP code via a URL in the (1) module or (2) view parameter.  NOTE: some of these details are obtained from third party information.</descript></desc><sols><sol source="nvd">Successful exploitation requires that &quot;register_globals&quot; is enabled and &quot;magic_quotes_gpc&quot; is disabled.</sol></sols><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://www.simpleinvoices.org/index.php?news=25"></ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24040">24040</ref><ref source="BID" url="http://www.securityfocus.com/bid/22389">
22389</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0481">
ADV-2007-0481</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32207">
simpleinvoices-controller-file-include(32207)</ref></refs><vuln_soft><prod name="Simple Invoices" vendor="Simple Invoices"><vers num="2007-02-02"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" modified="2007-02-06" name="CVE-2007-0788" published="2007-02-06" seq="2007-0788" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in MediaWiki 1.9.x before 1.9.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors related to &quot;sortable tables JavaScript.&quot;</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" source="" url="http://svn.wikimedia.org/svnroot/mediawiki/tags/REL1_9_2/phase3/RELEASE-NOTES"></ref><ref source="SECUNIA" url="http://secunia.com/advisories/24039">24039</ref><ref source="MLIST" url="http://lists.wikimedia.org/pipermail/mediawiki-announce/2007-February/000059.html">

[MediaWiki-announce] 20070204 MediaWiki 1.9.2 released</ref><ref source="BID" url="http://www.securityfocus.com/bid/22397">
22397</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0490">
ADV-2007-0490</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32217">
mediawiki-sortabletable-xss(32217)</ref></refs><vuln_soft><prod name="MediaWiki" vendor="MediaWiki"><vers num="1.9.0"/><vers num="1.9.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-08-03" name="CVE-2007-0789" published="2007-02-06" seq="2007-0789" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in Mambo before 4.5.5 allows remote attackers to execute arbitrary SQL commands via unspecified vectors in cancel edit functions, possibly related to the id parameter.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs><ref adv="1" source="" url="http://mamboxchange.com/frs/shownotes.php?release_id=6232"></ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0480">ADV-2007-0480</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24044">24044</ref></refs><vuln_soft><prod name="Mambo" vendor="Mambo"><vers num="4.5.4" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-02-06" name="CVE-2007-0790" published="2007-02-06" seq="2007-0790" severity="High" type="CVE"><desc><descript source="cve">Heap-based buffer overflow in SmartFTP 2.0.1002 allows remote FTP servers to execute arbitrary code via a large banner.  NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref source="SECUNIA" url="http://secunia.com/advisories/24051">24051</ref><ref source="BID" url="http://www.securityfocus.com/bid/22390">

22390</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32214">
smartftp-banner-bo(32214)</ref></refs><vuln_soft><prod name="SmartFTP" vendor="SmartFTP"><vers num="2.0.1002"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" modified="2007-02-06" name="CVE-2007-0791" published="2007-02-06" seq="2007-0791" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in Atom feeds in Bugzilla 2.20.3, 2.22.1, and 2.23.3, and earlier versions down to 2.20.1, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.</descript></desc><loss_types><int/></loss_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/459025/100/0/threaded">20070203 Security Advisory for Bugzilla 2.20.3, 2.22.1, and 2.23.3</ref><ref adv="1" source="" url="http://www.bugzilla.org/security/2.20.3/"></ref><ref source="BID" url="http://www.securityfocus.com/bid/22380">22380</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0477">ADV-2007-0477</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1017585">1017585</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24031">24031</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32248">
bugzilla-atom-feed-xss(32248)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2222">2222</ref></refs><vuln_soft><prod name="Bugzilla" vendor="Mozilla"><vers num="2.23.3"/><vers num="2.23.2"/><vers num="2.22.1"/><vers num="2.21.2"/><vers num="2.21.1"/><vers num="2.21"/><vers num="2.20.3"/><vers num="2.20.2"/><vers num="2.20.1"/><vers num="2.22 RC1"/><vers num="2.22"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-02-06" name="CVE-2007-0792" published="2007-02-06" seq="2007-0792" severity="High" type="CVE"><desc><descript source="cve">The mod_perl initialization script in Bugzilla 2.23.3 does not set the Bugzilla Apache configuration to allow .htaccess permissions to override file permissions, which allows remote attackers to obtain the database username and password via a direct request for the localconfig file.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/459025/100/0/threaded">20070203 Security Advisory for Bugzilla 2.20.3, 2.22.1, and 2.23.3</ref><ref adv="1" source="" url="http://www.bugzilla.org/security/2.20.3/"></ref><ref source="BID" url="http://www.securityfocus.com/bid/22380">22380</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0477">ADV-2007-0477</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1017585">1017585</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32252">
bugzilla-htaccess-information-disclosure(32252)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2222">2222</ref></refs><vuln_soft><prod name="Bugzilla" vendor="Mozilla"><vers num="2.23.3"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-02-06" name="CVE-2007-0793" published="2007-02-06" seq="2007-0793" severity="High" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in inc/common.php in GlobalMegaCorp dvddb 0.6 allows remote attackers to execute arbitrary PHP code via a URL in the config parameter.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/459149/100/0/threaded">20070204 dvddb-0.6 media remote file include vuln.</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2221">2221</ref></refs><vuln_soft><prod name="Dvddb" vendor="GlobalMegaCorp"><vers num="0.6"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-08-03" name="CVE-2007-0794" published="2007-02-06" seq="2007-0794" severity="High" type="CVE"><desc><descript source="cve">** DISPUTED **  SQL injection vulnerability in inc/common.php in GlobalMegaCorp dvddb 0.6 allows remote attackers to execute arbitrary SQL commands via the user parameter.  NOTE: this issue has been disputed by a reliable third party, who states that inc/common.php only contains function definitions.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/459151/100/0/threaded">20070204 dvddb-0.6 media sql-inj. vuln.</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/459180/100/0/threaded">20070205 Re: dvddb-0.6 media sql-inj. vuln.</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/481327/100/100/threaded">20071002 Re: dvddb-0.6 media sql-inj. vuln.</ref></refs><vuln_soft><prod name="Dvddb" vendor="GlobalMegaCorp"><vers num="0.6"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-02-06" name="CVE-2007-0795" published="2007-02-06" seq="2007-0795" severity="High" type="CVE"><desc><descript source="cve">Multiple PHP remote file inclusion vulnerabilities in Wap Portal Server 1.x allow remote attackers to execute arbitrary PHP code via a URL in the language parameter to (1) index.php and (2) admin/index.php.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/459147/100/0/threaded">20070203 Wap Portal Serve 1.* &lt;= Remote File Inclusion</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32196">
wapportal-index-file-include(32196)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2216">2216</ref></refs><vuln_soft><prod name="Wap Portal Server" vendor="Wap"><vers num="1.x"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-02-06" name="CVE-2007-0796" published="2007-02-06" seq="2007-0796" severity="High" type="CVE"><desc><descript source="cve">Blue Coat Systems WinProxy 6.1a and 6.0 r1c, and possibly earlier, allows remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code via a long HTTP CONNECT request, which triggers heap corruption.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="IDEFENSE" url="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=471">20070202 Blue Coat Systems WinProxy CONNECT Method Heap Overflow Vulnerability</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0482">ADV-2007-0482</ref><ref source="BID" url="http://www.securityfocus.com/bid/22393">
22393</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1017586">
1017586</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24049">
24049</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32204">
winproxy-connect-bo(32204)</ref></refs><vuln_soft><prod name="WinProxy" vendor="Blue Coat Systems"><vers num="6.1a"/><vers num="6.0 r1c"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-02-07" name="CVE-2007-0797" published="2007-02-06" seq="2007-0797" severity="High" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in theme/settings.php in bluevirus-design SMA-DB 0.3.9 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the pfad_z parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://www.milw0rm.com/exploits/3268"></ref><ref source="BID" url="http://www.securityfocus.com/bid/22391">22391</ref><ref source="MILW0RM" url="http://milw0rm.com/exploits/3268">

3268</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0494">
ADV-2007-0494</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24035">
24035</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32190">
smadb-settings-file-include(32190)</ref></refs><vuln_soft><prod name="SMA-DB" vendor="Bluevirus-design"><vers num="0.3.9"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" modified="2007-02-07" name="CVE-2007-0798" published="2007-02-06" seq="2007-0798" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Ublog Reload 1.0.5 allow remote attackers to inject arbitrary web script or HTML via unspecified parameters to (1) login.asp; and allow remote authenticated users to inject arbitrary web script or HTML via unspecified parameters to (2) badword.asp, (3) polls.asp, and (4) users.asp.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/459027/100/0/threaded">20070203 Ublog Reload Admin Panel Multiple HTML Injections</ref><ref adv="1" source="" url="http://www.hackerscenter.com/archive/view.asp?id=27270"></ref><ref source="BID" url="http://www.securityfocus.com/bid/22382">22382</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32185">ublog-login-xss(32185)</ref></refs><vuln_soft><prod name="Ublog Reload" vendor="Uapplication"><vers num="1.0.5"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-02-07" name="CVE-2007-0799" published="2007-02-06" seq="2007-0799" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in badword.asp in Ublog Reload 1.0.5 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/459027/100/0/threaded">20070203 Ublog Reload Admin Panel Multiple HTML Injections</ref><ref adv="1" source="" url="http://www.hackerscenter.com/archive/view.asp?id=27270"></ref><ref source="BID" url="http://www.securityfocus.com/bid/22382">22382</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32187">ublog-badword-sql-injection(32187)</ref></refs><vuln_soft><prod name="Ublog" vendor="Uapplication"><vers num="Reload 1.0.5"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)" CVSS_version="2.0" modified="2007-02-07" name="CVE-2007-0800" published="2007-02-07" seq="2007-0800" severity="Medium" type="CVE"><desc><descript source="cve">Cross-zone vulnerability in Mozilla Firefox 1.5.0.9 considers blocked popups to have an internal zone origin, which allows user-assisted remote attackers to cross zone restrictions and read arbitrary file:// URIs by convincing a user to show a blocked popup.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/459162/100/0/threaded">20070205 Firefox + popup blocker + XMLHttpRequest + srand() = oops</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/459163/100/0/threaded">20070205 Re: [Full-disclosure] Firefox + popup blocker + XMLHttpRequest + srand() = oops</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/22396">22396</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/461336/100/0/threaded">
20070226 rPSA-2007-0040-1 firefox</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/461809/100/0/threaded">
20070303 rPSA-2007-0040-3 firefox thunderbird</ref><ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2007-February/052209.html">
20070205 Firefox + popup blocker + XMLHttpRequest + srand() = oops</ref><ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2007-February/052211.html">
20070205 Re: Firefox + popup blocker + XMLHttpRequest + srand() = oops</ref><ref source="" url="http://www.mozilla.org/security/announce/2007/mfsa2007-05.html"></ref><ref source="" url="https://issues.rpath.com/browse/RPL-1081"></ref><ref source="" url="https://issues.rpath.com/browse/RPL-1103"></ref><ref source="FEDORA" url="http://fedoranews.org/cms/node/2713">
FEDORA-2007-281</ref><ref source="FEDORA" url="http://fedoranews.org/cms/node/2728">
FEDORA-2007-293</ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200703-04.xml">
GLSA-200703-04</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200703-08.xml">
GLSA-200703-08</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2007:050">
MDKSA-2007:050</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2007-0079.html">
RHSA-2007:0079</ref><ref source="REDHAT" url="http://rhn.redhat.com/errata/RHSA-2007-0077.html">
RHSA-2007:0077</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2007-0078.html">
RHSA-2007:0078</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2007-0097.html">
RHSA-2007:0097</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2007-0108.html">
RHSA-2007:0108</ref><ref source="SUSE" url="http://lists.suse.com/archive/suse-security-announce/2007-Mar/0001.html">
SUSE-SA:2007:019</ref><ref source="UBUNTU" url="http://www.ubuntu.com/usn/usn-428-1">
USN-428-1</ref><ref source="BID" url="http://www.securityfocus.com/bid/22694">
22694</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0718">
ADV-2007-0718</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017702">
1017702</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24238">
24238</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24287">
24287</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24290">
24290</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24205">
24205</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24328">
24328</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24333">
24333</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24343">
24343</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24320">
24320</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24293">
24293</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24393">
24393</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24395">
24395</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24384">
24384</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24437">
24437</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32194">
firefox-popup-security-bypass(32194)</ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20070301-01-P.asc">
20070301-01-P</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24650">
24650</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:050">MDKSA-2007:050</ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20070202-01-P.asc">20070202-01-P</ref><ref source="SLACKWARE" url="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2007&amp;m=slackware-security.338131">SSA:2007-066-05</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2007_22_mozilla.html">SUSE-SA:2007:022</ref><ref source="OSVDB" url="http://www.osvdb.org/32108">32108</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24457">24457</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24342">24342</ref><ref source="HP" url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00771742">HPSBUX02153</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/0083">ADV-2008-0083</ref></refs><vuln_soft><prod name="Firefox" vendor="Mozilla"><vers num="1.5.0.9"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)" CVSS_version="2.0" modified="2007-02-07" name="CVE-2007-0801" published="2007-02-07" seq="2007-0801" severity="Medium" type="CVE"><desc><descript source="cve">The nsExternalAppHandler::SetUpTempFile function in Mozilla Firefox 1.5.0.9 creates temporary files with predictable filenames based on creation time, which allows remote attackers to execute arbitrary web script or HTML via a crafted XMLHttpRequest.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/459162/100/0/threaded">20070205 Firefox + popup blocker + XMLHttpRequest + srand() = oops</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/459163/100/0/threaded">20070205 Re: [Full-disclosure] Firefox + popup blocker + XMLHttpRequest + srand() = oops</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/22396">22396</ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200703-04.xml">
GLSA-200703-04</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200703-08.xml">
GLSA-200703-08</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24393">
24393</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24437">
24437</ref><ref source="OSVDB" url="http://www.osvdb.org/32108">32108</ref></refs><vuln_soft><prod name="Firefox" vendor="Mozilla"><vers num="1.5.0.9"/></prod></vuln_soft></entry><entry CVSS_base_score="6.4" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="4.9" CVSS_score="6.4" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_version="2.0" modified="2008-03-03" name="CVE-2007-0802" published="2007-02-07" seq="2007-0802" severity="Medium" type="CVE"><desc><descript source="cve">Mozilla Firefox 2.0.0.1 allows remote attackers to bypass the Phishing Protection mechanism by adding certain characters to the end of the domain name, as demonstrated by the &quot;.&quot; and &quot;/&quot; characters, which is not caught by the Phishing List blacklist filter.</descript></desc><loss_types><conf/><int/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/459265/100/0/threaded">20070206 Firefox 2.0.0.1 and Opera 9.10 Anty Fraud/Phishing Protection bypass.</ref><ref adv="1" source="" url="http://kaneda.bohater.net/security/20070111-firefox_2.0.0.1_bypass_phishing_protection.php"></ref><ref source="" url="https://bugzilla.mozilla.org/show_bug.cgi?id=367538"></ref></refs><vuln_soft><prod name="Opera" vendor="Opera Software"><vers num="9.10"/></prod><prod name="Firefox" vendor="Mozilla"><vers num="2.0.0.1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-02-07" name="CVE-2007-0803" published="2007-02-07" seq="2007-0803" severity="Medium" type="CVE"><desc><descript source="cve">Multiple buffer overflows in STLport before 5.0.3 allow remote attackers to execute arbitrary code via unspecified vectors relating to (1) &quot;print floats&quot; and (2) a missing null termination in the &quot;rope constructor.&quot;</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref source="" url="http://sourceforge.net/project/shownotes.php?release_id=483468"></ref><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/22423">22423</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24024">24024</ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200703-07.xml">
GLSA-200703-07</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0498">
ADV-2007-0498</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24428">
24428</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32242">
stlport-printed-floats-bo(32242)</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32244">
stlport-rope-constructors-bo(32244)</ref></refs><vuln_soft><prod name="STLport" vendor="STLport"><vers num="5.0.2"/><vers num="5.0.1"/><vers num="5.0.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-02-07" name="CVE-2007-0804" published="2007-02-07" seq="2007-0804" severity="High" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in admin/subpages.php in GGCMS 1.1.0 RC1 and earlier allows remote attackers to inject arbitrary PHP code into arbitrary files via &quot;..&quot; sequences in the subpageName parameter, as demonstrated by injecting PHP code into a template file.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://www.milw0rm.com/exploits/3271"></ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/22412">22412</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0492">ADV-2007-0492</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32211">ggcms-subpages-code-execution(32211)</ref><ref source="MILW0RM" url="http://milw0rm.com/exploits/3271">

3271</ref></refs><vuln_soft><prod name="GGCMS" vendor="GGCMS"><vers num="1.1.0 RC1"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0" modified="2007-02-07" name="CVE-2007-0805" published="2007-02-07" seq="2007-0805" severity="Low" type="CVE"><desc><descript source="cve">The ps (/usr/ucb/ps) command on HP Tru64 UNIX 5.1 1885 allows local users to obtain sensitive information, including environment variables of arbitrary processes, via the &quot;auxewww&quot; argument, a similar issue to CVE-1999-1587.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/459275/100/0/threaded">20070206 PS Information Leak on HP True64 Alpha OSF1 v5.1 1885</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/459266/100/0/threaded">20070206 Re: [Full-disclosure] PS Information Leak on HP Tru64 Alpha OSF1v5.1 1885</ref><ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2007-February/052227.html">20070206 PS Information Leak on HP True64 Alpha OSF1 v5.1 1885</ref><ref source="" url="http://rawlab.mindcreations.com/codes/exp/nix/osf1tru64ps.ksh"></ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24041">24041</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/459593/100/200/threaded">
20070207 Re: PS Information Leak on HP True64 Alpha OSF1 v5.1 1885</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1017592">
1017592</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32276">
tru64-ps-information-disclosure(32276)</ref><ref source="HP" url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00817515">
HPSBTU02179</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1654">
ADV-2007-1654</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25135">
25135</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1018005">
1018005</ref></refs><vuln_soft><prod name="Tru64 UNIX" vendor="HP"><vers num="5.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-02-07" name="CVE-2007-0806" published="2007-02-07" seq="2007-0806" severity="High" type="CVE"><desc><descript source="cve">Les News 2.2 allows remote attackers to bypass authentication and gain administrative access via a direct request for adminews/index_fr.php3, and possibly the adminews index documents for other localizations.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/459186/100/0/threaded">20070204 Les News v2.2 [Admin news without password]</ref><ref source="" url="http://forums.avenir-geopolitique.net/viewtopic.php?t=2622"></ref><ref source="SREASON" url="http://securityreason.com/securityalert/2226">2226</ref></refs><vuln_soft><prod name="Les News" vendor="Les News"><vers num="2.2"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-08-03" name="CVE-2007-0807" published="2007-02-07" seq="2007-0807" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in info.php in flashChat 4.7.8 allows remote attackers to inject arbitrary web script or HTML via a channel title (aka room name) that is not properly handled by the &quot;who&apos;s online&quot; feature.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/459160/100/0/threaded">20070205 flashChat 4.7.8 Cross Site Scripting Vulnerability</ref><ref source="BID" url="http://www.securityfocus.com/bid/22411">22411</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0495">ADV-2007-0495</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24071">24071</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32208">flashchat-info-xss(32208)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2228">2228</ref></refs><vuln_soft><prod name="FlashChat" vendor="Darrens 5-Dollar Script Archive"><vers num="4.7.8"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-02-07" name="CVE-2007-0808" published="2007-02-07" seq="2007-0808" severity="High" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in Mina Ajans Script allows remote attackers to execute arbitrary PHP code via a URL in the syf parameter to an unspecified PHP script.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/459191/100/0/threaded">20070205 Mina Ajans Script Remote File Inclusion Vuln.</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32243">
mina-multiple-file-include(32243)</ref></refs><vuln_soft><prod name="Mina Ajans Script" vendor="Mina Ajans"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-02-08" name="CVE-2007-0809" published="2007-02-07" seq="2007-0809" severity="High" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in includes/class_template.php in Categories hierarchy (aka CH or mod-CH) 2.1.2 in ptirhiikmods allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://www.milw0rm.com/exploits/3270"></ref><ref source="MILW0RM" url="http://milw0rm.com/exploits/3270">

3270</ref><ref source="BID" url="http://www.securityfocus.com/bid/22400">
22400</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0493">
ADV-2007-0493</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32193">
Ch-classtemplate-file-include(32193)</ref></refs><vuln_soft><prod name="mod-CH" vendor="Ptirhiikmods"><vers num="2.1.2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-02-08" name="CVE-2007-0810" published="2007-02-07" seq="2007-0810" severity="High" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in MVCnPHP/BaseView.php in GeekLog 2 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the glConf[path_libraries] parameter.  NOTE: this might be a vulnerability in MVCnPHP rather than a vulnerability in GeekLog.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://www.milw0rm.com/exploits/3267"></ref><ref source="MILW0RM" url="http://milw0rm.com/exploits/3267">

3267</ref><ref source="BID" url="http://www.securityfocus.com/bid/22386">
22386</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32205">
geeklog-baseview-file-include(32205)</ref></refs><vuln_soft><prod name="Geeklog" vendor="Geeklog"><vers num="2"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:P)" CVSS_version="2.0" modified="2007-02-08" name="CVE-2007-0811" published="2007-02-07" seq="2007-0811" severity="Medium" type="CVE"><desc><descript source="cve">Microsoft Internet Explorer 6.0 SP1 on Windows 2000, and 6.0 SP2 on Windows XP, allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via an HTML document containing a certain JavaScript for loop with an empty loop body, possibly involving getElementById.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/><design/></vuln_types><range><network/><user_init/></range><refs><ref source="" url="http://www.milw0rm.com/exploits/3272"></ref><ref source="" url="http://www.powerhacker.net/exploit/IE_NULL_CRASH.html"></ref><ref source="MILW0RM" url="http://milw0rm.com/exploits/3272">

3272</ref><ref source="BID" url="http://www.securityfocus.com/bid/22408">
22408</ref></refs><vuln_soft><prod name="Internet Explorer" vendor="Microsoft"><vers edition="Windows 2000" num="6"/><vers edition="Windows XP" num="6.0 SP2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-02-09" name="CVE-2007-0812" published="2007-02-07" seq="2007-0812" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in pms.php in Woltlab Burning Board (wBB) Lite 1.0.2pl3e and earlier allows remote authenticated users to execute arbitrary SQL commands via the pmid[0] parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://www.milw0rm.com/exploits/3262"></ref><ref source="MILW0RM" url="http://milw0rm.com/exploits/3262">

3262</ref><ref source="BID" url="http://www.securityfocus.com/bid/22415">
22415</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0491">
ADV-2007-0491</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24027">
24027</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32172">
wbblite-pms-sql-injection(32172)</ref></refs><vuln_soft><prod name="Burning Board Lite" vendor="Woltlab"><vers num="1.0.2 pl3e"/><vers num="1.0.2"/><vers num="1.0.1e"/><vers num="1.0.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" modified="2007-02-08" name="CVE-2007-0813" published="2007-02-07" seq="2007-0813" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in Home production MySearchEngine allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/459145/100/0/threaded">20070204 MysearchEngine XSS</ref><ref adv="1" source="" url="http://forums.avenir-geopolitique.net/viewtopic.php?t=2621"></ref><ref source="BID" url="http://www.securityfocus.com/bid/22402">22402</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32201">
mysearchengine-search-xss(32201)</ref></refs><vuln_soft><prod name="MySearchEngine" vendor="Home production"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" modified="2007-02-08" name="CVE-2007-0814" published="2007-02-07" seq="2007-0814" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Adrenalin&apos;s ASP Chat allow remote attackers to inject arbitrary web script or HTML (1) via the psuedo (pseudo) field or (2) during chat.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/459144/100/0/threaded">20070203 Adrenalin&apos;s ASP Chat XSS</ref><ref adv="1" source="" url="http://forums.avenir-geopolitique.net/viewtopic.php?t=2620"></ref><ref source="BID" url="http://www.securityfocus.com/bid/22392">22392</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32203">
adrenalin-unspecified-script-xss(32203)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2233">2233</ref></refs><vuln_soft><prod name="Adrenalin&apos;s ASP Chat" vendor="Adrenalin Labs"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" modified="2007-02-08" name="CVE-2007-0815" published="2007-02-07" seq="2007-0815" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in images_archive.asp in Uapplication Uphotogallery 1.1 allows remote authenticated administrators to inject arbitrary web script or HTML via the s parameter.  NOTE: the thumbnails.asp vector is already covered by CVE-2006-3023.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/459187/100/0/threaded">20070204 Uphotogallery Multiple Cross-Site Scripting Vulnerability</ref><ref source="BID" url="http://www.securityfocus.com/bid/22404">22404</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32229">
uphotogallery-imagesarchive-xss(32229)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2227">2227</ref></refs><vuln_soft><prod name="uPhotoGallery" vendor="Uapplication"><vers num="1.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0" modified="2007-08-03" name="CVE-2007-0816" published="2007-02-07" seq="2007-0816" severity="Medium" type="CVE"><desc><descript source="cve">The RPC Server service (catirpc.exe) in CA (formerly Computer Associates) BrightStor ARCserve Backup 11.5 SP2 and earlier allows remote attackers to cause a denial of service (service crash) via a crafted TADDR2UADDR that triggers a null pointer dereference in catirpc.dll, possibly related to null credentials or verifier fields.</descript></desc><loss_types><avail/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref source="" url="http://milw0rm.com/exploits/3248"></ref><ref source="BID" url="http://www.securityfocus.com/bid/22365">22365</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0461">ADV-2007-0461</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24009">24009</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32137">ca-brightstor-catirpc-dos(32137)</ref><ref source="" url="http://supportconnectw.ca.com/public/storage/infodocs/babtapeng-securitynotice.asp"></ref><ref source="" url="http://www3.ca.com/securityadvisor/newsinfo/collateral.aspx?cid=101317"></ref><ref source="" url="http://www3.ca.com/securityadvisor/vulninfo/vuln.aspx?id=35058"></ref><ref source="SECUNIA" url="http://secunia.com/advisories/24512">24512</ref></refs><vuln_soft><prod name="BrightStor ARCServe Backup" vendor="Computer Associates"><vers num="11.5"/><vers num="11.1"/><vers num="11.5 SP2"/><vers num="11.5 SP1"/><vers num="11"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" modified="2007-02-08" name="CVE-2007-0817" published="2007-02-07" seq="2007-0817" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in Adobe ColdFusion web server allows remote attackers to inject arbitrary HTML or web script via the User-Agent HTTP header, which is not sanitized before being displayed in an error page.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/459178/100/0/threaded">20070205 Cold Fusion Web Server XSS 0 day</ref><ref source="BID" url="http://www.securityfocus.com/bid/22401">22401</ref><ref source="" url="http://www.adobe.com/support/security/bulletins/apsb07-04.html"></ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0593">
ADV-2007-0593</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017645">
1017645</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24115">
24115</ref></refs><vuln_soft><prod name="ColdFusion MX" vendor="Adobe"><vers num="7.0.2"/><vers num="7.0.1"/><vers num="6.1"/></prod></vuln_soft></entry><entry modified="2007-03-30" name="CVE-2007-0818" published="2007-02-07" reject="1" seq="2007-0818" type="CVE"><desc><descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2007-0396.  Reason: This candidate is a duplicate of CVE-2007-0396.  Notes: All CVE users should reference CVE-2007-0396 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</descript></desc><loss_types><avail/></loss_types><range><network/></range><refs/><vuln_soft><prod name="HP-UX" vendor="HP"><vers num="B.11.23"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-02-09" name="CVE-2007-0819" published="2007-02-08" seq="2007-0819" severity="High" type="CVE"><desc><descript source="cve">HP Network Node Manager (NNM) Remote Console 7.50 assigns Everyone Full Control permission for the %PROGRAMFILES%\HP OpenView directory tree, which allows local users to gain privileges via a Trojan horse executable file or ActiveX component, or a modified bin\ovtrcsvc.exe for the HP Open View Shared Trace Service.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><access/><design/></vuln_types><range><local/></range><refs><ref adv="1" source="FULLDISC" url="http://archives.neohapsis.com/archives/fulldisclosure/2007-02/0174.html">20070208 SecurityVulns.com: HP Network Node Manager remote console weak files permissions</ref><ref adv="1" source="" url="http://securityvulns.com/news/HP/NNM/RC/WP.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/22475">
22475</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0533">
ADV-2007-0533</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1017609">
1017609</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24066">
24066</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32362">
openview-nnm-directory-privilege-escalation(32362)</ref></refs><vuln_soft><prod name="Network Node Manager Remote Console" vendor="HP"><vers num="7.50"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-02-08" name="CVE-2007-0820" published="2007-02-07" seq="2007-0820" severity="High" type="CVE"><desc><descript source="cve">Multiple PHP remote file inclusion vulnerabilities in Cedric CLAIRE PortailPhp 2 allow remote attackers to execute arbitrary PHP code via a URL in the chemin parameter to (1) mod_news/index.php, (2) mod_news/goodies.php, or (3) mod_search/index.php.  NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BID" url="http://www.securityfocus.com/bid/22381">22381</ref></refs><vuln_soft><prod name="CLAIRE PortailPhp" vendor="Cedric"><vers num="2"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0" modified="2007-02-08" name="CVE-2007-0821" published="2007-02-07" seq="2007-0821" severity="Medium" type="CVE"><desc><descript source="cve">Multiple directory traversal vulnerabilities in Cedric CLAIRE PortailPhp 2 allow remote attackers to read arbitrary files via a .. (dot dot) in the chemin parameter to (1) mod_news/index.php or (2) mod_news/goodies.php.  NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BID" url="http://www.securityfocus.com/bid/22381">22381</ref></refs><vuln_soft><prod name="CLAIRE PortailPhp" vendor="Cedric"><vers num="2"/></prod></vuln_soft></entry><entry CVSS_base_score="1.9" CVSS_exploit_subscore="3.4" CVSS_impact_subscore="2.9" CVSS_score="1.9" CVSS_vector="(AV:L/AC:M/Au:N/C:P/I:N/A:N)" CVSS_version="2.0" modified="2007-02-08" name="CVE-2007-0822" published="2007-02-07" seq="2007-0822" severity="Low" type="CVE"><desc><descript source="cve">umount, when running with the Linux 2.6.15 kernel on Slackware Linux 10.2, allows local users to trigger a NULL dereference and application crash by invoking the program with a pathname for a USB pen drive that was mounted and then physically removed, which might allow the users to obtain sensitive information, including core file contents.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref source="FULLDISC" url="http://archives.neohapsis.com/archives/fulldisclosure/2007-02/0012.html">20070201 umount crash and xterm (kind of) information leak!</ref><ref source="" url="http://gotfault.wordpress.com/2007/01/18/umount-bug/"></ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2007:053">
MDKSA-2007:053</ref><ref source="BID" url="http://www.securityfocus.com/bid/22850">
22850</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017729">
1017729</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:053">MDKSA-2007:053</ref></refs><vuln_soft><prod name="Kernel" vendor="Linux"><vers num="2.6.15"/></prod></vuln_soft></entry><entry CVSS_base_score="1.9" CVSS_exploit_subscore="3.4" CVSS_impact_subscore="2.9" CVSS_score="1.9" CVSS_vector="(AV:L/AC:M/Au:N/C:P/I:N/A:N)" CVSS_version="2.0" modified="2007-02-08" name="CVE-2007-0823" published="2007-02-07" seq="2007-0823" severity="Low" type="CVE"><desc><descript source="cve">xterm on Slackware Linux 10.2 stores information that had been displayed for a different user account using the same xterm process, which might allow local users to bypass file permissions and read other users&apos; files, or obtain other sensitive information, by reading the xterm process memory.  NOTE: it could be argued that this is an expected consequence of multiple users sharing the same interactive process, in which case this is not a vulnerability.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref source="FULLDISC" url="http://archives.neohapsis.com/archives/fulldisclosure/2007-02/0012.html">20070201 umount crash and xterm (kind of) information leak!</ref><ref source="" url="http://gotfault.wordpress.com/2007/02/01/a-funny-case/"></ref></refs><vuln_soft><prod name="Slackware Linux" vendor="Slackware"><vers num="10.2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-02-14" name="CVE-2007-0824" published="2007-02-07" seq="2007-0824" severity="High" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in inhalt.php in LightRO CMS 1.0 allows remote attackers to execute arbitrary PHP code via a URL in the dateien[news] parameter.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://www.milw0rm.com/exploits/3275"></ref><ref source="BID" url="http://www.securityfocus.com/bid/22430">22430</ref><ref source="MILW0RM" url="http://milw0rm.com/exploits/3275">

3275</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0511">
ADV-2007-0511</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32270">
lightro-inhalt-file-include(32270)</ref></refs><vuln_soft><prod name="LightRO CMS" vendor="LightRO"><vers num="1 Beta"/></prod></vuln_soft></entry><entry CVSS_base_score="7.8" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.9" CVSS_score="7.8" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_version="2.0" modified="2007-02-08" name="CVE-2007-0825" published="2007-02-07" seq="2007-0825" severity="High" type="CVE"><desc><descript source="cve">FlashFXP 3.4.0 build 1145 allows remote servers to cause a denial of service (CPU consumption) via a response to a PWD command that contains a long string with deeply nested directory structure, possibly due to a buffer overflow.</descript></desc><loss_types><avail/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref source="" url="http://www.milw0rm.com/exploits/3276"></ref><ref source="BID" url="http://www.securityfocus.com/bid/22433">22433</ref><ref source="MILW0RM" url="http://milw0rm.com/exploits/3276">

3276</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32416">
flashfxp-pwdcommand-dos(32416)</ref></refs><vuln_soft><prod name="FlashFXP" vendor="FlashFXP"><vers num="3.4.0 build 1145"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-02-08" name="CVE-2007-0826" published="2007-02-07" seq="2007-0826" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in forum.asp in Kisisel Site 2007 allows remote attackers to execute arbitrary SQL commands via the forumid parameter.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://www.milw0rm.com/exploits/3278"></ref><ref source="MILW0RM" url="http://milw0rm.com/exploits/3278">

3278</ref><ref source="BID" url="http://www.securityfocus.com/bid/22435">
22435</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0510">
ADV-2007-0510</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32422">
kisisel-forum-sql-injection(32422)</ref></refs><vuln_soft><prod name="Kisisel Site forum.asp" vendor="Kisisel Site 2007"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-08-03" name="CVE-2007-0827" published="2007-02-07" seq="2007-0827" severity="Medium" type="CVE"><desc><descript source="cve">The Alibaba Alipay PTA Module ActiveX control (PTA.DLL) allows remote attackers to execute arbitrary code via a JavaScript function that invokes the Remove method with an invalid index argument, which is used as an offset for a function call.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><access/><input buffer="1"/></vuln_types><range><network/><user_init/></range><refs><ref source="" url="http://www.milw0rm.com/exploits/3279"></ref><ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2007-February/052250.html">20070207 Alibaba Alipay Remote Code Execute Vulnerability-0DAY</ref><ref source="MILW0RM" url="http://milw0rm.com/exploits/3279">3279</ref><ref source="BID" url="http://www.securityfocus.com/bid/22446">22446</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0520">ADV-2007-0520</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24063">24063</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32367">alipay-activex-code-execution(32367)</ref></refs><vuln_soft><prod name="Alipay ActiveX control" vendor="Alibaba"><vers num="2.4.2.471" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-02-08" name="CVE-2007-0828" published="2007-02-07" seq="2007-0828" severity="High" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in affichearticles.php3 in MySQLNewsEngine allows remote attackers to execute arbitrary PHP code via a URL in the newsenginedir parameter.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/459290/100/0/threaded">20070206 MySQLNewsEngine (affichearticles.php3) Remote File Inc. Vuln.</ref><ref source="BID" url="http://www.securityfocus.com/bid/22431">22431</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0513">
ADV-2007-0513</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32266">
mysqlnewsengine-affichearticle-file-include(32266)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2229">2229</ref></refs><vuln_soft><prod name="MySQLNewsEngine" vendor="MySQLNewsEngine"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="4.4" CVSS_exploit_subscore="3.4" CVSS_impact_subscore="6.4" CVSS_score="4.4" CVSS_vector="(AV:L/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-02-08" name="CVE-2007-0829" published="2007-02-07" seq="2007-0829" severity="Medium" type="CVE"><desc><descript source="cve">avast! Server Edition before 4.7.726 does not demand a password in a certain intended context, even when a password has been set, which allows local users to bypass authentication requirements.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref source="" url="http://www.avast.com/eng/avast-4-server-revision-history.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/22425">22425</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0499">ADV-2007-0499</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24068">24068</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32269">
avast-password-security-bypass(32269)</ref></refs><vuln_soft><prod name="Avast Antivirus" vendor="ALWIL"><vers edition="Server" num="4.7.676"/><vers edition="Server" num="4.7.660"/><vers edition="Server" num="4.6.566"/><vers edition="Server" num="4.6.489"/><vers edition="Server" num="4.6.460"/></prod></vuln_soft></entry><entry CVSS_base_score="3.5" CVSS_exploit_subscore="6.8" CVSS_impact_subscore="2.9" CVSS_score="3.5" CVSS_vector="(AV:N/AC:M/Au:S/C:N/I:P/A:N)" CVSS_version="2.0" modified="2008-03-03" name="CVE-2007-0830" published="2007-02-07" seq="2007-0830" severity="Low" type="CVE"><desc><descript source="cve">** DISPUTED **  Multiple cross-site scripting (XSS) vulnerabilities in the Admin Control Panel (AdminCP) in Jelsoft vBulletin 3.6.4 allow remote authenticated administrators to inject arbitrary web script or HTML via unspecified vectors related to the (1) User Group Manager, (2) User Rank Manager, (3) User Title Manager, (4) BB Code Manager, (5) Attachment Manager, (6) Calendar Manager, and (7) Forums &amp; Moderators functions.  NOTE: the vendor disputes this issue, stating that modifying HTML is an intended privilege of an administrator.  NOTE: it is possible that this issue overlaps CVE-2006-6040.</descript></desc><impacts><impact source="nvd">Vendor has stated that remotely authenticated administrators were given the ability to inject arbitrary HTML/webscript code by design.</impact></impacts><loss_types><int/></loss_types><range><network/><user_init/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/459289/100/0/threaded">20070206 VBulletin AdminCP Index.PHP Multiple Cross-Site Scripting Vulnerability</ref><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/459367/100/0/threaded">20070207 Re: VBulletin AdminCP Index.PHP Multiple Cross-Site Scripting Vulnerability</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/32268">vbulletin-admincp-index-xss(32268)</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24085">24085</ref></refs><vuln_soft><prod name="VBulletin" vendor="Jelsoft"><vers num="3.6.4"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-02-09" name="CVE-2007-0831" published="2007-02-07" seq="2007-0831" severity="High" type="CVE"><desc><descript source="cve">** DISPUTED ** Multiple PHP remote file inclusion vulnerabilities in Atsphp 5.0.1 allow remote attackers to execute arbitrary PHP code via a URL in the CONF[path] parameter to (1) index.php, (2) sources/usercp.php, or (3) sources/admin.php.  NOTE: Another researcher has disputed this vulnerability, noting that CONF[path] is defined before use in index.php, that CONF[path] inclusion cannot occur through a direct request to other affected files, and that usercp.php is a typo of user_cp.php.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/458581/100/100/threaded">20070130 Atsphp 5.0.1 [Top Sites] [index.php] - Remote File Include</ref><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/458600/100/0/threaded">20070130 Re: BOGUS: Atsphp 5.0.1 [Top Sites] [index.php] - Remote File Include</ref></refs><vuln_soft><prod name="Atsphp" vendor="Atsphp"><vers num="5.0.1"/></prod></vuln_soft></entry><entry CVSS_base_score="1.2" CVSS_exploit_subscore="1.9" CVSS_impact_subscore="2.9" CVSS_score="1.2" CVSS_vector="(AV:L/AC:H/Au:N/C:P/I:N/A:N)" CVSS_version="2.0" modified="2007-02-09" name="CVE-2007-0832" published="2007-02-07" seq="2007-0832" severity="Low" type="CVE"><desc><descript source="cve">VMware Workstation 5.5.3 34685 does not immediately change the availability of a shared clipboard when the &quot;Enable copy and paste to and from this virtual machine&quot; checkbox is changed, which allows local users to obtain sensitive information or conduct certain attacks that are facilitated by weaker isolation between the host and guest operating systems.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/><env/></vuln_types><range><local/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/459140/100/0/threaded">20070203 Vmare workstation guest isolation weaknesses (clipboard transfer)</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/22413">22413</ref></refs><vuln_soft><prod name="VMWare Workstation" vendor="VMWare"><vers num="5.5.3.34685"/></prod></vuln_soft></entry><entry CVSS_base_score="1.2" CVSS_exploit_subscore="1.9" CVSS_impact_subscore="2.9" CVSS_score="1.2" CVSS_vector="(AV:L/AC:H/Au:N/C:P/I:N/A:N)" CVSS_version="2.0" modified="2007-02-09" name="CVE-2007-0833" published="2007-02-07" seq="2007-0833" severity="Low" type="CVE"><desc><descript source="cve">VMware Workstation 5.5.3 34685, when the &quot;Enable copy and paste to and from this virtual machine&quot; option is enabled, preserves clipboard data on the guest operating system after it was deleted on the host operating system, which might allow local users to read clipboard contents by moving the focus back to the host operating system.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/><env/></vuln_types><range><local/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/459140/100/0/threaded">20070203 Vmare workstation guest isolation weaknesses (clipboard transfer)</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/22413">22413</ref></refs><vuln_soft><prod name="VMWare Workstation" vendor="VMWare"><vers num="5.5.3.34685"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-02-09" name="CVE-2007-0834" published="2007-02-07" seq="2007-0834" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in FlashChat 4.7.8 allows remote attackers to inject arbitrary web script or HTML via the user name field when the user joins a chat room, a different vulnerability than CVE-2007-0807.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24071">24071</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32417">
flashchat-username-xss(32417)</ref></refs><vuln_soft><prod name="FlashChat" vendor="Darrens 5-Dollar Script Archive"><vers num="4.7.8"/></prod></vuln_soft></entry><entry CVSS_base_score="6.5" CVSS_exploit_subscore="8.0" CVSS_impact_subscore="6.4" CVSS_score="6.5" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-02-09" name="CVE-2007-0835" published="2007-02-07" seq="2007-0835" severity="Medium" type="CVE"><desc><descript source="cve">admin.php in Coppermine Photo Gallery 1.4.10, and possibly earlier, allows remote authenticated users to execute arbitrary shell commands via shell metacharacters (&quot;;&quot; semicolon) in the &quot;Command line options for ImageMagick&quot; form field, when used as an option to ImageMagick&apos;s convert command.  NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BID" url="http://www.securityfocus.com/bid/22406">22406</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24019">24019</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32236">coppermine-admin-command-execution(32236)</ref></refs><vuln_soft><prod name="Coppermine Photo Gallery" vendor="Coppermine"><vers num="1.4.10" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.0" CVSS_exploit_subscore="8.0" CVSS_impact_subscore="2.9" CVSS_score="4.0" CVSS_vector="(AV:N/AC:L/Au:S/C:N/I:P/A:N)" CVSS_version="2.0" modified="2007-02-09" name="CVE-2007-0836" published="2007-02-07" seq="2007-0836" severity="Medium" type="CVE"><desc><descript source="cve">admin.php in Coppermine Photo Gallery 1.4.10, and possibly earlier, allows remote authenticated users to include arbitrary local and possibly remote files via the (1) &quot;Path to custom header include&quot; and (2) &quot;Path to custom footer include&quot; form fields.  NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BID" url="http://www.securityfocus.com/bid/22409">22409</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24019">24019</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32233">coppermine-admin-file-include(32233)</ref></refs><vuln_soft><prod name="Coppermine Photo Gallery" vendor="Coppermine"><vers num="1.4.10" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-02-09" name="CVE-2007-0837" published="2007-02-07" seq="2007-0837" severity="High" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in examples/inc/top.inc.php in AgerMenu 0.03 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the rootdir parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://www.milw0rm.com/exploits/3280"></ref><ref source="VIM" url="http://www.attrition.org/pipermail/vim/2007-February/001297.html">20070207 false: Agermenu 0.03</ref><ref source="VIM" url="http://www.attrition.org/pipermail/vim/2007-February/001288.html">20070207 true: agermenu</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0512">ADV-2007-0512</ref><ref source="MILW0RM" url="http://milw0rm.com/exploits/3280">

3280</ref><ref source="BID" url="http://www.securityfocus.com/bid/22442">
22442</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32283">
agermenu-topinc-file-include(32283)</ref></refs><vuln_soft><prod name="AgerMenu" vendor="AgerMenu"><vers num="0.03"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0" modified="2007-02-09" name="CVE-2007-0838" published="2007-02-07" seq="2007-0838" severity="Medium" type="CVE"><desc><descript source="cve">FreeProxy before 3.92 Build 1626 allows malicious users to cause a denial of service (infinite loop) via a HOST: header with a hostname and port number that refers to the server itself.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/><design/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=117086856902907&amp;w=2">20070206 Medium level security hole in FreeProxy</ref><ref adv="1" source="FULLDISC" url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=117085666921871&amp;w=2">20070206 Medium level security hole in FreeProxy</ref><ref adv="1" patch="1" source="" url="http://www.handcraftedsoftware.org/index.php?page=3&amp;mode=article&amp;k=60"></ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0514">ADV-2007-0514</ref><ref source="BID" url="http://www.securityfocus.com/bid/22445">
22445</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24064">
24064</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32303">
freeproxy-hostname-portnumber-dos(32303)</ref></refs><vuln_soft><prod name="FreeProxy" vendor="FreeProxy"><vers num="3.92"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-02-09" name="CVE-2007-0839" published="2007-02-07" seq="2007-0839" severity="High" type="CVE"><desc><descript source="cve">Multiple PHP remote file inclusion vulnerabilities in index/index_album.php in Valarsoft WebMatic 2.6 allow remote attackers to execute arbitrary PHP code via a URL in the (1) P_LIB and (2) P_INDEX parameters.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://www.milw0rm.com/exploits/3281"></ref><ref source="VIM" url="http://www.attrition.org/pipermail/vim/2007-February/001292.html">20070207 true: WebMatic 2.6 RFI</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/22444">22444</ref><ref source="MILW0RM" url="http://milw0rm.com/exploits/3281">

3281</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0534">
ADV-2007-0534</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24092">
24092</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32318">
webmatic-indexalbum-file-include(32318)</ref></refs><vuln_soft><prod name="WebMatic" vendor="Valarsoft"><vers num="2.6"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-02-09" name="CVE-2007-0840" published="2007-02-07" seq="2007-0840" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in HLstats before 1.35 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors in the search class.  NOTE: it is possible that this issue overlaps CVE-2006-4543.3 or CVE-2006-4454.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref patch="1" source="" url="http://sourceforge.net/project/shownotes.php?release_id=484226"></ref><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/22422">22422</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24062">24062</ref></refs><vuln_soft><prod name="HLstats" vendor="HLstats"><vers num="1.34"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-02-09" name="CVE-2007-0841" published="2007-02-07" seq="2007-0841" severity="High" type="CVE"><desc><descript source="cve">Multiple unspecified vulnerabilities in vbDrupal before 4.7.6.0 have unknown impact and remote attack vectors.  NOTE: the vector related to Drupal is covered by CVE-2007-0626.  These vulnerabilities might be associated with other CVE identifiers.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs><ref adv="1" patch="1" source="" url="http://www.vbdrupal.org/forum/showthread.php?t=786"></ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0415">ADV-2007-0415</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/23990">23990</ref></refs><vuln_soft><prod name="vbDrupal" vendor="vbDrupal"><vers num="4.7.5.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.8" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.9" CVSS_score="7.8" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_version="2.0" modified="2007-08-03" name="CVE-2007-0842" published="2007-02-13" seq="2007-0842" severity="High" type="CVE"><desc><descript source="cve">The 64-bit versions of Microsoft Visual C++ 8.0 standard library (MSVCR80.DLL) time functions, including (1) localtime, (2) localtime_s, (3) gmtime, (4) gmtime_s, (5) ctime, (6) ctime_s, (7) wctime, (8) wctime_s, and (9) fstat, trigger an assertion error instead of a NULL pointer or EINVAL when processing a time argument later than Jan 1, 3000, which might allow context-dependent attackers to cause a denial of service (application exit) via large time values. NOTE: it could be argued that this is a design limitation of the functions, and the vulnerability lies with any application that does not validate arguments to these functions.  However, this behavior is inconsistent with documentation, which does not list assertions as a possible result of an error condition.</descript></desc><loss_types><avail/></loss_types><vuln_types><design/><exception/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/459847/100/0/threaded">20070212 SecurityVulns.com: Microsoft Visual C++ 8.0 standard library time functions invalid assertion DoS (Problem 3000). </ref><ref source="" url="http://msdn2.microsoft.com/en-us/library/a442x3ye(VS.80).aspx"></ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32454">visualstudio-time-dos(32454)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2237">2237</ref></refs><vuln_soft><prod name="Visual C++" vendor="Microsoft"><vers num="8.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2008-01-02" name="CVE-2007-0843" published="2007-02-22" seq="2007-0843" severity="Medium" type="CVE"><desc><descript source="cve">The ReadDirectoryChangesW API function on Microsoft Windows 2000, XP, Server 2003, and Vista does not check permissions for child objects, which allows local users to bypass permissions by opening a directory with LIST (READ) access and using ReadDirectoryChangesW to monitor changes of files that do not have LIST permissions, which can be leveraged to determine filenames, access times, and other sensitive information.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/460899/100/0/threaded">20070222 Microsoft Windows 2000/XP/2003/Vista ReadDirectoryChangesW informaton leak</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/460887/100/0/threaded">20070222 Re[2]: [Full-disclosure] Microsoft Windows 2000/XP/2003/Vista ReadDirectoryChangesW informaton leak</ref><ref adv="1" source="" url="http://securityvulns.com/advisories/readdirectorychanges.asp"></ref><ref source="BID" url="http://www.securityfocus.com/bid/22664">22664</ref><ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2007-February/052613.html">20070222 Microsoft Windows 2000/XP/2003/Vista ReadDirectoryChangesW informaton leak</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24245">24245</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0701">ADV-2007-0701</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2282">2282</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32644">win-readdirectory-information-disclosure(32644)</ref></refs><vuln_soft><prod name="Windows Vista" vendor="Microsoft"><vers num="Beta 1" prev="1"/></prod><prod name="Windows XP" vendor="Microsoft"><vers edition="Tablet PC" num="SP1" prev="1"/><vers edition="Professional" num="SP1" prev="1"/><vers edition="Media Center" num="SP1" prev="1"/><vers edition="Home" num="SP1" prev="1"/><vers edition="Gold" num="SP1" prev="1"/><vers edition="Embedded" num="SP1" prev="1"/><vers edition="64-bit 2003" num="SP1" prev="1"/><vers edition="Tablet PC" num="SP2" prev="1"/><vers edition="Professional" num="SP2" prev="1"/><vers edition="Media Center" num="SP2" prev="1"/><vers edition="Home" num="SP2" prev="1"/><vers num="Home"/></prod><prod name="windows-nt" vendor="Microsoft"><vers num="2000"/></prod><prod name="Windows Server 2003" vendor="Microsoft"><vers num="Web" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.4" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="4.9" CVSS_score="6.4" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_version="2.0" modified="2007-02-09" name="CVE-2007-0844" published="2007-02-08" seq="2007-0844" severity="Medium" type="CVE"><desc><descript source="cve">The auth_via_key function in pam_ssh.c in pam_ssh before 1.92, when the allow_blank_passphrase option is disabled, allows remote attackers to bypass authentication restrictions and use private encryption keys requiring a blank passphrase by entering a non-blank passphrase.</descript></desc><loss_types><conf/><int/></loss_types><vuln_types><input/><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="" url="http://sourceforge.net/project/shownotes.php?release_id=484376"></ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0524">ADV-2007-0524</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24061">24061</ref><ref source="BID" url="http://www.securityfocus.com/bid/22461">
22461</ref></refs><vuln_soft><prod name="pam_ssh" vendor="pam_ssh"><vers num="1.91"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-02-09" name="CVE-2007-0845" published="2007-02-08" seq="2007-0845" severity="High" type="CVE"><desc><descript source="cve">admin/index.php in Advanced Poll 2.0.0 through 2.0.5-dev allows remote attackers to bypass authentication and gain administrator privileges by obtaining a valid session identifier and setting the uid parameter to 1.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/><input/><design/></vuln_types><range><network/></range><refs><ref source="" url="http://www.milw0rm.com/exploits/3282"></ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/22451">22451</ref><ref source="MILW0RM" url="http://milw0rm.com/exploits/3282">

3282</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32337">
advancedpoll-index-code-execution(32337)</ref></refs><vuln_soft><prod name="Advanced Poll" vendor="Advanced Poll"><vers edition="dev" num="2.0.5"/><vers num="2.0.4"/><vers num="2.0.3"/><vers num="2.0.2"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-02-09" name="CVE-2007-0846" published="2007-02-08" seq="2007-0846" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in forum.php in Open Tibia Server CMS (OTSCMS) 2.1.5 and earlier allows remote attackers to inject arbitrary HTML or web script via the name parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref source="" url="http://www.milw0rm.com/exploits/3283"></ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/22450">22450</ref><ref source="MILW0RM" url="http://milw0rm.com/exploits/3283">

3283</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24116">
24116</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32324">
otscms-forum-xss(32324)</ref></refs><vuln_soft><prod name="Open Tibia Server CMS" vendor="Open Tibia Server CMS"><vers num="2.1.5"/><vers num="2.1.4"/><vers num="2.1.3"/><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-02-09" name="CVE-2007-0847" published="2007-02-08" seq="2007-0847" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in mod/PM/reply.php in Open Tibia Server CMS (OTSCMS) 2.1.5 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter to priv.php.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://www.milw0rm.com/exploits/3283"></ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/22450">22450</ref><ref source="MILW0RM" url="http://milw0rm.com/exploits/3283">

3283</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24116">
24116</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32322">
otscms-priv-sql-injection(32322)</ref></refs><vuln_soft><prod name="Open Tibia Server CMS" vendor="Open Tibia Server CMS"><vers num="2.1.5"/><vers num="2.1.4"/><vers num="2.1.3"/><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-02-09" name="CVE-2007-0848" published="2007-02-08" seq="2007-0848" severity="High" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in classes/class_mail.inc.php in Maian Recipe 1.0 allows remote attackers to execute arbitrary PHP code via a URL in the path_to_folder parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://www.milw0rm.com/exploits/3284"></ref><ref source="VIM" url="http://www.attrition.org/pipermail/vim/2007-February/001299.html">20070207 true: Agermenu 0.03</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24074">24074</ref><ref source="MILW0RM" url="http://milw0rm.com/exploits/3284">

3284</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0537">
ADV-2007-0537</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32346">
maianrecipe-classmail-file-include(32346)</ref></refs><vuln_soft><prod name="Maian Recipe" vendor="Maian Recipe"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-02-12" name="CVE-2007-0849" published="2007-02-08" seq="2007-0849" severity="High" type="CVE"><desc><descript source="cve">scripts/cronscript.php in SysCP 1.2.15 and earlier does not properly quote pathnames in user home directories, which allows local users to gain privileges by placing shell metacharacters in a directory name, and then using the control panel to protect this directory, a different vulnerability than CVE-2005-2568.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/459397/100/0/threaded">20070207 Ability to inject and execute any code as root in SysCP</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/22453">22453</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24102">
24102</ref></refs><vuln_soft><prod name="SysCP" vendor="SysCP Team"><vers num="1.2.15" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-02-09" name="CVE-2007-0850" published="2007-02-08" seq="2007-0850" severity="High" type="CVE"><desc><descript source="cve">scripts/cronscript.php in SysCP 1.2.15 and earlier includes and executes arbitrary PHP scripts that are referenced by the panel_cronscript table in the SysCP database, which allows attackers with database write privileges to execute arbitrary code by constructing a PHP file and adding its filename to this table.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/459397/100/0/threaded">20070207 Ability to inject and execute any code as root in SysCP</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/22454">22454</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24102">
24102</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32330">
syscp-cronscript-code-execution(32330)</ref></refs><vuln_soft><prod name="SysCP" vendor="SysCP Team"><vers num="1.2.15"/><vers num="1.2.10"/></prod></vuln_soft></entry><entry CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" CVSS_score="9.3" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-05-16" name="CVE-2007-0851" published="2007-02-08" seq="2007-0851" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in the Trend Micro Scan Engine 8.000 and 8.300 before virus pattern file 4.245.00, as used in other products such as Cyber Clean Center (CCC) Cleaner, allows remote attackers to execute arbitrary code via a malformed UPX compressed executable.</descript></desc><impacts><impact source="nvd">Failed exploit attempts will likely cause a denial-of-service condition.</impact></impacts><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="IDEFENSE" url="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=470">20070208 Trend Micro AntiVirus UPX Parsing Kernel Buffer Overflow Vulnerability</ref><ref adv="1" patch="1" source="" url="http://esupport.trendmicro.com/support/viewxml.do?ContentID=EN-1034289"></ref><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/22449">22449</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0522">ADV-2007-0522</ref><ref adv="1" patch="1" source="SECTRACK" url="http://securitytracker.com/id?1017601">1017601</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/24087">24087</ref><ref source="" url="http://jvn.jp/jp/JVN%2377366274/index.html"></ref><ref source="" url="http://www.jpcert.or.jp/at/2007/at070004.txt"></ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/276432">VU#276432</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1017602">1017602</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1017603">1017603</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24128">24128</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32352">antivirus-upx-bo(32352)</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0569">ADV-2007-0569</ref></refs><vuln_soft><prod name="OfficeScan" vendor="Trend Micro"><vers num="7.3"/><vers edition="Corporate" num="3.0"/><vers edition="Windows NT Server" num="Corporate 3.0"/><vers edition="Windows NT Server" num="Corporate 3.1.1"/><vers num="Corporate 3.11"/><vers edition="Windows NT Server" num="Corporate 3.11"/><vers num="Corporate 3.13"/><vers edition="Windows NT Server" num="Corporate 3.13"/><vers num="Corporate 3.5"/><vers edition="Windows NT Server" num="Corporate 3.5"/><vers num="Corporate 3.54"/><vers num="Corporate 5.02"/><vers num="Corporate 5.5"/><vers num="Corporate 5.58"/><vers num="Corporate 6.5"/><vers num="Corporate 7.0"/><vers num="Corporate 7.3"/><vers edition="Microsof SBS" num="4.5.0"/></prod><prod name="InterScan VirusWall for Windows NT" vendor="Trend Micro"><vers num="3.4"/><vers num="3.5"/><vers num="3.51"/><vers num="3.52"/><vers num="3.52 build1466"/><vers num="3.6"/><vers num="5.1.0"/></prod><prod name="ScanMail" vendor="Trend Micro"><vers num="1.0.0"/><vers edition="Domino" num="2.51"/><vers edition="Domino" num="2.6"/><vers edition="Microsoft Exchange" num="3.8"/><vers edition="Microsoft Exchange" num="3.81"/><vers edition="Microsoft Exchange" num="6.1"/><vers edition="Lotus Domino on AIX" num="Gold"/><vers edition="Lotus Domino on AS_400" num="Gold"/><vers edition="Lotus Domino on S_390" num="Gold"/><vers edition="Lotus Domino on Solaris" num="Gold"/><vers edition="Lotus Domino on Windows" num="Gold"/></prod><prod name="Web Security Suite" vendor="Trend Micro"><vers num="1.2.0"/></prod><prod name="VirusWall" vendor="Trend Micro"><vers num="3.0.1"/></prod><prod name="InterScan WebManager" vendor="Trend Micro"><vers num="1.2"/><vers num="2.0"/><vers num="2.1"/></prod><prod name="InterScan VirusWall Scan Engine" vendor="Trend Micro"><vers num="7.510.0-1002"/></prod><prod name="Client-Server Suite SMB" vendor="Trend Micro"><vers edition="Windows" num="Gold"/></prod><prod name="PC-Cillin Internet Security" vendor="Trend Micro"><vers num="14 14.00.1485"/><vers num="2005 12.0.0 0 build 1244"/><vers num="2006 14.10.0.1023"/><vers num="2007"/></prod><prod name="InterScan VirusWall" vendor="Trend Micro"><vers edition="Unix" num="3.0.1"/><vers num="3.2.3"/><vers num="3.3"/><vers num="3.32"/><vers num="3.6"/><vers edition="Windows NT" num="3.6"/><vers num="3.6.0 build1166"/><vers num="3.6.0 Build 1182"/><vers num="3.7.0"/><vers num="3.7.0 Build1190"/><vers num="3.8.0 Build1130"/><vers edition="Windows NT" num="5.1"/><vers edition="AIX" num="Gold"/><vers edition="HP_UX" num="3.6"/><vers edition="Linux" num="3.0.1"/><vers edition="Linux" num="3.6.5"/><vers edition="SMB" num="Gold"/><vers edition="Solaris" num="3.6"/><vers edition="Windows" num="Gold"/><vers edition="Linux for SMB" num="Gold"/><vers edition="Windows NT for SMB" num="Gold"/><vers edition="Linux" num="3.1.0"/><vers edition="Linux" num="3.81"/></prod><prod name="PortalProtect" vendor="Trend Micro"><vers num="1.0"/><vers edition="Sharepoint" num="1.2"/></prod><prod name="Scanning Engine" vendor="Trend Micro"><vers num="7.1.0"/></prod><prod name="Client-Server-Messaging Suite SMB" vendor="Trend Micro"><vers edition="Windows" num="Gold"/></prod><prod name="WebProtect" vendor="Trend Micro"><vers num="3.1.0"/></prod><prod name="InterScan Messaging Security Suite" vendor="Trend Micro"><vers edition="Linux 5.1.1" num=""/><vers num="3.81"/><vers num="5.5"/><vers num="5.5 build 1183"/><vers edition="Linux" num="Gold"/><vers edition="Solaris" num="Gold"/><vers edition="Windows" num="Gold"/></prod><prod name="InterScan Web Security Suite" vendor="Trend Micro"><vers edition="Linux" num="Gold"/><vers edition="Solaris" num="Gold"/><vers edition="Windows" num="Gold"/><vers edition="Linux" num=""/><vers edition="Linux 1.0.0 ja" num=""/></prod><prod name="InterScan eManager" vendor="Trend Micro"><vers num="3.51"/><vers num="3.51 j"/><vers edition="HP" num="3.5"/><vers edition="Windows" num="3.5.2"/><vers edition="Sun" num="3.6"/><vers edition="Linux" num="3.6"/></prod><prod name="ScanMail eManager" vendor="Trend Micro"><vers num=""/></prod><prod name="ServerProtect" vendor="Trend Micro"><vers edition="Windows" num="5.58"/><vers num="5.3.1"/><vers num="5.5.8"/><vers num="5.58"/><vers num="Linux"/><vers num="Linux 1.2.0"/><vers num="Novell Netware"/><vers num="Windows"/></prod><prod name="InterScan WebProtect" vendor="Trend Micro"><vers edition="ISA" num="Gold"/></prod><prod name="Control Manager" vendor="Trend Micro"><vers num="2.5.0"/><vers num="3.5"/><vers edition="AS_400" num="Gold"/><vers num="NetWare"/><vers edition="S_390" num="Gold"/><vers edition="Solaris" num="Gold"/><vers edition="Windows" num="Gold"/><vers edition="Windows NT" num="Gold"/></prod><prod name="PC-cillin" vendor="Trend Micro"><vers num="2000"/><vers num="2002"/><vers num="2003"/><vers num="2005"/><vers num="2006"/><vers num="6.0"/></prod><prod name="PC Cillin - Internet Security 2006" vendor="Trend Micro"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-02-09" name="CVE-2007-0852" published="2007-02-08" seq="2007-0852" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in DevTrack 6.x allows remote attackers to inject arbitrary web script or HTML via the &quot;Keyword search&quot; form field and unspecified other form fields that populate a public saved query.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/23217">23217</ref><ref source="BID" url="http://www.securityfocus.com/bid/22460">

22460</ref></refs><vuln_soft><prod name="DevTrack" vendor="TechExcel Inc."><vers num="6.0.3"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-02-09" name="CVE-2007-0853" published="2007-02-08" seq="2007-0853" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in DevTrack 6.0.3 allows remote attackers to execute arbitrary SQL commands via the Username form field.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/23217">23217</ref><ref source="BID" url="http://www.securityfocus.com/bid/22460">

22460</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32348">
devtrack-username-sql-injection(32348)</ref></refs><vuln_soft><prod name="DevTrack" vendor="TechExcel Inc."><vers num="6.0.3"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-08-03" name="CVE-2007-0854" published="2007-02-08" seq="2007-0854" severity="High" type="CVE"><desc><descript source="cve">Remote file inclusion vulnerability in scripts2/objcache in cPanel WebHost Manager (WHM) allows remote attackers to execute arbitrary code via a URL in the obj parameter.  NOTE: a third party claims that this issue is not file inclusion because the contents are not parsed, but the attack can be used to overwrite files in /var/cpanel/objcache or provide unexpected web page contents.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/459409/100/0/threaded">20070207 remote file include in whm (all version)</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/459449/100/0/threaded">20070208 Re: remote file include in whm (all version)</ref><ref source="" url="http://changelog.cpanel.net/index.cgi"></ref><ref source="BID" url="http://www.securityfocus.com/bid/22455">22455</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0545">ADV-2007-0545</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24097">24097</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32400">cpanel-webhost-objcache-xss(32400)</ref></refs><vuln_soft><prod name="WebHost Manager" vendor="cPanel"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" discovered="2006-12-12" modified="2007-06-27" name="CVE-2007-0855" published="2007-02-08" seq="2007-0855" severity="Medium" type="CVE"><desc><descript source="cve">Stack-based buffer overflow in RARLabs Unrar, as packaged in WinRAR and possibly other products, allows user-assisted remote attackers to execute arbitrary code via a crafted, password-protected archive.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" patch="1" source="IDEFENSE" url="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=472">20070207 RARLabs Unrar Password Prompt Buffer Overflow Vulnerability</ref><ref source="BID" url="http://www.securityfocus.com/bid/22447">22447</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0523">ADV-2007-0523</ref><ref patch="1" source="SECTRACK" url="http://securitytracker.com/id?1017593">1017593</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/24077">24077</ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200702-04.xml">GLSA-200702-04</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24165">24165</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32357">unrar-password-archive-bo(32357)</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2007_5_sr.html">SUSE-SR:2007:005</ref></refs><vuln_soft><prod name="UnRAR" vendor="RARLAB"><vers num="3.61"/><vers num="3.60"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" discovered="2007-01-17" modified="2007-02-12" name="CVE-2007-0856" published="2007-02-08" seq="2007-0856" severity="High" type="CVE"><desc><descript source="cve">TmComm.sys 1.5.0.1052 in the Trend Micro Anti-Rootkit Common Module (RCM), with the VsapiNI.sys 3.320.0.1003 scan engine, as used in Trend Micro PC-cillin Internet Security 2007, Antivirus 2007, Anti-Spyware for SMB 3.2 SP1, Anti-Spyware for Consumer 3.5, Anti-Spyware for Enterprise 3.0 SP2, Client / Server / Messaging Security for SMB 3.5, Damage Cleanup Services 3.2, and possibly other products, assigns Everyone write permission for the \\.\TmComm DOS device interface, which allows local users to access privileged IOCTLs and execute arbitrary code or overwrite arbitrary memory in the kernel context.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref adv="1" source="IDEFENSE" url="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=469">20070207 Trend Micro TmComm Local Privilege Escalation Vulnerability</ref><ref patch="1" source="" url="http://esupport.trendmicro.com/support/viewxml.do?ContentID=EN-1034432&amp;id=EN-1034432"></ref><ref source="BID" url="http://www.securityfocus.com/bid/22448">22448</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0521">ADV-2007-0521</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1017604">1017604</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1017605">1017605</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1017606">1017606</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/24069">24069</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/282240">
VU#282240</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/666800">
VU#666800</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32353">
trendmicro-tmcomm-privilege-escalation(32353)</ref></refs><vuln_soft><prod name="Client-Server-Messaging Security" vendor="Trend Micro"><vers edition="SMB" num="3.5"/></prod><prod name="TmComm.sys" vendor="Trend Micro"><vers num="1.5.1052"/></prod><prod name="PC-Cillin Internet Security" vendor="Trend Micro"><vers num="2007"/></prod><prod name="Trend Micro AntiVirus" vendor="Trend Micro"><vers num="2007"/></prod><prod name="Trend Micro AntiSpyware" vendor="Trend Micro"><vers edition="SMB" num="3.2 SP1"/><vers edition="Enterprise" num="3.0 SP2"/><vers edition="Consumer" num="3.5"/></prod><prod name="VsapiNI.sys" vendor="Trend Micro"><vers num="3.320.1003"/></prod><prod name="Trend Micro AntiRootkit Common Module" vendor="Trend Micro"><vers num=""/></prod><prod name="Damage Cleanup Services" vendor="Trend Micro"><vers num="3.2"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" modified="2007-02-12" name="CVE-2007-0857" published="2007-02-08" seq="2007-0857" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in MoinMoin before 1.5.7 allow remote attackers to inject arbitrary web script or HTML via (1) the page info, or the page name in a (2) AttachFile, (3) RenamePage, or (4) LocalSiteMap action.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://moinmoin.wikiwikiweb.de/MoinMoinRelease1.5/CHANGES"></ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/24096">24096</ref><ref source="UBUNTU" url="http://www.ubuntu.com/usn/usn-421-1">
USN-421-1</ref><ref source="BID" url="http://www.securityfocus.com/bid/22506">
22506</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0553">
ADV-2007-0553</ref><ref source="OSVDB" url="http://www.osvdb.org/31874">
31874</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24117">
24117</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32377">
moinmoin-pageinfo-pagename-xss(32377)</ref></refs><vuln_soft><prod name="MoinMoin" vendor="MoinMoin"><vers num="1.5.6" prev="1"/><vers num="1.5.5a"/><vers num="1.5.5"/><vers num="1.5.5 rc1"/><vers num="1.5.4"/><vers num="1.5.3"/><vers num="1.5.3 rc2"/><vers num="1.5.3 rc1"/><vers num="1.5.2"/><vers num="1.5.1"/><vers num="1.5.0"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0" discovered="2006-08-14" modified="2007-02-18" name="CVE-2007-0859" published="2007-02-15" seq="2007-0859" severity="Low" type="CVE"><desc><descript source="cve">The Find feature in Palm OS Treo smart phones operates despite the system password lock, which allows attackers with physical access to obtain sensitive information (memory contents) by doing (1) text searches or (2) paste operations after pressing certain keyboard shortcut keys.</descript></desc><loss_types><conf/></loss_types><vuln_types><access/><design/></vuln_types><range><local/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/460059/100/0/threaded">20070213 SYMSA-2007-002: Palm OS Treo Find Feature System Password Bypass</ref><ref adv="1" source="" url="http://www.symantec.com/enterprise/research/SYMSA-2007-002.txt"></ref><ref source="BID" url="http://www.securityfocus.com/bid/22468">22468</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/460954/100/0/threaded">
20070222 RE: SYMSA-2007-002: Palm OS Treo Find Feature System Password Bypass</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/460911/100/0/threaded">
20070222 Re: Re: SYMSA-2007-002: Palm OS Treo Find Feature System Password Bypass</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/460908/100/0/threaded">
20070222 Re: SYMSA-2007-002: Palm OS Treo Find Feature System Password Bypass</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/460901/100/0/threaded">
20070222 SYMSA-2007-002-1: Palm OS Treo Find Feature System Password Bypass</ref><ref source="" url="http://discussion.treocentral.com/showthread.php?p=1199445&amp;posted=1#post1199445"></ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32502">
palmos-findfeature-security-bypass(32502)</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/460328/100/0/threaded">20070216 Re: SYMSA-2007-002: Palm OS Treo Find Feature System Password Bypass</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2260">2260</ref></refs><vuln_soft><prod name="Treo" vendor="Palm"><vers num="700p"/><vers num="680"/><vers num="650"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-02-12" name="CVE-2007-0860" published="2007-02-08" seq="2007-0860" severity="High" type="CVE"><desc><descript source="cve">** DISPUTED **  Multiple PHP remote file inclusion vulnerabilities in local Calendar System 1.1 allow remote attackers to execute arbitrary PHP code via a URL in the (1) TEMPLATE_DIR parameter to (a) showinvoices.php, (b) showmonth.php, (c) showevents.php, (d) retrieveinvoice.php, (e) modifyitem.php, and (f) lookup_userid.php; or the LIBDIR parameter to (g) editevent.php, (h) resetpassword.php, (i) signup.php, showmonth.php, (j) showday.php, showevents.php, and lookup_userid.php. NOTE: this issue has been disputed by a third party, who states that the associated variables are set in config.php before use.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/458312/100/100/threaded">20070127 local Calendar System v1.1 (lcStdLib.inc) Remote File Include</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/458457/100/100/threaded">20070128 Re: local Calendar System v1.1 (lcStdLib.inc) Remote File Include</ref></refs><vuln_soft><prod name="LoCal Calendar System" vendor="Laboratory for Optical and Computational Instrumentation"><vers num="1.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-02-12" name="CVE-2007-0861" published="2007-02-08" seq="2007-0861" severity="High" type="CVE"><desc><descript source="cve">** DISPUTED **  PHP remote file inclusion vulnerability in modules/mail/index.php in phpCOIN RC-1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the _CCFG[&apos;_PKG_PATH_MDLS&apos;] parameter.  NOTE: this issue has been disputed by a reliable third party, who states that a fatal error occurs before the relevant code is reached.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/458064/100/200/threaded">20070125 Re: phpCOIN &lt;= RC-1 (modules/mail/index.php) Remote File Include Vulnerability</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/458080/100/200/threaded">20070125 phpCOIN &lt;= RC-1 (modules/mail/index.php) Remote File Include Vulnerability</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2230">2230</ref></refs><vuln_soft><prod name="phpCOIN" vendor="phpCOIN"><vers num="RC1" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2008-03-07" name="CVE-2007-0862" published="2007-02-08" seq="2007-0862" severity="Medium" type="CVE"><desc><descript source="cve">** DISPUTED **  PHP remote file inclusion vulnerability in index.php in gnopaste 0.5.3 and earlier allows remote attackers to execute arbitrary PHP code via the GNP_REAL_PATH parameter.  NOTE: CVE and a third party dispute this issue, since GNP_REAL_PATH is a constant, not a variable.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/458559/100/100/threaded">20070129 Re: gnopaste &lt;= 0.5.3 (index.php) Remote File Include Vulnerability</ref><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/458460/100/100/threaded">20070129 gnopaste &lt;= 0.5.3 (index.php) Remote File Include Vulnerability</ref></refs><vuln_soft><prod name="gnopaste" vendor="gnopaste"><vers num="0.5.3" prev="1"/><vers num="0.5.2"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-02-12" name="CVE-2007-0863" published="2007-02-08" seq="2007-0863" severity="High" type="CVE"><desc><descript source="cve">** DISPUTED **  PHP remote file inclusion vulnerability in Trevorchan 0.7 and earlier allows remote attackers to execute arbitrary code via the tc_config[rootdir] parameter to (1) upgrade.php, (2) paint_save.php, (3) menu.php, (4) manage.php, and (5) banned.php.  NOTE: his issue has been disputed by reliable third parties, who state that the variable is set before use in config.php.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="VIM" url="http://www.attrition.org/pipermail/vim/2007-January/001241.html">20070115 [Bogus] [ilkerkandemir at mynet.com: Trevorchan &lt;= v0.7 Remote File Include Vulnerability] (fwd)</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1017512">1017512</ref></refs><vuln_soft><prod name="Trevorchan" vendor="Trevorchan"><vers num="0.7" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-02-12" name="CVE-2007-0864" published="2007-02-08" seq="2007-0864" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in register.php in LushiWarPlaner 1.0 allows remote attackers to inject arbitrary SQL commands via the id parameter.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://www.milw0rm.com/exploits/3288"></ref><ref source="BID" url="http://www.securityfocus.com/bid/22470">22470</ref><ref source="MILW0RM" url="http://milw0rm.com/exploits/3288">

3288</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0538">
ADV-2007-0538</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24079">
24079</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32365">
lushiwarplaner-register-sql-injection(32365)</ref></refs><vuln_soft><prod name="LushiWarPlaner" vendor="LushiWarPlaner"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-02-12" name="CVE-2007-0865" published="2007-02-08" seq="2007-0865" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in comments.php in LushiNews 1.01 and earlier allows remote authenticated users to inject arbitrary SQL commands via the id parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://www.milw0rm.com/exploits/3287"></ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/22469">22469</ref><ref source="MILW0RM" url="http://milw0rm.com/exploits/3287">

3287</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0539">
ADV-2007-0539</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24081">
24081</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32360">
lushinews-comments-sql-injection(32360)</ref></refs><vuln_soft><prod name="LushiNews" vendor="LushiNews"><vers num="1.01"/><vers num="1.00"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="3.1" CVSS_impact_subscore="10.0" CVSS_score="6.8" CVSS_vector="(AV:L/AC:L/Au:S/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-02-12" name="CVE-2007-0866" published="2007-02-08" seq="2007-0866" severity="Medium" type="CVE"><desc><descript source="cve">Unspecified vulnerability in HP OpenView Storage Data Protector on HP-UX B.11.00, B.11.11, or B.11.23 allows local users to execute arbitrary code via unknown vectors.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><range><local/></range><refs><ref patch="1" source="HP" url="http://www.securityfocus.com/archive/1/archive/1/459497/100/0/threaded">HPSBMA02190</ref><ref adv="1" source="SECTRACK" url="http://securitytracker.com/id?1017614">1017614</ref><ref source="BID" url="http://www.securityfocus.com/bid/22488">
22488</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0542">
ADV-2007-0542</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24113">
24113</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32386">
openview-dataprotector-privilege-escalation(32386)</ref></refs><vuln_soft><prod name="OpenView Storage Data Protector" vendor="HP"><vers num="5.50"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-02-12" name="CVE-2007-0867" published="2007-02-09" seq="2007-0867" severity="High" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in classes/menu.php in Site-Assistant 0990 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the paths[version] parameter.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://www.milw0rm.com/exploits/3285"></ref><ref source="BID" url="http://www.securityfocus.com/bid/22467">22467</ref><ref source="MILW0RM" url="http://milw0rm.com/exploits/3285">

3285</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0541">
ADV-2007-0541</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32364">
siteassistant-menu-file-include(32364)</ref></refs><vuln_soft><prod name="Site-Assistant" vendor="Site-Assistant"><vers num="0990" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0" modified="2007-02-12" name="CVE-2007-0868" published="2007-02-09" seq="2007-0868" severity="Medium" type="CVE"><desc><descript source="cve">Unspecified vulnerability in the Chat Room functionality in Yahoo! Messenger 8.1.0.239 and earlier allows remote attackers to cause a denial of service via unspecified vectors.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript></desc><loss_types><avail/></loss_types><range><network/></range><refs><ref source="BID" url="http://www.securityfocus.com/bid/22407">22407</ref></refs><vuln_soft><prod name="Messenger" vendor="Yahoo"><vers num="8.0"/><vers num="7.5.0.814"/><vers num="7.0.438"/><vers num="6.0.0.1921"/><vers num="6.0.0.1750"/><vers num="6.0.0.1643"/><vers num="6.0"/><vers num="5.6.0.1358"/><vers num="5.6.0.1356"/><vers num="5.6.0.1355"/><vers num="5.6.0.1351"/><vers num="5.6.0.1347"/><vers num="5.6"/><vers num="5.5.1249"/><vers num="5.5"/><vers num="5.0.1232"/><vers num="5.0.1065"/><vers num="5.0.1046"/><vers num="5.0"/><vers num="4.0"/><vers num="8.1.0.239"/><vers num="8.1.0.209"/><vers num="8.0.0.863"/><vers num="8.0_2005.1.1.4"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" modified="2007-02-12" name="CVE-2007-0869" published="2007-02-09" seq="2007-0869" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in the Attachment Manager (admincp/attachment.php) in Jelsoft vBulletin 3.6.4 allows remote attackers to inject arbitrary web script or HTML via the Extension field, a different vector than CVE-2007-0830.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/22466">22466</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24085">24085</ref></refs><vuln_soft><prod name="VBulletin" vendor="Jelsoft"><vers num="3.6.4"/></prod></vuln_soft></entry><entry CVSS_base_score="7.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="10.0" CVSS_score="7.6" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-02-16" name="CVE-2007-0870" published="2007-02-11" seq="2007-0870" severity="High" type="CVE"><desc><descript source="cve">Unspecified vulnerability in Microsoft Word 2000 allows remote attackers to cause a denial of service (crash) via unknown vectors, a different vulnerability than CVE-2006-5994, CVE-2006-6456, CVE-2006-6561, and CVE-2007-0515, a variant of Exploit-MS06-027.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><range><network/><user_init/></range><refs><ref source="" url="http://www.avertlabs.com/research/blog/?p=199"></ref><ref source="" url="http://www.avertlabs.com/research/blog/?p=206"></ref><ref source="" url="http://www.microsoft.com/technet/security/advisory/933052.mspx"></ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/332404">
VU#332404</ref><ref source="BID" url="http://www.securityfocus.com/bid/22567">
22567</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0607">
ADV-2007-0607</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017653">
1017653</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24122">
24122</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32503">
word-unspecified-string-code-execution(32503)</ref><ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms07-024.mspx">
MS07-024</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1709">
ADV-2007-1709</ref><ref source="HP" url="http://www.securityfocus.com/archive/1/archive/1/468871/100/200/threaded">HPSBST02214</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA07-128A.html">TA07-128A</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1860">oval:org.mitre.oval:def:1860</ref></refs><vuln_soft><prod name="Word" vendor="Microsoft"><vers num="2000"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-02-13" name="CVE-2007-0871" published="2007-02-12" seq="2007-0871" severity="High" type="CVE"><desc><descript source="cve">Unrestricted file upload vulnerability in eXtremePow eXtreme File Hosting allows remote attackers to upload arbitrary PHP code via a filename with a double extension such as (1) .rar.php or (2) .zip.php.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/459562/100/0/threaded">20070209 eXtreme File Hosting remote file upload vulnerability</ref><ref source="BID" url="http://www.securityfocus.com/bid/22498">22498</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24088">
24088</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32435">
extremefilehosting-compressed-file-upload(32435)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2231">2231</ref></refs><vuln_soft><prod name="eXtreme File Hosting" vendor="eXtremePow"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0" modified="2007-02-13" name="CVE-2007-0872" published="2007-02-12" seq="2007-0872" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in the Plain Old Webserver (POW) add-on before 0.0.9 for Mozilla Firefox allows remote attackers to read arbitrary files via a .. (dot dot) in the URI.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="FULLDISC" url="http://seclists.org/fulldisclosure/2007/Feb/0196.html">20070209 Re: [WEB SECURITY] Plain Old Webserver - The coolest firefox extension</ref><ref source="FULLDISC" url="http://seclists.org/fulldisclosure/2007/Feb/0210.html">20070209 Re: [WEB SECURITY] Plain Old Webserver - The coolest firefox extension</ref><ref source="" url="https://addons.mozilla.org/firefox/3002/"></ref><ref source="BID" url="http://www.securityfocus.com/bid/22502">22502</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0558">
ADV-2007-0558</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24127">
24127</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32467">
pow-httprequest-directory-traversal(32467)</ref></refs><vuln_soft><prod name="Plain Old Webserver" vendor="Plain Old Webserver"><vers num="0.0.8"/><vers num="0.0.7"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-02-13" name="CVE-2007-0873" published="2007-02-12" seq="2007-0873" severity="High" type="CVE"><desc><descript source="cve">nabopoll 1.1.2 allows remote attackers to bypass authentication and access certain administrative functionality via a direct request for (1) config_edit.php, (2) template_edit.php, or (3) survey_edit.php in admin/.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/459655/100/0/threaded">20070210 nabopoll 1.1.2 sensitive file (admin without password)</ref><ref source="" url="http://forums.avenir-geopolitique.net/viewtopic.php?t=2643"></ref><ref source="BID" url="http://www.securityfocus.com/bid/22509">22509</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2232">2232</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32472">nabopoll-configedit-unathorized-access(32472)</ref></refs><vuln_soft><prod name="NaboPoll" vendor="NaboCorp Softwares"><vers num="1.2"/><vers num="1.1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-02-13" name="CVE-2007-0874" published="2007-02-12" seq="2007-0874" severity="Medium" type="CVE"><desc><descript source="cve">Allons_voter 1.0 allows remote attackers to bypass authentication and access certain administrative functionality via a direct request for (1) admin_ajouter.php or (2) admin_supprimer.php.  NOTE: this could be leveraged to conduct cross-site scripting (XSS) attacks.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/459652/100/0/threaded">20070209 Allons_voter Version 1.0 xss and admin votes</ref><ref source="" url="http://forums.avenir-geopolitique.net/viewtopic.php?t=2641"></ref><ref source="BID" url="http://www.securityfocus.com/bid/22508">22508</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32431">
allonsvoter-admin-authentication-bypass(32431)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2234">2234</ref></refs><vuln_soft><prod name="Allons_voter" vendor="Allons_voter"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-08-03" name="CVE-2007-0875" published="2007-02-12" seq="2007-0875" severity="High" type="CVE"><desc><descript source="cve">** DISPUTED **  SQL injection vulnerability in install.php in mcRefer allows remote attackers to execute arbitrary SQL commands via unspecified vectors. NOTE: this issue has been disputed by a third party, stating that the file does not use a SQL database.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/459649/100/0/threaded">20070209 mcRefer SQL injection</ref><ref source="" url="http://forums.avenir-geopolitique.net/viewtopic.php?t=2642"></ref><ref source="BID" url="http://www.securityfocus.com/bid/22507">22507</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/459796/100/200/threaded">20070211 Re: mcRefer SQL injection</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2235">2235</ref></refs><vuln_soft><prod name="McRefer" vendor="McRefer"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" modified="2007-02-13" name="CVE-2007-0876" published="2007-02-12" seq="2007-0876" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in Quick Digital Image Gallery (Qdig) 1.2.9.3 and devel-20060624 allows remote attackers to inject arbitrary web script or HTML via the Qwd parameter to the top-level URI.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/459664/100/0/threaded">20070210 [XSS] Qdig - Quick Digital Image Gallery Version 1.2.9.3 and -devel</ref><ref patch="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/459791/100/0/threaded">20070211 Re: [XSS] Qdig - Quick Digital Image Gallery Version 1.2.9.3 and -devel</ref><ref source="" url="http://sourceforge.net/project/shownotes.php?group_id=69837&amp;release_id=485558"></ref><ref source="BID" url="http://www.securityfocus.com/bid/22510">22510</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0555">
ADV-2007-0555</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24110">
24110</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32421">
qdig-qwd-xss(32421)</ref></refs><vuln_soft><prod name="Qdig" vendor="Qdig"><vers num="2006-06-24 dev"/><vers num="1.2.9.3"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0" modified="2007-02-13" name="CVE-2007-0877" published="2007-02-12" seq="2007-0877" severity="Medium" type="CVE"><desc><descript source="cve">Unspecified vulnerability in March Networks DVR 3000 and 4000 Digital Video Recorders allows attackers to cause an unspecified denial of service.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript></desc><loss_types><avail/></loss_types><range><network/></range><refs><ref source="BID" url="http://www.securityfocus.com/bid/22497">22497</ref></refs><vuln_soft><prod name="3108 DVR" vendor="March Networks"><vers num=""/></prod><prod name="3204 DVR" vendor="March Networks"><vers num=""/></prod><prod name="4210 DVR" vendor="March Networks"><vers num=""/></prod><prod name="4310 DVR" vendor="March Networks"><vers num=""/></prod><prod name="4410 DVR" vendor="March Networks"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.8" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.9" CVSS_score="7.8" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_version="2.0" modified="2007-02-13" name="CVE-2007-0878" published="2007-02-12" seq="2007-0878" severity="High" type="CVE"><desc><descript source="cve">Unspecified vulnerability in Microsoft Internet Explorer on Windows Mobile 5.0 allows remote attackers to cause a denial of service (loss of browser and other device functionality) via a malformed WML page, related to an &quot;overflow state.&quot; NOTE: it is possible that this issue is related to CVE-2007-0685.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/459571/100/0/threaded">20070209 Denial Of Service in Internet Explorer for MS Windows Mobile 5.0</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/459591/100/0/threaded">20070209 RE: Denial Of Service in Internet Explorer for MS Windows Mobile 5.0</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/459584/100/0/threaded">20070209 Re: Denial Of Service in Internet Explorer for MS Windows Mobile 5.0</ref><ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2007-February/052293.html">20070209 Denial Of Service in Internet Explorer for MS Windows Mobile 5.0</ref><ref source="BID" url="http://www.securityfocus.com/bid/22500">22500</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32394">ie-mobile-unspecified-bo(32394)</ref></refs><vuln_soft><prod name="Internet Explorer" vendor="Microsoft"><vers num="Windows Mobile 5.0"/></prod></vuln_soft></entry><entry CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" CVSS_score="9.3" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-02-13" name="CVE-2007-0879" published="2007-02-12" seq="2007-0879" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in SmidgeonSoft PEBrowse Professional 8.2.1.0 allows user-assisted remote attackers to execute arbitrary code via certain executable files in PE format.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/><user_init/></range><refs><ref source="BID" url="http://www.securityfocus.com/bid/22501">22501</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0665">
ADV-2007-0665</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32524">
smidgeonsoft-files-bo(32524)</ref></refs><vuln_soft><prod name="PEBrowse" vendor="SmidgeonSoft"><vers num="Professional 8.2.1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.8" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.9" CVSS_score="7.8" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:N/A:N)" CVSS_version="2.0" modified="2007-02-13" name="CVE-2007-0880" published="2007-02-12" seq="2007-0880" severity="High" type="CVE"><desc><descript source="cve">Capital Request Forms stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain database credentials via a direct request for inc/common_db.inc.</descript></desc><loss_types><conf/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/459574/100/0/threaded">20070209 Capital Request Forms Db Username and Password Vulnerabilities</ref></refs><vuln_soft><prod name="Capital Request Forms" vendor="Capital Request Forms"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-02-13" name="CVE-2007-0881" published="2007-02-12" seq="2007-0881" severity="Medium" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in the Seitenschutz plugin for OPENi-CMS 1.0 allows remote attackers to execute arbitrary PHP code via a URL in the (1) config[oi_dir] and possibly (2) config[openi_dir] parameters to open-admin/plugins/site_protection/index.php.  NOTE: vector 2 might be the same as CVE-2006-4750.</descript></desc><impacts><impact source="nvd">Successful exploitation requires that &quot;register_globals&quot; is enabled.</impact></impacts><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://echo.or.id/adv/adv64-y3dips-2007.txt"></ref><ref source="" url="http://www.milw0rm.com/exploits/3292"></ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24119">24119</ref><ref source="MILW0RM" url="http://milw0rm.com/exploits/3292">
3292</ref><ref source="BID" url="http://www.securityfocus.com/bid/22511">
22511</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0556">
ADV-2007-0556</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32423">
internalrange-oidir-file-include(32423)</ref></refs><vuln_soft><prod name="OPENi-CMS" vendor="OPENi-CMS Group"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-08-03" name="CVE-2007-0882" published="2007-02-12" seq="2007-0882" severity="High" type="CVE"><desc><descript source="cve">Argument injection vulnerability in the telnet daemon (in.telnetd) in Solaris 10 and 11 (SunOS 5.10 and 5.11) misinterprets certain client &quot;-f&quot; sequences as valid requests for the login program to skip authentication, which allows remote attackers to log into certain accounts, as demonstrated by the bin account.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref source="" url="http://isc.sans.org/diary.html?storyid=2220"></ref><ref source="Milw0rm" url="http://www.milw0rm.com/exploits/3293">Exploit 3293</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/459980/100/0/threaded">20070213 Re: [BLACKLIST] [Full-disclosure] Solaris telnet vulnberability - how many on yournetwork?</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/459855/100/0/threaded">20070212 Re: [BLACKLIST] [Full-disclosure] Solaris telnet vulnberability - how many on yournetwork?</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/459831/100/0/threaded">20070212 Re: [Full-disclosure] Solaris telnet vulnberability - how many on your network?</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/459843/100/0/threaded">20070212 Solaris telnet vulnberability - how many on your network?</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/460086/100/100/threaded">20070214 Solaris telnet vuln solutions digest and network risks</ref><ref source="MILW0RM" url="http://milw0rm.com/exploits/3293">3293</ref><ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102802-1">102802</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA07-059A.html">TA07-059A</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/881872">VU#881872</ref><ref source="BID" url="http://www.securityfocus.com/bid/22512">22512</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0560">ADV-2007-0560</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017625">1017625</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24120">24120</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32434">solaris-telnet-authentication-bypass(32434)</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/460103/100/100/threaded">20070214 RE: [Full-disclosure] Solaris telnet vulnberability - how many onyour network?</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2202">oval:org.mitre.oval:def:2202</ref></refs><vuln_soft><prod name="Solaris" vendor="Sun"><vers edition="SPARC" num="10.0"/><vers num="11.0"/></prod><prod name="SunOS" vendor="Sun"><vers num="5.10"/><vers num="5.11"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0" modified="2007-02-13" name="CVE-2007-0883" published="2007-02-12" seq="2007-0883" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in portalgroups/portalgroups/getfile.cgi in IP3 NetAccess before firmware 4.1.9.6 allows remote attackers to read arbitrary files via a .. (dot dot) in the filename parameter.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="" url="http://www.devtarget.org/ip3-advisory-02-2007.txt"></ref><ref source="" url="http://www.milw0rm.com/exploits/3294"></ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/459806/100/0/threaded">

20070211 Arbitrary file disclosure vulnerability in IP3 NetAccess &lt; 4.1.9.6</ref><ref source="MILW0RM" url="http://milw0rm.com/exploits/3294">
3294</ref><ref source="BID" url="http://www.securityfocus.com/bid/22513">
22513</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0615">
ADV-2007-0615</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017623">
1017623</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24118">
24118</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32432">
ip3netaccess-getfile-directory-traversal(32432)</ref></refs><vuln_soft><prod name="IP3 NetAccess" vendor="Second Rule LLC"><vers num="4.1.9.5" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-02-13" name="CVE-2007-0884" published="2007-02-12" seq="2007-0884" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in Roaring Penguin MIMEDefang 2.59 and 2.60 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via unspecified vectors.</descript></desc><sols><sol source="nvd">Upgrade to 2.61</sol></sols><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref patch="1" source="MLIST" url="http://lists.roaringpenguin.com/pipermail/mimedefang/2007-February/032011.html">[mimedefang] 20070209 SECURITY: MIMEDefang 2.61 is Released</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24133">24133</ref><ref source="" url="http://www.mimedefang.org/node.php?id=62"></ref><ref source="BID" url="http://www.securityfocus.com/bid/22514">
22514</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0572">
ADV-2007-0572</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32466">
mimedefang-unspecified-bo(32466)</ref></refs><vuln_soft><prod name="MIMEDefang" vendor="Roaring Penguin"><vers num="2.59"/><vers num="2.60"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-02-13" name="CVE-2007-0885" published="2007-02-12" seq="2007-0885" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in jira/secure/BrowseProject.jspa in Rainbow with the Zen (Rainbow.Zen) extension allows remote attackers to inject arbitrary web script or HTML via the id parameter.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/459590/100/0/threaded">20070209 XSS in Rainbow with Rainbow.Zen</ref><ref source="BID" url="http://www.securityfocus.com/bid/22503">
22503</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32418">
rainbow-browseproject-xss(32418)</ref></refs><vuln_soft><prod name="Rainbow.Zen" vendor="Rainbow Portal"><vers num=""/></prod><prod name="Rainbow with the Zen" vendor="Rainbow Portal"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-02-13" name="CVE-2007-0886" published="2007-02-12" seq="2007-0886" severity="High" type="CVE"><desc><descript source="cve">Heap-based buffer underflow in axigen 1.2.6 through 2.0.0b1 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via certain base64-encoded data on the pop3 port (110/tcp), which triggers an integer overflow.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref source="FULLDISC" url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=117094708423302&amp;w=2">20070208 Axigen &lt;2.0.0b1 DoS</ref><ref source="" url="http://www.milw0rm.com/exploits/3289"></ref><ref source="BID" url="http://www.securityfocus.com/bid/22473">22473</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32342">axigen-memcpy-dos(32342)</ref><ref source="MILW0RM" url="http://milw0rm.com/exploits/3289">
3289</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24073">
24073</ref></refs><vuln_soft><prod name="Axigen Mail Server" vendor="Gecad Technologies"><vers num="1.2.6"/><vers num="2.0.0b1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.8" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.9" CVSS_score="7.8" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_version="2.0" modified="2007-02-13" name="CVE-2007-0887" published="2007-02-12" seq="2007-0887" severity="High" type="CVE"><desc><descript source="cve">axigen 1.2.6 through 2.0.0b1 does not properly parse login credentials, which allows remote attackers to cause a denial of service (NULL dereference and application crash) via a base64-encoded &quot;*\x00&quot; sequence on the imap port (143/tcp).</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref source="FULLDISC" url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=117094708423302&amp;w=2">20070208 Axigen &lt;2.0.0b1 DoS</ref><ref source="" url="http://www.milw0rm.com/exploits/3290"></ref><ref source="BID" url="http://www.securityfocus.com/bid/22473">22473</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32345">axigen-nullpointer-dos(32345)</ref><ref source="MILW0RM" url="http://milw0rm.com/exploits/3290">
3290</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24073">
24073</ref></refs><vuln_soft><prod name="Axigen Mail Server" vendor="Gecad Technologies"><vers num="1.2.6"/><vers num="2.0.0b1"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-03-06" name="CVE-2007-0888" published="2007-02-12" seq="2007-0888" severity="High" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in the TFTP server in Kiwi CatTools before 3.2.0 beta allows remote attackers to read arbitrary files, and upload files to arbitrary locations, via ..// (dot dot) sequences in the pathname argument to an FTP (1) GET or (2) PUT command.</descript></desc><impacts><impact source="nvd">This vulnerability is addressed in the following product update:
Kiwi Enterprises, Kiwi CatTools, 3.2.0 Beta</impact></impacts><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref patch="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/459500/100/0/threaded">20070208 TFTP directory traversal in Kiwi CatTools</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/459933/100/0/threaded">
20070213 Re: TFTP directory traversal in Kiwi CatTools</ref><ref source="" url="http://www.kiwisyslog.com/kb/idx/5/178/article/"></ref><ref source="BID" url="http://www.securityfocus.com/bid/22490">
22490</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0536">
ADV-2007-0536</ref><ref source="OSVDB" url="http://www.osvdb.org/33162">
33162</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24103">
24103</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32398">
kiwicattools-tftp-directory-traversal(32398)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2236">2236</ref></refs><vuln_soft><prod name="Kiwi CatTools" vendor="Kiwi Enterprises"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-02-13" name="CVE-2007-0889" published="2007-02-12" seq="2007-0889" severity="Medium" type="CVE"><desc><descript source="cve">Kiwi CatTools before 3.2.0 beta uses weak encryption (&quot;reversible encoding&quot;) for passwords, account names, and IP addresses in kiwidb-cattools.kdb, which might allow local users to gain sensitive information by decrypting the file.  NOTE: this issue could be leveraged with a directory traversal vulnerability for a remote attack vector.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref patch="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/459500/100/0/threaded">20070208 TFTP directory traversal in Kiwi CatTools</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24103">
24103</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2236">2236</ref></refs><vuln_soft><prod name="Kiwi CatTools" vendor="Kiwi Enterprises"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" modified="2007-02-13" name="CVE-2007-0890" published="2007-02-12" seq="2007-0890" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in scripts/passwdmysql in cPanel WebHost Manager (WHM) 11.0.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the password parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/459585/100/0/threaded">20070208 local bug :[xxs] in whm</ref><ref source="" url="http://changelog.cpanel.net/index.cgi"></ref><ref source="BID" url="http://www.securityfocus.com/bid/22474">22474</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0568">
ADV-2007-0568</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24106">
24106</ref></refs><vuln_soft><prod name="WebHost Manager" vendor="cPanel"><vers num="11.0"/><vers num="10.9"/><vers num="10.8.2 118"/><vers num="10.8.1 113"/><vers num="10.8.1 build84"/><vers num="10.6.0 R137"/><vers num="10.2.0 R82"/><vers num="9.9.1 R3"/><vers num="9.4.1 R64"/><vers num="9.1.0 R85"/><vers num="9.1"/><vers num="9.0"/><vers num="8.0"/><vers num="7.0"/><vers num="6.4.2 Stable_48"/><vers num="6.4.2"/><vers num="6.4.1"/><vers num="6.4"/><vers num="6.2"/><vers num="6.0"/><vers num="5.3"/><vers num="5.0"/><vers num="11 Beta"/><vers num="11"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" modified="2007-02-13" name="CVE-2007-0891" published="2007-02-12" seq="2007-0891" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in the GetCurrentCompletePath function in phpmyvisites.php in phpMyVisites before 2.2 allows remote attackers to inject arbitrary web script or HTML via the query string.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" source="FULLDISC" url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=117121596803908&amp;w=2">20070211 Multiple vulnerabilities in phpMyVisites</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24124">24124</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/459792/100/0/threaded">

20070211 Multiple vulnerabilities in phpMyVisites</ref><ref source="BID" url="http://www.securityfocus.com/bid/22516">
22516</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0566">
ADV-2007-0566</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32430">
phpmyvisites-phpmyvisites-xss(32430)</ref></refs><vuln_soft><prod name="phpMyVisites" vendor="Matthieu Aubry"><vers num="2.1" prev="1"/><vers num="1.3"/><vers num="1.2.2"/><vers num="1.2.1"/><vers num="1.2 Beta"/><vers num="1.2"/><vers num="1.1"/><vers num="1.0"/><vers num="0.1 Beta"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-02-13" name="CVE-2007-0892" published="2007-02-12" seq="2007-0892" severity="High" type="CVE"><desc><descript source="cve">CRLF injection vulnerability in phpMyVisites before 2.2 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via CRLF sequences in the url parameter, when the pagename parameter begins with &quot;FILE:&quot;.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="FULLDISC" url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=117121596803908&amp;w=2">20070211 Multiple vulnerabilities in phpMyVisites</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/459792/100/0/threaded">

20070211 Multiple vulnerabilities in phpMyVisites</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32428">
phpmyvisites-pagename-response-splitting(32428)</ref></refs><vuln_soft><prod name="phpMyVisites" vendor="Matthieu Aubry"><vers num="2.1" prev="1"/><vers num="1.3"/><vers num="1.2.2"/><vers num="1.2.1"/><vers num="1.2 Beta"/><vers num="1.2"/><vers num="1.1"/><vers num="1.0"/><vers num="0.1 Beta"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" modified="2007-02-13" name="CVE-2007-0893" published="2007-02-12" seq="2007-0893" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in phpMyVisites before 2.2 allows remote attackers to include arbitrary files via leading &quot;..&quot; sequences on the pmv_ck_view COOKIE parameter, which bypasses the protection scheme.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="FULLDISC" url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=117121596803908&amp;w=2">20070211 Multiple vulnerabilities in phpMyVisites</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/459792/100/0/threaded">

20070211 Multiple vulnerabilities in phpMyVisites</ref><ref source="BID" url="http://www.securityfocus.com/bid/22516">
22516</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32433">
phpmyvisites-pmvckview-file-include(32433)</ref></refs><vuln_soft><prod name="phpMyVisites" vendor="Matthieu Aubry"><vers num="2.1" prev="1"/><vers num="1.3"/><vers num="1.2.2"/><vers num="1.2.1"/><vers num="1.2 Beta"/><vers num="1.2"/><vers num="1.1"/><vers num="1.0"/><vers num="0.1 Beta"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0" modified="2007-02-13" name="CVE-2007-0894" published="2007-02-12" seq="2007-0894" severity="Medium" type="CVE"><desc><descript source="cve">MediaWiki before 1.9.2 allows remote attackers to obtain sensitive information via a direct request to (1) Simple.deps.php, (2) MonoBook.deps.php, (3) MySkin.deps.php, or (4) Chick.deps.php in wiki/skins, which shows the installation path in the resulting error message.</descript></desc><loss_types><conf/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/459793/100/0/threaded">20070211 MediaWiki Full Path Disclosure Vulnerability</ref><ref source="" url="http://zone14.free.fr/advisories/7/"></ref><ref source="" url="http://bugzilla.wikimedia.org/show_bug.cgi?id=8819"></ref><ref patch="1" source="" url="http://svn.wikimedia.org/viewvc/mediawiki?view=rev&amp;revision=19681"></ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32440">
mediawiki-multiple-scripts-path-disclosure(32440)</ref></refs><vuln_soft><prod name="MediaWiki" vendor="MediaWiki"><vers num="1.9.1"/><vers edition="RC2" num="1.9.0"/><vers num="1.8.2"/><vers num="1.8.1"/><vers num="1.8.0"/><vers num="1.7.1"/><vers num="1.7.0"/><vers num="1.6.6"/><vers num="1.6.5 r14348"/><vers num="1.6.5"/><vers num="1.6.4"/><vers num="1.6.3"/><vers num="1.6.2"/><vers num="1.6.1"/><vers num="1.6.0"/><vers num="1.5 rc4"/><vers num="1.5 rc3"/><vers num="1.5 rc2"/><vers num="1.5 Beta4"/><vers num="1.5 Beta3"/><vers num="1.5 Beta2"/><vers num="1.5 Beta1"/><vers num="1.5 alpha2"/><vers num="1.5 alpha1"/><vers num="1.5.7"/><vers num="1.5.6"/><vers num="1.5.5"/><vers num="1.5.4"/><vers num="1.5.3"/><vers num="1.5.2"/><vers num="1.5.1"/><vers num="1.5.0"/><vers num="1.4.9"/><vers num="1.4.8"/><vers num="1.4.7"/><vers num="1.4.6"/><vers num="1.4.5"/><vers num="1.4.4"/><vers num="1.4.3"/><vers num="1.4.2"/><vers num="1.4.14"/><vers num="1.4.13"/><vers num="1.4.12"/><vers num="1.4.11"/><vers num="1.4.10"/><vers num="1.4.1"/><vers num="1.4 beta6"/><vers num="1.4 beta5"/><vers num="1.4 beta4"/><vers num="1.4 beta3"/><vers num="1.4 beta2"/><vers num="1.4 beta1"/><vers num="1.3.9"/><vers num="1.3.8"/><vers num="1.3.7"/><vers num="1.3.6"/><vers num="1.3.5"/><vers num="1.3.4"/><vers num="1.3.3"/><vers num="1.3.2"/><vers num="1.3.15"/><vers num="1.3.14"/><vers num="1.3.13"/><vers num="1.3.12"/><vers num="1.3.11"/><vers num="1.3.10"/><vers num="1.3.1"/><vers num="1.3.0"/><vers num="1.3"/><vers num="1.2.6"/><vers num="1.2.5"/><vers num="1.2.4"/><vers num="1.2.3"/><vers num="1.2.2"/><vers num="1.2.1"/><vers num="1.2.0"/><vers num="1.1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="2.6" CVSS_exploit_subscore="1.9" CVSS_impact_subscore="4.9" CVSS_score="2.6" CVSS_vector="(AV:L/AC:H/Au:N/C:N/I:P/A:P)" CVSS_version="2.0" modified="2007-02-13" name="CVE-2007-0895" published="2007-02-12" seq="2007-0895" severity="Low" type="CVE"><desc><descript source="cve">Race condition in recursive directory deletion with the (1) -r or (2) -R option in rm in Solaris 8 through 10 before 20070208 allows local users to delete files and directories as the user running rm by moving a low-level directory to a higher level as it is being deleted, which causes rm to chdir to a &quot;..&quot; directory that is higher than expected, possibly up to the root file system, a related issue to CVE-2002-0435.</descript></desc><loss_types><avail/><int/></loss_types><vuln_types><race/></vuln_types><range><local/></range><refs><ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102782-1">102782</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0543">ADV-2007-0543</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/24082">24082</ref><ref source="" url="http://support.avaya.com/elmodocs2/security/ASA-2007-102.htm"></ref><ref source="OSVDB" url="http://www.osvdb.org/31880">
31880</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24405">
24405</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32399">
solaris-rm-dos(32399)</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:8272">oval:org.mitre.oval:def:8272</ref></refs><vuln_soft><prod name="Solaris" vendor="Sun"><vers num="8.0"/><vers edition="SPARC" num="9.0"/><vers edition="SPARC" num="10.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" modified="2008-08-18" name="CVE-2007-0896" published="2007-02-13" seq="2007-0896" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in the (1) Sage before 1.3.10, and (2) Sage++ extensions for Firefox, allows remote attackers to inject arbitrary web script or HTML via a &quot;&lt;SCRIPT/=&apos;SRC=&apos;&quot; sequence in an RSS feed, a different vulnerability than CVE-2006-4712.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" source="" url="http://jvn.jp/jp/JVN%2384430861/index.html"></ref><ref source="" url="http://mozdev.org/bugs/show_bug.cgi?id=16320"></ref><ref source="" url="http://sage.mozdev.org/blog/archives/2007/1/sage_1_3_10_released.html"></ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24086">24086</ref><ref source="BID" url="http://www.securityfocus.com/bid/22493">22493</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017624">1017624</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32395">sage-rssfeed-xss(32395)</ref></refs><vuln_soft><prod name="Sage" vendor="Sage"><vers num="1.3.6"/><vers num="1.0 Beta 3"/><vers num=""/><vers num="1.3.9" prev="1"/></prod><prod name="Firefox" vendor="Mozilla"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:P)" CVSS_version="2.0" modified="2008-03-07" name="CVE-2007-0897" published="2007-02-16" seq="2007-0897" severity="Medium" type="CVE"><desc><descript source="cve">Clam AntiVirus ClamAV before 0.90 does not close open file descriptors under certain conditions, which allows remote attackers to cause a denial of service (file descriptor consumption and failed scans) via CAB archives with a cabinet header record length of zero, which causes a function to return without closing a file descriptor.</descript></desc><sols><sol source="nvd">This vulnerability is addressed in the following product release:
Clam AntiVirus, ClamAV, 0.90 Stable</sol></sols><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/22580">22580</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0623">ADV-2007-0623</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/24187">24187</ref><ref source="DEBIAN" url="http://www.debian.org/security/2007/dsa-1263">DSA-1263</ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200703-03.xml">GLSA-200703-03</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:043">MDKSA-2007:043</ref><ref source="SUSE" url="http://lists.suse.com/archive/suse-security-announce/2007-Feb/0004.html">SUSE-SA:2007:017</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017659">1017659</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24192">24192</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24183">24183</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24319">24319</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24332">24332</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24425">24425</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32531">clamav-cabfile-dos(32531)</ref><ref adv="1" source="IDEFENSE" url="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=475">20070215 Multiple Vendor ClamAV CAB File Denial of Service Vulnerability</ref><ref source="" url="http://docs.info.apple.com/article.html?artnum=307562"></ref><ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2008/Mar/msg00001.html">APPLE-SA-2008-03-18</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/0924/references">ADV-2008-0924</ref><ref source="SECUNIA" url="http://secunia.com/advisories/29420">29420</ref></refs><vuln_soft><prod name="ClamAV" vendor="Clam Anti-Virus"><vers num="0.15" prev="1"/><vers num="0.20" prev="1"/><vers num="0.21" prev="1"/><vers num="0.22" prev="1"/><vers num="0.23" prev="1"/><vers num="0.24" prev="1"/><vers num="0.51" prev="1"/><vers num="0.52" prev="1"/><vers num="0.53" prev="1"/><vers num="0.54" prev="1"/><vers num="0.60" prev="1"/><vers num="0.60p" prev="1"/><vers num="0.65" prev="1"/><vers num="0.67" prev="1"/><vers num="0.68" prev="1"/><vers num="0.68.1" prev="1"/><vers num="0.70" prev="1"/><vers num="0.71" prev="1"/><vers num="0.72" prev="1"/><vers num="0.73" prev="1"/><vers num="0.74" prev="1"/><vers num="0.75" prev="1"/><vers num="0.75.1" prev="1"/><vers num="0.80" prev="1"/><vers num="0.80 rc1" prev="1"/><vers num="0.80 rc2" prev="1"/><vers num="0.80 rc3" prev="1"/><vers num="0.80 rc4" prev="1"/><vers num="0.81" prev="1"/><vers num="0.81 rc1" prev="1"/><vers num="0.82" prev="1"/><vers num="0.83" prev="1"/><vers num="0.84" prev="1"/><vers num="0.84 rc1" prev="1"/><vers num="0.84 rc2" prev="1"/><vers num="0.85" prev="1"/><vers num="0.85.1" prev="1"/><vers num="0.86" prev="1"/><vers num="0.86 rc1" prev="1"/><vers num="0.86.1" prev="1"/><vers num="0.86.2" prev="1"/><vers num="0.87" prev="1"/><vers num="0.87.1" prev="1"/><vers num="0.88" prev="1"/><vers num="0.88.1" prev="1"/><vers num="0.88.3" prev="1"/><vers num="0.88.4" prev="1"/><vers num="0.88.6" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.4" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="4.9" CVSS_score="6.4" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:P)" CVSS_version="2.0" modified="2008-03-07" name="CVE-2007-0898" published="2007-02-16" seq="2007-0898" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in clamd in Clam AntiVirus ClamAV before 0.90 allows remote attackers to overwrite arbitrary files via a .. (dot dot) in the id MIME header parameter in a multi-part message.</descript></desc><sols><sol source="nvd">This vulnerability is addressed in the following product release:
Clam Anti-Virus, ClamAV, 0.90</sol></sols><loss_types><avail/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref patch="1" source="IDEFENSE" url="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=476">20070215 Multiple Vendor ClamAV MIME Parsing Directory Traversal Vulnerability</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/22581">22581</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0623">ADV-2007-0623</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/24187">24187</ref><ref source="DEBIAN" url="http://www.debian.org/security/2007/dsa-1263">DSA-1263</ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200703-03.xml">GLSA-200703-03</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:043">MDKSA-2007:043</ref><ref source="SUSE" url="http://lists.suse.com/archive/suse-security-announce/2007-Feb/0004.html">SUSE-SA:2007:017</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017660">1017660</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24192">24192</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24183">24183</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24319">24319</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24332">24332</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24425">24425</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32535">clamav-mimeheader-directory-traversal(32535)</ref><ref source="" url="http://docs.info.apple.com/article.html?artnum=307562"></ref><ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2008/Mar/msg00001.html">APPLE-SA-2008-03-18</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/0924/references">ADV-2008-0924</ref><ref source="SECUNIA" url="http://secunia.com/advisories/29420">29420</ref></refs><vuln_soft><prod name="ClamAV" vendor="Clam Anti-Virus"><vers num="0.15"/><vers num="0.20"/><vers num="0.21"/><vers num="0.22"/><vers num="0.23"/><vers num="0.24"/><vers num="0.51"/><vers num="0.52"/><vers num="0.53"/><vers num="0.54"/><vers num="0.60"/><vers num="0.60p"/><vers num="0.65"/><vers num="0.67"/><vers num="0.68"/><vers num="0.68.1"/><vers num="0.70"/><vers num="0.71"/><vers num="0.72"/><vers num="0.73"/><vers num="0.74"/><vers num="0.75"/><vers num="0.75.1"/><vers num="0.80"/><vers num="0.80 rc1"/><vers num="0.80 rc2"/><vers num="0.80 rc3"/><vers num="0.80 rc4"/><vers num="0.81"/><vers num="0.81 rc1"/><vers num="0.82"/><vers num="0.83"/><vers num="0.84"/><vers num="0.84 rc1"/><vers num="0.84 rc2"/><vers num="0.85"/><vers num="0.85.1"/><vers num="0.86"/><vers num="0.86 rc1"/><vers num="0.86.1"/><vers num="0.86.2"/><vers num="0.87"/><vers num="0.87.1"/><vers num="0.88"/><vers num="0.88.1"/><vers num="0.88.3"/><vers num="0.88.4"/><vers num="0.88.6" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-02-13" name="CVE-2007-0900" published="2007-02-13" seq="2007-0900" severity="High" type="CVE"><desc><descript source="cve">Multiple PHP remote file inclusion vulnerabilities in TagIt! Tagboard 2.1.B Build 2 and earlier, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the (1) configpath parameter to (a) tagviewer.php, (b) tag_process.php, and (c) CONFIG/errmsg.inc.php; and (d) addTagmin.php, (e) ban_watch.php, (f) delTagmin.php, (g) delTag.php, (h) editTagmin.php, (i) editTag.php, (j) manageTagmins.php, and (k) verify.php in tagmin/; the (2) adminpath parameter to (l) tagviewer.php, (m) tag_process.php, and (n) tagmin/index.php; and the (3) admin parameter to (o) readconf.php, (p) updateconf.php, (q) updatefilter.php, and (r) wordfilter.php in tagmin/; different vectors than CVE-2006-5249.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="OSVDB" url="http://www.osvdb.org/34615">
34615</ref><ref source="OSVDB" url="http://www.osvdb.org/34616">
34616</ref><ref source="OSVDB" url="http://www.osvdb.org/34617">
34617</ref><ref source="OSVDB" url="http://www.osvdb.org/34618">
34618</ref><ref source="" url="http://advisories.echo.or.id/adv/adv65-K-159-2007.txt"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0557">ADV-2007-0557</ref><ref source="BID" url="http://www.securityfocus.com/bid/22518">
22518</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32436">
tagit-multiplescripts-file-include(32436)</ref><ref source="OSVDB" url="http://www.osvdb.org/34603">
34603</ref><ref source="OSVDB" url="http://www.osvdb.org/34604">
34604</ref><ref source="OSVDB" url="http://www.osvdb.org/34605">
34605</ref><ref source="OSVDB" url="http://www.osvdb.org/34606">
34606</ref><ref source="OSVDB" url="http://www.osvdb.org/34607">
34607</ref><ref source="OSVDB" url="http://www.osvdb.org/34608">
34608</ref><ref source="OSVDB" url="http://www.osvdb.org/34609">
34609</ref><ref source="OSVDB" url="http://www.osvdb.org/34610">
34610</ref><ref source="OSVDB" url="http://www.osvdb.org/34611">
34611</ref><ref source="OSVDB" url="http://www.osvdb.org/34612">
34612</ref><ref source="OSVDB" url="http://www.osvdb.org/34613">
34613</ref><ref source="OSVDB" url="http://www.osvdb.org/34614">
34614</ref></refs><vuln_soft><prod name="Tagboard" vendor="TagIt"><vers num="2.1.B Build 2" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" modified="2007-02-14" name="CVE-2007-0901" published="2007-02-13" seq="2007-0901" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Info pages in MoinMoin 1.5.7 allow remote attackers to inject arbitrary web script or HTML via the (1) hitcounts and (2) general parameters, different vectors than CVE-2007-0857.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24138">24138</ref><ref source="UBUNTU" url="http://www.ubuntu.com/usn/usn-423-1">

USN-423-1</ref><ref source="BID" url="http://www.securityfocus.com/bid/22515">
22515</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24244">
24244</ref></refs><vuln_soft><prod name="MoinMoin" vendor="MoinMoin"><vers num="1.5.7"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0" modified="2007-02-14" name="CVE-2007-0902" published="2007-02-13" seq="2007-0902" severity="Medium" type="CVE"><desc><descript source="cve">Unspecified vulnerability in the &quot;Show debugging information&quot; feature in MoinMoin 1.5.7 allows remote attackers to obtain sensitive information.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24138">24138</ref><ref source="UBUNTU" url="http://www.ubuntu.com/usn/usn-423-1">

USN-423-1</ref><ref source="BID" url="http://www.securityfocus.com/bid/22515">
22515</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24244">
24244</ref></refs><vuln_soft><prod name="MoinMoin" vendor="MoinMoin"><vers num="1.5.7"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-02-14" name="CVE-2007-0903" published="2007-02-13" seq="2007-0903" severity="High" type="CVE"><desc><descript source="cve">Unspecified vulnerability in the mod_roster_odbc module in ejabberd before 1.1.3 has unknown impact and attack vectors.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs><ref source="" url="http://www.process-one.net/en/ejabberd/release_notes/release_note_ejabberd_113/"></ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24075">24075</ref><ref source="BID" url="http://www.securityfocus.com/bid/22525">
22525</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0570">
ADV-2007-0570</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32437">
ejabberd-modrosterodbc-unspecified(32437)</ref></refs><vuln_soft><prod name="ejabberd" vendor="Process-one"><vers num="1.1.2"/><vers num="1.1.1"/><vers num="1.1.0"/><vers num="1.0.0"/><vers num="0.9.8"/><vers num="0.9.1"/><vers num="0.9"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-02-14" name="CVE-2007-0904" published="2007-02-13" seq="2007-0904" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in projects.php in LightRO CMS 1.0 allows remote attackers to execute arbitrary SQL commands via the ID parameter to index.php.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://www.milw0rm.com/exploits/3286"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0540">ADV-2007-0540</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32347">lightro-index-sql-injection(32347)</ref><ref source="MILW0RM" url="http://milw0rm.com/exploits/3286">

3286</ref></refs><vuln_soft><prod name="LightRO CMS" vendor="LightRO"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-02-14" name="CVE-2007-0905" published="2007-02-13" seq="2007-0905" severity="High" type="CVE"><desc><descript source="cve">PHP before 5.2.1 allows attackers to bypass safe_mode and open_basedir restrictions via unspecified vectors in the session extension.  NOTE: it is possible that this issue is a duplicate of CVE-2006-6383.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs><ref source="" url="http://www.php.net/ChangeLog-5.php#5.2.1"></ref><ref source="" url="http://www.php.net/releases/5_2_1.php"></ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/22496">22496</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0546">ADV-2007-0546</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24089">24089</ref><ref source="OPENPKG" url="http://www.openpkg.com/security/advisories/OpenPKG-SA-2007.010.html">
OpenPKG-SA-2007.010</ref><ref source="TRUSTIX" url="http://www.trustix.org/errata/2007/0009/">2007-0009</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24419">24419</ref></refs><vuln_soft><prod name="Secure Linux" vendor="Trustix"><vers num="3.0"/><vers num="2.2"/></prod><prod name="PHP" vendor="PHP"><vers num="5.1.6"/><vers num="5.1.5"/><vers num="5.1.4"/><vers num="5.1.3"/><vers num="5.1.2"/><vers num="5.1.1"/><vers num="5.1"/><vers num="5.0.5"/><vers num="5.0.4"/><vers num="5.0.3"/><vers num="5.0.2"/><vers num="5.0.1"/><vers num="5.0 candidate 3"/><vers num="5.0 candidate 2"/><vers num="5.0 candidate 1"/><vers num="5.0.0"/><vers num="4.4.4"/><vers num="4.4.3"/><vers num="4.4.2"/><vers num="4.4.1"/><vers num="4.4.0"/><vers num="4.3.11"/><vers num="4.3.10"/><vers num="4.3.9"/><vers num="4.3.8"/><vers num="4.3.7"/><vers num="4.3.6"/><vers num="4.3.5"/><vers num="4.3.4"/><vers num="4.3.3"/><vers num="4.3.2"/><vers num="4.3.1"/><vers num="4.3"/><vers num="4.2.3"/><vers num="4.2.2"/><vers num="4.2.1"/><vers num="4.2.0"/><vers edition="Dev" num="4.2"/><vers num="4.1.2"/><vers num="4.1.1"/><vers num="4.1.0"/><vers num="4.0.7 RC3"/><vers num="4.0.7 RC2"/><vers num="4.0.7 RC1"/><vers num="4.0.7"/><vers num="4.0.6"/><vers num="4.0.5"/><vers num="4.0.4"/><vers num="4.0.3 pl1"/><vers num="4.0.3"/><vers num="4.0.2"/><vers num="4.0.1 pl2"/><vers num="4.0.1 pl1"/><vers num="4.0.1"/><vers num="4.0"/><vers num="3.0.18"/><vers num="3.0.17"/><vers num="3.0.16"/><vers num="3.0.15"/><vers num="3.0.14"/><vers num="3.0.13"/><vers num="3.0.12"/><vers num="3.0.11"/><vers num="3.0.10"/><vers num="3.0.9"/><vers num="3.0.8"/><vers num="3.0.7"/><vers num="3.0.6"/><vers num="3.0.5"/><vers num="3.0.4"/><vers num="3.0.3"/><vers num="3.0.2"/><vers num="3.0.1"/><vers num="3.0"/><vers num="5.2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-04-19" name="CVE-2007-0906" published="2007-02-13" seq="2007-0906" severity="High" type="CVE"><desc><descript source="cve">Multiple buffer overflows in PHP before 5.2.1 allow attackers to cause a denial of service and possibly execute arbitrary code via unspecified vectors in the (1) session, (2) zip, (3) imap, and (4) sqlite extensions; (5) stream filters; and the (6) str_replace, (7) mail, (8) ibase_delete_user, (9) ibase_add_user, and (10) ibase_modify_user functions.  NOTE: vector 6 might actually be an integer overflow (CVE-2007-1885).  NOTE: as of 20070411, vector (3) might involve the imap_mail_compose function (CVE-2007-1825).</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref source="" url="http://www.php.net/ChangeLog-5.php#5.2.1"></ref><ref source="" url="http://www.php.net/releases/5_2_1.php"></ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/22496">22496</ref><ref patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0546">ADV-2007-0546</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24089">24089</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/461462/100/0/threaded">20070227 rPSA-2007-0043-1 php php-mysql php-pgsql</ref><ref source="" url="https://issues.rpath.com/browse/RPL-1088"></ref><ref source="" url="http://support.avaya.com/elmodocs2/security/ASA-2007-101.htm"></ref><ref source="DEBIAN" url="http://www.us.debian.org/security/2007/dsa-1264">DSA-1264</ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200703-21.xml">GLSA-200703-21</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2007:048">MDKSA-2007:048</ref><ref source="OPENPKG" url="http://www.openpkg.com/security/advisories/OpenPKG-SA-2007.010.html">OpenPKG-SA-2007.010</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2007-0076.html">RHSA-2007:0076</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2007-0081.html">RHSA-2007:0081</ref><ref source="REDHAT" url="http://rhn.redhat.com/errata/RHSA-2007-0089.html">RHSA-2007:0089</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2007-0088.html">RHSA-2007:0088</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2007-0082.html">RHSA-2007:0082</ref><ref source="SUSE" url="http://lists.suse.com/archive/suse-security-announce/2007-Mar/0003.html">SUSE-SA:2007:020</ref><ref source="UBUNTU" url="http://www.ubuntu.com/usn/usn-424-1">USN-424-1</ref><ref source="UBUNTU" url="http://www.ubuntu.com/usn/usn-424-2">USN-424-2</ref><ref source="OSVDB" url="http://www.osvdb.org/32776">32776</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017671">1017671</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24195">24195</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24217">24217</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24248">24248</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24236">24236</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24295">24295</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24322">24322</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24432">24432</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24421">24421</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24514">24514</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24606">24606</ref><ref source="" url="http://support.avaya.com/elmodocs2/security/ASA-2007-136.htm"></ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24642">24642</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/466166/100/0/threaded">
20070418 rPSA-2007-0073-1 php php-mysql php-pgsql</ref><ref source="" url="https://issues.rpath.com/browse/RPL-1268"></ref><ref source="SECUNIA" url="http://secunia.com/advisories/24945">
24945</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:048">MDKSA-2007:048</ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20070201-01-P.asc">20070201-01-P</ref><ref source="SUSE" url="http://lists.opensuse.org/opensuse-security-announce/2007-07/msg00006.html">SUSE-SA:2007:044</ref><ref source="TRUSTIX" url="http://www.trustix.org/errata/2007/0009/">2007-0009</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24284">24284</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24419">24419</ref><ref source="SECUNIA" url="http://secunia.com/advisories/26048">26048</ref></refs><vuln_soft><prod name="Secure Linux" vendor="Trustix"><vers num="3.0"/><vers num="2.2"/></prod><prod name="PHP" vendor="PHP"><vers num="5.1.6"/><vers num="5.1.5"/><vers num="5.1.4"/><vers num="5.1.3"/><vers num="5.1.2"/><vers num="5.1.1"/><vers num="5.1"/><vers num="5.0.5"/><vers num="5.0.4"/><vers num="5.0.3"/><vers num="5.0.2"/><vers num="5.0.1"/><vers num="5.0 candidate 3"/><vers num="5.0 candidate 2"/><vers num="5.0 candidate 1"/><vers num="5.0.0"/><vers num="4.4.4"/><vers num="4.4.3"/><vers num="4.4.2"/><vers num="4.4.1"/><vers num="4.4.0"/><vers num="4.3.11"/><vers num="4.3.10"/><vers num="4.3.9"/><vers num="4.3.8"/><vers num="4.3.7"/><vers num="4.3.6"/><vers num="4.3.5"/><vers num="4.3.4"/><vers num="4.3.3"/><vers num="4.3.2"/><vers num="4.3.1"/><vers num="4.3"/><vers num="4.2.3"/><vers num="4.2.2"/><vers num="4.2.1"/><vers num="4.2.0"/><vers edition="Dev" num="4.2"/><vers num="4.1.2"/><vers num="4.1.1"/><vers num="4.1.0"/><vers num="4.0.7 RC3"/><vers num="4.0.7 RC2"/><vers num="4.0.7 RC1"/><vers num="4.0.7"/><vers num="4.0.6"/><vers num="4.0.5"/><vers num="4.0.4"/><vers num="4.0.3 pl1"/><vers num="4.0.3"/><vers num="4.0.2"/><vers num="4.0.1 pl2"/><vers num="4.0.1 pl1"/><vers num="4.0.1"/><vers num="4.0"/><vers num="3.0.18"/><vers num="3.0.17"/><vers num="3.0.16"/><vers num="3.0.15"/><vers num="3.0.14"/><vers num="3.0.13"/><vers num="3.0.12"/><vers num="3.0.11"/><vers num="3.0.10"/><vers num="3.0.9"/><vers num="3.0.8"/><vers num="3.0.7"/><vers num="3.0.6"/><vers num="3.0.5"/><vers num="3.0.4"/><vers num="3.0.3"/><vers num="3.0.2"/><vers num="3.0.1"/><vers num="3.0"/><vers num="5.2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0" modified="2007-04-27" name="CVE-2007-0907" published="2007-02-13" seq="2007-0907" severity="Medium" type="CVE"><desc><descript source="cve">Buffer underflow in PHP before 5.2.1 allows attackers to cause a denial of service via unspecified vectors involving the sapi_header_op function.</descript></desc><loss_types><avail/></loss_types><range><network/></range><refs><ref source="UBUNTU" url="http://www.ubuntu.com/usn/usn-424-2">USN-424-2</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017671">1017671</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24195">24195</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24217">24217</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24248">24248</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24236">24236</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24295">24295</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24322">24322</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24432">24432</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24421">24421</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24514">24514</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24606">24606</ref><ref source="" url="http://support.avaya.com/elmodocs2/security/ASA-2007-136.htm"></ref><ref source="SECUNIA" url="http://secunia.com/advisories/24642">24642</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:048">MDKSA-2007:048</ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20070201-01-P.asc">20070201-01-P</ref><ref source="TRUSTIX" url="http://www.trustix.org/errata/2007/0009/">2007-0009</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24284">24284</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24419">24419</ref><ref source="" url="http://www.php.net/ChangeLog-5.php#5.2.1"></ref><ref source="" url="http://www.php.net/releases/5_2_1.php"></ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/22496">22496</ref><ref patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0546">ADV-2007-0546</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24089">24089</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/461462/100/0/threaded">20070227 rPSA-2007-0043-1 php php-mysql php-pgsql</ref><ref source="" url="https://issues.rpath.com/browse/RPL-1088"></ref><ref source="" url="http://support.avaya.com/elmodocs2/security/ASA-2007-101.htm"></ref><ref source="DEBIAN" url="http://www.us.debian.org/security/2007/dsa-1264">DSA-1264</ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200703-21.xml">GLSA-200703-21</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2007:048">MDKSA-2007:048</ref><ref source="OPENPKG" url="http://www.openpkg.com/security/advisories/OpenPKG-SA-2007.010.html">OpenPKG-SA-2007.010</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2007-0076.html">RHSA-2007:0076</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2007-0081.html">RHSA-2007:0081</ref><ref source="REDHAT" url="http://rhn.redhat.com/errata/RHSA-2007-0089.html">RHSA-2007:0089</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2007-0088.html">RHSA-2007:0088</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2007-0082.html">RHSA-2007:0082</ref><ref source="SUSE" url="http://lists.suse.com/archive/suse-security-announce/2007-Mar/0003.html">SUSE-SA:2007:020</ref><ref source="UBUNTU" url="http://www.ubuntu.com/usn/usn-424-1">USN-424-1</ref></refs><vuln_soft><prod name="Secure Linux" vendor="Trustix"><vers num="3.0"/><vers num="2.2"/></prod><prod name="PHP" vendor="PHP"><vers num="5.1.6"/><vers num="5.1.5"/><vers num="5.1.4"/><vers num="5.1.3"/><vers num="5.1.2"/><vers num="5.1.1"/><vers num="5.1"/><vers num="5.0.5"/><vers num="5.0.4"/><vers num="5.0.3"/><vers num="5.0.2"/><vers num="5.0.1"/><vers num="5.0 candidate 3"/><vers num="5.0 candidate 2"/><vers num="5.0 candidate 1"/><vers num="5.0.0"/><vers num="4.4.4"/><vers num="4.4.3"/><vers num="4.4.2"/><vers num="4.4.1"/><vers num="4.4.0"/><vers num="4.3.11"/><vers num="4.3.10"/><vers num="4.3.9"/><vers num="4.3.8"/><vers num="4.3.7"/><vers num="4.3.6"/><vers num="4.3.5"/><vers num="4.3.4"/><vers num="4.3.3"/><vers num="4.3.2"/><vers num="4.3.1"/><vers num="4.3"/><vers num="4.2.3"/><vers num="4.2.2"/><vers num="4.2.1"/><vers num="4.2.0"/><vers edition="Dev" num="4.2"/><vers num="4.1.2"/><vers num="4.1.1"/><vers num="4.1.0"/><vers num="4.0.7 RC3"/><vers num="4.0.7 RC2"/><vers num="4.0.7 RC1"/><vers num="4.0.7"/><vers num="4.0.6"/><vers num="4.0.5"/><vers num="4.0.4"/><vers num="4.0.3 pl1"/><vers num="4.0.3"/><vers num="4.0.2"/><vers num="4.0.1 pl2"/><vers num="4.0.1 pl1"/><vers num="4.0.1"/><vers num="4.0"/><vers num="3.0.18"/><vers num="3.0.17"/><vers num="3.0.16"/><vers num="3.0.15"/><vers num="3.0.14"/><vers num="3.0.13"/><vers num="3.0.12"/><vers num="3.0.11"/><vers num="3.0.10"/><vers num="3.0.9"/><vers num="3.0.8"/><vers num="3.0.7"/><vers num="3.0.6"/><vers num="3.0.5"/><vers num="3.0.4"/><vers num="3.0.3"/><vers num="3.0.2"/><vers num="3.0.1"/><vers num="3.0"/><vers num="5.2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0" modified="2007-04-23" name="CVE-2007-0908" published="2007-02-13" seq="2007-0908" severity="Medium" type="CVE"><desc><descript source="cve">The WDDX deserializer in the wddx extension in PHP 5 before 5.2.1 and PHP 4 before 4.4.5 does not properly initialize the key_length variable for a numerical key, which allows context-dependent attackers to read stack memory via a wddxPacket element that contains a variable with a string name before a numerical variable.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref source="" url="http://www.php.net/ChangeLog-5.php#5.2.1"></ref><ref source="" url="http://www.php.net/releases/5_2_1.php"></ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/22496">22496</ref><ref patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0546">ADV-2007-0546</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24089">24089</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/461462/100/0/threaded">20070227 rPSA-2007-0043-1 php php-mysql php-pgsql</ref><ref source="" url="https://issues.rpath.com/browse/RPL-1088"></ref><ref source="" url="http://support.avaya.com/elmodocs2/security/ASA-2007-101.htm"></ref><ref source="DEBIAN" url="http://www.us.debian.org/security/2007/dsa-1264">DSA-1264</ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200703-21.xml">GLSA-200703-21</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2007:048">MDKSA-2007:048</ref><ref source="OPENPKG" url="http://www.openpkg.com/security/advisories/OpenPKG-SA-2007.010.html">OpenPKG-SA-2007.010</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2007-0076.html">RHSA-2007:0076</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2007-0081.html">RHSA-2007:0081</ref><ref source="REDHAT" url="http://rhn.redhat.com/errata/RHSA-2007-0089.html">RHSA-2007:0089</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2007-0088.html">RHSA-2007:0088</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2007-0082.html">RHSA-2007:0082</ref><ref source="SUSE" url="http://lists.suse.com/archive/suse-security-announce/2007-Mar/0003.html">SUSE-SA:2007:020</ref><ref source="UBUNTU" url="http://www.ubuntu.com/usn/usn-424-1">USN-424-1</ref><ref source="UBUNTU" url="http://www.ubuntu.com/usn/usn-424-2">USN-424-2</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017671">1017671</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24195">24195</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24217">24217</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24248">24248</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24236">24236</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24295">24295</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24322">24322</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24432">24432</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24421">24421</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24514">24514</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24606">24606</ref><ref source="" url="http://support.avaya.com/elmodocs2/security/ASA-2007-136.htm"></ref><ref source="SECUNIA" url="http://secunia.com/advisories/24642">24642</ref><ref source="" url="http://www.php-security.org/MOPB/MOPB-11-2007.html"></ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32493">php-wddx-information-disclosure(32493)</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:048">MDKSA-2007:048</ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20070201-01-P.asc">20070201-01-P</ref><ref source="TRUSTIX" url="http://www.trustix.org/errata/2007/0009/">2007-0009</ref><ref source="BID" url="http://www.securityfocus.com/bid/22806">22806</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24284">24284</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24419">24419</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2321">2321</ref></refs><vuln_soft><prod name="Secure Linux" vendor="Trustix"><vers num="3.0"/><vers num="2.2"/></prod><prod name="PHP" vendor="PHP"><vers num="5.1.6"/><vers num="5.1.5"/><vers num="5.1.4"/><vers num="5.1.3"/><vers num="5.1.2"/><vers num="5.1.1"/><vers num="5.1"/><vers num="5.0.5"/><vers num="5.0.4"/><vers num="5.0.3"/><vers num="5.0.2"/><vers num="5.0.1"/><vers num="5.0 candidate 3"/><vers num="5.0 candidate 2"/><vers num="5.0 candidate 1"/><vers num="5.0.0"/><vers num="4.4.4"/><vers num="4.4.3"/><vers num="4.4.2"/><vers num="4.4.1"/><vers num="4.4.0"/><vers num="4.3.11"/><vers num="4.3.10"/><vers num="4.3.9"/><vers num="4.3.8"/><vers num="4.3.7"/><vers num="4.3.6"/><vers num="4.3.5"/><vers num="4.3.4"/><vers num="4.3.3"/><vers num="4.3.2"/><vers num="4.3.1"/><vers num="4.3"/><vers num="4.2.3"/><vers num="4.2.2"/><vers num="4.2.1"/><vers num="4.2.0"/><vers edition="Dev" num="4.2"/><vers num="4.1.2"/><vers num="4.1.1"/><vers num="4.1.0"/><vers num="4.0.7 RC3"/><vers num="4.0.7 RC2"/><vers num="4.0.7 RC1"/><vers num="4.0.7"/><vers num="4.0.6"/><vers num="4.0.5"/><vers num="4.0.4"/><vers num="4.0.3 pl1"/><vers num="4.0.3"/><vers num="4.0.2"/><vers num="4.0.1 pl2"/><vers num="4.0.1 pl1"/><vers num="4.0.1"/><vers num="4.0"/><vers num="3.0.18"/><vers num="3.0.17"/><vers num="3.0.16"/><vers num="3.0.15"/><vers num="3.0.14"/><vers num="3.0.13"/><vers num="3.0.12"/><vers num="3.0.11"/><vers num="3.0.10"/><vers num="3.0.9"/><vers num="3.0.8"/><vers num="3.0.7"/><vers num="3.0.6"/><vers num="3.0.5"/><vers num="3.0.4"/><vers num="3.0.3"/><vers num="3.0.2"/><vers num="3.0.1"/><vers num="3.0"/><vers num="5.2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-04-03" name="CVE-2007-0909" published="2007-02-13" seq="2007-0909" severity="High" type="CVE"><desc><descript source="cve">Multiple format string vulnerabilities in PHP before 5.2.1 might allow attackers to execute arbitrary code via format string specifiers to (1) all of the *print functions on 64-bit systems, and (2) the odbc_result_all function.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="SECUNIA" url="http://secunia.com/advisories/24236">24236</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24295">24295</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24322">24322</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24432">24432</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24421">24421</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24514">24514</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24606">24606</ref><ref source="" url="http://support.avaya.com/elmodocs2/security/ASA-2007-136.htm"></ref><ref source="SECUNIA" url="http://secunia.com/advisories/24642">
24642</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:048">MDKSA-2007:048</ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20070201-01-P.asc">20070201-01-P</ref><ref source="TRUSTIX" url="http://www.trustix.org/errata/2007/0009/">2007-0009</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24284">24284</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24419">24419</ref><ref source="" url="http://www.php.net/ChangeLog-5.php#5.2.1"></ref><ref source="" url="http://www.php.net/releases/5_2_1.php"></ref><ref source="BID" url="http://www.securityfocus.com/bid/22496">22496</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0546">ADV-2007-0546</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24089">24089</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/461462/100/0/threaded">20070227 rPSA-2007-0043-1 php php-mysql php-pgsql</ref><ref source="" url="https://issues.rpath.com/browse/RPL-1088"></ref><ref source="" url="http://support.avaya.com/elmodocs2/security/ASA-2007-101.htm"></ref><ref source="DEBIAN" url="http://www.us.debian.org/security/2007/dsa-1264">DSA-1264</ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200703-21.xml">GLSA-200703-21</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2007:048">MDKSA-2007:048</ref><ref source="OPENPKG" url="http://www.openpkg.com/security/advisories/OpenPKG-SA-2007.010.html">OpenPKG-SA-2007.010</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2007-0076.html">RHSA-2007:0076</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2007-0081.html">RHSA-2007:0081</ref><ref source="REDHAT" url="http://rhn.redhat.com/errata/RHSA-2007-0089.html">RHSA-2007:0089</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2007-0088.html">RHSA-2007:0088</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2007-0082.html">RHSA-2007:0082</ref><ref source="SUSE" url="http://lists.suse.com/archive/suse-security-announce/2007-Mar/0003.html">SUSE-SA:2007:020</ref><ref source="UBUNTU" url="http://www.ubuntu.com/usn/usn-424-1">USN-424-1</ref><ref source="UBUNTU" url="http://www.ubuntu.com/usn/usn-424-2">USN-424-2</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017671">1017671</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24195">24195</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24217">24217</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24248">24248</ref></refs><vuln_soft><prod name="Secure Linux" vendor="Trustix"><vers num="3.0"/><vers num="2.2"/></prod><prod name="PHP" vendor="PHP"><vers num="5.1.6"/><vers num="5.1.5"/><vers num="5.1.4"/><vers num="5.1.3"/><vers num="5.1.2"/><vers num="5.1.1"/><vers num="5.1"/><vers num="5.0.5"/><vers num="5.0.4"/><vers num="5.0.3"/><vers num="5.0.2"/><vers num="5.0.1"/><vers num="5.0 candidate 3"/><vers num="5.0 candidate 2"/><vers num="5.0 candidate 1"/><vers num="5.0.0"/><vers num="4.4.4"/><vers num="4.4.3"/><vers num="4.4.2"/><vers num="4.4.1"/><vers num="4.4.0"/><vers num="4.3.11"/><vers num="4.3.10"/><vers num="4.3.9"/><vers num="4.3.8"/><vers num="4.3.7"/><vers num="4.3.6"/><vers num="4.3.5"/><vers num="4.3.4"/><vers num="4.3.3"/><vers num="4.3.2"/><vers num="4.3.1"/><vers num="4.3"/><vers num="4.2.3"/><vers num="4.2.2"/><vers num="4.2.1"/><vers num="4.2.0"/><vers edition="Dev" num="4.2"/><vers num="4.1.2"/><vers num="4.1.1"/><vers num="4.1.0"/><vers num="4.0.7 RC3"/><vers num="4.0.7 RC2"/><vers num="4.0.7 RC1"/><vers num="4.0.7"/><vers num="4.0.6"/><vers num="4.0.5"/><vers num="4.0.4"/><vers num="4.0.3 pl1"/><vers num="4.0.3"/><vers num="4.0.2"/><vers num="4.0.1 pl2"/><vers num="4.0.1 pl1"/><vers num="4.0.1"/><vers num="4.0"/><vers num="3.0.18"/><vers num="3.0.17"/><vers num="3.0.16"/><vers num="3.0.15"/><vers num="3.0.14"/><vers num="3.0.13"/><vers num="3.0.12"/><vers num="3.0.11"/><vers num="3.0.10"/><vers num="3.0.9"/><vers num="3.0.8"/><vers num="3.0.7"/><vers num="3.0.6"/><vers num="3.0.5"/><vers num="3.0.4"/><vers num="3.0.3"/><vers num="3.0.2"/><vers num="3.0.1"/><vers num="3.0"/><vers num="5.2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2008-06-25" name="CVE-2007-0910" published="2007-02-13" seq="2007-0910" severity="High" type="CVE"><desc><descript source="cve">Unspecified vulnerability in PHP before 5.2.1 allows attackers to &quot;clobber&quot; certain super-global variables via unspecified vectors.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><range><network/></range><refs><ref source="" url="http://www.php.net/ChangeLog-5.php#5.2.1"></ref><ref source="" url="http://www.php.net/releases/5_2_1.php"></ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/22496">22496</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0546">ADV-2007-0546</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24089">24089</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/461462/100/0/threaded">20070227 rPSA-2007-0043-1 php php-mysql php-pgsql</ref><ref source="" url="https://issues.rpath.com/browse/RPL-1088"></ref><ref source="" url="http://support.avaya.com/elmodocs2/security/ASA-2007-101.htm"></ref><ref source="DEBIAN" url="http://www.us.debian.org/security/2007/dsa-1264">DSA-1264</ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200703-21.xml">GLSA-200703-21</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2007:048">MDKSA-2007:048</ref><ref source="OPENPKG" url="http://www.openpkg.com/security/advisories/OpenPKG-SA-2007.010.html">OpenPKG-SA-2007.010</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2007-0076.html">RHSA-2007:0076</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2007-0081.html">RHSA-2007:0081</ref><ref source="REDHAT" url="http://rhn.redhat.com/errata/RHSA-2007-0089.html">RHSA-2007:0089</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2007-0088.html">RHSA-2007:0088</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2007-0082.html">RHSA-2007:0082</ref><ref source="SUSE" url="http://lists.suse.com/archive/suse-security-announce/2007-Mar/0003.html">SUSE-SA:2007:020</ref><ref source="UBUNTU" url="http://www.ubuntu.com/usn/usn-424-1">USN-424-1</ref><ref source="UBUNTU" url="http://www.ubuntu.com/usn/usn-424-2">USN-424-2</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017671">1017671</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24195">24195</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24217">24217</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24248">24248</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24236">24236</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24295">24295</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24322">24322</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24432">24432</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24421">24421</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24514">24514</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24606">24606</ref><ref source="" url="http://support.avaya.com/elmodocs2/security/ASA-2007-136.htm"></ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24642">24642</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/466166/100/0/threaded">20070418 rPSA-2007-0073-1 php php-mysql php-pgsql</ref><ref source="" url="https://issues.rpath.com/browse/RPL-1268"></ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24945">24945</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:048">MDKSA-2007:048</ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20070201-01-P.asc">20070201-01-P</ref><ref source="TRUSTIX" url="http://www.trustix.org/errata/2007/0009/">2007-0009</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24284">24284</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24419">24419</ref></refs><vuln_soft><prod name="Secure Linux" vendor="Trustix"><vers num="3.0"/><vers num="2.2"/></prod><prod name="PHP" vendor="PHP"><vers num="5.1.6"/><vers num="5.1.5"/><vers num="5.1.4"/><vers num="5.1.3"/><vers num="5.1.2"/><vers num="5.1.1"/><vers num="5.1"/><vers num="5.0.5"/><vers num="5.0.4"/><vers num="5.0.3"/><vers num="5.0.2"/><vers num="5.0.1"/><vers num="5.0 candidate 3"/><vers num="5.0 candidate 2"/><vers num="5.0 candidate 1"/><vers num="5.0.0"/><vers num="4.4.4"/><vers num="4.4.3"/><vers num="4.4.2"/><vers num="4.4.1"/><vers num="4.4.0"/><vers num="4.3.11"/><vers num="4.3.10"/><vers num="4.3.9"/><vers num="4.3.8"/><vers num="4.3.7"/><vers num="4.3.6"/><vers num="4.3.5"/><vers num="4.3.4"/><vers num="4.3.3"/><vers num="4.3.2"/><vers num="4.3.1"/><vers num="4.3"/><vers num="4.2.3"/><vers num="4.2.2"/><vers num="4.2.1"/><vers num="4.2.0"/><vers edition="Dev" num="4.2"/><vers num="4.1.2"/><vers num="4.1.1"/><vers num="4.1.0"/><vers num="4.0.7 RC3"/><vers num="4.0.7 RC2"/><vers num="4.0.7 RC1"/><vers num="4.0.7"/><vers num="4.0.6"/><vers num="4.0.5"/><vers num="4.0.4"/><vers num="4.0.3 pl1"/><vers num="4.0.3"/><vers num="4.0.2"/><vers num="4.0.1 pl2"/><vers num="4.0.1 pl1"/><vers num="4.0.1"/><vers num="4.0"/><vers num="3.0.18"/><vers num="3.0.17"/><vers num="3.0.16"/><vers num="3.0.15"/><vers num="3.0.14"/><vers num="3.0.13"/><vers num="3.0.12"/><vers num="3.0.11"/><vers num="3.0.10"/><vers num="3.0.9"/><vers num="3.0.8"/><vers num="3.0.7"/><vers num="3.0.6"/><vers num="3.0.5"/><vers num="3.0.4"/><vers num="3.0.3"/><vers num="3.0.2"/><vers num="3.0.1"/><vers num="3.0"/><vers num="5.2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.8" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.9" CVSS_score="7.8" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_version="2.0" modified="2007-02-14" name="CVE-2007-0911" published="2007-02-13" seq="2007-0911" severity="High" type="CVE"><desc><descript source="cve">Off-by-one error in the str_ireplace function in PHP 5.2.1 might allow context-dependent attackers to cause a denial of service (crash).</descript></desc><loss_types><avail/></loss_types><range><network/></range><refs><ref source="MLIST" url="http://marc.theaimsgroup.com/?l=php-dev&amp;m=117104930526516&amp;w=2">[php-dev] 20070209 PHP 5.2.1 crashing Apache/IIS...</ref><ref source="MLIST" url="http://marc.theaimsgroup.com/?l=php-dev&amp;m=117106751715609&amp;w=2">[php-dev] 20070210 Re: PHP 5.2.1 crashing Apache/IIS...</ref><ref source="" url="http://cvs.php.net/viewvc.cgi/php-src/ext/standard/string.c?r1=1.445.2.14.2.36&amp;r2=1.445.2.14.2.37"></ref><ref source="BID" url="http://www.securityfocus.com/bid/22505">22505</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/459856/100/0/threaded">

20070209 PHP 5.2.1 crash bug</ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200703-21.xml">
GLSA-200703-21</ref><ref source="SUSE" url="http://lists.suse.com/archive/suse-security-announce/2007-Mar/0003.html">
SUSE-SA:2007:020</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24514">
24514</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24606">
24606</ref></refs><vuln_soft><prod name="PHP" vendor="PHP"><vers num="5.2.1"/></prod></vuln_soft></entry><entry CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" CVSS_score="9.3" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-02-14" name="CVE-2007-0912" published="2007-02-13" seq="2007-0912" severity="High" type="CVE"><desc><descript source="cve">Cross-Site Request Forgery (CSRF) vulnerability in admin/admin.adm.php in Jportal 2.3.1, and possibly earlier, allows remote attackers to perform privileged actions as administrators by tricking the admin into accessing a URL with modified arguments to admin/admin.adm.php.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/459827/100/0/threaded">20070211 Jportal 2.3.1 CSRF vulnerability</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32458">
jportal-admin-csrf(32458)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2239">2239</ref></refs><vuln_soft><prod name="JPortal Web Server" vendor="JPortal"><vers num="2.3.1"/></prod></vuln_soft></entry><entry CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" CVSS_score="9.3" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-02-14" name="CVE-2007-0913" published="2007-02-13" seq="2007-0913" severity="High" type="CVE"><desc><descript source="cve">Unspecified vulnerability in Microsoft Powerpoint allows remote user-assisted attackers to execute arbitrary code via unknown attack vectors, as exploited by Trojan.PPDropper.G.  NOTE: as of 20070213, it is not clear whether this is the same issue as CVE-2006-5296, CVE-2006-4694, CVE-2006-3876, CVE-2006-3877, or older issues.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><range><network/><user_init/></range><refs><ref source="" url="http://www.symantec.com/enterprise/security_response/writeup.jsp?docid=2007-021312-5133-99&amp;tabid=2"></ref></refs><vuln_soft><prod name="Powerpoint" vendor="Microsoft"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.1" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.9" CVSS_score="7.1" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:C)" CVSS_version="2.0" modified="2007-06-27" name="CVE-2007-0914" published="2007-02-13" seq="2007-0914" severity="High" type="CVE"><desc><descript source="cve">Race condition in the TCP subsystem for Solaris 10 allows remote attackers to cause a denial of service (system panic) via unknown vectors.</descript></desc><loss_types><avail/></loss_types><vuln_types><race/></vuln_types><range><network/></range><refs><ref patch="1" source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102796-1">102796</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/22550">22550</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0588">ADV-2007-0588</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017649">1017649</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24166">24166</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32484">solaris-tcp-race-condition-dos(32484)</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2120">oval:org.mitre.oval:def:2120</ref></refs><vuln_soft><prod name="Solaris" vendor="Sun"><vers edition="SPARC" num="10.0"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-02-14" name="CVE-2007-0915" published="2007-02-13" seq="2007-0915" severity="High" type="CVE"><desc><descript source="cve">Distributed SLS daemon (SLSd) on HP-UX B.11.11 allows remote attackers to overwrite arbitrary files and gain privileges via a crafted RPC request.</descript></desc><sols><sol source="nvd">See HP&apos;s advisory.</sol></sols><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref source="HP" url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=c00862809">HPSBUX02191</ref><ref source="BID" url="http://www.securityfocus.com/bid/22551">22551</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017630">1017630</ref><ref source="IDEFENSE" url="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=474">

20070213 Hewlett-Packard HP-UX SLSd Arbitrary File Creation Vulnerability</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0590">
ADV-2007-0590</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24169">
24169</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32471">
hpux-slsd-unauthorized-access(32471)</ref></refs><vuln_soft><prod name="HP-UX" vendor="HP"><vers num="B.11.11"/></prod></vuln_soft></entry><entry CVSS_base_score="4.9" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.9" CVSS_score="4.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:C)" CVSS_version="2.0" modified="2007-08-03" name="CVE-2007-0916" published="2007-02-13" seq="2007-0916" severity="Medium" type="CVE"><desc><descript source="cve">Unspecified vulnerability in the Address and Routing Parameter Area (ARPA) transport functionality in HP-UX B.11.11 and B.11.23 allows local users to cause an unspecified denial of service via unknown vectors.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><local/></range><refs><ref source="HP" url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=c00863839">HPSBUX02192</ref><ref source="BID" url="http://www.securityfocus.com/bid/22546">22546</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017629">1017629</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0596">ADV-2007-0596</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24173">24173</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32468">hpux-arpa-dos(32468)</ref></refs><vuln_soft><prod name="HP-UX" vendor="HP"><vers num="B.11.11"/><vers edition="IA64 64-bit" num="B.11.23"/></prod></vuln_soft></entry><entry CVSS_base_score="6.4" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="4.9" CVSS_score="6.4" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_version="2.0" modified="2007-02-14" name="CVE-2007-0917" published="2007-02-13" seq="2007-0917" severity="Medium" type="CVE"><desc><descript source="cve">The Intrusion Prevention System (IPS) feature for Cisco IOS 12.4XE to 12.3T allows remote attackers to bypass IPS signatures that use regular expressions via fragmented packets.</descript></desc><loss_types><conf/><int/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref source="CISCO" url="http://www.cisco.com/en/US/products/products_security_advisory09186a00807e0a5b.shtml">20070213 Multiple IOS IPS Vulnerabilities</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017631">1017631</ref><ref source="" url="http://www.cisco.com/en/US/products/products_security_response09186a00807e0a5e.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/22549">
22549</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0597">
ADV-2007-0597</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24142">
24142</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32473">
cisco-ios-ips-security-bypass(32473)</ref></refs><vuln_soft><prod name="IOS" vendor="Cisco"><vers num="12.3T"/><vers num="12.3XQ"/><vers num="12.3XR"/><vers num="12.3XS"/><vers num="12.3XW"/><vers num="12.3XX"/><vers num="12.3XY"/><vers num="12.3YA"/><vers num="12.3YD"/><vers num="12.3YG"/><vers num="12.3YH"/><vers num="12.3YI"/><vers num="12.3YJ"/><vers num="12.3YK"/><vers num="12.3YM"/><vers num="12.3YQ"/><vers num="12.3YS"/><vers num="12.3YT"/><vers num="12.3YX"/><vers num="12.3YZ"/><vers num="12.4"/><vers num="12.4MR"/><vers num="12.4T"/><vers num="12.4XA"/><vers num="12.4XB"/></prod></vuln_soft></entry><entry CVSS_base_score="7.8" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.9" CVSS_score="7.8" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_version="2.0" modified="2008-01-02" name="CVE-2007-0918" published="2007-02-13" seq="2007-0918" severity="High" type="CVE"><desc><descript source="cve">The ATOMIC.TCP signature engine in the Intrusion Prevention System (IPS) feature for Cisco IOS 12.4XA, 12.3YA, 12.3T, and other trains allows remote attackers to cause a denial of service (IPS crash and traffic loss) via unspecified manipulations that are not properly handled by the regular expression feature, as demonstrated using the 3123.0 (Netbus Pro Traffic) signature.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref source="CISCO" url="http://www.cisco.com/en/US/products/products_security_advisory09186a00807e0a5b.shtml">20070213 Multiple IOS IPS Vulnerabilities</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017631">1017631</ref><ref source="" url="http://www.cisco.com/en/US/products/products_security_response09186a00807e0a5e.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/22549">22549</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0597">ADV-2007-0597</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24142">24142</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32474">cisco-ios-ips-dos(32474)</ref></refs><vuln_soft><prod name="IOS" vendor="Cisco"><vers num="12.3YA"/><vers num="12.4XA"/><vers num="12.3T"/></prod></vuln_soft></entry><entry CVSS_base_score="7.8" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.9" CVSS_score="7.8" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:N/A:N)" CVSS_version="2.0" modified="2007-02-14" name="CVE-2007-0919" published="2007-02-14" seq="2007-0919" severity="High" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in Nickolas Grigoriadis Mini Web server (MiniWebsvr) 0.0.6 allows remote attackers to list the directory immediately above the web root via a ..%00 sequence in the URI.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/459829/100/0/threaded">20070211 Miniwebsvr 0.0.6 - Directory traversal</ref><ref source="VIM" url="http://attrition.org/pipermail/vim/2007-February/001315.html">20060213 Verified: dot in Miniwebsvr 0.0.6</ref><ref source="BID" url="http://www.securityfocus.com/bid/22523">22523</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32451">
miniwebsvr-unspecified-directory-traversal(32451)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2248">2248</ref></refs><vuln_soft><prod name="Mini Web server" vendor="Nickolas Grigoriadis"><vers num="0.0.6"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-02-14" name="CVE-2007-0920" published="2007-02-14" seq="2007-0920" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in philboard_forum.asp in Philboard 1.14 and earlier allows remote attackers to execute arbitrary SQL commands via the forumid parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://www.milw0rm.com/exploits/3295"></ref><ref source="BID" url="http://www.securityfocus.com/bid/22532">22532</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32442">philboard-philboardforum-sql-injection(32442)</ref><ref source="MILW0RM" url="http://milw0rm.com/exploits/3295">

3295</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0600">
ADV-2007-0600</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32472">
nabopoll-configedit-unathorized-access(32472)</ref></refs><vuln_soft><prod name="Philboard" vendor="Philboard"><vers num="1.14" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="9.4" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="9.2" CVSS_score="9.4" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:C/A:C)" CVSS_version="2.0" modified="2007-02-14" name="CVE-2007-0921" published="2007-02-14" seq="2007-0921" severity="High" type="CVE"><desc><descript source="cve">Portal Search allows remote attackers to redirect a URL to an arbitrary web site by placing the URL in the query string to the top-level URI.</descript></desc><loss_types><avail/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/459794/100/0/threaded">20070212 Radical Technologies - Portal Search- multiple XSS issue</ref><ref source="BID" url="http://www.securityfocus.com/bid/22533">22533</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32460">
portalsearch-frame-url-spoofing(32460)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2247">2247</ref></refs><vuln_soft><prod name="Portal Search" vendor="Radical Technologies"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" modified="2007-06-29" name="CVE-2007-0922" published="2007-02-14" seq="2007-0922" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in buscador/buscador.htm in Portal Search allows remote attackers to inject arbitrary web script or HTML via the query string.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/459794/100/0/threaded">20070212 Radical Technologies - Portal Search- multiple XSS issue</ref><ref source="BID" url="http://www.securityfocus.com/bid/22533">22533</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2247">2247</ref></refs><vuln_soft><prod name="Portal Search" vendor="Radical Technologies"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.8" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.9" CVSS_score="7.8" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:N/A:N)" CVSS_version="2.0" modified="2007-02-14" name="CVE-2007-0923" published="2007-02-14" seq="2007-0923" severity="High" type="CVE"><desc><descript source="cve">buscador/buscador.htm in Portal Search allows remote attackers to obtain sensitive information (business logic) via a query string composed of a search for certain characters.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/459794/100/0/threaded">20070212 Radical Technologies - Portal Search- multiple XSS issue</ref><ref source="BID" url="http://www.securityfocus.com/bid/22533">22533</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32452">
portalsearch-buscador-info-disclosure(32452)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2247">2247</ref></refs><vuln_soft><prod name="Portal Search" vendor="Radical Technologies"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-02-14" name="CVE-2007-0924" published="2007-02-14" seq="2007-0924" severity="High" type="CVE"><desc><descript source="cve">Till Gerken phpPolls 1.0.3 allows remote attackers to bypass authentication and perform certain administrative actions via a direct request to phpPollAdmin.php3.  NOTE: this issue might subsume CVE-2006-3764.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/459789/100/0/threaded">20070211 phpPolls 1.0.3 (acces to sensitive file)</ref><ref source="BID" url="http://www.securityfocus.com/bid/22522">22522</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2242">2242</ref></refs><vuln_soft><prod name="phpPolls" vendor="Till Gerken"><vers num="1.0.3"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" modified="2007-02-14" name="CVE-2007-0925" published="2007-02-14" seq="2007-0925" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in search/SearchResults.aspx in Community Server allows remote attackers to inject arbitrary web script or HTML via the q parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/459848/100/0/threaded">20070209 XSS in communityserver !</ref><ref source="BID" url="http://www.securityfocus.com/bid/22529">22529</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32444">
communityserver-searchresults-xss(32444)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2241">2241</ref></refs><vuln_soft><prod name="Community Server" vendor="CommunityServer.org"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-02-14" name="CVE-2007-0926" published="2007-02-14" seq="2007-0926" severity="High" type="CVE"><desc><descript source="cve">The dologin function in guestbook.php in KvGuestbook 1.0 Beta allows remote attackers to gain administrative privileges, probably via modified $mysql[&apos;pass&apos;] and $gbpass variables.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/459799/100/0/threaded">20070211 KvGuestbook Remote Add Admin Exploit</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2246">2246</ref></refs><vuln_soft><prod name="KvGuestbook" vendor="KvGuestbook"><vers num="1.0 Beta"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-02-14" name="CVE-2007-0927" published="2007-02-14" seq="2007-0927" severity="High" type="CVE"><desc><descript source="cve">Heap-based buffer overflow in uTorrent 1.6 allows remote attackers to execute arbitrary code via a torrent file with a crafted announce header.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref source="" url="http://www.milw0rm.com/exploits/3296"></ref><ref source="BID" url="http://www.securityfocus.com/bid/22530">22530</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/460346/100/0/threaded">

20070216 utorrent issue?</ref><ref source="MILW0RM" url="http://milw0rm.com/exploits/3296">
3296</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0571">
ADV-2007-0571</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017648">
1017648</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24130">
24130</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32455">
utorrent-torrent-bo(32455)</ref><ref source="OSVDB" url="http://www.osvdb.org/33180">33180</ref></refs><vuln_soft><prod name="uTorrent" vendor="uTorrent"><vers num="1.6"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0" modified="2007-02-14" name="CVE-2007-0928" published="2007-02-14" seq="2007-0928" severity="Medium" type="CVE"><desc><descript source="cve">Virtual Calendar stores sensitive information under the web root with insufficient access control, which allows remote attackers to download an encoded password via a direct request for pwd.txt.</descript></desc><loss_types><conf/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/459844/100/0/threaded">20070210 Virtual Calendar &lt;= (pwd.txt) Remote Password Disclosur Vulnerability</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24125">
24125</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32446">
virtualcalendar-pwd-information-disclosure(32446)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2240">2240</ref></refs><vuln_soft><prod name="Virtual Calendar" vendor="Virtual Calendar"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0" modified="2007-02-14" name="CVE-2007-0929" published="2007-02-14" seq="2007-0929" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in php rrd browser before 0.2.1 allows remote attackers to read arbitrary files via &quot;..&quot; sequences in the p parameter.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/459804/100/0/threaded">20070211 Arbitrary file disclosure vulnerability in php rrd browser &lt; 0.2.1 (prb)</ref><ref patch="1" source="" url="http://sourceforge.net/project/shownotes.php?group_id=176562&amp;release_id=485414"></ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32425">prb-url-file-disclosure(32425)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2245">2245</ref></refs><vuln_soft><prod name="PHP RRD Browser" vendor="Guillaume Fontaine"><vers num="0.2.0" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-02-14" name="CVE-2007-0930" published="2007-02-14" seq="2007-0930" severity="High" type="CVE"><desc><descript source="cve">Variable extract vulnerability in Apache Stats before 0.0.3beta allows attackers to modify arbitrary variables and conduct attacks via unknown vectors involving the use of PHP&apos;s extract function.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref patch="1" source="" url="http://sourceforge.net/forum/forum.php?forum_id=660919"></ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/22388">22388</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0559">ADV-2007-0559</ref></refs><vuln_soft><prod name="Apache Stats" vendor="Apache Stats"><vers num="0.0.2 Beta"/><vers num="0.0.1 Beta"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-08-03" name="CVE-2007-0931" published="2007-02-14" seq="2007-0931" severity="High" type="CVE"><desc><descript source="cve">Heap-based buffer overflow in the management interfaces in (1) Aruba Mobility Controllers 200, 800, 2400, and 6000 and (2) Alcatel-Lucent OmniAccess Wireless 43xx and 6000 allows remote attackers to cause a denial of service (process crash) and possibly execute arbitrary code via long credential strings.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/459928/100/0/threaded">20070213 Aruba Mobility Controller Management Buffer Overflow</ref><ref adv="1" source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2007-February/052380.html">20070213 Aruba Mobility Controller Management Buffer Overflow</ref><ref adv="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/319913">VU#319913</ref><ref source="BID" url="http://www.securityfocus.com/bid/22538">22538</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24144">24144</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32459">aruba-management-interface-bo(32459)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2244">2244</ref></refs><vuln_soft><prod name="Mobility Controller" vendor="Aruba"><vers num="200"/><vers num="800"/><vers num="2400"/><vers num="6000"/></prod><prod name="OmniAccess Wireless" vendor="Alcatel-Lucent"><vers num="43xx"/><vers num="6000"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-08-03" name="CVE-2007-0932" published="2007-02-14" seq="2007-0932" severity="High" type="CVE"><desc><descript source="cve">The (1) Aruba Mobility Controllers 200, 600, 2400, and 6000 and (2) Alcatel-Lucent OmniAccess Wireless 43xx and 6000 do not properly implement authentication and privilege assignment for the guest account, which allows remote attackers to access administrative interfaces or the WLAN.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><config/></vuln_types><range><network/></range><refs><ref adv="1" source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2007-February/052382.html">20070213 Aruba Networks - Unauthorized Administrative and WLAN Access through Guest Account</ref><ref adv="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/613833">VU#613833</ref><ref source="BID" url="http://www.securityfocus.com/bid/22538">22538</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24144">24144</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32461">aruba-guestaccount-privilege-escalation(32461)</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/459927/100/0/threaded">20070213 Aruba Networks - Unauthorized Administrative and WLAN Access through Guest Account</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2243">2243</ref></refs><vuln_soft><prod name="Mobility Controller" vendor="Aruba"><vers num="200"/><vers num="800"/><vers num="2400"/><vers num="6000"/></prod><prod name="OmniAccess Wireless" vendor="Alcatel-Lucent"><vers num="43xx"/><vers num="6000"/></prod></vuln_soft></entry><entry CVSS_base_score="7.8" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.9" CVSS_score="7.8" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_version="2.0" modified="2007-06-06" name="CVE-2007-0933" published="2007-06-05" seq="2007-0933" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in the wireless driver 6.0.0.18 for D-Link DWL-G650+ (Rev. A1) on Windows XP allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a beacon frame with a long TIM Information Element.</descript></desc><loss_types><avail/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref source="" url="http://www.blackhat.com/presentations/bh-europe-07/Butti/Presentation/bh-eu-07-Butti.pdf"></ref><ref source="BID" url="http://www.securityfocus.com/bid/24438">24438</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25602">25602</ref></refs><vuln_soft><prod name="Windows XP" vendor="Microsoft"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" CVSS_score="9.3" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-06-13" name="CVE-2007-0934" published="2007-06-12" seq="2007-0934" severity="High" type="CVE"><desc><descript source="cve">Unspecified vulnerability in Microsoft Visio 2002 allows remote user-assisted attackers to execute arbitrary code via a Visio (.VSD, VSS, .VST) file with a crafted version number that triggers memory corruption.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><range><network/><user_init/></range><refs><ref adv="1" source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms07-030.mspx">MS07-030</ref><ref source="HP" url="http://www.securityfocus.com/archive/1/archive/1/471947/100/0/threaded">HPSBST02231</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA07-163A.html">TA07-163A</ref><ref source="BID" url="http://www.securityfocus.com/bid/24349">24349</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/2150">ADV-2007-2150</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1925">oval:org.mitre.oval:def:1925</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1018227">1018227</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25619">25619</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/34607">visio-version-code-execution(34607)</ref></refs><vuln_soft><prod name="Visio" vendor="Microsoft"><vers num="2002"/></prod></vuln_soft></entry><entry CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" CVSS_score="9.3" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-06-13" name="CVE-2007-0936" published="2007-06-12" seq="2007-0936" severity="High" type="CVE"><desc><descript source="cve">Multiple unspecified vulnerabilities in Microsoft Visio 2002 allow remote user-assisted attackers to execute arbitrary code via a Visio (.VSD, VSS, .VST) file with a crafted packed object that triggers memory corruption, aka &quot;Visio Document Packaging Vulnerability.&quot;</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><range><network/><user_init/></range><refs><ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms07-030.mspx">MS07-030</ref><ref source="HP" url="http://www.securityfocus.com/archive/1/archive/1/471947/100/0/threaded">HPSBST02231</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA07-163A.html">TA07-163A</ref><ref source="BID" url="http://www.securityfocus.com/bid/24384">24384</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/2150">ADV-2007-2150</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1369">oval:org.mitre.oval:def:1369</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1018227">1018227</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25619">25619</ref></refs><vuln_soft><prod name="Office" vendor="Microsoft"><vers num="2003"/></prod><prod name="Visio" vendor="Microsoft"><vers num="2002 SP2"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-04-11" name="CVE-2007-0938" published="2007-04-10" seq="2007-0938" severity="High" type="CVE"><desc><descript source="cve">Microsoft Content Management Server (MCMS) 2001 SP1 and 2002 SP2 does not properly handle certain characters in a crafted HTTP GET request, which allows remote attackers to execute arbitrary code, aka the &quot;CMS Memory Corruption Vulnerability.&quot;</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms07-018.mspx">MS07-018</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/434137">
VU#434137</ref><ref source="BID" url="http://www.securityfocus.com/bid/22861">
22861</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017894">
1017894</ref><ref source="OSVDB" url="http://www.osvdb.org/34006">
34006</ref><ref source="HP" url="http://www.securityfocus.com/archive/1/archive/1/466331/100/200/threaded">

HPSBST02208</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1322">ADV-2007-1322</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2001">oval:org.mitre.oval:def:2001</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24819">24819</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32736">mcms-http-get-code-execution(32736)</ref></refs><vuln_soft><prod name="Content Management Server" vendor="Microsoft"><vers num="2001 SP1"/><vers num="2002 SP2"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" modified="2007-08-02" name="CVE-2007-0939" published="2007-04-10" seq="2007-0939" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in Microsoft Content Management Server (MCMS) 2001 SP1 and 2002 SP2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors involving HTML redirection queries, aka &quot;Cross-site Scripting and Spoofing Vulnerability.&quot;</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" patch="1" source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms07-018.mspx">MS07-018</ref><ref source="BID" url="http://www.securityfocus.com/bid/22860">22860</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017894">1017894</ref><ref source="HP" url="http://www.securityfocus.com/archive/1/archive/1/466331/100/200/threaded">HPSBST02208</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1322">ADV-2007-1322</ref><ref source="OSVDB" url="http://www.osvdb.org/34007">34007</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1575">oval:org.mitre.oval:def:1575</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24819">24819</ref></refs><vuln_soft><prod name="Content Management Server" vendor="Microsoft"><vers num="2001 SP1"/><vers num="2002 SP2"/></prod></vuln_soft></entry><entry CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" CVSS_score="9.3" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-05-14" name="CVE-2007-0940" published="2007-05-08" seq="2007-0940" severity="High" type="CVE"><desc><descript source="cve">Unspecified vulnerability in the Cryptographic API Component Object Model Certificates ActiveX control (CAPICOM.dll) in Microsoft CAPICOM and BizTalk Server 2004 SP1 and SP2 allows remote attackers to execute arbitrary code via unspecified vectors, aka the &quot;CAPICOM.Certificates Vulnerability.&quot;</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms07-028.mspx">MS07-028</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/866305">
VU#866305</ref><ref source="BID" url="http://www.securityfocus.com/bid/23782">
23782</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1018016">
1018016</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1018017">
1018017</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1713">
ADV-2007-1713</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25185">
25185</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32739">
ms-capicom-code-execution(32739)</ref><ref source="HP" url="http://www.securityfocus.com/archive/1/archive/1/468871/100/200/threaded">HPSBST02214</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA07-128A.html">TA07-128A</ref><ref source="OSVDB" url="http://www.osvdb.org/34397">34397</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1670">oval:org.mitre.oval:def:1670</ref></refs><vuln_soft><prod name="CAPICOM" vendor="Microsoft"><vers num=""/></prod><prod name="BizTalk Server" vendor="Microsoft"><vers num="2004 SP1"/><vers num="2004 SP2"/></prod></vuln_soft></entry><entry CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" CVSS_score="9.3" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-12-31" name="CVE-2007-0942" published="2007-05-08" seq="2007-0942" severity="High" type="CVE"><desc><descript source="cve">Microsoft Internet Explorer 5.01 SP4 on Windows 2000 SP4; 6 SP1 on Windows 2000 SP4; 6 and 7 on Windows XP SP2, or Windows Server 2003 SP1 or SP2; and possibly 7 on Windows Vista does not properly &quot;instantiate certain COM objects as ActiveX controls,&quot; which allows remote attackers to execute arbitrary code via a crafted COM object from chtskdic.dll.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><design/></vuln_types><range><network/><user_init/></range><refs><ref patch="1" source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms07-027.mspx">MS07-027</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1712">ADV-2007-1712</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1018019">1018019</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/23769">23769</ref><ref source="HP" url="http://www.securityfocus.com/archive/1/archive/1/468871/100/200/threaded">HPSBST02214</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA07-128A.html">TA07-128A</ref><ref source="OSVDB" url="http://www.osvdb.org/34399">34399</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1939">oval:org.mitre.oval:def:1939</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33252">ie-chtskdic-com-code-execution(33252)</ref></refs><vuln_soft><prod name="Internet Explorer" vendor="Microsoft"><vers num="5.0.1 SP4"/><vers num="6.0"/><vers num="7.0"/><vers num="6.0 SP1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-12-19" name="CVE-2007-0943" published="2007-08-14" seq="2007-0943" severity="Medium" type="CVE"><desc><descript source="cve">Unspecified vulnerability in Internet Explorer 5.01 and 6 SP1 allows remote attackers to execute arbitrary code via crafted Cascading Style Sheets (CSS) strings that trigger memory corruption during parsing, related to use of out-of-bounds pointers.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><design/></vuln_types><range><network/><user_init/></range><refs><ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms07-045.mspx">MS07-045</ref><ref source="" url="http://www.nsfocus.com/english/homepage/research/0701.htm"></ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA07-226A.html">TA07-226A</ref><ref source="BID" url="http://www.securityfocus.com/bid/25288">25288</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/2869">ADV-2007-2869</ref><ref source="OSVDB" url="http://www.osvdb.org/36397">36397</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1673">oval:org.mitre.oval:def:1673</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1018562">1018562</ref><ref source="SECUNIA" url="http://secunia.com/advisories/26419">26419</ref></refs><vuln_soft><prod name="Internet Explorer" vendor="Microsoft"><vers num="5.01"/><vers num="6.0 SP1"/></prod></vuln_soft></entry><entry CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" CVSS_score="9.3" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-05-10" name="CVE-2007-0944" published="2007-05-08" seq="2007-0944" severity="High" type="CVE"><desc><descript source="cve">Unspecified vulnerability in the CTableCol::OnPropertyChange method in Microsoft Internet Explorer 5.01 SP4 on Windows 2000 SP4; 6 SP1 on Windows 2000 SP4; and 6 on Windows XP SP2, or Windows Server 2003 SP1 or SP2 allows remote attackers to execute arbitrary code by calling deleteCell on a named table row in a named table column, then accessing the column, which causes Internet Explorer to access previously deleted objects, aka the &quot;Uninitialized Memory Corruption Vulnerability.&quot;</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><range><network/><user_init/></range><refs><ref adv="1" source="" url="http://www.zerodayinitiative.com/advisories/ZDI-07-027.html"></ref><ref patch="1" source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms07-027.mspx">MS07-027</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/467989/100/0/threaded">

20070508 ZDI-07-027: Microsoft Internet Explorer Table Column Deletion Memory Corruption Vulnerability</ref><ref source="BID" url="http://www.securityfocus.com/bid/23771">
23771</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1712">
ADV-2007-1712</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1018019">
1018019</ref><ref source="SECUNIA" url="http://secunia.com/advisories/23769">
23769</ref><ref source="HP" url="http://www.securityfocus.com/archive/1/archive/1/468871/100/200/threaded">HPSBST02214</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA07-128A.html">TA07-128A</ref><ref source="OSVDB" url="http://www.osvdb.org/34400">34400</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1722">oval:org.mitre.oval:def:1722</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33253">ie-object-array-code-execution(33253)</ref></refs><vuln_soft><prod name="Internet Explorer" vendor="Microsoft"><vers num="5.01 SP4"/><vers num="6.0 SP1"/><vers num="6.0 SP1"/><vers num="6.0 SP1"/><vers num="6.0 SP1"/></prod></vuln_soft></entry><entry CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" CVSS_score="9.3" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-05-10" name="CVE-2007-0945" published="2007-05-08" seq="2007-0945" severity="High" type="CVE"><desc><descript source="cve">Microsoft Internet Explorer 6 SP1 on Windows 2000 SP4; 6 and 7 on Windows XP SP2, or Windows Server 2003 SP1 or SP2; and 7 on Windows Vista allows remote attackers to execute arbitrary code via certain property methods that may trigger memory corruption, aka &quot;Property Memory Corruption Vulnerability.&quot;</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><range><network/><user_init/></range><refs><ref patch="1" source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms07-027.mspx">MS07-027</ref><ref source="BID" url="http://www.securityfocus.com/bid/23769">
23769</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1712">
ADV-2007-1712</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1018019">
1018019</ref><ref source="SECUNIA" url="http://secunia.com/advisories/23769">
23769</ref><ref source="HP" url="http://www.securityfocus.com/archive/1/archive/1/468871/100/200/threaded">HPSBST02214</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA07-128A.html">TA07-128A</ref><ref source="OSVDB" url="http://www.osvdb.org/34401">34401</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1463">oval:org.mitre.oval:def:1463</ref></refs><vuln_soft><prod name="Internet Explorer" vendor="Microsoft"><vers num="6 SP1"/><vers num="6.0"/><vers num="7.0"/><vers num="6.0"/><vers num="7.0"/><vers num="6.0"/><vers num="7.0"/><vers num="7.0"/></prod></vuln_soft></entry><entry CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" CVSS_score="9.3" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-05-10" name="CVE-2007-0946" published="2007-05-08" seq="2007-0946" severity="High" type="CVE"><desc><descript source="cve">Unspecified vulnerability in Microsoft Internet Explorer 7 on Windows XP SP2, Windows Server 2003 SP1 or SP2, or Windows Vista allows remote attackers to execute arbitrary code via crafted HTML objects, which results in memory corruption, aka the first of two &quot;HTML Objects Memory Corruption Vulnerabilities&quot; and a different issue than CVE-2007-0947.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><range><network/><user_init/></range><refs><ref patch="1" source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms07-027.mspx">MS07-027</ref><ref source="BID" url="http://www.securityfocus.com/bid/23770">
23770</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1712">
ADV-2007-1712</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1018019">
1018019</ref><ref source="SECUNIA" url="http://secunia.com/advisories/23769">
23769</ref><ref source="HP" url="http://www.securityfocus.com/archive/1/archive/1/468871/100/200/threaded">HPSBST02214</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA07-128A.html">TA07-128A</ref><ref source="OSVDB" url="http://www.osvdb.org/34402">34402</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1441">oval:org.mitre.oval:def:1441</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33255">ie-html-memory-code-execution(33255)</ref></refs><vuln_soft><prod name="Internet Explorer" vendor="Microsoft"><vers num="7.0"/><vers num="7.0"/><vers num="7.0"/><vers num="7.0"/></prod></vuln_soft></entry><entry CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" CVSS_score="9.3" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-08-02" name="CVE-2007-0947" published="2007-05-08" seq="2007-0947" severity="High" type="CVE"><desc><descript source="cve">Use-after-free vulnerability in Microsoft Internet Explorer 7 on Windows XP SP2, Windows Server 2003 SP1 or SP2, or Windows Vista allows remote attackers to execute arbitrary code via crafted HTML objects, resulting in accessing deallocated memory of CMarkup objects, aka the second of two &quot;HTML Objects Memory Corruption Vulnerabilities&quot; and a different issue than CVE-2007-0946.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input/><other/></vuln_types><range><network/><user_init/></range><refs><ref patch="1" source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms07-027.mspx">MS07-027</ref><ref adv="1" patch="1" source="" url="http://secunia.com/secunia_research/2007-36/advisory/"></ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/23772">23772</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1712">ADV-2007-1712</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1018019">1018019</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/23769">23769</ref><ref source="HP" url="http://www.securityfocus.com/archive/1/archive/1/468871/100/200/threaded">HPSBST02214</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA07-128A.html">TA07-128A</ref><ref source="OSVDB" url="http://www.osvdb.org/34403">34403</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2048">oval:org.mitre.oval:def:2048</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33256">ie-html-memory-code-execution-variant(33256)</ref></refs><vuln_soft><prod name="Internet Explorer" vendor="Microsoft"><vers num="7.0"/><vers num="7.0"/><vers num="7.0"/><vers num="7.0"/><vers num="6"/><vers num="6"/><vers num="6"/></prod></vuln_soft></entry><entry CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" CVSS_score="9.3" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-08-15" name="CVE-2007-0948" published="2007-08-14" seq="2007-0948" severity="High" type="CVE"><desc><descript source="cve">Heap-based buffer overflow in Microsoft Virtual PC 2004 and PC for Mac 7.1 and 7, and Virtual Server 2005 and 2005 R2, allows local guest OS administrators to execute arbitrary code on the host OS via unspecified vectors related to &quot;interaction and initialization of components.&quot;</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><exception/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" patch="1" source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms07-049.mspx">MS07-049</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/25298">25298</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1018567">1018567</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/26444">26444</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA07-226A.html">TA07-226A</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/2873">ADV-2007-2873</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1259">oval:org.mitre.oval:def:1259</ref></refs><vuln_soft><prod name="Virtual Server" vendor="Microsoft"><vers num="2005"/><vers num="2005 r2"/></prod><prod name="Virtual PC for Mac" vendor="Microsoft"><vers num="6.1"/><vers num="7"/></prod><prod name="Virtual PC" vendor="Microsoft"><vers num="2004"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-02-16" name="CVE-2007-0949" published="2007-02-14" seq="2007-0949" severity="High" type="CVE"><desc><descript source="cve">Stack-based buffer overflow in iTinySoft Studio Total Video Player 1.03, and possibly earlier, allows remote attackers to execute arbitrary code via a M3U playlist file that contains a long file name. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref source="BID" url="http://www.securityfocus.com/bid/22553">22553</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/23999">23999</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32479">
totalvideoplayer-m3u-bo(32479)</ref></refs><vuln_soft><prod name="Total Video Player" vendor="iTinySoft Studio"><vers num="1.03" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-02-16" name="CVE-2007-0950" published="2007-02-14" seq="2007-0950" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in listmain.asp in Fullaspsite ASP Hosting Site allows remote attackers to inject arbitrary web script or HTML via the cat parameter.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/459979/100/0/threaded">20070213 Fullaspsite Shop (tr) Xss &amp; SqL Inj. VulnZ.</ref><ref source="BID" url="http://www.securityfocus.com/bid/22545">22545</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32469">
fullaspsite-listmain-xss(32469)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2250">2250</ref></refs><vuln_soft><prod name="ASP Hosting Site" vendor="Fullaspsite"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-02-16" name="CVE-2007-0951" published="2007-02-14" seq="2007-0951" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in listmain.asp in Fullaspsite ASP Hosting Site allows remote attackers to execute arbitrary SQL commands via the cat parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/459979/100/0/threaded">20070213 Fullaspsite Shop (tr) Xss &amp; SqL Inj. VulnZ.</ref><ref source="BID" url="http://www.securityfocus.com/bid/22545">22545</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32470">
fullaspsite-listmain-sql-injection(32470)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2250">2250</ref></refs><vuln_soft><prod name="ASP Hosting Site" vendor="Fullaspsite"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-02-16" name="CVE-2007-0952" published="2007-02-14" seq="2007-0952" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Scriptsez.net Virtual Calendar allow remote attackers to inject arbitrary web script or HTML via the (1) t and (2) yr parameters, and the (3) sho parameter when the m parameter is outside the intended range.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BID" url="http://www.securityfocus.com/bid/22536">22536</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24125">24125</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32448">virtualcalendar-unspecified-xss(32448)</ref></refs><vuln_soft><prod name="Virtual Calendar" vendor="Scriptsez.net"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" modified="2007-02-16" name="CVE-2007-0953" published="2007-02-14" seq="2007-0953" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in search.pl in @Mail 4.61 and earlier allows remote attackers to inject arbitrary web script or HTML via the keywords parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://lostmon.blogspot.com/2007/02/mail-searchpl-keywords-variable-cross.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/22552">22552</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0603">ADV-2007-0603</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24155">24155</ref></refs><vuln_soft><prod name="atmail webmail" vendor="atMail"><vers num="4.61"/><vers num="4.6"/><vers num="4.51"/><vers edition="Windows" num="4.3"/><vers edition="Linux" num="4.11"/><vers edition="Solaris" num="4.11"/><vers edition="FreeBSD" num="4.11"/><vers edition="HP-UX" num="4.11"/><vers edition="Mac OS X" num="4.11"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-02-16" name="CVE-2007-0954" published="2007-02-14" seq="2007-0954" severity="High" type="CVE"><desc><descript source="cve">MOHA Chat 0.1b7 and earlier does not require authentication for use of the plug in API, which has unknown impact and attack vectors.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref patch="1" source="" url="http://mohachat.sourceforge.net/download/release_notes/#0.1b8"></ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0599">ADV-2007-0599</ref></refs><vuln_soft><prod name="MOHA Chat" vendor="secure computing"><vers num="0.1b7" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.8" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.9" CVSS_score="7.8" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_version="2.0" modified="2007-07-24" name="CVE-2007-0955" published="2007-02-14" seq="2007-0955" severity="High" type="CVE"><desc><descript source="cve">The NTLM_UnPack_Type3 function in MENTLM.dll in MailEnable Professional 2.35 and earlier allows remote attackers to cause a denial of service (application crash) via certain base64-encoded data following an AUTHENTICATE NTLM command to the imap port (143/tcp), which results in an out-of-bounds read.</descript></desc><loss_types><avail/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2007-February/052427.html">20071214 MailEnable DoS POC</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24139">24139</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0614">ADV-2007-0614</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32482">mailenable-ntlm-dos(32482)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2249">2249</ref></refs><vuln_soft><prod name="MailEnable Professional" vendor="MailEnable"><vers num="2.35"/><vers num="2.34"/><vers num="2.33"/><vers num="2.32"/><vers num="2.31"/><vers num="2.3"/><vers num="2.29"/><vers num="2.28"/><vers num="2.27"/><vers num="2.26"/><vers num="2.25"/><vers num="2.24"/><vers num="2.23"/><vers num="2.22"/><vers num="2.19"/><vers num="2.2"/><vers num="2.18"/><vers num="2.17"/><vers num="2.16"/><vers num="2.15"/><vers num="2.14"/><vers num="2.13"/><vers num="2.12"/><vers num="2.11"/><vers num="2.1"/><vers num="2.09"/><vers num="2.08"/><vers num="2.07"/><vers num="2.06"/><vers num="2.05"/><vers num="2.04"/><vers num="2.03"/><vers num="2.02"/><vers num="2.01"/><vers num="2"/><vers edition="83" num="1"/><vers num="1.82"/><vers num="1.81"/><vers num="1.8"/><vers num="1.79"/><vers num="1.78"/><vers num="1.77"/><vers num="1.76"/><vers num="1.75"/><vers num="1.74"/><vers num="1.73"/><vers num="1.72"/><vers num="1.71"/><vers num="1.7"/><vers num="1.69"/><vers num="1.68"/><vers num="1.67"/><vers num="1.66"/><vers num="1.65"/><vers num="1.64"/><vers num="1.63"/><vers num="1.62"/><vers num="1.61"/><vers num="1.6"/><vers num="1.54"/><vers num="1.53"/><vers num="1.52"/><vers num="1.51"/><vers num="1.5"/><vers num="1.2a"/><vers num="1.2"/><vers num="1.19"/><vers num="1.18"/><vers num="1.17"/><vers num="1.16"/><vers num="1.15"/><vers num="1.14"/><vers num="1.13"/><vers num="1.12"/><vers num="1.116"/><vers num="1.115"/><vers num="1.114"/><vers num="1.113"/><vers num="1.112"/><vers num="1.111"/><vers num="1.110"/><vers num="1.109"/><vers num="1.108"/><vers num="1.107"/><vers num="1.106"/><vers num="1.105"/><vers num="1.104"/><vers num="1.103"/><vers num="1.102"/><vers num="1.101"/><vers num="1.1"/><vers num="1.0.017"/><vers num="1.0.016"/><vers num="1.0.015"/><vers num="1.0.014"/><vers num="1.0.013"/><vers num="1.0.012"/><vers num="1.0.011"/><vers num="1.0.010"/><vers num="1.0.009"/><vers num="1.0.008"/><vers num="1.0.007"/><vers num="1.0.006"/><vers num="1.0.005"/><vers num="1.0.004"/></prod></vuln_soft></entry><entry CVSS_base_score="7.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="10.0" CVSS_score="7.6" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-04-10" name="CVE-2007-0956" published="2007-04-05" seq="2007-0956" severity="High" type="CVE"><desc><descript source="cve">The telnet daemon (telnetd) in MIT krb5 before 1.6.1 allows remote attackers to bypass authentication and gain system access via a username beginning with a &apos;-&apos; character, a similar issue to CVE-2007-0882.</descript></desc><sols><sol source="nvd">The vendor will address this issue in the upcoming krb5-1.6.1 release.</sol></sols><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" source="" url="http://web.mit.edu/kerberos/www/advisories/MITKRB5-SA-2007-001-telnetd.txt"></ref><ref adv="1" source="DEBIAN" url="http://www.debian.org/security/2007/dsa-1276">DSA-1276</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2007-0095.html">RHSA-2007:0095</ref><ref source="UBUNTU" url="http://www.ubuntu.com/usn/usn-449-1">USN-449-1</ref><ref adv="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/220816">VU#220816</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24706">24706</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24736">24736</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24757">24757</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/464590/100/0/threaded">

20070403 MITKRB5-SA-2007-001: telnetd allows login as arbitrary user [CVE-2007-0956]</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/464666/100/0/threaded">
20070404 rPSA-2007-0063-1 krb5 krb5-server krb5-services krb5-test krb5-workstation</ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200704-02.xml">
GLSA-200704-02</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2007:077">
MDKSA-2007:077</ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20070401-01-P.asc">
20070401-01-P</ref><ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102867-1">
102867</ref><ref source="SUSE" url="http://lists.suse.com/archive/suse-security-announce/2007-Apr/0001.html">
SUSE-SA:2007:025</ref><ref source="BID" url="http://www.securityfocus.com/bid/23281">
23281</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1249">
ADV-2007-1249</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017848">
1017848</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24740">
24740</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24750">
24750</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24755">
24755</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24785">
24785</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24786">
24786</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24817">
24817</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24735">
24735</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33414">
kerberos-telnet-security-bypass(33414)</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1218">
ADV-2007-1218</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:077">MDKSA-2007:077</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA07-093B.html">TA07-093B</ref></refs><vuln_soft><prod name="Kerberos 5" vendor="MIT"><vers num="1.6" prev="1"/></prod><prod name="Linux" vendor="rPath"><vers num="1"/></prod><prod name="Debian Linux" vendor="Debian"><vers num="3.1"/><vers num="4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="9.0" CVSS_exploit_subscore="8.0" CVSS_impact_subscore="10.0" CVSS_score="9.0" CVSS_vector="(AV:N/AC:L/Au:S/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-04-09" name="CVE-2007-0957" published="2007-04-05" seq="2007-0957" severity="High" type="CVE"><desc><descript source="cve">Stack-based buffer overflow in the krb5_klog_syslog function in the kadm5 library, as used by the Kerberos administration daemon (kadmind) and Key Distribution Center (KDC), in MIT krb5 before 1.6.1 allows remote authenticated users to execute arbitrary code and modify the Kerberos key database via crafted arguments, possibly involving certain format string specifiers.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="" url="http://web.mit.edu/kerberos/www/advisories/MITKRB5-SA-2007-002-syslog.txt"></ref><ref adv="1" patch="1" source="DEBIAN" url="http://www.debian.org/security/2007/dsa-1276">DSA-1276</ref><ref adv="1" patch="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2007-0095.html">RHSA-2007:0095</ref><ref adv="1" patch="1" source="UBUNTU" url="http://www.ubuntu.com/usn/usn-449-1">USN-449-1</ref><ref adv="1" patch="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/704024">VU#704024</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/24706">24706</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/24736">24736</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/24757">24757</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/464666/100/0/threaded">

20070404 rPSA-2007-0063-1 krb5 krb5-server krb5-services krb5-test krb5-workstation</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/464592/100/0/threaded">
20070403 MITKRB5-SA-2007-002: KDC, kadmind stack overflow in krb5_klog_syslog [CVE-2007-0957]</ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200704-02.xml">
GLSA-200704-02</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2007:077">
MDKSA-2007:077</ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20070401-01-P.asc">
20070401-01-P</ref><ref source="SUSE" url="http://lists.suse.com/archive/suse-security-announce/2007-Apr/0001.html">
SUSE-SA:2007:025</ref><ref source="BID" url="http://www.securityfocus.com/bid/23285">
23285</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1250">
ADV-2007-1250</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017849">
1017849</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24740">
24740</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24750">
24750</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24785">
24785</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24786">
24786</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24798">
24798</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24817">
24817</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24735">
24735</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33411">
kerberos-krb5klogsyslog-bo(33411)</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1218">
ADV-2007-1218</ref><ref source="" url="http://docs.info.apple.com/article.html?artnum=305391"></ref><ref source="APPLE" url="http://lists.apple.com/archives/Security-announce/2007/Apr/msg00001.html">
APPLE-SA-2007-04-19</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1470">
ADV-2007-1470</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24966">
24966</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:077">MDKSA-2007:077</ref><ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102930-1">102930</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA07-093B.html">TA07-093B</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA07-109A.html">TA07-109A</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1983">ADV-2007-1983</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25464">25464</ref></refs><vuln_soft><prod name="Kerberos 5" vendor="MIT"><vers num="1.6" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0" modified="2007-08-13" name="CVE-2007-0958" published="2007-02-15" seq="2007-0958" severity="Low" type="CVE"><desc><descript source="cve">Linux kernel 2.6.x before 2.6.20 allows local users to read unreadable binaries by using the interpreter (PT_INTERP) functionality and triggering a core dump, a variant of CVE-2004-1073.</descript></desc><loss_types><conf/></loss_types><vuln_types><exception/></vuln_types><range><local/></range><refs><ref adv="1" source="" url="http://www.isec.pl/vulnerabilities/isec-0017-binfmt_elf.txt"></ref><ref source="" url="http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.20"></ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2007:060">MDKSA-2007:060</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2007-0099.html">RHSA-2007:0099</ref><ref source="BID" url="http://www.securityfocus.com/bid/22903">22903</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24482">24482</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2007:078">MDKSA-2007:078</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24777">24777</ref><ref source="UBUNTU" url="http://www.ubuntu.com/usn/usn-451-1">USN-451-1</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24752">24752</ref><ref source="DEBIAN" url="http://www.debian.org/security/2007/dsa-1286">DSA-1286</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/25078">25078</ref><ref source="" url="http://support.avaya.com/elmodocs2/security/ASA-2007-287.htm"></ref><ref source="DEBIAN" url="http://www.debian.org/security/2007/dsa-1304">DSA-1304</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:060">MDKSA-2007:060</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:078">MDKSA-2007:078</ref><ref source="REDHAT" url="http://rhn.redhat.com/errata/RHSA-2007-0488.html">RHSA-2007:0488</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25714">25714</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25838">25838</ref><ref source="SECUNIA" url="http://secunia.com/advisories/26289">26289</ref></refs><vuln_soft><prod name="Kernel" vendor="Linux"><vers num="2.6.20"/><vers num="2.6.19.3"/><vers num="2.6.19.2"/><vers num="2.6.19"/><vers num="2.6.18.6"/><vers num="2.6.18.5"/><vers num="2.6.18.4"/><vers num="2.6.18.3"/><vers num="2.6.18.2"/><vers num="2.6.18.1"/><vers num="2.6.18"/><vers num="2.6.17.14"/><vers num="2.6.17.13"/><vers num="2.6.17.12"/><vers num="2.6.17.11"/><vers num="2.6.17.10"/><vers num="2.6.17.9"/><vers num="2.6.17.8"/><vers num="2.6.17.7"/><vers num="2.6.17.6"/><vers num="2.6.17.5"/><vers num="2.6.17.4"/><vers num="2.6.17.3"/><vers num="2.6.17.2"/><vers num="2.6.17.1"/><vers num="2.6.17"/><vers num="2.6.16.41"/><vers num="2.6.16.40"/><vers num="2.6.16.39"/><vers num="2.6.16.38"/><vers num="2.6.16.37"/><vers num="2.6.16.36"/><vers num="2.6.16.35"/><vers num="2.6.16.34"/><vers num="2.6.16.33"/><vers num="2.6.16.32"/><vers num="2.6.16.31"/><vers num="2.6.16.30"/><vers num="2.6.16.29"/><vers num="2.6.16.28"/><vers num="2.6.16.27"/><vers num="2.6.16.26"/><vers num="2.6.16.25"/><vers num="2.6.16.24"/><vers num="2.6.16.23"/><vers num="2.6.16.22"/><vers num="2.6.16.21"/><vers num="2.6.16.20"/><vers num="2.6.16.19"/><vers num="2.6.16.18"/><vers num="2.6.16.17"/><vers num="2.6.16.16"/><vers num="2.6.16.15"/><vers num="2.6.16.14"/><vers num="2.6.16.13"/><vers num="2.6.16.12"/><vers num="2.6.16.11"/><vers num="2.6.16.10"/><vers num="2.6.16.9"/><vers num="2.6.16.8"/><vers num="2.6.16.7"/><vers num="2.6.16.6"/><vers num="2.6.16.5"/><vers num="2.6.16.4"/><vers num="2.6.16.3"/><vers num="2.6.16.2"/><vers num="2.6.16.1"/><vers num="2.6.16"/><vers num="2.6.15.7"/><vers num="2.6.15.6"/><vers num="2.6.15.5"/><vers num="2.6.15.4"/><vers num="2.6.15.3"/><vers num="2.6.15.2"/><vers num="2.6.15.1"/><vers num="2.6.15"/><vers num="2.6.14.7"/><vers num="2.6.14.6"/><vers num="2.6.14.5"/><vers num="2.6.14.4"/><vers num="2.6.14.3"/><vers num="2.6.14.2"/><vers num="2.6.14.1"/><vers num="2.6.14"/><vers num="2.6.13.5"/><vers num="2.6.13.4"/><vers num="2.6.13.3"/><vers num="2.6.13.2"/><vers num="2.6.13.1"/><vers num="2.6.13"/><vers num="2.6.12.6"/><vers num="2.6.12.5"/><vers num="2.6.12.4"/><vers num="2.6.12.3"/><vers num="2.6.12.2"/><vers num="2.6.12.1"/><vers num="2.6.12"/><vers num="2.6.11.12"/><vers num="2.6.11.11"/><vers num="2.6.11.10"/><vers num="2.6.11.9"/><vers num="2.6.11.8"/><vers num="2.6.11.7"/><vers num="2.6.11.6"/><vers num="2.6.11.5"/><vers num="2.6.11.4"/><vers num="2.6.11.3"/><vers num="2.6.11.2"/><vers num="2.6.11.1"/><vers num="2.6.11"/><vers num="2.6.10"/><vers edition="2.6.20" num="2.6.9"/><vers num="2.6.8.1"/><vers num="2.6.8"/><vers num="2.6.7"/><vers num="2.6.6"/><vers num="2.6.5"/><vers num="2.6.4"/><vers num="2.6.3"/><vers num="2.6.2"/><vers num="2.6.1"/><vers num="2.6.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.8" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.9" CVSS_score="7.8" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_version="2.0" modified="2007-02-19" name="CVE-2007-0959" published="2007-02-15" seq="2007-0959" severity="High" type="CVE"><desc><descript source="cve">Cisco PIX 500 and ASA 5500 Series Security Appliances 7.2.2, when configured to inspect certain TCP-based protocols, allows remote attackers to cause a denial of service (device reboot) via malformed TCP packets.</descript></desc><loss_types><avail/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref source="CISCO" url="http://www.cisco.com/en/US/products/products_security_advisory09186a00807e2484.shtml">20070214 Multiple Vulnerabilities in Cisco PIX and ASA Appliances</ref><ref source="BID" url="http://www.securityfocus.com/bid/22562">22562</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0608">ADV-2007-0608</ref><ref patch="1" source="SECTRACK" url="http://www.securitytracker.com/id?1017651">1017651</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24160">24160</ref><ref source="BID" url="http://www.securityfocus.com/bid/22561">
22561</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017652">
1017652</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32488">
cisco-pix-asa-tcp-dos(32488)</ref></refs><vuln_soft><prod name="PIX 500" vendor="Cisco"><vers num="7.2.2"/></prod><prod name="ASA 5500" vendor="Cisco"><vers num="7.2.2"/></prod></vuln_soft></entry><entry CVSS_base_score="9.0" CVSS_exploit_subscore="8.0" CVSS_impact_subscore="10.0" CVSS_score="9.0" CVSS_vector="(AV:N/AC:L/Au:S/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-02-19" name="CVE-2007-0960" published="2007-02-15" seq="2007-0960" severity="High" type="CVE"><desc><descript source="cve">Unspecified vulnerability in Cisco PIX 500 and ASA 5500 Series Security Appliances 7.2.2, when configured to use the LOCAL authentication method, allows remote authenticated users to gain privileges via unspecified vectors.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><config/></vuln_types><range><network/></range><refs><ref source="CISCO" url="http://www.cisco.com/en/US/products/products_security_advisory09186a00807e2484.shtml">20070214 Multiple Vulnerabilities in Cisco PIX and ASA Appliances</ref><ref source="BID" url="http://www.securityfocus.com/bid/22562">22562</ref><ref patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0608">ADV-2007-0608</ref><ref patch="1" source="SECTRACK" url="http://www.securitytracker.com/id?1017651">1017651</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24160">24160</ref><ref source="BID" url="http://www.securityfocus.com/bid/22561">
22561</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017652">
1017652</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24179">
24179</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32489">
cisco-pix-asa-local-privilege-escalation(32489)</ref></refs><vuln_soft><prod name="PIX 500" vendor="Cisco"><vers num="7.2.2"/></prod><prod name="ASA 5500" vendor="Cisco"><vers num="7.2.2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.8" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.9" CVSS_score="7.8" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_version="2.0" modified="2007-02-19" name="CVE-2007-0961" published="2007-02-15" seq="2007-0961" severity="High" type="CVE"><desc><descript source="cve">Cisco PIX 500 and ASA 5500 Series Security Appliances 6.x before 6.3(5.115), 7.0 before 7.0(5.2), and 7.1 before 7.1(2.5), and the FWSM 3.x before 3.1(3.24), when the &quot;inspect sip&quot; option is enabled, allows remote attackers to cause a denial of service (device reboot) via malformed SIP packets.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="CISCO" url="http://www.cisco.com/en/US/products/products_security_advisory09186a00807e2484.shtml">20070214 Multiple Vulnerabilities in Cisco PIX and ASA Appliances</ref><ref adv="1" patch="1" source="CISCO" url="http://www.cisco.com/en/US/products/products_security_advisory09186a00807e2481.shtml">20070214 Multiple Vulnerabilities in Firewall Services Module</ref><ref source="BID" url="http://www.securityfocus.com/bid/22562">22562</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0608">ADV-2007-0608</ref><ref patch="1" source="SECTRACK" url="http://securitytracker.com/id?1017651">1017651</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24160">24160</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/24180">24180</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/430969">
VU#430969</ref><ref source="BID" url="http://www.securityfocus.com/bid/22561">
22561</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017652">
1017652</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24179">
24179</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32487">
cisco-pix-asa-sip-dos(32487)</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32501">
cisco-fwsm-sip-dos(32501)</ref></refs><vuln_soft><prod name="PIX 500" vendor="Cisco"><vers num="7.2"/><vers num="7.1"/><vers num="7.0"/><vers num="6.3"/></prod><prod name="ASA 5500" vendor="Cisco"><vers num="7.2"/><vers num="7.1"/><vers num="7.0"/><vers num="6.3"/></prod></vuln_soft></entry><entry CVSS_base_score="7.8" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.9" CVSS_score="7.8" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_version="2.0" modified="2007-02-19" name="CVE-2007-0962" published="2007-02-15" seq="2007-0962" severity="High" type="CVE"><desc><descript source="cve">Cisco PIX 500 and ASA 5500 Series Security Appliances 7.0 before 7.0(4.14) and 7.1 before 7.1(2.1), and the FWSM 2.x before 2.3(4.12) and 3.x before 3.1(3.24), when &quot;inspect http&quot; is enabled, allows remote attackers to cause a denial of service (device reboot) via malformed HTTP traffic.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="CISCO" url="http://www.cisco.com/en/US/products/products_security_advisory09186a00807e2484.shtml">20070214 Multiple Vulnerabilities in Cisco PIX and ASA Appliances</ref><ref adv="1" patch="1" source="CISCO" url="http://www.cisco.com/en/US/products/products_security_advisory09186a00807e2481.shtml">20070214 Multiple Vulnerabilities in Firewall Services Module</ref><ref source="BID" url="http://www.securityfocus.com/bid/22562">22562</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0608">ADV-2007-0608</ref><ref patch="1" source="SECTRACK" url="http://securitytracker.com/id?1017651">1017651</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24160">24160</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/24180">24180</ref><ref source="BID" url="http://www.securityfocus.com/bid/22561">
22561</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017652">
1017652</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32486">
cisco-pix-asa-http-dos(32486)</ref></refs><vuln_soft><prod name="PIX 500" vendor="Cisco"><vers num="7.1"/><vers num="7.0"/></prod><prod name="FWSM" vendor="Cisco"><vers num="2.3"/><vers num="3.1"/></prod><prod name="ASA 5500" vendor="Cisco"><vers num="7.1"/><vers num="7.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.8" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.9" CVSS_score="7.8" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_version="2.0" modified="2007-02-19" name="CVE-2007-0963" published="2007-02-15" seq="2007-0963" severity="High" type="CVE"><desc><descript source="cve">Unspecified vulnerability in Cisco Firewall Services Module (FWSM) 3.x before 3.1(3.3), when set to log at the &quot;debug&quot; level, allows remote attackers to cause a denial of service (device reboot) by sending packets that are not of a particular protocol such as TCP or UDP, which triggers the reboot during generation of Syslog message 710006.</descript></desc><loss_types><avail/></loss_types><range><network/></range><refs><ref adv="1" patch="1" source="CISCO" url="http://www.cisco.com/en/US/products/products_security_advisory09186a00807e2481.shtml">20070214 Multiple Vulnerabilities in Firewall Services Module</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0609">ADV-2007-0609</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24172">24172</ref><ref source="BID" url="http://www.securityfocus.com/bid/22561">
22561</ref></refs><vuln_soft><prod name="FWSM" vendor="Cisco"><vers num="3.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.4" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="6.9" CVSS_score="5.4" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:N/A:C)" CVSS_version="2.0" modified="2007-02-19" name="CVE-2007-0964" published="2007-02-15" seq="2007-0964" severity="Medium" type="CVE"><desc><descript source="cve">Cisco FWSM 3.x before 3.1(3.18), when authentication is configured to use &quot;aaa authentication match&quot; or &quot;aaa authentication include&quot;, allows remote attackers to cause a denial of service (device reboot) via a malformed HTTPS request.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="CISCO" url="http://www.cisco.com/en/US/products/products_security_advisory09186a00807e2481.shtml">20070214 Multiple Vulnerabilities in Firewall Services Module</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0609">ADV-2007-0609</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24172">24172</ref><ref source="BID" url="http://www.securityfocus.com/bid/22561">
22561</ref></refs><vuln_soft><prod name="FWSM" vendor="Cisco"><vers num="3.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.8" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.9" CVSS_score="7.8" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_version="2.0" modified="2007-02-19" name="CVE-2007-0965" published="2007-02-15" seq="2007-0965" severity="High" type="CVE"><desc><descript source="cve">Cisco FWSM 3.x before 3.1(3.2), when authentication is configured to use &quot;aaa authentication match&quot; or &quot;aaa authentication include&quot;, allows remote attackers to cause a denial of service (device reboot) via a long HTTP request.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="CISCO" url="http://www.cisco.com/en/US/products/products_security_advisory09186a00807e2481.shtml">20070214 Multiple Vulnerabilities in Firewall Services Module</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0609">ADV-2007-0609</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24172">24172</ref><ref source="BID" url="http://www.securityfocus.com/bid/22561">
22561</ref></refs><vuln_soft><prod name="FWSM" vendor="Cisco"><vers num="3.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.8" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.9" CVSS_score="7.8" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_version="2.0" modified="2007-02-19" name="CVE-2007-0966" published="2007-02-15" seq="2007-0966" severity="High" type="CVE"><desc><descript source="cve">Cisco Firewall Services Module (FWSM) 3.x before 3.1(3.11), when the HTTPS server is enabled, allows remote attackers to cause a denial of service (device reboot) via certain HTTPS traffic.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="CISCO" url="http://www.cisco.com/en/US/products/products_security_advisory09186a00807e2481.shtml">20070214 Multiple Vulnerabilities in Firewall Services Module</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0609">ADV-2007-0609</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24172">24172</ref><ref source="BID" url="http://www.securityfocus.com/bid/22561">
22561</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32497">
cisco-fwsm-http-dos(32497)</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32513">
cisco-fwsm-https-server-dos(32513)</ref></refs><vuln_soft><prod name="FWSM" vendor="Cisco"><vers num="3.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.8" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.9" CVSS_score="7.8" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_version="2.0" modified="2007-02-19" name="CVE-2007-0967" published="2007-02-15" seq="2007-0967" severity="High" type="CVE"><desc><descript source="cve">Cisco Firewall Services Module (FWSM) 3.x before 3.1(3.1) allows remote attackers to cause a denial of service (device reboot) via malformed SNMP requests.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="CISCO" url="http://www.cisco.com/en/US/products/products_security_advisory09186a00807e2481.shtml">20070214 Multiple Vulnerabilities in Firewall Services Module</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0609">ADV-2007-0609</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24172">24172</ref><ref source="BID" url="http://www.securityfocus.com/bid/22561">
22561</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32515">
cisco-fwsm-snmp-dos(32515)</ref></refs><vuln_soft><prod name="FWSM" vendor="Cisco"><vers num="3.1"/></prod></vuln_soft></entry><entry CVSS_base_score="9.0" CVSS_exploit_subscore="8.0" CVSS_impact_subscore="10.0" CVSS_score="9.0" CVSS_vector="(AV:N/AC:L/Au:S/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-06-27" name="CVE-2007-0968" published="2007-02-15" seq="2007-0968" severity="High" type="CVE"><desc><descript source="cve">Unspecified vulnerability in Cisco Firewall Services Module (FWSM) before 2.3(4.7) and 3.x before 3.1(3.1) causes the access control entries (ACE) in an ACL to be improperly evaluated, which allows remote authenticated users to bypass intended certain ACL protections.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><range><network/></range><refs><ref adv="1" patch="1" source="CISCO" url="http://www.cisco.com/en/US/products/products_security_advisory09186a00807e2481.shtml">20070214 Multiple Vulnerabilities in Firewall Services Module</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0609">ADV-2007-0609</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24172">24172</ref><ref source="BID" url="http://www.securityfocus.com/bid/22561">22561</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017650">1017650</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32521">cisco-fwsm-acl-security-bypass(32521)</ref></refs><vuln_soft><prod name="FWSM" vendor="Cisco"><vers num="2.3"/><vers num="3.1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-02-19" name="CVE-2007-0969" published="2007-02-15" seq="2007-0969" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in WebTester 5.0.20060927 and earlier allow remote attackers to inject arbitrary web script or HTML via unspecified vectors related to POST parameters to multiple files.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/460078/100/0/threaded">20070214 WebTester 5.0.2 sql injection and XSS vulnerabilities</ref><ref source="BID" url="http://www.securityfocus.com/bid/22559">22559</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0633">
ADV-2007-0633</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24157">
24157</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32492">
webtester-post-xss(32492)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2261">2261</ref></refs><vuln_soft><prod name="WebTester" vendor="WebTester"><vers num="5.0 2006-09-27" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-02-19" name="CVE-2007-0970" published="2007-02-15" seq="2007-0970" severity="High" type="CVE"><desc><descript source="cve">Multiple SQL injection vulnerabilities in WebTester 5.0.20060927 and earlier allow remote attackers to execute arbitrary SQL commands via the testID parameter to directions.php, and unspecified parameters to other files that accept GET or POST input.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/460078/100/0/threaded">20070214 WebTester 5.0.2 sql injection and XSS vulnerabilities</ref><ref source="BID" url="http://www.securityfocus.com/bid/22559">22559</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0633">
ADV-2007-0633</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24157">
24157</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32490">
webtester-directions-sql-injection(32490)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2261">2261</ref></refs><vuln_soft><prod name="WebTester" vendor="WebTester"><vers num="5.0 2006-09-27" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-02-19" name="CVE-2007-0971" published="2007-02-15" seq="2007-0971" severity="High" type="CVE"><desc><descript source="cve">Multiple SQL injection vulnerabilities in Jupiter CMS 1.1.5 allow remote attackers to execute arbitrary SQL commands via the Client-IP HTTP header and certain other HTTP headers, which set the ip variable that is used in SQL queries performed by index.php and certain other PHP scripts.  NOTE: the attack vector might involve _SERVER.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/460076/100/0/threaded">20070214 Jupiter CMS 1.1.5 Multiple Vulnerabilities</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/460100/100/0/threaded">20070214 Re: Jupiter CMS 1.1.5 Multiple Vulnerabilities</ref><ref adv="1" source="" url="http://mgsdl.free.fr/advisories/12070214.txt"></ref><ref adv="1" source="" url="http://www.acid-root.new.fr/advisories/12070214.txt"></ref><ref source="" url="http://www.milw0rm.com/exploits/3310"></ref><ref source="BID" url="http://www.securityfocus.com/bid/22560">22560</ref><ref source="MILW0RM" url="http://milw0rm.com/exploits/3310">
3310</ref></refs><vuln_soft><prod name="Jupiter CMS" vendor="Jupiter CMS"><vers num="1.1.5"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-02-20" name="CVE-2007-0972" published="2007-02-15" seq="2007-0972" severity="High" type="CVE"><desc><descript source="cve">Unrestricted file upload vulnerability in modules/emoticons.php in Jupiter CMS 1.1.5 allows remote attackers to upload arbitrary files by modifying the HTTP request to send an image content type, and to omit is_guest and is_user parameters.  NOTE: this issue might be related to CVE-2006-4875.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/460076/100/0/threaded">20070214 Jupiter CMS 1.1.5 Multiple Vulnerabilities</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/460100/100/0/threaded">20070214 Re: Jupiter CMS 1.1.5 Multiple Vulnerabilities</ref><ref adv="1" source="" url="http://mgsdl.free.fr/advisories/12070214.txt"></ref><ref adv="1" source="" url="http://www.acid-root.new.fr/advisories/12070214.txt"></ref><ref source="" url="http://www.milw0rm.com/exploits/3311"></ref><ref source="BID" url="http://www.securityfocus.com/bid/22560">22560</ref><ref source="MILW0RM" url="http://milw0rm.com/exploits/3311">
3311</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32517">
jupitercm-emoticons-file-upload(32517)</ref></refs><vuln_soft><prod name="Jupiter CMS" vendor="Jupiter CMS"><vers num="1.1.5"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-02-19" name="CVE-2007-0973" published="2007-02-15" seq="2007-0973" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in index.php in Jupiter CMS 1.1.5 allow remote attackers to inject arbitrary web script or HTML via the Referer HTTP header and certain other HTTP headers, which are displayed without proper sanitization when an administrator performs a Logged Guest action.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/460076/100/0/threaded">20070214 Jupiter CMS 1.1.5 Multiple Vulnerabilities</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/460100/100/0/threaded">20070214 Re: Jupiter CMS 1.1.5 Multiple Vulnerabilities</ref><ref adv="1" source="" url="http://mgsdl.free.fr/advisories/12070214.txt"></ref><ref adv="1" source="" url="http://www.acid-root.new.fr/advisories/12070214.txt"></ref><ref source="BID" url="http://www.securityfocus.com/bid/22560">22560</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32518">
jupitercm-loggedguests-xss(32518)</ref></refs><vuln_soft><prod name="Jupiter CMS" vendor="Jupiter CMS"><vers num="1.1.5"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-02-19" name="CVE-2007-0974" published="2007-02-15" seq="2007-0974" severity="High" type="CVE"><desc><descript source="cve">Multiple unspecified vulnerabilities in Ian Bezanson DropBox before 0.0.4 beta have unknown impact and attack vectors, possibly related to a variable extraction vulnerability.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref source="" url="http://sourceforge.net/forum/forum.php?forum_id=660819"></ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0598">ADV-2007-0598</ref></refs><vuln_soft><prod name="DropBox" vendor="Ian Bezanson"><vers num="0.0.3 Beta"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0" modified="2007-02-19" name="CVE-2007-0975" published="2007-02-15" seq="2007-0975" severity="Medium" type="CVE"><desc><descript source="cve">Variable extraction vulnerability in Ian Bezanson Apache Stats before 0.0.3 beta allows attackers to overwrite critical variables, with unknown impact, when the extract function is used on the _REQUEST superglobal array.</descript></desc><loss_types><avail/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref patch="1" source="" url="http://sourceforge.net/forum/forum.php?forum_id=660919"></ref><ref patch="1" source="" url="http://superb-east.dl.sourceforge.net/sourceforge/apachestats/apacheStats_0.0.3Beta.tar.bz2"></ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0598">ADV-2007-0598</ref></refs><vuln_soft><prod name="Apache Stats" vendor="Apache Stats"><vers num="0.0.2 Beta"/><vers num="0.0.1 Beta"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-02-19" name="CVE-2007-0976" published="2007-02-15" seq="2007-0976" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in the ActSoft DVD-Tools ActiveX control (dvdtools.ocx) allows remote attackers to execute arbitrary code via a long DVD_TOOLS.OpenDVD property value.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3307">3307</ref><ref source="BID" url="http://www.securityfocus.com/bid/22558">22558</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32529">
dvdtools-dvdtools-bo(32529)</ref><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3610">
3610</ref><ref source="" url="http://www.shinnai.altervista.org/moaxb/20070504/actsoft.txt"></ref><ref source="" url="http://www.shinnai.altervista.org/viewtopic.php?id=41&amp;t_id=30"></ref></refs><vuln_soft><prod name="ActSoft DVD Tools" vendor="ActiveX Soft"><vers num="3.8.5"/></prod></vuln_soft></entry><entry CVSS_base_score="7.1" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.9" CVSS_score="7.1" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:N/A:N)" CVSS_version="2.0" modified="2007-02-19" name="CVE-2007-0977" published="2007-02-15" seq="2007-0977" severity="High" type="CVE"><desc><descript source="cve">IBM Lotus Domino R5 and R6 WebMail, with &quot;Generate HTML for all fields&quot; enabled, stores HTTPPassword hashes from names.nsf in a manner accessible through Readviewentries and OpenDocument requests to the defaultview view, a different vector than CVE-2005-2428.</descript></desc><impacts><impact source="nvd">&quot;Generate HTML for all fields&quot; must be enabled for successful exploitation.</impact></impacts><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3302">3302</ref></refs><vuln_soft><prod name="Lotus Domino" vendor="IBM"><vers num="R5"/><vers num="R6"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-02-19" name="CVE-2007-0978" published="2007-02-15" seq="2007-0978" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in swcons in IBM AIX 5.3 allows local users to gain privileges via long input data.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref source="AIXAPAR" url="http://www-1.ibm.com/support/docview.wss?uid=isg1IY94901">IY94901</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24154">24154</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0617">
ADV-2007-0617</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017656">
1017656</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32508">
aix-swcons-bo(32508)</ref></refs><vuln_soft><prod name="AIX" vendor="IBM"><vers num="5.3"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0" modified="2007-10-24" name="CVE-2007-0979" published="2007-02-15" seq="2007-0979" severity="Medium" type="CVE"><desc><descript source="cve">Unspecified vulnerability in LifeType before 1.1.6, and 1.2 before 1.2-beta2, allows remote attackers to obtain sensitive information (file contents) via a &quot;crafted URL.&quot;</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://www.lifetype.net/blog/lifetype-development-journal/releases"></ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0616">ADV-2007-0616</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24170">24170</ref></refs><vuln_soft><prod name="LifeType" vendor="LifeType"><vers num="1.1.5" prev="1"/><vers num="1.2 Beta 1" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2008-03-03" name="CVE-2007-0980" published="2007-02-15" seq="2007-0980" severity="High" type="CVE"><desc><descript source="cve">Unspecified vulnerability in HP Serviceguard for Linux; packaged for SuSE SLES8 and United Linux 1.0 before SG A.11.15.07, SuSE SLES9 and SLES10 before SG A.11.16.10, and Red Hat Enterprise Linux (RHEL) before SG A.11.16.10; allows remote attackers to obtain unauthorized access via unspecified vectors.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><range><network/></range><refs><ref adv="1" patch="1" source="HP" url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00860750">HBSBGN02189</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24134">24134</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/22574">22574</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0619">ADV-2007-0619</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017655">1017655</ref></refs><vuln_soft><prod name="Serviceguard for Linux" vendor="HP"><vers num="A.11.14.06"/><vers num="A.11.15.07"/><vers num="A.11.16.10"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-08-03" name="CVE-2007-0981" published="2007-02-15" seq="2007-0981" severity="High" type="CVE"><desc><descript source="cve">Mozilla based browsers, including Firefox before 1.5.0.10 and 2.x before 2.0.0.2, and SeaMonkey before 1.0.8, allow remote attackers to bypass the same origin policy, steal cookies, and conduct other attacks by writing a URI with a null byte to the hostname (location.hostname) DOM property, due to interactions with DNS resolver code.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="FULLDISC" url="http://www.securityfocus.com/archive/1/460217/100/0/threaded">20070215 Firefox: serious cookie stealing / same-domain bypass vulnerability</ref><ref source="" url="http://lcamtuf.dione.cc/ffhostname.html"></ref><ref adv="1" source="" url="https://bugzilla.mozilla.org/show_bug.cgi?id=370445"></ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/885753">VU#885753</ref><ref source="BID" url="http://www.securityfocus.com/bid/22566">22566</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1017654">1017654</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/461336/100/0/threaded">20070226 rPSA-2007-0040-1 firefox</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/461809/100/0/threaded">20070303 rPSA-2007-0040-3 firefox thunderbird</ref><ref source="" url="http://www.mozilla.org/security/announce/2007/mfsa2007-07.html"></ref><ref source="" url="https://issues.rpath.com/browse/RPL-1081"></ref><ref source="" url="https://issues.rpath.com/browse/RPL-1103"></ref><ref source="FEDORA" url="http://fedoranews.org/cms/node/2713">FEDORA-2007-281</ref><ref source="FEDORA" url="http://fedoranews.org/cms/node/2728">FEDORA-2007-293</ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200703-04.xml">GLSA-200703-04</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200703-08.xml">GLSA-200703-08</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2007:050">MDKSA-2007:050</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2007-0079.html">RHSA-2007:0079</ref><ref source="REDHAT" url="http://rhn.redhat.com/errata/RHSA-2007-0077.html">RHSA-2007:0077</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2007-0078.html">RHSA-2007:0078</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2007-0097.html">RHSA-2007:0097</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2007-0108.html">RHSA-2007:0108</ref><ref source="SUSE" url="http://lists.suse.com/archive/suse-security-announce/2007-Mar/0001.html">SUSE-SA:2007:019</ref><ref source="UBUNTU" url="http://www.ubuntu.com/usn/usn-428-1">USN-428-1</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0624">ADV-2007-0624</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0718">ADV-2007-0718</ref><ref source="OSVDB" url="http://www.osvdb.org/32104">32104</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24175">24175</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24238">24238</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24287">24287</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24290">24290</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24205">24205</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24328">24328</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24333">24333</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24343">24343</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24320">24320</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24293">24293</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24393">24393</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24395">24395</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24384">24384</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24437">24437</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32533">firefox-locationhostname-security-bypass(32533)</ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20070301-01-P.asc">20070301-01-P</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24650">24650</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/460126/100/200/threaded">20070214 Firefox: serious cookie stealing / same-domain bypass vulnerability</ref><ref source="DEBIAN" url="http://www.debian.org/security/2007/dsa-1336">DSA-1336</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:050">MDKSA-2007:050</ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20070202-01-P.asc">20070202-01-P</ref><ref source="SLACKWARE" url="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2007&amp;m=slackware-security.374851">SSA:2007-066-03</ref><ref source="SLACKWARE" url="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2007&amp;m=slackware-security.338131">SSA:2007-066-05</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2007_22_mozilla.html">SUSE-SA:2007:022</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24455">24455</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24457">24457</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24342">24342</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25588">25588</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2262">2262</ref><ref source="HP" url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00771742">HPSBUX02153</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/0083">ADV-2008-0083</ref></refs><vuln_soft><prod name="SeaMonkey" vendor="Mozilla"><vers num="1.0"/><vers num="1.0.1"/><vers num="1.0.2"/><vers num="1.0.3"/><vers num="1.0.4"/><vers num="1.0.5"/><vers num="1.0.6"/><vers num="1.0.7"/></prod><prod name="Firefox" vendor="Mozilla"><vers num="Preview Release"/><vers num="2.0.0.1"/><vers edition="Beta 1" num="2.0"/><vers num="2.0"/><vers num="1.5.8"/><vers num="1.5.7"/><vers num="1.5.6"/><vers num="1.5.5"/><vers num="1.5.4"/><vers num="1.5.3"/><vers num="1.5.2"/><vers num="1.5.1"/><vers num="1.5.0.9"/><vers num="1.5.0.8"/><vers num="1.5.0.7"/><vers num="1.5.0.6"/><vers num="1.5.0.5"/><vers num="1.5.0.4"/><vers num="1.5.0.3"/><vers num="1.5.0.2"/><vers num="1.5.0.1"/><vers edition="Beta 2" num="1.5"/><vers edition="Beta 1" num="1.5"/><vers num="1.5"/><vers num="1.0.8"/><vers num="1.0.7"/><vers edition="Linux" num="1.0.6"/><vers num="1.0.6"/><vers num="1.0.5"/><vers num="1.0.4"/><vers num="1.0.3"/><vers num="1.0.2"/><vers num="1.0.1"/><vers num="1.0"/><vers num="0.9.3"/><vers num="0.9.2"/><vers num="0.9.1"/><vers edition="rc" num="0.9"/><vers num="0.9"/><vers num="0.8"/><vers num="0.10.1"/><vers num="0.10"/><vers edition="RC3" num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" modified="2007-03-08" name="CVE-2007-0982" published="2007-02-16" seq="2007-0982" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in error.php in TaskFreak! 0.5.5 allows remote attackers to inject arbitrary web script or HTML via the tznMessage parameter.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref source="BID" url="http://www.securityfocus.com/bid/22537">22537</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24123">24123</ref><ref source="" url="http://www.taskfreak.com/versions.html"></ref></refs><vuln_soft><prod name="TaskFreak" vendor="TaskFreak"><vers num="0.5.5"/></prod></vuln_soft></entry><entry CVSS_base_score="8.5" CVSS_exploit_subscore="6.8" CVSS_impact_subscore="10.0" CVSS_score="8.5" CVSS_vector="(AV:N/AC:M/Au:S/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-02-21" name="CVE-2007-0983" published="2007-02-16" seq="2007-0983" severity="High" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in _admin/nav.php in AT Contenator 1.0 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the Root_To_Script parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref source="milw0rm" url="http://www.milw0rm.com/exploits/3297">3297</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/32453">atcontenator-nav-file-include(32453)</ref><ref source="MILW0RM" url="http://milw0rm.com/exploits/3297">

3297</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0606">
ADV-2007-0606</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24141">
24141</ref></refs><vuln_soft><prod name="AT Contenator" vendor="Ansatheus"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-08-03" name="CVE-2007-0984" published="2007-02-16" seq="2007-0984" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in admin_poll.asp in PollMentor 2.0 allows remote attackers to execute arbitrary SQL commands via the id parameter to pollmentorres.asp.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="milw0rm" url="http://www.milw0rm.com/exploits/3301">3301</ref><ref source="BID" url="http://www.securityfocus.com/bid/22542">22542</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0601">ADV-2007-0601</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24137">24137</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32456">pollmentor-pollmentorres-sql-injection(32456)</ref></refs><vuln_soft><prod name="Pollmentor" vendor="ASPcode.net"><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2008-03-07" name="CVE-2007-0985" published="2007-02-16" seq="2007-0985" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in nickpage.php in phpCC 4.2 beta and earlier allows remote attackers to execute arbitrary SQL commands via the npid parameter in a sign_gb action.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="Milw0rm" url="http://www.milw0rm.com/exploits/3299">Exploit 3299</ref><ref source="BID" url="http://www.securityfocus.com/bid/22540">22540</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0602">ADV-2007-0602</ref></refs><vuln_soft><prod name="phpCC" vendor="phpCC"><vers num="Beta 4.2" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.1" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="6.4" CVSS_score="5.1" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2008-03-07" name="CVE-2007-0986" published="2007-02-16" seq="2007-0986" severity="Medium" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in index.php in Jupiter CMS 1.1.5, when PHP 5.0.0 or later is used, allows remote attackers to execute arbitrary PHP code via an ftp URL in the n parameter.</descript></desc><impacts><impact source="nvd">Successful exploitation requires that &quot;magic_quotes_gpc&quot; is disabled and that &quot;allow_url_fopen&quot; is enabled.</impact></impacts><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/460076/100/0/threaded">20070214 Jupiter CMS 1.1.5 Multiple Vulnerabilities</ref><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/460100/100/0/threaded">20070214 Re: Jupiter CMS 1.1.5 Multiple Vulnerabilities</ref><ref adv="1" source="" url="http://mgsdl.free.fr/advisories/12070214.txt"></ref><ref adv="1" source="" url="http://www.acid-root.new.fr/advisories/12070214.txt"></ref><ref source="Milw0rm" url="http://www.milw0rm.com/exploits/3309">Exploit 3309</ref><ref source="BID" url="http://www.securityfocus.com/bid/22560">22560</ref><ref source="MILW0RM" url="http://milw0rm.com/exploits/3309">3309</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32519">jupitercm-index-n-file-include(32519)</ref></refs><vuln_soft><prod name="Jupiter CMS" vendor="Jupiter CMS"><vers num="1.1.5"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-02-20" name="CVE-2007-0987" published="2007-02-16" seq="2007-0987" severity="High" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in index.php in Jupiter CMS 1.1.5 allows remote attackers to include and execute arbitrary local files via a .. (dot dot), or an absolute pathname, in the n parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/460076/100/0/threaded">20070214 Jupiter CMS 1.1.5 Multiple Vulnerabilities</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/460100/100/0/threaded">20070214 Re: Jupiter CMS 1.1.5 Multiple Vulnerabilities</ref><ref adv="1" source="" url="http://mgsdl.free.fr/advisories/12070214.txt"></ref><ref adv="1" source="" url="http://www.acid-root.new.fr/advisories/12070214.txt"></ref><ref source="" url="http://www.milw0rm.com/exploits/3309"></ref><ref source="BID" url="http://www.securityfocus.com/bid/22560">22560</ref><ref source="MILW0RM" url="http://milw0rm.com/exploits/3309">
3309</ref></refs><vuln_soft><prod name="Jupiter CMS" vendor="Jupiter CMS"><vers num="1.1.5"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:P)" CVSS_version="2.0" modified="2007-08-03" name="CVE-2007-0988" published="2007-02-20" seq="2007-0988" severity="Medium" type="CVE"><desc><descript source="cve">The zend_hash_init function in PHP 5 before 5.2.1 and PHP 4 before 4.4.5, when running on a 64-bit platform, allows context-dependent attackers to cause a denial of service (infinite loop) by unserializing certain integer expressions, which only cause 32-bit arguments to be used after the check for a negative value, as demonstrated by an &quot;a:2147483649:{&quot; argument.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref source="" url="http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=228858"></ref><ref patch="1" source="" url="http://www.php.net/releases/5_2_1.php"></ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2007-0076.html">RHSA-2007:0076</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24195">24195</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/461462/100/0/threaded">20070227 rPSA-2007-0043-1 php php-mysql php-pgsql</ref><ref source="" url="https://issues.rpath.com/browse/RPL-1088"></ref><ref source="" url="http://support.avaya.com/elmodocs2/security/ASA-2007-101.htm"></ref><ref source="DEBIAN" url="http://www.us.debian.org/security/2007/dsa-1264">DSA-1264</ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200703-21.xml">GLSA-200703-21</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2007:048">MDKSA-2007:048</ref><ref source="OPENPKG" url="http://www.openpkg.com/security/advisories/OpenPKG-SA-2007.010.html">OpenPKG-SA-2007.010</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2007-0081.html">RHSA-2007:0081</ref><ref source="REDHAT" url="http://rhn.redhat.com/errata/RHSA-2007-0089.html">RHSA-2007:0089</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2007-0088.html">RHSA-2007:0088</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2007-0082.html">RHSA-2007:0082</ref><ref source="UBUNTU" url="http://www.ubuntu.com/usn/usn-424-1">USN-424-1</ref><ref source="UBUNTU" url="http://www.ubuntu.com/usn/usn-424-2">USN-424-2</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017671">1017671</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24217">24217</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24248">24248</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24236">24236</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24295">24295</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24322">24322</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24432">24432</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24421">24421</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24606">24606</ref><ref source="" url="http://support.avaya.com/elmodocs2/security/ASA-2007-136.htm"></ref><ref source="SECUNIA" url="http://secunia.com/advisories/24642">24642</ref><ref source="" url="http://www.php-security.org/MOPB/MOPB-05-2007.html"></ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32709">php-zendhashinit-dos(32709)</ref><ref source="HP" url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&amp;cc=us&amp;objectID=c01056506">HPSBMA02215</ref><ref source="HP" url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&amp;cc=us&amp;objectID=c01086137">HPSBTU02232</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:048">MDKSA-2007:048</ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20070201-01-P.asc">20070201-01-P</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2007_32_php.html">SUSE-SA:2007:032</ref><ref source="TRUSTIX" url="http://www.trustix.org/errata/2007/0009/">2007-0009</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1991">ADV-2007-1991</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/2374">ADV-2007-2374</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25056">25056</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25423">25423</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24284">24284</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24419">24419</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25850">25850</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2315">2315</ref></refs><vuln_soft><prod name="PHP" vendor="PHP"><vers num="4.0.0"/><vers num="4.0.1"/><vers num="4.0.1 pl1"/><vers num="4.0.1 pl2"/><vers num="4.0.2"/><vers num="4.0.3"/><vers num="4.0.3 pl1"/><vers num="4.0.4"/><vers num="4.0.4 pl1"/><vers num="4.0.5"/><vers num="4.0.6"/><vers num="4.0.7"/><vers num="4.0.7 RC1"/><vers num="4.0.7 RC2"/><vers num="4.0.7 RC3"/><vers num="4.0.7 RC4"/><vers num="4.1.0"/><vers num="4.1.1"/><vers num="4.1.2"/><vers num="4.2.0"/><vers num="4.2.1"/><vers num="4.2.2"/><vers num="4.2.3"/><vers num="4.3"/><vers num="4.3.1"/><vers num="4.3.10"/><vers num="4.3.11"/><vers num="4.3.2"/><vers num="4.3.3"/><vers num="4.3.4"/><vers num="4.3.5"/><vers num="4.3.6"/><vers num="4.3.7"/><vers num="4.3.8"/><vers num="4.3.9"/><vers num="5.0.1"/><vers num="5.0.2"/><vers num="5.0.3"/><vers num="5.0.4"/><vers num="5.0.5"/><vers num="5.1"/><vers num="5.1.0"/><vers num="5.1.1"/><vers num="5.1.2"/><vers num="5.1.3"/><vers num="5.1.4"/><vers num="5.1.5"/><vers num="5.1.6"/><vers num="5.2.0"/><vers num="5.2.1"/></prod><prod name="Engine" vendor="Zend"><vers num=""/></prod></vuln_soft></entry><entry name="CVE-2007-0993" published="2007-06-05" reject="1" seq="2007-0993" type="CVE"><desc><descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2007-0933.  Reason: This candidate is a duplicate of CVE-2007-0933 due to a typo.  Notes: All CVE users should reference CVE-2007-0933 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</descript></desc><refs/></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2008-04-04" name="CVE-2007-0994" published="2007-03-05" seq="2007-0994" severity="Medium" type="CVE"><desc><descript source="cve">A regression error in Mozilla Firefox 2.x before 2.0.0.2 and 1.x before 1.5.0.10, and SeaMonkey 1.1 before 1.1.1 and 1.0 before 1.0.8, allows remote attackers to execute arbitrary JavaScript as the user via an HTML mail message with a javascript: URI in an (1) img, (2) link, or (3) style tag, which bypasses the access checks and executes code with chrome privileges.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref patch="1" source="" url="http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=230733"></ref><ref source="" url="https://issues.rpath.com/browse/RPL-1103"></ref><ref source="" url="http://www.mozilla.org/security/announce/2007/mfsa2007-09.html"></ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2007-0097.html">RHSA-2007:0097</ref><ref source="SUSE" url="http://lists.suse.com/archive/suse-security-announce/2007-Mar/0001.html">SUSE-SA:2007:019</ref><ref source="BID" url="http://www.securityfocus.com/bid/22826">22826</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0823">ADV-2007-0823</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1017726">1017726</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24395">24395</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24384">24384</ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20070301-01-P.asc">20070301-01-P</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24650">24650</ref><ref source="DEBIAN" url="http://www.debian.org/security/2007/dsa-1336">DSA-1336</ref><ref source="SLACKWARE" url="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2007&amp;m=slackware-security.374851">SSA:2007-066-03</ref><ref source="SLACKWARE" url="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2007&amp;m=slackware-security.338131">SSA:2007-066-05</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2007_22_mozilla.html">SUSE-SA:2007:022</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24455">24455</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24457">24457</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25588">25588</ref><ref source="HP" url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00771742">HPSBUX02153</ref></refs><vuln_soft><prod name="SeaMonkey" vendor="Mozilla"><vers num="1.1" prev="1"/></prod><prod name="Firefox" vendor="Mozilla"><vers num="2.0.0.2" prev="1"/><vers num="1.5.0.10" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" modified="2008-01-07" name="CVE-2007-0995" published="2007-02-26" seq="2007-0995" severity="Medium" type="CVE"><desc><descript source="cve">Mozilla Firefox before 1.5.0.10 and 2.x before 2.0.0.2, and SeaMonkey before 1.0.8 ignores trailing invalid HTML characters in attribute names, which allows remote attackers to bypass content filters that use regular expressions.</descript></desc><loss_types><int/></loss_types><vuln_types><input/><exception/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" patch="1" source="" url="http://www.mozilla.org/security/announce/2007/mfsa2007-02.html"></ref><ref source="" url="http://ha.ckers.org/xss.html#XSS_Non_alpha_non_digit2"></ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/461336/100/0/threaded">20070226 rPSA-2007-0040-1 firefox</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/461809/100/0/threaded">20070303 rPSA-2007-0040-3 firefox thunderbird</ref><ref source="" url="https://issues.rpath.com/browse/RPL-1081"></ref><ref source="" url="https://issues.rpath.com/browse/RPL-1103"></ref><ref source="FEDORA" url="http://fedoranews.org/cms/node/2713">FEDORA-2007-281</ref><ref source="FEDORA" url="http://fedoranews.org/cms/node/2728">FEDORA-2007-293</ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200703-04.xml">GLSA-200703-04</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200703-08.xml">GLSA-200703-08</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2007:050">MDKSA-2007:050</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2007-0079.html">RHSA-2007:0079</ref><ref source="REDHAT" url="http://rhn.redhat.com/errata/RHSA-2007-0077.html">RHSA-2007:0077</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2007-0078.html">RHSA-2007:0078</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2007-0097.html">RHSA-2007:0097</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2007-0108.html">RHSA-2007:0108</ref><ref source="SUSE" url="http://lists.suse.com/archive/suse-security-announce/2007-Mar/0001.html">SUSE-SA:2007:019</ref><ref source="UBUNTU" url="http://www.ubuntu.com/usn/usn-428-1">USN-428-1</ref><ref source="BID" url="http://www.securityfocus.com/bid/22694">22694</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0718">ADV-2007-0718</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017702">1017702</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24238">24238</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24287">24287</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24290">24290</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24205">24205</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24328">24328</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24333">24333</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24343">24343</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24320">24320</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24293">24293</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24393">24393</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24395">24395</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24384">24384</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24437">24437</ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20070301-01-P.asc">20070301-01-P</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24650">24650</ref><ref source="DEBIAN" url="http://www.debian.org/security/2007/dsa-1336">DSA-1336</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:050">MDKSA-2007:050</ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20070202-01-P.asc">20070202-01-P</ref><ref source="SLACKWARE" url="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2007&amp;m=slackware-security.374851">SSA:2007-066-03</ref><ref source="SLACKWARE" url="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2007&amp;m=slackware-security.338131">SSA:2007-066-05</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2007_22_mozilla.html">SUSE-SA:2007:022</ref><ref source="OSVDB" url="http://www.osvdb.org/32111">32111</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24455">24455</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24457">24457</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24342">24342</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25588">25588</ref><ref source="HP" url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00771742">HPSBUX02153</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/0083">ADV-2008-0083</ref></refs><vuln_soft><prod name="SeaMonkey" vendor="Mozilla"><vers num="1.0.7" prev="1"/></prod><prod name="Firefox" vendor="Mozilla"><vers num="1.5.0.10"/><vers num="2.0"/><vers num="2.0.0.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="4.9" CVSS_score="5.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:N)" CVSS_version="2.0" modified="2007-02-27" name="CVE-2007-0996" published="2007-02-26" seq="2007-0996" severity="Medium" type="CVE"><desc><descript source="cve">The child frames in Mozilla Firefox before 1.5.0.10 and 2.x before 2.0.0.2, and SeaMonkey before 1.0.8 inherit the default charset from the parent window, which allows remote attackers to conduct cross-site scripting (XSS) attacks, as demonstrated using the UTF-7 character set.</descript></desc><loss_types><conf/><int/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="" url="http://www.mozilla.org/security/announce/2007/mfsa2007-02.html"></ref><ref adv="1" source="" url="http://www.hardened-php.net/advisory_032007.142.html"></ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2007-0079.html">RHSA-2007:0079</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/461076/100/0/threaded">

20070223 Advisory 03/2007: Multiple Browsers Cross Domain Charset Inheritance Vulnerability</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/461336/100/0/threaded">
20070226 rPSA-2007-0040-1 firefox</ref><ref source="" url="https://issues.rpath.com/browse/RPL-1103"></ref><ref source="FEDORA" url="http://fedoranews.org/cms/node/2713">
FEDORA-2007-281</ref><ref source="FEDORA" url="http://fedoranews.org/cms/node/2728">
FEDORA-2007-293</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2007:050">
MDKSA-2007:050</ref><ref source="REDHAT" url="http://rhn.redhat.com/errata/RHSA-2007-0077.html">
RHSA-2007:0077</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2007-0078.html">
RHSA-2007:0078</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2007-0097.html">
RHSA-2007:0097</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2007-0108.html">
RHSA-2007:0108</ref><ref source="SUSE" url="http://lists.suse.com/archive/suse-security-announce/2007-Mar/0001.html">
SUSE-SA:2007:019</ref><ref source="UBUNTU" url="http://www.ubuntu.com/usn/usn-428-1">
USN-428-1</ref><ref source="BID" url="http://www.securityfocus.com/bid/22694">
22694</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0718">
ADV-2007-0718</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017702">
1017702</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24287">
24287</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24290">
24290</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24205">
24205</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24328">
24328</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24333">
24333</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24343">
24343</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24320">
24320</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24395">
24395</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24384">
24384</ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20070301-01-P.asc">
20070301-01-P</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24650">
24650</ref><ref source="DEBIAN" url="http://www.debian.org/security/2007/dsa-1336">DSA-1336</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:050">MDKSA-2007:050</ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20070202-01-P.asc">20070202-01-P</ref><ref source="SLACKWARE" url="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2007&amp;m=slackware-security.374851">SSA:2007-066-03</ref><ref source="SLACKWARE" url="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2007&amp;m=slackware-security.338131">SSA:2007-066-05</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2007_22_mozilla.html">SUSE-SA:2007:022</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24455">24455</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24457">24457</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24342">24342</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25588">25588</ref><ref source="HP" url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00771742">HPSBUX02153</ref></refs><vuln_soft><prod name="SeaMonkey" vendor="Mozilla"><vers edition="Alpha" num="1.0"/><vers edition="Beta" num="1.0"/><vers edition="dev" num="1.0"/><vers num="1.0"/><vers num="1.0.1"/><vers num="1.0.2"/><vers num="1.0.3"/><vers num="1.0.4"/><vers num="1.0.5"/><vers num="1.0.6"/><vers num="1.0.7"/></prod><prod name="Firefox" vendor="Mozilla"><vers edition="Beta 1" num="1.5"/><vers num="1.5"/><vers edition="Beta 2" num="1.5"/><vers num="1.5.0.1"/><vers num="1.5.0.2"/><vers num="1.5.0.3"/><vers num="1.5.0.4"/><vers num="1.5.0.5"/><vers num="1.5.0.6"/><vers num="1.5.0.7"/><vers num="1.5.0.8"/><vers num="1.5.0.9"/><vers edition="RC2" num="2.0"/><vers num="2.0"/><vers edition="Beta 1" num="2.0"/><vers edition="RC3" num="2.0"/><vers num="2.0.0.1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.9" CVSS_exploit_subscore="3.4" CVSS_impact_subscore="10.0" CVSS_score="6.9" CVSS_vector="(AV:L/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-10-03" name="CVE-2007-0997" published="2007-09-18" seq="2007-0997" severity="Medium" type="CVE"><desc><descript source="cve">Race condition in the tee (sys_tee) system call in the Linux kernel 2.6.17 through 2.6.17.6 might allow local users to cause a denial of service (system crash), obtain sensitive information (kernel memory contents), or gain privileges via unspecified vectors related to a potentially dropped ipipe lock during a race between two pipe readers.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><range><local/></range><refs><ref source="MLIST" url="http://lkml.org/lkml/2006/7/17/140">[linux-kernel] 20060717 [patch 25/45] splice: fix problems with sys_tee()</ref><ref source="" url="http://kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.18"></ref></refs><vuln_soft><prod name="Kernel" vendor="Linux"><vers num="2.6.17"/><vers num="2.6.17 rc1"/><vers num="2.6.17 rc2"/><vers num="2.6.17 rc3"/><vers num="2.6.17 rc4"/><vers num="2.6.17 rc5"/><vers num="2.6.17 rc6"/><vers num="2.6.17.1"/><vers num="2.6.17.2"/><vers num="2.6.17.3"/><vers num="2.6.17.4"/><vers num="2.6.17.5"/><vers num="2.6.17.6"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)" CVSS_version="2.0" modified="2007-04-10" name="CVE-2007-0998" published="2007-03-20" seq="2007-0998" severity="Medium" type="CVE"><desc><descript source="cve">The VNC server implementation in QEMU, as used by Xen and possibly other environments, allows local users of a guest operating system to read arbitrary files on the host operating system via unspecified vectors related to QEMU monitor mode, as demonstrated by mapping files to a CDROM device.  NOTE: some of these details are obtained from third party information.</descript></desc><loss_types><conf/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref patch="1" source="REDHAT" url="http://rhn.redhat.com/errata/RHSA-2007-0114.html">RHSA-2007:0114</ref><ref source="BID" url="http://www.securityfocus.com/bid/22967">22967</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017764">1017764</ref><ref source="FEDORA" url="http://fedoranews.org/cms/node/2803">FEDORA-2007-343</ref><ref source="FEDORA" url="http://fedoranews.org/cms/node/2802">FEDORA-2007-344</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1020">ADV-2007-1020</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1021">ADV-2007-1021</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1019">ADV-2007-1019</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24575">24575</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33085">fedora-xen-qemuvnc-information-disclosure(33085)</ref></refs><vuln_soft><prod name="Qemu" vendor="Xen"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" CVSS_score="9.3" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-03-15" name="CVE-2007-0999" published="2007-03-10" seq="2007-0999" severity="High" type="CVE"><desc><descript source="cve">Format string vulnerability in Ekiga 2.0.3, and probably other versions, allows remote attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2007-1006.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2007:058">MDKSA-2007:058</ref><ref adv="1" source="UBUNTU" url="http://www.ubuntu.com/usn/usn-434-1">USN-434-1</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2007-0087.html">
RHSA-2007:0087</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:058">MDKSA-2007:058</ref></refs><vuln_soft><prod name="Ekiga" vendor="GNOME"><vers num="2.0.3" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-03-13" name="CVE-2007-1000" published="2007-03-12" seq="2007-1000" severity="High" type="CVE"><desc><descript source="cve">The ipv6_getsockopt_sticky function in net/ipv6/ipv6_sockglue.c in the Linux kernel before 2.6.20.2 allows local users to read arbitrary kernel memory via certain getsockopt calls that trigger a NULL dereference.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input/><design/></vuln_types><range><local/></range><refs><ref source="" url="http://bugzilla.kernel.org/show_bug.cgi?id=8134"></ref><ref source="" url="http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.20.2"></ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/22904">22904</ref><ref source="FEDORA" url="http://fedoranews.org/cms/node/2787">
FEDORA-2007-335</ref><ref source="FEDORA" url="http://fedoranews.org/cms/node/2788">
FEDORA-2007-336</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/920689">
VU#920689</ref><ref source="OSVDB" url="http://www.osvdb.org/33025">
33025</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24518">
24518</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2007:078">
MDKSA-2007:078</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24777">
24777</ref><ref source="" url="https://issues.rpath.com/browse/RPL-1153"></ref><ref source="SECUNIA" url="http://secunia.com/advisories/24901">
24901</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2007-0169.html">
RHSA-2007:0169</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25080">
25080</ref><ref source="SUSE" url="http://lists.suse.com/archive/suse-security-announce/2007-May/0001.html">
SUSE-SA:2007:029</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25099">
25099</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/471457">20070615 rPSA-2007-0124-1 kernel xen</ref><ref source="" url="http://www.wslabi.com/wabisabilabi/initPublishedBid.do?"></ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:078">MDKSA-2007:078</ref><ref source="UBUNTU" url="http://www.ubuntu.com/usn/usn-486-1">USN-486-1</ref><ref source="UBUNTU" url="http://www.ubuntu.com/usn/usn-489-1">USN-489-1</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0907">ADV-2007-0907</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25691">25691</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24493">24493</ref><ref source="SECUNIA" url="http://secunia.com/advisories/26133">26133</ref><ref source="SECUNIA" url="http://secunia.com/advisories/26139">26139</ref></refs><vuln_soft><prod name="Kernel" vendor="Linux"><vers num="2.6.20.1" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-05-10" name="CVE-2007-1001" published="2007-04-05" seq="2007-1001" severity="Medium" type="CVE"><desc><descript source="cve">Multiple integer overflows in the (1) createwbmp and (2) readwbmp functions in wbmp.c in the GD library (libgd) in PHP 4.0.0 through 4.4.6 and 5.0.0 through 5.2.1 allow context-dependent attackers to execute arbitrary code via Wireless Bitmap (WBMP) images with large width or height values.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/><user_init/></range><refs><ref source="SECUNIA" url="http://secunia.com/advisories/25151">25151</ref><ref source="" url="http://cvs.php.net/viewvc.cgi/php-src/ext/gd/libgd/wbmp.c?r1=1.2.4.1&amp;r2=1.2.4.1.8.1"></ref><ref source="" url="http://cvs.php.net/viewvc.cgi/php-src/ext/gd/libgd/wbmp.c?revision=1.2.4.1.8.1&amp;view=markup"></ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1269">ADV-2007-1269</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33453">php-gd-overflow(33453)</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/464957/100/0/threaded">20070407 PHP &lt;= 5.2.1 wbmp file handling integer overflow</ref><ref source="BID" url="http://www.securityfocus.com/bid/23357">23357</ref><ref source="" url="http://ifsec.blogspot.com/2007/04/php-521-wbmp-file-handling-integer.html"></ref><ref source="REDHAT" url="http://rhn.redhat.com/errata/RHSA-2007-0155.html">RHSA-2007:0155</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24814">24814</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24924">24924</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/466166/100/0/threaded">20070418 rPSA-2007-0073-1 php php-mysql php-pgsql</ref><ref source="" url="https://issues.rpath.com/browse/RPL-1268"></ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2007-0153.html">RHSA-2007:0153</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2007-0162.html">RHSA-2007:0162</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24965">24965</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24945">24945</ref><ref source="" url="http://us2.php.net/releases/4_4_7.php"></ref><ref source="" url="http://us2.php.net/releases/5_2_2.php"></ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2007:087">
MDKSA-2007:087</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2007:088">
MDKSA-2007:088</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2007:089">
MDKSA-2007:089</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24909">
24909</ref><ref source="" url="http://docs.info.apple.com/article.html?artnum=306172"></ref><ref source="APPLE" url="http://lists.apple.com/archives/security-announce//2007/Jul/msg00004.html">APPLE-SA-2007-07-31</ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200705-19.xml">GLSA-200705-19</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:087">MDKSA-2007:087</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:088">MDKSA-2007:088</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:089">MDKSA-2007:089</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:090">MDKSA-2007:090</ref><ref source="SLACKWARE" url="http://www.slackware.org/security/viewer.php?l=slackware-security&amp;y=2007&amp;m=slackware-security.470053">SSA:2007-127</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2007_32_php.html">SUSE-SA:2007:032</ref><ref source="BID" url="http://www.securityfocus.com/bid/25159">25159</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/2732">ADV-2007-2732</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25056">25056</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25445">25445</ref><ref source="SECUNIA" url="http://secunia.com/advisories/26235">26235</ref></refs><vuln_soft><prod name="PHP" vendor="PHP"><vers num="4.0"/><vers num="4.0 Beta 1"/><vers num="4.0 Beta 2"/><vers num="4.0 Beta 3"/><vers num="4.0 Beta 4"/><vers num="4.0 Beta 4 Patch Level 1"/><vers num="4.0 RC1"/><vers num="4.0 RC2"/><vers num="4.0.0"/><vers num="4.0.1"/><vers num="4.0.1 pl1"/><vers num="4.0.1 pl2"/><vers num="4.0.2"/><vers num="4.0.3"/><vers num="4.0.3 pl1"/><vers num="4.0.4"/><vers num="4.0.4 pl1"/><vers num="4.0.5"/><vers num="4.0.6"/><vers num="4.0.7"/><vers num="4.0.7 RC1"/><vers num="4.0.7 RC2"/><vers num="4.0.7 RC3"/><vers num="4.1.0"/><vers num="4.1.1"/><vers num="4.1.2"/><vers edition="Dev" num="4.2"/><vers num="4.2.0"/><vers num="4.2.1"/><vers num="4.2.2"/><vers num="4.2.3"/><vers num="4.3"/><vers num="4.3.1"/><vers num="4.3.10"/><vers num="4.3.11"/><vers num="4.3.2"/><vers num="4.3.3"/><vers num="4.3.4"/><vers num="4.3.5"/><vers num="4.3.6"/><vers num="4.3.7"/><vers num="4.3.8"/><vers num="4.3.9"/><vers num="4.4.0"/><vers num="4.4.1"/><vers num="4.4.2"/><vers num="4.4.3"/><vers num="4.4.4"/><vers num="4.4.5"/><vers num="4.4.6"/><vers num="5.0 candidate 1"/><vers num="5.0 candidate 2"/><vers num="5.0 candidate 3"/><vers num="5.0.0"/><vers num="5.0.0 Beta1"/><vers num="5.0.0 Beta2"/><vers num="5.0.0 Beta3"/><vers num="5.0.0 Beta4"/><vers num="5.0.0 RC1"/><vers num="5.0.0 RC2"/><vers num="5.0.0 RC3"/><vers num="5.0.1"/><vers num="5.0.2"/><vers num="5.0.3"/><vers num="5.0.4"/><vers num="5.0.5"/><vers num="5.1"/><vers num="5.1.0"/><vers num="5.1.1"/><vers num="5.1.2"/><vers num="5.1.3"/><vers num="5.1.4"/><vers num="5.1.5"/><vers num="5.1.6"/><vers num="5.2.0"/><vers num="5.2.1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-03-23" name="CVE-2007-1002" published="2007-03-21" seq="2007-1002" severity="Medium" type="CVE"><desc><descript source="cve">Format string vulnerability in the write_html function in calendar/gui/e-cal-component-memo-preview.c in Evolution Shared Memo 2.8.2.1, and possibly earlier versions, allows user-assisted remote attackers to execute arbitrary code via format specifiers in the categories of a crafted shared memo.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" source="" url="http://secunia.com/secunia_research/2007-44/advisory/"></ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24234">24234</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33106">evolution-writehtml-format-string(33106)</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017808">
1017808</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24651">
24651</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24668">
24668</ref><ref source="REDHAT" url="https://rhn.redhat.com/errata/RHSA-2007-0158.html">
RHSA-2007:0158</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25102">
25102</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/463406/100/0/threaded">20070321 Secunia Research: Evolution Shared Memo Categories Format StringVulnerability</ref><ref source="DEBIAN" url="http://www.debian.org/security/2007/dsa-1325">DSA-1325</ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200706-02.xml">GLSA-200706-02</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:070">MDKSA-2007:070</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2007_15_sr.html">SUSE-SR:2007:015</ref><ref source="UBUNTU" url="http://www.ubuntu.com/usn/usn-442-1">USN-442-1</ref><ref source="BID" url="http://www.securityfocus.com/bid/23073">23073</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1058">ADV-2007-1058</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25551">25551</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25880">25880</ref></refs><vuln_soft><prod name="Shared Memo" vendor="Evolution"><vers num="2.8.2.1"/></prod></vuln_soft></entry><entry CVSS_base_score="9.0" CVSS_exploit_subscore="8.0" CVSS_impact_subscore="10.0" CVSS_score="9.0" CVSS_vector="(AV:N/AC:L/Au:S/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-04-09" name="CVE-2007-1003" published="2007-04-05" seq="2007-1003" severity="High" type="CVE"><desc><descript source="cve">Integer overflow in ALLOCATE_LOCAL in the ProcXCMiscGetXIDList function in the XC-MISC extension in the X.Org X11 server (xserver) 7.1-1.1.0, and other versions before 20070403, allows remote authenticated users to execute arbitrary code via a large expression, which results in memory corruption.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="IDEFENSE" url="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=503">20070403 Multiple Vendor X Server XC-MISC Extension Memory Corruption Vulnerability</ref><ref source="MLIST" url="http://lists.freedesktop.org/archives/xorg-announce/2007-April/000286.html">[xorg-announce] 20070403 various integer overflow vulnerabilites in xserver, libX11 and libXfont</ref><ref adv="1" patch="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2007-0126.html">RHSA-2007:0126</ref><ref adv="1" patch="1" source="UBUNTU" url="http://www.ubuntu.com/usn/usn-448-1">USN-448-1</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/23284">23284</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1217">ADV-2007-1217</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017857">1017857</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24741">24741</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/24756">24756</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/24770">24770</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/464686/100/0/threaded">
20070404 rPSA-2007-0065-1 freetype xorg-x11 xorg-x11-fonts xorg-x11-tools xorg-x11-xfs</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/464816/100/0/threaded">
20070405 FLEA-2007-0009-1: xorg-x11 freetype</ref><ref source="" url="http://issues.foresightlinux.org/browse/FL-223"></ref><ref source="" url="https://issues.rpath.com/browse/RPL-1213"></ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2007:079">
MDKSA-2007:079</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2007:080">
MDKSA-2007:080</ref><ref source="REDHAT" url="http://rhn.redhat.com/errata/RHSA-2007-0125.html">
RHSA-2007:0125</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24745">
24745</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24758">
24758</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24765">
24765</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24771">
24771</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24772">
24772</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24791">
24791</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33424">
xorg-xcmisc-overflow(33424)</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2007-0127.html">
RHSA-2007:0127</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2007_27_x.html">
SUSE-SA:2007:027</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25004">
25004</ref><ref source="OPENBSD" url="http://www.openbsd.org/errata39.html#021_xorg">
[3.9] 021: SECURITY FIX: April 4, 2007</ref><ref source="OPENBSD" url="http://www.openbsd.org/errata40.html#011_xorg">
[4.0] 011: SECURITY FIX: April 4, 2007</ref><ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102886-1">
102886</ref><ref source="BID" url="http://www.securityfocus.com/bid/23300">
23300</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1548">
ADV-2007-1548</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25006">
25006</ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200705-10.xml">
GLSA-200705-10</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25195">
25195</ref><ref source="" url="http://support.avaya.com/elmodocs2/security/ASA-2007-178.htm"></ref><ref source="SECUNIA" url="http://secunia.com/advisories/25216">
25216</ref><ref source="DEBIAN" url="http://www.debian.org/security/2007/dsa-1294">DSA-1294</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:079">MDKSA-2007:079</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:080">MDKSA-2007:080</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1980">oval:org.mitre.oval:def:1980</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25305">25305</ref><ref source="SUSE" url="http://lists.opensuse.org/opensuse-security-announce/2008-04/msg00005.html">SUSE-SR:2008:008</ref><ref source="SECUNIA" url="http://secunia.com/advisories/29622">29622</ref></refs><vuln_soft><prod name="X11" vendor="X.Org"><vers num="7.1_1.1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" modified="2007-08-03" name="CVE-2007-1004" published="2007-02-19" seq="2007-1004" severity="Medium" type="CVE"><desc><descript source="cve">Mozilla Firefox might allow remote attackers to conduct spoofing and phishing attacks by writing to an about:blank tab and overlaying the location bar.</descript></desc><loss_types><int/></loss_types><vuln_types><access/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/460369/100/0/threaded">20070216 Firefox: about:blank is phisher&apos;s best friend</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/460412/100/0/threaded">20070217 Re: Firefox: about:blank is phisher&apos;s best friend</ref><ref source="BID" url="http://www.securityfocus.com/bid/22601">22601</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32580">firefox-aboutblank-security-bypass(32580)</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/460617/100/0/threaded">20070219 RE: Firefox: about:blank is phisher&apos;s best friend</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24153">24153</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2264">2264</ref></refs><vuln_soft><prod name="Firefox" vendor="Mozilla"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.8" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.9" CVSS_score="7.8" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_version="2.0" discovered="2007-01-16" modified="2007-03-06" name="CVE-2007-1005" published="2007-03-02" seq="2007-1005" severity="High" type="CVE"><desc><descript source="cve">Heap-based buffer overflow in SW3eng.exe in the eID Engine service in CA (formerly Computer Associates) eTrust Intrusion Detection 3.0.5.57 and earlier allows remote attackers to cause a denial of service (application crash) via a long key length value to the remote administration port (9191/tcp).</descript></desc><loss_types><avail/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="IDEFENSE" url="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=484">20070227 Computer Associates eTrust Intrusion Detection Denial of Service Vulnerability</ref><ref adv="1" patch="1" source="" url="http://supportconnectw.ca.com/public/ca_common_docs/eid_secnotice.asp"></ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/22743">22743</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0776">ADV-2007-0776</ref><ref source="OSVDB" url="http://www.osvdb.org/32290">32290</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/24309">24309</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/461567/100/100/threaded">
20070228 [CAID 35112]: CA eTrust Intrusion Detection Denial of Service Vulnerability</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017706">
1017706</ref></refs><vuln_soft><prod name="eTrust Intrusion Detection" vendor="CA"><vers edition="SP1" num="2.0"/><vers edition="SP1" num="3.0"/><vers num="3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-08-03" name="CVE-2007-1006" published="2007-02-19" seq="2007-1006" severity="High" type="CVE"><desc><descript source="cve">Multiple format string vulnerabilities in the gm_main_window_flash_message function in Ekiga before 2.0.5 allow attackers to cause a denial of service and possibly execute arbitrary code via a crafted Q.931 SETUP packet.</descript></desc><sols><sol source="nvd">Update to version 2.0.5.</sol></sols><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref source="SECUNIA" url="http://secunia.com/advisories/24194">24194</ref><ref source="MLIST" url="http://mail.gnome.org/archives/ekiga-list/2007-February/msg00060.html">[Ekiga-list] 20070213 Ekiga 2.0.5 available</ref><ref source="" url="http://labs.musecurity.com/advisories/MU-200702-01.txt"></ref><ref source="" url="http://www.ekiga.org/index.php?rub=10&amp;archive=1"></ref><ref source="DEBIAN" url="http://www.debian.org/security/2007/dsa-1262">DSA-1262</ref><ref source="FEDORA" url="http://fedoranews.org/cms/node/2682">FEDORA-2007-262</ref><ref source="FEDORA" url="http://fedoranews.org/cms/node/2683">FEDORA-2007-263</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:044">MDKSA-2007:044</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2007-0087.html">RHSA-2007:0087</ref><ref source="UBUNTU" url="http://www.ubuntu.com/usn/usn-426-1">USN-426-1</ref><ref source="BID" url="http://www.securityfocus.com/bid/22613">22613</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0655">ADV-2007-0655</ref><ref source="OSVDB" url="http://www.osvdb.org/31939">31939</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017673">1017673</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24228">24228</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24229">24229</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24271">24271</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24379">24379</ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200703-25.xml">GLSA-200703-25</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24680">24680</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2007_9_sr.html">SUSE-SR:2007:009</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25119">25119</ref></refs><vuln_soft><prod name="Ekiga" vendor="Ekiga"><vers num="2.0.4" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-02-21" name="CVE-2007-1007" published="2007-02-20" seq="2007-1007" severity="High" type="CVE"><desc><descript source="cve">Format string vulnerability in GnomeMeeting 1.0.2 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via format strings in the name, which is not properly handled in a call to the gnomemeeting_log_insert function.</descript></desc><impacts><impact source="nvd">Failed exploit attempts will like result in a system level denial-of-service condition.</impact></impacts><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=229266"></ref><ref adv="1" patch="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2007-0086.html">RHSA-2007:0086</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/24185">24185</ref><ref source="DEBIAN" url="http://www.debian.org/security/2007/dsa-1262">
DSA-1262</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2007:045">
MDKSA-2007:045</ref><ref source="UBUNTU" url="http://www.ubuntu.com/usn/usn-426-1">
USN-426-1</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24271">
24271</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24379">
24379</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2007_9_sr.html">
SUSE-SR:2007:009</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25119">
25119</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:045">MDKSA-2007:045</ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20070201-01-P.asc">20070201-01-P</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24284">24284</ref></refs><vuln_soft><prod name="Desktop" vendor="Red Hat"><vers num="3.0"/><vers num="4.0"/></prod><prod name="Enterprise Linux WS" vendor="Red Hat"><vers edition="Workstation" num="3.0"/><vers edition="Workstation" num="4.0"/></prod><prod name="Ekiga" vendor="Ekiga"><vers num="1.0.2"/></prod><prod name="Enterprise Linux ES" vendor="Red Hat"><vers edition="Enterprise Server" num="3.0"/><vers edition="Enterprise Server" num="4.0"/></prod><prod name="Enterprise Linux AS" vendor="Red Hat"><vers edition="Advanced Servers" num="3.0"/><vers edition="Advanced Server" num="4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="2.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="2.9" CVSS_score="2.6" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:N/A:P)" CVSS_version="2.0" modified="2007-02-21" name="CVE-2007-1008" published="2007-02-19" seq="2007-1008" severity="Low" type="CVE"><desc><descript source="cve">Apple iTunes 7.0.2 allows user-assisted remote attackers to cause a denial of service (application crash) via a crafted XML list of radio stations, which results in memory corruption.  NOTE: iTunes retrieves the XML document from a static URL, which requires an attacker to perform DNS spoofing or man-in-the-middle attacks for exploitation.</descript></desc><impacts><impact source="nvd">Successful exploitation requires that an attacker perform some type of DNS spoofing or man-in-the-middle attack prior to launching this attack.</impact></impacts><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/460544/100/0/threaded">20070219 iTunes remote memory corruption vulnerability</ref><ref source="BID" url="http://www.securityfocus.com/bid/22615">22615</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2278">2278</ref></refs><vuln_soft><prod name="iTunes" vendor="Apple"><vers num="7.0.2"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-04-19" name="CVE-2007-1009" published="2007-04-19" seq="2007-1009" severity="Medium" type="CVE"><desc><descript source="cve">Macrovision InstallAnywhere Enterprise before 8.0.1 uses the InstallScript.iap_xml configuration file without integrity protection to verify authorization for installing an application, which allows local users to perform unauthorized installations by removing the (1) password or (2) serial number verification sections from this file.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/466035/100/0/threaded">20070416 SYMSA-2007-003 Macrovision InstallAnywhere Password and Serial Number Bypass</ref><ref adv="1" source="" url="http://www.symantec.com/content/en/us/enterprise/research/SYMSA-2007-003.txt"></ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/22643">22643</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1433">ADV-2007-1433</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2596">2596</ref></refs><vuln_soft><prod name="InstallAnywhere" vendor="Macrovision"><vers edition="Standard" num="8"/><vers edition="Enterprise" num="8"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-02-21" name="CVE-2007-1010" published="2007-02-21" seq="2007-1010" severity="Medium" type="CVE"><desc><descript source="cve">Multiple PHP remote file inclusion vulnerabilities in ZebraFeeds 1.0, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the zf_path parameter to (1) aggregator.php and (2) controller.php in newsfeeds/includes/.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3314">3314</ref><ref patch="1" source="" url="http://cazalet.org/category/zebrafeeds"></ref><ref source="" url="http://cazalet.org/zebrafeeds/forums/viewtopic.php?pid=358"></ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/22576">22576</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0622">ADV-2007-0622</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/24162">24162</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32507">zebrafeeds-zfpath-file-include(32507)</ref></refs><vuln_soft><prod name="ZebraFeeds" vendor="ZebraFeeds"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-02-21" name="CVE-2007-1011" published="2007-02-21" seq="2007-1011" severity="High" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in functions_inc.php in VS-Gastebuch 1.5.3 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the gb_pfad parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://milw0rm.com/exploits/3328"></ref><ref source="BID" url="http://www.securityfocus.com/bid/22605">22605</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0646">ADV-2007-0646</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24182">24182</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32555">
vsgastebuch-functions-file-include(32555)</ref></refs><vuln_soft><prod name="VS-Gastebuch" vendor="VS-Gastebuch"><vers num="1.5.3" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-02-21" name="CVE-2007-1012" published="2007-02-21" seq="2007-1012" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in faq.php in DeskPRO 1.1.0 allows remote attackers to inject arbitrary web script or HTML via the article parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/460200/100/0/threaded">20070214 XSS in [deskpro.com v1.1.0 ]</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32525">deskprocom-faq-xss(32525)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2267">2267</ref></refs><vuln_soft><prod name="DeskPro" vendor="DeskPro"><vers num="1.1 .0"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-02-21" name="CVE-2007-1013" published="2007-02-21" seq="2007-1013" severity="High" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in generate.php in VirtualSystem Htaccess Passwort Generator 1.1 allows remote attackers to execute arbitrary PHP code via a URL in the ht_pfad parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3324">3324</ref><ref source="BID" url="http://www.securityfocus.com/bid/22598">22598</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0643">ADV-2007-0643</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24214">
24214</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32559">
htaccess-generate-file-include(32559)</ref></refs><vuln_soft><prod name="Htaccess Passwort Generator" vendor="VirtualSystem"><vers num="1.1"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-02-22" name="CVE-2007-1014" published="2007-02-21" seq="2007-1014" severity="High" type="CVE"><desc><descript source="cve">Stack-based buffer overflow in VicFTPS before 5.0 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a long CWD command.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3331">3331</ref><ref source="" url="http://vicftps.50webs.com/"></ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/22608">22608</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0648">ADV-2007-0648</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/24161">24161</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32557">
vicftps-cwd-bo(32557)</ref></refs><vuln_soft><prod name="VicFTPS" vendor="VicFTPS"><vers num="3.9"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-02-21" name="CVE-2007-1015" published="2007-02-21" seq="2007-1015" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in HaberDetay.asp in Aktueldownload Haber script allows remote attackers to execute arbitrary SQL commands via the id parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3318">3318</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0620">ADV-2007-0620</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32527">aktueldownload-haberdetay-sql-injection(32527)</ref></refs><vuln_soft><prod name="Aktueldownload Haber Script" vendor="Aktueldownload"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-02-22" name="CVE-2007-1016" published="2007-02-21" seq="2007-1016" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in Aktueldownload Haber script allows remote attackers to execute arbitrary SQL commands via certain vectors related to the HaberDetay.asp and rss.asp components, and the id and kid parameters.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.  NOTE: the combination of the HaberDetay.asp component and the id parameter is already covered by another February 2007 CVE candidate.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0620">ADV-2007-0620</ref></refs><vuln_soft><prod name="Aktueldownload Haber Script" vendor="Aktueldownload"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" CVSS_score="9.3" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-02-21" name="CVE-2007-1017" published="2007-02-21" seq="2007-1017" severity="High" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in show_news_inc.php in VirtualSystem VS-News-System 1.2.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the newsordner parameter.</descript></desc><impacts><impact source="nvd">Successful exploitation requires that &quot;register_globals&quot; is enabled.</impact></impacts><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3322">3322</ref><ref source="BID" url="http://www.securityfocus.com/bid/22592">22592</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24220">24220</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32544">vsnewssystem-shownewsinc-file-include(32544)</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0649">
ADV-2007-0649</ref></refs><vuln_soft><prod name="VS-News-System" vendor="VirtualSystem"><vers num="1.2.1" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" CVSS_score="9.3" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-02-21" name="CVE-2007-1018" published="2007-02-21" seq="2007-1018" severity="High" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in tpl/header.php in VirtualSystem VS-News-System 1.2.1 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the newsordner parameter.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24220">24220</ref></refs><vuln_soft><prod name="VS-News-System" vendor="VirtualSystem"><vers num="1.2.1" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-02-21" name="CVE-2007-1019" published="2007-02-21" seq="2007-1019" severity="Medium" type="CVE"><desc><descript source="cve">SQL injection vulnerability in news.php in webSPELL 4.01.02, when register_globals is enabled, allows remote attackers to execute arbitrary SQL commands via the showonly parameter to index.php, a different vector than CVE-2006-5388.</descript></desc><impacts><impact source="nvd">Successful exploitation e.g. allows retrieval of password hashes, but requires that &quot;register_globals&quot; is enabled.</impact></impacts><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3325">3325</ref><ref source="BID" url="http://www.securityfocus.com/bid/22541">22541</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24191">24191</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32554">webspell-showonly-sql-injection(32554)</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0650">
ADV-2007-0650</ref></refs><vuln_soft><prod name="webSPELL" vendor="webSPELL"><vers num="4.01.02"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-02-21" name="CVE-2007-1020" published="2007-02-21" seq="2007-1020" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in index.php in CedStat 1.31 allows remote attackers to inject arbitrary web script or HTML via the hier parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/460260/100/0/threaded">20070215 CedStat v1.31 XSS</ref><ref source="" url="http://forums.avenir-geopolitique.net/viewtopic.php?t=2672"></ref><ref source="BID" url="http://www.securityfocus.com/bid/22588">22588</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32537">Cedstat-index-xss(32537)</ref><ref source="BID" url="http://www.securityfocus.com/bid/22653">
22653</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0680">
ADV-2007-0680</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2265">2265</ref></refs><vuln_soft><prod name="CedStat" vendor="CedStat"><vers num="1.31"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-02-21" name="CVE-2007-1021" published="2007-02-21" seq="2007-1021" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in inc_listnews.asp in CodeAvalanche News 1.x allows remote attackers to execute arbitrary SQL commands via the CAT_ID parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3317">3317</ref><ref source="BID" url="http://www.securityfocus.com/bid/22582">22582</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0621">ADV-2007-0621</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32528">codeavalanche-inclistnews-sql-injection(32528)</ref></refs><vuln_soft><prod name="CodeAvalanche News" vendor="CodeAvalanche"><vers num="1.x"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-02-21" name="CVE-2007-1022" published="2007-02-21" seq="2007-1022" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in h_goster.asp in Turuncu Portal 1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BID" url="http://www.securityfocus.com/bid/22591">22591</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24209">24209</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32571">
turuncu-hgoster-sql-injection(32571)</ref></refs><vuln_soft><prod name="Turuncu Portal" vendor="Turuncu Portal"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-02-21" name="CVE-2007-1023" published="2007-02-21" seq="2007-1023" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in pop_profile.asp in Snitz Forums 2000 3.1 SR4 allows remote attackers to execute arbitrary SQL commands via the id parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3321">3321</ref><ref source="BID" url="http://www.securityfocus.com/bid/22593">22593</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32543">snitzforums-popprofile-sql-injection(32543)</ref></refs><vuln_soft><prod name="Snitz Forums 2000" vendor="Snitz Communications"><vers edition="SR4" num="3.1"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-02-21" name="CVE-2007-1024" published="2007-02-21" seq="2007-1024" severity="High" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in include.php in Meganoide&apos;s news 1.1.1 allows remote attackers to execute arbitrary PHP code via a URL in the _SERVER[DOCUMENT_ROOT] parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/460323/100/0/threaded">20070216 Meganoide&apos;s news v1.1.1 &lt; = RFi Vulnerabilities</ref><ref source="BID" url="http://www.securityfocus.com/bid/22589">22589</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32546">meganoidesnews-include-file-include(32546)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2266">2266</ref></refs><vuln_soft><prod name="Meganoide&apos;s News" vendor="Marcello Vitagliano"><vers num="1.1.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-02-21" name="CVE-2007-1025" published="2007-02-21" seq="2007-1025" severity="High" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in inc/functions_inc.php in VS-Link-Partner 2.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the gb_pfad, or possibly script_pfad, parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3323">3323</ref><ref source="BID" url="http://www.securityfocus.com/bid/22594">22594</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0651">ADV-2007-0651</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32547">vslinkpartner-functions-file-include(32547)</ref></refs><vuln_soft><prod name="VS-Link-Partner" vendor="VirtualSystem"><vers num="2.1" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-02-21" name="CVE-2007-1026" published="2007-02-21" seq="2007-1026" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in view.php in XLAtunes 0.1 and earlier allows remote attackers to execute arbitrary SQL commands via the album parameter in view mode.  NOTE: some of these details are obtained from third party information.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3327">3327</ref><ref source="BID" url="http://www.securityfocus.com/bid/22602">22602</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0644">ADV-2007-0644</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/460592/100/0/threaded">

20070219 XLAtunes 0.1 (album) Remote SQL Injection Vulnerability</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/460621/100/0/threaded">
20070220 Re: XLAtunes 0.1 (album) Remote SQL Injection Vulnerability</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/460739/100/0/threaded">
20070221 XLAtunes 0.1 (album) Remote SQL Injection Vulnerability</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32556">
xlatunes-album-sql-injection(32556)</ref></refs><vuln_soft><prod name="XLAtunes" vendor="ScriptDungeon"><vers num="0.1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="3.1" CVSS_impact_subscore="6.4" CVSS_score="4.3" CVSS_vector="(AV:L/AC:L/Au:S/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-06-27" name="CVE-2007-1027" published="2007-02-21" seq="2007-1027" severity="Medium" type="CVE"><desc><descript source="cve">Certain setuid DB2 binaries in IBM DB2 before 9 Fix Pack 2 for Linux and Unix allow local users to overwrite arbitrary files via a symlink attack on the DB2DIAG.LOG temporary file.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><race/></vuln_types><range><local/></range><refs><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0652">ADV-2007-0652</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24213">24213</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017695">1017695</ref><ref source="BID" url="http://www.securityfocus.com/bid/22614">22614</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017665">1017665</ref></refs><vuln_soft><prod name="DB2" vendor="IBM"><vers edition="Linux" num="9.0"/><vers edition="Unix" num="9.0"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-02-21" name="CVE-2007-1028" published="2007-02-21" seq="2007-1028" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in the Barry Jaspan Image Pager 4.7.x-1.x-dev and 5.x-1.x-dev before 2007-02-08 module for Drupal allows remote attackers to inject arbitrary web script or HTML via unspecified vectors related to HTML entities and the IMG element.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://drupal.org/node/119293"></ref><ref source="BID" url="http://www.securityfocus.com/bid/22586">22586</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0636">ADV-2007-0636</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32539">imagepager-img-xss(32539)</ref></refs><vuln_soft><prod name="Image Pager" vendor="Barry Jaspan"><vers num="4.7"/><vers num="5.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="10.0" CVSS_score="7.6" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-03-05" name="CVE-2007-1029" published="2007-02-21" seq="2007-1029" severity="High" type="CVE"><desc><descript source="cve">Stack-based buffer overflow in the Connect method in the IMAP4 component in Quiksoft EasyMail Objects before 6.5 allows remote attackers to execute arbitrary code via a long host name.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref patch="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/460237/100/0/threaded">20070215 EasyMail Objects v6.5 Connect Method Stack Overflow</ref><ref adv="1" source="" url="http://security-assessment.com/files/advisories/easymail_advisory.pdf"></ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/22583">22583</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0634">ADV-2007-0634</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24199">24199</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32540">easymailobjects-connect-bo(32540)</ref><ref source="OSVDB" url="http://www.osvdb.org/33208">33208</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2277">2277</ref></refs><vuln_soft><prod name="EasyMail Objects" vendor="Quicksoft"><vers num="6.4" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.8" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.9" CVSS_score="7.8" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_version="2.0" modified="2007-02-21" name="CVE-2007-1030" published="2007-02-21" seq="2007-1030" severity="High" type="CVE"><desc><descript source="cve">Niels Provos libevent 1.2 and 1.2a allows remote attackers to cause a denial of service (infinite loop) via a DNS response containing a label pointer that references its own offset.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/460530/100/0/threaded">20070219 Remote DoS in libevent DNS parsing &lt;= 1.2a</ref><ref source="" url="http://monkey.org/~provos/libevent/"></ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/22606">22606</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0647">ADV-2007-0647</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24181">24181</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2268">2268</ref></refs><vuln_soft><prod name="libevent" vendor="Niels Provos"><vers num="1.2"/><vers num="1.2a"/></prod></vuln_soft></entry><entry CVSS_base_score="5.1" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="6.4" CVSS_score="5.1" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-02-21" name="CVE-2007-1031" published="2007-02-21" seq="2007-1031" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in include/db_conn.php in SpoonLabs Vivvo Article Management CMS 3.4 allows remote attackers to include and execute arbitrary local files via the root parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3326">3326</ref><ref source="BID" url="http://www.securityfocus.com/bid/22600">22600</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32553">vivvo-dbconn-file-include(32553)</ref></refs><vuln_soft><prod name="Article Manager CMS" vendor="Vivvo"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-08-03" name="CVE-2007-1032" published="2007-02-21" seq="2007-1032" severity="Medium" type="CVE"><desc><descript source="cve">Unspecified vulnerability in phpMyFAQ 1.6.9 and earlier, when register_globals is enabled, allows remote attackers to &quot;gain the privilege for uploading files on the server.&quot;</descript></desc><impacts><impact source="nvd">Successful exploitation requires that &quot;register_globals&quot; is enabled.</impact></impacts><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><range><network/></range><refs><ref source="" url="http://www.phpmyfaq.de/advisory_2007-02-18.php"></ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/24230">24230</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32573">phpmyfaq-unspecified-globals-file-upload(32573)</ref></refs><vuln_soft><prod name="phpMyFAQ" vendor="phpMyFAQ"><vers num="1.6.9" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-02-21" name="CVE-2007-1033" published="2007-02-21" seq="2007-1033" severity="Medium" type="CVE"><desc><descript source="cve">Unspecified vulnerability in the Secure site 4.7.x-1.x-dev and 5.x-1.x-dev module for Drupal allows remote attackers to bypass access restrictions via a crafted URL.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://drupal.org/node/119619"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0637">ADV-2007-0637</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32538">securesite-url-security-bypass(32538)</ref></refs><vuln_soft><prod name="Secure Site module" vendor="Drupal"><vers num="4.7"/><vers num="5.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-08-03" name="CVE-2007-1034" published="2007-02-21" seq="2007-1034" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in the category file in modules.php in the Emporium 2.3.0 and earlier module for PHP-Nuke allows remote attackers to execute arbitrary SQL commands via the category_id parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="MILW0RM" url="http://www.milw0rm.com/exploits/3334">3334</ref><ref source="BID" url="http://www.securityfocus.com/bid/22612">22612</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0661">ADV-2007-0661</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/23699">emporium-modules-sql-injection(23699)</ref></refs><vuln_soft><prod name="PHP-Nuke Emporium Module" vendor="PHP-Nuke"><vers num="2.3.0" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-02-26" name="CVE-2007-1035" published="2007-02-21" seq="2007-1035" severity="High" type="CVE"><desc><descript source="cve">Unspecified vulnerability in certain demonstration scripts in getID3 1.7.1, as used in the Mediafield and Audio modules for Drupal, allows remote attackers to read and delete arbitrary files, list arbitrary directories, and write to empty files or .mp3 files via unknown vectors.</descript></desc><impacts><impact source="nvd">This vulnerability affects the following versions of Drupal Mediafield Module:
Drupal, Mediafield Module, 4.7.x-1.x-dev
Drupal, Mediafield Module, 5.x-1.x-dev

This vulnerability affects the following versions of Drupal Audio Module:
Drupal, Audio Module, 4.7.x-1.x-dev
Drupal, Audio Module, 5.x-0.2
Drupal, Audio Module, 5.x-0.x-dev
</impact></impacts><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><range><network/></range><refs><ref source="" url="http://blamcast.net/articles/highly-critical-security-flaws-in-drupal-audio-module"></ref><ref adv="1" patch="1" source="DRUPAL" url="http://drupal.org/node/119385">DRUPAL-SA-2007-009</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/22587">22587</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0635">ADV-2007-0635</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/32542">drupal-getid3-code-execution(32542)</ref></refs><vuln_soft><prod name="getID3" vendor="Drupal"><vers num="1.7.1"/></prod><prod name="Mediafield Module" vendor="Drupal"><vers num=""/></prod><prod name="Audio Module" vendor="Drupal"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-02-22" name="CVE-2007-1036" published="2007-02-21" seq="2007-1036" severity="High" type="CVE"><desc><descript source="cve">The default configuration of JBoss does not restrict access to the (1) console and (2) web management interfaces, which allows remote attackers to bypass authentication and gain administrative access via direct requests.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><config/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/460597/100/0/threaded">20070220 Jboss vulnerability</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/460695/100/0/threaded">20070220 Re: Jboss vulnerability</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/460605/100/0/threaded">20070220 Re: Jboss vulnerability</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/632656">VU#632656</ref><ref source="" url="http://wiki.jboss.org/wiki/Wiki.jsp?page=SecureJBoss"></ref><ref source="" url="http://wiki.jboss.org/wiki/Wiki.jsp?page=SecureTheJmxConsole"></ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017677">
1017677</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32596">
jboss-admin-unauth-access(32596)</ref></refs><vuln_soft><prod name="JBoss Application Server" vendor="JBoss"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" CVSS_score="9.3" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2008-03-07" name="CVE-2007-1037" published="2007-02-21" seq="2007-1037" severity="High" type="CVE"><desc><descript source="cve">Stack-based buffer overflow in News File Grabber 4.1.0.1 and earlier allows remote attackers to execute arbitrary code via a .nzb file with a long subject field.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/><user_init/></range><refs><ref source="BID" url="http://www.securityfocus.com/bid/22617">22617</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0662">ADV-2007-0662</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24237">24237</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32577">newsfilegrabber-nzb-bo(32577)</ref></refs><vuln_soft><prod name="News File Grabber" vendor="RSBR-Software"><vers num="4.1.0.1" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0" modified="2007-02-22" name="CVE-2007-1038" published="2007-02-21" seq="2007-1038" severity="Medium" type="CVE"><desc><descript source="cve">Shemes.com Grabit 1.5.3, and possibly earlier, allows remote attackers to cause a denial of service (application crash) via a .nzb file with a subject field containing &apos;;&apos; (semicolon) characters.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript></desc><loss_types><avail/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref source="BID" url="http://www.securityfocus.com/bid/22619">22619</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0664">ADV-2007-0664</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32579">
grabit-nzb-dos(32579)</ref></refs><vuln_soft><prod name="Grabit" vendor="Shemes.com"><vers num="1.5.3" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-02-22" name="CVE-2007-1039" published="2007-02-21" seq="2007-1039" severity="High" type="CVE"><desc><descript source="cve">Unspecified vulnerability in Peanut Knowledge Base (PeanutKB) 0.0.3 and earlier has unknown impact and attack vectors.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs><ref source="" url="http://sourceforge.net/project/shownotes.php?group_id=157653&amp;release_id=483888"></ref><ref patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0666">ADV-2007-0666</ref><ref source="BID" url="http://www.securityfocus.com/bid/22628">
22628</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32574">
peanutkb-multiple-unspecified(32574)</ref></refs><vuln_soft><prod name="Peanut Knowledge Base" vendor="PeanutKB"><vers num="0.0.1"/><vers num="0.0.2"/><vers num="0.0.3"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-02-22" name="CVE-2007-1040" published="2007-02-21" seq="2007-1040" severity="High" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in archives.php in Xpression News (X-News) 1.0.1 allows remote attackers to include arbitrary files or obtain sensitive information via a .. (dot dot) in the xnews-template parameter.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3332">3332</ref><ref source="BID" url="http://www.securityfocus.com/bid/22609">22609</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0645">ADV-2007-0645</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24177">24177</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/32560">xnews-archives-news-directory-traversal(32560)</ref></refs><vuln_soft><prod name="Xpression News" vendor="Xpression News"><vers num="1.0.1"/></prod></vuln_soft></entry><entry CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" CVSS_score="9.3" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2008-03-05" name="CVE-2007-1041" published="2007-02-21" seq="2007-1041" severity="High" type="CVE"><desc><descript source="cve">Multiple stack-based buffer overflows in S&amp;H Computer Systems News Rover 12.1 Rev 1 allow remote attackers to execute arbitrary code via a .nzb file with a long (1) group or (2) subject string.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/><user_init/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3342">3342</ref><ref source="BID" url="http://www.securityfocus.com/bid/22618">22618</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0663">ADV-2007-0663</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24216">24216</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32576">newsrover-nzb-bo(32576)</ref></refs><vuln_soft><prod name="News Rover" vendor="SandH"><vers edition="rev1" num="12.1"/></prod></vuln_soft></entry><entry CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" CVSS_score="9.3" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-02-22" name="CVE-2007-1042" published="2007-02-21" seq="2007-1042" severity="High" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in news.php in Xpression News (X-News) 1.0.1, when magic_quotes_gpc is disabled, allows remote attackers to include arbitrary files or obtain sensitive information via a .. (dot dot) in the xnews-template parameter.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24177">24177</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32560">xnews-archives-news-directory-traversal(32560)</ref></refs><vuln_soft><prod name="Xpression News" vendor="Xpression News"><vers num="1.0.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-05-16" name="CVE-2007-1043" published="2007-02-21" seq="2007-1043" severity="High" type="CVE"><desc><descript source="cve">Ezboo webstats, possibly 3.0.3, allows remote attackers to bypass authentication and gain access via a direct request to (1) update.php and (2) config.php.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/460325/100/0/threaded">20070215 Ezboo webstats acces to sensitive files</ref><ref adv="1" source="" url="http://forums.avenir-geopolitique.net/viewtopic.php?t=2674"></ref><ref source="BID" url="http://www.securityfocus.com/bid/22590">22590</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32563">ezboo-update-unauthorized-access(32563)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2275">2275</ref></refs><vuln_soft><prod name="Webstats" vendor="Ezboo"><vers num="3.0.3"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0" modified="2008-01-14" name="CVE-2007-1044" published="2007-02-21" seq="2007-1044" severity="Medium" type="CVE"><desc><descript source="cve">Pearson Education PowerSchool 4.3.6 allows remote attackers to list the contents of the admin folder via a URI composed of the admin/ directory name and an arbitrary filename ending in &quot;.js.&quot;  NOTE: it was later reported that this issue had been addressed by 5.1.2.</descript></desc><loss_types><conf/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/460533/100/0/threaded">20070219 Powerschool 404 Admin Exposure</ref><ref source="BID" url="http://www.securityfocus.com/bid/22611">22611</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32569">powerschool-js-information-disclosure(32569)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2276">2276</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/484569/100/200/threaded">20071204 Re: Powerschool 404 Admin Exposure</ref></refs><vuln_soft><prod name="Powerschool" vendor="Pearson Education"><vers num="4.3.6"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-02-22" name="CVE-2007-1045" published="2007-02-21" seq="2007-1045" severity="High" type="CVE"><desc><descript source="cve">mAlbum 0.3 has default accunts (1) &quot;login&quot;/&quot;pass&quot; for its administrative account and (2) &quot;dqsfg&quot;/&quot;sdfg&quot;, which allows remote attackers to gain privileges.</descript></desc><sols><sol source="nvd">mAlbum should reconfigure their administrative login and password from their default values.</sol></sols><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><config/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/460402/100/0/threaded">20070217 mAlbum v0.3 admin by default user/pass</ref><ref adv="1" source="" url="http://forums.avenir-geopolitique.net/viewtopic.php?t=2677"></ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32562">malbum-default-admin-account(32562)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2272">2272</ref></refs><vuln_soft><prod name="mAlbum" vendor="mAlbum"><vers num="0.3"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0" modified="2007-02-22" name="CVE-2007-1046" published="2007-02-21" seq="2007-1046" severity="Medium" type="CVE"><desc><descript source="cve">Dem_trac allows remote attackers to read log file contents via a direct request for /anc_sit.txt.</descript></desc><loss_types><conf/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/460306/100/0/threaded">20070215 Dem_trac acces to log file wihtout authentification</ref><ref adv="1" source="" url="http://forums.avenir-geopolitique.net/viewtopic.php?t=2673"></ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32566">demtrac-ancsit-information-disclosure(32566)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2271">2271</ref></refs><vuln_soft><prod name="Dem_trac" vendor="Dem_trac"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-02-22" name="CVE-2007-1047" published="2007-02-21" seq="2007-1047" severity="High" type="CVE"><desc><descript source="cve">Unspecified vulnerability in Distributed Checksum Clearinghouse (DCC) before 1.3.51 allows remote attackers to delete or add hosts in /var/dcc/maps.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref patch="1" source="" url="http://www.rhyolite.com/anti-spam/dcc/CHANGES"></ref><ref source="BID" url="http://www.securityfocus.com/bid/22622">22622</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0654">ADV-2007-0654</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24176">24176</ref></refs><vuln_soft><prod name="DCC" vendor="Distributed Checksum ClearingHouse"><vers num="1.3"/><vers num="1.3.1"/><vers num="1.3.10"/><vers num="1.3.11"/><vers num="1.3.12"/><vers num="1.3.13"/><vers num="1.3.14"/><vers num="1.3.15"/><vers num="1.3.16"/><vers num="1.3.2"/><vers num="1.3.3"/><vers num="1.3.4"/><vers num="1.3.5"/><vers num="1.3.6"/><vers num="1.3.7"/><vers num="1.3.8"/><vers num="1.3.9"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-02-23" name="CVE-2007-1048" published="2007-02-21" seq="2007-1048" severity="High" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in admin_rebuild_search.php in phpbb_wordsearch allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/460338/100/0/threaded">20070216 phpbb_wordsearch &lt; = RFi Vulnerabilities</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32551">phpbbwordsearch-rebuildsearch-file-include(32551)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2280">2280</ref></refs><vuln_soft><prod name="phpbb_wordsearch" vendor="phpbb_wordsearch"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" modified="2007-02-22" name="CVE-2007-1049" published="2007-02-21" seq="2007-1049" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in the wp_explain_nonce function in the nonce AYS functionality (wp-includes/functions.php) for WordPress 2.0 before 2.0.9 and 2.1 before 2.1.1 allows remote attackers to inject arbitrary web script or HTML via the file parameter to wp-admin/templates.php, and possibly other vectors involving the action variable.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref source="" url="http://downloads.securityfocus.com/vulnerabilities/exploits/22534.html"></ref><ref patch="1" source="" url="http://trac.wordpress.org/changeset/4876"></ref><ref source="" url="http://trac.wordpress.org/changeset/4877"></ref><ref adv="1" source="" url="http://trac.wordpress.org/ticket/3781"></ref><ref source="BID" url="http://www.securityfocus.com/bid/22534">22534</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200703-23.xml">
GLSA-200703-23</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0741">
ADV-2007-0741</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24306">
24306</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24566">
24566</ref></refs><vuln_soft><prod name="WordPress" vendor="WordPress"><vers num="(B2) 0.6.2"/><vers num="(B2) 0.6.2.1"/><vers num="0.7"/><vers num="0.71"/><vers num="1.2.2"/><vers num="1.5"/><vers num="1.5.1"/><vers num="1.5.1.2"/><vers num="1.5.1.3"/><vers num="1.5.2"/><vers num="2.0"/><vers num="2.0.1"/><vers num="2.0.2"/><vers num="2.0.3"/><vers num="2.0.4"/><vers num="2.0.5"/><vers num="2.0.6"/><vers num="2.0.7"/><vers num="1.2"/><vers num="1.2.1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-08-03" name="CVE-2007-1050" published="2007-02-21" seq="2007-1050" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in index.php in AbleDesign MyCalendar allow remote attackers to inject arbitrary web script or HTML via (1) the go parameter, (2) the keyword parameter in the search menu (go=search), or (3) the username or (4) the password in a go=Login action.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/460598/100/0/threaded">20070219 MyCalendar multiple XSS</ref><ref source="" url="http://forums.avenir-geopolitique.net/viewtopic.php?t=2686"></ref><ref source="BID" url="http://www.securityfocus.com/bid/22635">22635</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0679">ADV-2007-0679</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24222">24222</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32581">mycalendar-index-xss(32581)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2270">2270</ref></refs><vuln_soft><prod name="MyCalendar" vendor="AbleDesign"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-02-22" name="CVE-2007-1051" published="2007-02-21" seq="2007-1051" severity="Medium" type="CVE"><desc><descript source="cve">Comodo Firewall Pro (formerly Comodo Personal Firewall) 2.4.17.183 and earlier uses a weak cryptographic hashing function (CRC32) to identify trusted modules, which allows local users to bypass security protections by substituting modified modules that have the same CRC32 value.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/460209/100/100/threaded">20070215 Comodo DLL injection via weak hash function exploitation Vulnerability</ref><ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2007-February/052461.html">20070215 Comodo DLL injection via weak hash function exploitation Vulnerability</ref><ref source="" url="http://www.matousec.com/info/advisories/Comodo-DLL-injection-via-weak-hash-function-exploitation.php"></ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32530">comodofirewallpro-crc32-security-bypass(32530)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2279">2279</ref></refs><vuln_soft><prod name="Comodo Firewall Pro" vendor="Comodo"><vers num="2.4.17.183" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-02-22" name="CVE-2007-1052" published="2007-02-21" seq="2007-1052" severity="High" type="CVE"><desc><descript source="cve">** DISPUTED **  PHP remote file inclusion vulnerability in index.php in PBLang (PBL) 4.60 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the dbpath parameter, a different vector than CVE-2006-5062.  NOTE: this issue has been disputed by a reliable third party for 4.65, stating that the dbpath variable is initialized in an included file that is created upon installation.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/460315/100/0/threaded">20070216 PBLang 4.60 &lt;= (index.php) Remote File Include Vulnerability</ref><ref source="VIM" url="http://attrition.org/pipermail/vim/2007-February/001356.html">20070216 PBLang 4.60 &lt;= (index.php) Remote File Include Vulnerability</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2269">2269</ref></refs><vuln_soft><prod name="PBLang" vendor="PBLang"><vers num="4.60" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-02-22" name="CVE-2007-1053" published="2007-02-21" seq="2007-1053" severity="High" type="CVE"><desc><descript source="cve">** DISPUTED **  Multiple PHP remote file inclusion vulnerabilities in phpXmms 1.0 allow remote attackers to execute arbitrary PHP code via a URL in the tcmdp parameter to (1) phpxmmsb.php or (2) phpxmmst.php.  NOTE: this issue has been disputed by a reliable third party, stating that the tcmdp variable is initialized by config.php.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/460618/100/0/threaded">20070220 phpXmms 1.0 (tcmdp) Remote File Include Vulnerabilities</ref><ref source="VIM" url="http://attrition.org/pipermail/vim/2007-February/001365.html">20070220 false: phpXmms 1.0 (tcmdp) Remote File Include Vulnerabilities</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2273">2273</ref></refs><vuln_soft><prod name="phpXmms" vendor="Warped Systems"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-02-22" name="CVE-2007-1054" published="2007-02-21" seq="2007-1054" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in the AJAX features in index.php in MediaWiki 1.6.x through 1.9.2, when $wgUseAjax is enabled, allows remote attackers to inject arbitrary web script or HTML via a UTF-7 encoded value of the rs parameter, which is processed by Internet Explorer.</descript></desc><impacts><impact source="nvd">Successful exploitation requires that &quot;$wgUseAjax&quot; is enabled</impact></impacts><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/460596/100/0/threaded">20070220 MediaWiki Cross-site Scripting</ref><ref source="" url="http://www.bugsec.com/articles.php?Security=24"></ref><ref source="" url="http://svn.wikimedia.org/svnroot/mediawiki/tags/REL1_9_3/phase3/RELEASE-NOTES"></ref><ref source="VIM" url="http://attrition.org/pipermail/vim/2007-February/001367.html">20070221 [unsure] MediaWiki Cross-site Scripting</ref><ref source="" url="http://sourceforge.net/project/shownotes.php?release_id=487921&amp;group_id=34373"></ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0678">
ADV-2007-0678</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24211">
24211</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32586">
mediawiki-index-xss(32586)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2274">2274</ref></refs><vuln_soft><prod name="MediaWiki" vendor="MediaWiki"><vers num="1.8.2" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-02-22" name="CVE-2007-1055" published="2007-02-21" seq="2007-1055" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in the AJAX features in index.php in MediaWiki 1.9.x before 1.9.0rc2, and 1.8.2 and earlier allows remote attackers to inject arbitrary web script or HTML via the rs parameter.  NOTE: this issue might be a duplicate of CVE-2007-0177.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/460596/100/0/threaded">20070220 MediaWiki Cross-site Scripting</ref><ref source="" url="http://www.bugsec.com/articles.php?Security=24"></ref><ref source="" url="http://svn.wikimedia.org/svnroot/mediawiki/tags/REL1_9_0/phase3/RELEASE-NOTES"></ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32586">
mediawiki-index-xss(32586)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2274">2274</ref></refs><vuln_soft><prod name="MediaWiki" vendor="MediaWiki"><vers edition="RC2" num="1.9.0" prev="1"/><vers num="1.8.2" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-08-03" name="CVE-2007-1056" published="2007-02-21" seq="2007-1056" severity="High" type="CVE"><desc><descript source="cve">VMware Workstation 5.5.3 build 34685 does not provide per-user restrictions on certain privileged actions, which allows local users to perform restricted operations such as changing system time, accessing hardware components, and stopping the &quot;VMware tools service&quot; service.  NOTE: exploitation is simplified via (1) weak file permisssions (Users = Read &amp; Execute) for %PROGRAMFILES%\VMware; and weak registry key permissions (access by Users) for (2) vmmouse, (3) vmscsi, (4) VMTools, (5) vmx_svga, and (6) vmxnet in HKLM\SYSTEM\CurrentControlSet\Services\; which allows local users to perform various privileged actions outside of the guest OS by executing certain files under %PROGRAMFILES%\VMware\VMware Tools, as demonstrated by (a) VMControlPanel.cpl and (b) vmwareservice.exe.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/460664/100/0/threaded">20070219 VMware Workstation multiple denial of service and isolation manipulation vulnerabilities</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/461807/100/0/threaded">20070303 Re: VMware Workstation multiple denial of service and isolation manipulation vulnerabilities</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2281">2281</ref></refs><vuln_soft><prod name="VMWare Workstation" vendor="VMWare"><vers num="5.5.3.34685"/></prod></vuln_soft></entry><entry CVSS_base_score="6.9" CVSS_exploit_subscore="3.4" CVSS_impact_subscore="10.0" CVSS_score="6.9" CVSS_vector="(AV:L/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-06-27" name="CVE-2007-1057" published="2007-02-21" seq="2007-1057" severity="Medium" type="CVE"><desc><descript source="cve">The Net Direct client for Linux before 6.0.5 in Nortel Application Switch 2424, VPN 3050 and 3070, and SSL VPN Module 1000 extracts and executes files with insecure permissions, which allows local users to exploit a race condition to replace a world-writable file in /tmp/NetClient and cause another user to execute arbitrary code when attempting to execute this client, as demonstrated by replacing /tmp/NetClient/client.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><race/></vuln_types><range><local/></range><refs><ref source="" url="http://spoofed.org/blog/archive/2007/02/nortel_vpn_unix_client_local_root_compromise.html"></ref><ref source="" url="http://www116.nortelnetworks.com/pub/repository/CLARIFY/DOCUMENT/2007/08/021886-01.pdf"></ref><ref patch="1" source="" url="http://www130.nortelnetworks.com/go/main.jsp?cscat=BLTNDETAIL&amp;DocumentOID=540071"></ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24231">24231</ref><ref source="BID" url="http://www.securityfocus.com/bid/22632">22632</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0671">ADV-2007-0671</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017678">1017678</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32597">netdirect-permissions-privilege-escalation(32597)</ref></refs><vuln_soft><prod name="Net Direct client" vendor="Nortel"><vers edition="Linux" num="6.0.4" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-02-23" name="CVE-2007-1058" published="2007-02-21" seq="2007-1058" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in user_pages/page.asp in Online Web Building 2.0 allows remote attackers to execute arbitrary SQL commands via the art_id parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MILW0RM" url="http://milw0rm.com/exploits/3339">3339</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0674">ADV-2007-0674</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24208">24208</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32583">
onlineweb-page-sql-injection(32583)</ref></refs><vuln_soft><prod name="Online Web Building" vendor="Online Web Building"><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-02-23" name="CVE-2007-1059" published="2007-02-21" seq="2007-1059" severity="Medium" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in function.php in Ultimate Fun Book 1.02 allows remote attackers to execute arbitrary PHP code via a URL in the gbpfad parameter.  NOTE: some sources mention &quot;Ultimate Fun Board,&quot; but this appears to be an error.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MILW0RM" url="http://milw0rm.com/exploits/3336">3336</ref><ref source="BID" url="http://www.securityfocus.com/bid/22633">22633</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0675">ADV-2007-0675</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24219">24219</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32584">
ultimatefunbook-function-file-include(32584)</ref></refs><vuln_soft><prod name="Ultimate Fun Book" vendor="Ultimate Fun Book"><vers num="1.02"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-02-23" name="CVE-2007-1060" published="2007-02-21" seq="2007-1060" severity="Medium" type="CVE"><desc><descript source="cve">Multiple PHP remote file inclusion vulnerabilities in Interspire SendStudio 2004.14 and earlier, when register_globals and allow_fopenurl are enabled, allow remote attackers to execute arbitrary PHP code via a URL in the ROOTDIR parameter to (1) createemails.inc.php and (2) send_emails.inc.php in /admin/includes/.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MILW0RM" url="http://advisories.echo.or.id/adv/adv66-K-159-2007.txt">3348</ref><ref source="" url="http://www.milw0rm.com/exploits/3348"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0672">ADV-2007-0672</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24212">24212</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/460964/100/0/threaded">

20070221 [ECHO_ADV_66$2007] SendStudio &lt;= 2004.14 Remote File Inclusion Vulnerability</ref><ref source="BID" url="http://www.securityfocus.com/bid/22642">
22642</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32602">
sendstudio-rootdir-file-include(32602)</ref></refs><vuln_soft><prod name="SendStudio" vendor="Interspire"><vers num="2004.14" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-02-23" name="CVE-2007-1061" published="2007-02-21" seq="2007-1061" severity="Medium" type="CVE"><desc><descript source="cve">SQL injection vulnerability in index.php in Francisco Burzi PHP-Nuke 8.0 Final and earlier, when the &quot;HTTP Referers&quot; block is enabled, allows remote attackers to execute arbitrary SQL commands via the HTTP Referer header (HTTP_REFERER variable).</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3346">3346</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0673">ADV-2007-0673</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24224">24224</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/461148/100/0/threaded">

20070224 Blind sql injection attack in INSERT syntax on PHP-nuke &lt;=8.0 Final</ref><ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2007-February/052570.html">
20070220 Blind sql injection attack in INSERT syntax on PHP-nuke &lt;=8.0 Final</ref><ref source="BID" url="http://www.securityfocus.com/bid/22638">
22638</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32607">
phpnuke-index-sql-injection(32607)</ref></refs><vuln_soft><prod name="PHP-Nuke" vendor="Francisco Burzi"><vers num="8.0 FINAL" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-08-03" name="CVE-2007-1062" published="2007-02-21" seq="2007-1062" severity="High" type="CVE"><desc><descript source="cve">The Cisco Unified IP Conference Station 7935 3.2(15) and earlier, and Station 7936 3.3(12) and earlier does not properly handle administrator HTTP sessions, which allows remote attackers to bypass authentication controls via a direct URL request to the administrative HTTP interface for a limited time</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="CISCO" url="http://www.cisco.com/warp/public/707/cisco-sa-20070221-phone.shtml">20070221 Cisco Unified IP Conference Station and IP Phone Vulnerabilities</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0688">ADV-2007-0688</ref><ref source="CISCO" url="http://www.cisco.com/warp/public/707/cisco-air-20070221-phone.shtml">20070221 Identifying and Mitigating Exploitation of Cisco Unified IP Conference Station and IP Phone Vulnerabilities</ref><ref source="BID" url="http://www.securityfocus.com/bid/22647">22647</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1017680">1017680</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24262">24262</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32623">cisco-unified-ip-conference-url-auth-bypass(32623)</ref></refs><vuln_soft><prod name="Unified IP Conference Station 7936" vendor="Cisco"><vers num="3.3(12)" prev="1"/></prod><prod name="Unified IP Conference Station 7935" vendor="Cisco"><vers num="3.2(15)" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-02-23" name="CVE-2007-1063" published="2007-02-21" seq="2007-1063" severity="High" type="CVE"><desc><descript source="cve">The SSH server in Cisco Unified IP Phone 7906G, 7911G, 7941G, 7961G, 7970G, and 7971G, with firmware 8.0(4)SR1 and earlier, uses a hard-coded username and password, which allows remote attackers to access the device.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><access/><design/></vuln_types><range><network/></range><refs><ref source="CISCO" url="http://www.cisco.com/warp/public/707/cisco-sa-20070221-phone.shtml">20070221 Cisco Unified IP Conference Station and IP Phone Vulnerabilities</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0689">ADV-2007-0689</ref><ref source="CISCO" url="http://www.cisco.com/warp/public/707/cisco-air-20070221-phone.shtml">
20070221 Identifying and Mitigating Exploitation of Cisco Unified IP Conference Station and IP Phone Vulnerabilities</ref><ref source="BID" url="http://www.securityfocus.com/bid/22647">
22647</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017681">
1017681</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24262">
24262</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32627">
cisco-unified-ip-phone-default-user-account(32627)</ref></refs><vuln_soft><prod name="Unified IP Phone 7941G" vendor="Cisco"><vers edition="SR1" num="8.0(4)" prev="1"/></prod><prod name="Unified IP Conference Station 7936" vendor="Cisco"><vers num="3.2(15)" prev="1"/></prod><prod name="Unified IP Phone 7906G" vendor="Cisco"><vers edition="SR1" num="8.0(4)" prev="1"/></prod><prod name="Unified IP Phone 7961G" vendor="Cisco"><vers edition="SR1" num="8.0(4)" prev="1"/></prod><prod name="Unified IP Phone 7971G" vendor="Cisco"><vers edition="SR1" num="8.0(4)" prev="1"/></prod><prod name="Unified IP Phone 7911G" vendor="Cisco"><vers edition="SR1" num="8.0(4)" prev="1"/></prod><prod name="Unified IP Conference Station 7935" vendor="Cisco"><vers num="3.2(15)" prev="1"/></prod><prod name="Unified IP Phone 7970G" vendor="Cisco"><vers edition="SR1" num="8.0(4)" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="3.1" CVSS_impact_subscore="10.0" CVSS_score="6.8" CVSS_vector="(AV:L/AC:L/Au:S/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-08-03" name="CVE-2007-1064" published="2007-02-21" seq="2007-1064" severity="Medium" type="CVE"><desc><descript source="cve">Cisco Secure Services Client (CSSC) 4.x, Trust Agent 1.x and 2.x, Cisco Security Agent (CSA) 5.0 and 5.1 (when a vulnerable Trust Agent has been deployed), and the Meetinghouse AEGIS SecureConnect Client do not drop privileges when the help facility in the supplicant GUI is invoked, which allows local users to gain privileges, aka CSCsf14120.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><access/><exception/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="CISCO" url="http://www.cisco.com/warp/public/707/cisco-sa-20070221-supplicant.shtml">20070221 Multiple Vulnerabilities in 802.1X Supplicant</ref><ref source="BID" url="http://www.securityfocus.com/bid/22648">22648</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0690">ADV-2007-0690</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017683">1017683</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017684">1017684</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24258">24258</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32621">cisco-cssc-help-privilege-escalation(32621)</ref></refs><vuln_soft><prod name="Secure Services Client" vendor="Cisco"><vers num="4.0"/><vers num="4.0.5"/><vers num="4.0.51"/></prod><prod name="Security Agent" vendor="Cisco"><vers num="5.0"/><vers num="5.1"/></prod><prod name="Trust Agent" vendor="Cisco"><vers num="1.0"/><vers num="2.0"/><vers num="2.0.1"/><vers num="2.1"/></prod><prod name="AEGIS SecureConnect Client" vendor="Meetinghouse"><vers num="Windows platform"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="3.1" CVSS_impact_subscore="10.0" CVSS_score="6.8" CVSS_vector="(AV:L/AC:L/Au:S/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-08-03" name="CVE-2007-1065" published="2007-02-21" seq="2007-1065" severity="Medium" type="CVE"><desc><descript source="cve">Cisco Secure Services Client (CSSC) 4.x, Trust Agent 1.x and 2.x, Cisco Security Agent (CSA) 5.0 and 5.1 (when a vulnerable Trust Agent has been deployed), and the Meetinghouse AEGIS SecureConnect Client allows local users to gain SYSTEM privileges via unspecified vectors in the supplicant, aka CSCsf15836.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><access/><exception/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="CISCO" url="http://www.cisco.com/warp/public/707/cisco-sa-20070221-supplicant.shtml">20070221 Multiple Vulnerabilities in 802.1X Supplicant</ref><ref source="BID" url="http://www.securityfocus.com/bid/22648">22648</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0690">ADV-2007-0690</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017683">1017683</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017684">1017684</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24258">24258</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32622">cisco-cssc-privilege-escalation(32622)</ref></refs><vuln_soft><prod name="Secure Services Client" vendor="Cisco"><vers num="4.0"/><vers num="4.0.5"/><vers num="4.0.51"/></prod><prod name="Security Agent" vendor="Cisco"><vers num="5.0"/><vers num="5.1"/></prod><prod name="Trust Agent" vendor="Cisco"><vers num="1.0"/><vers num="2.0"/><vers num="2.0.1"/><vers num="2.1"/></prod><prod name="AEGIS SecureConnect Client" vendor="Meetinghouse"><vers num="Windows platform"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="3.1" CVSS_impact_subscore="10.0" CVSS_score="6.8" CVSS_vector="(AV:L/AC:L/Au:S/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-08-03" name="CVE-2007-1066" published="2007-02-21" seq="2007-1066" severity="Medium" type="CVE"><desc><descript source="cve">Cisco Secure Services Client (CSSC) 4.x, Trust Agent 1.x and 2.x, Cisco Security Agent (CSA) 5.0 and 5.1 (when a vulnerable Trust Agent has been deployed), and the Meetinghouse AEGIS SecureConnect Client use an insecure default Discretionary Access Control Lists (DACL) for the connection client GUI, which allows local users to gain privileges by injecting &quot;a thread under ConnectionClient.exe,&quot; aka CSCsg20558.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input/><exception/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="CISCO" url="http://www.cisco.com/warp/public/707/cisco-sa-20070221-supplicant.shtml">20070221 Multiple Vulnerabilities in 802.1X Supplicant</ref><ref source="BID" url="http://www.securityfocus.com/bid/22648">22648</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0690">ADV-2007-0690</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017683">1017683</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017684">1017684</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24258">24258</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32625">cisco-cssc-dacl-privilege-escalation(32625)</ref></refs><vuln_soft><prod name="Secure Services Client" vendor="Cisco"><vers num="4.0"/><vers num="4.0.5"/><vers num="4.0.51"/></prod><prod name="Security Agent" vendor="Cisco"><vers num="5.0"/><vers num="5.1"/></prod><prod name="Trust Agent" vendor="Cisco"><vers num="1.0"/><vers num="2.0"/><vers num="2.0.1"/><vers num="2.1"/></prod><prod name="AEGIS SecureConnect Client" vendor="Meetinghouse"><vers num="Windows platform"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-08-03" name="CVE-2007-1067" published="2007-02-21" seq="2007-1067" severity="High" type="CVE"><desc><descript source="cve">Cisco Secure Services Client (CSSC) 4.x, Trust Agent 1.x and 2.x, Cisco Security Agent (CSA) 5.0 and 5.1 (when a vulnerable Trust Agent has been deployed), and the Meetinghouse AEGIS SecureConnect Client do not properly parse commands, which allows local users to gain privileges via unspecified vectors, aka CSCsh30624.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input/><exception/></vuln_types><range><local/></range><refs><ref source="CISCO" url="http://www.cisco.com/warp/public/707/cisco-sa-20070221-supplicant.shtml">20070221 Multiple Vulnerabilities in 802.1X Supplicant</ref><ref source="BID" url="http://www.securityfocus.com/bid/22648">22648</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0690">ADV-2007-0690</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017683">1017683</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017684">1017684</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24258">24258</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32624">cisco-cssc-parsing-privilege-escalation(32624)</ref></refs><vuln_soft><prod name="Secure Services Client" vendor="Cisco"><vers num="4.x"/></prod><prod name="Security Agent" vendor="Cisco"><vers num="5.0"/><vers num="5.1"/></prod><prod name="Trust Agent" vendor="Cisco"><vers num="1.x"/></prod><prod name="AEGIS SecureConnect Client" vendor="Meetinghouse"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="3.1" CVSS_impact_subscore="10.0" CVSS_score="6.8" CVSS_vector="(AV:L/AC:L/Au:S/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-08-03" name="CVE-2007-1068" published="2007-02-21" seq="2007-1068" severity="Medium" type="CVE"><desc><descript source="cve">The (1) TTLS CHAP, (2) TTLS MSCHAP, (3) TTLS MSCHAPv2, (4) TTLS PAP, (5) MD5, (6) GTC, (7) LEAP, (8) PEAP MSCHAPv2, (9) PEAP GTC, and (10) FAST authentication methods in Cisco Secure Services Client (CSSC) 4.x, Trust Agent 1.x and 2.x, Cisco Security Agent (CSA) 5.0 and 5.1 (when a vulnerable Trust Agent has been deployed), and the Meetinghouse AEGIS SecureConnect Client store transmitted authentication credentials in plaintext log files, which allows local users to obtain sensitive information by reading these files, aka CSCsg34423.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><access/><exception/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="CISCO" url="http://www.cisco.com/warp/public/707/cisco-sa-20070221-supplicant.shtml">20070221 Multiple Vulnerabilities in 802.1X Supplicant</ref><ref source="BID" url="http://www.securityfocus.com/bid/22648">22648</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0690">ADV-2007-0690</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017683">1017683</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017684">1017684</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24258">24258</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32626">cisco-cssc-password-information-disclosure(32626)</ref></refs><vuln_soft><prod name="Secure Services Client" vendor="Cisco"><vers num="4.0"/><vers num="4.0.5"/><vers num="4.0.51"/></prod><prod name="Security Agent" vendor="Cisco"><vers num="5.0"/><vers num="5.1"/></prod><prod name="Trust Agent" vendor="Cisco"><vers num="1.0"/><vers num="2.0"/><vers num="2.0.1"/><vers num="2.1"/></prod><prod name="AEGIS SecureConnect Client" vendor="Meetinghouse"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.8" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.9" CVSS_score="7.8" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_version="2.0" modified="2007-05-03" name="CVE-2007-1069" published="2007-05-02" seq="2007-1069" severity="High" type="CVE"><desc><descript source="cve">The memory management in VMware Workstation before 5.5.4 allows attackers to cause a denial of service (Windows virtual machine crash) by triggering certain general protection faults (GPF).</descript></desc><loss_types><avail/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref patch="1" source="" url="http://www.vmware.com/support/ws55/doc/releasenotes_ws55.html#554"></ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/467836/100/0/threaded">

20070507 [Reversemode Advisory] VMware Products - GPF Denial of Service</ref><ref source="" url="http://www.reversemode.com/index.php?option=com_remository&amp;Itemid=2&amp;func=fileinfo&amp;id=49"></ref><ref source="SECUNIA" url="http://secunia.com/advisories/25079">
25079</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33994">
vmware-gpf-dos(33994)</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1018011">
1018011</ref><ref source="BID" url="http://www.securityfocus.com/bid/23732">23732</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1592">ADV-2007-1592</ref></refs><vuln_soft><prod name="VMWare Workstation" vendor="VMWare"><vers num="5.5.3" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-02-22" name="CVE-2007-1070" published="2007-02-21" seq="2007-1070" severity="High" type="CVE"><desc><descript source="cve">Multiple stack-based buffer overflows in Trend Micro ServerProtect for Windows and EMC 5.58, and for Network Appliance Filer 5.61 and 5.62, allow remote attackers to execute arbitrary code via crafted RPC requests to TmRpcSrv.dll that trigger overflows when calling the (1) CMON_NetTestConnection, (2) CMON_ActiveUpdate, and (3) CMON_ActiveRollback functions in (a) StCommon.dll, and (4) ENG_SetRealTimeScanConfigInfo and (5) ENG_SendEMail functions in (b) eng50.dll.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="" url="http://www.tippingpoint.com/security/advisories/TSRT-07-01.html"></ref><ref adv="1" source="" url="http://www.tippingpoint.com/security/advisories/TSRT-07-02.html"></ref><ref adv="1" patch="1" source="" url="http://esupport.trendmicro.com/support/viewxml.do?ContentID=EN-1034290"></ref><ref adv="1" source="" url="http://www.trendmicro.com/ftp/documentation/readme/spnt_558_win_en_securitypatch1_readme.txt"></ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/460686/100/0/threaded">

20070220 TSRT-07-01: Trend Micro ServerProtect StCommon.dll Stack Overflow Vulnerabilities</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/460690/100/0/threaded">
20070220 TSRT-07-02: Trend Micro ServerProtect eng50.dll Stack Overflow Vulnerabilities</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/349393">
VU#349393</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/466609">
VU#466609</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/630025">
VU#630025</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/730433">
VU#730433</ref><ref source="BID" url="http://www.securityfocus.com/bid/22639">
22639</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0670">
ADV-2007-0670</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017676">
1017676</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24243">
24243</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32594">
serverprotect-eng50-bo(32594)</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32601">
serverprotect-stcommon-bo(32601)</ref></refs><vuln_soft><prod name="ServerProtect" vendor="Trend Micro"><vers edition="EMC" num="5.58"/><vers edition="EMC" num="5.58"/><vers edition="Network Appliance Filer" num="5.61"/><vers edition="Network Appliance Filer" num="5.62"/></prod></vuln_soft></entry><entry CVSS_base_score="7.8" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.9" CVSS_score="7.8" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_version="2.0" modified="2007-03-26" name="CVE-2007-1071" published="2007-02-22" seq="2007-1071" severity="High" type="CVE"><desc><descript source="cve">Integer overflow in the gifGetBandProc function in ImageIO in Apple Mac OS X 10.4.8 allows remote attackers to cause a denial of service (segmentation fault) and possibly execute arbitrary code via a crafted GIF image that triggers the overflow during decompression.  NOTE: this is a different issue than CVE-2006-3502 and CVE-2006-3503.</descript></desc><loss_types><avail/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref source="" url="http://security-protocols.com/sp-x39-advisory.php"></ref><ref source="BID" url="http://www.securityfocus.com/bid/22630">22630</ref><ref source="" url="http://docs.info.apple.com/article.html?artnum=305214"></ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/559444">
VU#559444</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0930">
ADV-2007-0930</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017758">
1017758</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24479">
24479</ref><ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2007/Mar/msg00002.html">APPLE-SA-2007-03-13</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA07-072A.html">TA07-072A</ref><ref source="OSVDB" url="http://www.osvdb.org/34854">34854</ref></refs><vuln_soft><prod name="Mac OS X Server" vendor="Apple"><vers num="10.4.8"/></prod><prod name="Mac OS X" vendor="Apple"><vers num="10.4.8"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-02-23" name="CVE-2007-1072" published="2007-02-22" seq="2007-1072" severity="High" type="CVE"><desc><descript source="cve">The command line interface (CLI) in Cisco Unified IP Phone 7906G, 7911G, 7941G, 7961G, 7970G, and 7971G, with firmware 8.0(4)SR1 and earlier allows local users to obtain privileges or cause a denial of service via unspecified vectors.  NOTE: this issue can be leveraged remotely via CVE-2007-1063.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><access/><design/></vuln_types><range><local/></range><refs><ref patch="1" source="CISCO" url="http://www.cisco.com/warp/public/707/cisco-sa-20070221-phone.shtml">20070221 Cisco Unified IP Conference Station and IP Phone Vulnerabilities</ref><ref source="CISCO" url="http://www.cisco.com/warp/public/707/cisco-air-20070221-phone.shtml">20070221 Identifying and Mitigating Exploitation of Cisco Unified IP Conference Station and IP Phone Vulnerabilities</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24262">24262</ref><ref source="BID" url="http://www.securityfocus.com/bid/22647">
22647</ref></refs><vuln_soft><prod name="Unified IP Phone 7941G" vendor="Cisco"><vers edition="SR1" num="8.0(4)" prev="1"/></prod><prod name="Unified IP Phone 7906G" vendor="Cisco"><vers edition="SR1" num="8.0(4)" prev="1"/></prod><prod name="Unified IP Phone 7961G" vendor="Cisco"><vers edition="SR1" num="8.0(4)" prev="1"/></prod><prod name="Unified IP Phone 7971G" vendor="Cisco"><vers edition="SR1" num="8.0(4)" prev="1"/></prod><prod name="Unified IP Phone 7911G" vendor="Cisco"><vers edition="SR1" num="8.0(4)" prev="1"/></prod><prod name="Unified IP Phone 7970G" vendor="Cisco"><vers edition="SR1" num="8.0(4)" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-02-23" name="CVE-2007-1073" published="2007-02-22" seq="2007-1073" severity="High" type="CVE"><desc><descript source="cve">Static code injection vulnerability in install.php in mcRefer allows remote attackers to execute arbitrary PHP code via the bgcolor parameter, which is inserted into mcrconf.inc.php.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/459796/100/200/threaded">20070211 Re: mcRefer SQL injection</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2283">2283</ref></refs><vuln_soft><prod name="McRefer" vendor="McRefer"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" CVSS_score="9.3" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-02-23" name="CVE-2007-1074" published="2007-02-22" seq="2007-1074" severity="High" type="CVE"><desc><descript source="cve">Multiple buffer overflows in NewsBin Pro 5.33 and NewsBin Pro 4.x allow user-assisted remote attackers to execute arbitrary code via a long (1) DataPath or (2) DownloadPath attributed in a (a) NBI file, or (3) a long group field in a (b) NZB file.</descript></desc><impacts><impact source="nvd">Successful exploitation allows execution of arbitrary code, but requires that the user is tricked into e.g. loading a malicious NBI configuration file.</impact></impacts><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/><user_init/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3349">3349</ref><ref source="BID" url="http://www.securityfocus.com/bid/22652">22652</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24261">24261</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32598">newsbinpro-nbi-bo(32598)</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0694">
ADV-2007-0694</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32608">
newsbinpro-nzb-bo(32608)</ref></refs><vuln_soft><prod name="NewsBin Pro" vendor="DJI"><vers num="5.33"/><vers num="4.x"/></prod></vuln_soft></entry><entry CVSS_base_score="7.8" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.9" CVSS_score="7.8" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_version="2.0" modified="2007-02-23" name="CVE-2007-1075" published="2007-02-22" seq="2007-1075" severity="High" type="CVE"><desc><descript source="cve">TurboFTP 5.30 Build 572 allows remote servers to cause a denial of service (CPU consumption) via a response with a large number of newline characters.</descript></desc><loss_types><avail/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3341">3341</ref><ref source="BID" url="http://www.securityfocus.com/bid/22634">22634</ref></refs><vuln_soft><prod name="TurboFTP" vendor="TurboSoft"><vers edition="Build 572" num="5.3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-02-23" name="CVE-2007-1076" published="2007-02-22" seq="2007-1076" severity="High" type="CVE"><desc><descript source="cve">Multiple directory traversal vulnerabilities in phpTrafficA 1.4.1, and possibly earlier, allow remote attackers to include arbitrary local files via a .. (dot dot) in the (1) file parameter to plotStat.php and the (2) lang parameter to banref.php.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BID" url="http://www.securityfocus.com/bid/22655">22655</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24242">24242</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0709">
ADV-2007-0709</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32628">
phptraffica-plotstat-banref-file-include(32628)</ref><ref source="" url="http://soft.zoneo.net/phpTrafficA/news.php"></ref></refs><vuln_soft><prod name="phpTrafficA" vendor="phpTrafficA"><vers num="1.4.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-02-23" name="CVE-2007-1077" published="2007-02-22" seq="2007-1077" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in page.asp in Design4Online UserPages2 2.0 allows remote attackers to execute arbitrary SQL commands via the art_id parameter.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BID" url="http://www.securityfocus.com/bid/22636">22636</ref></refs><vuln_soft><prod name="UserPages2" vendor="Design4Online"><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-08-03" name="CVE-2007-1078" published="2007-02-22" seq="2007-1078" severity="High" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in index.php in FlashGameScript 1.5.4 allows remote attackers to execute arbitrary PHP code via a URL in the func parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BID" url="http://www.securityfocus.com/bid/22646">22646</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/460951/100/0/threaded">20070221 FlashGameScript v1.5.4 Remote File Inclusion Vulnerability</ref><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3360">3360</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0707">ADV-2007-0707</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24267">24267</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32635">flashgamescript-index-file-include(32635)</ref></refs><vuln_soft><prod name="FlashGameScript" vendor="FlashGameScript"><vers num="1.5.4"/></prod></vuln_soft></entry><entry CVSS_base_score="7.8" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.9" CVSS_score="7.8" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_version="2.0" modified="2007-02-23" name="CVE-2007-1079" published="2007-02-22" seq="2007-1079" severity="High" type="CVE"><desc><descript source="cve">Stack-based buffer overflow in Rhino Software, Inc. FTP Voyager 14.0.0.3 and earlier allows remote servers to cause a denial of service (crash) via a long response to a CWD command, which triggers the overflow when the user aborts the command.</descript></desc><loss_types><avail/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3343">3343</ref><ref source="BID" url="http://www.securityfocus.com/bid/22637">22637</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32593">ftpvoyager-cwd-dos(32593)</ref></refs><vuln_soft><prod name="FTP Voyager" vendor="RhinoSoft"><vers num="14.0.0.3" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.8" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.9" CVSS_score="7.8" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_version="2.0" modified="2007-02-23" name="CVE-2007-1080" published="2007-02-22" seq="2007-1080" severity="High" type="CVE"><desc><descript source="cve">Multiple heap-based buffer overflows in TurboFTP 5.30 Build 572 allow remote servers to cause a denial of service via (1) long filename in a response to a LIST command, and (2) a long response to a CWD command.</descript></desc><loss_types><avail/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3341">3341</ref><ref source="BID" url="http://www.securityfocus.com/bid/22634">22634</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32605">
turboftp-cwd-dos(32605)</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32604">
turboftp-list-dos(32604)</ref></refs><vuln_soft><prod name="TurboFTP" vendor="TurboSoft"><vers edition="Build 572" num="5.3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-03-06" name="CVE-2007-1081" published="2007-02-22" seq="2007-1081" severity="High" type="CVE"><desc><descript source="cve">The start function in class.t3lib_formmail.php in TYPO3 before 4.0.5, 4.1beta, and 4.1RC1 allows attackers to inject arbitrary email headers via unknown vectors.  NOTE: some details were obtained from third party information.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://typo3.org/teams/security/security-bulletins/typo3-20070221-1"></ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0697">ADV-2007-0697</ref><ref source="BID" url="http://www.securityfocus.com/bid/22668">
22668</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24207">
24207</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32630">
typo3-t3libformmail-field-email-injection(32630)</ref></refs><vuln_soft><prod name="TYPO3" vendor="TYPO3"><vers num="4.0.4" prev="1"/><vers edition="Beta" num="4.1" prev="1"/><vers edition="RC1" num="4.1" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.1" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.9" CVSS_score="7.1" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:C)" CVSS_version="2.0" modified="2007-06-25" name="CVE-2007-1082" published="2007-02-22" seq="2007-1082" severity="High" type="CVE"><desc><descript source="cve">FTP Explorer 1.0.1 Build 047, and other versions before 1.0.1.52, allows remote servers to cause a denial of service (CPU consumption) via a long response to a PWD command.</descript></desc><loss_types><avail/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3347">3347</ref><ref source="BID" url="http://www.securityfocus.com/bid/22640">22640</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32606">ftpexplorer-pwd-dos(32606)</ref><ref patch="1" source="VIM" url="http://www.attrition.org/pipermail/vim/2007-March/001470.html">20070324 Vendor ACK for FTPx DoS (CVE-2007-1082)</ref></refs><vuln_soft><prod name="FTP Explorer" vendor="FTPx"><vers num="1.0.1.47"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-08-02" name="CVE-2007-1083" published="2007-02-22" seq="2007-1083" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in the Configuration Checker (ConfigChk) ActiveX control in VSCnfChk.dll 2.0.0.2 for Verisign Managed PKI Service, Secure Messaging for Microsoft Exchange, and Go Secure! allows remote attackers to execute arbitrary code via long arguments to the VerCompare method.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/><user_init/></range><refs><ref source="IDEFENSE" url="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=479">20070222 VeriSign ConfigChk ActiveX Control Buffer Overflow Vulnerability</ref><ref source="" url="http://jvn.jp/cert/JVNVU%23308087/index.html"></ref><ref source="" url="http://www.jpcert.or.jp/at/2007/at070006.txt"></ref><ref adv="1" source="" url="https://download.verisign.co.jp/support/announce/20070216.html"></ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/308087">VU#308087</ref><ref source="BID" url="http://www.securityfocus.com/bid/22671">22671</ref><ref source="BID" url="http://www.securityfocus.com/bid/22676">22676</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0702">ADV-2007-0702</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017692">1017692</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017693">1017693</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017694">1017694</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24249">24249</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32639">verisign-configchk-bo(32639)</ref></refs><vuln_soft><prod name="MPKI" vendor="Verisign"><vers num="4.6.1"/><vers num="5.0"/><vers num="6.0"/><vers num="6.1.3" prev="1"/><vers num="7.0"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-08-03" name="CVE-2007-1084" published="2007-02-22" seq="2007-1084" severity="Medium" type="CVE"><desc><descript source="cve">Mozilla Firefox 2.0.0.1 and earlier does not prompt users before saving bookmarklets, which allows remote attackers to bypass the same-domain policy by tricking a user into saving a bookmarklet with a data: scheme, which is executed in the context of the last visited web page.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><network/><user_init/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/460885/100/0/threaded">20070221 Firefox bookmark cross-domain surfing vulnerability</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/460890/100/0/threaded">20070221 Re: [Full-disclosure] Firefox bookmark cross-domain surfing vulnerability</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/460896/100/0/threaded">20070221 Re: [Full-disclosure] Firefox bookmark cross-domain surfing vulnerability</ref><ref source="" url="http://lcamtuf.coredump.cx/ffbook"></ref><ref source="" url="https://bugzilla.mozilla.org/show_bug.cgi?id=371179"></ref><ref source="BID" url="http://www.securityfocus.com/bid/22666">22666</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/460896/100/0/threaded">20070222 Re: [Full-disclosure] Firefox bookmark cross-domain surfing vulnerability</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/461021/100/0/threaded">20070223 Re: [Full-disclosure] Firefox bookmark cross-domain surfingvulnerability</ref><ref source="" url="http://lcamtuf.coredump.cx/ffbook/"></ref><ref source="" url="http://www.heise-security.co.uk/news/85728"></ref><ref source="SREASON" url="http://securityreason.com/securityalert/2304">2304</ref></refs><vuln_soft><prod name="Firefox" vendor="Mozilla"><vers num="0.10"/><vers num="0.10.1"/><vers num="0.8"/><vers num="0.9"/><vers num="0.9.1"/><vers num="0.9.2"/><vers num="0.9.3"/><vers num="1.0"/><vers num="1.0.1"/><vers num="1.0.2"/><vers num="1.0.3"/><vers num="1.0.4"/><vers num="1.0.5"/><vers num="1.0.6"/><vers num="1.0.7"/><vers num="1.0.8"/><vers num="1.5"/><vers num="1.5.0.1"/><vers num="1.5.0.2"/><vers num="1.5.0.3"/><vers num="1.5.0.4"/><vers num="1.5.0.5"/><vers num="1.5.0.6"/><vers num="1.5.0.7"/><vers num="1.5.0.8"/><vers num="1.5.0.9"/><vers num="1.5.6"/><vers num="1.5.8"/><vers num="2.0"/><vers num="2.0.0.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="10.0" CVSS_score="7.6" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-03-06" name="CVE-2007-1085" published="2007-02-22" seq="2007-1085" severity="High" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in Google Desktop allows remote attackers to bypass protection schemes and inject arbitrary web script or HTML, and possibly gain full access to the system, by using an XSS vulnerability in google.com to extract the signature for the internal web server, then calling the &quot;under&quot; parameter in Advanced Search with the proper signature.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><access/><input/></vuln_types><range><network/><user_init/></range><refs><ref patch="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/460735/100/0/threaded">20070221 Overtaking Google Desktop</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/460928/100/0/threaded">20070222 RE: Overtaking Google Desktop</ref><ref source="" url="http://www.watchfire.com/resources/Overtaking-Google-Desktop.pdf"></ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/615857">VU#615857</ref><ref source="BID" url="http://www.securityfocus.com/bid/22650">22650</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017686">1017686</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2301">2301</ref></refs><vuln_soft><prod name="Google Desktop" vendor="Google"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-05-16" name="CVE-2007-1086" published="2007-02-23" seq="2007-1086" severity="High" type="CVE"><desc><descript source="cve">Unspecified binaries in IBM DB2 8.x before 8.1 FixPak 15 and 9.1 before Fix Pack 2 allow local users to create or modify arbitrary files via unspecified environment variables related to &quot;unsafe file access.&quot;</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref patch="1" source="IDEFENSE" url="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=481">20070222 IBM DB2 Universal Database Multiple Privilege Escalation Vulnerabilities</ref><ref source="AIXAPAR" url="http://www-1.ibm.com/support/docview.wss?uid=swg21255747">IY94833</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/22677">22677</ref><ref source="VIM" url="http://www.attrition.org/pipermail/vim/2007-August/001765.html">20070818 Recent DB2 Vulnerabilities</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32650">db2-setuid-privilege-escalation(32650)</ref></refs><vuln_soft><prod name="DB2 Universal Database" vendor="IBM"><vers edition="Linux" num="8.0"/><vers edition="AIX" num="8.1"/><vers num="8.1.4"/><vers num="8.1.5"/><vers num="8.1.6"/><vers num="8.1.6c"/><vers num="8.1.7"/><vers num="8.1.7b"/><vers num="8.1.8"/><vers num="8.1.8a"/><vers num="8.1.9"/><vers num="8.1.9a"/><vers num="8.10"/><vers num="8.12"/><vers edition="HP_UX" num="9.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-05-16" name="CVE-2007-1087" published="2007-02-23" seq="2007-1087" severity="High" type="CVE"><desc><descript source="cve">IBM DB2 8.x before 8.1 FixPak 15 and 9.1 before Fix Pack 2 does not properly terminate certain input strings, which allows local users to execute arbitrary code via unspecified environment variables that trigger a heap-based buffer overflow.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref patch="1" source="IDEFENSE" url="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=481">20070222 IBM DB2 Universal Database Multiple Privilege Escalation Vulnerabilities</ref><ref patch="1" source="AIXAPAR" url="http://www-1.ibm.com/support/docview.wss?uid=swg21255747">IY94833</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/22677">22677</ref><ref source="VIM" url="http://www.attrition.org/pipermail/vim/2007-August/001765.html">20070818 Recent DB2 Vulnerabilities</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32651">db2-bss-bo(32651)</ref></refs><vuln_soft><prod name="DB2 Universal Database" vendor="IBM"><vers edition="Linux" num="8.0" prev="1"/><vers num="8.0 FixPak13" prev="1"/><vers edition="AIX" num="8.1" prev="1"/><vers num="8.0 Fixpak14" prev="1"/><vers num="8.1.4" prev="1"/><vers num="8.1.5" prev="1"/><vers num="8.1.6" prev="1"/><vers num="8.1.6c" prev="1"/><vers num="8.1.7" prev="1"/><vers num="8.1.7b" prev="1"/><vers num="8.1.8" prev="1"/><vers num="8.1.8a" prev="1"/><vers num="8.1.9" prev="1"/><vers num="8.1.9a" prev="1"/><vers num="8.10" prev="1"/><vers num="8.12" prev="1"/><vers edition="HP_UX" num="9.1" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-05-16" name="CVE-2007-1088" published="2007-02-23" seq="2007-1088" severity="High" type="CVE"><desc><descript source="cve">Stack-based buffer overflow in IBM DB2 8.x before 8.1 FixPak 15 and 9.1 before Fix Pack 2 allows local users to execute arbitrary code via a long string in unspecified environment variables.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref patch="1" source="IDEFENSE" url="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=481">20070222 IBM DB2 Universal Database Multiple Privilege Escalation Vulnerabilities</ref><ref patch="1" source="AIXAPAR" url="http://www-1.ibm.com/support/docview.wss?uid=swg21255747">IY94833</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/22677">22677</ref><ref source="VIM" url="http://www.attrition.org/pipermail/vim/2007-August/001765.html">20070818 Recent DB2 Vulnerabilities</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32652">db2-variable-bo(32652)</ref></refs><vuln_soft><prod name="DB2 Universal Database" vendor="IBM"><vers edition="Linux" num="8.0" prev="1"/><vers num="8.0 FixPak13" prev="1"/><vers edition="AIX" num="8.1" prev="1"/><vers num="8.1 Fixpak10" prev="1"/><vers num="8.1 Fixpak11" prev="1"/><vers num="8.0 Fixpak14" prev="1"/><vers num="8.1 Fixpak8" prev="1"/><vers num="8.0 FixPak9" prev="1"/><vers num="8.1.4" prev="1"/><vers num="8.1.5" prev="1"/><vers num="8.1.6" prev="1"/><vers num="8.1.6c" prev="1"/><vers num="8.1.7" prev="1"/><vers num="8.1.7b" prev="1"/><vers num="8.1.8" prev="1"/><vers num="8.1.8a" prev="1"/><vers num="8.1.9" prev="1"/><vers num="8.1.9a" prev="1"/><vers num="8.10" prev="1"/><vers num="8.12" prev="1"/><vers edition="HP_UX" num="9.1" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-05-16" name="CVE-2007-1089" published="2007-02-23" seq="2007-1089" severity="High" type="CVE"><desc><descript source="cve">IBM DB2 Universal Database (UDB) 9.1 GA through 9.1 FP1 allows local users with table SELECT privileges to perform unauthorized UPDATE and DELETE SQL commands via unknown vectors.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref patch="1" source="AIXAPAR" url="http://www-1.ibm.com/support/docview.wss?uid=swg1JR25941">JR25941</ref><ref patch="1" source="SECUNIA" url="http://secunia.com/advisories/24283">24283</ref><ref source="VIM" url="http://www.attrition.org/pipermail/vim/2007-August/001765.html">20070818 Recent DB2 Vulnerabilities</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0721">ADV-2007-0721</ref></refs><vuln_soft><prod name="DB2 Universal Database" vendor="IBM"><vers edition="AIX" num="9.1 FixPack1" prev="1"/><vers num="9.1 GA"/></prod></vuln_soft></entry><entry CVSS_base_score="7.1" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.9" CVSS_score="7.1" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:C)" CVSS_version="2.0" modified="2007-04-26" name="CVE-2007-1090" published="2007-02-26" seq="2007-1090" severity="High" type="CVE"><desc><descript source="cve">Microsoft Windows Explorer on Windows XP and 2003 allows remote user-assisted attackers to cause a denial of service (crash) via a malformed WMF file, which triggers the crash when the user browses the folder.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/><user_init/></range><refs><ref source="" url="http://securityvulns.com/Qdocument170.html"></ref><ref source="" url="http://securityvulns.com/news/Microsoft/Windows/Explorer/DoS.html"></ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/461373/100/0/threaded">20070225 Few unreported vulnerabilities by SehaTo</ref><ref source="BID" url="http://www.securityfocus.com/bid/22715">22715</ref></refs><vuln_soft><prod name="Windows Explorer" vendor="Microsoft"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-02-27" name="CVE-2007-1091" published="2007-02-26" seq="2007-1091" severity="Medium" type="CVE"><desc><descript source="cve">Microsoft Internet Explorer 7 allows remote attackers to prevent users from leaving a site, spoof the address bar, and conduct phishing and other attacks via onUnload Javascript handlers.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/><exception/></vuln_types><range><network/><user_init/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/461023/100/0/threaded">20070223 MSIE7 browser entrapment vulnerability (probably Firefox, too)</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/461027/100/0/threaded">20070223 Secunia Research: Internet Explorer 7 </ref><ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2007-February/052630.html">20070223 MSIE7 browser entrapment vulnerability (probably Firefox, too)</ref><ref source="" url="http://lcamtuf.coredump.cx/ietrap"></ref><ref source="BID" url="http://www.securityfocus.com/bid/22680">22680</ref><ref patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0713">ADV-2007-0713</ref><ref patch="1" source="SECUNIA" url="http://secunia.com/advisories/23014">23014</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32647">ie-mozilla-onunload-dos(32647)</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32649">
ie-mozilla-onunload-url-spoofing(32649)</ref><ref source="HP" url="http://www.securityfocus.com/archive/1/archive/1/482366/100/0/threaded">HPSBST02280</ref><ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms07-057.mspx">MS07-057</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA07-282A.html">TA07-282A</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1018788">1018788</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2291">2291</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2162">oval:org.mitre.oval:def:2162</ref></refs><vuln_soft><prod name="Internet Explorer" vendor="Microsoft"><vers num="6.0"/><vers num="6.0 SP1"/><vers num="6.0 SP2"/><vers edition="Vista" num="7.0"/></prod></vuln_soft></entry><entry CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" CVSS_score="9.3" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-04-26" name="CVE-2007-1092" published="2007-02-26" seq="2007-1092" severity="High" type="CVE"><desc><descript source="cve">Mozilla Firefox 1.5.0.9 and 2.0.0.1, and SeaMonkey before 1.0.8 allow remote attackers to execute arbitrary code via JavaScript onUnload handlers that modify the structure of a document, wich triggers memory corruption due to the lack of a finalize hook on DOM window objects.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><design/></vuln_types><range><network/><user_init/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/461024/100/0/threaded">20070223 Firefox onUnload + document.write() memory corruption vulnerability (MSIE7 null ptr)</ref><ref source="" url="http://www.mozilla.org/security/announce/2007/mfsa2007-08.html"></ref><ref source="" url="https://bugzilla.mozilla.org/show_bug.cgi?id=371321"></ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/393921">VU#393921</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/22679">22679</ref><ref source="" url="https://issues.rpath.com/browse/RPL-1103"></ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2007:050">MDKSA-2007:050</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2007-0078.html">RHSA-2007:0078</ref><ref source="SUSE" url="http://lists.suse.com/archive/suse-security-announce/2007-Mar/0001.html">SUSE-SA:2007:019</ref><ref source="UBUNTU" url="http://www.ubuntu.com/usn/usn-428-1">USN-428-1</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017701">1017701</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24333">24333</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24343">24343</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24395">24395</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24384">24384</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32648">mozilla-onunload-code-execution(32648)</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32647">ie-mozilla-onunload-dos(32647)</ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20070301-01-P.asc">20070301-01-P</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24650">24650</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:050">MDKSA-2007:050</ref><ref source="SLACKWARE" url="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2007&amp;m=slackware-security.338131">SSA:2007-066-05</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2007_22_mozilla.html">SUSE-SA:2007:022</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24457">24457</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2302">2302</ref><ref source="HP" url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00771742">HPSBUX02153</ref></refs><vuln_soft><prod name="SeaMonkey" vendor="Mozilla"><vers num="1.0.7" prev="1"/></prod><prod name="Firefox" vendor="Mozilla"><vers num="1.5.0.9"/><vers num="2.0.0.1"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2008-03-31" name="CVE-2007-1093" published="2007-02-26" seq="2007-1093" severity="High" type="CVE"><desc><descript source="cve">Multiple unspecified vulnerabilities in JP1/Cm2/Network Node Manager (NNM) before 07-10-05, and before 08-00-02 in the 08-x series, allow remote attackers to execute arbitrary code, cause a denial of service, or trigger invalid Web utility behavior.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><range><network/></range><refs><ref patch="1" source="" url="http://www.hitachi-support.com/security_e/vuls_e/HS07-002_e/index-e.html"></ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/24276">24276</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0739">ADV-2007-0739</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32682">nnm-unspecified-code-execution(32682)</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32683">nnm-unspecified-dos(32683)</ref></refs><vuln_soft><prod name="JP1-Cm2-Network Node Manager 250" vendor="Hitachi"><vers num="05_20"/><vers num="05_20_E"/><vers num="06_00"/><vers num="06_50_A"/><vers num="06_51"/><vers num="06_71_C"/><vers num="05_20"/><vers num="05_20_E"/><vers num="05_20_F"/><vers num="06_00"/><vers num="06_50_A"/><vers num="06_51"/><vers num="06_71_C"/><vers num="06_71_D"/><vers num="05_20"/><vers num="05_20_E"/><vers num="06_00"/><vers num="06_50_A"/><vers num="06_51"/><vers num="06_71_C"/></prod><prod name="JP1-Cm2-Network Node Manager Starter" vendor="Hitachi"><vers edition="Enterprise" num="08_00"/><vers edition="Enterprise" num="08_00_01"/><vers edition="Enterprise" num="08_00"/><vers edition="Enterprise" num="08_00_01"/><vers edition="Enterprise" num="08_00"/><vers edition="Enterprise" num="08_00_01"/><vers edition="Enterprise" num="08_00"/><vers edition="Enterprise" num="08_00_01"/></prod><prod name="Cm2-Network Node Manager" vendor="Hitachi"><vers edition="Unlimited" num="05_00"/><vers edition="Enterprise" num="05_00"/><vers edition="Enterprise" num="05_00_C"/><vers edition="Enterprise" num="05_00"/></prod><prod name="JP1-Cm2-Network Node Manager Starter 250" vendor="Hitachi"><vers num="08_00"/><vers num="08_00_01"/><vers num="08_00"/><vers num="08_00_01"/><vers num="08_00"/><vers num="08_00_01"/><vers num="08_00"/><vers num="08_00_01"/></prod><prod name="Cm2-Network Node Manager 250" vendor="Hitachi"><vers num="05_00"/><vers num="05_00_C"/><vers num="05_00"/><vers num="05_00_A"/><vers num="05_00"/></prod><prod name="JP1-Cm2-Network Node Manager" vendor="Hitachi"><vers edition="Enterprise" num="05_20"/><vers edition="Enterprise" num="05_20_E"/><vers edition="Enterprise" num="06_00"/><vers edition="Enterprise" num="06_50_A"/><vers edition="Enterprise" num="06_51"/><vers edition="Enterprise" num="06_71_C"/><vers edition="Enterprise" num="05_20"/><vers edition="Enterprise" num="05_20_E"/><vers edition="Enterprise" num="05_20_F"/><vers edition="Enterprise" num="06_00"/><vers edition="Enterprise" num="06_50_A"/><vers edition="Enterprise" num="06_51"/><vers edition="Enterprise" num="06_71_C"/><vers edition="Enterprise" num="06_71_D"/><vers edition="Enterprise" num="05_20"/><vers edition="Enterprise" num="05_20_E"/><vers edition="Enterprise" num="06_00"/><vers edition="Enterprise" num="06_50_A"/><vers edition="Enterprise" num="06_51"/><vers edition="Enterprise" num="06_71_C"/><vers num="07_00"/><vers num="07_10_04"/><vers num="07_00"/><vers num="07_10_04"/><vers num="07_00"/><vers num="07_10_04"/></prod></vuln_soft></entry><entry CVSS_base_score="7.8" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.9" CVSS_score="7.8" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_version="2.0" modified="2007-06-27" name="CVE-2007-1094" published="2007-02-26" seq="2007-1094" severity="High" type="CVE"><desc><descript source="cve">Microsoft Internet Explorer 7 allows remote attackers to cause a denial of service (NULL dereference and application crash) via JavaScript onUnload handlers that modify the structure of a document.</descript></desc><loss_types><avail/></loss_types><vuln_types><race/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/461024/100/0/threaded">20070223 Firefox onUnload + document.write() memory corruption vulnerability (MSIE7 null ptr)</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/22678">22678</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32647">ie-mozilla-onunload-dos(32647)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2302">2302</ref></refs><vuln_soft><prod name="Internet Explorer" vendor="Microsoft"><vers num="6.0"/><vers num="6.0 SP1"/><vers num="6.0 SP2"/><vers edition="Vista" num="7.0"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2008-01-02" name="CVE-2007-1095" published="2007-02-26" seq="2007-1095" severity="Medium" type="CVE"><desc><descript source="cve">Mozilla Firefox before 2.0.0.8 and SeaMonkey before 1.1.5 do not properly implement JavaScript onUnload handlers, which allows remote attackers to run certain JavaScript code and access the location DOM hierarchy in the context of the next web site that is visited by a client.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><network/><user_init/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/461007/100/0/threaded">20070223 Firefox: onUnload tailgating (MSIE7 entrapment bug variant)</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/461023/100/0/threaded">20070223 MSIE7 browser entrapment vulnerability (probably Firefox, too)</ref><ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2007-February/052630.html">20070223 MSIE7 browser entrapment vulnerability (probably Firefox, too)</ref><ref source="" url="http://lcamtuf.coredump.cx/ietrap/ff/"></ref><ref source="" url="https://bugzilla.mozilla.org/show_bug.cgi?id=371360"></ref><ref source="BID" url="http://www.securityfocus.com/bid/22688">22688</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32647">ie-mozilla-onunload-dos(32647)</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32649">ie-mozilla-onunload-url-spoofing(32649)</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/482925/100/0/threaded">20071029 FLEA-2007-0062-1 firefox</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/482876/100/200/threaded">20071026 rPSA-2007-0225-1 firefox</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/482932/100/200/threaded">20071029 rPSA-2007-0225-2 firefox thunderbird</ref><ref source="" url="http://www.mozilla.org/security/announce/2007/mfsa2007-30.html"></ref><ref source="" url="https://issues.rpath.com/browse/RPL-1858"></ref><ref source="" url="http://support.novell.com/techcenter/psdb/60eb95b75c76f9fbfcc9a89f99cd8f79.html"></ref><ref source="DEBIAN" url="http://www.debian.org/security/2007/dsa-1396">DSA-1396</ref><ref source="DEBIAN" url="http://www.debian.org/security/2007/dsa-1401">DSA-1401</ref><ref source="DEBIAN" url="http://www.debian.org/security/2007/dsa-1392">DSA-1392</ref><ref source="FEDORA" url="https://www.redhat.com/archives/fedora-package-announce/2007-October/msg00285.html">FEDORA-2007-2601</ref><ref source="FEDORA" url="https://www.redhat.com/archives/fedora-package-announce/2007-October/msg00355.html">FEDORA-2007-2664</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200711-14.xml">GLSA-200711-14</ref><ref source="MANDRIVA" url="http://www.mandriva.com/en/security/advisories?name=MDKSA-2007:202">MDKSA-2007:202</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2007-0979.html">RHSA-2007:0979</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2007-0980.html">RHSA-2007:0980</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2007-0981.html">RHSA-2007:0981</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2007_57_mozilla.html">SUSE-SA:2007:057</ref><ref source="UBUNTU" url="http://www.ubuntulinux.org/support/documentation/usn/usn-535-1">USN-535-1</ref><ref source="UBUNTU" url="http://www.ubuntu.com/usn/usn-536-1">USN-536-1</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/3544">ADV-2007-3544</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1018837">1018837</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/27276">27276</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/27325">27325</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/27327">27327</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/27335">27335</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/27356">27356</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/27383">27383</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/27425">27425</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/27403">27403</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/27480">27480</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/27387">27387</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/27298">27298</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/27311">27311</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/27315">27315</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/27336">27336</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/27665">27665</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/27414">27414</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2310">2310</ref><ref source="FEDORA" url="https://www.redhat.com/archives/fedora-package-announce/2007-November/msg00498.html">FEDORA-2007-3431</ref><ref source="SECUNIA" url="http://secunia.com/advisories/27680">27680</ref><ref source="HP" url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00771742">HPSBUX02153</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/3587">ADV-2007-3587</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/0083">ADV-2008-0083</ref><ref source="SECUNIA" url="http://secunia.com/advisories/27360">27360</ref><ref source="SECUNIA" url="http://secunia.com/advisories/28398">28398</ref><ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-66-201516-1">201516</ref></refs><vuln_soft><prod name="SeaMonkey" vendor="Mozilla"><vers num="1.1.5" prev="1"/></prod><prod name="Firefox" vendor="Mozilla"><vers num="2.0"/><vers edition="Beta 1" num="2.0"/><vers edition="RC2" num="2.0"/><vers edition="RC3" num="2.0"/><vers num="2.0.0.1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-02-27" name="CVE-2007-1096" published="2007-02-26" seq="2007-1096" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in ps_cart.php in VirtueMart before 20070116 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.  NOTE: this issue might overlap CVE-2007-0376.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://virtuemart.svn.sourceforge.net/viewvc/*checkout*/virtuemart/trunk/virtuemart/CHANGELOG.php?revision=692"></ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0817">
ADV-2007-0817</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24399">
24399</ref></refs><vuln_soft><prod name="Virtuemart" vendor="VirtueMart"><vers num="1.0.8" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-04-16" name="CVE-2007-1097" published="2007-02-26" seq="2007-1097" severity="High" type="CVE"><desc><descript source="cve">Unrestricted file upload vulnerability in the onAttachFiles function in the upload tool (inc/lib/attachment.lib.php) in Wiclear before 0.11.1 allows remote attackers to upload and execute arbitrary PHP code via unspecified vectors related to filename validation.  NOTE: some details were obtained from third party information.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://wiclear.free.fr/?Download"></ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0792">ADV-2007-0792</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24286">24286</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32757">wiclear-onattachfiles-file-upload(32757)</ref></refs><vuln_soft><prod name="WiClear" vendor="WiClear"><vers num="0.11" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.8" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.9" CVSS_score="7.8" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_version="2.0" modified="2007-02-27" name="CVE-2007-1098" published="2007-02-26" seq="2007-1098" severity="High" type="CVE"><desc><descript source="cve">Multiple unspecified vulnerabilities in ScryMUD before 2.1.11 have unknown impact and attack vectors, possibly related to denial of service caused by a search that begins with a .* sequence.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/><exception/></vuln_types><range><network/></range><refs><ref source="MLIST" url="http://www.wanfear.com/pipermail/scrymud/2007q1/001157.html">[ScryMUD] 20070223 ScryMUD 2.1.11 (stable) has been released.</ref><ref source="" url="http://scrymud.net/downloads/Changelog-2.1.10-2.1.11.txt"></ref></refs><vuln_soft><prod name="ScryMUD" vendor="ScryMUD"><vers num="2.1.10" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-03-01" name="CVE-2007-1099" published="2007-02-26" seq="2007-1099" severity="High" type="CVE"><desc><descript source="cve">dbclient in Dropbear SSH client before 0.49 does not sufficiently warn the user when it detects a hostkey mismatch, which might allow remote attackers to conduct man-in-the-middle attacks.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref source="" url="http://matt.ucc.asn.au/dropbear/CHANGES"></ref><ref source="BID" url="http://www.securityfocus.com/bid/22761">
22761</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0785">
ADV-2007-0785</ref><ref source="OSVDB" url="http://www.osvdb.org/32088">
32088</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24345">
24345</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32762">
dropbear-hostkey-weak-security(32762)</ref></refs><vuln_soft><prod name="Dropbear SSH Server" vendor="Matt Johnston"><vers num="0.40"/><vers num="0.41"/><vers num="0.42"/><vers num="0.43"/><vers num="0.44"/><vers num="0.44test1"/><vers num="0.44test2"/><vers num="0.44test3"/><vers num="0.44test4"/><vers num="0.45"/><vers num="0.46"/><vers num="0.47"/><vers num="0.48"/><vers num="0.48.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.8" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.9" CVSS_score="7.8" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:N/A:N)" CVSS_version="2.0" modified="2007-04-16" name="CVE-2007-1100" published="2007-02-26" seq="2007-1100" severity="High" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in download.php in Ahmet Sacan Pickle before 20070301 allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/461145/100/0/threaded">20070223 pickle download local file</ref><ref source="BID" url="http://www.securityfocus.com/bid/22703">22703</ref><ref source="" url="http://user.ceng.metu.edu.tr/~ahmet/Wiki/Software/pickle/pickle"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0748">ADV-2007-0748</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24294">24294</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32712">pickle-download-directory-traversal(32712)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2293">2293</ref></refs><vuln_soft><prod name="picKLE" vendor="picKLE"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" modified="2007-04-16" name="CVE-2007-1101" published="2007-02-26" seq="2007-1101" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Photostand 1.2.0 allow remote attackers to inject arbitrary web script or HTML via the (1) message (&quot;comment&quot;) or (2) name field, or the (3) q parameter in a search action in index.php.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/461150/100/0/threaded">20070224 Photostand_1.2.0 Multiple Cross Site Scripting</ref><ref source="BID" url="http://www.securityfocus.com/bid/22706">22706</ref><ref source="BID" url="http://www.securityfocus.com/bid/22707">22707</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0752">ADV-2007-0752</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24310">24310</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32701">photostand-index-xss(32701)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2296">2296</ref></refs><vuln_soft><prod name="Photostand" vendor="Photostand"><vers num="1.2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0" modified="2007-02-27" name="CVE-2007-1102" published="2007-02-26" seq="2007-1102" severity="Medium" type="CVE"><desc><descript source="cve">Photostand 1.2.0 allows remote attackers to obtain sensitive information via a &apos; (quote) character in (1) a PHPSESSID cookie or (2) the id parameter in an article action in index.php, which reveal the path in various error messages.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/461150/100/0/threaded">20070224 Photostand_1.2.0 Multiple Cross Site Scripting</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0752">
ADV-2007-0752</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32702">
photostand-index-path-disclosure(32702)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2296">2296</ref></refs><vuln_soft><prod name="Photostand" vendor="Photostand"><vers num="1.2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)" CVSS_version="2.0" modified="2007-02-27" name="CVE-2007-1103" published="2007-02-26" seq="2007-1103" severity="Medium" type="CVE"><desc><descript source="cve">Tor does not verify a node&apos;s uptime and bandwidth advertisements, which allows remote attackers who operate a low resource node to make false claims of greater resources, which places the node into use for many circuits and compromises the anonymity of traffic sources and destinations.</descript></desc><loss_types><conf/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref source="MLIST" url="http://archives.seul.org/or/talk/Feb-2007/msg00197.html">[or-talk] 20070225 </ref><ref source="MLIST" url="http://archives.seul.org/or/talk/Feb-2007/msg00200.html">[or-talk] 20070225 Re: </ref><ref source="MLIST" url="http://archives.seul.org/or/talk/Feb-2007/msg00202.html">[or-talk] 20070225 Re: ISP controlling entry/exti (</ref><ref source="" url="http://www.cs.colorado.edu/department/publications/reports/docs/CU-CS-1025-07.pdf"></ref></refs><vuln_soft><prod name="Tor" vendor="Tor"><vers num="0.1.1.26" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" modified="2007-02-27" name="CVE-2007-1104" published="2007-02-26" seq="2007-1104" severity="Medium" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in top.php in PHP Module Implementation (PHP-MIP) 0.1 allows remote attackers to execute arbitrary PHP code via a URL in the laypath parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3374">3374</ref><ref source="BID" url="http://www.securityfocus.com/bid/22714">
22714</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0732">
ADV-2007-0732</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32672">
phpmodule-top-file-include(32672)</ref></refs><vuln_soft><prod name="PHP MIP" vendor="PHP MIP"><vers num="0.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" modified="2007-02-27" name="CVE-2007-1105" published="2007-02-26" seq="2007-1105" severity="Medium" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in functions.php in Extreme phpBB (aka phpBB Extreme) 3.0.1 allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3370">3370</ref><ref source="BID" url="http://www.securityfocus.com/bid/22708">22708</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0733">
ADV-2007-0733</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32685">
extremephpbb-functions-file-include(32685)</ref></refs><vuln_soft><prod name="Extreme phpBB" vendor="Extreme phpBB"><vers num="3.0.1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-02-27" name="CVE-2007-1106" published="2007-02-26" seq="2007-1106" severity="Medium" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in includes/functions_nomoketos_rules.php in the NoMoKeTos Rules 0.0.1 module for phpBB allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3373">3373</ref><ref source="BID" url="http://www.securityfocus.com/bid/22713">22713</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0735">
ADV-2007-0735</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32686">
nomoketo-functions-file-include(32686)</ref></refs><vuln_soft><prod name="NoMoKeTos Rules" vendor="NoMoKeTos Rules"><vers num="0.0.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-02-27" name="CVE-2007-1107" published="2007-02-26" seq="2007-1107" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in thumbnails.php in Coppermine Photo Gallery (CPG) 1.3.x allows remote authenticated users to execute arbitrary SQL commands via a cpg131_fav cookie.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/461158/100/0/threaded">20070224 Coppermine Photo Gallery 1.3.x Blind SQL Injection Exploit</ref><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3371">3371</ref><ref source="BID" url="http://www.securityfocus.com/bid/22709">
22709</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32688">
coppermine-thumbnails-sql-injection(32688)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2297">2297</ref></refs><vuln_soft><prod name="Photo Gallery" vendor="Coppermine"><vers num="1.3.2"/><vers num="1.3.3"/><vers num="1.3.4"/></prod><prod name="Coppermine Photo Gallery" vendor="Coppermine"><vers num="1.3"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-02-27" name="CVE-2007-1108" published="2007-02-26" seq="2007-1108" severity="Medium" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in index.php in Christian Schneider CS-Gallery 2.0 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the album parameter during a securealbum todo action.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3372">3372</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/22712">22712</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0734">
ADV-2007-0734</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24291">
24291</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32674">
csgallery-index-file-include(32674)</ref></refs><vuln_soft><prod name="CS-Gallery" vendor="CS-Gallery"><vers num="2.0" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" modified="2007-08-02" name="CVE-2007-1109" published="2007-02-26" seq="2007-1109" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Phpwebgallery 1.4.1 allow remote attackers to inject arbitrary web script or HTML via the (1) login or (2) mail_address field in Register.php, or the (3) search_author, (4) mode, (5) start_year, (6) end_year, or (7) date_type field in Search.php, a different vulnerability than CVE-2006-1674.  NOTE: 1.6.2 and other versions might also be affected.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/461160/100/0/threaded">20070224 Phpwebgallery-1.4.1, Multiple Cross Site Scripting</ref><ref source="BID" url="http://www.securityfocus.com/bid/22711">22711</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24308">24308</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32687">phpwebgallery-register-search-xss(32687)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2298">2298</ref></refs><vuln_soft><prod name="PhpWebGallery" vendor="PhpWebGallery"><vers num="1.6.1" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0" modified="2007-02-27" name="CVE-2007-1110" published="2007-02-26" seq="2007-1110" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in data/showcode.php in ActiveCalendar 1.2.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the page parameter.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/461146/100/0/threaded">20070224 ActiveCalendar 1.2.0, Multiple vulnerabilities</ref><ref source="BID" url="http://www.securityfocus.com/bid/22704">22704</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/461313/100/0/threaded">
20070224 Re: ActiveCalendar 1.2.0, Multiple vulnerabilities</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0759">
ADV-2007-0759</ref><ref source="OSVDB" url="http://www.osvdb.org/33144">
33144</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32691">
activecalendar-showcode-file-include(32691)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2299">2299</ref></refs><vuln_soft><prod name="ActiveCalendar" vendor="ActiveCalendar"><vers num="1.2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-02-27" name="CVE-2007-1111" published="2007-02-26" seq="2007-1111" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in ActiveCalendar 1.2.0 allow remote attackers to inject arbitrary web script or HTML via the css parameter to (1) flatevents.php, (2) js.php, (3) mysqlevents.php, (4) m_2.php, (5) m_3.php, (6) m_4.php, (7) xmlevents.php, (8) y_2.php, or (9) y_3.php in data/.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/461146/100/0/threaded">20070224 ActiveCalendar 1.2.0, Multiple vulnerabilities</ref><ref source="BID" url="http://www.securityfocus.com/bid/22705">22705</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/461313/100/0/threaded">
20070224 Re: ActiveCalendar 1.2.0, Multiple vulnerabilities</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0759">
ADV-2007-0759</ref><ref source="OSVDB" url="http://www.osvdb.org/33145">
33145</ref><ref source="OSVDB" url="http://www.osvdb.org/33146">
33146</ref><ref source="OSVDB" url="http://www.osvdb.org/33147">
33147</ref><ref source="OSVDB" url="http://www.osvdb.org/33148">
33148</ref><ref source="OSVDB" url="http://www.osvdb.org/33149">
33149</ref><ref source="OSVDB" url="http://www.osvdb.org/33150">
33150</ref><ref source="OSVDB" url="http://www.osvdb.org/33153">
33153</ref><ref source="OSVDB" url="http://www.osvdb.org/33151">
33151</ref><ref source="OSVDB" url="http://www.osvdb.org/33152">
33152</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32690">
activecalendar-multiple-scripts-xss(32690)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2299">2299</ref></refs><vuln_soft><prod name="ActiveCalendar" vendor="ActiveCalendar"><vers num="1.2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-04-06" name="CVE-2007-1112" published="2007-04-05" seq="2007-1112" severity="High" type="CVE"><desc><descript source="cve">Kaspersky Anti-Virus 6.0 and Internet Security 6.0 exposes unsafe methods in the (a) AXKLPROD60Lib.KAV60Info (AxKLProd60.dll) and (b) AXKLSYSINFOLib.SysInfo (AxKLSysInfo.dll) ActiveX controls, which allows remote attackers to &quot;download&quot; or delete arbitrary files via crafted arguments to the (1) DeleteFile, (2) StartBatchUploading, (3) StartStrBatchUploading, or (4) StartUploading methods.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="" url="http://www.zerodayinitiative.com/advisories/ZDI-07-014.html"></ref><ref patch="1" source="" url="http://www.kaspersky.com/technews?id=203038694"></ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1268">ADV-2007-1268</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/24778">24778</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/464882/100/0/threaded">

20070405 ZDI-07-014: Kaspersky Anti-Virus ActiveX Control Unsafe Method Exposure Vulnerablity</ref><ref source="BID" url="http://www.securityfocus.com/bid/23345">
23345</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017884">
1017884</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017885">
1017885</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33464">
kaspersky-startuploading-info-disclosure(33464)</ref></refs><vuln_soft><prod name="Kaspersky Internet Security" vendor="Kaspersky Lab"><vers num="6.0"/></prod><prod name="Kaspersky Anti-Virus" vendor="Kaspersky Lab"><vers num="6.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" modified="2007-02-27" name="CVE-2007-1114" published="2007-02-26" seq="2007-1114" severity="Medium" type="CVE"><desc><descript source="cve">The child frames in Microsoft Internet Explorer 7 inherit the default charset from the parent window when a charset is not specified in an HTTP Content-Type header or META tag, which allows remote attackers to conduct cross-site scripting (XSS) attacks, as demonstrated using the UTF-7 character set.</descript></desc><loss_types><int/></loss_types><vuln_types><design/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" source="" url="http://www.hardened-php.net/advisory_032007.142.html"></ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/461076/100/0/threaded">

20070223 Advisory 03/2007: Multiple Browsers Cross Domain Charset Inheritance Vulnerability</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0744">
ADV-2007-0744</ref><ref source="OSVDB" url="http://www.osvdb.org/32119">
32119</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24314">
24314</ref><ref source="BID" url="http://www.securityfocus.com/bid/22701">
22701</ref></refs><vuln_soft><prod name="Internet Explorer" vendor="Microsoft"><vers edition="Vista" num="7.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="4.9" CVSS_score="5.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:N)" CVSS_version="2.0" modified="2007-08-02" name="CVE-2007-1115" published="2007-02-26" seq="2007-1115" severity="Medium" type="CVE"><desc><descript source="cve">The child frames in Opera 9 before 9.20 inherit the default charset from the parent window when a charset is not specified in an HTTP Content-Type header or META tag, which allows remote attackers to conduct cross-site scripting (XSS) attacks, as demonstrated using the UTF-7 character set.</descript></desc><loss_types><conf/><int/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="" url="http://www.hardened-php.net/advisory_032007.142.html"></ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/461076/100/0/threaded">20070223 Advisory 03/2007: Multiple Browsers Cross Domain Charset Inheritance Vulnerability</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0745">ADV-2007-0745</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24312">24312</ref><ref source="" url="http://www.opera.com/support/search/view/855/"></ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017909">1017909</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2007_28_opera.html">SUSE-SA:2007:028</ref><ref source="BID" url="http://www.securityfocus.com/bid/22701">22701</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/25027">25027</ref></refs><vuln_soft><prod name="Opera" vendor="Opera Software"><vers num="9.0"/><vers num="9.01"/><vers num="9.02"/><vers num="9.10"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0" modified="2007-04-16" name="CVE-2007-1116" published="2007-02-26" seq="2007-1116" severity="Medium" type="CVE"><desc><descript source="cve">The CheckLoadURI function in Mozilla Firefox 1.8 lists the about: URI as a ChromeProtocol and can be loaded via JavaScript, which allows remote attackers to obtain sensitive information by querying the browser&apos;s session history.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/461006/100/0/threaded">20070223 Firefox Cache Hack - Firefox History Hack redux</ref><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/461013/100/0/threaded">20070223 Re: [Full-disclosure] Firefox Cache Hack - Firefox History Hack redux</ref><ref adv="1" source="" url="http://www.gnucitizen.org/projects/hscan-redux/"></ref><ref adv="1" patch="1" source="" url="https://bugzilla.mozilla.org/show_bug.cgi?id=371375"></ref><ref source="SREASON" url="http://securityreason.com/securityalert/2309">2309</ref></refs><vuln_soft><prod name="Firefox" vendor="Mozilla"><vers num="2.0.0.2" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-02-27" name="CVE-2007-1117" published="2007-02-26" seq="2007-1117" severity="High" type="CVE"><desc><descript source="cve">Unspecified vulnerability in Publisher 2007 in Microsoft Office 2007 allows remote attackers to execute arbitrary code via unspecified vectors, related to a &quot;file format vulnerability.&quot; NOTE: this information is based upon a vague pre-advisory with no actionable information.  However, the advisory is from a reliable source.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><range><network/></range><refs><ref adv="1" source="" url="http://news.com.com/2100-1002_3-6161835.html"></ref><ref adv="1" source="" url="http://research.eeye.com/html/advisories/upcoming/20070216.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/22702">
22702</ref></refs><vuln_soft><prod name="Publisher" vendor="Microsoft"><vers num="2007"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-02-27" name="CVE-2007-1118" published="2007-02-26" seq="2007-1118" severity="Medium" type="CVE"><desc><descript source="cve">Multiple PHP remote file inclusion vulnerabilities in eFiction 3.1.1 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the path_to_smf parameter to (1) bridges/SMF/logout.php or (2) get_session_vars.php.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3361">3361</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/22682">22682</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0708">ADV-2007-0708</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24268">24268</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32662">
efiction-pathtosmf-file-include(32662)</ref></refs><vuln_soft><prod name="efiction" vendor="efiction"><vers num="3.1.1" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.4" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="4.9" CVSS_score="6.4" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_version="2.0" modified="2007-02-28" name="CVE-2007-1119" published="2007-02-26" seq="2007-1119" severity="Medium" type="CVE"><desc><descript source="cve">Unspecified vulnerability in Novell ZENworks 7 Desktop Management Support Pack 1 before Hot patch 3 (ZDM7SP1HP3) allows remote attackers to upload images to certain folders that were not configured in the &quot;Only allow uploads to the following directories&quot; setting via unspecified vectors.</descript></desc><loss_types><conf/><int/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="" url="https://secure-support.novell.com/KanisaPlatform/Publishing/408/3563780_f.SAL_Public.html"></ref><ref patch="1" source="" url="https://secure-support.novell.com/KanisaPlatform/Publishing/650/3484245_f.SAL_Public.html"></ref><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/22686">22686</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0712">ADV-2007-0712</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/24274">24274</ref></refs><vuln_soft><prod name="ZENworks" vendor="Novell"><vers edition="Support Pack 1" num="7"/></prod></vuln_soft></entry><entry CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" CVSS_score="9.3" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-02-28" name="CVE-2007-1120" published="2007-02-26" seq="2007-1120" severity="High" type="CVE"><desc><descript source="cve">The (1) Import.LoadFromURL and (2) Export.asText.SaveToFile functions in TeeChart Pro ActiveX control (TeeChart7.ocx) allow remote attackers to download a crafted .tee file to an arbitrary location.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><design/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/22689">22689</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24263">24263</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32694">
teechart-activex-file-upload(32694)</ref></refs><vuln_soft><prod name="TeeChart Pro" vendor="Steema Software"><vers num="7.0.1.3"/></prod></vuln_soft></entry><entry CVSS_base_score="6.4" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="4.9" CVSS_score="6.4" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_version="2.0" modified="2007-02-27" name="CVE-2007-1121" published="2007-02-26" seq="2007-1121" severity="Medium" type="CVE"><desc><descript source="cve">Multiple SQL injection vulnerabilities in Mathis Dirksen-Thedens ZephyrSoft Toolbox Address Book Continued (ABC) 1.00 allow remote attackers to execute arbitrary SQL commands via the id parameter to the (1) updateRow and (2) deleteRow functions in functions.php.  NOTE: some of these details are obtained from third party information.</descript></desc><loss_types><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref patch="1" source="" url="http://sourceforge.net/project/shownotes.php?release_id=488406"></ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/22685">22685</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0715">ADV-2007-0715</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/24269">24269</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32665">
zephyrsoft-id-sql-injection(32665)</ref></refs><vuln_soft><prod name="ZephyrSoft Toolbox Address Book Continued" vendor="Zephyr"><vers num="1.00"/><vers num="1.01"/></prod></vuln_soft></entry><entry CVSS_base_score="6.4" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="4.9" CVSS_score="6.4" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_version="2.0" modified="2007-02-28" name="CVE-2007-1122" published="2007-02-26" seq="2007-1122" severity="Medium" type="CVE"><desc><descript source="cve">Multiple SQL injection vulnerabilities in Mathis Dirksen-Thedens ZephyrSoft Toolbox Address Book Continued (ABC) 1.00 and 1.01 allow remote attackers to execute arbitrary SQL commands via the id parameter to the (1) updateRow and (2) deleteRow functions in functions.php, a variant of a SQL injection issue that was fixed in 1.01.  NOTE: some of these details are obtained from third party information.</descript></desc><loss_types><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://sourceforge.net/project/downloading.php?group_id=153333&amp;use_mirror=osdn&amp;filename=abc-1.02.zip"></ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/22685">22685</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0715">ADV-2007-0715</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24269">24269</ref></refs><vuln_soft><prod name="Address Book Continued" vendor="ZephyrSoft Toolbox"><vers num="1.01"/><vers num="1.00"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-03-07" name="CVE-2007-1123" published="2007-02-26" seq="2007-1123" severity="High" type="CVE"><desc><descript source="cve">Multiple PHP remote file inclusion vulnerabilities in ZPanel 2.0 allow remote attackers to execute arbitrary PHP code via a URL in (1) the body parameter to templates/ZPanelV2/template.php or (2) the page parameter to zpanel.php.  NOTE: the zpanel.php vector may overlap CVE-2005-0793.2.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/22683">22683</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0710">ADV-2007-0710</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24275">24275</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/32659">zpanel-template-file-include(32659)</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32680">
zpanel-zpanel-file-include(32680)</ref></refs><vuln_soft><prod name="ZPanel" vendor="ZPanel"><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0" modified="2007-02-28" name="CVE-2007-1124" published="2007-02-26" seq="2007-1124" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in gallery.php in XeroXer Simple one-file gallery allows remote attackers to read arbitrary files via a .. (dot dot) in the f parameter.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/461080/100/0/threaded">20070223 Simple one-file gallery</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/22700">22700</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32654">
sofg-gallery-file-include(32654)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2292">2292</ref></refs><vuln_soft><prod name="Simple one-file gallery" vendor="XeroXer"><vers num="0.6" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" modified="2007-02-28" name="CVE-2007-1125" published="2007-02-26" seq="2007-1125" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in gallery.php in XeroXer Simple one-file gallery allows remote attackers to inject arbitrary web script or HTML via the f parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/461080/100/0/threaded">20070223 Simple one-file gallery</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/22700">22700</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0740">
ADV-2007-0740</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24292">
24292</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32655">
sofg-gallery-xss(32655)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2292">2292</ref></refs><vuln_soft><prod name="Simple one-file gallery" vendor="XeroXer"><vers num="0.6" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0" modified="2007-02-28" name="CVE-2007-1126" published="2007-02-26" seq="2007-1126" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in index.php in xtcommerce allows remote attackers to read arbitrary files via a .. (dot dot) in the template parameter.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/461073/100/0/threaded">20070223 xtcommerce local file include</ref><ref source="BID" url="http://www.securityfocus.com/bid/22698">
22698</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0746">
ADV-2007-0746</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24301">
24301</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32656">
xtcommerce-index-file-include(32656)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2294">2294</ref></refs><vuln_soft><prod name="XT-Commerce Community Made Shopping" vendor="XT-Commerce"><vers edition="RC 1.2" num="2.0" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.4" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="4.9" CVSS_score="6.4" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_version="2.0" modified="2007-02-28" name="CVE-2007-1127" published="2007-02-26" seq="2007-1127" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in enc/stylecss.php in shopkitplus allows remote attackers to read arbitrary files via a .. (dot dot) in the changetheme parameter.</descript></desc><loss_types><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/461071/100/0/threaded">20070223 shopkitplus local file include</ref><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/22697">22697</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0747">
ADV-2007-0747</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24279">
24279</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32660">
shopkitplus-stylecss-file-include(32660)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2295">2295</ref></refs><vuln_soft><prod name="Shop Kit Plus" vendor="Watersweb Shops"><vers num="Initial"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0" modified="2007-02-28" name="CVE-2007-1128" published="2007-02-26" seq="2007-1128" severity="Medium" type="CVE"><desc><descript source="cve">shopkitplus allows remote attackers to obtain sensitive information via a request to (1) events.php with a curmonth[]=01 query string or (2) enc/stylecss.php with a changetheme[]= query string, which reveals the path in various error messages.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/><design/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/461071/100/0/threaded">20070223 shopkitplus local file include</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32661">
shopkitplus-events-stylecss-info-disclosure(32661)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2295">2295</ref></refs><vuln_soft><prod name="Shop Kit Plus" vendor="Watersweb Shops"><vers num="Initial"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-04-16" name="CVE-2007-1129" published="2007-02-26" seq="2007-1129" severity="High" type="CVE"><desc><descript source="cve">Multiple unrestricted file upload vulnerabilities in MTCMS 3.2 allow remote attackers to upload and execute files via (1) an avatar upload in an add_down action, or (2) an add_link action.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BID" url="http://www.securityfocus.com/bid/22690">22690</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/461330/100/100/threaded">20070223 MTCMS multiple upload vulnerabilities</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0755">ADV-2007-0755</ref></refs><vuln_soft><prod name="MTCMS" vendor="MTCMS"><vers num="2.2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-02-28" name="CVE-2007-1130" published="2007-02-26" seq="2007-1130" severity="High" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in sinagb.php in Sinapis Gastebuch 2.2 allows remote attackers to execute arbitrary PHP code via a URL in the fuss parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3366">3366</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/22696">22696</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0737">
ADV-2007-0737</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32657">
sinapis-gastebuch-sinagb-file-include(32657)</ref></refs><vuln_soft><prod name="Gastebuch" vendor="Sinapis"><vers num="2.2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-02-28" name="CVE-2007-1131" published="2007-02-26" seq="2007-1131" severity="High" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in sinapis.php in Sinapis Forum 2.2 allows remote attackers to execute arbitrary PHP code via a URL in the fuss parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3367">3367</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/22699">22699</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0738">
ADV-2007-0738</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32658">
sinapisforum-sinapis-file-include(32658)</ref></refs><vuln_soft><prod name="Sinapis Forum" vendor="Scripter.ch"><vers num="2.2"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" modified="2007-04-16" name="CVE-2007-1132" published="2007-02-26" seq="2007-1132" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in the &quot;Contact Us&quot; functionality in MTCMS 2.2 allow remote attackers to inject arbitrary web script or HTML via the (1) message and (2) title fields.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/22690">22690</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/461330/100/100/threaded">20070223 MTCMS multiple upload vulnerabilities</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0755">ADV-2007-0755</ref></refs><vuln_soft><prod name="MTCMS" vendor="MTCMS"><vers num="2.2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-03-02" name="CVE-2007-1133" published="2007-02-26" seq="2007-1133" severity="High" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in fcring.php in FCRing 1.3 allows remote attackers to execute arbitrary PHP code via a URL in the s_fuss parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3365">3365</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/22693">22693</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0736">
ADV-2007-0736</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24305">
24305</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32653">
fcring-fcring-file-include(32653)</ref></refs><vuln_soft><prod name="FCRing" vendor="Scripter.ch"><vers num="1.3"/><vers num="1.31"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-03-06" name="CVE-2007-1134" nvd_name="Watchtower Unspecified Authentication Bypass Vulnerability" published="2007-03-02" seq="2007-1134" severity="Medium" type="CVE"><desc><descript source="cve">Unspecified vulnerability in Watchtower (WT) before 0.12 has unknown impact and attack vectors, related to &quot;unauthorized accounts.&quot;</descript></desc><sols><sol source="nvd">The vendor has released version 0.12 to address this issue.  
Watchtower wt0.12.tar.gz

Download: http://downloads.sourceforge.net/wtelements/wt0.12.tar.gz?modtime=1171 460836&amp;big_mirror=0
</sol></sols><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref source="" url="http://sourceforge.net/project/shownotes.php?release_id=486435&amp;group_id=188798"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0743">ADV-2007-0743</ref><ref source="BID" url="http://www.securityfocus.com/bid/22721">
22721</ref></refs><vuln_soft><prod name="Watchtower" vendor="SourceForge"><vers num="0.11"/><vers num="0.1alpha"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-03-05" name="CVE-2007-1135" published="2007-03-02" seq="2007-1135" severity="Medium" type="CVE"><desc><descript source="cve">Multiple SQL injection vulnerabilities in WebMplayer before 0.6.1-Alpha allow remote attackers to execute arbitrary SQL commands via the (1) strid parameter to index.php and the (2) id[0] or other id array index parameter to filecheck.php.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref patch="1" source="" url="http://sourceforge.net/project/shownotes.php?release_id=486880&amp;group_id=172354"></ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0742">ADV-2007-0742</ref><ref source="BID" url="http://www.securityfocus.com/bid/22726">
22726</ref></refs><vuln_soft><prod name="WebMplayer" vendor="SourceForge"><vers num="0.6.1-alpha" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-03-05" name="CVE-2007-1136" published="2007-03-02" seq="2007-1136" severity="Medium" type="CVE"><desc><descript source="cve">index.php in WebMplayer before 0.6.1-Alpha allows remote attackers to execute arbitrary code via shell metacharacters in an exec function call.  NOTE: some sources have referred to this as eval injection in the param parameter, but CVE source inspection suggests that this is erroneous.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://sourceforge.net/project/shownotes.php?release_id=486880&amp;group_id=172354"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0742">ADV-2007-0742</ref><ref source="BID" url="http://www.securityfocus.com/bid/22726">
22726</ref></refs><vuln_soft><prod name="WebMplayer" vendor="SourceForge"><vers num="0.6.1-alpha" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0" modified="2007-03-05" name="CVE-2007-1137" published="2007-03-02" seq="2007-1137" severity="Medium" type="CVE"><desc><descript source="cve">putmail.py in Putmail before 1.4 does not detect when a user attempts to use TLS with a server that does not support it, which causes putmail.py to send the username and password in plaintext while the user believes encryption is in use, and allows remote attackers to obtain sensitive information.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref source="" url="http://putmail.sourceforge.net/home.html"></ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24266">24266</ref><ref source="BID" url="http://www.securityfocus.com/bid/22718">
22718</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0753">
ADV-2007-0753</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32689">
putmail-tls-password-plaintext(32689)</ref></refs><vuln_soft><prod name="Putmail" vendor="SourceForge"><vers num=".10"/><vers num=".11"/><vers num=".12"/><vers num=".8"/><vers num=".9"/><vers num="1.0"/><vers num="1.1"/><vers num="1.2"/><vers num="1.3"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-03-05" name="CVE-2007-1138" published="2007-03-02" seq="2007-1138" severity="High" type="CVE"><desc><descript source="cve">Absolute path traversal vulnerability in list_main_pages.php in Cromosoft Simple Plantilla PHP (SPP) allows remote attackers to list arbitrary directories, and read arbitrary files, via an absolute pathname in the nfolder parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/460913/100/0/threaded">20070222 Plantilla PHP Simple</ref><ref source="BID" url="http://www.securityfocus.com/bid/22669">22669</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2332">2332</ref></refs><vuln_soft><prod name="Simple Plantilla PHP" vendor="Cromosoft Technologies"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-03-05" name="CVE-2007-1139" published="2007-03-02" seq="2007-1139" severity="High" type="CVE"><desc><descript source="cve">Unrestricted file upload vulnerability in Cromosoft Simple Plantilla PHP (SPP) allows remote attackers to upload arbitrary scripts via a filename with a double extension.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/460913/100/0/threaded">20070222 Plantilla PHP Simple</ref><ref source="BID" url="http://www.securityfocus.com/bid/22669">22669</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2332">2332</ref></refs><vuln_soft><prod name="Simple Plantilla PHP" vendor="Cromosoft Technologies"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-03-05" name="CVE-2007-1140" published="2007-03-02" seq="2007-1140" severity="High" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in edit.php in pheap allows remote attackers to read and modify arbitrary files via a .. (dot dot) in the filename parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/460920/100/0/threaded">20070222 pheap [edit LFI] vulnerability</ref><ref source="BID" url="http://www.securityfocus.com/bid/22670">22670</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2354">2354</ref></refs><vuln_soft><prod name="Pheap" vendor="Pheap"><vers num="1.0"/><vers num="1.1"/><vers num="1.3"/><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-03-05" name="CVE-2007-1141" published="2007-03-02" seq="2007-1141" severity="Medium" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in preview.php in Magic News Plus 1.0.2 allows remote attackers to execute arbitrary PHP code via a URL in the php_script_path parameter.  NOTE: This issue may overlap CVE-2006-0723.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/460902/100/0/threaded">20070221 Magic News Plus File Inclusion And Xss Vulnerabilitis</ref><ref source="BID" url="http://www.securityfocus.com/bid/22661">22661</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2334">2334</ref></refs><vuln_soft><prod name="Magic News Plus" vendor="Reamday Enterprises"><vers num="1.0.2"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-03-05" name="CVE-2007-1142" published="2007-03-02" seq="2007-1142" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in Magic News Plus 1.0.2 allows remote attackers to inject arbitrary web script or HTML via the link_parameters parameter in (1) news.php and (2) n_layouts.php.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/460902/100/0/threaded">20070221 Magic News Plus File Inclusion And Xss Vulnerabilitis</ref><ref source="BID" url="http://www.securityfocus.com/bid/22661">22661</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2334">2334</ref></refs><vuln_soft><prod name="Magic News Plus" vendor="Reamday Enterprises"><vers num="1.0.2"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-03-05" name="CVE-2007-1143" nvd_name="J-Web Pics Navigator Jwpn-Photos.PHP Directory Traversal Vulnerability" published="2007-03-02" seq="2007-1143" severity="High" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in pn-menu.php in J-Web Pics Navigator 1.0 allows remote attackers to list arbitrary directories via a .. (dot dot) in the dir parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/460907/100/0/threaded">20070222 Pics Navigator Directory Traversal Vulnerability</ref><ref source="" url="http://forums.avenir-geopolitique.net/viewtopic.php?t=2692"></ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32646">
picsnavigator-dir-directory-traversal(32646)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2340">2340</ref></refs><vuln_soft><prod name="J-Web Pics Navigator" vendor="ComScripts"><vers num="1.0"/><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" CVSS_score="9.3" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-03-05" name="CVE-2007-1144" nvd_name="J-Web Pics Navigator Jwpn-Photos.PHP Directory Traversal Vulnerability" published="2007-03-02" seq="2007-1144" severity="High" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in jwpn-photos.php in J-Web Pics Navigator 2.0 allows remote attackers to list arbitrary directories via a .. (dot dot) in the dir parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/460907/100/0/threaded">20070222 Pics Navigator Directory Traversal Vulnerability</ref><ref source="" url="http://forums.avenir-geopolitique.net/viewtopic.php?t=2692"></ref><ref source="BID" url="http://www.securityfocus.com/bid/22681">
22681</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0711">
ADV-2007-0711</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24273">
24273</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32646">
picsnavigator-dir-directory-traversal(32646)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2340">2340</ref></refs><vuln_soft><prod name="J-Web Pics Navigator" vendor="ComScripts"><vers num="1.0"/><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" modified="2008-03-04" name="CVE-2007-1145" published="2007-03-02" seq="2007-1145" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Kayako SupportSuite - ESupport 3.00.13 and 3.04.10 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors related to a (1) lostpassword or (2) register action in index.php, (3) unspecified vectors in the Submit form in a submit action in index.php, and (4) the user&apos;s name in index.php; and (5) allow remote authenticated users to inject arbitrary web script or HTML via unspecified vectors related to the Admin and Staff Control Panel. NOTE: this might issue overlap CVE-2004-1412, CVE-2005-0487, or CVE-2005-0842.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/460591/100/0/threaded">20070219 ESupport Multiple HTML Injection Vulnerabilities</ref><ref source="BID" url="http://www.securityfocus.com/bid/22631">22631</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0717">ADV-2007-0717</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24223">24223</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2335">2335</ref></refs><vuln_soft><prod name="eSupport" vendor="Kayako"><vers num="3.00.13"/><vers num="3.04.10"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-03-06" name="CVE-2007-1146" published="2007-03-02" seq="2007-1146" severity="High" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in function.php in arabhost allows remote attackers to execute arbitrary PHP code via a URL in the adminfolder parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/460933/100/0/threaded">20070222 Hasadya Raed</ref><ref source="VIM" url="http://attrition.org/pipermail/vim/2007-February/001396.html">20070227 Verified: arabhost function.php RFI</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2339">2339</ref></refs><vuln_soft><prod name="arabhost" vendor="Delmaa.com"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2008-03-04" name="CVE-2007-1147" published="2007-03-02" seq="2007-1147" severity="High" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in view.php in hbm allows remote attackers to execute arbitrary PHP code via a URL in the hbmpath parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/460933/100/0/threaded">20070222 Hasadya Raed</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2339">2339</ref></refs><vuln_soft><prod name="hbm" vendor="hbm"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2008-03-04" name="CVE-2007-1148" published="2007-03-02" seq="2007-1148" severity="High" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in install/index.php in LoveCMS 1.4 allows remote attackers to execute arbitrary PHP code via a URL in the step parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/460917/100/0/threaded">20070222 LoveCMS 1.4 multiple vulnerabilities</ref><ref source="BID" url="http://www.securityfocus.com/bid/22675">22675</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0716">ADV-2007-0716</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2338">2338</ref></refs><vuln_soft><prod name="LoveCMS" vendor="LoveCMS"><vers num="1.4"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0" modified="2008-03-04" name="CVE-2007-1149" published="2007-03-02" seq="2007-1149" severity="Medium" type="CVE"><desc><descript source="cve">Multiple directory traversal vulnerabilities in LoveCMS 1.4 allow remote attackers to read arbitrary files via a .. (dot dot) in (1) the step parameter to install/index.php or (2) the load parameter to the top-level URI.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/460917/100/0/threaded">20070222 LoveCMS 1.4 multiple vulnerabilities</ref><ref source="BID" url="http://www.securityfocus.com/bid/22675">22675</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0716">ADV-2007-0716</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2338">2338</ref></refs><vuln_soft><prod name="LoveCMS" vendor="LoveCMS"><vers num="1.4"/></prod></vuln_soft></entry><entry CVSS_base_score="3.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="4.9" CVSS_score="3.6" CVSS_vector="(AV:N/AC:H/Au:S/C:N/I:P/A:P)" CVSS_version="2.0" modified="2008-03-04" name="CVE-2007-1150" published="2007-03-02" seq="2007-1150" severity="Low" type="CVE"><desc><descript source="cve">Unrestricted file upload vulnerability in LoveCMS 1.4 allows remote authenticated administrators to upload arbitrary files to /modules/content/pictures/tmp/.</descript></desc><loss_types><avail/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/460917/100/0/threaded">20070222 LoveCMS 1.4 multiple vulnerabilities</ref><ref source="BID" url="http://www.securityfocus.com/bid/22675">22675</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2338">2338</ref></refs><vuln_soft><prod name="LoveCMS" vendor="LoveCMS"><vers num="1.4"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" modified="2008-03-04" name="CVE-2007-1151" published="2007-03-02" seq="2007-1151" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in LoveCMS 1.4 allows remote attackers to inject arbitrary web script or HTML via the id parameter to the top-level URI, possibly related to a SQL error.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/460917/100/0/threaded">20070222 LoveCMS 1.4 multiple vulnerabilities</ref><ref source="BID" url="http://www.securityfocus.com/bid/22675">22675</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0716">ADV-2007-0716</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2338">2338</ref></refs><vuln_soft><prod name="LoveCMS" vendor="LoveCMS"><vers num="1.4"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0" modified="2008-03-04" name="CVE-2007-1152" published="2007-03-02" seq="2007-1152" severity="Medium" type="CVE"><desc><descript source="cve">Multiple directory traversal vulnerabilities in Pyrophobia 2.1.3.1 allow remote attackers to read arbitrary files via a .. (dot dot) in the (1) act or (2) pid parameter to the top-level URI, or the (3) action parameter to admin/index.php.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript></desc><loss_types><conf/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref source="BID" url="http://www.securityfocus.com/bid/22667">22667</ref></refs><vuln_soft><prod name="Pyrophobia" vendor="Pyrophobia"><vers num="2.1.3.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2008-03-04" name="CVE-2007-1153" published="2007-03-02" seq="2007-1153" severity="High" type="CVE"><desc><descript source="cve">Multiple PHP remote file inclusion vulnerabilities in CutePHP CuteNews 1.3.6 allow remote attackers to execute arbitrary PHP code via unspecified vectors.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. NOTE: issue might overlap CVE-2004-1660 or CVE-2006-4445.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BID" url="http://www.securityfocus.com/bid/22674">22674</ref></refs><vuln_soft><prod name="CuteNews" vendor="CutePHP"><vers num="1.3.6"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2008-03-04" name="CVE-2007-1154" published="2007-03-02" seq="2007-1154" severity="Medium" type="CVE"><desc><descript source="cve">SQL injection vulnerability in webSPELL allows remote attackers to execute arbitrary SQL commands via a ws_auth cookie, a different vulnerability than CVE-2006-4782.</descript></desc><impacts><impact source="nvd">Successful exploitation requires that &quot;magic_quotes_gpc&quot; is disabled.</impact></impacts><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/460937/100/0/threaded">20070222 WebSpell &gt; 4.0 Authentication Bypass and arbitrary code execution</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32669">webspell-login-sql-injection(32669)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2337">2337</ref></refs><vuln_soft><prod name="webSPELL" vendor="webSPELL"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:N/AC:H/Au:S/C:P/I:P/A:P)" CVSS_version="2.0" modified="2008-02-29" name="CVE-2007-1155" published="2007-03-02" seq="2007-1155" severity="Medium" type="CVE"><desc><descript source="cve">Unrestricted file upload vulnerability in webSPELL allows remote authenticated administrators to upload and execute arbitrary PHP code via the add squad feature.  NOTE: this issue may be an administrative feature, in which case this CVE may be REJECTED.</descript></desc><impacts><impact source="nvd">Affected product versions unspecified.</impact></impacts><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/460937/100/0/threaded">20070222 WebSpell &gt; 4.0 Authentication Bypass and arbitrary code execution</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32670">webspell-addsquad-file-upload(32670)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2337">2337</ref></refs><vuln_soft><prod name="webSPELL" vendor="webSPELL"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-03-06" name="CVE-2007-1156" published="2007-03-02" seq="2007-1156" severity="High" type="CVE"><desc><descript source="cve">JBrowser allows remote attackers to bypass authentication and access certain administrative capabilities via a direct request for _admin/.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/460923/100/0/threaded">20070222 JBrowser acces to admin/config files</ref><ref source="" url="http://forums.avenir-geopolitique.net/viewtopic.php?t=2693"></ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/461298/100/100/threaded">
20070223 JBrowser Acces to Admin Panel Exploit</ref><ref source="BID" url="http://www.securityfocus.com/bid/9537">9537</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1008909">1008909</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2370">2370</ref></refs><vuln_soft><prod name="JBrowser" vendor="Man Machine Systems"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="10.0" CVSS_score="7.6" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2008-02-29" name="CVE-2007-1157" published="2007-03-02" seq="2007-1157" severity="High" type="CVE"><desc><descript source="cve">Cross-site request forgery (CSRF) vulnerability in jmx-console/HtmlAdaptor in JBoss allows remote attackers to perform privileged actions as administrators via certain MBean operations, a different vulnerability than CVE-2006-3733.</descript></desc><impacts><impact source="nvd">Affected product versions unspecified.</impact></impacts><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/460934/100/0/threaded">20070222 JBoss jmx-console CSRF</ref><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/461004/100/0/threaded">20070223 Re: JBoss jmx-console CSRF</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32673">jboss-jmxconsole-csrf(32673)</ref></refs><vuln_soft><prod name="JBoss" vendor="JBoss"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0" discovered="2007-02-08" modified="2007-03-06" name="CVE-2007-1158" published="2007-03-02" seq="2007-1158" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in index.php in the Pagesetter 6.2.0 through 6.3.0 beta 5 module for PostNuke allows remote attackers to read arbitrary files via a .. (dot dot) in the id parameter.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/461339/100/0/threaded">20070226 SEC Consult SA-20070226-0 :: File Disclosure in Pagesetter for PostNuke</ref><ref adv="1" source="FULLDISC" url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=117251821622820&amp;w=2">20070226 SEC Consult SA-20070226-0 :: File Disclosure in</ref><ref source="FULLDISC" url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=117256698219502&amp;w=2">20070227 Re:SEC Consult SA-20070226-0 :: File Disclosure</ref><ref source="" url="http://www.elfisk.dk/index.php?module=pagesetter&amp;func=viewpub&amp;tid=7&amp;pid=125"></ref><ref source="BID" url="http://www.securityfocus.com/bid/22733">22733</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/24299">24299</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0758">
ADV-2007-0758</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32695">
pagesetter-index-directory-traversal(32695)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2336">2336</ref></refs><vuln_soft><prod name="Pagesetter" vendor="PostNuke Software Foundation"><vers num="6.2"/><vers edition="Beta 5" num="6.3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" modified="2008-02-29" name="CVE-2007-1159" published="2007-03-02" seq="2007-1159" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in modules/out.php in Pyrophobia 2.1.3.1 allows remote attackers to inject arbitrary web script or HTML via the id parameter.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref source="BID" url="http://www.securityfocus.com/bid/22667">22667</ref></refs><vuln_soft><prod name="Pyrophobia" vendor="Pyrophobia"><vers num="2.1.3.1"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2008-02-29" name="CVE-2007-1160" published="2007-03-02" seq="2007-1160" severity="High" type="CVE"><desc><descript source="cve">webSPELL 4.0, and possibly later versions, allows remote attackers to bypass authentication via a ws_auth cookie, a different vulnerability than CVE-2006-4782.</descript></desc><impacts><impact source="nvd">This vulnerability may affect more recent versions of the product as well. (WebSPELL, WebSPELL, 4.0 and later)</impact></impacts><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><access/><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/460937/100/0/threaded">20070222 WebSpell &gt; 4.0 Authentication Bypass and arbitrary code execution</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2337">2337</ref></refs><vuln_soft><prod name="webSPELL" vendor="webSPELL"><vers num="4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" modified="2008-02-29" name="CVE-2007-1161" published="2007-03-02" seq="2007-1161" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in call_entry.php in Call Center Software 0,93 allows remote attackers to inject arbitrary web script or HTML via the problem_desc parameter, as demonstrated by the ONLOAD attribute of a BODY element.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/460797/100/0/threaded">20070221 Call Center Software - Remote Xss Post Exploit -</ref><ref source="VIM" url="http://www.attrition.org/pipermail/vim/2007-February/001378.html">20070222 [TRUE] Call Center Software - Remote Xss Post Exploit -</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2333">2333</ref></refs><vuln_soft><prod name="Call Center Software" vendor="Call Center Software"><vers num="0.93"/></prod></vuln_soft></entry><entry CVSS_base_score="7.8" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.9" CVSS_score="7.8" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_version="2.0" modified="2007-03-06" name="CVE-2007-1162" published="2007-03-02" seq="2007-1162" severity="High" type="CVE"><desc><descript source="cve">A certain ActiveX control in the Common Controls Replacement Project (CCRP) CCRP BrowseDialog Server (ccrpbds6.dll) allows remote attackers to cause a denial of service (Internet Explorer 7 crash) via a long (1) IsFolderAvailable or (2) RootFolder property value, different vectors than CVE-2007-0371.</descript></desc><loss_types><avail/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref source="" url="http://www.securityfocus.com/data/vulnerabilities/exploits/22645.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/22645">22645</ref></refs><vuln_soft><prod name="BrowseDialog Server" vendor="Common Controls Replacement Project"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2008-02-29" name="CVE-2007-1163" published="2007-03-02" seq="2007-1163" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in printview.php in webSPELL 4.01.02 and earlier allows remote attackers to execute arbitrary SQL commands via the topic parameter, a different vector than CVE-2007-1019, CVE-2006-5388, and CVE-2006-4783.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3351">3351</ref><ref source="BID" url="http://www.securityfocus.com/bid/22659">22659</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0714">ADV-2007-0714</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24257">24257</ref></refs><vuln_soft><prod name="webSPELL" vendor="webSPELL"><vers num="4.0"/><vers num="4.01.00"/><vers num="4.01.01"/><vers num="4.01.02" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2008-02-29" name="CVE-2007-1164" published="2007-03-02" seq="2007-1164" severity="High" type="CVE"><desc><descript source="cve">Multiple PHP remote file inclusion vulnerabilities in DBImageGallery 1.2.2 allow remote attackers to execute arbitrary PHP code via a URL in the donsimg_base_path parameter to (1) attributes.php, (2) images.php, or (3) scan.php in admin/; or (4) attributes.php, (5) db_utils.php, (6) images.php, (7) utils.php, or (8) values.php in includes/.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3353">3353</ref><ref source="BID" url="http://www.securityfocus.com/bid/22657">22657</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/461741/100/0/threaded">20070302 Remote File Include In DBImageGallery</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/462142/100/0/threaded">20070305 Re: Remote File Include In DBImageGallery</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0692">ADV-2007-0692</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32612">dbimagegallery-donsimg-file-include(32612)</ref></refs><vuln_soft><prod name="DBImageGallery" vendor="DBScripts"><vers num="1.2.2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2008-02-29" name="CVE-2007-1165" published="2007-03-02" seq="2007-1165" severity="High" type="CVE"><desc><descript source="cve">Multiple PHP remote file inclusion vulnerabilities in DBGuestbook 1.1 allow remote attackers to execute arbitrary PHP code via a URL in the dbs_base_path parameter to (1) utils.php, (2) guestbook.php, or (3) views.php in includes/.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3354">3354</ref><ref source="BID" url="http://www.securityfocus.com/bid/22658">22658</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0693">ADV-2007-0693</ref></refs><vuln_soft><prod name="DBGuestbook" vendor="DBScripts"><vers num="1.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2008-02-29" name="CVE-2007-1166" published="2007-03-02" seq="2007-1166" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in result.php in Nabopoll 1.2 allows remote attackers to execute arbitrary SQL commands via the surv parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/460765/100/0/threaded">20070221 Nabopoll Blind SQL Injection vulnerabilies</ref><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3355">3355</ref><ref source="BID" url="http://www.securityfocus.com/bid/22649">22649</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2372">2372</ref></refs><vuln_soft><prod name="nabopoll" vendor="Nabocorp"><vers num="1.2"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0" modified="2008-02-29" name="CVE-2007-1167" published="2007-03-02" seq="2007-1167" severity="Medium" type="CVE"><desc><descript source="cve">inc/filebrowser/browser.php in deV!L`z Clanportal (DZCP) 1.4.5 and earlier allows remote attackers to obtain MySQL data via the inc/mysql.php value of the file parameter.</descript></desc><sols><sol source="nvd">This vulnerability is addressed in the following product release:
1.4.6</sol></sols><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3357">3357</ref><ref source="" url="http://www.dzcp.de/inc/tinymce_files/Downloads/dzcp_update/notes_1.4.6.txt"></ref><ref source="BID" url="http://www.securityfocus.com/bid/22660">22660</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/24260">24260</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0695">ADV-2007-0695</ref></refs><vuln_soft><prod name="Clanportal" vendor="DZCP"><vers num="1.4.5" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-04-05" name="CVE-2007-1168" published="2007-03-02" seq="2007-1168" severity="High" type="CVE"><desc><descript source="cve">Trend Micro ServerProtect for Linux (SPLX) 1.25, 1.3, and 2.5 before 20070216 allows remote attackers to access arbitrary web pages and reconfigure the product via HTTP requests with the splx_2376_info cookie to the web interface port (14942/tcp).</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/><design/></vuln_types><range><network/></range><refs><ref adv="1" source="IDEFENSE" url="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=477">20070221 Trend Micro ServerProtect Web Interface Authorization Bypass Vulnerability</ref><ref patch="1" source="" url="http://www.trendmicro.com/download/product.asp?productid=20"></ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/22662">22662</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0691">ADV-2007-0691</ref><ref patch="1" source="SECTRACK" url="http://securitytracker.com/id?1017685">1017685</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/24264">24264</ref></refs><vuln_soft><prod name="ServerProtect" vendor="Trend Micro"><vers edition="Linux" num="1.25_2007-02-16"/><vers edition="Linux" num="1.3"/><vers edition="Linux" num="2.5"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0" modified="2007-06-05" name="CVE-2007-1169" published="2007-03-02" seq="2007-1169" severity="Medium" type="CVE"><desc><descript source="cve">The web interface in Trend Micro ServerProtect for Linux (SPLX) 1.25, 1.3, and 2.5 before 20070216 accepts logon requests through unencrypted HTTP, which might allow remote attackers to obtain credentials by sniffing the network.</descript></desc><loss_types><conf/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref patch="1" source="" url="http://www.trendmicro.com/download/product.asp?productid=20"></ref></refs><vuln_soft><prod name="ServerProtect" vendor="Trend Micro"><vers edition="Linux" num="1.25_2007-02-16"/><vers edition="1.3" num="1.25_2007-02-16"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0" modified="2007-03-06" name="CVE-2007-1170" published="2007-03-02" seq="2007-1170" severity="Medium" type="CVE"><desc><descript source="cve">SimBin GTR - FIA GT Racing Game 1.5.0.0 and earlier, GT Legends 1.1.0.0 and earlier, GTR 2 1.1 and earlier, and RACE - The WTCC Game 1.0 and earlier allow remote attackers to cause a denial of service (client disconnection) via an empty UDP packet to the server port.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/460762/100/0/threaded">20070221 Players disconnection in Simbin racing games</ref><ref source="BID" url="http://www.securityfocus.com/bid/22651">22651</ref><ref source="" url="http://aluigi.altervista.org/adv/simbinzero-adv.txt"></ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0696">
ADV-2007-0696</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2369">2369</ref></refs><vuln_soft><prod name="Race - The WTCC Game" vendor="SimBin"><vers num="1.0" prev="1"/></prod><prod name="GTR 2" vendor="SimBin"><vers num="1.1" prev="1"/></prod><prod name="GTR - FIA GET Racing Game" vendor="SimBin"><vers num="1.5.0.0" prev="1"/></prod><prod name="GT Legends" vendor="SimBin"><vers num="1.1.0.0" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2008-01-02" name="CVE-2007-1171" published="2007-03-02" seq="2007-1171" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in includes/nsbypass.php in NukeSentinel 2.5.05, 2.5.11, and other versions before 2.5.12 allows remote attackers to execute arbitrary SQL commands via an admin cookie.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/460628/100/0/threaded">20070220 NukeSentinel 2.5.05 (nsbypass.php) Blind SQL Injection Exploit</ref><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3337">3337</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/22629">22629</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32582">nukesentinel-nsbypass-sql-injection(32582)</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/480575/100/0/threaded">20070925 [waraxe-2007-SA#053] - Critical Sql Injection in NukeSentinel 2.5.11</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/480994/100/0/threaded">20070928 Re: [waraxe-2007-SA#053] - Critical Sql Injection in NukeSentinel 2.5.11</ref><ref source="" url="http://www.waraxe.us/advisory-53.html"></ref><ref source="" url="http://www.nukescripts.net/index.php?op=NEArticle&amp;sid=4076"></ref><ref source="VIM" url="http://www.attrition.org/pipermail/vim/2007-September/001806.html">20070928 CVE-2007-5125 - dupe</ref><ref source="BID" url="http://www.securityfocus.com/bid/25805">25805</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/26954">26954</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2344">2344</ref></refs><vuln_soft><prod name="NukeSentinel" vendor="NukeScripts"><vers num="2.5.11" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.4" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="4.9" CVSS_score="6.4" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_version="2.0" modified="2007-03-06" name="CVE-2007-1172" published="2007-03-02" seq="2007-1172" severity="Medium" type="CVE"><desc><descript source="cve">SQL injection vulnerability in nukesentinel.php in NukeSentinel 2.5.05, and possibly earlier, allows remote attackers to execute arbitrary SQL commands via the Client-IP HTTP header, aka the &quot;File Disclosure Exploit.&quot;</descript></desc><loss_types><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/460599/100/0/threaded">20070220 NukeSentinel 2.5.05 (nukesentinel.php) File Disclosure Exploit</ref><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3338">3338</ref><ref source="VIM" url="http://attrition.org/pipermail/vim/2007-March/001429.html">
20070314 SQL injection (x2) in NukeSentinel</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24221">
24221</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2341">2341</ref></refs><vuln_soft><prod name="NukeSentinel" vendor="NukeScripts"><vers num="2.5.05"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-05-24" name="CVE-2007-1173" published="2007-05-16" seq="2007-1173" severity="High" type="CVE"><desc><descript source="cve">Multiple buffer overflows in the CentennialIPTransferServer service (XFERWAN.EXE), as used by (1) Centennial Discovery 2006 Feature Pack 1, (2) Numara Asset Manager 8.0, and (3) Symantec Discovery 6.5, allow remote attackers to execute arbitrary code via long strings in a crafted TCP packet.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="" url="http://secunia.com/secunia_research/2007-41/advisory/"></ref><ref adv="1" source="" url="http://secunia.com/secunia_research/2007-42/advisory/"></ref><ref adv="1" source="" url="http://secunia.com/secunia_research/2007-43/advisory/"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1832">ADV-2007-1832</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1833">ADV-2007-1833</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1834">ADV-2007-1834</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24090">24090</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24281">24281</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24329">24329</ref><ref source="BID" url="http://www.securityfocus.com/bid/24002">24002</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1018072">1018072</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/34313">xferwan-tcp-bo(34313)</ref></refs><vuln_soft><prod name="Discovery" vendor="Centennial"><vers num="2006 FeaturePack1"/></prod><prod name="Asset Manager" vendor="Numara"><vers num="8.0"/></prod><prod name="Discovery" vendor="Symantec"><vers num="6.5"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" modified="2007-03-06" name="CVE-2007-1174" published="2007-03-02" seq="2007-1174" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in WebAPP before 20070214 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors, related to unspecified fields in user Profiles.  NOTE: some of these details are obtained from third party information.</descript></desc><loss_types><int/></loss_types><range><network/><user_init/></range><refs><ref patch="1" source="" url="http://www.web-app.org/cgi-bin/index.cgi?action=viewnews&amp;id=251"></ref><ref source="BID" url="http://www.securityfocus.com/bid/22563">22563</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0605">ADV-2007-0605</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32506">webapp-profileedit-xss(32506)</ref></refs><vuln_soft><prod name="WebAPP" vendor="Web-APP.org"><vers num="0.9.9.4" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" modified="2007-03-06" name="CVE-2007-1175" published="2007-03-02" seq="2007-1175" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in an admin feature in WebAPP before 20070209 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.</descript></desc><loss_types><int/></loss_types><range><network/><user_init/></range><refs><ref adv="1" patch="1" source="" url="http://www.web-app.org/cgi-bin/index.cgi?action=viewnews&amp;id=249"></ref><ref source="BID" url="http://www.securityfocus.com/bid/22563">22563</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0604">ADV-2007-0604</ref></refs><vuln_soft><prod name="WebAPP" vendor="Web-APP.org"><vers num="0.9.9.4" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" modified="2007-03-06" name="CVE-2007-1176" published="2007-03-02" seq="2007-1176" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in WebAPP before 0.9.9.5 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors related to (1) Gallery Comments pages, (2) Feedback pages, (3) Search Results pages, and (4) the Statistics Log viewer.</descript></desc><loss_types><int/></loss_types><range><network/><user_init/></range><refs><ref adv="1" patch="1" source="" url="http://www.web-app.org/cgi-bin/index.cgi?action=viewnews&amp;id=250"></ref><ref source="BID" url="http://www.securityfocus.com/bid/22563">22563</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0604">ADV-2007-0604</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24080">24080</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32526">webapp-gallery-feedback-xss(32526)</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32499">webapp-searchresultspages-xss(32499)</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32498">webapp-statisticslogviewer-xss(32498)</ref></refs><vuln_soft><prod name="WebAPP" vendor="Web-APP.org"><vers num="0.9.9.4" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="4.9" CVSS_score="5.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:N)" CVSS_version="2.0" modified="2007-03-06" name="CVE-2007-1177" published="2007-03-02" seq="2007-1177" severity="Medium" type="CVE"><desc><descript source="cve">WebAPP before 0.9.9.5 does not properly filter certain characters in contexts related to (1) the query string, (2) Profiles, (3) the Forum Post icon field, (4) the Edit Profile, and (5) the Gallery, which has unknown impact and remote attack vectors, possibly related to cross-site scripting (XSS).</descript></desc><loss_types><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://www.web-app.org/cgi-bin/index.cgi?action=viewnews&amp;id=250"></ref><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/22563">22563</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0604">ADV-2007-0604</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/24080">24080</ref></refs><vuln_soft><prod name="WebAPP" vendor="Web-APP.org"><vers num="0.9.9"/><vers num="0.9.9.1"/><vers num="0.9.9.2"/><vers num="0.9.9.2.1"/><vers num="0.9.9.3"/><vers num="0.9.9.3.1"/><vers num="0.9.9.3.2"/><vers num="0.9.9.4"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-03-06" name="CVE-2007-1178" published="2007-03-02" seq="2007-1178" severity="High" type="CVE"><desc><descript source="cve">WebAPP before 0.9.9.5 does not check access in certain contexts related to (1) Calendar Administration, (2) Instant Messages Administration, and (3) the Image Uploader, which has unknown impact and attack vectors.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs><ref adv="1" patch="1" source="" url="http://www.web-app.org/cgi-bin/index.cgi?action=viewnews&amp;id=250"></ref><ref source="BID" url="http://www.securityfocus.com/bid/22563">22563</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0604">ADV-2007-0604</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24080">24080</ref></refs><vuln_soft><prod name="WebAPP" vendor="Web-APP.org"><vers num="0.9.9.4" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0" modified="2007-03-06" name="CVE-2007-1179" published="2007-03-02" seq="2007-1179" severity="Medium" type="CVE"><desc><descript source="cve">WebAPP before 0.9.9.5 does not properly manage e-mail addresses in certain contexts related to (1) the Recommend feature, Email Article (2) senders and (3) recipients, (4) New User Approval, (5) Edit Profiles, (6) the Newsletter Subscription form, (7) the Recommend form, and (8) sending of articles, which has unknown impact, and remote attack vectors related to spam attacks and possibly other attacks.</descript></desc><loss_types><conf/></loss_types><range><network/></range><refs><ref adv="1" patch="1" source="" url="http://www.web-app.org/cgi-bin/index.cgi?action=viewnews&amp;id=250"></ref><ref source="BID" url="http://www.securityfocus.com/bid/22563">22563</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0604">ADV-2007-0604</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24080">24080</ref></refs><vuln_soft><prod name="WebAPP" vendor="Web-APP.org"><vers num="0.9.9.4" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" modified="2007-06-27" name="CVE-2007-1180" published="2007-03-02" seq="2007-1180" severity="Medium" type="CVE"><desc><descript source="cve">WebAPP before 0.9.9.5 does not check referrers in certain forms, which might facilitate remote cross-site request forgery (CSRF) attacks or have other unknown impact.</descript></desc><loss_types><int/></loss_types><vuln_types><input/><exception/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" patch="1" source="" url="http://www.web-app.org/cgi-bin/index.cgi?action=viewnews&amp;id=250"></ref><ref source="BID" url="http://www.securityfocus.com/bid/22563">22563</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0604">ADV-2007-0604</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24080">24080</ref></refs><vuln_soft><prod name="WebAPP" vendor="Web-APP.org"><vers num="0.9.9.4" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0" modified="2007-03-06" name="CVE-2007-1181" published="2007-03-02" seq="2007-1181" severity="Medium" type="CVE"><desc><descript source="cve">WebAPP before 0.9.9.5 passes (1) Unused Informations and (2) the username through Edit Profile forms, which has unknown impact and attack vectors.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref source="" url="http://www.web-app.org/cgi-bin/index.cgi?action=viewnews&amp;id=250"></ref><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/22563">22563</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0604">ADV-2007-0604</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24080">24080</ref></refs><vuln_soft><prod name="WebAPP" vendor="Web-APP.org"><vers num="0.9.9"/><vers num="0.9.9.1"/><vers num="0.9.9.2"/><vers num="0.9.9.2.1"/><vers num="0.9.9.3"/><vers num="0.9.9.3.1"/><vers num="0.9.9.3.2"/><vers num="0.9.9.4"/></prod></vuln_soft></entry><entry CVSS_base_score="6.4" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="4.9" CVSS_score="6.4" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_version="2.0" modified="2007-03-06" name="CVE-2007-1182" published="2007-03-02" seq="2007-1182" severity="Medium" type="CVE"><desc><descript source="cve">WebAPP before 0.9.9.5 allows remote Guest users to edit a Guest profile, which has unknown impact.</descript></desc><loss_types><conf/><int/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref source="" url="http://www.web-app.org/cgi-bin/index.cgi?action=viewnews&amp;id=250"></ref><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/22563">22563</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0604">ADV-2007-0604</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24080">24080</ref></refs><vuln_soft><prod name="WebAPP" vendor="Web-APP.org"><vers num="0.9.9"/><vers num="0.9.9.1"/><vers num="0.9.9.2"/><vers num="0.9.9.2.1"/><vers num="0.9.9.3"/><vers num="0.9.9.3.1"/><vers num="0.9.9.3.2"/><vers num="0.9.9.4"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-03-06" name="CVE-2007-1183" published="2007-03-02" seq="2007-1183" severity="High" type="CVE"><desc><descript source="cve">WebAPP before 0.9.9.5 allows remote authenticated users to spoof another user&apos;s Real Name via whitespace, which has unknown impact and attack vectors.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs><ref adv="1" patch="1" source="" url="http://www.web-app.org/cgi-bin/index.cgi?action=viewnews&amp;id=250"></ref><ref source="BID" url="http://www.securityfocus.com/bid/22563">22563</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0604">ADV-2007-0604</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24080">24080</ref></refs><vuln_soft><prod name="WebAPP" vendor="Web-APP.org"><vers num="0.9.9.4" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" modified="2008-03-03" name="CVE-2007-1184" published="2007-03-02" seq="2007-1184" severity="Medium" type="CVE"><desc><descript source="cve">The default configuration of WebAPP before 0.9.9.5 has a CAPTCHA setting of &quot;no,&quot; which makes it easier for automated programs to submit false data.</descript></desc><loss_types><int/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref source="" url="http://www.web-app.org/cgi-bin/index.cgi?action=viewnews&amp;id=250"></ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/22563">22563</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0604">ADV-2007-0604</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24080">24080</ref></refs><vuln_soft><prod name="WebAPP" vendor="Web-APP.org"><vers num="0.9.9"/><vers num="0.9.9.1"/><vers num="0.9.9.2"/><vers num="0.9.9.2.1"/><vers num="0.9.9.3"/><vers num="0.9.9.3.1"/><vers num="0.9.9.3.2"/><vers num="0.9.9.4"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0" modified="2007-03-06" name="CVE-2007-1185" published="2007-03-02" seq="2007-1185" severity="Medium" type="CVE"><desc><descript source="cve">The (1) Search, (2) Edit Profile, (3) Recommend, and (4) User Approval forms in WebAPP before 0.9.9.5 use hidden inputs, which has unknown impact and remote attack vectors.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref source="" url="http://www.web-app.org/cgi-bin/index.cgi?action=viewnews&amp;id=250"></ref><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/22563">22563</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0604">ADV-2007-0604</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24080">24080</ref></refs><vuln_soft><prod name="WebAPP" vendor="Web-APP.org"><vers num="0.9.9"/><vers num="0.9.9.1"/><vers num="0.9.9.2"/><vers num="0.9.9.2.1"/><vers num="0.9.9.3"/><vers num="0.9.9.3.1"/><vers num="0.9.9.3.2"/><vers num="0.9.9.4"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0" modified="2007-03-06" name="CVE-2007-1186" published="2007-03-02" seq="2007-1186" severity="Medium" type="CVE"><desc><descript source="cve">WebAPP before 0.9.9.5 does not &quot;censor&quot; the Latest Member real name, which has unknown impact.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref source="" url="http://www.web-app.org/cgi-bin/index.cgi?action=viewnews&amp;id=250"></ref><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/22563">22563</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0604">ADV-2007-0604</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24080">24080</ref></refs><vuln_soft><prod name="WebAPP" vendor="Web-APP.org"><vers num="0.9.9"/><vers num="0.9.9.1"/><vers num="0.9.9.2"/><vers num="0.9.9.2.1"/><vers num="0.9.9.3"/><vers num="0.9.9.3.1"/><vers num="0.9.9.3.2"/><vers num="0.9.9.4"/></prod></vuln_soft></entry><entry CVSS_base_score="5.5" CVSS_exploit_subscore="8.0" CVSS_impact_subscore="4.9" CVSS_score="5.5" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:N)" CVSS_version="2.0" modified="2007-03-06" name="CVE-2007-1187" published="2007-03-02" seq="2007-1187" severity="Medium" type="CVE"><desc><descript source="cve">WebAPP before 0.9.9.5 allows remote authenticated users, without admin privileges, to obtain sensitive information via (1) the Forum Archive feature and (2) Recent Searches.</descript></desc><loss_types><conf/><int/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref source="" url="http://www.web-app.org/cgi-bin/index.cgi?action=viewnews&amp;id=250"></ref><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/22563">22563</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0604">ADV-2007-0604</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24080">24080</ref></refs><vuln_soft><prod name="WebAPP" vendor="Web-APP.org"><vers num="0.9.9"/><vers num="0.9.9.1"/><vers num="0.9.9.2"/><vers num="0.9.9.2.1"/><vers num="0.9.9.3"/><vers num="0.9.9.3.1"/><vers num="0.9.9.3.2"/><vers num="0.9.9.4"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-03-06" name="CVE-2007-1188" published="2007-03-02" seq="2007-1188" severity="High" type="CVE"><desc><descript source="cve">WebAPP before 0.9.9.5 allows remote attackers to submit Search form input that is not checked for (1) composition or (2) length, which has unknown impact, possibly related to &quot;search form hijacking&quot;.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://www.web-app.org/cgi-bin/index.cgi?action=viewnews&amp;id=250"></ref><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/22563">22563</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0604">ADV-2007-0604</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24080">24080</ref></refs><vuln_soft><prod name="WebAPP" vendor="Web-APP.org"><vers num="0.9.9"/><vers num="0.9.9.1"/><vers num="0.9.9.2"/><vers num="0.9.9.2.1"/><vers num="0.9.9.3"/><vers num="0.9.9.3.1"/><vers num="0.9.9.3.2"/><vers num="0.9.9.4"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-03-06" name="CVE-2007-1189" published="2007-03-02" seq="2007-1189" severity="High" type="CVE"><desc><descript source="cve">Integer overflow in the envwrite function in the Alcatel-Lucent Bell Labs Plan 9 kernel allows local users to overwrite certain memory addresses with kernel memory via a large n argument, as demonstrated by (1) modifying the iseve function to gain privileges and (2) making the devpermcheck function grant unrestricted device permissions.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3383">3383</ref><ref source="MLIST" url="http://lists.immunitysec.com/pipermail/dailydave/2007-February/004118.html">[dailydave] 20070227 Wow, free kernel zero day?</ref><ref source="" url="http://kernelspace.us/itheft.c"></ref><ref source="BID" url="http://www.securityfocus.com/bid/22749">22749</ref></refs><vuln_soft><prod name="Plan 9" vendor="Bell Labs"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-03-06" name="CVE-2007-1190" published="2007-03-02" seq="2007-1190" severity="Medium" type="CVE"><desc><descript source="cve">Unspecified vulnerability in the EmbeddedWB Web Browser ActiveX control allows remote attackers to execute arbitrary code via unspecified vectors.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/22755">22755</ref></refs><vuln_soft><prod name="EmbeddedWB Web Browser" vendor="Bsalsa"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0" modified="2007-03-06" name="CVE-2007-1191" published="2007-03-02" seq="2007-1191" severity="Low" type="CVE"><desc><descript source="cve">The Social Bookmarks (del.icio.us) plug-in 8F in Quicksilver writes usernames and passwords in plaintext to the /Library/Logs/Console/UID/Console.log file, which allows local users to obtain sensitive information by reading this file.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2007-February/052722.html">20070228 Quicksilver Social Bookmark plugin v.8F: password in clear text</ref><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/22752">22752</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/32721">socialbookmarks-password-plaintext(32721)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2368">2368</ref></refs><vuln_soft><prod name="Del.icio.us Module" vendor="Quicksilver"><vers num="8F"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0" modified="2007-03-06" name="CVE-2007-1192" published="2007-03-02" seq="2007-1192" severity="Medium" type="CVE"><desc><descript source="cve">Thomas R. Pasawicz HyperBook Guestbook 1.30 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download an admin password hash via a direct request for data/gbconfiguration.dat.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref source="" url="http://downloads.securityfocus.com/vulnerabilities/exploits/22754.py"></ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/22754">22754</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24392">
24392</ref></refs><vuln_soft><prod name="Guestbook" vendor="HyperBook"><vers num="1.30"/></prod></vuln_soft></entry><entry CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" CVSS_score="9.3" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-03-13" name="CVE-2007-1193" published="2007-03-02" seq="2007-1193" severity="High" type="CVE"><desc><descript source="cve">Multiple unspecified vulnerabilities in the Login page in OrangeHRM before 20070212 have unknown impact and attack vectors.</descript></desc><impacts><impact source="nvd">Successful exploitation requires that &quot;magic_quotes_gpc&quot; is disabled.</impact></impacts><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs><ref patch="1" source="" url="http://sourceforge.net/tracker/index.php?func=detail&amp;aid=1656000&amp;group_id=156477&amp;atid=799942"></ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/22756">22756</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0781">ADV-2007-0781</ref></refs><vuln_soft><prod name="OrangeHRM" vendor="OrangeHRM"><vers edition="alpha 4" num="2.1"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0" modified="2008-03-03" name="CVE-2007-1194" published="2007-03-02" seq="2007-1194" severity="Low" type="CVE"><desc><descript source="cve">Norman SandBox Analyzer does not use the proper range for Interrupt Descriptor Table (IDT) entries, which allows local users to determine that the local machine is an emulator, or a similar environment not based on a physical Intel processor, which allows attackers to produce malware that is more difficult to analyze.</descript></desc><loss_types><conf/></loss_types><range><local/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/461555/100/0/threaded">20070228 Evading the Norman SandBox Analyzer</ref><ref source="" url="http://www.ntsecurity.nu/onmymind/2007/2007-02-27.html"></ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/461804/100/100/threaded">20070302 Re: Evading the Norman SandBox Analyzer</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/461805/100/100/threaded">20070303 Re: Evading the Norman SandBox Analyzer</ref></refs><vuln_soft><prod name="Norman Sandbox Analyzer" vendor="Norman"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-03-06" name="CVE-2007-1195" published="2007-03-02" seq="2007-1195" severity="High" type="CVE"><desc><descript source="cve">Multiple buffer overflows in XM Easy Personal FTP Server 5.3.0 allow remote attackers to execute arbitrary code via unspecified vectors. NOTE: this issue might overlap CVE-2006-2225, CVE-2006-2226, or CVE-2006-5728.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref source="" url="http://downloads.securityfocus.com/vulnerabilities/exploits/22747.pl"></ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/22747">22747</ref></refs><vuln_soft><prod name="XM Easy Personal FTP Server" vendor="Dxmsoft"><vers num="5.0.1"/><vers num="5.2.1"/><vers num="5.3"/></prod></vuln_soft></entry><entry CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" CVSS_score="9.3" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-03-06" name="CVE-2007-1196" published="2007-03-02" seq="2007-1196" severity="High" type="CVE"><desc><descript source="cve">Unspecified vulnerability in Citrix Presentation Server Client for Windows before 10.0 allows remote web sites to execute arbitrary code via unspecified vectors, related to the implementation of ICA connectivity through proxy servers.</descript></desc><sols><sol source="nvd">Upgrade to Citrix Presentation Server Client for Windows version 10.0:
http://www.citrix.com/English/SS/downloads/downloads.asp?dID=2755 
</sol></sols><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref source="Citrix" url="http://support.citrix.com/article/CTX112589">CTX112589</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0784">ADV-2007-0784</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/798364">
VU#798364</ref><ref source="BID" url="http://www.securityfocus.com/bid/22762">
22762</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017712">
1017712</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24350">
24350</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32754">
citrix-ica-code-execution(32754)</ref></refs><vuln_soft><prod name="Presentation Server Client" vendor="Citrix"><vers edition="Windows" num="9.200" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" CVSS_score="9.3" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-03-06" name="CVE-2007-1197" published="2007-03-02" seq="2007-1197" severity="High" type="CVE"><desc><descript source="cve">Multiple unspecified vulnerabilities in Epiware before 4.7.5 have unknown impact and attack vectors, possibly related to cross-site scripting (XSS) and other unspecified issues.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs><ref patch="1" source="" url="http://sourceforge.net/forum/forum.php?forum_id=669653"></ref></refs><vuln_soft><prod name="Epiware" vendor="Epiware"><vers num="4.6.6"/><vers num="4.7"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" modified="2007-03-06" name="CVE-2007-1198" published="2007-03-02" seq="2007-1198" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in TaskFreak! before 0.5.7 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, possibly a variant of CVE-2007-0982.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://www.taskfreak.com/versions.html"></ref></refs><vuln_soft><prod name="TaskFreak" vendor="TaskFreak"><vers num="0.5.0"/><vers num="0.5.1"/><vers num="0.5.2"/><vers num="0.5.3"/><vers num="0.5.4"/><vers num="0.5.5"/><vers num="0.5.6"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)" CVSS_version="2.0" modified="2007-03-06" name="CVE-2007-1199" published="2007-03-02" seq="2007-1199" severity="Medium" type="CVE"><desc><descript source="cve">Adobe Reader and Acrobat Trial allow remote attackers to read arbitrary files via a file:// URI in a PDF document, as demonstrated with &lt;&lt;/URI(file:///C:/)/S/URI&gt;&gt;, a different issue than CVE-2007-0045.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref source="" url="http://www.gnucitizen.org/projects/pdf-strikes-back/"></ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/22753">22753</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24408">
24408</ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200803-01.xml">GLSA-200803-01</ref><ref source="SECUNIA" url="http://secunia.com/advisories/29205">29205</ref></refs><vuln_soft><prod name="Acrobat Reader" vendor="Adobe"><vers num="4.0"/><vers num="4.0.5"/><vers num="4.5"/><vers num="5.0"/><vers num="5.0.10"/><vers num="5.0.5"/><vers num="5.0.6"/><vers num="5.0.7"/><vers num="5.0.9"/><vers num="5.1"/><vers num="6.0"/><vers num="6.0.1"/><vers num="6.0.2"/><vers num="6.0.3"/><vers num="6.0.4"/><vers num="7.0"/><vers num="7.0.1"/><vers num="7.0.2"/><vers num="7.0.3"/><vers num="7.0.4"/><vers num="7.0.5"/><vers num="7.0.6"/><vers num="7.0.7"/><vers num="7.0.8"/><vers num="7.0.9"/><vers num="8.0"/></prod></vuln_soft></entry><entry CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" CVSS_score="9.3" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2008-03-12" name="CVE-2007-1201" published="2008-03-11" seq="2007-1201" severity="High" type="CVE"><desc><descript source="cve">Unspecified vulnerability in certain COM objects in Microsoft Office Web Components 2000 allows user-assisted remote attackers to execute arbitrary code via vectors related to DataSource that trigger memory corruption, aka &quot;Office Web Components DataSource Vulnerability.&quot;</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/><user_init/></range><refs><ref patch="1" source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms08-017.mspx">MS08-017</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA08-071A.html">TA08-071A</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/28136">28136</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/0849/references">ADV-2008-0849</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/29328">29328</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1019581">1019581</ref><ref source="HP" url="http://marc.info/?l=bugtraq&amp;m=120585858807305&amp;w=2">HPSBST02320</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5327">oval:org.mitre.oval:def:5327</ref></refs><vuln_soft><prod name="Internet_Security_and_Acceleration_Server" vendor="Microsoft"><vers edition="SP2" num="2000"/></prod><prod name="Office" vendor="Microsoft"><vers edition="sp3" num="2000"/><vers edition="sp3" num="XP"/></prod><prod name="commerce_server" vendor="Microsoft"><vers num="2000"/></prod><prod name="Visual Studio .NET" vendor="Microsoft"><vers edition="SP1" num="2002"/><vers edition="SP1" num="2003"/></prod><prod name="BizTalk Server" vendor="Microsoft"><vers num="2000"/><vers num="2002"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-08-02" name="CVE-2007-1202" published="2007-05-08" seq="2007-1202" severity="Medium" type="CVE"><desc><descript source="cve">Word (or Word Viewer) in Microsoft Office 2000 SP3, XP SP3, 2003 SP2, 2004 for Mac, and Works Suite 2004, 2005, and 2006 does not properly parse certain rich text &quot;property strings of certain control words,&quot; which allows user-assisted remote attackers to trigger heap corruption and execute arbitrary code, aka the &quot;Word RTF Parsing Vulnerability.&quot;</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input/><design/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" patch="1" source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms07-024.mspx">MS07-024</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/555489">VU#555489</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/23836">23836</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1709">ADV-2007-1709</ref><ref patch="1" source="SECTRACK" url="http://www.securitytracker.com/id?1018013">1018013</ref><ref patch="1" source="IDEFENSE" url="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=525">20070508 Microsoft Word RTF File Parsing Heap Corruption Vulnerability</ref><ref source="HP" url="http://www.securityfocus.com/archive/1/archive/1/468871/100/200/threaded">HPSBST02214</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA07-128A.html">TA07-128A</ref><ref source="OSVDB" url="http://www.osvdb.org/34388">34388</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1900">oval:org.mitre.oval:def:1900</ref></refs><vuln_soft><prod name="Works Suite" vendor="Microsoft"><vers num="2004"/><vers num="2005"/><vers num="2006"/></prod><prod name="Word" vendor="Microsoft"><vers num="2000 SP3"/><vers num="2002 SP3"/><vers num="2003 SP2"/><vers num="2003 Viewer"/><vers edition="Mac" num="2004"/></prod></vuln_soft></entry><entry CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" CVSS_score="9.3" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-05-09" name="CVE-2007-1203" published="2007-05-08" seq="2007-1203" severity="High" type="CVE"><desc><descript source="cve">Unspecified vulnerability in Microsoft Excel 2000 SP3, 2002 SP3, 2003 SP2, 2003 Viewer, 2004 for Mac, and 2007 allows user-assisted remote attackers to execute arbitrary code via a crafted set font value in an Excel file, which results in memory corruption.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref patch="1" source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms07-023.mspx">MS07-023</ref><ref source="BID" url="http://www.securityfocus.com/bid/23779">
23779</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1708">
ADV-2007-1708</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1018012">
1018012</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25150">
25150</ref><ref source="HP" url="http://www.securityfocus.com/archive/1/archive/1/468871/100/200/threaded">HPSBST02214</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA07-128A.html">TA07-128A</ref><ref source="OSVDB" url="http://www.osvdb.org/34394">34394</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2014">oval:org.mitre.oval:def:2014</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33914">excel-placeholder-code-execution(33914)</ref></refs><vuln_soft><prod name="Excel" vendor="Microsoft"><vers num="2000 sp3"/><vers num="2002 sp3"/><vers num="2003 sp2"/><vers num="2003 Viewer"/><vers num="2007"/><vers edition="Mac" num="2004"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="3.2" CVSS_impact_subscore="10.0" CVSS_score="6.8" CVSS_vector="(AV:A/AC:H/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-04-19" name="CVE-2007-1204" published="2007-04-10" seq="2007-1204" severity="Medium" type="CVE"><desc><descript source="cve">Stack-based buffer overflow in the Universal Plug and Play (UPnP) service in Microsoft Windows XP SP2 allows remote attackers on the same subnet to execute arbitrary code via crafted HTTP headers in request or notification messages, which trigger memory corruption.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input/></vuln_types><range><local_network/></range><refs><ref adv="1" patch="1" source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms07-019.mspx">MS07-019</ref><ref source="IDEFENSE" url="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=509">20070410 Microsoft Windows Universal Plug and Play Memory Corruption Vulnerability</ref><ref source="BID" url="http://www.securityfocus.com/bid/23371">23371</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017895">1017895</ref><ref source="HP" url="http://www.securityfocus.com/archive/1/archive/1/466331/100/200/threaded">
HPSBST02208</ref><ref source="OSVDB" url="http://www.osvdb.org/34010">
34010</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1323">ADV-2007-1323</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2049">oval:org.mitre.oval:def:2049</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24822">24822</ref></refs><vuln_soft><prod name="Windows XP" vendor="Microsoft"><vers num="SP2"/></prod></vuln_soft></entry><entry CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" CVSS_score="9.3" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-05-14" name="CVE-2007-1205" published="2007-04-10" seq="2007-1205" severity="High" type="CVE"><desc><descript source="cve">Unspecified vulnerability in Microsoft Agent (msagent\agentsvr.exe) in Windows 2000 SP4, XP SP2, and Server 2003, 2003 SP1, and 2003 SP2 allows remote attackers to execute arbitrary code via crafted URLs, which result in memory corruption.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" patch="1" source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms07-020.mspx">MS07-020</ref><ref source="" url="http://secunia.com/secunia_research/2006-74/advisory/"></ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/465235/100/0/threaded">20070410 Secunia Research: Microsoft Agent URL Parsing Memory CorruptionVulnerability</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/728057">VU#728057</ref><ref source="BID" url="http://www.securityfocus.com/bid/23337">23337</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017896">1017896</ref><ref source="SECUNIA" url="http://secunia.com/advisories/22896">22896</ref><ref source="HP" url="http://www.securityfocus.com/archive/1/archive/1/466331/100/200/threaded">
HPSBST02208</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA07-100A.html">TA07-100A</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1324">ADV-2007-1324</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2034">oval:org.mitre.oval:def:2034</ref></refs><vuln_soft><prod name="Windows XP" vendor="Microsoft"><vers num="SP2"/><vers edition="Professional x64" num="Gold"/><vers edition="Professional x64" num="SP2"/></prod><prod name="Windows Server 2003" vendor="Microsoft"><vers num="SP1"/><vers num="SP2"/><vers num="Gold"/><vers edition="x64" num="SP1"/><vers edition="x64" num="SP2"/><vers edition="Itanium" num="Gold"/><vers edition="Itanium" num="SP1"/><vers edition="Itanium" num="SP2"/></prod><prod name="Windows 2000" vendor="Microsoft"><vers num="SP4"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-05-25" name="CVE-2007-1206" published="2007-04-10" seq="2007-1206" severity="High" type="CVE"><desc><descript source="cve">The Virtual DOS Machine (VDM) in the Windows Kernel in Microsoft Windows NT 4.0; 2000 SP4; XP SP2; Server 2003, 2003 SP1, and 2003 SP2; and Windows Vista before June 2006; uses insecure permissions (PAGE_READWRITE) for a physical memory view, which allows local users to gain privileges by modifying the &quot;zero page&quot; during a race condition before the view is unmapped.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms07-022.mspx">MS07-022</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/465232/100/0/threaded">20070410 EEYE: Windows VDM Zero Page Race Condition Privilege Escalation</ref><ref source="" url="http://research.eeye.com/html/advisories/published/AD20070410a.html"></ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/337953">VU#337953</ref><ref source="BID" url="http://www.securityfocus.com/bid/23367">23367</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1017898">1017898</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24834">24834</ref><ref source="OSVDB" url="http://www.osvdb.org/34011">34011</ref><ref source="HP" url="http://www.securityfocus.com/archive/1/archive/1/466331/100/200/threaded">HPSBST02208</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA07-100A.html">TA07-100A</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1326">ADV-2007-1326</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1639">oval:org.mitre.oval:def:1639</ref></refs><vuln_soft><prod name="Windows XP" vendor="Microsoft"><vers num="SP2"/></prod><prod name="Windows Server 2003" vendor="Microsoft"><vers num="Gold"/><vers num="SP1"/><vers num="SP2"/></prod><prod name="Windows 2000" vendor="Microsoft"><vers num="SP4"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-04-19" name="CVE-2007-1209" published="2007-04-10" seq="2007-1209" severity="High" type="CVE"><desc><descript source="cve">Use-after-free vulnerability in the Client/Server Run-time Subsystem (CSRSS) in Microsoft Windows Vista does not properly handle connection resources when starting and stopping processes, which allows local users to gain privileges by opening and closing multiple ApiPort connections, which leaves a &quot;dangling pointer&quot; to a process data structure.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/465233/100/0/threaded">20070410 EEYE: Windows Vista CSRSS Dangling Process Pointer Privilege Escalation</ref><ref adv="1" patch="1" source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms07-021.mspx">MS07-021</ref><ref source="" url="http://research.eeye.com/html/advisories/published/AD20070410b.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/23338">23338</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017897">1017897</ref><ref source="OSVDB" url="http://www.osvdb.org/34008">
34008</ref><ref source="HP" url="http://www.securityfocus.com/archive/1/archive/1/466331/100/200/threaded">
HPSBST02208</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA07-100A.html">TA07-100A</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/219848">VU#219848</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1325">ADV-2007-1325</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1524">oval:org.mitre.oval:def:1524</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24823">24823</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2531">2531</ref></refs><vuln_soft><prod name="Windows Vista" vendor="Microsoft"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.1" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.9" CVSS_score="7.1" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:C)" CVSS_version="2.0" modified="2007-05-14" name="CVE-2007-1211" published="2007-04-04" seq="2007-1211" severity="High" type="CVE"><desc><descript source="cve">Unspecified kernel GDI functions in Microsoft Windows 2000 SP4; XP SP2; and Server 2003 Gold, SP1, and SP2 allows user-assisted remote attackers to cause a denial of service (possibly persistent restart) via a crafted Windows Metafile (WMF) image that causes an invalid dereference of an offset in a kernel structure, a related issue to CVE-2005-4560.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" patch="1" source="MS" url="http://www.microsoft.com/technet/security/Bulletin/ms07-017.mspx">MS07-017</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33258">win-wmf-dos(33258)</ref><ref source="IDEFENSE" url="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=499">20070403 Microsoft Windows WMF Triggerable Kernel Design Error DoS Vulnerability</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1215">ADV-2007-1215</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017843">1017843</ref><ref source="BID" url="http://www.securityfocus.com/bid/23275">23275</ref><ref source="HP" url="http://www.securityfocus.com/archive/1/archive/1/466186/100/200/threaded">
HPSBST02206</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1571">oval:org.mitre.oval:def:1571</ref></refs><vuln_soft><prod name="Windows XP" vendor="Microsoft"><vers num="SP2"/><vers edition="Professional x64" num="Gold"/><vers edition="Professional x64" num="SP2"/></prod><prod name="Windows Server 2003" vendor="Microsoft"><vers num="Gold"/><vers num="SP1"/><vers num="SP2"/><vers edition="Itanium" num="Gold"/><vers edition="Itanium" num="SP1"/><vers edition="Itanium" num="SP2"/><vers edition="x64" num="Gold"/><vers edition="x64" num="SP2"/></prod><prod name="Windows 2000" vendor="Microsoft"><vers num="SP4"/></prod></vuln_soft></entry><entry CVSS_base_score="6.6" CVSS_exploit_subscore="2.7" CVSS_impact_subscore="10.0" CVSS_score="6.6" CVSS_vector="(AV:L/AC:M/Au:S/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-05-14" name="CVE-2007-1212" published="2007-04-04" seq="2007-1212" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in the Graphics Device Interface (GDI) in Microsoft Windows 2000 SP4; XP SP2; Server 2003 Gold, SP1, and SP2; and Vista allows local users to gain privileges via a crafted Enhanced Metafile (EMF) image format file.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="MS" url="http://www.microsoft.com/technet/security/Bulletin/ms07-017.mspx">MS07-017</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1215">ADV-2007-1215</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017844">1017844</ref><ref source="BID" url="http://www.securityfocus.com/bid/23278">23278</ref><ref source="HP" url="http://www.securityfocus.com/archive/1/archive/1/466186/100/200/threaded">

HPSBST02206</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1923">oval:org.mitre.oval:def:1923</ref></refs><vuln_soft><prod name="Windows Vista" vendor="Microsoft"><vers num="Gold"/><vers edition="x64" num="Gold"/></prod><prod name="Windows XP" vendor="Microsoft"><vers num="SP2"/><vers edition="Professional x64" num="Gold"/><vers edition="Professional x64" num="SP2"/></prod><prod name="Windows Server 2003" vendor="Microsoft"><vers num="Gold"/><vers num="SP1"/><vers num="SP2"/><vers edition="Itanium" num="Gold"/><vers edition="Itanium" num="SP1"/><vers edition="Itanium" num="SP2"/><vers edition="x64" num="Gold"/><vers edition="x64" num="SP2"/></prod><prod name="Windows 2000" vendor="Microsoft"><vers num="SP4"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-05-14" name="CVE-2007-1213" published="2007-04-04" seq="2007-1213" severity="High" type="CVE"><desc><descript source="cve">The TrueType Fonts rasterizer in Microsoft Windows 2000 SP4 allows local users to gain privileges via crafted TrueType fonts, which result in an uninitialized function pointer.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input bound="1"/></vuln_types><range><local/></range><refs><ref patch="1" source="MS" url="http://www.microsoft.com/technet/security/Bulletin/ms07-017.mspx">MS07-017</ref><ref source="BID" url="http://www.securityfocus.com/bid/23276">23276</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1215">ADV-2007-1215</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017845">1017845</ref><ref source="HP" url="http://www.securityfocus.com/archive/1/archive/1/466186/100/200/threaded">

HPSBST02206</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1797">oval:org.mitre.oval:def:1797</ref></refs><vuln_soft><prod name="Windows 2000" vendor="Microsoft"><vers num="SP4"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-08-02" name="CVE-2007-1214" published="2007-05-08" seq="2007-1214" severity="Medium" type="CVE"><desc><descript source="cve">Microsoft Excel 2000 SP3, 2002 SP3, 2003 SP2, 2003 Viewer, and 2004 for Mac allows user-assisted remote attackers to execute arbitrary code via a crafted AutoFilter filter record in an Excel BIFF8 format XLS file, which triggers memory corruption.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref patch="1" source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms07-023.mspx">MS07-023</ref><ref patch="1" source="IDEFENSE" url="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=527">20070508 Microsoft Excel Filter Record Code Execution Vulnerability</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/253825">VU#253825</ref><ref source="BID" url="http://www.securityfocus.com/bid/23780">23780</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1708">ADV-2007-1708</ref><ref patch="1" source="SECTRACK" url="http://www.securitytracker.com/id?1018012">1018012</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/25150">25150</ref><ref source="HP" url="http://www.securityfocus.com/archive/1/archive/1/468871/100/200/threaded">HPSBST02214</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA07-128A.html">TA07-128A</ref><ref source="OSVDB" url="http://www.osvdb.org/34395">34395</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2064">oval:org.mitre.oval:def:2064</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33915">excel-autofilter-code-execution(33915)</ref></refs><vuln_soft><prod name="Excel" vendor="Microsoft"><vers num="2000 sp3"/><vers num="2002 sp3"/><vers num="2003 sp2"/><vers num="2003 Viewer"/><vers edition="Mac" num="2004"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-05-14" name="CVE-2007-1215" published="2007-04-04" seq="2007-1215" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in the Graphics Device Interface (GDI) in Microsoft Windows 2000 SP4; XP SP2; Server 2003 Gold, SP1, and SP2; and Vista allows local users to gain privileges via certain &quot;color-related parameters&quot; in crafted images.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref source="MS" url="http://www.microsoft.com/technet/security/Bulletin/ms07-017.mspx">MS07-017</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1215">ADV-2007-1215</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017847">1017847</ref><ref source="BID" url="http://www.securityfocus.com/bid/23273">23273</ref><ref source="HP" url="http://www.securityfocus.com/archive/1/archive/1/466186/100/200/threaded">

HPSBST02206</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1927">oval:org.mitre.oval:def:1927</ref></refs><vuln_soft><prod name="Windows Vista" vendor="Microsoft"><vers num="Gold"/><vers edition="x64" num="Gold"/></prod><prod name="Windows XP" vendor="Microsoft"><vers num="SP2"/><vers edition="Professional x64" num="Gold"/><vers edition="Professional x64" num="SP2"/></prod><prod name="Windows Server 2003" vendor="Microsoft"><vers num="Gold"/><vers num="SP1"/><vers num="SP2"/><vers edition="Itanium" num="Gold"/><vers edition="Itanium" num="SP1"/><vers edition="Itanium" num="SP2"/><vers edition="x64" num="Gold"/><vers edition="x64" num="SP2"/></prod><prod name="Windows 2000" vendor="Microsoft"><vers num="SP4"/></prod></vuln_soft></entry><entry CVSS_base_score="8.5" CVSS_exploit_subscore="6.8" CVSS_impact_subscore="10.0" CVSS_score="8.5" CVSS_vector="(AV:N/AC:M/Au:S/C:C/I:C/A:C)" CVSS_version="2.0" modified="2008-02-26" name="CVE-2007-1216" published="2007-04-05" seq="2007-1216" severity="High" type="CVE"><desc><descript source="cve">Double free vulnerability in the GSS-API library (lib/gssapi/krb5/k5unseal.c), as used by the Kerberos administration daemon (kadmind) in MIT krb5 before 1.6.1, when used with the authentication method provided by the RPCSEC_GSS RPC library, allows remote authenticated users to execute arbitrary code and modify the Kerberos key database via a message with an &quot;an invalid direction encoding&quot;.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="" url="http://web.mit.edu/kerberos/www/advisories/MITKRB5-SA-2007-003.txt"></ref><ref adv="1" patch="1" source="DEBIAN" url="http://www.debian.org/security/2007/dsa-1276">DSA-1276</ref><ref adv="1" patch="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2007-0095.html">RHSA-2007:0095</ref><ref adv="1" patch="1" source="UBUNTU" url="http://www.ubuntu.com/usn/usn-449-1">USN-449-1</ref><ref adv="1" patch="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/419344">VU#419344</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/24706">24706</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/24736">24736</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/24757">24757</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/464666/100/0/threaded">20070404 rPSA-2007-0063-1 krb5 krb5-server krb5-services krb5-test krb5-workstation</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/464591/100/0/threaded">20070403 MITKRB5-SA-2007-003: double-free vulnerability in kadmind (via GSS-API library) [CVE-2007-1216]</ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200704-02.xml">GLSA-200704-02</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2007:077">MDKSA-2007:077</ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20070401-01-P.asc">20070401-01-P</ref><ref source="SUSE" url="http://lists.suse.com/archive/suse-security-announce/2007-Apr/0001.html">SUSE-SA:2007:025</ref><ref source="BID" url="http://www.securityfocus.com/bid/23282">23282</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017852">1017852</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24740">24740</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24750">24750</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24785">24785</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24786">24786</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24817">24817</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24735">24735</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33413">kerberos-kadmind-code-execution(33413)</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1218">ADV-2007-1218</ref><ref source="" url="http://docs.info.apple.com/article.html?artnum=305391"></ref><ref source="APPLE" url="http://lists.apple.com/archives/Security-announce/2007/Apr/msg00001.html">APPLE-SA-2007-04-19</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1470">ADV-2007-1470</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24966">24966</ref><ref source="HP" url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&amp;cc=us&amp;objectID=c01056923">HPSBUX02217</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:077">MDKSA-2007:077</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA07-093B.html">TA07-093B</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA07-109A.html">TA07-109A</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1916">ADV-2007-1916</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/25388">25388</ref></refs><vuln_soft><prod name="Kerberos 5" vendor="MIT"><vers num="1.6" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.9" CVSS_exploit_subscore="3.4" CVSS_impact_subscore="10.0" CVSS_score="6.9" CVSS_vector="(AV:L/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-10-25" name="CVE-2007-1217" published="2007-03-02" seq="2007-1217" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in the bufprint function in capiutil.c in libcapi, as used in Linux kernel 2.6.9 to 2.6.20 and isdn4k-utils, allows local users to cause a denial of service (crash) and possibly gain privileges via a crafted CAPI packet.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref source="" url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=408530"></ref><ref source="" url="http://bugzilla.kernel.org/show_bug.cgi?id=8028"></ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2007:078">MDKSA-2007:078</ref><ref source="BID" url="http://www.securityfocus.com/bid/23333">23333</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24777">24777</ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200704-23.xml">GLSA-200704-23</ref><ref source="" url="http://support.avaya.com/elmodocs2/security/ASA-2007-404.htm"></ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:078">MDKSA-2007:078</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2007-0673.html">RHSA-2007:0673</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2007-0672.html">RHSA-2007:0672</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2007-0671.html">RHSA-2007:0671</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2007-0774.html">RHSA-2007:0774</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2007-0705.html">RHSA-2007:0705</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1018539">1018539</ref><ref source="SECUNIA" url="http://secunia.com/advisories/26379">26379</ref><ref source="SECUNIA" url="http://secunia.com/advisories/26478">26478</ref><ref source="SECUNIA" url="http://secunia.com/advisories/26709">26709</ref><ref source="SECUNIA" url="http://secunia.com/advisories/26760">26760</ref><ref source="SECUNIA" url="http://secunia.com/advisories/27528">27528</ref></refs><vuln_soft><prod name="Kernel" vendor="Linux"><vers num="2.6.10"/><vers num="2.6.10 rc1"/><vers num="2.6.10 rc2"/><vers num="2.6.10 rc3"/><vers num="2.6.11"/><vers num="2.6.11.11"/><vers num="2.6.11.12"/><vers num="2.6.11.5"/><vers num="2.6.11.6"/><vers num="2.6.11.7"/><vers num="2.6.11.8"/><vers edition="x86_64" num="2.6.11"/><vers num="2.6.11 rc1"/><vers num="2.6.11 rc1 bk6"/><vers num="2.6.11 rc2"/><vers num="2.6.11 rc3"/><vers num="2.6.11 rc4"/><vers num="2.6.11 rc5"/><vers num="2.6.11.1"/><vers num="2.6.11.10"/><vers num="2.6.11.2"/><vers num="2.6.11.3"/><vers num="2.6.11.4"/><vers num="2.6.11.9"/><vers num="2.6.12"/><vers num="2.6.12.1"/><vers num="2.6.12.2"/><vers num="2.6.12.3"/><vers num="2.6.12.4"/><vers num="2.6.12.5"/><vers num="2.6.12.6"/><vers num="2.6.12 rc1"/><vers num="2.6.12 rc2"/><vers num="2.6.12 rc3"/><vers num="2.6.12 rc4"/><vers num="2.6.12 rc5"/><vers num="2.6.12 rc6"/><vers num="2.6.12.12"/><vers num="2.6.12.22"/><vers num="2.6.13"/><vers num="2.6.13.1"/><vers num="2.6.13.2"/><vers num="2.6.13.3"/><vers num="2.6.13.4"/><vers num="2.6.13 rc1"/><vers num="2.6.13 rc2"/><vers num="2.6.13 rc3"/><vers num="2.6.13 rc4"/><vers num="2.6.13 rc5"/><vers num="2.6.13 rc6"/><vers num="2.6.13 rc7"/><vers num="2.6.13.5"/><vers num="2.6.14"/><vers num="2.6.14.1"/><vers num="2.6.14.2"/><vers num="2.6.14.3"/><vers num="2.6.14.4"/><vers num="2.6.14.5"/><vers num="2.6.14 rc1"/><vers num="2.6.14 rc2"/><vers num="2.6.14 rc3"/><vers num="2.6.14 -rc3"/><vers num="2.6.14 rc4"/><vers num="2.6.14 -rc4"/><vers num="2.6.14 rc5"/><vers num="2.6.14.6"/><vers num="2.6.14.7"/><vers num="2.6.14-rc1"/><vers num="2.6.14-rc2"/><vers num="2.6.14-rc3"/><vers num="2.6.14-rc4"/><vers num="2.6.14-rc5"/><vers num="2.6.15"/><vers num="2.6.15 .1"/><vers num="2.6.15 .2"/><vers num="2.6.15 .3"/><vers num="2.6.15 .4"/><vers num="2.6.15 rc1"/><vers num="2.6.15 -rc1"/><vers num="2.6.15 rc2"/><vers num="2.6.15 -rc2"/><vers num="2.6.15 rc3"/><vers num="2.6.15 -rc3"/><vers num="2.6.15 rc4"/><vers num="2.6.15 rc5"/><vers num="2.6.15 rc6"/><vers num="2.6.15 rc7"/><vers num="2.6.15.1"/><vers num="2.6.15.11"/><vers num="2.6.15.2"/><vers num="2.6.15.3"/><vers num="2.6.15.4"/><vers num="2.6.15.5"/><vers num="2.6.15.6"/><vers num="2.6.15.7"/><vers num="2.6.15-rc1"/><vers num="2.6.15-rc2"/><vers num="2.6.15-rc3"/><vers num="2.6.15-rc4"/><vers num="2.6.15-rc5"/><vers num="2.6.15-rc6"/><vers num="2.6.15-rc7"/><vers num="2.6.16"/><vers num="2.6.16 .1"/><vers num="2.6.16 .11"/><vers num="2.6.16 .12"/><vers num="2.6.16 .19"/><vers num="2.6.16 .23"/><vers num="2.6.16 .7"/><vers num="2.6.16 .9"/><vers num="2.6.16 13"/><vers num="2.6.16 27"/><vers num="2.6.16 rc1"/><vers num="2.6.16 -rc1"/><vers num="2.6.16 rc2"/><vers num="2.6.16 rc3"/><vers num="2.6.16 rc4"/><vers num="2.6.16 rc5"/><vers num="2.6.16 rc6"/><vers num="2.6.16 rc7"/><vers num="2.6.16.1"/><vers num="2.6.16.10"/><vers num="2.6.16.11"/><vers num="2.6.16.12"/><vers num="2.6.16.13"/><vers num="2.6.16.14"/><vers num="2.6.16.15"/><vers num="2.6.16.16"/><vers num="2.6.16.17"/><vers num="2.6.16.18"/><vers num="2.6.16.19"/><vers num="2.6.16.2"/><vers num="2.6.16.20"/><vers num="2.6.16.21"/><vers num="2.6.16.22"/><vers num="2.6.16.23"/><vers num="2.6.16.24"/><vers num="2.6.16.25"/><vers num="2.6.16.26"/><vers num="2.6.16.27"/><vers num="2.6.16.28"/><vers num="2.6.16.29"/><vers num="2.6.16.3"/><vers num="2.6.16.30"/><vers num="2.6.16.31"/><vers num="2.6.16.32"/><vers num="2.6.16.33"/><vers num="2.6.16.34"/><vers num="2.6.16.35"/><vers num="2.6.16.36"/><vers num="2.6.16.37"/><vers num="2.6.16.38"/><vers num="2.6.16.39"/><vers num="2.6.16.4"/><vers num="2.6.16.40"/><vers num="2.6.16.41"/><vers num="2.6.16.5"/><vers num="2.6.16.6"/><vers num="2.6.16.7"/><vers num="2.6.16.8"/><vers num="2.6.16.9"/><vers num="2.6.16-rc1"/><vers num="2.6.16-rc2"/><vers num="2.6.16-rc3"/><vers num="2.6.16-rc4"/><vers num="2.6.16-rc5"/><vers num="2.6.16-rc6"/><vers num="2.6.16-rc7"/><vers num="2.6.17"/><vers num="2.6.17 .1"/><vers num="2.6.17 .10"/><vers num="2.6.17 .11"/><vers num="2.6.17 .12"/><vers num="2.6.17 .13"/><vers num="2.6.17 .14"/><vers num="2.6.17 .3"/><vers num="2.6.17 .5"/><vers num="2.6.17 .6"/><vers num="2.6.17 .7"/><vers num="2.6.17 .8"/><vers num="2.6.17 rc1"/><vers num="2.6.17 rc2"/><vers num="2.6.17 rc3"/><vers num="2.6.17 rc4"/><vers num="2.6.17 rc5"/><vers num="2.6.17 -rc5"/><vers num="2.6.17 rc6"/><vers num="2.6.17.1"/><vers num="2.6.17.10"/><vers num="2.6.17.11"/><vers num="2.6.17.12"/><vers num="2.6.17.13"/><vers num="2.6.17.14"/><vers num="2.6.17.2"/><vers num="2.6.17.3"/><vers num="2.6.17.4"/><vers num="2.6.17.5"/><vers num="2.6.17.6"/><vers num="2.6.17.7"/><vers num="2.6.17.8"/><vers num="2.6.17.9"/><vers num="2.6.17-rc1"/><vers num="2.6.17-rc2"/><vers num="2.6.17-rc3"/><vers num="2.6.17-rc4"/><vers num="2.6.17-rc5"/><vers num="2.6.17-rc6"/><vers num="2.6.18"/><vers num="2.6.18 .1"/><vers num="2.6.18 rc1"/><vers num="2.6.18 rc2"/><vers num="2.6.18 rc5"/><vers num="2.6.18.1"/><vers num="2.6.18.2"/><vers num="2.6.18.3"/><vers num="2.6.18.4"/><vers num="2.6.18.5"/><vers num="2.6.18.6"/><vers num="2.6.18-rc1"/><vers num="2.6.18-rc2"/><vers num="2.6.18-rc3"/><vers num="2.6.18-rc4"/><vers num="2.6.18-rc5"/><vers num="2.6.18-rc6"/><vers num="2.6.18-rc7"/><vers num="2.6.18-stable"/><vers num="2.6.19"/><vers num="2.6.19 -rc1"/><vers num="2.6.19.1"/><vers num="2.6.19.2"/><vers num="2.6.19.3"/><vers num="2.6.19-rc1"/><vers num="2.6.19-rc2"/><vers num="2.6.19-rc3"/><vers num="2.6.19-rc4"/><vers num="2.6.20"/><vers num="2.6.9"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2008-03-03" name="CVE-2007-1218" published="2007-03-02" seq="2007-1218" severity="Medium" type="CVE"><desc><descript source="cve">Off-by-one buffer overflow in the parse_elements function in the 802.11 printer code (print-802_11.c) for tcpdump 3.9.5 and earlier allows remote attackers to cause a denial of service (crash) via a crafted 802.11 frame.  NOTE: this was originally referred to as heap-based, but it might be stack-based.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref source="FULDISC" url="http://seclists.org/fulldisclosure/2007/Mar/0003.html">20070301 tcpdump: off-by-one heap overflow in 802.11 printer</ref><ref source="" url="https://issues.rpath.com/browse/RPL-1100"></ref><ref adv="1" source="" url="https://bugs.gentoo.org/show_bug.cgi?id=168916"></ref><ref source="" url="http://cvs.tcpdump.org/cgi-bin/cvsweb/tcpdump/print-802_11.c?r1=1.31.2.11&amp;r2=1.31.2.12"></ref><ref source="" url="http://cvs.tcpdump.org/cgi-bin/cvsweb/tcpdump/print-802_11.c"></ref><ref source="DEBIAN" url="http://www.debian.org/security/2007/dsa-1272">DSA-1272</ref><ref source="FEDORA" url="http://fedoranews.org/cms/node/2798">FEDORA-2007-347</ref><ref source="FEDORA" url="http://fedoranews.org/cms/node/2799">FEDORA-2007-348</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2007:056">MDKSA-2007:056</ref><ref source="UBUNTU" url="http://www.ubuntu.com/usn/usn-429-1">USN-429-1</ref><ref source="BID" url="http://www.securityfocus.com/bid/22772">22772</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0793">ADV-2007-0793</ref><ref source="OSVDB" url="http://www.osvdb.org/32427">32427</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017717">1017717</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24318">24318</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24354">24354</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24423">24423</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24451">24451</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24583">24583</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24610">24610</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32749">tcpdump-print80211c-bo(32749)</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:056">MDKSA-2007:056</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:155">MDKSA-2007:155</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2007-0368.html">RHSA-2007:0368</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2007-0387.html">RHSA-2007:0387</ref><ref source="TURBO" url="http://www.turbolinux.com/security/2007/TLSA-2007-46.txt">TLSA-2007-46</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/27580">27580</ref><ref source="" url="http://docs.info.apple.com/article.html?artnum=307179"></ref><ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2007/Dec/msg00002.html">APPLE-SA-2007-12-17</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA07-352A.html">TA07-352A</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/4238">ADV-2007-4238</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/28136">28136</ref></refs><vuln_soft><prod name="TCPDump" vendor="TCPDump"><vers num="3.9.5" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-03-06" name="CVE-2007-1219" published="2007-03-02" seq="2007-1219" severity="High" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in actions/del.php in Admin Phorum 3.3.1a allows remote attackers to execute arbitrary PHP code via a URL in the include_path parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3382">3382</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/22739">22739</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0778">ADV-2007-0778</ref></refs><vuln_soft><prod name="Admin Phorum" vendor="Admin Phorum"><vers num="3.3.1a"/></prod></vuln_soft></entry><entry CVSS_base_score="6.2" CVSS_exploit_subscore="1.9" CVSS_impact_subscore="10.0" CVSS_score="6.2" CVSS_vector="(AV:L/AC:H/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-03-06" name="CVE-2007-1220" published="2007-03-02" seq="2007-1220" severity="Medium" type="CVE"><desc><descript source="cve">The Hypervisor in Microsoft Xbox 360 kernel 4532 and 4548 does not properly verify the parameters passed to the syscall dispatcher, which allows attackers with physical access to bypass code-signing requirements and execute arbitrary code.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/461489/100/0/threaded">20070227 Xbox 360 Hypervisor Privilege Escalation Vulnerability</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/22745">22745</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2367">2367</ref></refs><vuln_soft><prod name="Xbox 360 kernel" vendor="Microsoft"><vers num="4532"/><vers num="4548"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-03-06" name="CVE-2007-1221" published="2007-03-02" seq="2007-1221" severity="High" type="CVE"><desc><descript source="cve">The Hypervisor in Microsoft Xbox 360 kernel 4532 and 4548 allows attackers with physical access to force execution of the hypervisor syscall with a certain register set, which bypasses intended code protection.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/461489/100/0/threaded">20070227 Xbox 360 Hypervisor Privilege Escalation Vulnerability</ref><ref source="BID" url="http://www.securityfocus.com/bid/22745">22745</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/463974/100/200/threaded">20070327 Re: RE: Xbox 360 Hypervisor Privilege Escalation Vulnerability</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2367">2367</ref></refs><vuln_soft><prod name="Xbox 360 kernel" vendor="Microsoft"><vers num="4532"/><vers num="4548"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-03-06" name="CVE-2007-1222" published="2007-03-02" seq="2007-1222" severity="High" type="CVE"><desc><descript source="cve">Parallels Desktop for Mac before 20070216 implements Drag and Drop by sharing the entire host filesystem as the .psf share, which allows local users of the guest operating system to write arbitrary files to the host filesystem, and execute arbitrary code via launchd by writing a plist file to a LaunchAgents directory.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref source="MLIST" url="http://lists.immunitysec.com/pipermail/dailydave/2007-February/004091.html">[dailydave] 20070216 Minor Virtualization Vulnerability</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24171">24171</ref></refs><vuln_soft><prod name="Parallels Desktop" vendor="Parallels"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-03-06" name="CVE-2007-1223" published="2007-03-02" seq="2007-1223" severity="High" type="CVE"><desc><descript source="cve">Unspecified vulnerability in Hitachi OSAS/FT/W before 20070223 allows attackers to cause a denial of service (responder control processing halt) by sending &quot;data unexpectedly through the port&quot;.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref source="" url="http://www.hitachi-support.com/security_e/vuls_e/HS07-004_e/index-e.html"></ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32696">osas-unspecified-dos(32696)</ref></refs><vuln_soft><prod name="OSAS" vendor="Hitachi"><vers edition="HI_UX" num="01_04"/><vers edition="Solaris" num="01_05"/><vers edition="AIX" num="01_10"/><vers edition="HI_UX" num="01_10"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0" modified="2007-03-06" name="CVE-2007-1224" published="2007-03-02" seq="2007-1224" severity="Medium" type="CVE"><desc><descript source="cve">Grok Developments NetProxy 4.03 allows remote attackers to bypass URL filtering via a request that omits &quot;http://&quot; from the URL and specifies the destination port (:80).</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3381">3381</ref><ref source="BID" url="http://www.securityfocus.com/bid/22741">22741</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0779">ADV-2007-0779</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32697">netproxy-url-filtering-bypass(32697)</ref></refs><vuln_soft><prod name="NetProxy" vendor="Grok Developments"><vers num="4.03"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-03-06" name="CVE-2007-1225" published="2007-03-02" seq="2007-1225" severity="High" type="CVE"><desc><descript source="cve">The connection log file implementation in Grok Developments NetProxy 4.03 does not record requests that omit http:// in a URL, which might allow remote attackers to conduct unauthorized activities and avoid detection.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3381">3381</ref><ref source="BID" url="http://www.securityfocus.com/bid/22741">22741</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0779">ADV-2007-0779</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32697">netproxy-url-filtering-bypass(32697)</ref></refs><vuln_soft><prod name="NetProxy" vendor="Grok Developments"><vers num="4.03"/></prod></vuln_soft></entry><entry CVSS_base_score="4.1" CVSS_exploit_subscore="2.7" CVSS_impact_subscore="6.4" CVSS_score="4.1" CVSS_vector="(AV:L/AC:M/Au:S/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-06-26" name="CVE-2007-1226" published="2007-03-02" seq="2007-1226" severity="Medium" type="CVE"><desc><descript source="cve">McAfee VirusScan for Mac (Virex) before 7.7 patch 1 has weak permissions (0666) for /Library/Application Support/Virex/VShieldExclude.txt, which allows local users to reconfigure Virex to skip scanning of arbitrary files.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/461485/100/0/threaded">20070227 [NETRAGARD-20070220 SECURITY ADVISORY] [McAfee VirusScan for Mac (Virex) Local root exploit and Scan Bypass]</ref><ref adv="1" source="McAfee" url="https://knowledge.mcafee.com/SupportSite/dynamickc.do?externalId=518722&amp;sliceId=SAL_Public&amp;command=show&amp;forward=nonthreadedKC&amp;kcId=518722"></ref><ref source="BID" url="http://www.securityfocus.com/bid/22744">22744</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0777">ADV-2007-0777</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/24337">24337</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017707">1017707</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2342">2342</ref></refs><vuln_soft><prod name="Virex" vendor="McAfee"><vers edition="Macintosh" num="7.7" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.1" CVSS_exploit_subscore="2.7" CVSS_impact_subscore="6.4" CVSS_score="4.1" CVSS_vector="(AV:L/AC:M/Au:S/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-03-06" name="CVE-2007-1227" published="2007-03-02" seq="2007-1227" severity="Medium" type="CVE"><desc><descript source="cve">VShieldCheck in McAfee VirusScan for Mac (Virex) before 7.7 patch 1 allow local users to change permissions of arbitrary files via a symlink attack on /Library/Application Support/Virex/VShieldExclude.txt, as demonstrated by symlinking to the root crontab file to execute arbitrary commands.</descript></desc><sols><sol source="nvd">Apply patch 1 for McAfee Virex version 7.7:
https://mysupport.mcafee.com/eservice_enu/ 
</sol></sols><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/461485/100/0/threaded">20070227 [NETRAGARD-20070220 SECURITY ADVISORY] [McAfee VirusScan for Mac (Virex) Local root exploit and Scan Bypass]</ref><ref source="McAfee" url="https://knowledge.mcafee.com/SupportSite/dynamickc.do?externalId=518722&amp;sliceId=SAL_Public&amp;command=show&amp;forward=nonthreadedKC&amp;kcId=518722">Security Bulletin</ref><ref source="BID" url="http://www.securityfocus.com/bid/22744">22744</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0777">ADV-2007-0777</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24337">24337</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017707">
1017707</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32729">
mcafee-virex-library-privilege-escalation(32729)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2342">2342</ref></refs><vuln_soft><prod name="Virex" vendor="McAfee"><vers num="7.7" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.1" CVSS_exploit_subscore="2.7" CVSS_impact_subscore="6.4" CVSS_score="4.1" CVSS_vector="(AV:L/AC:M/Au:S/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-03-06" name="CVE-2007-1228" published="2007-03-02" seq="2007-1228" severity="Medium" type="CVE"><desc><descript source="cve">IBM DB2 UDB 8.2 before Fixpak 7 (aka fixpack 14), and DB2 9 before Fix Pack 2, on UNIX allows the &quot;fenced&quot; user to access certain unauthorized directories.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref adv="1" source="AIXAPAR" url="http://www-1.ibm.com/support/docview.wss?uid=swg1IY86711">IY86711</ref><ref adv="1" source="AIXAPAR" url="http://www-1.ibm.com/support/docview.wss?uid=swg1IY87492">IY87492</ref><ref source="BID" url="http://www.securityfocus.com/bid/22729">22729</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017731">
1017731</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24387">
24387</ref></refs><vuln_soft><prod name="DB2" vendor="IBM"><vers num="9.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" modified="2007-06-27" name="CVE-2007-1229" published="2007-03-02" seq="2007-1229" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in the Nullsoft ShoutcastServer 1.9.7 allows remote attackers to inject arbitrary web script or HTML via the top-level URI on the Incoming interface (port 8001/tcp), which is not properly handled in the administrator interface when viewing the log file.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/461474/100/0/threaded">20070227 Nullsoft ShoutcastServer Persistant XSS - 0day</ref><ref source="BID" url="http://www.securityfocus.com/bid/22742">22742</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0775">ADV-2007-0775</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24323">24323</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32726">shoutcast-admin-interface-xss(32726)</ref></refs><vuln_soft><prod name="SHOUTcast server" vendor="Nullsoft"><vers edition="Win32" num="1.9.7"/></prod></vuln_soft></entry><entry CVSS_base_score="5.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="4.9" CVSS_score="5.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:N)" CVSS_version="2.0" modified="2007-03-06" name="CVE-2007-1230" published="2007-03-02" seq="2007-1230" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in wp-includes/functions.php in WordPress before 2.1.2-alpha allow remote attackers to inject arbitrary web script or HTML via (1) the Referer HTTP header or (2) the URI, a different vulnerability than CVE-2007-1049.</descript></desc><loss_types><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref patch="1" source="" url="http://trac.wordpress.org/changeset/4951"></ref><ref patch="1" source="" url="http://trac.wordpress.org/changeset/4952"></ref><ref patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0756">ADV-2007-0756</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200703-23.xml">
GLSA-200703-23</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24566">
24566</ref></refs><vuln_soft><prod name="WordPress" vendor="WordPress"><vers num="2.1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-03-06" name="CVE-2007-1231" published="2007-03-03" seq="2007-1231" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in SQLiteManager 1.2.0 allow remote attackers to inject arbitrary web script or HTML via the (1) database name, (2) table name, (3) ViewName, (4) view, (5) trigger, and (6) function fields in main.php and certain other files.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/461304/100/0/threaded">20070224 SQLiteManager v1.2.0 Multiple Vulnerabilities</ref><ref source="BID" url="http://www.securityfocus.com/bid/22731">22731</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32692">
sqlitemanager-main-xss(32692)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2366">2366</ref></refs><vuln_soft><prod name="SQLite Manager" vendor="SQLite Manager"><vers num="1.2"/></prod></vuln_soft></entry><entry CVSS_base_score="5.1" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="6.4" CVSS_score="5.1" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-04-10" name="CVE-2007-1232" published="2007-03-03" seq="2007-1232" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in SQLiteManager 1.2.0 allows remote attackers to read arbitrary files via a .. (dot dot) in a SQLiteManager_currentTheme cookie.</descript></desc><impacts><impact source="nvd">Successful exploitation requires that &quot;magic_quotes_gpc&quot; is disabled.  Additionally, in order to exploit this vulnerability to execute arbitrary code, the attacker would first be required to upload a malicious file or inject arbitrary commands into an existing file.</impact></impacts><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/461304/100/0/threaded">20070224 SQLiteManager v1.2.0 Multiple Vulnerabilities</ref><ref source="BID" url="http://www.securityfocus.com/bid/22727">22727</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24296">24296</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32693">sqlitemanager-sqlitemanager-file-include(32693)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2366">2366</ref></refs><vuln_soft><prod name="SQLite Manager" vendor="SQLite Manager"><vers num="1.2"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-03-06" name="CVE-2007-1233" published="2007-03-03" seq="2007-1233" severity="High" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in downloadcounter.php in STWC-Counter 3.4.0.0 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the stwc_counter_verzeichniss parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3379">3379</ref><ref source="BID" url="http://www.securityfocus.com/bid/22723">22723</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32681">stwccounter-downloadcounter-file-include(32681)</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0754">
ADV-2007-0754</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24280">
24280</ref></refs><vuln_soft><prod name="STWC-Counter" vendor="STWC-Counter"><vers num="3.4" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-05-29" name="CVE-2007-1234" published="2007-03-03" seq="2007-1234" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in sitex allow remote attackers to inject arbitrary web script or HTML via (1) the sxYear parameter to calendar.php, (2) the search parameter to search.php, (3) the linkid parameter to redirect.php, or (4) the page parameter to calendar_events.php.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/461305/100/0/threaded">20070223 sitex multiple vulnerabilities</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/465849/100/200/threaded">20070414 Re: sitex multiple vulnerabilities</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2373">2373</ref></refs><vuln_soft><prod name="SiteX" vendor="BJ Sintay"><vers num="0.7.3"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-03-06" name="CVE-2007-1235" published="2007-03-03" seq="2007-1235" severity="High" type="CVE"><desc><descript source="cve">Unrestricted file upload vulnerability in sitex allows remote attackers to upload arbitrary PHP code via an avatar filename with a double extension such as .php.jpg, which fails verification and is saved as a .php file.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/461305/100/0/threaded">20070223 sitex multiple vulnerabilities</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2373">2373</ref></refs><vuln_soft><prod name="SiteX" vendor="BJ Sintay"><vers num="0.7.3"/></prod></vuln_soft></entry><entry CVSS_base_score="6.4" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="4.9" CVSS_score="6.4" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_version="2.0" modified="2007-03-06" name="CVE-2007-1236" published="2007-03-03" seq="2007-1236" severity="Medium" type="CVE"><desc><descript source="cve">sitex allows remote attackers to obtain sensitive information via a request with a numerical value for the (1) sxMonth[] or (2) sxYear[] parameter to calendar.php, or the (3) page[] parameter to calendar_events.php, which reveals the path in various error messages.</descript></desc><loss_types><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/461305/100/0/threaded">20070223 sitex multiple vulnerabilities</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2373">2373</ref></refs><vuln_soft><prod name="sitex" vendor="sitex"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-03-06" name="CVE-2007-1237" published="2007-03-03" seq="2007-1237" severity="High" type="CVE"><desc><descript source="cve">sitex allows remote attackers to obtain potentially sensitive information via a &apos; (quote) value for certain parameters, as demonstrated by parameters used in forum and search, which forces a SQL error.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/461305/100/0/threaded">20070223 sitex multiple vulnerabilities</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2373">2373</ref></refs><vuln_soft><prod name="SiteX" vendor="BJ Sintay"><vers num="0.7.3"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:N/AC:H/Au:S/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-03-06" name="CVE-2007-1238" published="2007-03-03" seq="2007-1238" severity="Medium" type="CVE"><desc><descript source="cve">Microsoft Office 2003 allows user-assisted remote attackers to cause a denial of service (application crash) by attempting to insert a corrupted WMF file.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/461373/100/0/threaded">20070225 Few unreported vulnerabilities by SehaTo</ref><ref source="" url="http://securityvulns.com/Qdocument120.html"></ref></refs><vuln_soft><prod name="Office" vendor="Microsoft"><vers num="2003"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:P)" CVSS_version="2.0" modified="2007-03-06" name="CVE-2007-1239" published="2007-03-03" seq="2007-1239" severity="Medium" type="CVE"><desc><descript source="cve">Microsoft Excel 2003 does not properly parse .XLS files, which allows remote attackers to cause a denial of service (application crash) via a file with a (1) corrupted XML format or a (2) corrupted XLS format, which triggers a NULL pointer dereference.</descript></desc><loss_types><avail/></loss_types><vuln_types><design/></vuln_types><range><network/><user_init/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/461373/100/0/threaded">20070225 Few unreported vulnerabilities by SehaTo</ref><ref source="" url="http://securityvulns.com/news/Microsoft/Excel/XML/DoS.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/22717">
22717</ref></refs><vuln_soft><prod name="Excel" vendor="Microsoft"><vers num="2003"/><vers edition="SP1" num="2003"/><vers edition="SP2" num="2003"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-03-06" name="CVE-2007-1240" published="2007-03-03" seq="2007-1240" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Docebo CMS 3.0.3 through 3.0.5 allow remote attackers to inject arbitrary web script or HTML via (1) the searchkey parameter to index.php, or the (2) sn or (3) ri parameter to modules/htmlframechat/index.php.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://downloads.securityfocus.com/vulnerabilities/exploits/22719.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/22719">22719</ref></refs><vuln_soft><prod name="Docebo" vendor="Docebo"><vers num="3.0.3"/><vers num="3.0.4"/><vers num="3.0.5"/></prod></vuln_soft></entry><entry CVSS_base_score="5.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="4.9" CVSS_score="5.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:N)" CVSS_version="2.0" modified="2007-03-06" name="CVE-2007-1241" published="2007-03-03" seq="2007-1241" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in setup.php in Audins Audiens 3.3 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript></desc><loss_types><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://downloads.securityfocus.com/vulnerabilities/exploits/22728.html"></ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/22728">22728</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32839">
audins-setup-xss(32839)</ref></refs><vuln_soft><prod name="Audins Audiens" vendor="Audins Audiens"><vers num="3.3"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-03-06" name="CVE-2007-1242" published="2007-03-03" seq="2007-1242" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in system/index.php in Audins Audiens 3.3 allows remote attackers to execute arbitrary SQL commands via the PHPSESSID cookie.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/22728">22728</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32837">
audins-index-sql-injection(32837)</ref></refs><vuln_soft><prod name="Audins Audiens" vendor="Audins Audiens"><vers num="3.3"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-03-06" name="CVE-2007-1243" published="2007-03-03" seq="2007-1243" severity="High" type="CVE"><desc><descript source="cve">Audins Audiens 3.3 allows remote attackers to bypass authentication and perform certain privileged actions, possibly an uninstall of the product, by calling unistall.php with the values cnf=disinstalla and status=on.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/22728">22728</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24254">24254</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32707">audins-unistall-authentication-bypass(32707)</ref></refs><vuln_soft><prod name="Audins Audiens" vendor="Audins Audiens"><vers num="3.3"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-03-06" name="CVE-2007-1244" published="2007-03-03" seq="2007-1244" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site request forgery (CSRF) vulnerability in the AdminPanel in WordPress 2.1.1 and earlier allows remote attackers to perform privileged actions as administrators, as demonstrated using the delete action in wp-admin/post.php.  NOTE: this issue can be leveraged to perform cross-site scripting (XSS) attacks and steal cookies via the post parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/461351/100/0/threaded">20070226 WordPress AdminPanel CSRF/XSS - 0day</ref><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/22735">22735</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200703-23.xml">
GLSA-200703-23</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24566">
24566</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32703">
wordpress-post-csrf(32703)</ref></refs><vuln_soft><prod name="WordPress" vendor="WordPress"><vers num="2.1.1" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:P)" CVSS_version="2.0" modified="2008-02-29" name="CVE-2007-1245" published="2007-03-03" seq="2007-1245" severity="Medium" type="CVE"><desc><descript source="cve">IrfanView 3.99 allows remote attackers to cause a denial of service (application crash) via a malformed WMF file.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/461373/100/0/threaded">20070225 Few unreported vulnerabilities by SehaTo</ref><ref source="" url="http://securityvulns.com/Qdocument120.html"></ref><ref source="" url="http://securityvulns.com/news/IrfanView/WMF/DoS.html"></ref></refs><vuln_soft><prod name="IrfanView" vendor="IrfanView"><vers num="3.99"/></prod></vuln_soft></entry><entry CVSS_base_score="7.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="10.0" CVSS_score="7.6" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-04-16" name="CVE-2007-1246" published="2007-03-03" seq="2007-1246" severity="High" type="CVE"><desc><descript source="cve">The DMO_VideoDecoder_Open function in loader/dmo/DMO_VideoDecoder.c in MPlayer 1.0rc1 and earlier, as used in xine-lib, does not set the biSize before use in a memcpy, which allows user-assisted remote attackers to cause a buffer overflow and possibly execute arbitrary code, a different vulnerability than CVE-2007-1387.</descript></desc><impacts><impact source="nvd">Failed exploit attempts will likely result in a denial-of-service condition.</impact></impacts><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/><user_init/></range><refs><ref source="" url="http://svn.mplayerhq.hu/mplayer/trunk/loader/dmo/DMO_VideoDecoder.c?r1=22019&amp;r2=22204"></ref><ref patch="1" source="" url="http://svn.mplayerhq.hu/mplayer/trunk/loader/dmo/DMO_VideoDecoder.c"></ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0794">ADV-2007-0794</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/32747">mplayer-dmovideodecoder-bo(32747)</ref><ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2007-March/052738.html">20070301 MPlayer DMO buffer overflow</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2007:055">MDKSA-2007:055</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2007:057">MDKSA-2007:057</ref><ref source="UBUNTU" url="http://www.ubuntu.com/usn/usn-433-1">USN-433-1</ref><ref source="BID" url="http://www.securityfocus.com/bid/22771">22771</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24448">24448</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24462">24462</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24444">24444</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24446">24446</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2007_5_sr.html">SUSE-SR:2007:005</ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200704-09.xml">
GLSA-200704-09</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24897">
24897</ref><ref source="SLACKWARE" url="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2007&amp;m=slackware-security.449141">
SSA:2007-109-02</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2007_007_suse.html">
SUSE-SR:2007:007</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24995">
24995</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24866">
24866</ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200705-21.xml">GLSA-200705-21</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:055">MDKSA-2007:055</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:057">MDKSA-2007:057</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25462">25462</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24443">24443</ref><ref source="DEBIAN" url="http://www.debian.org/security/2008/dsa-1536">DSA-1536</ref><ref source="SECUNIA" url="http://secunia.com/advisories/29601">29601</ref></refs><vuln_soft><prod name="Mplayer" vendor="Mplayer"><vers num="1.0 rc1" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2008-02-29" name="CVE-2007-1247" published="2007-03-03" seq="2007-1247" severity="Medium" type="CVE"><desc><descript source="cve">Multiple PHP remote file inclusion vulnerabilities in aWeb Labs aWebNews 1.5 allow remote attackers to execute arbitrary PHP code via a URL in the path_to_news parameter to (1) listing.php or (2) visview.php.</descript></desc><impacts><impact source="nvd">Successful exploitation requires that &quot;register_globals&quot; is enabled.</impact></impacts><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/461684/100/0/threaded">20070301 aWebNews V 1.1</ref><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/461680/100/0/threaded">20070301 aWebNews v 1.1=&gt;RFI</ref><ref source="BID" url="http://www.securityfocus.com/bid/22781">22781</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24351">24351</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0808">ADV-2007-0808</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32770">awebnews-pathtonews-file-include(32770)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2365">2365</ref></refs><vuln_soft><prod name="aWebNews" vendor="aWeb Labs"><vers num="1.5"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" modified="2008-02-29" name="CVE-2007-1248" published="2007-03-03" seq="2007-1248" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in built2go News Manager Blog 1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) cid, (2) uid, and (3) nid parameters to (a) news.php, and the nid parameter to (b) rating.php.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/461672/100/0/threaded">20070301 Built2Go v.1.0 =&gt; ( news.php &amp; rating.php ) Cross Site Scripting</ref><ref source="BID" url="http://www.securityfocus.com/bid/22783">22783</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0818">ADV-2007-0818</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24334">24334</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32772">newsmanagerblog-news-rating-xss(32772)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2343">2343</ref></refs><vuln_soft><prod name="News Manager Blog" vendor="Built2Go"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-03-07" name="CVE-2007-1249" published="2007-03-03" seq="2007-1249" severity="Medium" type="CVE"><desc><descript source="cve">MoveSortedContentAction in C1 Financial Services Contelligent 9.1.4 does not check &quot;the additional environment security configuration,&quot; which allows remote attackers with write permissions to reorder components.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref source="" url="http://www.contelligent.com/contell/cms/c1web/contelligent/site/contelligent/changelog.html?fromRelease=9.1.4"></ref><ref source="BID" url="http://www.securityfocus.com/bid/22785">22785</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24364">24364</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0814">
ADV-2007-0814</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32775">
contelligent-sortedcontent-security-bypass(32775)</ref></refs><vuln_soft><prod name="C1 Financial Services" vendor="Contelligent"><vers num="9.1.4"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-03-07" name="CVE-2007-1250" published="2007-03-03" seq="2007-1250" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in section/default.asp in ANGEL Learning Management Suite (LMS) 7.1 allows remote attackers to execute arbitrary SQL commands via the id parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/461638/100/0/threaded">20070301 Angel LMS 7.1 - Remote SQL Injection</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/461673/100/0/threaded">20070301 Re: Angel LMS 7.1 - Remote SQL Injection</ref><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3390">3390</ref><ref source="BID" url="http://www.securityfocus.com/bid/22768">22768</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/461811/100/0/threaded">
20070301 [Fwd: Re: Angel LMS 7.1 - Remote SQL Injection]</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0807">
ADV-2007-0807</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24368">
24368</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32756">
angellms-default-sql-injection(32756)</ref></refs><vuln_soft><prod name="Learning Management Suite" vendor="Angel Learning"><vers num="7.1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-03-07" name="CVE-2007-1251" published="2007-03-03" seq="2007-1251" severity="Medium" type="CVE"><desc><descript source="cve">Format string vulnerability in the new_warning function in ntserv/warning.c for Netrek Vanilla Server 2.12.0, when EVENTLOG is enabled, allows remote attackers to cause a denial of service (crash) or execute arbitrary code via format string specifiers in the message handling.</descript></desc><sols><sol source="nvd">This vulnerability is addressed in the following product update: 
http://sourceforge.net/project/shownotes.php?release_id=490561</sol></sols><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://aluigi.altervista.org/adv/netrekfs-adv.txt"></ref><ref source="" url="http://sourceforge.net/project/shownotes.php?release_id=490561"></ref><ref source="BID" url="http://www.securityfocus.com/bid/22786">22786</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24357">24357</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/461755/100/0/threaded">

20070302 Limited format string in Netrek 2.12.0</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0815">
ADV-2007-0815</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32777">
vanilla-vsprintf-format-string(32777)</ref></refs><vuln_soft><prod name="Netrek Vanilla Server" vendor="SourceForge"><vers num="2.12.0" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" CVSS_score="9.3" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-03-13" name="CVE-2007-1252" published="2007-03-03" seq="2007-1252" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in Symantec Mail Security for SMTP 5.0 before Patch 175 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via crafted headers in an e-mail message.  NOTE: some information was obtained from third party sources.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref source="" url="ftp://ftp.symantec.com/public/english_us_canada/products/symantec_mail_security/5.0_smtp/updates/release_notes_p175.txt"></ref><ref adv="1" patch="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/875633">VU#875633</ref><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/22782">22782</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0799">ADV-2007-0799</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24371">24371</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017716">
1017716</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32781">
symantec-email-headers-code-execution(32781)</ref></refs><vuln_soft><prod name="Symantec Mail Security SMTP" vendor="Symantec"><vers num="5.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.1" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="6.4" CVSS_score="5.1" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-03-07" name="CVE-2007-1253" published="2007-03-03" seq="2007-1253" severity="Medium" type="CVE"><desc><descript source="cve">Eval injection vulnerability in the (a) kmz_ImportWithMesh.py Script for Blender 0.1.9h, as used in (b) Blender before 2.43, allows user-assisted remote attackers to execute arbitrary Python code by importing a crafted (1) KML or (2) KMZ file.</descript></desc><sols><sol source="nvd">This vulnerability is addressed in the following product update:
http://www.blender.org/download/get-blender/</sol></sols><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="" url="http://secunia.com/secunia_research/2007-39/advisory/"></ref><ref adv="1" source="" url="http://secunia.com/secunia_research/2007-40/advisory/"></ref><ref source="BID" url="http://www.securityfocus.com/bid/22770">22770</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0798">ADV-2007-0798</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017714">1017714</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24232">24232</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24233">24233</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32778">
blender-kml-kmz-command-execution(32778)</ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200704-19.xml">
GLSA-200704-19</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24991">
24991</ref></refs><vuln_soft><prod name="Blender" vendor="Blender Foundation"><vers num="2.25" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.5" CVSS_exploit_subscore="8.0" CVSS_impact_subscore="6.4" CVSS_score="6.5" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-03-07" name="CVE-2007-1254" published="2007-03-03" seq="2007-1254" severity="Medium" type="CVE"><desc><descript source="cve">SQL injection vulnerability in part.userprofile.php in Connectix Boards 0.7 and earlier allows remote authenticated users to execute arbitrary SQL commands and obtain privileges via the p_skin parameter to index.php.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/460947/100/0/threaded">20070221 Connectix Boards &lt;= 0.7 (p_skin) Multiple Vulnerabilities Exploit</ref><ref source="MILW0RM" url="http://milw0rm.com/exploits/3352">3352</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24255">24255</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2364">2364</ref></refs><vuln_soft><prod name="Connectix Boards" vendor="Connectix"><vers num="0.4"/><vers num="0.4.1"/><vers num="0.4.2"/><vers num="0.4.3"/><vers num="0.4.4"/><vers num="0.5"/><vers num="0.5.1"/><vers num="0.5.2"/><vers num="0.5.3"/><vers num="0.5.4"/><vers num="0.5.5"/><vers num="0.6"/><vers num="0.6.1"/><vers num="0.7"/></prod></vuln_soft></entry><entry CVSS_base_score="6.0" CVSS_exploit_subscore="6.8" CVSS_impact_subscore="6.4" CVSS_score="6.0" CVSS_vector="(AV:N/AC:M/Au:S/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-03-07" name="CVE-2007-1255" published="2007-03-03" seq="2007-1255" severity="Medium" type="CVE"><desc><descript source="cve">Unrestricted file upload vulnerability in admin.bbcode.php in Connectix Boards 0.7 and earlier allows remote authenticated administrators to execute arbitrary PHP code by uploading a crafted GIF smiley image with a .php extension via the uploadimage parameter to admin.php, which can be later accessed via a direct request for the file in smileys/.  NOTE: this can be leveraged with a separate SQL injection issue for remote unauthenticated attacks.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/460947/100/0/threaded">20070221 Connectix Boards &lt;= 0.7 (p_skin) Multiple Vulnerabilities Exploit</ref><ref source="MILW0RM" url="http://milw0rm.com/exploits/3352">3352</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24255">24255</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2364">2364</ref></refs><vuln_soft><prod name="Connectix Boards" vendor="Connectix"><vers num="0.4"/><vers num="0.4.1"/><vers num="0.4.2"/><vers num="0.4.3"/><vers num="0.4.4"/><vers num="0.5"/><vers num="0.5.1"/><vers num="0.5.2"/><vers num="0.5.3"/><vers num="0.5.4"/><vers num="0.5.5"/><vers num="0.6"/><vers num="0.6.1"/><vers num="0.7"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-03-07" name="CVE-2007-1256" published="2007-03-03" seq="2007-1256" severity="Medium" type="CVE"><desc><descript source="cve">Mozilla Firefox 2.0.0.2 allows remote attackers to spoof the address bar, favicons, and document source, and perform updates in the context of arbitrary websites, by repeatedly setting document.location in the onunload attribute when linking to another website, a variant of CVE-2007-1092.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><design/></vuln_types><range><network/><user_init/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/461437/100/0/threaded">20070227 Re: [Full-disclosure] Firefox onUnload + document.write() memory corruption vulnerability (MSIE7 null ptr)</ref><ref source="FULLDISC" url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=117259225402112&amp;w=2">20070227 RE: [Full-disclosure] Firefox onUnload + document.write() memory corruption vulnerability (MSIE7 null ptr)</ref><ref source="FULLDISC" url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=117258301222007&amp;w=2">20070227 Re: [Full-disclosure] Firefox onUnload + document.write() memory corruption vulnerability (MSIE7 null ptr)</ref></refs><vuln_soft><prod name="Firefox" vendor="Mozilla"><vers num="2.0"/><vers num="2.0.0.1"/><vers num="2.0.0.2"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-09-28" name="CVE-2007-1257" published="2007-03-03" seq="2007-1257" severity="High" type="CVE"><desc><descript source="cve">The Network Analysis Module (NAM) in Cisco Catalyst Series 6000, 6500, and 7600 allows remote attackers to execute arbitrary commands via certain SNMP packets that are spoofed from the NAM&apos;s own IP address.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref source="CISCO" url="http://www.cisco.com/warp/public/707/cisco-sa-20070228-nam.shtml">20070228 Cisco Catalyst 6000, 6500 Series and Cisco 7600 Series NAM (Network Analysis Module) Vulnerability</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/472412">VU#472412</ref><ref source="BID" url="http://www.securityfocus.com/bid/22751">22751</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0783">ADV-2007-0783</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017710">1017710</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24344">24344</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32750">cisco-catalyst-nam-unauthorized-access(32750)</ref></refs><vuln_soft><prod name="Network Analysis Module" vendor="Cisco"><vers num=""/></prod><prod name="Catalyst 6500" vendor="Cisco"><vers num="2.2 (1a)WS-SVC-NAM-1"/><vers num="2.2 (1a)WS-SVC-NAM-2"/><vers num="3.1 (1a)WS-X6380-NAM"/></prod><prod name="Catalyst 7600" vendor="Cisco"><vers num="2.2 (1a)WS-SVC-NAM-1"/><vers num="2.2 (1a)WS-SVC-NAM-2"/><vers num="3.1 (1a)WS-X6380-NAM"/></prod><prod name="Catalyst 6000" vendor="Cisco"><vers num="2.2 (1a)WS-SVC-NAM-1"/><vers num="2.2 (1a)WS-SVC-NAM-2"/><vers num="3.1 (1a)WS-X6380-NAM"/></prod></vuln_soft></entry><entry CVSS_base_score="6.1" CVSS_exploit_subscore="6.5" CVSS_impact_subscore="6.9" CVSS_score="6.1" CVSS_vector="(AV:A/AC:L/Au:N/C:N/I:N/A:C)" CVSS_version="2.0" modified="2007-08-27" name="CVE-2007-1258" published="2007-03-03" seq="2007-1258" severity="Medium" type="CVE"><desc><descript source="cve">Unspecified vulnerability in Cisco IOS 12.2SXA, SXB, SXD, and SXF; and the MSFC2, MSFC2a and MSFC3 running in Hybrid Mode on Cisco Catalyst 6000, 6500 and Cisco 7600 series systems; allows remote attackers on a local network segment to cause a denial of service (software reload) via a certain MPLS packet.</descript></desc><loss_types><avail/></loss_types><vuln_types><design/></vuln_types><range><local_network/></range><refs><ref source="CISCO" url="http://www.cisco.com/warp/public/707/cisco-sa-20070228-mpls.shtml">20070228 Cisco Catalyst 6000, 6500 and Cisco 7600 Series MPLS Packet Vulnerability</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0782">ADV-2007-0782</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017709">1017709</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24348">24348</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32748">cisco-catalyst-mpls-dos(32748)</ref></refs><vuln_soft><prod name="Catalyst 6500" vendor="Cisco"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-04-16" name="CVE-2007-1259" published="2007-03-03" seq="2007-1259" severity="High" type="CVE"><desc><descript source="cve">Multiple unspecified vulnerabilities in WebAPP before 0.9.9.6 have unknown impact and attack vectors.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref patch="1" source="" url="http://www.web-app.org/cgi-bin/index.cgi?action=viewnews&amp;id=252"></ref><ref patch="1" source="" url="http://www.web-app.org/cgi-bin/index.cgi?action=viewnews&amp;id=254"></ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0720">ADV-2007-0720</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24227">24227</ref></refs><vuln_soft><prod name="WebAPP" vendor="Web-APP.org"><vers num="0.9.9"/><vers num="0.9.9.1"/><vers num="0.9.9.2"/><vers num="0.9.9.2.1"/><vers num="0.9.9.3"/><vers num="0.9.9.3.1"/><vers num="0.9.9.3.2"/><vers num="0.9.9.4"/><vers num="0.9.9.5"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-03-07" name="CVE-2007-1260" published="2007-03-03" seq="2007-1260" severity="High" type="CVE"><desc><descript source="cve">Stack-based buffer overflow in the connectHandle function in server.cpp in WebMod 0.48 allows remote attackers to execute arbitrary code via a long string in the Content-Length HTTP header.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref source="" url="http://cybermind.user.stfunoob.com/w48crash/"></ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24346">24346</ref><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3395">

3395</ref><ref source="BID" url="http://www.securityfocus.com/bid/22788">
22788</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32755">
webmod-contentlength-bo(32755)</ref></refs><vuln_soft><prod name="WebMod" vendor="WebMod"><vers num="0.48"/></prod></vuln_soft></entry><entry CVSS_base_score="6.6" CVSS_exploit_subscore="2.7" CVSS_impact_subscore="10.0" CVSS_score="6.6" CVSS_vector="(AV:L/AC:M/Au:S/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-03-07" name="CVE-2007-1261" published="2007-03-03" seq="2007-1261" severity="Medium" type="CVE"><desc><descript source="cve">Unspecified vulnerability in the reports system in OpenBiblio before 0.6.0 allows attackers to gain privileges via unspecified vectors.</descript></desc><sols><sol source="nvd">This vulnerability is addressed in the following product update:
http://sourceforge.net/project/showfiles.php?group_id=50071</sol></sols><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref source="" url="http://sourceforge.net/project/shownotes.php?group_id=50071&amp;release_id=488061"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0790">ADV-2007-0790</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32758">
openbiblio-reports-privilege-escalation(32758)</ref></refs><vuln_soft><prod name="OpenBiblio" vendor="SourceForge"><vers num="0.5.2" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" modified="2007-10-03" name="CVE-2007-1262" published="2007-05-11" seq="2007-1262" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in the HTML filter in SquirrelMail 1.4.0 through 1.4.9a allow remote attackers to inject arbitrary web script or HTML via the (1) data: URI in an HTML e-mail attachment or (2) various non-ASCII character sets that are not properly filtered when viewed with Microsoft Internet Explorer.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref source="" url="http://www.squirrelmail.org/security/issue/2007-05-09"></ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1748">ADV-2007-1748</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/25200">25200</ref><ref source="DEBIAN" url="http://www.debian.org/security/2007/dsa-1290">DSA-1290</ref><ref source="BID" url="http://www.securityfocus.com/bid/23910">23910</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1018033">1018033</ref><ref source="REDHAT" url="https://rhn.redhat.com/errata/RHSA-2007-0358.html">RHSA-2007:0358</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25236">25236</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25320">25320</ref><ref source="" url="https://issues.rpath.com/browse/RPL-1353"></ref><ref source="" url="http://docs.info.apple.com/article.html?artnum=306172"></ref><ref source="APPLE" url="http://lists.apple.com/archives/security-announce//2007/Jul/msg00004.html">APPLE-SA-2007-07-31</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:106">MDKSA-2007:106</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2007_13_sr.html">SUSE-SR:2007:013</ref><ref source="BID" url="http://www.securityfocus.com/bid/25159">25159</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/2732">ADV-2007-2732</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25690">25690</ref><ref source="SECUNIA" url="http://secunia.com/advisories/26235">26235</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25787">25787</ref></refs><vuln_soft><prod name="SquirrelMail" vendor="SquirrelMail"><vers num="1.4.0"/><vers num="1.4.1"/><vers num="1.4.2"/><vers num="1.4.3"/><vers num="1.4.3a"/><vers num="1.4.3aa"/><vers num="1.4.3 r3"/><vers num="1.4.3 RC1"/><vers num="1.4.4"/><vers num="1.4.4 RC1"/><vers num="1.4.5"/><vers num="1.4.6"/><vers num="1.4.6 cvs"/><vers num="1.4.6 rc1"/><vers num="1.4.7"/><vers num="1.4.8"/><vers num="1.4.9"/><vers num="1.4.9a"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" modified="2007-03-07" name="CVE-2007-1263" published="2007-03-06" seq="2007-1263" severity="Medium" type="CVE"><desc><descript source="cve">GnuPG 1.4.6 and earlier and GPGME before 1.1.4, when run from the command line, does not visually distinguish signed and unsigned portions of OpenPGP messages with multiple components, which might allow remote attackers to forge the contents of a message without detection.</descript></desc><loss_types><int/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/461958/100/0/threaded">20070305 CORE-2007-0115: GnuPG and GnuPG clients unsigned data injection vulnerability </ref><ref adv="1" patch="1" source="" url="http://www.coresecurity.com/?action=item&amp;id=1687"></ref><ref source="BID" url="http://www.securityfocus.com/bid/22757">22757</ref><ref source="MLIST" url="http://lists.gnupg.org/pipermail/gnupg-users/2007-March/030514.html">
[gnupg-users] 20070306 [Announce] Multiple Messages Problem in GnuPG and GPGME</ref><ref source="" url="https://issues.rpath.com/browse/RPL-1111"></ref><ref source="DEBIAN" url="http://www.debian.org/security/2007/dsa-1266">
DSA-1266</ref><ref source="FEDORA" url="http://fedoranews.org/cms/node/2776">
FEDORA-2007-315</ref><ref source="FEDORA" url="http://fedoranews.org/cms/node/2775">
FEDORA-2007-316</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2007-0106.html">
RHSA-2007:0106</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2007-0107.html">
RHSA-2007:0107</ref><ref source="UBUNTU" url="http://www.ubuntu.com/usn/usn-432-1">
USN-432-1</ref><ref source="UBUNTU" url="http://www.ubuntu.com/usn/usn-432-2">
USN-432-2</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0835">
ADV-2007-0835</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017727">
1017727</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24365">
24365</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24420">
24420</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24438">
24438</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24489">
24489</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24511">
24511</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24544">
24544</ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20070301-01-P.asc">
20070301-01-P</ref><ref source="SUSE" url="http://lists.suse.com/archive/suse-security-announce/2007-Mar/0008.html">
SUSE-SA:2007:024</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24734">
24734</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24650">
24650</ref><ref source="" url="http://support.avaya.com/elmodocs2/security/ASA-2007-144.htm"></ref><ref source="SECUNIA" url="http://secunia.com/advisories/24875">
24875</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:059">MDKSA-2007:059</ref><ref source="TRUSTIX" url="http://www.trustix.org/errata/2007/0009/">2007-0009</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24407">24407</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24419">24419</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2353">2353</ref></refs><vuln_soft><prod name="GPGME" vendor="Gnu"><vers num="1.1.3" prev="1"/></prod><prod name="GnuPG" vendor="GnuPG"><vers num="1.4.6" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" modified="2007-03-07" name="CVE-2007-1264" published="2007-03-06" seq="2007-1264" severity="Medium" type="CVE"><desc><descript source="cve">Enigmail 0.94.2 and earlier does not properly use the --status-fd argument when invoking GnuPG, which prevents Enigmail from visually distinguishing between signed and unsigned portions of OpenPGP messages with multiple components, which allows remote attackers to forge the contents of a message without detection.</descript></desc><loss_types><int/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/461958/100/0/threaded">20070305 CORE-2007-0115: GnuPG and GnuPG clients unsigned data injection vulnerability </ref><ref adv="1" patch="1" source="" url="http://www.coresecurity.com/?action=item&amp;id=1687"></ref><ref source="BID" url="http://www.securityfocus.com/bid/22758">22758</ref><ref source="MLIST" url="http://lists.gnupg.org/pipermail/gnupg-users/2007-March/030514.html">
[gnupg-users] 20070306 [Announce] Multiple Messages Problem in GnuPG and GPGME</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0835">
ADV-2007-0835</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017727">
1017727</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24416">
24416</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2353">2353</ref></refs><vuln_soft><prod name="Enigmail" vendor="Enigmail"><vers num="0.94.2" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.8" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.9" CVSS_score="7.8" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:C/A:N)" CVSS_version="2.0" modified="2007-03-07" name="CVE-2007-1265" published="2007-03-06" seq="2007-1265" severity="High" type="CVE"><desc><descript source="cve">KMail 1.9.5 and earlier does not properly use the --status-fd argument when invoking GnuPG, which prevents KMail from visually distinguishing between signed and unsigned portions of OpenPGP messages with multiple components, which allows remote attackers to forge the contents of a message without detection.</descript></desc><loss_types><int/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/461958/100/0/threaded">20070305 CORE-2007-0115: GnuPG and GnuPG clients unsigned data injection vulnerability </ref><ref source="" url="http://www.coresecurity.com/?action=item&amp;id=1687"></ref><ref source="BID" url="http://www.securityfocus.com/bid/22759">22759</ref><ref source="MLIST" url="http://lists.gnupg.org/pipermail/gnupg-users/2007-March/030514.html">
[gnupg-users] 20070306 [Announce] Multiple Messages Problem in GnuPG and GPGME</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0835">
ADV-2007-0835</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017727">
1017727</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24413">
24413</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2353">2353</ref></refs><vuln_soft><prod name="K-Mail" vendor="KDE"><vers num="0.0.29.2"/><vers num="1.0.23"/><vers num="1.0.24"/><vers num="1.0.25"/><vers num="1.0.26"/><vers num="1.0.27"/><vers num="1.0.28"/><vers num="1.0.29"/><vers num="1.0.29.1"/><vers num="1.0.29.2"/><vers num="1.1"/><vers num="1.101"/><vers num="1.102"/><vers num="1.2"/><vers num="1.3.1"/><vers num="1.7.1"/><vers num="1.86.2.36"/><vers num="1.87"/><vers num="1.88"/><vers num="1.89"/><vers num="1.9.1"/><vers num="1.90"/><vers num="1.92"/><vers num="1.93"/><vers num="1.94"/><vers num="1.95"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" modified="2007-03-07" name="CVE-2007-1266" published="2007-03-06" seq="2007-1266" severity="Medium" type="CVE"><desc><descript source="cve">Evolution 2.8.1 and earlier does not properly use the --status-fd argument when invoking GnuPG, which prevents Evolution from visually distinguishing between signed and unsigned portions of OpenPGP messages with multiple components, which allows remote attackers to forge the contents of a message without detection.</descript></desc><loss_types><int/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/461958/100/0/threaded">20070305 CORE-2007-0115: GnuPG and GnuPG clients unsigned data injection vulnerability </ref><ref adv="1" patch="1" source="" url="http://www.coresecurity.com/?action=item&amp;id=1687"></ref><ref source="BID" url="http://www.securityfocus.com/bid/22760">22760</ref><ref source="MLIST" url="http://lists.gnupg.org/pipermail/gnupg-users/2007-March/030514.html">
[gnupg-users] 20070306 [Announce] Multiple Messages Problem in GnuPG and GPGME</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0835">
ADV-2007-0835</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017727">
1017727</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24412">
24412</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2353">2353</ref></refs><vuln_soft><prod name="Evolution" vendor="GNOME"><vers num="2.8.1" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" modified="2007-03-07" name="CVE-2007-1267" published="2007-03-06" seq="2007-1267" severity="Medium" type="CVE"><desc><descript source="cve">Sylpheed 2.2.7 and earlier does not properly use the --status-fd argument when invoking GnuPG, which prevents Sylpheed from visually distinguishing between signed and unsigned portions of OpenPGP messages with multiple components, which allows remote attackers to forge the contents of a message without detection.</descript></desc><loss_types><int/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/461958/100/0/threaded">20070305 CORE-2007-0115: GnuPG and GnuPG clients unsigned data injection vulnerability </ref><ref adv="1" source="" url="http://www.coresecurity.com/?action=item&amp;id=1687"></ref><ref source="BID" url="http://www.securityfocus.com/bid/22777">22777</ref><ref source="MLIST" url="http://lists.gnupg.org/pipermail/gnupg-users/2007-March/030514.html">
[gnupg-users] 20070306 [Announce] Multiple Messages Problem in GnuPG and GPGME</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0835">
ADV-2007-0835</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017727">
1017727</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24414">
24414</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2353">2353</ref></refs><vuln_soft><prod name="Sylpheed" vendor="Sylpheed"><vers num="2.2.7" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" modified="2007-03-07" name="CVE-2007-1268" published="2007-03-06" seq="2007-1268" severity="Medium" type="CVE"><desc><descript source="cve">Mutt 1.5.13 and earlier does not properly use the --status-fd argument when invoking GnuPG, which prevents Mutt from visually distinguishing between signed and unsigned portions of OpenPGP messages with multiple components, which allows remote attackers to forge the contents of a message without detection.</descript></desc><loss_types><int/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/461958/100/0/threaded">20070305 CORE-2007-0115: GnuPG and GnuPG clients unsigned data injection vulnerability </ref><ref adv="1" source="" url="http://www.coresecurity.com/?action=item&amp;id=1687"></ref><ref source="BID" url="http://www.securityfocus.com/bid/22778">22778</ref><ref source="MLIST" url="http://lists.gnupg.org/pipermail/gnupg-users/2007-March/030514.html">
[gnupg-users] 20070306 [Announce] Multiple Messages Problem in GnuPG and GPGME</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0835">
ADV-2007-0835</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017727">
1017727</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24415">
24415</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2353">2353</ref></refs><vuln_soft><prod name="Mutt" vendor="Mutt"><vers num="1.5.13" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" modified="2007-03-07" name="CVE-2007-1269" published="2007-03-06" seq="2007-1269" severity="Medium" type="CVE"><desc><descript source="cve">GNUMail 1.1.2 and earlier does not properly use the --status-fd argument when invoking GnuPG, which prevents GNUMail from visually distinguishing between signed and unsigned portions of OpenPGP messages with multiple components, which allows remote attackers to forge the contents of a message without detection.</descript></desc><loss_types><int/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/461958/100/0/threaded">20070305 CORE-2007-0115: GnuPG and GnuPG clients unsigned data injection vulnerability </ref><ref adv="1" source="" url="http://www.coresecurity.com/?action=item&amp;id=1687"></ref><ref source="BID" url="http://www.securityfocus.com/bid/22779">22779</ref><ref source="MLIST" url="http://lists.gnupg.org/pipermail/gnupg-users/2007-March/030514.html">
[gnupg-users] 20070306 [Announce] Multiple Messages Problem in GnuPG and GPGME</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0835">
ADV-2007-0835</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017727">
1017727</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24417">
24417</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2353">2353</ref></refs><vuln_soft><prod name="GNUMail" vendor="Gnu"><vers num="1.1.2" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" modified="2008-03-03" name="CVE-2007-1270" published="2007-04-05" seq="2007-1270" severity="Medium" type="CVE"><desc><descript source="cve">Double free vulnerability in VMware ESX Server 3.0.0 and 3.0.1 allows attackers to cause a denial of service (crash), obtain sensitive information, or possibly execute arbitrary code via unspecified vectors.</descript></desc><loss_types><int/></loss_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/464745/100/0/threaded">20070404 VMSA-2007-0003 VMware ESX 3.0.1 and 3.0.0 server security updates</ref><ref source="" url="http://www.vmware.com/support/vi3/doc/esx-5754280-patch.html"></ref><ref source="" url="http://www.vmware.com/support/vi3/doc/esx-6431040-patch.html"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1267">ADV-2007-1267</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24788">24788</ref><ref source="BID" url="http://www.securityfocus.com/bid/23323">23323</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017875">1017875</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2524">2524</ref></refs><vuln_soft><prod name="ESX Server" vendor="VMWare"><vers num="3.0.0"/><vers num="3.0.1"/><vers num="3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="6.6" CVSS_exploit_subscore="2.7" CVSS_impact_subscore="10.0" CVSS_score="6.6" CVSS_vector="(AV:L/AC:M/Au:S/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-04-09" name="CVE-2007-1271" published="2007-04-05" seq="2007-1271" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in VMware ESX Server 3.0.0 and 3.0.1 might allow attackers to gain privileges or cause a denial of service (application crash) via unspecified vectors.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/464745/100/0/threaded">20070404 VMSA-2007-0003 VMware ESX 3.0.1 and 3.0.0 server security updates</ref><ref patch="1" source="" url="http://www.vmware.com/support/vi3/doc/esx-5754280-patch.html"></ref><ref patch="1" source="" url="http://www.vmware.com/support/vi3/doc/esx-6431040-patch.html"></ref><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/23322">23322</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1267">ADV-2007-1267</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/24788">24788</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017875">
1017875</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2524">2524</ref></refs><vuln_soft><prod name="ESX Server" vendor="VMWare"><vers num="3.0.0"/><vers num="3.0.1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.9" CVSS_exploit_subscore="3.4" CVSS_impact_subscore="10.0" CVSS_score="6.9" CVSS_vector="(AV:L/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-03-15" name="CVE-2007-1273" published="2007-03-10" seq="2007-1273" severity="Medium" type="CVE"><desc><descript source="cve">Integer overflow in the ktruser function in NetBSD-current before 20061022, NetBSD 3 aand 3-0 before 20061024, and NetBSD 2 before 20070209, when the kernel is built with the COMPAT_FREEBSD or COMPAT_DARWIN option, allows local users to cause a denial of service and possibly gain privileges.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref source="NETBSD" url="ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2007-001.txt.asc">NetBSD-SA2007-001</ref><ref source="BID" url="http://www.securityfocus.com/bid/22878">22878</ref></refs><vuln_soft><prod name="Financials Server" vendor="Navision"><vers num="3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="4.9" CVSS_score="5.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:N)" CVSS_version="2.0" modified="2007-04-16" name="CVE-2007-1276" published="2007-03-05" seq="2007-1276" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in chooser.cgi in Webmin before 1.330 and Usermin before 1.260 allow remote attackers to inject arbitrary web script or HTML via a crafted filename.</descript></desc><loss_types><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://www.webmin.com/changes-1.330.html"></ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0780">ADV-2007-0780</ref><ref source="" url="http://www.webmin.com/security.html"></ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017711">1017711</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24321">24321</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32725">webmin-chooser-xss(32725)</ref></refs><vuln_soft><prod name="Usermin" vendor="Usermin"><vers num="1.000"/><vers num="1.010"/><vers num="1.020"/><vers num="1.030"/><vers num="1.040"/><vers num="1.051"/><vers num="1.060"/><vers num="1.070"/><vers num="1.080"/><vers num="1.090"/><vers num="1.100"/><vers num="1.110"/><vers num="1.120"/><vers num="1.130"/><vers num="1.140"/><vers num="1.150"/><vers num="1.210"/><vers num="1.220"/><vers num="1.230"/><vers num="1.240"/><vers num="1.250"/></prod><prod name="Webmin" vendor="Webmin"><vers num="1.0.00"/><vers num="1.0.10"/><vers num="1.0.20"/><vers num="1.0.30"/><vers num="1.0.40"/><vers num="1.0.50"/><vers num="1.0.51"/><vers num="1.0.60"/><vers num="1.0.70"/><vers num="1.0.80"/><vers num="1.0.90"/><vers num="1.1.00"/><vers num="1.1.10"/><vers num="1.1.20"/><vers num="1.1.21"/><vers num="1.1.30"/><vers num="1.1.40"/><vers num="1.1.50"/><vers num="1.2.20"/><vers num="1.2.30"/><vers num="1.2.40"/><vers num="1.2.50"/><vers num="1.3.20"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-07-16" name="CVE-2007-1277" published="2007-03-05" seq="2007-1277" severity="High" type="CVE"><desc><descript source="cve">WordPress 2.1.1, as downloaded from some official distribution sites during February and March 2007, contains an externally introduced backdoor that allows remote attackers to execute arbitrary commands via (1) an eval injection vulnerability in the ix parameter to wp-includes/feed.php, and (2) an untrusted passthru call in the iz parameter to wp-includes/theme.php.</descript></desc><sols><sol source="nvd">This vulnerability is addressed in the following product update:
http://wordpress.org/development/2007/03/upgrade-212/</sol></sols><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><design/><config/></vuln_types><range><network/></range><refs><ref source="" url="http://ifsec.blogspot.com/2007/03/wordpress-code-compromised-to-enable.html"></ref><ref source="" url="http://wordpress.org/development/2007/03/upgrade-212/"></ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/214480">VU#214480</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/641456">VU#641456</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/461794/100/0/threaded">20070303 WordPress source code compromised to enable remote code execution</ref><ref source="BID" url="http://www.securityfocus.com/bid/22797">22797</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0812">ADV-2007-0812</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24374">24374</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32804">wordpress-feed-code-execution(32804)</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32807">wordpress-theme-command-execution(32807)</ref></refs><vuln_soft><prod name="WordPress" vendor="WordPress"><vers num="2.1.1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-03-19" name="CVE-2007-1278" published="2007-03-16" seq="2007-1278" severity="Medium" type="CVE"><desc><descript source="cve">Unspecified vulnerability in the IIS connector in Adobe JRun 4.0 Updater 6, and ColdFusion MX 6.1 and 7.0 Enterprise, when using Microsoft IIS 6, allows remote attackers to cause a denial of service via unspecified vectors, involving the request of a file in the JRun web root.</descript></desc><sols><sol source="nvd">This vulnerability has been addressed by the vendor with the following patch: http://www.adobe.com/support/security/bulletins/apsb07-07.html </sol></sols><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref patch="1" source="" url="http://www.adobe.com/support/security/bulletins/apsb07-07.html"></ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24488">24488</ref><ref source="BID" url="http://www.securityfocus.com/bid/22958">
22958</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0932">
ADV-2007-0932</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017752">
1017752</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32994">
coldfusion-jrun-iisconnector-dos(32994)</ref></refs><vuln_soft><prod name="ColdFusion MX" vendor="Adobe"><vers edition="Enterprise Server" num="6.1"/><vers edition="Enterprise Server" num="7.0"/></prod><prod name="JRun" vendor="Adobe"><vers num="4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-08-02" name="CVE-2007-1279" published="2007-04-11" seq="2007-1279" severity="High" type="CVE"><desc><descript source="cve">Unspecified vulnerability in the installer for Adobe Bridge 1.0.3 update for Apple OS X, when patching with desktop management tools, allows local users to gain privileges via unspecified vectors during installation of the update by a different user who has administrative privileges.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><range><local/></range><refs><ref adv="1" patch="1" source="" url="http://www.adobe.com/support/security/bulletins/apsb07-09.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/23404">23404</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1342">ADV-2007-1342</ref><ref adv="1" source="SECTRACK" url="http://www.securitytracker.com/id?1017900">1017900</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24854">24854</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33570">bridge-unspecified-privilege-escalation(33570)</ref><ref source="OSVDB" url="http://www.osvdb.org/34896">34896</ref></refs><vuln_soft><prod name="Bridge" vendor="Adobe"><vers num="1.0.3"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" modified="2007-08-01" name="CVE-2007-1280" published="2007-05-09" seq="2007-1280" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in Adobe RoboHelp X5, 6, and Server 6 allows remote attackers to inject arbitrary web script or HTML via a URL after a # (hash) in the URL path, as demonstrated using en/frameset-7.html, and possibly other unspecified vectors involving templates and (1) whstart.js and (2) whcsh_home.htm in WebHelp, (3) wf_startpage.js and (4) wf_startqs.htm in FlashHelp, or (5) WindowManager.dll in RoboHelp Server 6.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" patch="1" source="" url="http://www.adobe.com/support/security/bulletins/apsb07-10.html"></ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/23878">23878</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1714">ADV-2007-1714</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/25211">25211</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/468360/100/0/threaded">20070511 Cross-Site Scripting in Adobe RoboHelp 6, Server 6 and X5</ref><ref source="" url="http://www.devtarget.org/adobe-advisory-05-2007.txt"></ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1018020">1018020</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/34181">robohelp-files-xss(34181)</ref></refs><vuln_soft><prod name="RoboHelp Server" vendor="Adobe"><vers num="6"/></prod><prod name="RoboHelp" vendor="Adobe"><vers num="6"/><vers num="X5"/></prod></vuln_soft></entry><entry CVSS_base_score="7.8" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.9" CVSS_score="7.8" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_version="2.0" modified="2007-04-26" name="CVE-2007-1281" published="2007-03-05" seq="2007-1281" severity="High" type="CVE"><desc><descript source="cve">Kaspersky AntiVirus Engine 6.0.1.411 for Windows and 5.5-10 for Linux allows remote attackers to cause a denial of service (CPU consumption) via a crafted UPX compressed file with a negative offset, which triggers an infinite loop during decompression.</descript></desc><loss_types><avail/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="IDEFENSE" url="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=485">20070302 Kaspersky AntiVirus UPX File Decompression DoS Vulnerability</ref><ref source="BID" url="http://www.securityfocus.com/bid/22795">22795</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017718">1017718</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0810">ADV-2007-0810</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24391">24391</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32797">kaspersky-upx-dos(32797)</ref></refs><vuln_soft><prod name="Kaspersky Antivirus Engine" vendor="Kaspersky Lab"><vers num="6.0.1.411"/><vers num="5.5.10"/></prod></vuln_soft></entry><entry CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" CVSS_score="9.3" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-04-26" name="CVE-2007-1282" published="2007-03-05" seq="2007-1282" severity="High" type="CVE"><desc><descript source="cve">Integer overflow in Mozilla Thunderbird before 1.5.0.10 and SeaMonkey before 1.0.8 allows remote attackers to trigger a buffer overflow and possibly execute arbitrary code via a text/enhanced or text/richtext e-mail message with an extremely long line.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/><user_init/></range><refs><ref patch="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2007-0078.html">RHSA-2007:0078</ref><ref patch="1" source="" url="http://www.mozilla.org/security/announce/2007/mfsa2007-10.html"></ref><ref source="" url="https://bugzilla.mozilla.org/show_bug.cgi?id=362735"></ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200703-18.xml">GLSA-200703-18</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2007-0108.html">RHSA-2007:0108</ref><ref source="BID" url="http://www.securityfocus.com/bid/22845">22845</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0824">ADV-2007-0824</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24522">24522</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32810">mozilla-email-messages-overflow(32810)</ref><ref source="DEBIAN" url="http://www.debian.org/security/2007/dsa-1336">DSA-1336</ref><ref source="FEDORA" url="http://fedoranews.org/cms/node/2747">FEDORA-2007-308</ref><ref source="FEDORA" url="http://fedoranews.org/cms/node/2749">FEDORA-2007-309</ref><ref source="SLACKWARE" url="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2007&amp;m=slackware-security.363947">SSA:2007-066-04</ref><ref source="SLACKWARE" url="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2007&amp;m=slackware-security.338131">SSA:2007-066-05</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24406">24406</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24456">24456</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24457">24457</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25588">25588</ref></refs><vuln_soft><prod name="SeaMonkey" vendor="Mozilla"><vers num="1.0"/><vers num="1.0.1"/><vers num="1.0.2"/><vers num="1.0.3"/><vers num="1.0.4"/><vers num="1.0.5"/><vers num="1.0.6"/><vers num="1.0.7"/></prod><prod name="Thunderbird" vendor="Mozilla"><vers num="0.1"/><vers num="0.2"/><vers num="0.3"/><vers num="0.4"/><vers num="0.5"/><vers num="0.6"/><vers num="0.7"/><vers num="0.7.1"/><vers num="0.7.2"/><vers num="0.7.3"/><vers num="0.8"/><vers num="0.9"/><vers num="1.0"/><vers num="1.0.1"/><vers num="1.0.2"/><vers num="1.0.3"/><vers num="1.0.4"/><vers num="1.0.5"/><vers num="1.0.6"/><vers num="1.0.7"/><vers num="1.0.8"/><vers num="1.5"/><vers num="1.5.0.1"/><vers num="1.5.0.2"/><vers num="1.5.0.3"/><vers num="1.5.0.4"/><vers num="1.5.0.6"/><vers num="1.5.0.7"/><vers num="1.5.0.8"/><vers num="1.5.0.9"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0" modified="2007-08-03" name="CVE-2007-1285" published="2007-03-06" seq="2007-1285" severity="Medium" type="CVE"><desc><descript source="cve">The Zend Engine in PHP 4.x before 4.4.7, and 5.x before 5.2.2, allows remote attackers to cause a denial of service (stack exhaustion and PHP crash) via deeply nested arrays, which trigger deep recursion in the variable destruction routines.</descript></desc><loss_types><avail/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="" url="http://www.php-security.org/MOPB/MOPB-03-2007.html"></ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2007-0082.html">RHSA-2007:0082</ref><ref source="BID" url="http://www.securityfocus.com/bid/22764">22764</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017771">1017771</ref><ref source="REDHAT" url="http://rhn.redhat.com/errata/RHSA-2007-0154.html">RHSA-2007:0154</ref><ref source="REDHAT" url="http://rhn.redhat.com/errata/RHSA-2007-0155.html">RHSA-2007:0155</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24910">24910</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24924">24924</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/466166/100/0/threaded">20070418 rPSA-2007-0073-1 php php-mysql php-pgsql</ref><ref source="" url="https://issues.rpath.com/browse/RPL-1268"></ref><ref source="REDHAT" url="http://rhn.redhat.com/errata/RHSA-2007-0163.html">RHSA-2007:0163</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2007-0162.html">RHSA-2007:0162</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24945">24945</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24941">24941</ref><ref source="" url="http://us2.php.net/releases/4_4_7.php"></ref><ref source="" url="http://us2.php.net/releases/5_2_2.php"></ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2007:087">MDKSA-2007:087</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2007:088">MDKSA-2007:088</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2007:089">MDKSA-2007:089</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24909">24909</ref><ref source="" url="http://www.php.net/ChangeLog-5.php#5.2.4"></ref><ref source="" url="http://www.php.net/releases/5_2_4.php"></ref><ref source="" url="https://launchpad.net/bugs/173043"></ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200705-19.xml">GLSA-200705-19</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:087">MDKSA-2007:087</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:088">MDKSA-2007:088</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:089">MDKSA-2007:089</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:090">MDKSA-2007:090</ref><ref source="SUSE" url="http://lists.opensuse.org/opensuse-security-announce/2007-07/msg00006.html">SUSE-SA:2007:044</ref><ref source="UBUNTU" url="http://www.ubuntulinux.org/support/documentation/usn/usn-549-1">USN-549-1</ref><ref source="UBUNTU" url="http://www.ubuntu.com/usn/usn-549-2">USN-549-2</ref><ref source="OSVDB" url="http://www.osvdb.org/32769">32769</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25445">25445</ref><ref source="SECUNIA" url="http://secunia.com/advisories/26048">26048</ref><ref source="SECUNIA" url="http://secunia.com/advisories/26642">26642</ref><ref source="SECUNIA" url="http://secunia.com/advisories/27864">27864</ref><ref source="" url="http://www.php.net/ChangeLog-4.php"></ref><ref source="" url="http://www.php.net/releases/4_4_8.php"></ref><ref source="SLACKWARE" url="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2008&amp;m=slackware-security.335136">SSA:2008-045-03</ref><ref source="SECUNIA" url="http://secunia.com/advisories/28936">28936</ref></refs><vuln_soft><prod name="PHP" vendor="PHP"><vers num="4.0.0"/><vers num="4.0.1"/><vers num="4.0.1 pl1"/><vers num="4.0.1 pl2"/><vers num="4.0.2"/><vers num="4.0.3"/><vers num="4.0.3 pl1"/><vers num="4.0.4"/><vers num="4.0.4 pl1"/><vers num="4.0.5"/><vers num="4.0.6"/><vers num="4.0.7"/><vers num="4.0.7 RC1"/><vers num="4.0.7 RC2"/><vers num="4.0.7 RC3"/><vers num="4.0.7 RC4"/><vers num="4.1.0"/><vers num="4.1.1"/><vers num="4.1.2"/><vers num="4.2.0"/><vers num="4.2.1"/><vers num="4.2.2"/><vers num="4.2.3"/><vers num="4.3"/><vers num="4.3.1"/><vers num="4.3.10"/><vers num="4.3.11"/><vers num="4.3.2"/><vers num="4.3.3"/><vers num="4.3.4"/><vers num="4.3.5"/><vers num="4.3.6"/><vers num="4.3.7"/><vers num="4.3.8"/><vers num="4.3.9"/><vers num="5.0.1"/><vers num="5.0.2"/><vers num="5.0.3"/><vers num="5.0.4"/><vers num="5.0.5"/><vers num="5.1"/><vers num="5.1.0"/><vers num="5.1.1"/><vers num="5.1.2"/><vers num="5.1.3"/><vers num="5.1.4"/><vers num="5.1.5"/><vers num="5.1.6"/><vers num="5.2.0"/><vers num="5.2.1"/></prod><prod name="Engine" vendor="Zend"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-03-07" name="CVE-2007-1286" published="2007-03-06" seq="2007-1286" severity="Medium" type="CVE"><desc><descript source="cve">Integer overflow in PHP 4.4.4 and earlier allows remote context-dependent attackers to execute arbitrary code via a long string to the unserialize function, which triggers the overflow in the ZVAL reference counter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="" url="http://www.php-security.org/MOPB/MOPB-04-2007.html"></ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200703-21.xml">
GLSA-200703-21</ref><ref source="BID" url="http://www.securityfocus.com/bid/22765">
22765</ref><ref source="OSVDB" url="http://www.osvdb.org/32771">
32771</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24606">
24606</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32796">
php-zval-code-execution(32796)</ref><ref source="REDHAT" url="http://rhn.redhat.com/errata/RHSA-2007-0154.html">
RHSA-2007:0154</ref><ref source="REDHAT" url="http://rhn.redhat.com/errata/RHSA-2007-0155.html">
RHSA-2007:0155</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24910">
24910</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24924">
24924</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/466166/100/0/threaded">

20070418 rPSA-2007-0073-1 php php-mysql php-pgsql</ref><ref source="" url="https://issues.rpath.com/browse/RPL-1268"></ref><ref source="REDHAT" url="http://rhn.redhat.com/errata/RHSA-2007-0163.html">
RHSA-2007:0163</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24945">
24945</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24941">
24941</ref><ref source="DEBIAN" url="http://www.debian.org/security/2007/dsa-1282">
DSA-1282</ref><ref source="DEBIAN" url="http://www.debian.org/security/2007/dsa-1283">
DSA-1283</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25025">
25025</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25062">
25062</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2007:087">
MDKSA-2007:087</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2007:088">
MDKSA-2007:088</ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200705-19.xml">GLSA-200705-19</ref><ref source="HP" url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&amp;cc=us&amp;objectID=c01056506">HPSBMA02215</ref><ref source="HP" url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&amp;cc=us&amp;objectID=c01086137">HPSBTU02232</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:087">MDKSA-2007:087</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:088">MDKSA-2007:088</ref><ref source="TRUSTIX" url="http://www.trustix.org/errata/2007/0009/">2007-0009</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1991">ADV-2007-1991</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/2374">ADV-2007-2374</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25445">25445</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25423">25423</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24419">24419</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25850">25850</ref></refs><vuln_soft><prod name="PHP" vendor="PHP"><vers num="4.4.0.4" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" modified="2007-03-07" name="CVE-2007-1287" published="2007-03-06" seq="2007-1287" severity="Medium" type="CVE"><desc><descript source="cve">A regression error in the phpinfo function in PHP 4.4.3 to 4.4.6, and PHP 6.0 in CVS, allows remote attackers to conduct cross-site scripting (XSS) attacks via GET, POST, or COOKIE array values, which are not escaped in the phpinfo output, as originally fixed for CVE-2005-3388.</descript></desc><loss_types><int/></loss_types><vuln_types><design/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" patch="1" source="" url="http://www.php-security.org/MOPB/MOPB-08-2007.html"></ref><ref source="OSVDB" url="http://www.osvdb.org/32774">
32774</ref><ref source="" url="http://us2.php.net/releases/4_4_7.php"></ref><ref source="" url="http://docs.info.apple.com/article.html?artnum=306172"></ref><ref source="APPLE" url="http://lists.apple.com/archives/security-announce//2007/Jul/msg00004.html">APPLE-SA-2007-07-31</ref><ref source="BID" url="http://www.securityfocus.com/bid/25159">25159</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/2732">ADV-2007-2732</ref><ref source="SECUNIA" url="http://secunia.com/advisories/26235">26235</ref></refs><vuln_soft><prod name="PHP" vendor="PHP"><vers num="4.4.0.4"/><vers num="4.4.5"/><vers num="4.4.6"/><vers num="6.0"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-03-07" name="CVE-2007-1288" published="2007-03-06" seq="2007-1288" severity="High" type="CVE"><desc><descript source="cve">Multiple PHP remote file inclusion vulnerabilities in Webmobo WB News 1.4.1 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the config[installdir] parameter to (1) comment.php, (2) themes.php, (3) directory.php, and (4) sendmsg.php in admin/.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/461674/100/0/threaded">20070301 WB News Remote File Include in all versions</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32774">wbnews-multiple-scripts-file-include(32774)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2355">2355</ref></refs><vuln_soft><prod name="WBNews" vendor="WebMobo"><vers num="1.4.1" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.4" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="4.9" CVSS_score="6.4" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_version="2.0" modified="2007-03-07" name="CVE-2007-1289" published="2007-03-06" seq="2007-1289" severity="Medium" type="CVE"><desc><descript source="cve">SQL injection vulnerability in ViewBugs.php in Tyger Bug Tracking System (TygerBT) 1.1.3 allows remote attackers to execute arbitrary SQL commands via the s parameter.</descript></desc><loss_types><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/461801/100/0/threaded">20070303 Tyger Bug Tracking System Multiple Vulnerability</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/22799">22799</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24385">24385</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0822">
ADV-2007-0822</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32791">
tyger-viewbugs-sql-injection(32791)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2356">2356</ref></refs><vuln_soft><prod name="Bug Tracking System" vendor="Tyger"><vers num="1.1.3"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-03-07" name="CVE-2007-1290" published="2007-03-06" seq="2007-1290" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in ViewReport.php in Tyger Bug Tracking System (TygerBT) 1.1.3 allows remote attackers to execute arbitrary SQL commands via the bug parameter.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="SECUNIA" url="http://secunia.com/advisories/24385">24385</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32791">tyger-viewbugs-sql-injection(32791)</ref></refs><vuln_soft><prod name="Bug Tracking System" vendor="Tyger"><vers num="1.1.3"/></prod></vuln_soft></entry><entry CVSS_base_score="5.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="4.9" CVSS_score="5.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:N)" CVSS_version="2.0" modified="2007-03-07" name="CVE-2007-1291" published="2007-03-06" seq="2007-1291" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Tyger Bug Tracking System (TygerBT) 1.1.3 allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to (1) Login.php and (2) Register.php.</descript></desc><loss_types><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/461801/100/0/threaded">20070303 Tyger Bug Tracking System Multiple Vulnerability</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/22799">22799</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24385">24385</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0822">
ADV-2007-0822</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32792">
tyger-login-register-xss(32792)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2356">2356</ref></refs><vuln_soft><prod name="Bug Tracking System" vendor="Tyger"><vers num="1.1.3"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-03-07" name="CVE-2007-1292" published="2007-03-06" seq="2007-1292" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in inlinemod.php in Jelsoft vBulletin before 3.5.8, and before 3.6.5 in the 3.6.x series, might allow remote authenticated users to execute arbitrary SQL commands via the postids parameter.  NOTE: the vendor states that the attack is feasible only in circumstances &quot;almost impossible to achieve.&quot;</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3387">3387</ref><ref adv="1" patch="1" source="" url="http://www.vbulletin.com/forum/showthread.php?postid=1314422"></ref><ref source="BID" url="http://www.securityfocus.com/bid/22780">22780</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24341">24341</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32746">vbulletin-inlinemod-sql-injection(32746)</ref></refs><vuln_soft><prod name="vBulletin" vendor="Jelsoft"><vers num="3.5.8" prev="1"/><vers num="3.6.0"/><vers num="3.6.1"/><vers num="3.6.2"/><vers num="3.6.3"/><vers num="3.6.4"/><vers num="3.6.5"/></prod></vuln_soft></entry><entry CVSS_base_score="5.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="4.9" CVSS_score="5.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:N)" CVSS_version="2.0" modified="2007-03-07" name="CVE-2007-1293" published="2007-03-06" seq="2007-1293" severity="Medium" type="CVE"><desc><descript source="cve">SQL injection vulnerability in Rigter Portal System (RPS) 6.2, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the categoria parameter to the top-level URI (index.php), possibly related to ver_descarga.php.</descript></desc><loss_types><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3403">3403</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0813">ADV-2007-0813</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24382">24382</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/462146/100/0/threaded">

20070303 RPS 6.2 SQL Injection Exploit</ref><ref source="BID" url="http://www.securityfocus.com/bid/22813">
22813</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32784">
rps-index-sql-injection(32784)</ref></refs><vuln_soft><prod name="Rigter Portal System" vendor="Rigter Portal System"><vers num="6.2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.8" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.9" CVSS_score="7.8" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_version="2.0" modified="2007-03-07" name="CVE-2007-1294" published="2007-03-06" seq="2007-1294" severity="High" type="CVE"><desc><descript source="cve">A certain ActiveX control in the DivXBrowserPlugin (npdivx32.dll) in DivX Web Player, as distributed with DivX Player 1.3.0, allows remote attackers to cause a denial of service (Internet Explorer 7 crash) via large values to DivxWP.Resize, related to resizing images.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3392">3392</ref><ref source="BID" url="http://www.securityfocus.com/bid/22776">22776</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32759">divxwebplayer-npdivx32-dos(32759)</ref></refs><vuln_soft><prod name="DivX Web Player" vendor="DivX"><vers num="1.3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-03-07" name="CVE-2007-1295" published="2007-03-06" seq="2007-1295" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in topic_title.php in AJ Forum 1.0 allows remote attackers to execute arbitrary SQL commands via the td_id parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MILW0RM" url="http://milw0rm.com/exploits/3411">3411</ref><ref source="BID" url="http://www.securityfocus.com/bid/22808">22808</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24378">24378</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0820">
ADV-2007-0820</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32785">
ajforum-topictitle-sql-injection(32785)</ref></refs><vuln_soft><prod name="AJ Forum" vendor="AJ Forum"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-03-07" name="CVE-2007-1296" published="2007-03-06" seq="2007-1296" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in postingdetails.php in AJ Classifieds 1.0 allows remote attackers to execute arbitrary SQL commands via the postingid parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3410">3410</ref><ref source="BID" url="http://www.securityfocus.com/bid/22808">22808</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0833">
ADV-2007-0833</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32786">
ajclassifieds-postingdetails-sql-injection(32786)</ref></refs><vuln_soft><prod name="AJ Classifieds" vendor="AJ Square"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-03-07" name="CVE-2007-1297" published="2007-03-06" seq="2007-1297" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in view_profile.php in AJDating 1.0 allows remote attackers to execute arbitrary SQL commands via the user_id parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3409">3409</ref><ref source="BID" url="http://www.securityfocus.com/bid/22808">22808</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0821">
ADV-2007-0821</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24376">
24376</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32788">
ajdating-viewprofile-sql-injection(32788)</ref><ref source="BID" url="http://www.securityfocus.com/bid/29154">29154</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/42326">ajdating-userid-sql-injection(42326)</ref></refs><vuln_soft><prod name="AJDating" vendor="AJ Square"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-03-07" name="CVE-2007-1298" published="2007-03-06" seq="2007-1298" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in subcat.php in AJ Auction 1.0 allows remote attackers to execute arbitrary SQL commands via the cate_id parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3408">3408</ref><ref source="BID" url="http://www.securityfocus.com/bid/22808">22808</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0819">
ADV-2007-0819</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24375">
24375</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32789">
ajauctionpro-subcat-sql-injection(32789)</ref></refs><vuln_soft><prod name="AJAuction" vendor="AJ Square"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-03-07" name="CVE-2007-1299" published="2007-03-06" seq="2007-1299" severity="High" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in index.php in Mani Stats Reader 1.2 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the ipath parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3398">3398</ref><ref source="BID" url="http://www.securityfocus.com/bid/22794">22794</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32782">mani-stats-index-file-include(32782)</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24394">
24394</ref></refs><vuln_soft><prod name="Mani Stats Reader" vendor="Mani Stats Reader"><vers num="1.2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.8" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.9" CVSS_score="7.8" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:N/A:N)" CVSS_version="2.0" modified="2007-03-07" name="CVE-2007-1300" published="2007-03-06" seq="2007-1300" severity="High" type="CVE"><desc><descript source="cve">DOURAN Software Technologies ISPUtil 3.32.84.1, and possibly earlier versions, stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain user and reseller data via a direct request for scripts/activesessions.ini.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24304">24304</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32800">
isputil-activesessions-info-disclosure(32800)</ref></refs><vuln_soft><prod name="ISPUtil" vendor="Douran Software Technologies"><vers num="3.32.84.1"/></prod></vuln_soft></entry><entry CVSS_base_score="9.0" CVSS_exploit_subscore="8.0" CVSS_impact_subscore="10.0" CVSS_score="9.0" CVSS_vector="(AV:N/AC:L/Au:S/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-07-24" name="CVE-2007-1301" published="2007-03-06" seq="2007-1301" severity="High" type="CVE"><desc><descript source="cve">Stack-based buffer overflow in the IMAP service in MailEnable Enterprise and Professional Editions 2.37 and earlier allows remote authenticated users to execute arbitrary code via a long argument to the APPEND command.  NOTE: this is probably different than CVE-2006-6423.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3397">3397</ref><ref source="BID" url="http://www.securityfocus.com/bid/22792">22792</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0811">ADV-2007-0811</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24361">24361</ref><ref source="" url="http://www.mailenable.com/hotfix/"></ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017739">1017739</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32801">mailenable-append-bo(32801)</ref></refs><vuln_soft><prod name="MailEnable Professional" vendor="MailEnable"><vers edition="Professional" num="2.37"/></prod><prod name="MailEnable Enterprise" vendor="MailEnable"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2008-01-02" name="CVE-2007-1302" published="2007-03-06" seq="2007-1302" severity="Medium" type="CVE"><desc><descript source="cve">SQL injection vulnerability in guestbook.php in LI-Guestbook 1.1, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the country parameter.  NOTE: it was later reported that 1.2 is also affected.</descript></desc><impacts><impact source="nvd">Successful exploitation requires &quot;magic_quotes_gpc&quot; to be disabled.</impact></impacts><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/461912/100/0/threaded">20070305 LI-Guestbook SQL Injection Vulnerability</ref><ref adv="1" source="" url="http://belsec.com/advisories/139/summary.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/22821">22821</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/483524/100/0/threaded">20071109 li-guestbook sql inj</ref><ref source="" url="http://www.security-news.ws/li-sql-injection"></ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/27650">27650</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2348">2348</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/38369">liguestbook-country-sql-injection(38369)</ref></refs><vuln_soft><prod name="LI-Guestbook" vendor="LI-Scripts"><vers num="1.1"/><vers num="1.2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.8" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.9" CVSS_score="7.8" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:N/A:N)" CVSS_version="2.0" modified="2007-03-07" name="CVE-2007-1303" published="2007-03-06" seq="2007-1303" severity="High" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in rb.cgi in RRDBrowse 1.6 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/461911/100/0/threaded">20070304 Arbitrary file disclosure vulnerability in rrdbrowse &lt;= 1.6</ref><ref source="" url="http://www.devtarget.org/rrdbrowse-advisory-03-2007.txt"></ref><ref patch="1" source="" url="http://www.rrdbrowse.org/index.php"></ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/22817">22817</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0834">
ADV-2007-0834</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32793">
rrdbrowse-file-directory-traversal(32793)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2349">2349</ref></refs><vuln_soft><prod name="RRDBrowse" vendor="RRDBrowse"><vers num="1.6" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-03-07" name="CVE-2007-1304" published="2007-03-06" seq="2007-1304" severity="Medium" type="CVE"><desc><descript source="cve">Multiple SQL injection vulnerabilities in add2.php in Sava&apos;s Guestbook 23.11.2006, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) name, (2) country, (3) email, (4) website, and (5) message parameters.</descript></desc><impacts><impact source="nvd">Successful exploitation requires that &quot;magic_quotes_gpc&quot; is disabled.</impact></impacts><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/461910/100/0/threaded">20070305 Sava&apos;s GuestBook Multiple Vulnerabilities</ref><ref source="BID" url="http://www.securityfocus.com/bid/22820">22820</ref><ref source="" url="http://belsec.com/advisories/142/summary.html"></ref><ref source="SECUNIA" url="http://secunia.com/advisories/24411">
24411</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32811">
savasguestbook-add2-sql-injection(32811)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2350">2350</ref></refs><vuln_soft><prod name="Savas Guestbook" vendor="Savas Place"><vers num="2006-11-23"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-03-07" name="CVE-2007-1305" published="2007-03-06" seq="2007-1305" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in add2.php in Sava&apos;s Guestbook 23.11.2006 allow remote attackers to inject arbitrary web script or HTML via the (1) name, (2) country, (3) email, and (4) website parameters.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/461910/100/0/threaded">20070305 Sava&apos;s GuestBook Multiple Vulnerabilities</ref><ref source="BID" url="http://www.securityfocus.com/bid/22820">22820</ref><ref source="" url="http://belsec.com/advisories/142/summary.html"></ref><ref source="SECUNIA" url="http://secunia.com/advisories/24411">
24411</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32812">
savasguestbook-add2-xss(32812)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2350">2350</ref></refs><vuln_soft><prod name="Savas Guestbook" vendor="Savas Place"><vers num="2006-11-23"/></prod></vuln_soft></entry><entry CVSS_base_score="7.8" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.9" CVSS_score="7.8" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_version="2.0" modified="2007-04-11" name="CVE-2007-1306" published="2007-03-06" seq="2007-1306" severity="High" type="CVE"><desc><descript source="cve">Asterisk 1.4 before 1.4.1 and 1.2 before 1.2.16 allows remote attackers to cause a denial of service (crash) by sending a Session Initiation Protocol (SIP) packet without a URI and SIP-version header, which results in a NULL pointer dereference.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref source="" url="http://asterisk.org/node/48319"></ref><ref source="" url="http://asterisk.org/node/48320"></ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/228032">VU#228032</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017723">1017723</ref><ref source="" url="http://labs.musecurity.com/advisories/MU-200703-01.txt"></ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200703-14.xml">GLSA-200703-14</ref><ref source="BID" url="http://www.securityfocus.com/bid/22838">22838</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0830">ADV-2007-0830</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24380">24380</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24578">24578</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32830">asterisk-sip-channeldriver-dos(32830)</ref><ref source="OSVDB" url="http://www.osvdb.org/33888">
33888</ref><ref source="DEBIAN" url="http://www.debian.org/security/2007/dsa-1358">DSA-1358</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2007_34_asterisk.html">SUSE-SA:2007:034</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25582">25582</ref></refs><vuln_soft><prod name="Asterisk" vendor="Digium"><vers num="1.2 Beta1"/><vers num="1.2 Beta2"/><vers num="1.2.0 Beta1"/><vers num="1.2.0 Beta2"/><vers num="1.2.10"/><vers num="1.2.11"/><vers num="1.2.12"/><vers num="1.2.12.1"/><vers num="1.2.13"/><vers num="1.2.14"/><vers num="1.2.15"/><vers num="1.2.6"/><vers num="1.2.7"/><vers num="1.2.8"/><vers num="1.2.9"/><vers num="1.4.0"/><vers num="1.4.0 Beta1"/><vers num="1.4.0 Beta2"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-03-07" name="CVE-2007-1307" published="2007-03-06" seq="2007-1307" severity="High" type="CVE"><desc><descript source="cve">Unspecified vulnerability in Lenovo Intel PRO/1000 LAN adapter before Build 135400, as used on IBM Lenovo ThinkPad systems, has unknown impact and attack vectors.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs><ref patch="1" source="" url="http://www-307.ibm.com/pc/support/site.wss/document.do?sitestyle=lenovo&amp;lndocid=MIGR-62922"></ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/22822">22822</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0801">ADV-2007-0801</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/24349">24349</ref></refs><vuln_soft><prod name="PRO 1000 LAN Adapter" vendor="Intel"><vers num="135400"/></prod><prod name="ThinkPad" vendor="Lenovo"><vers num="R50"/><vers num="R50e"/><vers num="R50p"/><vers num="R51"/><vers num="T41"/><vers num="T41P"/><vers num="T42"/><vers num="T42P"/><vers num="T60"/><vers num="T60P"/><vers num="X31"/><vers num="X32"/><vers num="X40"/><vers num="X60"/><vers num="X60 Tablet"/><vers num="X60S"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:P)" CVSS_version="2.0" modified="2008-02-29" name="CVE-2007-1308" published="2007-03-06" seq="2007-1308" severity="Medium" type="CVE"><desc><descript source="cve">ecma/kjs_html.cpp in KDE JavaScript (KJS), as used in Konqueror in KDE 3.5.5, allows remote attackers to cause a denial of service (crash) by accessing the content of an iframe with an ftp:// URI in the src attribute, probably due to a NULL pointer dereference.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/461897/100/0/threaded">20070304 Konqueror DoS Via JavaScript Read Of FTP Iframe</ref><ref patch="1" source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2007-March/052793.html">20070304 Konqueror DoS Via JavaScript Read Of FTP Iframe</ref><ref adv="1" patch="1" source="" url="http://bindshell.net/advisories/konq355"></ref><ref source="" url="http://bindshell.net/advisories/konq355/konq355-patch.diff"></ref><ref source="BID" url="http://www.securityfocus.com/bid/22814">22814</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32798">konqueror-ftp-dos(32798)</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2007:054">MDKSA-2007:054</ref><ref source="UBUNTU" url="http://www.ubuntu.com/usn/usn-447-1">USN-447-1</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:054">MDKSA-2007:054</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2007-0909.html">RHSA-2007:0909</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0886">ADV-2007-0886</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/27108">27108</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2345">2345</ref></refs><vuln_soft><prod name="Konqueror" vendor="KDE"><vers num="3.5.5"/></prod></vuln_soft></entry><entry CVSS_base_score="9.0" CVSS_exploit_subscore="8.0" CVSS_impact_subscore="10.0" CVSS_score="9.0" CVSS_vector="(AV:N/AC:L/Au:S/C:C/I:C/A:C)" CVSS_version="2.0" modified="2008-02-25" name="CVE-2007-1309" published="2007-03-06" seq="2007-1309" severity="High" type="CVE"><desc><descript source="cve">Novell Access Management 3 SSLVPN Server allows remote authenticated users to bypass VPN restrictions by making policy.txt read-only, disconnecting, then manually modifying policy.txt.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref patch="1" source="" url="https://secure-support.novell.com/KanisaPlatform/Publishing/648/3429077_f.SAL_Public.html"></ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0800">ADV-2007-0800</ref><ref adv="1" patch="1" source="SECTRACK" url="http://www.securitytracker.com/id?1017722">1017722</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/24369">24369</ref></refs><vuln_soft><prod name="Access Manager" vendor="Novell"><vers num="3"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-04-09" name="CVE-2007-1313" published="2007-03-21" seq="2007-1313" severity="High" type="CVE"><desc><descript source="cve">NETxAutomation NETxEIB OPC Server before 3.0.1300 does not properly validate OLE for Process Control (OPC) server handles, which allows attackers to cause a denial of service or possibly execute arbitrary code via unspecified vectors involving the (1) IOPCSyncIO::Read, (2) IOPCSyncIO::Write, (3) IOPCServer::AddGroup, (4) IOPCServer::RemoveGroup, (5) IOPCCommon::SetClientName, and (6) IOPCGroupStateMgt::CloneGroup functions, which allow access to arbitrary memory. NOTE: the vectors might be limited to attackers with physical access.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input/><design/></vuln_types><range><local/></range><refs><ref adv="1" source="" url="http://www.kb.cert.org/vuls/id/MIMG-6XEPXN"></ref><ref adv="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/296593">VU#296593</ref><ref source="BID" url="http://www.securityfocus.com/bid/23059">23059</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1038">ADV-2007-1038</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24612">24612</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/463539/100/0/threaded">20070322 [NB07-22] Multiple vulnerabilities in NETxEIB OPC server</ref><ref source="" url="http://www.neutralbit.com/advisories/NB07-22.txt"></ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017803">1017803</ref></refs><vuln_soft><prod name="NETxEIB" vendor="NETxAutomation"><vers num="3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-04-10" name="CVE-2007-1319" published="2007-03-19" seq="2007-1319" severity="High" type="CVE"><desc><descript source="cve">Unspecified vulnerability in the IOPCServer::RemoveGroup function in the OPCDA interface in Takebishi Electric DeviceXPlorer OLE for Process Control (OPC) Server before 3.12 Build3 allows remote attackers to execute arbitrary code via unspecified vectors involving access to arbitrary memory. NOTE: this issue affects the (1) HIDIC, (2) MELSEC, (3) FA-M3, (4) MODBUS, and (5) SYSMAC OPC Servers.</descript></desc><sols><sol source="nvd">This vulnerability is addressed in the following product update: http://www.faweb.net/us/opc/1231207.html</sol></sols><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://www.faweb.net/us/opc/1231207.html"></ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/926551">VU#926551</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/463546/100/0/threaded">20070322 [NB07-07] Multiple vulnerabilities in Takebishi Electric DeviceXplorer HIDIC OPC server</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/463550/100/0/threaded">20070322 [NB07-08] Multiple vulnerabilities in Takebishi Electric DeviceXplorer MELSEC OPC server</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/463556/100/0/threaded">20070322 [NB07-09] Multiple vulnerabilities in Takebishi Electric DeviceXplorer FA-M3 OPC server</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/463559/100/0/threaded">20070322 [NB07-10] Multiple vulnerabilities in Takebishi Electric DeviceXplorer MODBUS OPC server</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/463537/100/0/threaded">20070322 [NB07-17] Multiple vulnerabilities in Takebishi Electric DeviceXplorer SYSMAC OPC server</ref><ref source="" url="http://www.neutralbit.com/advisories/NB07-07.txt"></ref><ref source="" url="http://www.neutralbit.com/advisories/NB07-08.txt"></ref><ref source="" url="http://www.neutralbit.com/advisories/NB07-09.txt"></ref><ref source="" url="http://www.neutralbit.com/advisories/NB07-10.txt"></ref><ref source="" url="http://www.neutralbit.com/advisories/NB07-17.txt"></ref><ref source="BID" url="http://www.securityfocus.com/bid/23037">23037</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1029">ADV-2007-1029</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017793">1017793</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24570">24570</ref></refs><vuln_soft><prod name="DeviceXPlorer OPC Server" vendor="Takebishi Corporation"><vers num="3.12 Build2" prev="1"/><vers num="3.12 Build1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-12-31" name="CVE-2007-1320" published="2007-05-02" seq="2007-1320" severity="High" type="CVE"><desc><descript source="cve">Multiple heap-based buffer overflows in the cirrus_invalidate_region function in the Cirrus VGA extension in QEMU 0.8.2, as used in Xen and possibly other products, might allow local users to execute arbitrary code via unspecified vectors related to &quot;attempting to mark non-existent regions as dirty,&quot; aka the &quot;bitblt&quot; heap overflow.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input bound="1"/><exception/></vuln_types><range><local/></range><refs><ref source="" url="http://taviso.decsystem.org/virtsec.pdf"></ref><ref source="DEBIAN" url="http://www.debian.org/security/2007/dsa-1284">DSA-1284</ref><ref source="BID" url="http://www.securityfocus.com/bid/23731">23731</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1597">ADV-2007-1597</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/25073">25073</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/25095">25095</ref><ref source="DEBIAN" url="http://www.debian.org/security/2007/dsa-1384">DSA-1384</ref><ref source="FEDORA" url="https://www.redhat.com/archives/fedora-package-announce/2007-October/msg00082.html">FEDORA-2007-713</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:203">MDKSA-2007:203</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2007-0323.html">RHSA-2007:0323</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/27085">27085</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/27103">27103</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/27486">27486</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/27047">27047</ref><ref source="FEDORA" url="https://www.redhat.com/archives/fedora-package-announce/2008-May/msg00706.html">FEDORA-2008-4386</ref><ref source="FEDORA" url="https://www.redhat.com/archives/fedora-package-announce/2008-May/msg00935.html">FEDORA-2008-4604</ref><ref source="SECUNIA" url="http://secunia.com/advisories/30413">30413</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDVSA-2008:162">MDVSA-2008:162</ref></refs><vuln_soft><prod name="QEMU" vendor="Fabrice Bellard"><vers num="0.8.2"/></prod></vuln_soft></entry><entry CVSS_base_score="6.6" CVSS_exploit_subscore="2.7" CVSS_impact_subscore="10.0" CVSS_score="6.6" CVSS_vector="(AV:L/AC:M/Au:S/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-12-14" name="CVE-2007-1321" published="2007-10-30" seq="2007-1321" severity="Medium" type="CVE"><desc><descript source="cve">Integer signedness error in the NE2000 emulator in QEMU 0.8.2, as used in Xen and possibly other products, allows local users to trigger a heap-based buffer overflow via certain register values that bypass sanity checks, aka QEMU NE2000 &quot;receive&quot; integer signedness error. NOTE: this identifier was inadvertently used by some sources to cover multiple issues that were labeled &quot;NE2000 network driver and the socket code,&quot; but separate identifiers have been created for the individual vulnerabilities since there are sometimes different fixes; see CVE-2007-5729 and CVE-2007-5730.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><local/></range><refs><ref source="" url="http://taviso.decsystem.org/virtsec.pdf"></ref><ref source="DEBIAN" url="http://www.debian.org/security/2007/dsa-1284">DSA-1284</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2007-0323.html">RHSA-2007:0323</ref><ref source="FEDORA" url="https://www.redhat.com/archives/fedora-package-announce/2007-October/msg00030.html">FEDORA-2007-2270</ref><ref source="FEDORA" url="https://www.redhat.com/archives/fedora-package-announce/2007-October/msg00082.html">FEDORA-2007-713</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:203">MDKSA-2007:203</ref><ref source="VIM" url="http://www.attrition.org/pipermail/vim/2007-October/001842.html">20071030 Clarification on old QEMU/NE2000/Xen issues</ref><ref source="BID" url="http://www.securityfocus.com/bid/23731">23731</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1597">ADV-2007-1597</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1018761">1018761</ref><ref source="SECUNIA" url="http://secunia.com/advisories/27072">27072</ref><ref source="SECUNIA" url="http://secunia.com/advisories/27103">27103</ref><ref source="SECUNIA" url="http://secunia.com/advisories/27486">27486</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25073">25073</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25095">25095</ref><ref source="SECUNIA" url="http://secunia.com/advisories/27047">27047</ref><ref source="FEDORA" url="https://www.redhat.com/archives/fedora-package-announce/2007-November/msg00004.html">FEDORA-2007-2708</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDVSA-2008:162">MDVSA-2008:162</ref></refs><vuln_soft><prod name="QEMU" vendor="Fabrice Bellard"><vers num="0.8.2"/></prod></vuln_soft></entry><entry CVSS_base_score="4.9" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.9" CVSS_score="4.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:C)" CVSS_version="2.0" modified="2007-05-04" name="CVE-2007-1322" published="2007-05-02" seq="2007-1322" severity="Medium" type="CVE"><desc><descript source="cve">QEMU 0.8.2 allows local users to halt a virtual machine by executing the icebp instruction.</descript></desc><loss_types><avail/></loss_types><vuln_types><input bound="1"/></vuln_types><range><local/></range><refs><ref source="" url="http://taviso.decsystem.org/virtsec.pdf"></ref><ref source="DEBIAN" url="http://www.debian.org/security/2007/dsa-1284">DSA-1284</ref><ref source="BID" url="http://www.securityfocus.com/bid/23731">23731</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1597">ADV-2007-1597</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/25073">25073</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/25095">25095</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/34043">qemu-icebp-dos(34043)</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDVSA-2008:162">MDVSA-2008:162</ref></refs><vuln_soft><prod name="QEMU" vendor="Fabrice Bellard"><vers num="0.8.2"/></prod></vuln_soft></entry><entry name="CVE-2007-1323" published="2007-10-30" reject="1" seq="2007-1323" type="CVE"><desc><descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2007-2893.  Reason: this candidate was intended for one issue, but some sources used this identifier for a separate issue, and a duplicate identifier had also been created by the time dual use was detected.  Notes: All CVE users should consult CVE-2007-2893 to determine if it is appropriate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</descript></desc><loss_types/><refs/></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0" modified="2007-03-12" name="CVE-2007-1324" published="2007-03-07" seq="2007-1324" severity="Medium" type="CVE"><desc><descript source="cve">SnapGear 560, 585, 580, 640, 710, and 720 appliances before the 3.1.4u5 firmware allow remote attackers to cause a denial of service (complete packet loss) via a packet flood, a different vulnerability than CVE-2006-4613.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="" url="http://www.cyberguard.info/snapgear/releases.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/22835">22835</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24388">24388</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0850">
ADV-2007-0850</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32824">
snapgear-packet-dos(32824)</ref></refs><vuln_soft><prod name="720" vendor="SnapGear"><vers num="1.7.10 firmware"/><vers num="1.7.8 firmware"/><vers num="1.7.9 firmware"/><vers num="1.8 firmware"/><vers num="1.8.4 firmware"/><vers num="1.8.5 firmware"/><vers num="3.1.4u2 firmware"/></prod><prod name="710" vendor="SnapGear"><vers num="1.7.10 firmware"/><vers num="1.7.8 firmware"/><vers num="1.7.9 firmware"/><vers num="1.8 firmware"/><vers num="1.8.4 firmware"/><vers num="1.8.5 firmware"/><vers num="3.1.4u2 firmware"/></prod><prod name="585" vendor="SnapGear"><vers num="1.7.10 firmware"/><vers num="1.7.8 firmware"/><vers num="1.7.9 firmware"/><vers num="1.8 firmware"/><vers num="1.8.4 firmware"/><vers num="1.8.5 firmware"/><vers num="3.1.4u2 firmware"/></prod><prod name="580" vendor="SnapGear"><vers num="1.7.10 firmware"/><vers num="1.7.8 firmware"/><vers num="1.7.9 firmware"/><vers num="1.8 firmware"/><vers num="1.8.4 firmware"/><vers num="1.8.5 firmware"/><vers num="3.1.4u2 firmware"/></prod><prod name="560" vendor="SnapGear"><vers num="1.7.10 firmware"/><vers num="1.7.8 firmware"/><vers num="1.7.9 firmware"/><vers num="1.8 firmware"/><vers num="1.8.4 firmware"/><vers num="1.8.5 firmware"/><vers num="3.1.4u2 firmware"/></prod><prod name="640" vendor="SnapGear"><vers num="1.7.10 firmware"/><vers num="1.7.8 firmware"/><vers num="1.7.9 firmware"/><vers num="1.8 firmware"/><vers num="1.8.4 firmware"/><vers num="1.8.5 firmware"/><vers num="3.1.4u2 firmware"/></prod></vuln_soft></entry><entry CVSS_base_score="7.1" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.9" CVSS_score="7.1" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:C)" CVSS_version="2.0" modified="2007-03-12" name="CVE-2007-1325" published="2007-03-07" seq="2007-1325" severity="High" type="CVE"><desc><descript source="cve">The PMA_ArrayWalkRecursive function in libraries/common.lib.php in phpMyAdmin before 2.10.0.2 does not limit recursion on arrays provided by users, which allows context-dependent attackers to cause a denial of service (web server crash) via an array with many dimensions.  NOTE: it could be argued that this vulnerability is caused by a problem in PHP (CVE-2006-1549) and the proper fix should be in PHP; if so, then this should not be treated as a vulnerability in phpMyAdmin.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://www.php-security.org/MOPB/MOPB-02-2007.html"></ref><ref patch="1" source="" url="http://sourceforge.net/tracker/index.php?func=detail&amp;aid=1671813&amp;group_id=23067&amp;atid=377408"></ref><ref patch="1" source="" url="http://www.phpmyadmin.net/home_page/security.php?issue=PMASA-2007-3"></ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/22841">22841</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0831">ADV-2007-0831</ref><ref source="DEBIAN" url="http://www.us.debian.org/security/2007/dsa-1370">DSA-1370</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:199">MDKSA-2007:199</ref><ref source="SECUNIA" url="http://secunia.com/advisories/26733">26733</ref><ref source="" url="http://www.php.net/ChangeLog-4.php"></ref><ref source="" url="http://www.php.net/releases/4_4_8.php"></ref></refs><vuln_soft><prod name="phpMyAdmin" vendor="phpMyAdmin"><vers num="2.10.0.1" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-03-09" name="CVE-2007-1326" published="2007-03-07" seq="2007-1326" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in index.php in Serendipity 1.1.1 allows remote attackers to execute arbitrary SQL commands via the serendipity[multiCat][] parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/461671/100/0/threaded">20070301 Serendipity unauthenticated SQL-Injection</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32768">serendipity-index-sql-injection(32768)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2383">2383</ref></refs><vuln_soft><prod name="Serendipity" vendor="Serendipity"><vers num="1.1.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.8" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.9" CVSS_score="7.8" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_version="2.0" modified="2007-03-09" name="CVE-2007-1327" published="2007-03-07" seq="2007-1327" severity="High" type="CVE"><desc><descript source="cve">The SILC_SERVER_CMD_FUNC function in apps/silcd/command.c in silc-server 1.0.2 allows remote attackers to cause a denial of service (NULL dereference and daemon crash) via a request without a cipher algorithm and an invalid HMAC algorithm.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="FULLDISC" url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=117320823618036&amp;w=2">20070306 silc-server 1.0.2 denial-of-service vulnerability</ref><ref source="BID" url="http://www.securityfocus.com/bid/22846">22846</ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200703-12.xml">
GLSA-200703-12</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24431">
24431</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24426">
24426</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32846">
silc-command-dos(32846)</ref></refs><vuln_soft><prod name="SILC-Server" vendor="SILC"><vers num="1.0.2"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" modified="2007-03-09" name="CVE-2007-1328" published="2007-03-07" seq="2007-1328" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in formulaire.php in Bernard JOLY BJ Webring allows remote attackers to inject arbitrary web script or HTML via an unspecified parameter related to the add link menu.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/461802/100/0/threaded">20070303 BJ Webring XSS</ref><ref source="" url="http://forums.avenir-geopolitique.net/viewtopic.php?t=2707"></ref><ref source="SREASON" url="http://securityreason.com/securityalert/2384">2384</ref></refs><vuln_soft><prod name="BJ Webring" vendor="Bernard Joly"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-03-09" name="CVE-2007-1329" published="2007-03-07" seq="2007-1329" severity="High" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in SQL-Ledger, and LedgerSMB before 1.1.5, allows remote attackers to read and overwrite arbitrary files, and execute arbitrary code, via . (dot) characters adjacent to (1) users and (2) users/members strings, which are removed by blacklisting functions that filter these strings and collapse into .. (dot dot) sequences.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/461630/100/0/threaded">20070301 Full disclosure: Directory Transversal and Arbitrary Code Execution Vulnerability in SQL-Ledger and LedgerSMB</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1017715">1017715</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32776">sqlledger-userpathmemberfile-dir-traversal(32776)</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24363">
24363</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24366">
24366</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2381">2381</ref></refs><vuln_soft><prod name="SQL-Ledger" vendor="SQL-Ledger"><vers num=""/></prod><prod name="LedgerSMB" vendor="LedgerSMB"><vers num="1.1.1" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.4" CVSS_exploit_subscore="3.4" CVSS_impact_subscore="6.4" CVSS_score="4.4" CVSS_vector="(AV:L/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-03-09" name="CVE-2007-1330" published="2007-03-07" seq="2007-1330" severity="Medium" type="CVE"><desc><descript source="cve">Comodo Firewall Pro (CFP) (formerly Comodo Personal Firewall) 2.4.18.184 and earlier allows local users to bypass driver protections on the HKLM\SYSTEM\Software\Comodo\Personal Firewall registry key by guessing the name of a named pipe under \Device\NamedPipe\OLE and attempting to open it multiple times.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/461635/100/0/threaded">20070301 Comodo Bypassing settings protection using magic pipe Vulnerability</ref><ref adv="1" source="" url="http://www.matousec.com/info/advisories/Comodo-Bypassing-settings-protection-using-magic-pipe.php"></ref><ref source="BID" url="http://www.securityfocus.com/bid/22775">22775</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32771">comodofirewallpro-pipe-security-bypass(32771)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2388">2388</ref></refs><vuln_soft><prod name="Comodo Firewall Pro" vendor="Comodo"><vers num="2.4.16.174"/><vers num="2.4.17.183"/><vers num="2.4.18.184"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" modified="2007-03-09" name="CVE-2007-1331" published="2007-03-07" seq="2007-1331" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in TKS Banking Solutions ePortfolio 1.0 Java allow remote attackers to inject arbitrary web script or HTML via unspecified vectors that bypass the client-side protection scheme, one of which may be the q parameter to the search program.  NOTE: some of these details are obtained from third party information.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/461895/100/0/threaded">20070305 ePortfolio version 1.0 Java Multiple Input Validation Vulnerabilities</ref><ref source="" url="http://www.scip.ch/cgi-bin/smss/showadvf.pl?id=2893"></ref><ref source="" url="http://www.scip.ch/publikationen/advisories/scip_advisory-2893_eportfolio_%201.0_java_multiple_vulnerabilities.txt"></ref><ref source="BID" url="http://www.securityfocus.com/bid/22829">22829</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24331">
24331</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2385">2385</ref></refs><vuln_soft><prod name="ePortfolio" vendor="TKS Banking Solutions"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" CVSS_score="9.3" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-03-09" name="CVE-2007-1332" published="2007-03-07" seq="2007-1332" severity="High" type="CVE"><desc><descript source="cve">Multiple cross-site request forgery (CSRF) vulnerabilities in TKS Banking Solutions ePortfolio 1.0 Java allow remote attackers to perform unspecified restricted actions in the context of certain accounts by bypassing the client-side protection scheme.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/461895/100/0/threaded">20070305 ePortfolio version 1.0 Java Multiple Input Validation Vulnerabilities</ref><ref source="" url="http://www.scip.ch/cgi-bin/smss/showadvf.pl?id=2893"></ref><ref adv="1" source="" url="http://www.scip.ch/publikationen/advisories/scip_advisory-2893_eportfolio_%201.0_java_multiple_vulnerabilities.txt"></ref><ref source="BID" url="http://www.securityfocus.com/bid/22829">22829</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24331">
24331</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2385">2385</ref></refs><vuln_soft><prod name="ePortfolio" vendor="TKS Banking Solutions"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.8" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.9" CVSS_score="7.8" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_version="2.0" modified="2007-05-04" name="CVE-2007-1337" published="2007-05-02" seq="2007-1337" severity="High" type="CVE"><desc><descript source="cve">The virtual machine process (VMX) in VMware Workstation before 5.5.4 does not properly read state information when moving from the ACPI sleep state to the run state, which allows attackers to cause a denial of service (virtual machine reboot) via unknown vectors.</descript></desc><loss_types><avail/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref patch="1" source="" url="http://www.vmware.com/support/ws55/doc/releasenotes_ws55.html#554"></ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33990">vmware-acpi-unspecified(33990)</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25079">
25079</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1018011">
1018011</ref><ref source="BID" url="http://www.securityfocus.com/bid/23732">23732</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1592">ADV-2007-1592</ref></refs><vuln_soft><prod name="VMWare Workstation" vendor="VMWare"><vers num="5.5.3" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-03-09" name="CVE-2007-1338" published="2007-03-08" seq="2007-1338" severity="High" type="CVE"><desc><descript source="cve">The default configuration of the AirPort utility in Apple AirPort Extreme creates an IPv6 tunnel but does not enable the &quot;Block incoming IPv6 connections&quot; setting, which might allow remote attackers to bypass intended access restrictions by establishing IPv6 sessions that would have been rejected over IPv4.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref source="" url="http://arstechnica.com/journals/apple.ars/2007/2/14/7063"></ref><ref source="" url="http://docs.info.apple.com/article.html?artnum=305366"></ref><ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2007/Apr/msg00000.html">
APPLE-SA-2007-04-09</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1308">
ADV-2007-1308</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24830">
24830</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017889">
1017889</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33526">
airportextreme-ipv6-security-bypass(33526)</ref></refs><vuln_soft><prod name="AirPort Extreme" vendor="Apple"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-03-09" name="CVE-2007-1339" published="2007-03-08" seq="2007-1339" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in index.php in Links Management Application 1.0 allows remote attackers to execute arbitrary SQL commands via the lcnt parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MILW0RM" url="http://milw0rm.com/exploits/3416">3416</ref><ref source="BID" url="http://www.securityfocus.com/bid/22825">22825</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24355">24355</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0849">
ADV-2007-0849</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32813">
links-index-sql-injection(32813)</ref></refs><vuln_soft><prod name="Links Management" vendor="Monitor-Line"><vers num="1.0" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-03-09" name="CVE-2007-1340" published="2007-03-08" seq="2007-1340" severity="High" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in eintrag.php in Weltennetz News-Letterman 1.1 allows remote attackers to execute arbitrary PHP code via a URL in the sqllog parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3406">3406</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/22807">22807</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32787">newsletterman-eintrag-file-include(32787)</ref></refs><vuln_soft><prod name="News-Letterman" vendor="Weltennetz"><vers num="1.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0" modified="2007-03-09" name="CVE-2007-1341" published="2007-03-08" seq="2007-1341" severity="Medium" type="CVE"><desc><descript source="cve">include/auth/auth.php in Simple Invoices before 2007 03 05 does not use the login system to protect print preview pages for invoices, which might allow attackers to obtain sensitive information.</descript></desc><loss_types><conf/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref source="" url="http://code.google.com/p/simpleinvoices/issues/detail?id=35"></ref><ref source="" url="http://forum.tufat.com/showthread.php?p=116753#post116753"></ref><ref source="" url="https://sourceforge.net/project/shownotes.php?group_id=164303&amp;release_id=491300"></ref><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/22818">22818</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24402">24402</ref></refs><vuln_soft><prod name="Simple Invoices" vendor="Simple Invoices"><vers num="2006-12-11"/><vers num="2007-01-25"/><vers num="2007-02-02"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" modified="2007-03-09" name="CVE-2007-1342" published="2007-03-08" seq="2007-1342" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in admincp/index.php in Jelsoft vBulletin 3.6.5 and earlier allows remote attackers to inject arbitrary web script or HTML via the add rss url form.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/461727/100/0/threaded">20070302 vBulletin v3.6.5 admincp/index.php ( rss feed ) xss vuln.</ref><ref source="BID" url="http://www.securityfocus.com/bid/22790">22790</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32780">vbulletin-admincpindex-xss(32780)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2396">2396</ref></refs><vuln_soft><prod name="vBulletin" vendor="Jelsoft"><vers num="3.6.5" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-03-09" name="CVE-2007-1343" published="2007-03-08" seq="2007-1343" severity="High" type="CVE"><desc><descript source="cve">includes/functions.php in Craig Knudsen WebCalendar before 1.0.5 does not protect the noSet variable from external modification, which allows remote attackers to set arbitrary global variables via a URL with modified values in the noSet parameter, which leads to resultant vulnerabilities that probably include remote file inclusion and other issues.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref patch="1" source="" url="http://sourceforge.net/project/shownotes.php?group_id=3870&amp;release_id=491130"></ref><ref patch="1" source="" url="http://webcalendar.cvs.sourceforge.net/webcalendar/webcalendar/includes/functions.php?view=log"></ref><ref patch="1" source="" url="http://webcalendar.cvs.sourceforge.net/webcalendar/webcalendar/includes/functions.php?r1=1.211.2.7&amp;r2=1.211.2.8"></ref><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/22834">22834</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/24403">24403</ref><ref source="DEBIAN" url="http://www.debian.org/security/2007/dsa-1267">
DSA-1267</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0851">
ADV-2007-0851</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24519">
24519</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32832">
webcalendar-noset-variable-overwrite(32832)</ref><ref source="MLIST" url="http://sourceforge.net/mailarchive/forum.php?thread_id=31840112&amp;forum_id=46247">[webcalendar-announce] 20070304 Announce: Release 1.0.5 (security patch)</ref></refs><vuln_soft><prod name="WebCalendar" vendor="WebCalendar"><vers num="1.0.0"/><vers num="1.0.1"/><vers num="1.0.2"/><vers num="1.0.3"/><vers num="1.0.4"/></prod></vuln_soft></entry><entry CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" CVSS_score="9.3" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-03-09" name="CVE-2007-1344" published="2007-03-08" seq="2007-1344" severity="High" type="CVE"><desc><descript source="cve">Multiple buffer overflows in src/ezstream.c in Ezstream before 0.3.0 allow remote attackers to execute arbitrary code via a crafted XML configuration file processed by the (1) urlParse function, which causes a stack-based overflow and the (2) ReplaceString function, which causes a heap-based overflow.  NOTE: some of these details are obtained from third party information.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/><user_init/></range><refs><ref source="" url="http://www.icecast.org/ezstream.php#ez_relnotes"></ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/24383">24383</ref><ref source="BID" url="http://www.securityfocus.com/bid/22840">
22840</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0852">
ADV-2007-0852</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32867">
ezstream-replacestring-urlparse-bo(32867)</ref></refs><vuln_soft><prod name="Ezstream" vendor="Icecast"><vers num="0.1.0" prev="1"/><vers num="0.1.1" prev="1"/><vers num="0.1.2" prev="1"/><vers num="0.1.3" prev="1"/><vers num="0.2.0" prev="1"/><vers num="0.2.1" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.1" CVSS_exploit_subscore="2.7" CVSS_impact_subscore="6.4" CVSS_score="4.1" CVSS_vector="(AV:L/AC:M/Au:S/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-03-15" name="CVE-2007-1345" published="2007-03-10" seq="2007-1345" severity="Medium" type="CVE"><desc><descript source="cve">Unspecified vulnerability in cube.exe in the GINA component for CA (Computer Associates) eTrust Admin 8.1.0 through 8.1.2 allows attackers with physical interactive or Remote Desktop access to bypass authentication and gain privileges via the password reset interface.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/462312/100/0/threaded">20070309 [CAID 35145]: CA eTrust Admin Privilege Escalation Vulnerability</ref><ref patch="1" source="" url="http://www3.ca.com/securityadvisor/vulninfo/vuln.aspx?id=35145"></ref><ref source="BID" url="http://www.securityfocus.com/bid/22885">22885</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0885">ADV-2007-0885</ref><ref source="OSVDB" url="http://www.osvdb.org/32722">32722</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017740">1017740</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24441">24441</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32887">ca-etrust-admin-authentication-bypass(32887)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2404">2404</ref></refs><vuln_soft><prod name="eTrust Admin" vendor="Computer Associates"><vers num="8.1"/><vers num="8.1.1"/><vers num="8.1.2"/></prod></vuln_soft></entry><entry CVSS_base_score="6.6" CVSS_exploit_subscore="2.7" CVSS_impact_subscore="10.0" CVSS_score="6.6" CVSS_vector="(AV:L/AC:M/Au:S/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-03-13" name="CVE-2007-1346" published="2007-03-08" seq="2007-1346" severity="Medium" type="CVE"><desc><descript source="cve">Unspecified vulnerability in ipmitool for Sun Fire X2100M2 and X2200M2 allows local users to gain privileges and reset or turn off the server.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102828-1">102828</ref><ref source="BID" url="http://www.securityfocus.com/bid/22859">22859</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0869">
ADV-2007-0869</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017738">
1017738</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24447">
24447</ref></refs><vuln_soft><prod name="Sun Fire" vendor="Sun"><vers num="X2100M2"/><vers num="X2200M2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.1" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.9" CVSS_score="7.1" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:C)" CVSS_version="2.0" modified="2007-04-10" name="CVE-2007-1347" published="2007-03-08" seq="2007-1347" severity="High" type="CVE"><desc><descript source="cve">Microsoft Windows Explorer on Windows 2000 SP4 FR and XP SP2 FR, and possibly other versions and platforms, allows remote attackers to cause a denial of service (memory corruption and crash) via an Office file with crafted document summary information, which causes an error in Ole32.dll.</descript></desc><loss_types><avail/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3419">3419</ref><ref adv="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/194944">VU#194944</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017736">1017736</ref><ref source="" url="http://lostmon.blogspot.com/2007/08/windows-extended-file-attributes-buffer.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/22847">22847</ref></refs><vuln_soft><prod name="Windows Explorer" vendor="Microsoft"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:P)" CVSS_version="2.0" modified="2007-08-13" name="CVE-2007-1349" published="2007-03-29" seq="2007-1349" severity="Medium" type="CVE"><desc><descript source="cve">PerlRun.pm in Apache mod_perl before 1.30, and RegistryCooker.pm in mod_perl 2.x, does not properly escape PATH_INFO before use in a regular expression, which allows remote attackers to cause a denial of service (resource consumption) via a crafted URI.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://www.gossamer-threads.com/lists/modperl/modperl/92739"></ref><ref source="" url="http://svn.apache.org/repos/asf/perl/modperl/branches/1.x/Changes"></ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1150">ADV-2007-1150</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/24678">24678</ref><ref source="BID" url="http://www.securityfocus.com/bid/23192">23192</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2007:083">MDKSA-2007:083</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24839">24839</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2007_8_sr.html">SUSE-SR:2007:008</ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200705-04.xml">GLSA-200705-04</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/25110">25110</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/25072">25072</ref><ref source="" url="http://support.avaya.com/elmodocs2/security/ASA-2007-293.htm"></ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:083">MDKSA-2007:083</ref><ref source="REDHAT" url="http://rhn.redhat.com/errata/RHSA-2007-0395.html">RHSA-2007:0395</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2007-0486.html">RHSA-2007:0486</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2007-0396.html">RHSA-2007:0396</ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20070602-01-P.asc">20070602-01-P</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2007_12_sr.html">SUSE-SR:2007:012</ref><ref source="TRUSTIX" url="http://www.trustix.org/errata/2007/0023/">2007-0023</ref><ref source="UBUNTU" url="http://www.ubuntu.com/usn/usn-488-1">USN-488-1</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1018259">1018259</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25432">25432</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25655">25655</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25730">25730</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25894">25894</ref><ref source="SECUNIA" url="http://secunia.com/advisories/26084">26084</ref><ref source="SECUNIA" url="http://secunia.com/advisories/26231">26231</ref><ref source="SECUNIA" url="http://secunia.com/advisories/26290">26290</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2008-0261.html">RHSA-2008:0261</ref></refs><vuln_soft><prod name="Apache" vendor="Apache Software Foundation"><vers num=""/></prod><prod name="Apache_test" vendor="Apache Software Foundation"><vers num="1.29" prev="1"/></prod><prod name="mod_perl" vendor="Apache Software Foundation"><vers num="2.0.0"/><vers num="2.0.1"/><vers num="2.0.2"/><vers num="2.0.3"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-03-09" name="CVE-2007-1350" published="2007-03-08" seq="2007-1350" severity="Medium" type="CVE"><desc><descript source="cve">Stack-based buffer overflow in webadmin.exe in Novell NetMail 3.5.2 allows remote attackers to execute arbitrary code via a long username during HTTP Basic authentication.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/462154/100/0/threaded">20070307 ZDI-07-009: Novell Netmail WebAdmin Buffer Overflow Vulnerability</ref><ref adv="1" source="" url="http://www.zerodayinitiative.com/advisories/ZDI-07-009.html"></ref><ref patch="1" source="" url="http://download.novell.com/Download?buildid=sMYRODW09pw"></ref><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/22857">22857</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/32861">netmail-sprintf-bo(32861)</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/919369">
VU#919369</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0870">
ADV-2007-0870</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017734">
1017734</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24445">
24445</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2395">2395</ref></refs><vuln_soft><prod name="NetMail" vendor="Novell"><vers edition="c1" num="3.5.2"/><vers edition="e-ftfl" num="3.5.2"/><vers edition="a" num="3.5.2"/><vers edition="b" num="3.5.2"/><vers edition="c" num="3.5.2"/><vers edition="d" num="3.5.2"/></prod></vuln_soft></entry><entry CVSS_base_score="8.5" CVSS_exploit_subscore="6.8" CVSS_impact_subscore="10.0" CVSS_score="8.5" CVSS_vector="(AV:N/AC:M/Au:S/C:C/I:C/A:C)" CVSS_version="2.0" modified="2008-03-07" name="CVE-2007-1351" published="2007-04-05" seq="2007-1351" severity="High" type="CVE"><desc><descript source="cve">Integer overflow in the bdfReadCharacters function in bdfread.c in (1) X.Org libXfont before 20070403 and (2) freetype 2.3.2 and earlier allows remote authenticated users to execute arbitrary code via crafted BDF fonts, which result in a heap overflow.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref source="SECUNIA" url="http://secunia.com/advisories/25096">
25096</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25195">
25195</ref><ref source="" url="http://support.avaya.com/elmodocs2/security/ASA-2007-178.htm"></ref><ref source="SECUNIA" url="http://secunia.com/advisories/25216">
25216</ref><ref source="" url="http://support.avaya.com/elmodocs2/security/ASA-2007-193.htm"></ref><ref source="APPLE" url="http://lists.apple.com/archives/Security-announce/2007/Nov/msg00003.html">APPLE-SA-2007-11-14</ref><ref source="DEBIAN" url="http://www.debian.org/security/2007/dsa-1294">DSA-1294</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:079">MDKSA-2007:079</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:080">MDKSA-2007:080</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:081">MDKSA-2007:081</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1810">oval:org.mitre.oval:def:1810</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25305">25305</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25495">25495</ref><ref source="DEBIAN" url="http://www.debian.org/security/2008/dsa-1454">DSA-1454</ref><ref source="SECUNIA" url="http://secunia.com/advisories/28333">28333</ref><ref patch="1" source="IDEFENSE" url="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=501">20070403 Multiple Vendor X Server BDF Font Parsing Integer Overflow Vulnerability</ref><ref source="MLIST" url="http://lists.freedesktop.org/archives/xorg-announce/2007-April/000286.html">[xorg-announce] 20070403 various integer overflow vulnerabilites in xserver, libX11 and libXfont</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2007-0126.html">RHSA-2007:0126</ref><ref source="UBUNTU" url="http://www.ubuntu.com/usn/usn-448-1">USN-448-1</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/23283">23283</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1217">ADV-2007-1217</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017857">1017857</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24741">24741</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24756">24756</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24770">24770</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/464686/100/0/threaded">20070404 rPSA-2007-0065-1 freetype xorg-x11 xorg-x11-fonts xorg-x11-tools xorg-x11-xfs</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/464816/100/0/threaded">20070405 FLEA-2007-0009-1: xorg-x11 freetype</ref><ref source="" url="http://issues.foresightlinux.org/browse/FL-223"></ref><ref source="" url="http://sourceforge.net/project/shownotes.php?release_id=498954"></ref><ref source="" url="https://issues.rpath.com/browse/RPL-1213"></ref><ref source="" url="http://sourceforge.net/project/shownotes.php?group_id=3157&amp;release_id=498954"></ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2007:079">MDKSA-2007:079</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2007:080">MDKSA-2007:080</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2007:081">MDKSA-2007:081</ref><ref source="REDHAT" url="http://rhn.redhat.com/errata/RHSA-2007-0125.html">RHSA-2007:0125</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2007-0132.html">RHSA-2007:0132</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1264">ADV-2007-1264</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24745">24745</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24758">24758</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24765">24765</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24768">24768</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24771">24771</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24772">24772</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24776">24776</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24791">24791</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33417">xorg-bdf-font-bo(33417)</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2007-0150.html">RHSA-2007:0150</ref><ref source="BID" url="http://www.securityfocus.com/bid/23402">23402</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24885">24885</ref><ref source="SLACKWARE" url="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2007&amp;m=slackware-security.626733">SSA:2007-109-01</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2007_6_sr.html">SUSE-SR:2007:006</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2007_27_x.html">SUSE-SA:2007:027</ref><ref source="TRUSTIX" url="http://www.trustix.org/errata/2007/0013/">2007-0013</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24889">24889</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25004">25004</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24921">24921</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24996">24996</ref><ref source="OPENBSD" url="http://www.openbsd.org/errata39.html#021_xorg">[3.9] 021: SECURITY FIX: April 4, 2007</ref><ref source="OPENBSD" url="http://www.openbsd.org/errata40.html#011_xorg">[4.0] 011: SECURITY FIX: April 4, 2007</ref><ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102886-1">102886</ref><ref source="BID" url="http://www.securityfocus.com/bid/23300">23300</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1548">ADV-2007-1548</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25006">25006</ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200705-02.xml">GLSA-200705-02</ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200705-10.xml">GLSA-200705-10</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200805-07.xml">GLSA-200805-07</ref><ref source="SECUNIA" url="http://secunia.com/advisories/30161">30161</ref></refs><vuln_soft><prod name="rPath Linux" vendor="rPath"><vers num="1"/></prod><prod name="Enterprise Linux AS" vendor="Red Hat"><vers edition="Advanced Server" num="2.1"/><vers edition="Advanced Server" num="2.1"/><vers edition="Advanced Servers" num="3.0"/><vers edition="Advanced Server" num="4.0"/></prod><prod name="Enterprise Linux" vendor="Red Hat"><vers edition="Server" num="5.0"/></prod><prod name="Ubuntu Linux" vendor="Ubuntu"><vers edition="powerpc" num="5.10"/><vers edition="i386" num="5.10"/><vers edition="amd64" num="5.10"/><vers edition="SPARC" num="5.10"/><vers edition="SPARC" num="6.06 LTS"/><vers edition="powerpc" num="6.06 LTS"/><vers edition="i386" num="6.06 LTS"/><vers edition="amd64" num="6.06 LTS"/><vers edition="i386" num="6.10"/><vers edition="powerpc" num="6.10"/><vers edition="SPARC" num="6.10"/><vers edition="amd64" num="6.10"/></prod><prod name="Advanced Workstation" vendor="Red Hat"><vers edition="Itanium" num="2.1"/><vers edition="IA64" num="2.1"/></prod><prod name="LibXFont" vendor="X.Org"><vers num="1.2.2"/></prod><prod name="Enterprise Linux WS" vendor="Red Hat"><vers edition="Workstation" num="2.1"/><vers edition="Workstation" num="2.1"/><vers edition="Workstation" num="3.0"/><vers edition="Workstation" num="4.0"/></prod><prod name="Mandrake Multi Network Firewall" vendor="MandrakeSoft"><vers num="2.0"/></prod><prod name="X11R6" vendor="XFree86 Project"><vers num="4.3.0"/><vers num="4.3.0.1"/><vers num="4.3.0.2"/></prod><prod name="Enterprise Linux Desktop" vendor="Red Hat"><vers edition="Desktop" num="5.0"/></prod><prod name="Desktop" vendor="Red Hat"><vers num="3.0"/><vers num="4.0"/></prod><prod name="Enterprise Linux Desktop Workstation" vendor="Red Hat"><vers edition="Desktop Workstation" num="5.0"/></prod><prod name="Enterprise Linux ES" vendor="Red Hat"><vers edition="Enterprise Server" num="2.1"/><vers edition="Enterprise Server" num="2.1"/><vers edition="Enterprise Server" num="3.0"/><vers edition="Enterprise Server" num="4.0"/></prod><prod name="OpenBSD" vendor="OpenBSD"><vers num="3.9"/><vers num="4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="3.8" CVSS_exploit_subscore="4.4" CVSS_impact_subscore="4.9" CVSS_score="3.8" CVSS_vector="(AV:A/AC:M/Au:S/C:N/I:P/A:P)" CVSS_version="2.0" modified="2007-04-10" name="CVE-2007-1352" published="2007-04-05" seq="2007-1352" severity="Low" type="CVE"><desc><descript source="cve">Integer overflow in the FontFileInitTable function in X.Org libXfont before 20070403 allows remote authenticated users to execute arbitrary code via a long first line in the fonts.dir file, which results in a heap overflow.</descript></desc><sols><sol source="nvd">The vendor has addressed this vulnerability in the following product update: http://xorg.freedesktop.org/archive/X11R7.2/patches/</sol></sols><loss_types><avail/><int/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local_network/></range><refs><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2007:080">
MDKSA-2007:080</ref><ref source="REDHAT" url="http://rhn.redhat.com/errata/RHSA-2007-0125.html">
RHSA-2007:0125</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2007-0132.html">
RHSA-2007:0132</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24745">
24745</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24758">
24758</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24765">
24765</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24771">
24771</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24772">
24772</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24791">
24791</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33419">
xorg-fontsdir-bo(33419)</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2007_27_x.html">
SUSE-SA:2007:027</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25004">
25004</ref><ref source="OPENBSD" url="http://www.openbsd.org/errata39.html#021_xorg">
[3.9] 021: SECURITY FIX: April 4, 2007</ref><ref source="OPENBSD" url="http://www.openbsd.org/errata40.html#011_xorg">
[4.0] 011: SECURITY FIX: April 4, 2007</ref><ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102886-1">
102886</ref><ref source="BID" url="http://www.securityfocus.com/bid/23300">
23300</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1548">
ADV-2007-1548</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25006">
25006</ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200705-10.xml">
GLSA-200705-10</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25195">
25195</ref><ref source="" url="http://support.avaya.com/elmodocs2/security/ASA-2007-178.htm"></ref><ref source="SECUNIA" url="http://secunia.com/advisories/25216">
25216</ref><ref source="APPLE" url="http://lists.apple.com/archives/Security-announce/2007/Nov/msg00003.html">APPLE-SA-2007-11-14</ref><ref source="DEBIAN" url="http://www.debian.org/security/2007/dsa-1294">DSA-1294</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:079">MDKSA-2007:079</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:080">MDKSA-2007:080</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:13243">oval:org.mitre.oval:def:13243</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25305">25305</ref><ref source="IDEFENSE" url="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=502">20070403 Multiple Vendor X Server fonts.dir File Parsing Integer Overflow Vulnerability</ref><ref source="MLIST" url="http://lists.freedesktop.org/archives/xorg-announce/2007-April/000286.html">[xorg-announce] 20070403 various integer overflow vulnerabilites in xserver, libX11 and libXfont</ref><ref adv="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2007-0126.html">RHSA-2007:0126</ref><ref source="UBUNTU" url="http://www.ubuntu.com/usn/usn-448-1">USN-448-1</ref><ref source="BID" url="http://www.securityfocus.com/bid/23283">23283</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1217">ADV-2007-1217</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017857">1017857</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24741">24741</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/24756">24756</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/24770">24770</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/464686/100/0/threaded">
20070404 rPSA-2007-0065-1 freetype xorg-x11 xorg-x11-fonts xorg-x11-tools xorg-x11-xfs</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/464816/100/0/threaded">
20070405 FLEA-2007-0009-1: xorg-x11 freetype</ref><ref source="" url="http://issues.foresightlinux.org/browse/FL-223"></ref><ref source="" url="https://issues.rpath.com/browse/RPL-1213"></ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2007:079">
MDKSA-2007:079</ref></refs><vuln_soft><prod name="TurboLinux Desktop" vendor="TurboLinux"><vers num="10.0"/></prod><prod name="Enterprise Linux" vendor="Red Hat"><vers edition="Advanced Server" num="2.1"/><vers edition="Advanced Server" num="2.1"/><vers edition="Advanced Server" num="3.0"/><vers edition="Advanced Server" num="4.0"/><vers edition="Enterprise Server" num="2.1"/><vers edition="Enterprise Server" num="2.1"/><vers edition="Enterprise Server" num="3.0"/><vers edition="Enterprise Server" num="4.0"/><vers edition="Workstation" num="2.1"/><vers edition="Workstation" num="2.1"/><vers edition="Workstation Server" num="3.0"/><vers edition="Workstation" num="4.0"/></prod><prod name="Mandrake Multi Network Firewall" vendor="MandrakeSoft"><vers num="2.0"/></prod><prod name="Slackware Linux" vendor="Slackware"><vers num="9.0"/><vers num="9.1"/><vers num="current"/></prod><prod name="Advanced Workstation" vendor="Red Hat"><vers edition="Itanium" num="2.1"/><vers edition="IA64" num="2.1"/></prod><prod name="LibXFont" vendor="X.Org"><vers num="1.2.2"/></prod><prod name="Linux" vendor="rPath"><vers num="1"/></prod><prod name="Desktop" vendor="Red Hat"><vers num="3.0"/><vers num="4.0"/><vers edition="Client" num="5.0"/><vers edition="Client" num="5.0"/></prod><prod name="Fedora" vendor="Red Hat"><vers num="Core 1.0"/></prod><prod name="Ubuntu Linux" vendor="Ubuntu"><vers edition="ppc" num="4.1"/><vers edition="ia64" num="4.1"/><vers edition="ia32" num="4.1"/><vers edition="powerpc" num="5.10"/><vers edition="i386" num="5.10"/><vers edition="amd64" num="5.10"/><vers edition="SPARC" num="5.10"/><vers edition="SPARC" num="6.06 LTS"/><vers edition="powerpc" num="6.06 LTS"/><vers edition="i386" num="6.06 LTS"/><vers edition="amd64" num="6.06 LTS"/><vers edition="i386" num="6.10"/><vers edition="powerpc" num="6.10"/><vers edition="SPARC" num="6.10"/><vers edition="amd64" num="6.10"/></prod><prod name="OpenBSD" vendor="OpenBSD"><vers num="3.9"/><vers num="4.0"/></prod><prod name="Linux" vendor="Red Hat"><vers edition="i386" num="9.0"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0" modified="2007-08-13" name="CVE-2007-1353" published="2007-04-24" seq="2007-1353" severity="Low" type="CVE"><desc><descript source="cve">The setsockopt function in the L2CAP and HCI Bluetooth support in the Linux kernel before 2.4.34.3 allows context-dependent attackers to read kernel memory and obtain sensitive information via unspecified vectors involving the copy_from_user function accessing an uninitialized stack buffer.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref source="" url="http://www.kernel.org/pub/linux/kernel/v2.4/ChangeLog-2.4.34.3"></ref><ref source="BID" url="http://www.securityfocus.com/bid/23594">23594</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1495">ADV-2007-1495</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24976">24976</ref><ref source="" url="http://support.avaya.com/elmodocs2/security/ASA-2007-287.htm"></ref><ref source="" url="http://support.avaya.com/elmodocs2/security/ASA-2007-404.htm"></ref><ref source="DEBIAN" url="http://www.debian.org/security/2007/dsa-1356">DSA-1356</ref><ref source="REDHAT" url="https://rhn.redhat.com/errata/RHSA-2007-0376.html">RHSA-2007:0376</ref><ref source="REDHAT" url="http://rhn.redhat.com/errata/RHSA-2007-0488.html">RHSA-2007:0488</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2007-0673.html">RHSA-2007:0673</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2007-0672.html">RHSA-2007:0672</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2007-0671.html">RHSA-2007:0671</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2007_35_kernel.html">SUSE-SA:2007:035</ref><ref source="UBUNTU" url="http://www.ubuntu.com/usn/usn-470-1">USN-470-1</ref><ref source="UBUNTU" url="http://www.ubuntu.com/usn/usn-486-1">USN-486-1</ref><ref source="UBUNTU" url="http://www.ubuntu.com/usn/usn-489-1">USN-489-1</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25596">25596</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25700">25700</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25683">25683</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25838">25838</ref><ref source="SECUNIA" url="http://secunia.com/advisories/26133">26133</ref><ref source="SECUNIA" url="http://secunia.com/advisories/26139">26139</ref><ref source="SECUNIA" url="http://secunia.com/advisories/26289">26289</ref><ref source="SECUNIA" url="http://secunia.com/advisories/26379">26379</ref><ref source="SECUNIA" url="http://secunia.com/advisories/26478">26478</ref><ref source="SECUNIA" url="http://secunia.com/advisories/26450">26450</ref><ref source="SECUNIA" url="http://secunia.com/advisories/27528">27528</ref><ref source="DEBIAN" url="http://www.debian.org/security/2008/dsa-1503">DSA-1503</ref><ref source="DEBIAN" url="http://www.debian.org/security/2008/dsa-1504">DSA-1504</ref><ref source="SECUNIA" url="http://secunia.com/advisories/29058">29058</ref></refs><vuln_soft><prod name="Kernel" vendor="Linux"><vers num="2.4.34.2" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.0" CVSS_exploit_subscore="6.8" CVSS_impact_subscore="6.4" CVSS_score="6.0" CVSS_vector="(AV:N/AC:M/Au:S/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-07-30" name="CVE-2007-1354" published="2007-07-27" seq="2007-1354" severity="Medium" type="CVE"><desc><descript source="cve">The Access Control functionality (JMXOpsAccessControlFilter) in JMX Console in JBoss Application Server 4.0.2 and 4.0.5 before 20070416 uses a member variable to store the roles of the current user, which allows remote authenticated administrators to trigger a race condition and gain privileges by logging in during a session by a more privileged administrator, as demonstrated by privilege escalation from Read Mode to Write Mode.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><access/><race/></vuln_types><range><network/></range><refs><ref patch="1" source="MLIST" url="http://www.redhat.com/archives/jboss-watch-list/2007-April/msg00000.html">[jboss-watch-list] 20070416 [RHSA-2007:0151-01] Low: JBoss Application Server security update</ref><ref patch="1" source="" url="http://jira.jboss.com/jira/browse/ASPATCH-172"></ref><ref patch="1" source="" url="http://jira.jboss.com/jira/browse/ASPATCH-175"></ref><ref patch="1" source="REDHAT" url="http://rhn.redhat.com/errata/RHSA-2007-0151.html">RHSA-2007:0151</ref></refs><vuln_soft><prod name="JBoss Application Server" vendor="JBoss"><vers num="4.0.5.GA"/><vers num="4.0.5_CP01"/><vers num="4.0.5_CP02"/><vers num="4.0.2.GA_CP02"/><vers num="4.0.2.GA_CP03"/><vers num="4.0.2.GA_CP04"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" modified="2007-05-23" name="CVE-2007-1355" published="2007-05-21" seq="2007-1355" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in the appdev/sample/web/hello.jsp example application in Tomcat 4.0.0 through 4.0.6, 4.1.0 through 4.1.36, 5.0.0 through 5.0.30, 5.5.0 through 5.5.23, and 6.0.0 through 6.0.10 allow remote attackers to inject arbitrary web script or HTML via the test parameter and unspecified vectors.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/469067/100/0/threaded">20070519 [CVE-2007-1355] Tomcat documentation XSS vulnerabilities</ref><ref source="" url="http://tomcat.apache.org/security-4.html"></ref><ref source="" url="http://tomcat.apache.org/security-5.html"></ref><ref source="" url="http://tomcat.apache.org/security-6.html"></ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/24058">24058</ref><ref source="FEDORA" url="https://www.redhat.com/archives/fedora-package-announce/2007-November/msg00525.html">FEDORA-2007-3456</ref><ref source="HP" url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01178795">HPSBUX02262</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/3386">ADV-2007-3386</ref><ref source="SECUNIA" url="http://secunia.com/advisories/27037">27037</ref><ref source="SECUNIA" url="http://secunia.com/advisories/27727">27727</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2722">2722</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/34377">tomcat-hello-xss(34377)</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2008-0261.html">RHSA-2008:0261</ref><ref source="" url="http://support.apple.com/kb/HT2163"></ref><ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2008//Jun/msg00002.html">APPLE-SA-2008-06-30</ref><ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-239312-1">239312</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/1981/references">ADV-2008-1981</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/1979/references">ADV-2008-1979</ref><ref source="SECUNIA" url="http://secunia.com/advisories/30802">30802</ref><ref source="SECUNIA" url="http://secunia.com/advisories/30908">30908</ref><ref source="SECUNIA" url="http://secunia.com/advisories/30899">30899</ref></refs><vuln_soft><prod name="Tomcat" vendor="Apache Software Foundation"><vers num="4.0.0"/><vers num="4.0.1"/><vers num="4.0.2"/><vers num="4.0.3"/><vers num="4.0.4"/><vers num="4.0.5"/><vers num="4.0.6"/><vers num="4.1.10"/><vers num="4.1.15"/><vers num="4.1.24"/><vers num="4.1.28"/><vers num="4.1.31"/><vers num="5.0.1"/><vers num="5.0.10"/><vers num="5.0.11"/><vers num="5.0.12"/><vers num="5.0.13"/><vers num="5.0.14"/><vers num="5.0.15"/><vers num="5.0.16"/><vers num="5.0.17"/><vers num="5.0.18"/><vers num="5.0.19"/><vers num="5.0.2"/><vers num="5.0.21"/><vers num="5.0.22"/><vers num="5.0.23"/><vers num="5.0.24"/><vers num="5.0.25"/><vers num="5.0.26"/><vers num="5.0.27"/><vers num="5.0.28"/><vers num="5.0.29"/><vers num="5.0.3"/><vers num="5.0.30"/><vers num="5.0.4"/><vers num="5.0.5"/><vers num="5.0.6"/><vers num="5.0.7"/><vers num="5.0.8"/><vers num="5.0.9"/><vers num="6.0.9"/><vers num="6.0.0"/><vers num="6.0.1"/><vers num="6.0.10"/><vers num="6.0.2"/><vers num="6.0.3"/><vers num="6.0.4"/><vers num="6.0.5"/><vers num="6.0.6"/><vers num="6.0.7"/><vers num="6.0.8"/></prod></vuln_soft></entry><entry name="CVE-2007-1356" published="2007-08-23" reject="1" seq="2007-1356" type="CVE"><desc><descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: none.  Reason: This candidate was withdrawn by its CNA.  Further investigation showed that it was not a security issue.  Notes: none.</descript></desc><loss_types/><refs/></entry><entry CVSS_base_score="7.8" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.9" CVSS_score="7.8" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_version="2.0" modified="2007-04-11" name="CVE-2007-1357" published="2007-04-10" seq="2007-1357" severity="High" type="CVE"><desc><descript source="cve">The atalk_sum_skb function in AppleTalk for Linux kernel 2.6.x before 2.6.21, and possibly 2.4.x, allows remote attackers to cause a denial of service (crash) via an AppleTalk frame that is shorter than the specified length, which triggers a BUG_ON call when an attempt is made to perform a checksum.</descript></desc><loss_types><avail/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref source="" url="http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.20.5"></ref><ref source="" url="https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=235857"></ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/23376">23376</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24793">24793</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1340">
ADV-2007-1340</ref><ref source="" url="https://issues.rpath.com/browse/RPL-1244"></ref><ref source="SECUNIA" url="http://secunia.com/advisories/24901">
24901</ref><ref source="DEBIAN" url="http://www.debian.org/security/2007/dsa-1286">
DSA-1286</ref><ref source="SUSE" url="http://lists.suse.com/archive/suse-security-announce/2007-May/0001.html">
SUSE-SA:2007:029</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25078">
25078</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25099">
25099</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2007_30_kernel.html">
SUSE-SA:2007:030</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/471457">20070615 rPSA-2007-0124-1 kernel xen</ref><ref source="DEBIAN" url="http://www.debian.org/security/2007/dsa-1304">DSA-1304</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2007_35_kernel.html">SUSE-SA:2007:035</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2007_43_kernel.html">SUSE-SA:2007:043</ref><ref source="UBUNTU" url="http://www.ubuntu.com/usn/usn-464-1">USN-464-1</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25392">25392</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25683">25683</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25714">25714</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25691">25691</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25961">25961</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25226">25226</ref></refs><vuln_soft><prod name="Kernel" vendor="Linux"><vers num="2.6.20.4" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="2.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="2.9" CVSS_score="2.6" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" modified="2007-10-03" name="CVE-2007-1358" published="2007-05-09" seq="2007-1358" severity="Low" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in certain applications using Apache Tomcat 4.0.0 through 4.0.6 and 4.1.0 through 4.1.34 allows remote attackers to inject arbitrary web script or HTML via crafted &quot;Accept-Language headers that do not conform to RFC 2616&quot;.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref source="" url="http://tomcat.apache.org/security-4.html"></ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1729">ADV-2007-1729</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/471719/100/0/threaded">20070618 [CVE-2007-1358] Apache Tomcat XSS vulnerability in Accept-Language header processing</ref><ref source="" url="http://jvn.jp/jp/JVN%2316535199/index.html"></ref><ref source="" url="http://docs.info.apple.com/article.html?artnum=306172"></ref><ref source="" url="http://www.fujitsu.com/global/support/software/security/products-f/interstage-200704e.html"></ref><ref source="APPLE" url="http://lists.apple.com/archives/security-announce//2007/Jul/msg00004.html">APPLE-SA-2007-07-31</ref><ref source="FEDORA" url="https://www.redhat.com/archives/fedora-package-announce/2007-November/msg00525.html">FEDORA-2007-3456</ref><ref source="HP" url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01178795">HPSBUX02262</ref><ref source="BID" url="http://www.securityfocus.com/bid/24524">24524</ref><ref source="BID" url="http://www.securityfocus.com/bid/25159">25159</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/2732">ADV-2007-2732</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/3087">ADV-2007-3087</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/3386">ADV-2007-3386</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1018269">1018269</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25721">25721</ref><ref source="SECUNIA" url="http://secunia.com/advisories/26235">26235</ref><ref source="SECUNIA" url="http://secunia.com/advisories/26660">26660</ref><ref source="SECUNIA" url="http://secunia.com/advisories/27037">27037</ref><ref source="SECUNIA" url="http://secunia.com/advisories/27727">27727</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2008-0261.html">RHSA-2008:0261</ref><ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-239312-1">239312</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/1979/references">ADV-2008-1979</ref><ref source="SECUNIA" url="http://secunia.com/advisories/30908">30908</ref><ref source="SECUNIA" url="http://secunia.com/advisories/30899">30899</ref></refs><vuln_soft><prod name="Tomcat" vendor="Apache Software Foundation"><vers num="4.0.0"/><vers num="4.0.1"/><vers num="4.0.2"/><vers num="4.0.3"/><vers num="4.0.4"/><vers num="4.0.5"/><vers num="4.0.6"/><vers num="4.1.0"/><vers num="4.1.31" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2008-07-16" name="CVE-2007-1359" published="2007-03-08" seq="2007-1359" severity="Medium" type="CVE"><desc><descript source="cve">Interpretation conflict in ModSecurity (mod_security) 2.1.0 and earlier allows remote attackers to bypass request rules via application/x-www-form-urlencoded POST data that contains an ASCIIZ (0x00) byte, which mod_security treats as a terminator even though it is still processed as normal data by some HTTP parsers including PHP 5.2.0, and possibly parsers in Perl, and Python.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="" url="http://www.php-security.org/MOPB/BONUS-12-2007.html"></ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/22831">22831</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24373">24373</ref><ref source="" url="http://www.modsecurity.org/blog/archives/2007/03/modsecurity_asc.html"></ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0868">ADV-2007-0868</ref><ref source="OSVDB" url="http://www.osvdb.org/32778">32778</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32872">modsecurity-formurlencoded-security-bypass(32872)</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200705-17.xml">GLSA-200705-17</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25316">25316</ref><ref source="" url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujul2008.html"></ref><ref source="HP" url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00727143">HPSBMA02133</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/2115">ADV-2008-2115</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/2109/references">ADV-2008-2109</ref><ref source="SECUNIA" url="http://secunia.com/advisories/31113">31113</ref><ref source="SECUNIA" url="http://secunia.com/advisories/31087">31087</ref></refs><vuln_soft><prod name="mod_security" vendor="mod_security"><vers num="1.7"/><vers num="1.7.1"/><vers num="1.7.2"/><vers num="1.7.4"/><vers num="1.7.5"/><vers num="1.9.4"/><vers num="2.1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.0" CVSS_exploit_subscore="6.8" CVSS_impact_subscore="6.4" CVSS_score="6.0" CVSS_vector="(AV:N/AC:M/Au:S/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-03-09" name="CVE-2007-1360" published="2007-03-08" seq="2007-1360" severity="Medium" type="CVE"><desc><descript source="cve">Unspecified vulnerability in the Nodefamily module for Drupal 5.x before 5.x-1.0 allows remote authenticated users to access and modify other users&apos; profiles via unspecified URL parameters.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref patch="1" source="" url="http://drupal.org/node/125324"></ref><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/22853">22853</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0855">ADV-2007-0855</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24372">24372</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32873">
nodefamily-url-security-bypass(32873)</ref></refs><vuln_soft><prod name="Nodefamily" vendor="Drupal"><vers num="5.1_1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" modified="2007-03-09" name="CVE-2007-1361" published="2007-03-08" seq="2007-1361" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in virtuemart_parser.php in VirtueMart before 20070213 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.  NOTE: this issue is probably different than CVE-2007-0376.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref source="" url="http://sourceforge.net/project/shownotes.php?release_id=490831"></ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0817">ADV-2007-0817</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/24399">24399</ref><ref source="BID" url="http://www.securityfocus.com/bid/22816">22816</ref></refs><vuln_soft><prod name="Virtuemart" vendor="Virtuemart"><vers num="1.0.9" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:P)" CVSS_version="2.0" modified="2007-10-03" name="CVE-2007-1362" published="2007-05-31" seq="2007-1362" severity="Medium" type="CVE"><desc><descript source="cve">Mozilla Firefox 1.5.x before 1.5.0.12 and 2.x before 2.0.0.4, and SeaMonkey 1.0.9 and 1.1.2, allows remote attackers to cause a denial of service via (1) a large cookie path parameter, which triggers memory consumption, or (2) an internal delimiter within cookie path or name values, which could trigger a misinterpretation of cookie data, aka &quot;Path Abuse in Cookies.&quot;</descript></desc><loss_types><avail/></loss_types><vuln_types><input/><exception/></vuln_types><range><network/></range><refs><ref patch="1" source="" url="http://www.mozilla.org/security/announce/2007/mfsa2007-14.html"></ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/470172/100/200/threaded">20070531 FLEA-2007-0023-1: firefox</ref><ref source="" url="https://issues.rpath.com/browse/RPL-1424"></ref><ref source="DEBIAN" url="http://www.debian.org/security/2007/dsa-1300">DSA-1300</ref><ref source="DEBIAN" url="http://www.debian.org/security/2007/dsa-1306">DSA-1306</ref><ref source="DEBIAN" url="http://www.debian.org/security/2007/dsa-1308">DSA-1308</ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200706-06.xml">GLSA-200706-06</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:120">MDKSA-2007:120</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:126">MDKSA-2007:126</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2007-0400.html">RHSA-2007:0400</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2007-0401.html">RHSA-2007:0401</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2007-0402.html">RHSA-2007:0402</ref><ref source="SLACKWARE" url="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2007&amp;m=slackware-security.571857">SSA:2007-152-02</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2007_36_mozilla.html">SUSE-SA:2007:036</ref><ref source="UBUNTU" url="http://www.ubuntu.com/usn/usn-468-1">USN-468-1</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA07-151A.html">TA07-151A</ref><ref source="BID" url="http://www.securityfocus.com/bid/24242">24242</ref><ref source="BID" url="http://www.securityfocus.com/bid/22879">22879</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1994">ADV-2007-1994</ref><ref source="OSVDB" url="http://www.osvdb.org/35139">35139</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1018162">1018162</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1018163">1018163</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25476">25476</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25533">25533</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25559">25559</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25635">25635</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25647">25647</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25685">25685</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25534">25534</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25490">25490</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25750">25750</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25858">25858</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/34613">mozilla-doccookie-dos(34613)</ref><ref source="HP" url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00771742">HPSBUX02153</ref></refs><vuln_soft><prod name="SeaMonkey" vendor="Mozilla"><vers num="1.0.9"/><vers num="1.1.2"/></prod><prod name="Firefox" vendor="Mozilla"><vers num="1.5.0.1"/><vers num="1.5.0.10"/><vers num="1.5.0.11"/><vers num="1.5.0.2"/><vers num="1.5.0.3"/><vers num="1.5.0.4"/><vers num="1.5.0.5"/><vers num="1.5.0.6"/><vers num="1.5.0.7"/><vers num="1.5.0.8"/><vers num="1.5.0.9"/><vers num="1.5.1"/><vers num="1.5.2"/><vers num="1.5.3"/><vers num="1.5.4"/><vers num="1.5.5"/><vers num="1.5.6"/><vers num="1.5.7"/><vers num="1.5.8"/><vers num="2.0"/><vers num="2.0.0.1"/><vers num="2.0.0.2"/><vers num="2.0.0.3"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-04-17" name="CVE-2007-1363" published="2007-04-11" seq="2007-1363" severity="High" type="CVE"><desc><descript source="cve">Multiple SQL injection vulnerabilities in DropAFew before 0.2.1 allow remote attackers to execute arbitrary SQL commands via the (1) id parameter in the delete action in (a) search.php or (b) search-pda.php, or the (2) calories parameter in a save action in editlogcal.php.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="" url="http://www.cynops.de/advisories/CVE-2007-1363.txt"></ref><ref patch="1" source="" url="http://www.dropafew.com/sphpblog/comments.php?y=07&amp;m=04&amp;entry=entry070403-224437"></ref><ref source="BID" url="http://www.securityfocus.com/bid/23400">23400</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24861">24861</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33560">
dropafew-multiple-sql-injection(33560)</ref></refs><vuln_soft><prod name="DropAFew" vendor="DropAFew"><vers num="0.2" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.4" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="4.9" CVSS_score="6.4" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_version="2.0" modified="2007-08-02" name="CVE-2007-1364" published="2007-04-11" seq="2007-1364" severity="Medium" type="CVE"><desc><descript source="cve">DropAFew before 0.2.1 does not require authorization for certain privileged actions, which allows remote attackers to (1) view the logged calorie information of arbitrary users via the id parameter in editlogcal.php, (2) add arbitrary links via links.php, or (3) create arbitrary users via newaccount2.php.</descript></desc><loss_types><conf/><int/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" source="" url="https://www.cynops.de/advisories/CVE-2007-1363.txt"></ref><ref patch="1" source="" url="http://www.dropafew.com/sphpblog/comments.php?y=07&amp;m=04&amp;entry=entry070403-224437"></ref><ref source="BID" url="http://www.securityfocus.com/bid/23400">23400</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24861">24861</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33561">dropafew-editlogcal-information-disclosure(33561)</ref></refs><vuln_soft><prod name="DropAFew" vendor="DropAFew"><vers num="0.2" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-08-02" name="CVE-2007-1365" published="2007-03-10" seq="2007-1365" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in kern/uipc_mbuf2.c in OpenBSD 3.9 and 4.0 allows remote attackers to execute arbitrary code via fragmented IPv6 packets due to &quot;incorrect mbuf handling for ICMP6 packets.&quot;  NOTE: this was originally reported as a denial of service.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref source="MLIST" url="http://marc.theaimsgroup.com/?l=openbsd-cvs&amp;m=117252151023868&amp;w=2">[source-changes] 20070226 CVS: cvs.openbsd.org: src</ref><ref patch="1" source="OPENBSD" url="http://www.openbsd.org/errata39.html#m_dup1">[3.9] 020: SECURITY FIX: March 7, 2007</ref><ref source="OPENBSD" url="http://www.openbsd.org/errata40.html#m_dup1">[4.0] 010: SECURITY FIX: March 7, 2007</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1017735">1017735</ref><ref source="" url="http://www.coresecurity.com/?action=item&amp;id=1703"></ref><ref source="BID" url="http://www.securityfocus.com/bid/22901">22901</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017744">1017744</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24490">24490</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/986425">VU#986425</ref><ref source="OSVDB" url="http://www.osvdb.org/33050">33050</ref></refs><vuln_soft><prod name="OpenBSD" vendor="OpenBSD"><vers num="3.9"/><vers num="4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.9" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.9" CVSS_score="4.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:C)" CVSS_version="2.0" modified="2007-05-04" name="CVE-2007-1366" published="2007-05-02" seq="2007-1366" severity="Medium" type="CVE"><desc><descript source="cve">QEMU 0.8.2 allows local users to crash a virtual machine via the divisor operand to the aam instruction, as demonstrated by &quot;aam 0x0,&quot; which triggers a divide-by-zero error.</descript></desc><loss_types><avail/></loss_types><vuln_types><input bound="1"/></vuln_types><range><local/></range><refs><ref source="MLIST" url="http://lists.gnu.org/archive/html/qemu-devel/2007-04/msg00650.html">[Qemu-devel] 20070428 Qemu crashes on AAM 0</ref><ref source="MLIST" url="http://lists.gnu.org/archive/html/qemu-devel/2007-04/msg00651.html">[Qemu-devel] 20070429 Re: Qemu crashes on AAM 0</ref><ref source="" url="http://taviso.decsystem.org/virtsec.pdf"></ref><ref source="DEBIAN" url="http://www.debian.org/security/2007/dsa-1284">DSA-1284</ref><ref source="BID" url="http://www.securityfocus.com/bid/23731">23731</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1597">ADV-2007-1597</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/25073">25073</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/25095">25095</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/34046">qemu-aam-dos(34046)</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDVSA-2008:162">MDVSA-2008:162</ref></refs><vuln_soft><prod name="QEMU" vendor="Fabrice Bellard"><vers num="0.8.2"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" modified="2007-03-15" name="CVE-2007-1367" published="2007-03-09" seq="2007-1367" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in the login page in Avaya Communications Manager (CM) S87XX, S8500, and S8300 products before 3.1.3 allows remote attackers to inject arbitrary web script or HTML via the Login field.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" patch="1" source="" url="http://support.avaya.com/elmodocs2/security/ASA-2007-064.htm"></ref><ref source="BID" url="http://www.securityfocus.com/bid/22866">22866</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24397">24397</ref><ref source="OSVDB" url="http://www.osvdb.org/33297">
33297</ref></refs><vuln_soft><prod name="S8710" vendor="Avaya"><vers num="CM 2.0"/><vers num="CM 3.1"/><vers num="R2.0.0"/><vers num="R2.0.1"/></prod><prod name="S8300" vendor="Avaya"><vers num="CM 2.0"/><vers num="CM 3.1"/><vers num="R2.0.0"/><vers num="R2.0.1"/></prod><prod name="S8500" vendor="Avaya"><vers num="CM 2.0"/><vers num="CM 3.1"/><vers num="R2.0.0"/><vers num="R2.0.1"/></prod><prod name="S8700 Series" vendor="Avaya"><vers num="CM 2.0"/><vers num="CM 3.1"/><vers num="R2.0.0"/><vers num="R2.0.1"/></prod></vuln_soft></entry><entry CVSS_base_score="3.5" CVSS_exploit_subscore="6.8" CVSS_impact_subscore="2.9" CVSS_score="3.5" CVSS_vector="(AV:N/AC:M/Au:S/C:P/I:N/A:N)" CVSS_version="2.0" modified="2007-03-15" name="CVE-2007-1368" published="2007-03-09" seq="2007-1368" severity="Low" type="CVE"><desc><descript source="cve">The Project issue tracking module before 4.7.x-1.3, 4.7.x-2.* before 4.7.x-2.3, and 5 before 5.x-0.2-beta for Drupal allows remote authenticated users, with &quot;access project issues&quot; permission, to read the contents of a private node via a URL with a modified node identifier.</descript></desc><loss_types><conf/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" source="" url="http://drupal.org/node/125832"></ref><ref patch="1" source="" url="http://drupal.org/node/125833"></ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/22867">22867</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0873">ADV-2007-0873</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/24409">24409</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32871">
projectissuetracking-node-security-bypass(32871)</ref></refs><vuln_soft><prod name="Drupal Project Issue Tracking" vendor="Drupal"><vers num="4.7_1.0"/><vers num="4.7_1.2"/><vers num="4.7_2.0"/><vers num="4.7_2.1"/><vers num="4.7_2.2"/><vers num="5.0_0.1"/><vers num="5.7_1.1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.4" CVSS_exploit_subscore="3.4" CVSS_impact_subscore="6.4" CVSS_score="4.4" CVSS_vector="(AV:L/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-03-15" name="CVE-2007-1369" published="2007-03-09" seq="2007-1369" severity="Medium" type="CVE"><desc><descript source="cve">ini_modifier (sgid-zendtech) in Zend Platform 2.2.3 and earlier allows local users to modify the system php.ini file by editing a copy of php.ini file using the -f parameter, and then performing a symlink attack using the directory that contains the attacker-controlled php.ini file, and linking this directory to /usr/local/Zend/etc.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/><input/></vuln_types><range><local/></range><refs><ref adv="1" source="" url="http://www.php-security.org/MOPB/BONUS-07-2007.html"></ref><ref adv="1" patch="1" source="" url="http://www.zend.com/products/zend_platform/security_vulnerabilities"></ref><ref source="BID" url="http://www.securityfocus.com/bid/22802">22802</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0829">ADV-2007-0829</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32820">zend-inimodifier-privilege-escalation(32820)</ref><ref source="OSVDB" url="http://www.osvdb.org/32773">
32773</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24501">
24501</ref></refs><vuln_soft><prod name="Zend Platform" vendor="Zend"><vers num="2.2.3" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.2" CVSS_exploit_subscore="1.9" CVSS_impact_subscore="10.0" CVSS_score="6.2" CVSS_vector="(AV:L/AC:H/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-03-12" name="CVE-2007-1370" published="2007-03-09" seq="2007-1370" severity="Medium" type="CVE"><desc><descript source="cve">Zend Platform 2.2.3 and earlier has incorrect ownership for scd.sh and certain other files, which allows local users to gain root privileges by modifying the files.  NOTE: this only occurs when safe_mode and open_basedir are disabled; other settings require leverage for other vulnerabilities.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><access/><input/><config/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="" url="http://www.php-security.org/MOPB/BONUS-06-2007.html"></ref><ref adv="1" source="" url="http://www.zend.com/products/zend_platform/security_vulnerabilities"></ref><ref source="BID" url="http://www.securityfocus.com/bid/22801">22801</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0829">ADV-2007-0829</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32825">zend-scd-privilege-escalation(32825)</ref><ref source="OSVDB" url="http://www.osvdb.org/32772">
32772</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24501">
24501</ref></refs><vuln_soft><prod name="Zend Platform" vendor="Zend"><vers edition="a" num="2.2.1a"/><vers num="2.2.1a"/></prod></vuln_soft></entry><entry CVSS_base_score="6.9" CVSS_exploit_subscore="3.4" CVSS_impact_subscore="10.0" CVSS_score="6.9" CVSS_vector="(AV:L/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-03-15" name="CVE-2007-1371" published="2007-03-09" seq="2007-1371" severity="Medium" type="CVE"><desc><descript source="cve">Multiple buffer overflows in Conquest 8.2a and earlier (1) allow local users to gain privileges by querying a metaserver that sends a long server entry processed by metaGetServerList and allow remote metaservers to execute arbitrary code via a long server entry processed by metaGetServerList; (2) allow attackers to have an unknown impact by exceeding the configured number of metaservers; and allow remote attackers to corrupt memory via a SP_CLIENTSTAT packet with certain values of (3) unum or (4) snum, different vulnerabilities than CVE-2003-0933.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/462184/100/0/threaded">20070307 Buffer-overflow in Conquest client 8.2a (svn 691)</ref><ref source="MLIST" url="http://www.radscan.com/conquest/cq-ml/msg00169.html">[conquest] 20070303 Re: security bugs in conquest</ref><ref source="BID" url="http://www.securityfocus.com/bid/22855">22855</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0854">ADV-2007-0854</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24370">24370</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32849">conquest-metagetserverlist-bo(32849)</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32860">conquest-processpacket-dos(32860)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2399">2399</ref></refs><vuln_soft><prod name="Conquest" vendor="Radscan"><vers num="8.2a" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-03-15" name="CVE-2007-1372" published="2007-03-09" seq="2007-1372" severity="High" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in styles/internal/header.php in the PostGuestbook 0.6.1 module for PHP-Nuke allows remote attackers to execute arbitrary PHP code via a URL in the tpl_pgb_moddir parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3423">3423</ref><ref source="BID" url="http://www.securityfocus.com/bid/22858">22858</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32866">postguestbook-header-file-include(32866)</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0880">
ADV-2007-0880</ref></refs><vuln_soft><prod name="PostGuestbook" vendor="PostGuestbook"><vers num="0.6.1"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-03-15" name="CVE-2007-1373" published="2007-03-09" seq="2007-1373" severity="High" type="CVE"><desc><descript source="cve">Stack-based buffer overflow in Mercury/32 (aka Mercury Mail Transport System) 4.01b and earlier allows remote attackers to execute arbitrary code via a long LOGIN command.  NOTE: this might be the same issue as CVE-2006-5961.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2007-March/052802.html">20070306 Mercury/32 4.01b</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24367">24367</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32848">mercury-imap-bo(32848)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2398">2398</ref></refs><vuln_soft><prod name="Mail Transport System" vendor="Mercury"><vers num="4.01b" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" modified="2007-03-15" name="CVE-2007-1374" published="2007-03-09" seq="2007-1374" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in pop_profile.asp in Snitz Forums 2000 3.4.06 allows remote attackers to inject arbitrary web script or HTML via the MSN parameter.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref source="BID" url="http://www.securityfocus.com/bid/22869">22869</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24358">24358</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32879">snitzforums-popprofile-xss(32879)</ref></refs><vuln_soft><prod name="Snitz Forums 2000" vendor="Snitz Communications"><vers num="3.4.06"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0" modified="2007-03-15" name="CVE-2007-1375" published="2007-03-09" seq="2007-1375" severity="Medium" type="CVE"><desc><descript source="cve">Integer overflow in the substr_compare function in PHP 5.2.1 and earlier allows context-dependent attackers to read sensitive memory via a large value in the length argument, a different vulnerability than CVE-2006-1991.</descript></desc><loss_types><conf/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3424">3424</ref><ref adv="1" source="" url="http://www.php-security.org/MOPB/MOPB-14-2007.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/22851">22851</ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200703-21.xml">
GLSA-200703-21</ref><ref source="OSVDB" url="http://www.osvdb.org/32780">
32780</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24606">
24606</ref><ref source="DEBIAN" url="http://www.debian.org/security/2007/dsa-1283">
DSA-1283</ref><ref source="UBUNTU" url="http://www.ubuntu.com/usn/usn-455-1">
USN-455-1</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25062">
25062</ref><ref source="" url="http://us2.php.net/releases/5_2_2.php"></ref><ref source="SECUNIA" url="http://secunia.com/advisories/25057">
25057</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:187">MDKSA-2007:187</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2007_32_php.html">SUSE-SA:2007:032</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25056">25056</ref><ref source="SECUNIA" url="http://secunia.com/advisories/26895">26895</ref></refs><vuln_soft><prod name="PHP" vendor="PHP"><vers num="5.2.1" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-03-15" name="CVE-2007-1376" published="2007-03-09" seq="2007-1376" severity="High" type="CVE"><desc><descript source="cve">The shmop functions in PHP before 4.4.5, and before 5.2.1 in the 5.x series, do not verify that their arguments correspond to a shmop resource, which allows context-dependent attackers to read and write arbitrary memory locations via arguments associated with an inappropriate resource, as demonstrated by a GD Image resource.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3426">3426</ref><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3427">3427</ref><ref source="" url="http://www.php-security.org/MOPB/MOPB-15-2007.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/22862">22862</ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200703-21.xml">
GLSA-200703-21</ref><ref source="OSVDB" url="http://www.osvdb.org/32781">
32781</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24606">
24606</ref><ref source="DEBIAN" url="http://www.debian.org/security/2007/dsa-1283">
DSA-1283</ref><ref source="UBUNTU" url="http://www.ubuntu.com/usn/usn-455-1">
USN-455-1</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25062">
25062</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25057">
25057</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2007_32_php.html">SUSE-SA:2007:032</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25056">25056</ref></refs><vuln_soft><prod name="PHP" vendor="PHP"><vers num="4.0"/><vers num="4.0 Beta 1"/><vers num="4.0 Beta 2"/><vers num="4.0 Beta 3"/><vers num="4.0 Beta 4"/><vers num="4.0 Beta 4 Patch Level 1"/><vers num="4.0 RC1"/><vers num="4.0 RC2"/><vers num="4.0.0"/><vers num="4.0.1"/><vers num="4.0.1 pl1"/><vers num="4.0.1 pl2"/><vers num="4.0.2"/><vers num="4.0.3"/><vers num="4.0.3 pl1"/><vers num="4.0.4"/><vers num="4.0.4 pl1"/><vers num="4.0.5"/><vers num="4.0.6"/><vers num="4.0.7"/><vers num="4.0.7 RC1"/><vers num="4.0.7 RC2"/><vers num="4.0.7 RC3"/><vers num="4.1.0"/><vers num="4.1.1"/><vers num="4.1.2"/><vers edition="Dev" num="4.2"/><vers num="4.2.0"/><vers num="4.2.1"/><vers num="4.2.2"/><vers num="4.2.3"/><vers num="4.3"/><vers num="4.3.1"/><vers num="4.3.10"/><vers num="4.3.11"/><vers num="4.3.2"/><vers num="4.3.3"/><vers num="4.3.4"/><vers num="4.3.5"/><vers num="4.3.6"/><vers num="4.3.7"/><vers num="4.3.8"/><vers num="4.3.9"/><vers num="4.4.0"/><vers num="4.4.1"/><vers num="4.4.2"/><vers num="4.4.3"/><vers num="4.4.4"/><vers num="4.4.5"/><vers num="5.0 candidate 1"/><vers num="5.0 candidate 2"/><vers num="5.0 candidate 3"/><vers num="5.0.0"/><vers num="5.0.0 Beta1"/><vers num="5.0.0 Beta2"/><vers num="5.0.0 Beta3"/><vers num="5.0.0 Beta4"/><vers num="5.0.0 RC1"/><vers num="5.0.0 RC2"/><vers num="5.0.0 RC3"/><vers num="5.0.1"/><vers num="5.0.2"/><vers num="5.0.3"/><vers num="5.0.4"/><vers num="5.0.5"/><vers num="5.1"/><vers num="5.1.0"/><vers num="5.1.1"/><vers num="5.1.2"/><vers num="5.1.3"/><vers num="5.1.4"/><vers num="5.1.5"/><vers num="5.1.6"/><vers num="5.2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0" modified="2007-03-15" name="CVE-2007-1377" published="2007-03-09" seq="2007-1377" severity="Medium" type="CVE"><desc><descript source="cve">AcroPDF.DLL in Adobe Reader 8.0, when accessed from Mozilla Firefox, Netscape, or Opera, allows remote attackers to cause a denial of service (unspecified resource consumption) via a .pdf URL with an anchor identifier that begins with search= followed by many %n sequences, a different vulnerability than CVE-2006-6027 and CVE-2006-6236.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref source="" url="http://www.securityfocus.com/data/vulnerabilities/exploits/22856.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/22856">22856</ref></refs><vuln_soft><prod name="Opera" vendor="Opera Software"><vers num=""/></prod><prod name="Netscape" vendor="Netscape"><vers num=""/></prod><prod name="Acrobat Reader" vendor="Adobe"><vers num="8.0"/><vers num="8.0"/><vers num="8.0"/></prod><prod name="Firefox" vendor="Mozilla"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.1" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="6.4" CVSS_score="5.1" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-04-11" name="CVE-2007-1378" published="2007-03-09" seq="2007-1378" severity="Medium" type="CVE"><desc><descript source="cve">The ovrimos_longreadlen function in the Ovrimos extension for PHP before 4.4.5 allows context-dependent attackers to write to arbitrary memory locations via the result_id and length arguments.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://www.php-security.org/MOPB/MOPB-13-2007.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/22833">22833</ref><ref source="OSVDB" url="http://www.osvdb.org/32779">32779</ref></refs><vuln_soft><prod name="PHP" vendor="PHP"><vers num="3.0"/><vers num="3.0.1"/><vers num="3.0.10"/><vers num="3.0.11"/><vers num="3.0.12"/><vers num="3.0.13"/><vers num="3.0.14"/><vers num="3.0.15"/><vers num="3.0.16"/><vers num="3.0.17"/><vers num="3.0.18"/><vers num="3.0.2"/><vers num="3.0.3"/><vers num="3.0.4"/><vers num="3.0.5"/><vers num="3.0.6"/><vers num="3.0.7"/><vers num="3.0.8"/><vers num="3.0.9"/><vers num="4.0"/><vers num="4.0 Beta 1"/><vers num="4.0 Beta 2"/><vers num="4.0 Beta 3"/><vers num="4.0 Beta 4"/><vers num="4.0 Beta 4 Patch Level 1"/><vers num="4.0 RC1"/><vers num="4.0 RC2"/><vers num="4.0.0"/><vers num="4.0.1"/><vers num="4.0.1 pl1"/><vers num="4.0.1 pl2"/><vers num="4.0.2"/><vers num="4.0.3"/><vers num="4.0.3 pl1"/><vers num="4.0.4"/><vers num="4.0.4 pl1"/><vers num="4.0.5"/><vers num="4.0.6"/><vers num="4.0.7"/><vers num="4.0.7 RC1"/><vers num="4.0.7 RC2"/><vers num="4.0.7 RC3"/><vers num="4.1.0"/><vers num="4.1.1"/><vers num="4.1.2"/><vers edition="Dev" num="4.2"/><vers num="4.2.0"/><vers num="4.2.1"/><vers num="4.2.2"/><vers num="4.2.3"/><vers num="4.3"/><vers num="4.3.1"/><vers num="4.3.10"/><vers num="4.3.11"/><vers num="4.3.2"/><vers num="4.3.3"/><vers num="4.3.4"/><vers num="4.3.5"/><vers num="4.3.6"/><vers num="4.3.7"/><vers num="4.3.8"/><vers num="4.3.9"/><vers num="4.4.0"/><vers num="4.4.1"/><vers num="4.4.2"/><vers num="4.4.3"/><vers num="4.4.4"/></prod></vuln_soft></entry><entry CVSS_base_score="5.1" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="6.4" CVSS_score="5.1" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-04-11" name="CVE-2007-1379" published="2007-03-09" seq="2007-1379" severity="Medium" type="CVE"><desc><descript source="cve">The ovrimos_close function in the Ovrimos extension for PHP before 4.4.5 can trigger efree of an arbitrary address, which might allow context-dependent attackers to execute arbitrary code.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://www.php-security.org/MOPB/MOPB-13-2007.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/22833">22833</ref><ref source="OSVDB" url="http://www.osvdb.org/34691">34691</ref></refs><vuln_soft><prod name="PHP" vendor="PHP"><vers num="3.0"/><vers num="3.0.1"/><vers num="3.0.10"/><vers num="3.0.11"/><vers num="3.0.12"/><vers num="3.0.13"/><vers num="3.0.14"/><vers num="3.0.15"/><vers num="3.0.16"/><vers num="3.0.17"/><vers num="3.0.18"/><vers num="3.0.2"/><vers num="3.0.3"/><vers num="3.0.4"/><vers num="3.0.5"/><vers num="3.0.6"/><vers num="3.0.7"/><vers num="3.0.8"/><vers num="3.0.9"/><vers num="4.0"/><vers num="4.0 Beta 1"/><vers num="4.0 Beta 2"/><vers num="4.0 Beta 3"/><vers num="4.0 Beta 4"/><vers num="4.0 Beta 4 Patch Level 1"/><vers num="4.0 RC1"/><vers num="4.0 RC2"/><vers num="4.0.0"/><vers num="4.0.1"/><vers num="4.0.1 pl1"/><vers num="4.0.1 pl2"/><vers num="4.0.2"/><vers num="4.0.3"/><vers num="4.0.3 pl1"/><vers num="4.0.4"/><vers num="4.0.4 pl1"/><vers num="4.0.5"/><vers num="4.0.6"/><vers num="4.0.7"/><vers num="4.0.7 RC1"/><vers num="4.0.7 RC2"/><vers num="4.0.7 RC3"/><vers num="4.1.0"/><vers num="4.1.1"/><vers num="4.1.2"/><vers edition="Dev" num="4.2"/><vers num="4.2.0"/><vers num="4.2.1"/><vers num="4.2.2"/><vers num="4.2.3"/><vers num="4.3"/><vers num="4.3.1"/><vers num="4.3.10"/><vers num="4.3.11"/><vers num="4.3.2"/><vers num="4.3.3"/><vers num="4.3.4"/><vers num="4.3.5"/><vers num="4.3.6"/><vers num="4.3.7"/><vers num="4.3.8"/><vers num="4.3.9"/><vers num="4.4.0"/><vers num="4.4.1"/><vers num="4.4.2"/><vers num="4.4.3"/><vers num="4.4.4"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0" modified="2007-04-19" name="CVE-2007-1380" published="2007-03-09" seq="2007-1380" severity="Medium" type="CVE"><desc><descript source="cve">The php_binary serialization handler in the session extension in PHP before 4.4.5, and 5.x before 5.2.1, allows context-dependent attackers to obtain sensitive information (memory contents) via a serialized variable entry with a large length value, which triggers a buffer over-read.</descript></desc><loss_types><conf/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3413">3413</ref><ref source="" url="http://www.php-security.org/MOPB/MOPB-10-2007.html"></ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200703-21.xml">GLSA-200703-21</ref><ref source="SUSE" url="http://lists.suse.com/archive/suse-security-announce/2007-Mar/0003.html">SUSE-SA:2007:020</ref><ref source="BID" url="http://www.securityfocus.com/bid/22805">22805</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24514">24514</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24606">24606</ref><ref source="DEBIAN" url="http://www.debian.org/security/2007/dsa-1282">
DSA-1282</ref><ref source="DEBIAN" url="http://www.debian.org/security/2007/dsa-1283">
DSA-1283</ref><ref source="UBUNTU" url="http://www.ubuntu.com/usn/usn-455-1">
USN-455-1</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25025">
25025</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25062">
25062</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25057">
25057</ref><ref source="HP" url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&amp;cc=us&amp;objectID=c01056506">HPSBMA02215</ref><ref source="HP" url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&amp;cc=us&amp;objectID=c01086137">HPSBTU02232</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2007_32_php.html">SUSE-SA:2007:032</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1991">ADV-2007-1991</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/2374">ADV-2007-2374</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25056">25056</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25423">25423</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25850">25850</ref></refs><vuln_soft><prod name="PHP" vendor="PHP"><vers num="4.0"/><vers num="4.0 Beta 1"/><vers num="4.0 Beta 2"/><vers num="4.0 Beta 3"/><vers num="4.0 Beta 4"/><vers num="4.0 Beta 4 Patch Level 1"/><vers num="4.0 RC1"/><vers num="4.0 RC2"/><vers num="4.0.0"/><vers num="4.0.1"/><vers num="4.0.1 pl1"/><vers num="4.0.1 pl2"/><vers num="4.0.2"/><vers num="4.0.3"/><vers num="4.0.3 pl1"/><vers num="4.0.4"/><vers num="4.0.4 pl1"/><vers num="4.0.5"/><vers num="4.0.6"/><vers num="4.0.7"/><vers num="4.0.7 RC1"/><vers num="4.0.7 RC2"/><vers num="4.0.7 RC3"/><vers num="4.1.0"/><vers num="4.1.1"/><vers num="4.1.2"/><vers edition="Dev" num="4.2"/><vers num="4.2.0"/><vers num="4.2.1"/><vers num="4.2.2"/><vers num="4.2.3"/><vers num="4.3"/><vers num="4.3.1"/><vers num="4.3.10"/><vers num="4.3.11"/><vers num="4.3.2"/><vers num="4.3.3"/><vers num="4.3.4"/><vers num="4.3.5"/><vers num="4.3.6"/><vers num="4.3.7"/><vers num="4.3.8"/><vers num="4.3.9"/><vers num="4.4.0"/><vers num="4.4.1"/><vers num="4.4.2"/><vers num="4.4.3"/><vers num="4.4.4"/><vers num="5.0 candidate 1"/><vers num="5.0 candidate 2"/><vers num="5.0 candidate 3"/><vers num="5.0.0"/><vers num="5.0.0 Beta1"/><vers num="5.0.0 Beta2"/><vers num="5.0.0 Beta3"/><vers num="5.0.0 Beta4"/><vers num="5.0.0 RC1"/><vers num="5.0.0 RC2"/><vers num="5.0.0 RC3"/><vers num="5.0.1"/><vers num="5.0.2"/><vers num="5.0.3"/><vers num="5.0.4"/><vers num="5.0.5"/><vers num="5.1"/><vers num="5.1.0"/><vers num="5.1.1"/><vers num="5.1.2"/><vers num="5.1.3"/><vers num="5.1.4"/><vers num="5.1.5"/><vers num="5.1.6"/><vers num="5.2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="10.0" CVSS_score="7.6" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2008-04-04" name="CVE-2007-1381" published="2007-03-09" seq="2007-1381" severity="High" type="CVE"><desc><descript source="cve">The wddx_deserialize function in wddx.c 1.119.2.10.2.12 and 1.119.2.10.2.13 in PHP 5, as modified in CVS on 20070224 and fixed on 20070304, calls strlcpy where strlcat was intended and uses improper arguments, which allows context-dependent attackers to execute arbitrary code via a WDDX packet with a malformed overlap of a STRING element, which triggers a buffer overflow.</descript></desc><impacts><impact source="nvd">This vulnerability impacts PHP CVS as of 2007-02-24</impact></impacts><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref source="" url="http://www.php-security.org/MOPB/MOPB-09-2007.html"></ref><ref source="OSVDB" url="http://www.osvdb.org/32775">32775</ref><ref source="" url="http://cvs.php.net/viewvc.cgi/php-src/ext/wddx/wddx.c?revision=1.119.2.10.2.14&amp;view=markup"></ref><ref source="" url="http://cvs.php.net/viewvc.cgi/php-src/ext/wddx/wddx.c?r1=1.119.2.10.2.13&amp;r2=1.119.2.10.2.14"></ref></refs><vuln_soft><prod name="PHP" vendor="PHP"><vers num="5.0.0"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="3.1" CVSS_impact_subscore="10.0" CVSS_score="6.8" CVSS_vector="(AV:L/AC:L/Au:S/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-04-26" name="CVE-2007-1382" published="2007-03-09" seq="2007-1382" severity="Medium" type="CVE"><desc><descript source="cve">The PHP COM extensions for PHP on Windows systems allow context-dependent attackers to execute arbitrary code via a WScript.Shell COM object, as demonstrated by using the Run method of this object to execute cmd.exe, which bypasses PHP&apos;s safe mode.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3429">3429</ref></refs><vuln_soft><prod name="COM extensions" vendor="PHP"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2008-04-28" name="CVE-2007-1383" published="2007-03-09" seq="2007-1383" severity="High" type="CVE"><desc><descript source="cve">Integer overflow in the 16 bit variable reference counter in PHP 4 allows context-dependent attackers to execute arbitrary code by overflowing this counter, which causes the same variable to be destroyed twice, a related issue to CVE-2007-1286.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref source="" url="http://www.php-security.org/MOPB/MOPB-01-2007.html"></ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200703-21.xml">GLSA-200703-21</ref><ref source="BID" url="http://www.securityfocus.com/bid/22765">22765</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24606">24606</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2007_32_php.html">SUSE-SA:2007:032</ref><ref source="OSVDB" url="http://www.osvdb.org/32770">32770</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25056">25056</ref></refs><vuln_soft><prod name="PHP" vendor="PHP"><vers num="4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="6.4" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="4.9" CVSS_score="6.4" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:P)" CVSS_version="2.0" modified="2007-03-15" name="CVE-2007-1384" published="2007-03-10" seq="2007-1384" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in torrent.cpp in KTorrent before 2.1.2 allows remote attackers to overwrite arbitrary files via &quot;..&quot; sequences in a torrent filename.</descript></desc><loss_types><avail/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="MLIST" url="http://lists.kde.org/?l=kde-announce&amp;m=117346514411140&amp;w=2">[kde-announce] 20070309 KTorrent 2.1.2 is out</ref><ref source="" url="http://ktorrent.org/forum/viewtopic.php?t=1401"></ref><ref source="" url="https://launchpad.net/bugs/91174"></ref><ref source="UBUNTU" url="http://www.ubuntu.com/usn/usn-436-1">
USN-436-1</ref><ref source="BID" url="http://www.securityfocus.com/bid/22930">
22930</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0913">
ADV-2007-0913</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24486">
24486</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24459">
24459</ref><ref source="SLACKWARE" url="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2007&amp;m=slackware-security.401332">
SSA:2007-093-02</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24753">
24753</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2007_007_suse.html">
SUSE-SR:2007:007</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24995">
24995</ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200705-01.xml">
GLSA-200705-01</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25097">
25097</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017747">1017747</ref></refs><vuln_soft><prod name="KTorrent" vendor="Joris Guisson"><vers num="2.1.1" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-03-15" name="CVE-2007-1385" published="2007-03-10" seq="2007-1385" severity="High" type="CVE"><desc><descript source="cve">chunkcounter.cpp in KTorrent before 2.1.2 allows remote attackers to cause a denial of service (crash) and heap corruption via a negative or large idx value.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref source="MLIST" url="http://lists.kde.org/?l=kde-announce&amp;m=117346514411140&amp;w=2">[kde-announce] 20070309 KTorrent 2.1.2 is out</ref><ref source="" url="http://ktorrent.org/forum/viewtopic.php?t=1401"></ref><ref source="" url="https://launchpad.net/bugs/91174"></ref><ref source="UBUNTU" url="http://www.ubuntu.com/usn/usn-436-1">
USN-436-1</ref><ref source="BID" url="http://www.securityfocus.com/bid/22930">
22930</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0913">
ADV-2007-0913</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24486">
24486</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24459">
24459</ref><ref source="SLACKWARE" url="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2007&amp;m=slackware-security.401332">
SSA:2007-093-02</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24753">
24753</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2007_007_suse.html">
SUSE-SR:2007:007</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24995">
24995</ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200705-01.xml">
GLSA-200705-01</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25097">
25097</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017747">1017747</ref></refs><vuln_soft><prod name="KTorrent" vendor="Joris Guisson"><vers num="2.1.1" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="3.2" CVSS_impact_subscore="10.0" CVSS_score="6.8" CVSS_vector="(AV:N/AC:H/Au:M/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-03-13" name="CVE-2007-1387" published="2007-03-13" seq="2007-1387" severity="Medium" type="CVE"><desc><descript source="cve">The DirectShow loader (loader/dshow/DS_VideoDecoder.c) in MPlayer 1.0rc1 and earlier, as used in xine-lib, does not set the biSize before use in a memcpy, which allows user-assisted remote attackers to cause a buffer overflow and possibly execute arbitrary code, a different vulnerability than CVE-2007-1246.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/><user_init/></range><refs><ref patch="1" source="" url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=414072;msg=12;filename=DS_VideoDecoder.c---SVN--22205.patch;att=1"></ref><ref source="" url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=414072"></ref><ref source="UBUNTU" url="http://www.ubuntulinux.org/support/documentation/usn/usn-435-1">USN-435-1</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24462">24462</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2007:061">
MDKSA-2007:061</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2007:062">
MDKSA-2007:062</ref><ref source="BID" url="http://www.securityfocus.com/bid/22933">
22933</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24444">
24444</ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200705-21.xml">GLSA-200705-21</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:061">MDKSA-2007:061</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:062">MDKSA-2007:062</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25462">25462</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24443">24443</ref><ref source="DEBIAN" url="http://www.debian.org/security/2008/dsa-1536">DSA-1536</ref><ref source="SECUNIA" url="http://secunia.com/advisories/29601">29601</ref></refs><vuln_soft><prod name="Mplayer" vendor="Mplayer"><vers num="1.0 rc1" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.4" CVSS_exploit_subscore="2.7" CVSS_impact_subscore="6.9" CVSS_score="4.4" CVSS_vector="(AV:L/AC:M/Au:S/C:N/I:N/A:C)" CVSS_version="2.0" modified="2007-04-10" name="CVE-2007-1388" published="2007-03-10" seq="2007-1388" severity="Medium" type="CVE"><desc><descript source="cve">The do_ipv6_setsockopt function in net/ipv6/ipv6_sockglue.c in Linux kernel before 2.6.20, and possibly other versions, allows local users to cause a denial of service (oops) by calling setsockopt with the IPV6_RTHDR option name and possibly a zero option length or invalid option value, which triggers a NULL pointer dereference.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><local/></range><refs><ref source="" url="http://bugzilla.kernel.org/show_bug.cgi?id=8155"></ref><ref source="" url="http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.20.4"></ref><ref source="BID" url="http://www.securityfocus.com/bid/23142">23142</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1122">ADV-2007-1122</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2007:078">
MDKSA-2007:078</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24777">
24777</ref><ref source="" url="https://issues.rpath.com/browse/RPL-1154"></ref><ref source="SECUNIA" url="http://secunia.com/advisories/24901">
24901</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2007-0169.html">
RHSA-2007:0169</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25080">
25080</ref><ref source="SUSE" url="http://lists.suse.com/archive/suse-security-announce/2007-May/0001.html">
SUSE-SA:2007:029</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25099">
25099</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:078">MDKSA-2007:078</ref><ref source="UBUNTU" url="http://www.ubuntu.com/usn/usn-464-1">USN-464-1</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25392">25392</ref></refs><vuln_soft><prod name="Kernel" vendor="Linux"><vers num="2.6.19-rc4" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-03-15" name="CVE-2007-1389" published="2007-03-10" seq="2007-1389" severity="High" type="CVE"><desc><descript source="cve">dynaliens 2.0 and 2.1 allows remote attackers to bypass authentication and perform certain privileged actions via a direct request for (1) validlien.php3 (2) supprlien.php3 (3) supprub.php3 (4) validlien.php3 (5) confsuppr.php3 (6) modiflien.php3, or (7) confmodif.php3 in admin/.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/462221/100/0/threaded">20070308 dynaliens v2.0/v2.1 bypass admin authentification + XSS</ref><ref source="" url="http://forums.avenir-geopolitique.net/viewtopic.php?t=2722"></ref><ref source="BID" url="http://www.securityfocus.com/bid/22873">22873</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2403">2403</ref></refs><vuln_soft><prod name="Dynaliens" vendor="Dynaliens"><vers num="2.0"/><vers num="2.1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" modified="2007-03-15" name="CVE-2007-1390" published="2007-03-10" seq="2007-1390" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in dynaliens 2.0 and 2.1 allow remote attackers to inject arbitrary web script or HTML via unspecified parameters to (1) recherche.php3 or (2) ajouter.php3.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/462221/100/0/threaded">20070308 dynaliens v2.0/v2.1 bypass admin authentification + XSS</ref><ref source="" url="http://forums.avenir-geopolitique.net/viewtopic.php?t=2722"></ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/22874">22874</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2403">2403</ref></refs><vuln_soft><prod name="Dynaliens" vendor="Dynaliens"><vers num="2.0"/><vers num="2.1"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-03-15" name="CVE-2007-1391" published="2007-03-10" seq="2007-1391" severity="High" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in modules/abook/foldertree.php in Leo West WEBO (aka weborganizer) 1.0 allows remote attackers to execute arbitrary PHP code via a URL in the baseDir parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3436">3436</ref><ref source="" url="http://advisories.echo.or.id/adv/adv67-K-159-2007.txt"></ref><ref source="BID" url="http://www.securityfocus.com/bid/22877">22877</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0883">ADV-2007-0883</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32877">webo-foldertree-file-include(32877)</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/462294/100/0/threaded">

20070309 [ECHO_ADV_67$2007] WEBO (Web Organizer) &lt;= 1.0 (baseDir) Remote File Inclusion Vulnerability</ref></refs><vuln_soft><prod name="Webo" vendor="Webo"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0" modified="2007-03-15" name="CVE-2007-1392" published="2007-03-10" seq="2007-1392" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in down.php in netForo! 0.1g allows remote attackers to read arbitrary files via a .. (dot dot) in the file_to_download parameter.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3435">3435</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/22875">22875</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0884">ADV-2007-0884</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32878">netforo-down-directory-traversal(32878)</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24449">
24449</ref></refs><vuln_soft><prod name="netForo" vendor="netForo"><vers edition="g" num="0.1"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-03-15" name="CVE-2007-1393" published="2007-03-10" seq="2007-1393" severity="High" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in mysave.php in Magic CMS 4.2.747 allows remote attackers to execute arbitrary PHP code via a URL in the file parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3438">3438</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/22162">22162</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0881">ADV-2007-0881</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24439">
24439</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32883">
magiccms-mysave-file-include(32883)</ref></refs><vuln_soft><prod name="Magic CMS" vendor="Geo Soft"><vers num="4.2.747"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-03-15" name="CVE-2007-1394" published="2007-03-10" seq="2007-1394" severity="High" type="CVE"><desc><descript source="cve">Direct static code injection vulnerability in startsession.php in Flat Chat 2.0 allows remote attackers to execute arbitrary PHP code via the Chat Name field, which is inserted into online.txt and included by users.php.  NOTE: some of these details are obtained from third party information.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3428">3428</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/22865">22865</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0871">ADV-2007-0871</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24433">24433</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32882">
flatchat-startsession-code-execution(32882)</ref></refs><vuln_soft><prod name="Flat Chat" vendor="Flat Chat"><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" modified="2007-03-15" name="CVE-2007-1395" published="2007-03-10" seq="2007-1395" severity="Medium" type="CVE"><desc><descript source="cve">Incomplete blacklist vulnerability in index.php in phpMyAdmin 2.8.0 through 2.9.2 allows remote attackers to conduct cross-site scripting (XSS) attacks by injecting arbitrary JavaScript or HTML in a (1) db or (2) table parameter value followed by an uppercase &lt;/SCRIPT&gt; end tag, which bypasses the protection against lowercase &lt;/script&gt;.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/462139/100/0/threaded">20070307 xss in phpmyadmin &gt;=2.8.0 and &lt; 2.10.0</ref><ref adv="1" source="" url="http://www.virtuax.be/advisories/Advisory2-24012007.txt"></ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32858">phpmyadmin-dbtable-xss(32858)</ref><ref source="DEBIAN" url="http://www.us.debian.org/security/2007/dsa-1370">DSA-1370</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:199">MDKSA-2007:199</ref><ref source="SECUNIA" url="http://secunia.com/advisories/26733">26733</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2402">2402</ref></refs><vuln_soft><prod name="phpMyAdmin" vendor="phpMyAdmin"><vers num="2.8.0"/><vers num="2.8.0.1"/><vers num="2.8.0.2"/><vers num="2.8.0.3"/><vers num="2.8.1"/><vers num="2.8.1 dev"/><vers num="2.8.2"/><vers num="2.8.3"/><vers num="2.8.4"/><vers num="2.9"/><vers num="2.9.0"/><vers num="2.9.0.1"/><vers num="2.9.0.2"/><vers num="2.9.0.3"/><vers num="2.9.0 Beta1"/><vers num="2.9.0 dev"/><vers num="2.9.0 rc1"/><vers num="2.9.1"/><vers num="2.9.1.1"/><vers num="2.9.1 rc1"/><vers num="2.9.1 rc2"/><vers num="2.9.2"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-07-03" name="CVE-2007-1396" published="2007-03-10" seq="2007-1396" severity="Medium" type="CVE"><desc><descript source="cve">The import_request_variables function in PHP 4.0.7 through 4.4.6, and 5.x before 5.2.2, when called without a prefix, does not prevent the (1) GET, (2) POST, (3) COOKIE, (4) FILES, (5) SERVER, (6) SESSION, and other superglobals from being overwritten, which allows remote attackers to spoof source IP address and Referer data, and have other unspecified impact.  NOTE: it could be argued that this is a design limitation of PHP and that only the misuse of this feature, i.e. implementation bugs in applications, should be included in CVE. However, it has been fixed by the vendor.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/462263/100/0/threaded">20070308 PHP import_request_variables() arbitrary variable overwrite</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/462457/100/0/threaded">20070310 Re: [Full-disclosure] PHP import_request_variables() arbitrary variable overwrite</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/462658/100/0/threaded">20070312 Re: [Full-disclosure] PHP import_request_variables() arbitrary variable overwrite</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/462800/100/0/threaded">20070314 Re: Re: [Full-disclosure] PHP import_request_variables() arbitrary variable overwrite</ref><ref source="BID" url="http://www.securityfocus.com/bid/22886">22886</ref><ref source="" url="http://us2.php.net/releases/4_4_7.php"></ref><ref source="" url="http://us2.php.net/releases/5_2_2.php"></ref><ref source="SUSE" url="http://lists.opensuse.org/opensuse-security-announce/2007-07/msg00006.html">SUSE-SA:2007:044</ref><ref source="SECUNIA" url="http://secunia.com/advisories/26048">26048</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2406">2406</ref></refs><vuln_soft><prod name="PHP" vendor="PHP"><vers num="4.0.7"/><vers num="4.1.0"/><vers num="4.1.1"/><vers num="4.1.2"/><vers num="4.2.0"/><vers num="4.2.1"/><vers num="4.2.2"/><vers num="4.2.3"/><vers num="4.3"/><vers num="4.3.1"/><vers num="4.3.10"/><vers num="4.3.11"/><vers num="4.3.2"/><vers num="4.3.3"/><vers num="4.3.4"/><vers num="4.3.5"/><vers num="4.3.6"/><vers num="4.3.7"/><vers num="4.3.8"/><vers num="4.3.9"/><vers num="4.4.0"/><vers num="4.4.1"/><vers num="4.4.2"/><vers num="4.4.3"/><vers num="4.4.4"/><vers num="4.4.5"/><vers num="4.4.6"/><vers num="5.0.0"/><vers num="5.0.1"/><vers num="5.0.2"/><vers num="5.0.3"/><vers num="5.0.4"/><vers num="5.0.5"/><vers num="5.1"/><vers num="5.1.0"/><vers num="5.1.1"/><vers num="5.1.2"/><vers num="5.1.3"/><vers num="5.1.4"/><vers num="5.1.5"/><vers num="5.1.6"/><vers num="5.2.0"/><vers num="5.2.1"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-03-15" name="CVE-2007-1397" published="2007-03-10" seq="2007-1397" severity="High" type="CVE"><desc><descript source="cve">Multiple stack-based buffer overflows in the (1) ExtractRnick and (2) decrypt_topic_332 functions in FiSH allow remote attackers to execute arbitrary code via long strings.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref source="" url="http://blogs.23.nu/ilja/stories/14493/"></ref><ref source="BID" url="http://www.securityfocus.com/bid/22880">22880</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0910">
ADV-2007-0910</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24495">
24495</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32892">
fish-multiple-bo(32892)</ref></refs><vuln_soft><prod name="Fish" vendor="Fish"><vers edition="XChat 0.98" num=""/><vers edition="mIRC 1.29" num=""/><vers edition="irssi 0.99" num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.1" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.9" CVSS_score="7.1" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:C)" CVSS_version="2.0" modified="2007-03-15" name="CVE-2007-1398" published="2007-03-10" seq="2007-1398" severity="High" type="CVE"><desc><descript source="cve">The frag3 preprocessor in Snort 2.6.1.1, 2.6.1.2, and 2.7.0 beta, when configured for inline use on Linux without the ip_conntrack module loaded, allows remote attackers to cause a denial of service (segmentation fault and application crash) via certain UDP packets produced by send_morefrag_packet and send_overlap_packet.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3434">3434</ref><ref source="BID" url="http://www.securityfocus.com/bid/22872">22872</ref><ref source="" url="http://www.snort.org/docs/release_notes/release_notes_2613.txt"></ref><ref source="OSVDB" url="http://www.osvdb.org/33024">
33024</ref></refs><vuln_soft><prod name="Snort" vendor="Snort"><vers num="2.6.1.1"/><vers num="2.6.1.2"/><vers num="2.7 Beta1"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-03-15" name="CVE-2007-1399" published="2007-03-10" seq="2007-1399" severity="High" type="CVE"><desc><descript source="cve">Stack-based buffer overflow in the zip:// URL wrapper in PECL ZIP 1.8.3 and earlier, as bundled with PHP 5.2.0 and 5.2.1, allows remote attackers to execute arbitrary code via a long zip:// URL, as demonstrated by actively triggering URL access from a remote PHP interpreter via avatar upload or blog pingback.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="" url="http://www.php-security.org/MOPB/MOPB-16-2007.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/22883">22883</ref><ref source="SUSE" url="http://lists.suse.com/archive/suse-security-announce/2007-Mar/0003.html">
SUSE-SA:2007:020</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0898">
ADV-2007-0898</ref><ref source="OSVDB" url="http://www.osvdb.org/32782">
32782</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24471">
24471</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24514">
24514</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32889">
pecl-url-wrapper-bo(32889)</ref><ref source="DEBIAN" url="http://www.debian.org/security/2007/dsa-1330">DSA-1330</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25938">25938</ref></refs><vuln_soft><prod name="1.8.3" vendor="PECL Zip"><vers num=""/></prod><prod name="PHP" vendor="PHP"><vers num="5.2.0"/><vers num="5.2.1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.9" CVSS_exploit_subscore="3.4" CVSS_impact_subscore="10.0" CVSS_score="6.9" CVSS_vector="(AV:L/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-03-14" name="CVE-2007-1400" published="2007-03-10" seq="2007-1400" severity="Medium" type="CVE"><desc><descript source="cve">Plash permits sandboxed processes to open /dev/tty, which allows local users to escape sandbox restrictions and execute arbitrary commands by sending characters to a shell process on the same termimal via the TIOCSTI ioctl.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><access/><design/></vuln_types><range><local/></range><refs><ref source="MLIST" url="http://lists.gnu.org/archive/html/plash/2007-03/msg00000.html">[plash] 20070301 TTY ioctl() vulnerability</ref><ref adv="1" patch="1" source="" url="http://plash.beasts.org/wiki/PlashIssues/TtyVulnerability"></ref><ref adv="1" patch="1" source="OSVDB" url="http://www.osvdb.org/32598">32598</ref><ref source="BID" url="http://www.securityfocus.com/bid/22892">
22892</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0909">
ADV-2007-0909</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24498">
24498</ref></refs><vuln_soft><prod name="Plesh" vendor="Plesh"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="6.9" CVSS_exploit_subscore="3.4" CVSS_impact_subscore="10.0" CVSS_score="6.9" CVSS_vector="(AV:L/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-03-14" name="CVE-2007-1401" published="2007-03-10" seq="2007-1401" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in the crack extension (CrackLib), as bundled with PHP 4.4.6 and other versions before 5.0.0, might allow local users to gain privileges via a long argument to the crack_opendict function.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/462226/100/0/threaded">20070308 PHP 4.4.6 crack_opendict() local buffer overflow poc exploit</ref><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3431">3431</ref><ref source="" url="http://retrogod.altervista.org/php_446_crack_opendict_local_bof.html"></ref><ref source="SREASON" url="http://securityreason.com/securityalert/2405">2405</ref></refs><vuln_soft><prod name="PHP" vendor="PHP"><vers num="4.4.6"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-03-14" name="CVE-2007-1402" published="2007-03-10" seq="2007-1402" severity="High" type="CVE"><desc><descript source="cve">The Rediff Toolbar 2.0 ActiveX control in redifftoolbar.dll allows remote attackers to cause a denial of service via unspecified manipulations, possibly involving improper initialization or blank arguments.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref source="" url="http://downloads.securityfocus.com/vulnerabilities/exploits/21924.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/21924">21924</ref></refs><vuln_soft><prod name="Toolbar" vendor="Rediff"><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-03-14" name="CVE-2007-1403" published="2007-03-10" seq="2007-1403" severity="High" type="CVE"><desc><descript source="cve">Multiple stack-based buffer overflows in an ActiveX control in SwDir.dll 10.1.4.20 in Macromedia Shockwave allow remote attackers to cause a denial of service (Internet Explorer 7 crash) and possibly execute arbitrary code via a long (1) BGCOLOR, (2) SRC, (3) AutoStart, (4) Sound, (5) DrawLogo, or (6) DrawProgress property value, different vectors than CVE-2006-6885.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3421">3421</ref><ref source="BID" url="http://www.securityfocus.com/bid/22842">22842</ref></refs><vuln_soft><prod name="Shockwave" vendor="Macromedia"><vers num="10.1.4.20"/></prod></vuln_soft></entry><entry CVSS_base_score="7.3" CVSS_exploit_subscore="5.5" CVSS_impact_subscore="9.2" CVSS_score="7.3" CVSS_vector="(AV:A/AC:M/Au:N/C:C/I:N/A:C)" CVSS_version="2.0" modified="2007-03-14" name="CVE-2007-1404" published="2007-03-10" seq="2007-1404" severity="High" type="CVE"><desc><descript source="cve">tftpd.exe in ProSysInfo TFTP Server TFTPDWIN 0.4.2 allows remote attackers to cause a denial of service via a long UDP packet that is not properly handled in a recv_from call.  NOTE: this issue might be related to CVE-2006-4948.</descript></desc><loss_types><avail/><conf/></loss_types><vuln_types><exception/></vuln_types><range><local_network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3432">3432</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24452">24452</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32886">
tftpdwin-recvfrom-dos(32886)</ref></refs><vuln_soft><prod name="TFTP Server TFTPDWIN" vendor="ProSysInfo"><vers num="0.4.2"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" modified="2007-03-14" name="CVE-2007-1405" published="2007-03-10" seq="2007-1405" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in the &quot;download wiki page as text&quot; feature in Trac before 0.10.3.1, when Microsoft Internet Explorer is used, allows remote attackers to inject arbitrary web script or HTML via unspecified parameters.</descript></desc><loss_types><int/></loss_types><vuln_types><input/><env/></vuln_types><range><network/><user_init/></range><refs><ref patch="1" source="" url="http://trac.edgewall.org/wiki/ChangeLog"></ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24470">24470</ref><ref source="BID" url="http://www.securityfocus.com/bid/22888">
22888</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0900">
ADV-2007-0900</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32897">
trac-downloadwikipageastext-xss(32897)</ref></refs><vuln_soft><prod name="Trac" vendor="Edgewall Software"><vers num="0.10"/><vers num="0.10.1"/><vers num="0.10.2"/><vers num="0.10.3"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-03-14" name="CVE-2007-1406" published="2007-03-10" seq="2007-1406" severity="High" type="CVE"><desc><descript source="cve">Trac before 0.10.3.1 does not send a Content-Disposition HTTP header specifying an attachment in certain &quot;unsafe&quot; situations, which has unknown impact and remote attack vectors.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref source="" url="http://trac.edgewall.org/wiki/ChangeLog"></ref></refs><vuln_soft><prod name="Trac" vendor="Edgewall Software"><vers num="0.10"/><vers num="0.10.1"/><vers num="0.10.2"/><vers num="0.10.3"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-03-13" name="CVE-2007-1407" published="2007-03-10" seq="2007-1407" severity="High" type="CVE"><desc><descript source="cve">Unspecified vulnerability in OpenSolution Quick.Cart before 2.1 has unknown impact and attack vectors, related to a &quot;low critical exploit.&quot;</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><other/></vuln_types><range><network/></range><refs><ref patch="1" source="" url="http://opensolution.org/Quick.Cart/forum/?p=readTopic&amp;nr=3878"></ref><ref source="" url="http://opensolution.org/download/Quick.Cart/changeLog.txt"></ref></refs><vuln_soft><prod name="Quick.Cart" vendor="Open Solution"><vers num="2.0" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-03-13" name="CVE-2007-1408" published="2007-03-10" seq="2007-1408" severity="High" type="CVE"><desc><descript source="cve">Multiple vulnerabilities in (1) bank.php, (2) landfill.php, (3) outposts.php, (4) tribes.php, (5) house.php, (6) tribearmor.php, (7) tribeastral.php, (8) tribeware.php, and (9) includes/head.php in Bartek Jasicki Vallheru before 1.3 beta have unknown impact and remote attack vectors, probably related to large integer values containing more than 15 digits.  NOTE: the original vendor report is for integer overflows, but this is probably an incorrect usage of the term.</descript></desc><impacts><impact source="nvd">This vulnerability is addressed in the following product release:
Vallheru, Vallheru, 1.3 Beta</impact></impacts><loss_types><avail/><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://vallheru.svn.sourceforge.net/viewvc/vallheru/vallheru2/bank.php?r1=910&amp;r2=918"></ref><ref source="" url="http://sourceforge.net/forum/forum.php?forum_id=672237"></ref><ref patch="1" source="" url="http://sourceforge.net/project/shownotes.php?release_id=491871&amp;group_id=118350"></ref></refs><vuln_soft><prod name="Vallheru" vendor="Vallheru"><vers num="1.0.6" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0" modified="2007-03-13" name="CVE-2007-1409" published="2007-03-10" seq="2007-1409" severity="Medium" type="CVE"><desc><descript source="cve">WordPress allows remote attackers to obtain sensitive information via a direct request for wp-admin/admin-functions.php, which reveals the path in an error message.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/462249/100/0/threaded">20070308 Re: Word Press Sensitive Directory exposure (SQL)</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/462230/100/0/threaded">20070308 Word Press Sensitive Directory exposure (SQL)</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200703-23.xml">
GLSA-200703-23</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24566">
24566</ref></refs><vuln_soft><prod name="WordPress" vendor="WordPress"><vers num="2.0"/><vers num="2.0.1"/><vers num="2.0.2"/><vers num="2.0.3"/><vers num="2.0.4"/><vers num="2.0.5"/><vers num="2.0.6"/><vers num="2.0.7"/><vers num="2.1"/><vers num="2.1.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-03-13" name="CVE-2007-1410" published="2007-03-10" seq="2007-1410" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in kategori.asp in GaziYapBoz Game Portal allows remote attackers to execute arbitrary SQL commands via the kategori parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3437">3437</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/22871">22871</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0882">ADV-2007-0882</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32884">
gaziyapboz-kategori-sql-injection(32884)</ref></refs><vuln_soft><prod name="Game Portal" vendor="GaziYapBoz"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-07-03" name="CVE-2007-1411" published="2007-03-10" seq="2007-1411" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in PHP 4.4.6 and earlier, and unspecified PHP 5 versions, allows local and possibly remote attackers to execute arbitrary code via long server name arguments to the (1) mssql_connect and (2) mssql_pconnect functions.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/462010/100/0/threaded">20070306 PHP &lt;= 4.4.6 mssql_connect() &amp; mssql_pconnect() local buffer overflow and safe_mode bypass</ref><ref source="" url="http://retrogod.altervista.org/php_446_mssql_connect_bof.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/22832">22832</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0867">ADV-2007-0867</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24353">24353</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2407">2407</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32885">php-ntwdblib-bo(32885)</ref></refs><vuln_soft><prod name="PHP" vendor="PHP"><vers num="4.4.6" prev="1"/><vers num="5.4.0" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.8" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.9" CVSS_score="7.8" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:N/A:N)" CVSS_version="2.0" modified="2007-03-13" name="CVE-2007-1412" published="2007-03-12" seq="2007-1412" severity="High" type="CVE"><desc><descript source="cve">The cpdf_open function in the ClibPDF (cpdf) extension in PHP 4.4.6 allows context-dependent attackers to obtain sensitive information (script source code) via a long string in the second argument.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3442">3442</ref><ref source="BID" url="http://www.securityfocus.com/bid/22897">22897</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32986">
php-clibpdf-source-disclosure(32986)</ref></refs><vuln_soft><prod name="PHP" vendor="PHP"><vers num="4.4.6"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2008-01-02" name="CVE-2007-1413" published="2007-03-12" seq="2007-1413" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in the snmpget function in the snmp extension in PHP 5.2.3 and earlier, including PHP 4.4.6 and probably other PHP 4 versions, allows context-dependent attackers to execute arbitrary code via a long value in the third argument (object id).</descript></desc><impacts><impact source="nvd">Failed exploit attempts will likely cause a denial of serivce on the webserver.</impact></impacts><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3439">3439</ref><ref source="BID" url="http://www.securityfocus.com/bid/22893">22893</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24440">24440</ref><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/4204">4204</ref><ref source="" url="http://retrogod.altervista.org/php_446_snmpget_local_bof.html"></ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/35517">php-snmpget-function-bo(35517)</ref></refs><vuln_soft><prod name="PHP" vendor="PHP"><vers num="4.4.6"/><vers num="5.2.3" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-03-13" name="CVE-2007-1414" published="2007-03-12" seq="2007-1414" severity="High" type="CVE"><desc><descript source="cve">Multiple PHP remote file inclusion vulnerabilities in Coppermine Photo Gallery (CPG) allow remote attackers to execute arbitrary PHP code via a URL in the (1) cmd parameter to (a) image_processor.php or (b) picmgmt.inc.php, or the (2) path parameter to (c) include/functions.php, (d) include/plugin_api.inc.php, (e) index.php, or (f) pluginmgr.php.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/462322/100/0/threaded">20070309 Remote File Include In Script Coppermine Photo Gallery</ref><ref source="BID" url="http://www.securityfocus.com/bid/22896">22896</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32894">coppermine-multiple-scripts-file-include(32894)</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/463532/100/0/threaded">
20070322 Remote File Include In Coppermine Photo Gallery</ref><ref source="OSVDB" url="http://www.osvdb.org/35065">35065</ref><ref source="OSVDB" url="http://www.osvdb.org/35066">35066</ref><ref source="OSVDB" url="http://www.osvdb.org/35067">35067</ref><ref source="OSVDB" url="http://www.osvdb.org/35068">35068</ref><ref source="OSVDB" url="http://www.osvdb.org/35069">35069</ref><ref source="OSVDB" url="http://www.osvdb.org/35070">35070</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2416">2416</ref></refs><vuln_soft><prod name="Coppermine Photo Gallery" vendor="Coppermine"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-04-10" name="CVE-2007-1415" published="2007-03-12" seq="2007-1415" severity="High" type="CVE"><desc><descript source="cve">Multiple PHP remote file inclusion vulnerabilities in PMB Services 3.0.13 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the (1) class_path parameter to (a) includes/resa_func.inc.php (b) admin/notices/perso.inc.php, or (c) admin/quotas/main.inc.php; the (2) base_path parameter to (d) opac_css/rec_panier.php or (e) opac_css/includes/author_see.inc.php; or the (3) include_path parameter to (f) bull_info.inc.php or (g) misc.inc.php in includes/; (h) options_date_box.php, (i) options_file_box.php, (j) options_list.php, (k) options_query_list.php, or (l) options_text.php in includes/options/; (m) options.php, (n) options_comment.php, (o) options_date_box.php, (p) options_list.php, (q) options_query_list.php, or (r) options_text.php in includes/options_empr/; or (s) admin/import/iimport_expl.php, (t) admin/netbase/clean.php, (u) admin/param/param_func.inc.php, (v) admin/sauvegarde/lieux.inc.php, (w) autorites.php, (x) account.php, (y) cart.php, or (z) edit.php.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3443">3443</ref><ref adv="1" source="" url="http://advisories.echo.or.id/adv/adv68-K-159-2007.txt"></ref><ref source="BID" url="http://www.securityfocus.com/bid/22895">22895</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32890">pmbservices-multiple-scripts-file-include(32890)</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/462452/100/0/threaded">20070310 [ECHO_ADV_68$2007] PMB Services &lt;= 3.0.13 Multiple Remote File Inclusion Vulnerability</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0917">ADV-2007-0917</ref><ref source="OSVDB" url="http://www.osvdb.org/35101">35101</ref><ref source="OSVDB" url="http://www.osvdb.org/35102">35102</ref><ref source="OSVDB" url="http://www.osvdb.org/35103">35103</ref><ref source="OSVDB" url="http://www.osvdb.org/35104">35104</ref><ref source="OSVDB" url="http://www.osvdb.org/35105">35105</ref><ref source="OSVDB" url="http://www.osvdb.org/35106">35106</ref><ref source="OSVDB" url="http://www.osvdb.org/35107">35107</ref><ref source="OSVDB" url="http://www.osvdb.org/35108">35108</ref><ref source="OSVDB" url="http://www.osvdb.org/35109">35109</ref><ref source="OSVDB" url="http://www.osvdb.org/35110">35110</ref><ref source="OSVDB" url="http://www.osvdb.org/35111">35111</ref><ref source="OSVDB" url="http://www.osvdb.org/35112">35112</ref><ref source="OSVDB" url="http://www.osvdb.org/35113">35113</ref><ref source="OSVDB" url="http://www.osvdb.org/35114">35114</ref><ref source="OSVDB" url="http://www.osvdb.org/35115">35115</ref><ref source="OSVDB" url="http://www.osvdb.org/35116">35116</ref><ref source="OSVDB" url="http://www.osvdb.org/35117">35117</ref><ref source="OSVDB" url="http://www.osvdb.org/35118">35118</ref><ref source="OSVDB" url="http://www.osvdb.org/35119">35119</ref><ref source="OSVDB" url="http://www.osvdb.org/35120">35120</ref><ref source="OSVDB" url="http://www.osvdb.org/35121">35121</ref><ref source="OSVDB" url="http://www.osvdb.org/35122">35122</ref><ref source="OSVDB" url="http://www.osvdb.org/35123">35123</ref><ref source="OSVDB" url="http://www.osvdb.org/35124">35124</ref><ref source="OSVDB" url="http://www.osvdb.org/35125">35125</ref></refs><vuln_soft><prod name="PMB Services" vendor="PMB Services"><vers num="3.0.13" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-03-13" name="CVE-2007-1416" published="2007-03-12" seq="2007-1416" severity="High" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in createurl.php in JCcorp (aka James Coyle) URLshrink allows remote attackers to execute arbitrary PHP code via a URL in the formurl parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/462310/100/0/threaded">20070309 Remote File Include In Script copyright (c) James Coyle; JCcorp</ref><ref source="BID" url="http://www.securityfocus.com/bid/22894">22894</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/463523/100/0/threaded">
20070322 Remote File Include In copyright &amp;copy; James Coyle; JCcorp</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0902">
ADV-2007-0902</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24340">
24340</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2415">2415</ref></refs><vuln_soft><prod name="URLshrink" vendor="JCcorp"><vers num="1.3.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-03-13" name="CVE-2007-1417" published="2007-03-12" seq="2007-1417" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in index.php in HC NEWSSYSTEM 1.0-4 allows remote attackers to execute arbitrary SQL commands via the ID parameter in a komm aktion.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/462347/100/0/threaded">20070309 HC NEWSSYSTEM 1.0-4 (index.php </ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/22898">22898</ref><ref source="MILW0RM" url="http://milw0rm.com/exploits/3449">
3449</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0904">
ADV-2007-0904</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24477">
24477</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2414">2414</ref></refs><vuln_soft><prod name="NewsSystem" vendor="HC Design"><vers num="1.0"/><vers num="1.4"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" modified="2007-03-13" name="CVE-2007-1418" published="2007-03-12" seq="2007-1418" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in skins/ace/popup-notopic.php in MindTouch OpenGarden DekiWiki before Gooseberry++ allows remote attackers to inject arbitrary web script or HTML via the message parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref source="" url="http://sourceforge.net/project/shownotes.php?group_id=173074&amp;release_id=492249"></ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/22891">22891</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/24453">24453</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32893">dekiwiki-popupnotopic-xss(32893)</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0899">
ADV-2007-0899</ref></refs><vuln_soft><prod name="DekiWiki" vendor="Mindtouch"><vers num="Gooseberry"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="3.1" CVSS_impact_subscore="6.4" CVSS_score="4.3" CVSS_vector="(AV:L/AC:L/Au:S/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-03-13" name="CVE-2007-1419" published="2007-03-12" seq="2007-1419" severity="Medium" type="CVE"><desc><descript source="cve">The Java Management Extensions Remote API Remote Method Invocation over Internet Inter-ORB Protocol (JMX RMI-IIOP) API in Java Dynamic Management Kit 5.1 before 20070309 does not properly enforce the java.policy, which allows local users to obtain certain MBeans data access by operating a server application accessed by a privileged remote authenticated user.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref patch="1" source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102835-1">102835</ref><ref source="BID" url="http://www.securityfocus.com/bid/22907">
22907</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0906">
ADV-2007-0906</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017745">
1017745</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24497">
24497</ref></refs><vuln_soft><prod name="Java Dynamic Management Kit" vendor="Sun"><vers num="5.1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.9" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.9" CVSS_score="4.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:C)" CVSS_version="2.0" modified="2007-04-10" name="CVE-2007-1420" published="2007-03-12" seq="2007-1420" severity="Medium" type="CVE"><desc><descript source="cve">MySQL 5.x before 5.0.36 allows local users to cause a denial of service (database crash) by performing information_schema table subselects and using ORDER BY to sort a single-row result, which prevents certain structure elements from being initialized and triggers a NULL dereference in the filesort function.</descript></desc><loss_types><avail/></loss_types><vuln_types><input bound="1"/><exception/></vuln_types><range><local/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/462339/100/0/threaded">20070309 SEC Consult SA-20070309-0 :: MySQL 5 Single Row Subselect Denial of Service</ref><ref source="" url="http://www.sec-consult.com/284.html"></ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/22900">22900</ref><ref source="" url="http://dev.mysql.com/doc/refman/5.0/en/releasenotes-es-5-0-36.html"></ref><ref source="" url="http://bugs.mysql.com/bug.php?id=24630"></ref><ref source="UBUNTU" url="http://www.ubuntu.com/usn/usn-440-1">USN-440-1</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0908">ADV-2007-0908</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24483">24483</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24609">24609</ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200705-11.xml">
GLSA-200705-11</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25196">
25196</ref><ref source="" url="https://issues.rpath.com/browse/RPL-1127"></ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:139">MDKSA-2007:139</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017746">1017746</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25389">25389</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25946">25946</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2413">2413</ref></refs><vuln_soft><prod name="MySQL" vendor="MySQL"><vers num="5.0"/><vers num="5.0.27"/><vers num="5.0.33"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-03-13" name="CVE-2007-1421" published="2007-03-12" seq="2007-1421" severity="High" type="CVE"><desc><descript source="cve">Multiple PHP remote file inclusion vulnerabilities in Premod SubDog 2 allow remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter to (1) functions_kb.php, (2) themen_portal_mitte.php, or (3) logger_engine.php in includes/.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/462444/100/0/threaded">20070310 Remote File Include In Script Premod SubDog 2</ref><ref source="BID" url="http://www.securityfocus.com/bid/22912">22912</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2412">2412</ref></refs><vuln_soft><prod name="Premod SubDog" vendor="Premod SubDog"><vers num="2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-03-13" name="CVE-2007-1422" published="2007-03-12" seq="2007-1422" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in goster.asp in fystyq Duyuru Scripti allows remote attackers to execute arbitrary SQL commands via the id parameter, a different vector than CVE-2007-0688.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/462448/100/0/threaded">20070310 Fistiq Duyuru Scripti Remote Sql Injection Exploit</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/22910">22910</ref></refs><vuln_soft><prod name="Duyuru Scripti" vendor="Duyuru Scripti"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" CVSS_score="9.3" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-03-13" name="CVE-2007-1423" published="2007-03-12" seq="2007-1423" severity="High" type="CVE"><desc><descript source="cve">Multiple PHP remote file inclusion vulnerabilities in WORK system e-commerce 3.0.5 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the g_include parameter to include/include_top.php and certain other PHP scripts.</descript></desc><impacts><impact source="nvd">Successful exploitation requires that &quot;register_globals&quot; is enabled.</impact></impacts><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MILW0RM" url="http://milw0rm.com/exploits/3448">3448</ref><ref source="BID" url="http://www.securityfocus.com/bid/22908">22908</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24476">24476</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0903">
ADV-2007-0903</ref></refs><vuln_soft><prod name="WORK system e-commerce" vendor="WORK system e-commerce"><vers num="3.0.3"/><vers num="3.0.4"/><vers num="3.0.41"/><vers num="3.0.5"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-03-13" name="CVE-2007-1424" published="2007-03-12" seq="2007-1424" severity="High" type="CVE"><desc><descript source="cve">Multiple PHP remote file inclusion vulnerabilities in Softnews Media Group DataLife Engine allow remote attackers to execute arbitrary PHP code via a URL in the root_dir parameter to (1) init.php and (2) Ajax/editnews.php.  NOTE: some of these details are obtained from third party information.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/462445/100/0/threaded">20070310 Remote File Include In Script SoftNews Media Group</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/22913">22913</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2411">2411</ref></refs><vuln_soft><prod name="DataLife Engine" vendor="Softnews Media Group"><vers num="4.1"/><vers num="5.5"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-03-13" name="CVE-2007-1425" published="2007-03-12" seq="2007-1425" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in index.php in Triexa SonicMailer Pro 3.2.3 and earlier allows remote attackers to execute arbitrary SQL commands via the list parameter in an archive action.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3457">3457</ref><ref source="BID" url="http://www.securityfocus.com/bid/22920">22920</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24474">24474</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0905">
ADV-2007-0905</ref></refs><vuln_soft><prod name="SonicMailer Pro" vendor="Triexa"><vers num="3.2.3" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.8" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.9" CVSS_score="7.8" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_version="2.0" modified="2008-06-05" name="CVE-2007-1426" published="2007-03-12" seq="2007-1426" severity="High" type="CVE"><desc><descript source="cve">The web interface in AstroCam 2.0.0 through 2.6.5 allows remote attackers to cause a denial of service (daemon shutdown) via requests that contain a large amount of data in the &quot;a&quot; variable, which &quot;fills up the message queue.&quot;</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref source="" url="http://sourceforge.net/project/shownotes.php?group_id=85523&amp;release_id=492572"></ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0901">ADV-2007-0901</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24480">24480</ref><ref source="BID" url="http://www.securityfocus.com/bid/22924">22924</ref><ref source="OSVDB" url="http://www.osvdb.org/32868">32868</ref><ref source="" url="http://astrocam.svn.sourceforge.net/viewvc/astrocam/BUGS?view=markup"></ref></refs><vuln_soft><prod name="AstroCam" vendor="AstroCam"><vers num="2.6.0"/><vers num="2.6.1"/><vers num="2.6.2"/><vers num="2.6.3"/><vers num="2.6.4"/><vers num="2.6.5"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0" modified="2007-03-13" name="CVE-2007-1427" published="2007-03-12" seq="2007-1427" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in download_pdf.php in AssetMan 2.4a and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the pdf_file parameter.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/462577/100/0/threaded">20070311 AssetMan 2.4a &lt;= (download_pdf.php) Remote File Disclosure Vulnerability</ref><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3458">3458</ref><ref source="BID" url="http://www.securityfocus.com/bid/22921">22921</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2410">2410</ref></refs><vuln_soft><prod name="AssetMan" vendor="AssetMan"><vers num="2.4a" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-03-13" name="CVE-2007-1428" published="2007-03-12" seq="2007-1428" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in search.php in PHP Labs JobSitePro 1.0 allows remote attackers to execute arbitrary SQL commands via the salary parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MILW0RM" url="http://milw0rm.com/exploits/3455">3455</ref><ref source="BID" url="http://www.securityfocus.com/bid/22916">22916</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24454">24454</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0918">
ADV-2007-0918</ref></refs><vuln_soft><prod name="JobSitePro" vendor="PHP Labs"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-03-13" name="CVE-2007-1429" published="2007-03-12" seq="2007-1429" severity="High" type="CVE"><desc><descript source="cve">Multiple PHP remote file inclusion vulnerabilities in Moodle 1.7.1 allow remote attackers to execute arbitrary PHP code via a URL in the cmd parameter to (1) admin/utfdbmigrate.php or (2) filter.php.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/462556/100/0/threaded">20070311 Remote File Include In Script moodle-1.7.1</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2007_15_sr.html">SUSE-SR:2007:015</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2409">2409</ref></refs><vuln_soft><prod name="moodle" vendor="Moodle"><vers num="1.7.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-03-13" name="CVE-2007-1430" published="2007-03-12" seq="2007-1430" severity="High" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in include/adodb-connection.inc.php in ClipShare 1.5.3 allows remote attackers to execute arbitrary PHP code via a URL in the cmd parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/462555/100/0/threaded">20070311 Remote File Include In ClipShare.v1.5.3</ref><ref source="BID" url="http://www.securityfocus.com/bid/22928">
22928</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2408">2408</ref></refs><vuln_soft><prod name="ClipShare" vendor="Clip-Share"><vers num="1.5.3"/></prod></vuln_soft></entry><entry CVSS_base_score="7.8" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.9" CVSS_score="7.8" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_version="2.0" modified="2007-03-14" name="CVE-2007-1431" published="2007-03-13" seq="2007-1431" severity="High" type="CVE"><desc><descript source="cve">Multiple unspecified vulnerabilities in PennMUSH 1.8.3 before 1.8.3p1 and 1.8.2 before 1.8.2p3 allow attackers to cause a denial of service (crash) related to the (1) speak and (2) buy functions.</descript></desc><loss_types><avail/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref patch="1" source="MLIST" url="http://www.pennmush.org/archives/pennmush-announce/2007/000137.html">[pennmush-announce] 20070311 PennMUSH 1.8.2p3 and 1.8.3p1 Released</ref><ref source="BID" url="http://www.securityfocus.com/bid/22935">22935</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0921">ADV-2007-0921</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/24504">24504</ref></refs><vuln_soft><prod name="PennMUSH" vendor="PennMUSH"><vers edition="p1" num="1.8.2"/><vers num="1.8.3"/><vers edition="p2" num="1.8.2"/><vers num="1.8.2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-03-13" name="CVE-2007-1432" published="2007-03-13" seq="2007-1432" severity="High" type="CVE"><desc><descript source="cve">Grayscale Blog 0.8.0, and possibly earlier versions, allows remote attackers to gain privileges via direct requests with modified arguments in (1) the user_permissions parameter to add_users.php, and unspecified parameters to (2) addblog.php, (3) editblog.php, (4) editlinks.php, (5) edit_users.php, and (6) add_links.php.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/462441/100/0/threaded">20070310 Grayscale &lt;= 0.8.0 Multiple Vulnerabilities</ref><ref source="BID" url="http://www.securityfocus.com/bid/22911">22911</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0916">ADV-2007-0916</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2417">2417</ref></refs><vuln_soft><prod name="Grayscale Blog" vendor="Grayscale"><vers num="0.8.0" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" modified="2007-03-13" name="CVE-2007-1433" published="2007-03-13" seq="2007-1433" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in Grayscale Blog 0.8.0, and possibly earlier versions, allows remote attackers to inject arbitrary web script or HTML via the comment fields to (1) scripts/addblog_comment.php and (2) detail.php.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/462441/100/0/threaded">20070310 Grayscale &lt;= 0.8.0 Multiple Vulnerabilities</ref><ref source="BID" url="http://www.securityfocus.com/bid/22911">22911</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0916">ADV-2007-0916</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2417">2417</ref></refs><vuln_soft><prod name="Grayscale Blog" vendor="Grayscale"><vers num="0.8.0" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-03-13" name="CVE-2007-1434" published="2007-03-13" seq="2007-1434" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in Grayscale Blog 0.8.0, and possibly earlier versions, might allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to (a) userdetail.php, id and (2) url parameter to (b) jump.php, and id variable to (c) detail.php.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/462441/100/0/threaded">20070310 Grayscale &lt;= 0.8.0 Multiple Vulnerabilities</ref><ref source="BID" url="http://www.securityfocus.com/bid/22911">22911</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0916">ADV-2007-0916</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2417">2417</ref></refs><vuln_soft><prod name="Grayscale Blog" vendor="Grayscale"><vers num="0.8.0" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-03-14" name="CVE-2007-1435" published="2007-03-13" seq="2007-1435" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in D-Link TFTP Server 1.0 allows remote attackers to cause a denial of service (crash) via a long (1) GET or (2) PUT request, which triggers memory corruption.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref source="BID" url="http://www.securityfocus.com/bid/22923">22923</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24360">24360</ref></refs><vuln_soft><prod name="TFTP Server" vendor="D-Link"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-03-14" name="CVE-2007-1436" published="2007-03-13" seq="2007-1436" severity="High" type="CVE"><desc><descript source="cve">Unspecified vulnerability in admin.pl in SQL-Ledger before 2.6.26 and LedgerSMB before 1.1.9 allows remote attackers to bypass authentication via unknown vectors that prevents a password check from occurring.</descript></desc><sols><sol source="nvd">This vulnerability is addressed in the following product updates:
SQL-Ledger, 2.6.26 
LedgerSMB, 1.1.9</sol></sols><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/462375/100/0/threaded">20070309 Security bypass vulnerability in LedgerSMB and SQL-Ledger (fixes released today)</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/22889">22889</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24467">24467</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/24496">24496</ref><ref source="" url="http://sourceforge.net/project/shownotes.php?release_id=494462&amp;group_id=175965"></ref><ref source="OSVDB" url="http://www.osvdb.org/33622">
33622</ref><ref source="OSVDB" url="http://www.osvdb.org/33623">
33623</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2436">2436</ref></refs><vuln_soft><prod name="SQL-Ledger" vendor="SQL-Ledger"><vers num="2.4.10"/><vers num="2.4.11"/><vers num="2.4.12"/><vers num="2.4.13"/><vers num="2.4.14"/><vers num="2.4.15"/><vers num="2.4.16"/><vers num="2.4.4"/><vers num="2.4.5"/><vers num="2.4.6"/><vers num="2.4.7"/><vers num="2.4.8"/><vers num="2.4.9"/><vers num="2.6.0"/><vers num="2.6.1"/><vers num="2.6.10"/><vers num="2.6.11"/><vers num="2.6.12"/><vers num="2.6.13"/><vers num="2.6.14"/><vers num="2.6.15"/><vers num="2.6.16"/><vers num="2.6.17"/><vers num="2.6.18"/><vers num="2.6.19"/><vers num="2.6.2"/><vers num="2.6.21"/><vers num="2.6.25" prev="1"/><vers num="2.6.3"/><vers num="2.6.4"/><vers num="2.6.5"/><vers num="2.6.6"/><vers num="2.6.7"/><vers num="2.6.8"/><vers num="2.6.9"/></prod><prod name="LedgerSMB" vendor="LedgerSMB"><vers num="1.0.0"/><vers num="1.1.0"/><vers num="1.1.1"/><vers num="1.1.5"/><vers num="1.1.8" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="9.0" CVSS_exploit_subscore="8.0" CVSS_impact_subscore="10.0" CVSS_score="9.0" CVSS_vector="(AV:N/AC:L/Au:S/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-03-14" name="CVE-2007-1437" published="2007-03-13" seq="2007-1437" severity="High" type="CVE"><desc><descript source="cve">Unspecified vulnerability in LedgerSMB before 1.1.5 and SQL-Ledger before 2.6.25 allows remote attackers to overwrite files and possibly bypass authentication, and remote authenticated users to execute unauthorized code, by calling a custom error function that returns from execution.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/461944/100/100/threaded">20070305 DoS and code execution issue in LedgerSMB &lt; 1.1.5 and SQL-Ledger &lt; 2.6.25</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24363">24363</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24366">24366</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2435">2435</ref></refs><vuln_soft><prod name="SQL-Ledger" vendor="SQL-Ledger"><vers num="2.6.24" prev="1"/></prod><prod name="LedgerSMB" vendor="LedgerSMB"><vers num="1.0.0"/><vers num="1.1.0"/><vers num="1.1.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-03-14" name="CVE-2007-1438" published="2007-03-13" seq="2007-1438" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in devami.asp in X-Ice News System 1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3469">3469</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/22939">22939</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0941">
ADV-2007-0941</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24502">
24502</ref></refs><vuln_soft><prod name="News System" vendor="X-Ice"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" CVSS_score="9.3" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-03-14" name="CVE-2007-1439" published="2007-03-13" seq="2007-1439" severity="High" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in ressourcen/dbopen.php in bitesser MySQL Commander 2.7 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the home parameter.</descript></desc><impacts><impact source="nvd">Successful exploitation requires that register_globals is enabled.</impact></impacts><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/462685/100/0/threaded">20070313 [ECHO_ADV_73$2007] MySQL Commander &lt;= 2.7 (home) Remote File Inclusion Vulnerability</ref><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3468">3468</ref><ref source="" url="http://advisories.echo.or.id/adv/adv73-K-159-2007.txt"></ref><ref source="BID" url="http://www.securityfocus.com/bid/22941">22941</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0942">
ADV-2007-0942</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24500">
24500</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2423">2423</ref></refs><vuln_soft><prod name="MySQL Commander" vendor="Bitesser"><vers num="2.7" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-03-14" name="CVE-2007-1440" published="2007-03-13" seq="2007-1440" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in search.asp in JGBBS 3.0 Beta 1 allows remote attackers to execute arbitrary SQL commands via the author parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/462699/100/0/threaded">20070313 JGBBS 3.0beta1 Version Search.ASP </ref><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3470">3470</ref><ref source="BID" url="http://www.securityfocus.com/bid/22943">22943</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0940">
ADV-2007-0940</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2431">2431</ref></refs><vuln_soft><prod name="JGBBS" vendor="JGBBS"><vers edition="Beta 1" num="3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0" modified="2008-01-02" name="CVE-2007-1441" published="2007-03-13" seq="2007-1441" severity="Medium" type="CVE"><desc><descript source="cve">The 4thPass browser (BlackBerry Browser) on the RIM BlackBerry 8100 (Pearl) before 4.2.1 allows remote attackers to cause a denial of service (temporary functionality loss) via a long href attribute in a link in a WML page.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/462589/100/0/threaded">20070312 RIM BlackBerry Pearl 8100 Browser DoS</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0945">ADV-2007-0945</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/462701/100/0/threaded">20070313 Re: Re: RIM BlackBerry Pearl 8100 Browser DoS</ref><ref source="" url="http://www.blackberry.com/btsc/articles/923/KB12577_f.SAL_Public.html"></ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/282856">VU#282856</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017748">1017748</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2434">2434</ref></refs><vuln_soft><prod name="Blackberry" vendor="RIM"><vers num="8100"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-03-14" name="CVE-2007-1442" published="2007-03-13" seq="2007-1442" severity="High" type="CVE"><desc><descript source="cve">Oracle Database 10g uses a NULL pDacl parameter when calling the SetSecurityDescriptorDacl function to create discretionary access control lists (DACLs), which allows local users to gain privileges.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref source="" url="http://argeniss.com/research/10MinSecAudit.zip"></ref><ref source="BID" url="http://www.securityfocus.com/bid/22905">22905</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24475">24475</ref></refs><vuln_soft><prod name="Oracle10g Database Server" vendor="Oracle"><vers edition="Standard" num="10.2.2"/><vers edition="Standard" num="10.2.3"/><vers edition="Standard" num="10.2.1"/><vers edition="Personal" num="10.2.2"/><vers edition="Enterprise" num="10.2.2"/><vers edition="Personal" num="10.2.3"/><vers edition="Enterprise" num="10.2.3"/><vers edition="Personal" num="10.2.1"/><vers edition="Enterprise" num="10.2.1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" modified="2007-04-10" name="CVE-2007-1443" published="2007-03-13" seq="2007-1443" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in register.php in Woltlab Burning Board (wBB) 2.3.6 and Burning Board Lite 1.0.2pl3e allow remote attackers to inject arbitrary web script or HTML via the (1) r_username, (2) r_email, (3) r_password, (4) r_confirmpassword, (5) r_homepage, (6) r_icq, (7) r_aim, (8) r_yim, (9) r_msn, (10) r_year, (11) r_month, (12) r_day, (13) r_gender, (14) r_signature, (15) r_usertext, (16) r_invisible, (17) r_usecookies, (18) r_admincanemail, (19) r_emailnotify, (20) r_notificationperpm, (21) r_receivepm, (22) r_emailonpm, (23) r_pmpopup, (24) r_showsignatures, (25) r_showavatars, (26) r_showimages, (27) r_daysprune, (28) r_umaxposts, (29) r_dateformat, (30) r_timeformat, (31) r_startweek, (32) r_timezoneoffset, (33) r_usewysiwyg, (34) r_styleid, (35) r_langid, (36) key_string, (37) key_number, (38) disablesmilies, (39) disablebbcode, (40) disableimages, (41) field[1], (42) field[2], and (43) field[3] parameters.  NOTE: a third-party researcher has disputed some of these vectors, stating that only the r_dateformat and r_timeformat parameters in Burning Board 2.3.6 are affected.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/461744/100/100/threaded">20070302 Re: Woltlab Burning Board (wbb) 2.3.6 CSRF/XSS - 0day</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/461737/100/100/threaded">20070302 Woltlab Burning Board (wbb) 2.3.6 CSRF/XSS - 0day</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0856">ADV-2007-0856</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24386">24386</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24404">24404</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2424">2424</ref></refs><vuln_soft><prod name="Burning Board Lite" vendor="Woltlab"><vers num="1.0.2 pl3e"/></prod><prod name="Burning Board" vendor="Woltlab"><vers num="2.3.6"/></prod></vuln_soft></entry><entry CVSS_base_score="4.4" CVSS_exploit_subscore="3.4" CVSS_impact_subscore="6.4" CVSS_score="4.4" CVSS_vector="(AV:L/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-03-14" name="CVE-2007-1444" published="2007-03-13" seq="2007-1444" severity="Medium" type="CVE"><desc><descript source="cve">netserver in netperf 2.4.3 allows local users to overwrite arbitrary files via a symlink attack on /tmp/netperf.debug.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><race/></vuln_types><range><local/></range><refs><ref source="" url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=413658"></ref><ref source="BID" url="http://www.securityfocus.com/bid/22925">22925</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0912">ADV-2007-0912</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24464">24464</ref></refs><vuln_soft><prod name="Netperf" vendor="Netperf"><vers num="2.4.3"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-03-14" name="CVE-2007-1445" published="2007-03-13" seq="2007-1445" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in the heme preview feature for default.asp in BP Blog 7.0 through 7.0.2 allows remote attackers to execute arbitrary SQL commands via the layout parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MILW0RM" url="http://milw0rm.com/exploits/3466">3466</ref><ref patch="1" source="" url="http://blog.betaparticle.com/template_permalink.asp?id=134"></ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0919">ADV-2007-0919</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/24473">24473</ref></refs><vuln_soft><prod name="betaparticle blog" vendor="betaparticle"><vers num="7.0.2" prev="1"/><vers num="7.0"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-03-14" name="CVE-2007-1446" published="2007-03-13" seq="2007-1446" severity="High" type="CVE"><desc><descript source="cve">Multiple PHP remote file inclusion vulnerabilities in Open Education System (OES) 0.1beta allow remote attackers to execute arbitrary PHP code via a URL in the CONF_INCLUDE_PATH parameter to (1) lib-account.inc.php, (2) lib-file.inc.php, (3) lib-group.inc.php, (4) lib-log.inc.php, (5) lib-mydb.inc.php, (6) lib-template-mod.inc.php, and (7) lib-themes.inc.php in includes/.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/462670/100/0/threaded">20070313 [ECHO_ADV_69$2007] OES (Open Educational System) 0.1beta Remote File Inclusion Vulnerability</ref><ref source="" url="http://advisories.echo.or.id/adv/adv69-K-159-2007.txt"></ref><ref source="BID" url="http://www.securityfocus.com/bid/22934">22934</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0920">ADV-2007-0920</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2421">2421</ref></refs><vuln_soft><prod name="Open Education System" vendor="Open Education System"><vers edition="beta" num="0.1"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-03-20" name="CVE-2007-1447" published="2007-03-16" seq="2007-1447" severity="High" type="CVE"><desc><descript source="cve">The Tape Engine in CA (formerly Computer Associates) BrightStor ARCserve Backup 11.5 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code via certain RPC procedure arguments, which result in memory corruption, a different vulnerability than CVE-2006-6076.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref source="" url="http://supportconnectw.ca.com/public/storage/infodocs/babtapeng-securitynotice.asp"></ref><ref source="" url="http://www3.ca.com/securityadvisor/newsinfo/collateral.aspx?cid=101317"></ref><ref source="OSVDB" url="http://www.osvdb.org/32990">32990</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/375353">
VU#375353</ref><ref source="BID" url="http://www.securityfocus.com/bid/22994">
22994</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0971">
ADV-2007-0971</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017783">
1017783</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24512">
24512</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33017">
brightstor-rpc-tapeengine-code-execution(33017)</ref></refs><vuln_soft><prod name="BrightStor ARCServe Backup" vendor="Computer Associates"><vers num="11.5" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0" modified="2007-03-19" name="CVE-2007-1448" published="2007-03-16" seq="2007-1448" severity="Low" type="CVE"><desc><descript source="cve">The Tape Engine in CA (formerly Computer Associates) BrightStor ARCserve Backup 11.5 and earlier allows remote attackers to cause a denial of service (disabled interface) by calling an unspecified RPC function.</descript></desc><loss_types><avail/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref source="" url="http://supportconnectw.ca.com/public/storage/infodocs/babtapeng-securitynotice.asp"></ref><ref patch="1" source="" url="http://www3.ca.com/securityadvisor/newsinfo/collateral.aspx?cid=101317"></ref><ref source="OSVDB" url="http://www.osvdb.org/32991">32991</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/647273">
VU#647273</ref><ref source="BID" url="http://www.securityfocus.com/bid/22994">
22994</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0971">
ADV-2007-0971</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017783">
1017783</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24512">
24512</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33020">
brightstor-rpc-tapeengine-dos(33020)</ref></refs><vuln_soft><prod name="BrightStor ARCServe Backup" vendor="Computer Associates"><vers num="11.5" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)" CVSS_version="2.0" modified="2007-03-14" name="CVE-2007-1449" published="2007-03-14" seq="2007-1449" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in mainfile.php in PHP-Nuke 8.0 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the lang parameter.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/462443/100/0/threaded">20070310 PHP-Nuke &lt;= 8.0 Cookie Manipulation (lang)</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/462588/100/0/threaded">20070311 Re: PHP-Nuke &lt;= 8.0 Cookie Manipulation (lang)</ref><ref source="BID" url="http://www.securityfocus.com/bid/22909">22909</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24484">24484</ref></refs><vuln_soft><prod name="PHP-Nuke" vendor="PHP-Nuke"><vers num="7.0"/><vers num="7.1"/><vers num="7.2"/><vers num="7.3"/><vers num="7.4"/><vers num="7.5"/><vers num="7.6"/><vers num="7.7"/><vers num="7.8"/><vers num="7.9"/><vers num="8.0"/><vers edition="Final" num="8.0.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-03-14" name="CVE-2007-1450" published="2007-03-14" seq="2007-1450" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in mainfile.php in PHP-Nuke 8.0 and earlier allows remote attackers to execute arbitrary SQL commands in the Top or News module via the lang parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/462443/100/0/threaded">20070310 PHP-Nuke &lt;= 8.0 Cookie Manipulation (lang)</ref><ref source="BID" url="http://www.securityfocus.com/bid/22909">22909</ref></refs><vuln_soft><prod name="PHP-Nuke" vendor="PHP-Nuke"><vers num="7.0"/><vers num="7.1"/><vers num="7.2"/><vers num="7.3"/><vers num="7.4"/><vers num="7.5"/><vers num="7.6"/><vers num="7.7"/><vers num="7.8"/><vers num="7.9"/><vers edition="Final" num="8.0.0"/></prod></vuln_soft></entry><entry CVSS_base_score="6.4" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="4.9" CVSS_score="6.4" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:P)" CVSS_version="2.0" modified="2007-03-14" name="CVE-2007-1451" published="2007-03-14" seq="2007-1451" severity="Medium" type="CVE"><desc><descript source="cve">GuppY 4.0 allows remote attackers to delete arbitrary files via a direct request to install/install.php, then selecting &quot;Installation propre&quot; (cleanup.php) and then &quot;Suppression des fichiers d&apos;installation&quot; (delete.php).</descript></desc><loss_types><avail/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/462584/100/0/threaded">20070311 GuppY v4.0 remote del files/index</ref><ref source="" url="http://forums.avenir-geopolitique.net/viewtopic.php?t=2728"></ref><ref source="SREASON" url="http://securityreason.com/securityalert/2433">2433</ref></refs><vuln_soft><prod name="GuppY" vendor="GuppY"><vers num="4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" modified="2007-03-14" name="CVE-2007-1452" published="2007-03-14" seq="2007-1452" severity="Medium" type="CVE"><desc><descript source="cve">The FDF support (ext/fdf) in PHP 5.2.0 and earlier does not implement the input filtering hooks for ext/filter, which allows remote attackers to bypass web site filters via an application/vnd.fdf formatted POST.</descript></desc><loss_types><int/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref source="" url="http://www.php-security.org/MOPB/MOPB-17-2007.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/22906">22906</ref></refs><vuln_soft><prod name="PHP" vendor="PHP"><vers num="5.0 candidate 1"/><vers num="5.0 candidate 2"/><vers num="5.0 candidate 3"/><vers num="5.0.0"/><vers num="5.0.1"/><vers num="5.0.2"/><vers num="5.0.3"/><vers num="5.0.4"/><vers num="5.0.5"/><vers num="5.1.0"/><vers num="5.1.1"/><vers num="5.1.2"/><vers num="5.1.3"/><vers num="5.1.4"/><vers num="5.1.5"/><vers num="5.1.6"/><vers num="5.2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-03-14" name="CVE-2007-1453" published="2007-03-14" seq="2007-1453" severity="High" type="CVE"><desc><descript source="cve">Buffer underflow in the PHP_FILTER_TRIM_DEFAULT macro in the filtering extension (ext/filter) in PHP 5.2.0 allows context-dependent attackers to execute arbitrary code by calling filter_var with certain modes such as FILTER_VALIDATE_INT, which causes filter to write a null byte in whitespace that precedes the buffer.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref source="" url="http://www.php-security.org/MOPB/MOPB-19-2007.html"></ref><ref source="" url="http://www.php.net/releases/5_2_1.php"></ref><ref source="BID" url="http://www.securityfocus.com/bid/22922">22922</ref><ref source="DEBIAN" url="http://www.debian.org/security/2007/dsa-1283">
DSA-1283</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25062">
25062</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2007_32_php.html">SUSE-SA:2007:032</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25056">25056</ref></refs><vuln_soft><prod name="PHP" vendor="PHP"><vers num="5.2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" modified="2007-03-14" name="CVE-2007-1454" published="2007-03-14" seq="2007-1454" severity="Medium" type="CVE"><desc><descript source="cve">ext/filter in PHP 5.2.0, when FILTER_SANITIZE_STRING is used with the FILTER_FLAG_STRIP_LOW flag, does not properly strip HTML tags, which allows remote attackers to conduct cross-site scripting (XSS) attacks via HTML with a &apos;&lt;&apos; character followed by certain whitespace characters, which passes one filter but is collapsed into a valid tag, as demonstrated using %0b.</descript></desc><loss_types><int/></loss_types><vuln_types><input/><config/></vuln_types><range><network/><user_init/></range><refs><ref source="" url="http://www.php-security.org/MOPB/MOPB-18-2007.html"></ref><ref source="DEBIAN" url="http://www.debian.org/security/2007/dsa-1283">
DSA-1283</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25062">
25062</ref><ref source="BID" url="http://www.securityfocus.com/bid/22914">
22914</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:090">MDKSA-2007:090</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2007_32_php.html">SUSE-SA:2007:032</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25056">25056</ref></refs><vuln_soft><prod name="PHP" vendor="PHP"><vers num="5.2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="9.0" CVSS_exploit_subscore="8.0" CVSS_impact_subscore="10.0" CVSS_score="9.0" CVSS_vector="(AV:N/AC:L/Au:S/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-03-14" name="CVE-2007-1455" published="2007-03-14" seq="2007-1455" severity="High" type="CVE"><desc><descript source="cve">Multiple absolute path traversal vulnerabilities in Fantastico, as used with cPanel 10.x, allow remote authenticated users to include and execute arbitrary local files via (1) the userlanguage parameter to includes/load_language.php or (2) the fantasticopath parameter to includes/mysqlconfig.php and certain other files.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/462562/100/0/threaded">20070311 Fantastico In all Version Cpanel 10.x &lt;= local File Include</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2420">2420</ref></refs><vuln_soft><prod name="Fantastico De Luxe" vendor="cPanel-Host"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-04-10" name="CVE-2007-1456" published="2007-03-14" seq="2007-1456" severity="High" type="CVE"><desc><descript source="cve">** DISPUTED **  PHP remote file inclusion vulnerability in common.php in PHP Photo Album allows remote attackers to execute arbitrary PHP code via a URL in the db_file parameter.  NOTE: CVE disputes this vulnerability, because versions 0.3.2.6 and 0.4.1beta do not contain this file. However, it is possible that the original researcher was referring to a different product.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/462559/100/0/threaded">20070311 Remote File Include In Script PHP Photo Album</ref><ref source="VIM" url="http://www.attrition.org/pipermail/vim/2007-March/001432.html">20070314 [false] Remote File Include In Script PHP Photo Album</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/462802/100/0/threaded">20070314 Re: Remote File Include In Script PHP Photo Album</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2422">2422</ref></refs><vuln_soft><prod name="phpalbum" vendor="phpAlbum.net"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-04-10" name="CVE-2007-1457" published="2007-03-14" seq="2007-1457" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in the urarlib_get function in Christian Scheurer UniquE RAR File Library (unrarlib, aka URARFileLib) 0.4 allows context-dependent attackers to execute arbitrary code via a long (1) filename, (2) rarfile, or (3) libpassword argument.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref source="BID" url="http://www.securityfocus.com/bid/22942">22942</ref><ref source="FULLDISC" url="http://marc.info/?l=full-disclosure&amp;m=117392197607422&amp;w=2">20070313 Unrarlib 0.4.0 (urarlib_get) Local buffer overflow</ref><ref source="" url="http://unrarlib.svn.sourceforge.net/viewvc/unrarlib/tags/unrarlib040/unrarlib/unrarlib.c?revision=3&amp;view=markup"></ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0961">ADV-2007-0961</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24472">24472</ref></refs><vuln_soft><prod name="unrarlib" vendor="Christian Scheurer"><vers num="0.4"/></prod><prod name="URARFileLib" vendor="Christian Scheurer"><vers num="0.4"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-07-03" name="CVE-2007-1458" published="2007-03-14" seq="2007-1458" severity="Medium" type="CVE"><desc><descript source="cve">Multiple PHP remote file inclusion vulnerabilities in CARE2X 1.1 allow remote attackers to execute arbitrary PHP code via a URL in the root_path parameter to (1) inc_checkdate_lang.php, (2) inc_charset_fx.php, (3) inc_config_color.php, (4) inc_currency_set.php, (5) inc_db_makelink.php, (6) inc_diagnostics_report_fx.php, (7) inc_environment_global.php, (8) inc_front_chain_lang.php, (9) inc_init_crypt.php, (10) inc_load_copyrite.php, or (11) inc_news_save.php in include/; (12) diagnostics-report-index.php, (13) config_options_mascot.php, (14) barcode-labels.php, (15) chg-color.php, or (16) config_options_gui_template.php in main/; or unspecified other files.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://advisories.echo.or.id/adv/adv72-theday-2007.txt"></ref><ref source="BID" url="http://www.securityfocus.com/bid/22951">22951</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/462808/100/0/threaded">20070314 [ECHO_ADV_72$2007] CARE2X (root_path) Remote File Inclusion Vulnerability</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0938">ADV-2007-0938</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24481">24481</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32981">care2x-rootpath-file-include(32981)</ref><ref source="OSVDB" url="http://www.osvdb.org/34045">34045</ref><ref source="OSVDB" url="http://www.osvdb.org/34046">34046</ref><ref source="OSVDB" url="http://www.osvdb.org/34047">34047</ref><ref source="OSVDB" url="http://www.osvdb.org/34048">34048</ref><ref source="OSVDB" url="http://www.osvdb.org/34049">34049</ref><ref source="OSVDB" url="http://www.osvdb.org/34056">34056</ref><ref source="OSVDB" url="http://www.osvdb.org/34057">34057</ref><ref source="OSVDB" url="http://www.osvdb.org/34058">34058</ref><ref source="OSVDB" url="http://www.osvdb.org/34059">34059</ref><ref source="OSVDB" url="http://www.osvdb.org/34060">34060</ref><ref source="OSVDB" url="http://www.osvdb.org/34050">34050</ref><ref source="OSVDB" url="http://www.osvdb.org/34051">34051</ref><ref source="OSVDB" url="http://www.osvdb.org/34052">34052</ref><ref source="OSVDB" url="http://www.osvdb.org/34053">34053</ref><ref source="OSVDB" url="http://www.osvdb.org/34054">34054</ref><ref source="OSVDB" url="http://www.osvdb.org/34055">34055</ref></refs><vuln_soft><prod name="CARE2X" vendor="CARE2X"><vers num="1.1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-07-03" name="CVE-2007-1459" published="2007-03-14" seq="2007-1459" severity="Medium" type="CVE"><desc><descript source="cve">Multiple PHP remote file inclusion vulnerabilities in WebCreator 0.2.6-rc3 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the moddir parameter to (1) content/load.inc.php, (2) config/load.inc.php, (3) http/load.inc.php, and unspecified other files.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://advisories.echo.or.id/adv/adv74-theday-2007.txt"></ref><ref source="BID" url="http://www.securityfocus.com/bid/22953">22953</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/462809/100/0/threaded">20070314 [ECHO_ADV_74$2007] WebCreator &lt;= 0.2.6-rc3 (moddir) Remote File Inclusion Vulnerability</ref><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3473">3473</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0937">ADV-2007-0937</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32972">webcreator-loadinc-file-include(32972)</ref></refs><vuln_soft><prod name="WebCreator" vendor="WebCreator"><vers num="0.2.5"/><vers num="0.2.6 RC3"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0" modified="2007-08-02" name="CVE-2007-1460" published="2007-03-14" seq="2007-1460" severity="Medium" type="CVE"><desc><descript source="cve">The zip:// URL wrapper provided by the PECL zip extension in PHP before 4.4.7, and 5.2.0 and 5.2.1, does not implement safemode or open_basedir checks, which allows remote attackers to read ZIP archives located outside of the intended directories.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref source="" url="http://www.php-security.org/MOPB/MOPB-20-2007.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/22954">22954</ref><ref source="" url="http://us2.php.net/releases/4_4_7.php"></ref><ref source="" url="http://us2.php.net/releases/5_2_2.php"></ref><ref source="" url="http://docs.info.apple.com/article.html?artnum=306172"></ref><ref source="APPLE" url="http://lists.apple.com/archives/security-announce//2007/Jul/msg00004.html">APPLE-SA-2007-07-31</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2007_32_php.html">SUSE-SA:2007:032</ref><ref source="BID" url="http://www.securityfocus.com/bid/25159">25159</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/2732">ADV-2007-2732</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25056">25056</ref><ref source="SECUNIA" url="http://secunia.com/advisories/26235">26235</ref></refs><vuln_soft><prod name="PHP" vendor="PHP"><vers num="5.2.0"/><vers num="5.2.1"/><vers num="4.4.6" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.8" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.9" CVSS_score="7.8" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:N/A:N)" CVSS_version="2.0" modified="2007-08-02" name="CVE-2007-1461" published="2007-03-14" seq="2007-1461" severity="High" type="CVE"><desc><descript source="cve">The compress.bzip2:// URL wrapper provided by the bz2 extension in PHP before 4.4.7, and 5.x before 5.2.2, does not implement safemode or open_basedir checks, which allows remote attackers to read bzip2 archives located outside of the intended directories.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref source="" url="http://www.php-security.org/MOPB/MOPB-21-2007.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/22954">22954</ref><ref source="" url="http://us2.php.net/releases/4_4_7.php"></ref><ref source="" url="http://us2.php.net/releases/5_2_2.php"></ref><ref source="" url="http://docs.info.apple.com/article.html?artnum=306172"></ref><ref source="APPLE" url="http://lists.apple.com/archives/security-announce//2007/Jul/msg00004.html">APPLE-SA-2007-07-31</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2007_32_php.html">SUSE-SA:2007:032</ref><ref source="BID" url="http://www.securityfocus.com/bid/25159">25159</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/2732">ADV-2007-2732</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25056">25056</ref><ref source="SECUNIA" url="http://secunia.com/advisories/26235">26235</ref></refs><vuln_soft><prod name="PHP" vendor="PHP"><vers num="5.0.0"/><vers num="5.0.1"/><vers num="5.0.2"/><vers num="5.0.3"/><vers num="5.0.4"/><vers num="5.0.5"/><vers num="5.1.0"/><vers num="5.1.1"/><vers num="5.1.2"/><vers num="5.1.3"/><vers num="5.1.4"/><vers num="5.1.5"/><vers num="5.1.6"/><vers num="5.2.0"/><vers num="5.2.1"/><vers num="4.4.6" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)" CVSS_version="2.0" modified="2007-03-18" name="CVE-2007-1462" published="2007-03-15" seq="2007-1462" severity="Medium" type="CVE"><desc><descript source="cve">The luci server component in conga preserves the password between page loads for the Add System/Cluster task flow by storing the password in the Value attribute of a password entry field, which allows attackers to steal the password by performing a &quot;view source&quot; or other operation to obtain the web page.  NOTE: there are limited circumstances under which such an attack is feasible.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="" url="https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=228637"></ref></refs><vuln_soft><prod name="Conga" vendor="Linux"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-07-13" name="CVE-2007-1463" published="2007-03-21" seq="2007-1463" severity="Medium" type="CVE"><desc><descript source="cve">Format string vulnerability in Inkscape before 0.45.1 allows user-assisted remote attackers to execute arbitrary code via format string specifiers in a URI, which is not properly handled by certain dialogs.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/><exception/></vuln_types><range><network/><user_init/></range><refs><ref source="BID" url="http://www.securityfocus.com/bid/23070">23070</ref><ref patch="1" source="" url="http://sourceforge.net/project/shownotes.php?group_id=93438&amp;release_id=495106"></ref><ref adv="1" source="UBUNTU" url="http://www.ubuntu.com/usn/usn-438-1">USN-438-1</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/463710/100/0/threaded">20070324 FLEA-2007-0002-1: inkscape</ref><ref source="" url="https://issues.rpath.com/browse/RPL-1170"></ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2007:069">MDKSA-2007:069</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1059">ADV-2007-1059</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24597">24597</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24615">24615</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24584">24584</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24661">24661</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33163">inkscape-dialogs-format-string(33163)</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200704-10.xml">GLSA-200704-10</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24859">24859</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2007_8_sr.html">SUSE-SR:2007:008</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25072">25072</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:069">MDKSA-2007:069</ref><ref source="BID" url="http://www.securityfocus.com/bid/23138">23138</ref></refs><vuln_soft><prod name="inkscape" vendor="inkscape"><vers num="0.40"/><vers num="0.41"/><vers num="0.42"/><vers num="0.42.1"/><vers num="0.42.2"/><vers num="0.43"/><vers num="0.44"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-03-22" name="CVE-2007-1464" published="2007-03-21" seq="2007-1464" severity="Medium" type="CVE"><desc><descript source="cve">Format string vulnerability in the whiteboard Jabber protocol in Inkscape before 0.45.1 allows user-assisted remote attackers to execute arbitrary code via unspecified vectors.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref source="" url="http://sourceforge.net/project/shownotes.php?group_id=93438&amp;release_id=495106"></ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/463710/100/0/threaded">

20070324 FLEA-2007-0002-1: inkscape</ref><ref source="" url="https://issues.rpath.com/browse/RPL-1170"></ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1059">
ADV-2007-1059</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24615">
24615</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24661">
24661</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33164">
inkscape-jabber-format-string(33164)</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200704-10.xml">
GLSA-200704-10</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24859">
24859</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2007_8_sr.html">
SUSE-SR:2007:008</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25072">
25072</ref><ref source="BID" url="http://www.securityfocus.com/bid/23138">23138</ref></refs><vuln_soft><prod name="inkscape" vendor="inkscape"><vers num="0.45" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-03-26" name="CVE-2007-1465" published="2007-03-24" seq="2007-1465" severity="High" type="CVE"><desc><descript source="cve">Stack-based buffer overflow in dproxy.c for dproxy 0.1 through 0.5 allows remote attackers to execute arbitrary code via a long DNS query packet to UDP port 53.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="FULLDISC" url="http://seclists.org/fulldisclosure/2007/Mar/0409.html">20070323 dproxy - arbitrary code execution through stack buffer overflow vulnerability</ref><ref adv="1" source="" url="https://www.cynops.de/advisories/CVE-2007-1465.txt"></ref><ref source="BID" url="http://www.securityfocus.com/bid/23112">
23112</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1091">
ADV-2007-1091</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24623">
24623</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33171">
dproxy-udp-packet-bo(33171)</ref></refs><vuln_soft><prod name="dproxy" vendor="dproxy"><vers num="0.1"/><vers num="0.2"/><vers num="0.3"/><vers num="0.4"/><vers num="0.5"/></prod></vuln_soft></entry><entry CVSS_base_score="6.0" CVSS_exploit_subscore="6.8" CVSS_impact_subscore="6.4" CVSS_score="6.0" CVSS_vector="(AV:N/AC:M/Au:S/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-03-19" name="CVE-2007-1466" published="2007-03-16" seq="2007-1466" severity="Medium" type="CVE"><desc><descript source="cve">Integer overflow in the the WP6GeneralTextPacket::_readContents function in WordPerfect Document importer/exporter (libwpd) before 0.8.9 allows user-assisted remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted WordPerfect file, a different vulnerability than CVE-2007-0002.</descript></desc><sols><sol source="nvd">This vulnerability has been address by the vendor through a product update: http://sourceforge.net/project/showfiles.php?group_id=62662 </sol></sols><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/><user_init/></range><refs><ref source="" url="http://sourceforge.net/project/shownotes.php?release_id=494122"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0976">ADV-2007-0976</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24507">24507</ref><ref source="IDEFENSE" url="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=490">

20070316 Multiple Vendor libwpd Multiple Buffer Overflow Vulnerabilities</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/463033/100/0/threaded">
20070316 rPSA-2007-0057-1 libwpd</ref><ref source="DEBIAN" url="http://www.debian.org/security/2007/dsa-1268">
DSA-1268</ref><ref source="FEDORA" url="http://fedoranews.org/cms/node/2805">
FEDORA-2007-350</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2007:063">
MDKSA-2007:063</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2007:064">
MDKSA-2007:064</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2007-0055.html">
RHSA-2007:0055</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2007-0033.html">
RHSA-2007:0033</ref><ref source="UBUNTU" url="http://www.ubuntu.com/usn/usn-437-1">
USN-437-1</ref><ref source="BID" url="http://www.securityfocus.com/bid/23006">
23006</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017789">
1017789</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24557">
24557</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24572">
24572</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24580">
24580</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24573">
24573</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24581">
24581</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24550">
24550</ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200704-07.xml">
GLSA-200704-07</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24794">
24794</ref><ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102863-1">
102863</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24856">
24856</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:063">MDKSA-2007:063</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:064">MDKSA-2007:064</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24588">24588</ref></refs><vuln_soft><prod name="WordPerfect Document Importer-Exporter" vendor="SourceForge"><vers num="0.8.8" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="3.5" CVSS_exploit_subscore="6.8" CVSS_impact_subscore="2.9" CVSS_score="3.5" CVSS_vector="(AV:N/AC:M/Au:S/C:N/I:P/A:N)" CVSS_version="2.0" modified="2007-03-22" name="CVE-2007-1467" published="2007-03-16" seq="2007-1467" severity="Low" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in (1) PreSearch.html and (2) PreSearch.class in Cisco Secure Access Control Server (ACS), VPN Client, Unified Personal Communicator, MeetingPlace, Unified MeetingPlace, Unified MeetingPlace Express, CallManager, IP Communicator, Unified Video Advantage, Unified Videoconferencing 35xx products, Unified Videoconferencing Manager, WAN Manager, Security Device Manager, Network Analysis Module (NAM), CiscoWorks and related products, Wireless LAN Solution Engine (WLSE), 2006 Wireless LAN Controllers (WLC), and Wireless Control System (WCS) allow remote attackers to inject arbitrary web script or HTML via the text field of the search form.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/462944/100/0/threaded">20070315 Re: XSS vulnerability in the online help system of several Cisco products</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/462932/100/0/threaded">20070315 XSS vulnerability in the online help system of several Cisco products</ref><ref adv="1" source="CISCO" url="http://www.cisco.com/en/US/products/products_security_response09186a0080803fe4.html">20070315 Cross-Site Scripting Vulnerability in Online Help System</ref><ref source="BID" url="http://www.securityfocus.com/bid/22982">22982</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0973">
ADV-2007-0973</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33024">
cisco-presearch-xss(33024)</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017778">1017778</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24499">24499</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2437">2437</ref></refs><vuln_soft><prod name="Security Device Manager" vendor="Cisco"><vers num=""/></prod><prod name="Unified MeetingPlace" vendor="Cisco"><vers num=""/></prod><prod name="Wireless Control System" vendor="Cisco"><vers num=""/></prod><prod name="WAN Manager" vendor="Cisco"><vers num=""/></prod><prod name="Unified Videoconferencing" vendor="Cisco"><vers num=""/></prod><prod name="Unified Personal Communicator" vendor="Cisco"><vers num=""/></prod><prod name="2006 Wireless LAN Controllers" vendor="Cisco"><vers num=""/></prod><prod name="Network Analysis Module" vendor="Cisco"><vers num=""/></prod><prod name="Unified Video Advantage" vendor="Cisco"><vers num=""/></prod><prod name="VPN Client" vendor="Cisco"><vers edition="Windows" num="4.8.1"/><vers edition="Solaris" num="3.5.1"/><vers edition="Solaris" num="3.5.2"/><vers edition="Solaris" num="3.5.2b"/><vers edition="Solaris" num="3.5.4"/><vers edition="Solaris" num="3.6"/><vers edition="Solaris" num="3.6.1"/><vers edition="Solaris" num="4.0.2a"/><vers edition="Solaris" num="4.0.2c"/><vers edition="Linux" num="3.5.1"/><vers edition="Mac OS X" num="3.5.2"/><vers edition="Mac OS X" num="3.5.2b"/><vers edition="Mac OS X" num="3.5.4"/><vers edition="Mac OS X" num="3.6"/><vers edition="Mac OS X" num="3.6.1"/><vers edition="Mac OS X" num="4.0.2a"/><vers edition="Mac OS X" num="4.0.2c"/><vers edition="Linux" num="3.5.2"/><vers edition="Linux" num="3.5.2b"/><vers edition="Linux" num="3.5.4"/><vers edition="Linux" num="3.6"/><vers edition="Linux" num="3.6.1"/></prod><prod name="CiscoWorks" vendor="Cisco"><vers num=""/></prod><prod name="ACS Solution Engine" vendor="Cisco"><vers edition="Windows" num="4.1"/><vers num="4.1"/></prod><prod name="Unified MeetingPlace Express" vendor="Cisco"><vers num=""/></prod><prod name="IP Communicator" vendor="Cisco"><vers num=""/></prod><prod name="MeetingPlace" vendor="Cisco"><vers num=""/></prod><prod name="Wireless LAN Solution Engine" vendor="Cisco"><vers num=""/></prod><prod name="Call Manager" vendor="Cisco"><vers num=""/></prod><prod name="Unified Videoconferencing Manager" vendor="Cisco"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-03-19" name="CVE-2007-1468" published="2007-03-16" seq="2007-1468" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in IBM Rational ClearQuest (CQ) Web 7.0.0.0 allows remote attackers to inject arbitrary web script or HTML via an attachment to a defect log entry.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/462919/100/0/threaded">20070315 IBM Rational ClearQuest Web - Cross Site Scripting</ref><ref source="BID" url="http://www.securityfocus.com/bid/22981">22981</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1036">
ADV-2007-1036</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017786">
1017786</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24523">
24523</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33001">
clearquest-defecttracking-xss(33001)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2442">2442</ref></refs><vuln_soft><prod name="Rational ClearQuest" vendor="IBM"><vers num="7.0.0.0"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-03-19" name="CVE-2007-1469" published="2007-03-16" seq="2007-1469" severity="Medium" type="CVE"><desc><descript source="cve">SQL injection vulnerability in gallery.asp in Absolute Image Gallery 2.0 allows remote attackers to execute arbitrary SQL commands via the categoryid parameter in a viewimage action.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/462971/100/0/threaded">20070315 Absolute Image Gallery Gallery.ASP (categoryid) MSSQL Injection Exploit</ref><ref source="BID" url="http://www.securityfocus.com/bid/22988">22988</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1002">
ADV-2007-1002</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24543">
24543</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33005">
absolute-gallery-sql-injection(33005)</ref><ref source="OSVDB" url="http://www.osvdb.org/34239">
34239</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2429">2429</ref></refs><vuln_soft><prod name="Absolute Image Gallery XE" vendor="XIGLA"><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" CVSS_score="9.3" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-03-19" name="CVE-2007-1470" published="2007-03-16" seq="2007-1470" severity="High" type="CVE"><desc><descript source="cve">Multiple buffer overflows in LIBFtp 5.0 allow user-assisted remote attackers to execute arbitrary code via certain long arguments to the (1) FtpArchie, (2) FtpDebugDebug, (3) FtpOpenDir, (4) FtpSize, or (5) FtpChmod function.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/462954/100/0/threaded">20070315 LIBFtp 5.0 (sprintf(), strcpy()) Multiple local buffer overflow</ref><ref source="BID" url="http://www.securityfocus.com/bid/22987">22987</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2441">2441</ref></refs><vuln_soft><prod name="LIBftp" vendor="NetSW"><vers num="5.0" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-03-19" name="CVE-2007-1471" published="2007-03-16" seq="2007-1471" severity="High" type="CVE"><desc><descript source="cve">admin/default.asp in Orion-Blog 2.0 allows remote attackers to bypass authentication controls and gain privileges via a direct URL request for admin/AdminBlogNewsEdit.asp.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/462920/100/0/threaded">20070315 Orion-Blog v2.0 Version Remote Privilege Escalation Exploit</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2440">2440</ref></refs><vuln_soft><prod name="Orion-Blog" vendor="Orion-Blog"><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" CVSS_score="9.3" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-03-19" name="CVE-2007-1472" published="2007-03-16" seq="2007-1472" severity="High" type="CVE"><desc><descript source="cve">Variable overwrite vulnerability in groupit/base/groupit.start.inc in Groupit 2.00b5 allows remote attackers to conduct remote file inclusion attacks and execute arbitrary PHP code via arguments that are written to $_GLOBALS, as demonstrated using a URL in the c_basepath parameter to (1) content.php, (2) userprofile.php, (3) password.php, (4) dispatch.php, and (5) deliver.php in html/, and possibly (6) load.inc.php and related files.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/462918/100/0/threaded">20070315 [ECHO_ADV_75$2007] Groupit 2.00b5 (c_basepath) Remote File Inclusion Vulnerability</ref><ref source="" url="http://advisories.echo.or.id/adv/adv75-theday-2007.txt"></ref><ref source="VIM" url="http://www.attrition.org/pipermail/vim/2007-March/001435.html">20070315 [ECHO_ADV_75$2007] Groupit 2.00b5 (c_basepath) Remote File Inclusion Vulnerability</ref><ref source="VIM" url="http://www.attrition.org/pipermail/vim/2007-March/001436.html">20070315 [ECHO_ADV_75$2007] Groupit 2.00b5 (c_basepath) Remote File Inclusion Vulnerability</ref><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3486">
3486</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0995">
ADV-2007-0995</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33000">
groupit-cbasepath-file-include(33000)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2428">2428</ref></refs><vuln_soft><prod name="GroupIT" vendor="T-Systems Solutions for Research GmbH"><vers num="2.00b5"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" modified="2007-03-19" name="CVE-2007-1473" published="2007-03-16" seq="2007-1473" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in framework/NLS/NLS.php in Horde Framework before 3.1.4 RC1, when the login page contains a language selection box, allows remote attackers to inject arbitrary web script or HTML via the new_lang parameter to login.php.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/462915/100/0/threaded">20070315 Horde 3.1.4 (RC1) fixes XSS issue</ref><ref adv="1" patch="1" source="MLIST" url="http://lists.horde.org/archives/announce/2007/000315.html">[announce] 20070314 Horde 3.1.4 (final)</ref><ref source="BID" url="http://www.securityfocus.com/bid/22984">22984</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1017775">1017775</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0965">
ADV-2007-0965</ref><ref source="OSVDB" url="http://www.osvdb.org/33084">
33084</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24528">
24528</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33013">
horde-login-xss(33013)</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2007_007_suse.html">
SUSE-SR:2007:007</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24995">
24995</ref><ref source="DEBIAN" url="http://www.debian.org/security/2007/dsa-1406">DSA-1406</ref><ref source="SECUNIA" url="http://secunia.com/advisories/27565">27565</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2427">2427</ref></refs><vuln_soft><prod name="Horde Application Framework" vendor="Horde"><vers num="1.2.0"/><vers num="1.2.1"/><vers num="1.2.2"/><vers num="1.2.3"/><vers num="1.2.4"/><vers num="1.2.5"/><vers num="1.2.6"/><vers num="1.2.7"/><vers num="1.2.8"/><vers num="1.3.3"/><vers num="1.3.4"/><vers num="2.0"/><vers num="2.1"/><vers num="2.2"/><vers num="2.2.1"/><vers num="2.2.3"/><vers num="2.2.4"/><vers num="2.2.5"/><vers num="2.2.6"/><vers num="2.2.7"/><vers num="2.2.8"/><vers num="2.2.9"/><vers num="3.0.0"/><vers num="3.0.1"/><vers num="3.0.10"/><vers num="3.0.2"/><vers num="3.0.3"/><vers num="3.0.4"/><vers num="3.0.5"/><vers num="3.0.6"/><vers num="3.0.7"/><vers num="3.0.7"/><vers num="3.0.8"/><vers num="3.0.8"/><vers num="3.0.9"/><vers num="3.0.9"/><vers num="3.1.0"/><vers num="3.1.0"/><vers num="3.1.1"/><vers num="3.1.1"/><vers num="3.1.2"/><vers num="3.1.2"/><vers num="3.1.3"/><vers num="3.1.3"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-03-19" name="CVE-2007-1474" published="2007-03-16" seq="2007-1474" severity="Medium" type="CVE"><desc><descript source="cve">Argument injection vulnerability in the cleanup cron script in Horde Project Horde and IMP before Horde Application Framework 3.1.4 allows local users to delete arbitrary files and possibly gain privileges via multiple space-delimited pathnames.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="IDEFENSE" url="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=489">20070315 Horde Project Cleanup Script Arbitrary File Deletion Vulnerability</ref><ref adv="1" patch="1" source="MLIST" url="http://lists.horde.org/archives/announce/2007/000315.html">[announce] 20070314 Horde 3.1.4 (final)</ref><ref source="BID" url="http://www.securityfocus.com/bid/22985">22985</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0965">
ADV-2007-0965</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017784">
1017784</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017785">
1017785</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32997">
horde-cron-file-deletion(32997)</ref><ref source="DEBIAN" url="http://www.debian.org/security/2007/dsa-1406">DSA-1406</ref><ref source="SECUNIA" url="http://secunia.com/advisories/27565">27565</ref></refs><vuln_soft><prod name="IMP" vendor="Horde"><vers num="2.0"/><vers num="2.2"/><vers num="2.2.1"/><vers num="2.2.2"/><vers num="2.2.3"/><vers num="2.2.4"/><vers num="2.2.5"/><vers num="2.2.6"/><vers num="2.2.7"/><vers num="2.2.8"/><vers num="2.3"/><vers num="3.0"/><vers num="3.1"/><vers num="3.1.2"/><vers num="3.2"/><vers num="3.2.1"/><vers num="3.2.2"/><vers num="3.2.3"/><vers num="3.2.4"/><vers num="3.2.5"/><vers num="3.2.6"/></prod><prod name="Horde Application Framework" vendor="Horde"><vers num="3.0.0"/><vers num="3.0.4"/><vers num="3.1.3"/></prod></vuln_soft></entry><entry CVSS_base_score="5.4" CVSS_exploit_subscore="5.5" CVSS_impact_subscore="6.4" CVSS_score="5.4" CVSS_vector="(AV:A/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-04-23" name="CVE-2007-1475" published="2007-03-16" seq="2007-1475" severity="Medium" type="CVE"><desc><descript source="cve">Multiple buffer overflows in the (1) ibase_connect and (2) ibase_pconnect functions in the interbase extension in PHP 4.4.6 and earlier allow context-dependent attackers to execute arbitrary code via a long argument.</descript></desc><impacts><impact source="nvd">Successful exploitation requires that the Interbase extension is installed.</impact></impacts><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local_network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/462931/100/0/threaded">20070315 PHP &lt;= 4.4.6 ibase_connect() local buffer overflow</ref><ref source="" url="http://retrogod.altervista.org/php_446_ibase_connect_bof.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/22976">22976</ref><ref source="MILW0RM" url="http://milw0rm.com/exploits/3488">3488</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24529">24529</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33019">php-interbase-extension-bo(33019)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2439">2439</ref></refs><vuln_soft><prod name="PHP" vendor="PHP"><vers num="3.0.6" prev="1"/><vers num="3.0.7" prev="1"/><vers num="3.0.8" prev="1"/><vers num="3.0.9" prev="1"/><vers num="3.0" prev="1"/><vers num="4.0" prev="1"/><vers num="4.0 Beta 1" prev="1"/><vers num="4.0 Beta 2" prev="1"/><vers num="4.0 Beta 3" prev="1"/><vers num="4.0 Beta 4" prev="1"/><vers num="4.0 Beta 4 Patch Level 1" prev="1"/><vers num="4.0 RC1" prev="1"/><vers num="4.0 RC2" prev="1"/><vers num="4.0.0" prev="1"/><vers num="4.0.1" prev="1"/><vers num="4.0.1 pl1" prev="1"/><vers num="4.0.1 pl2" prev="1"/><vers num="4.0.2" prev="1"/><vers num="4.0.3" prev="1"/><vers num="4.0.3 pl1" prev="1"/><vers num="4.0.4" prev="1"/><vers num="4.0.4 pl1" prev="1"/><vers num="4.0.5" prev="1"/><vers num="4.0.6" prev="1"/><vers num="4.0.7" prev="1"/><vers num="4.0.7 RC1" prev="1"/><vers num="4.0.7 RC2" prev="1"/><vers num="4.0.7 RC3" prev="1"/><vers num="4.1.0" prev="1"/><vers num="4.1.1" prev="1"/><vers num="4.1.2" prev="1"/><vers edition="Dev" num="4.2" prev="1"/><vers num="4.2.0" prev="1"/><vers num="4.2.1" prev="1"/><vers num="4.2.2" prev="1"/><vers num="4.2.3" prev="1"/><vers num="4.3" prev="1"/><vers num="4.3.1" prev="1"/><vers num="4.3.10" prev="1"/><vers num="4.3.11" prev="1"/><vers num="4.3.2" prev="1"/><vers num="4.3.3" prev="1"/><vers num="4.3.4" prev="1"/><vers num="4.3.5" prev="1"/><vers num="4.3.6" prev="1"/><vers num="4.3.7" prev="1"/><vers num="4.3.8" prev="1"/><vers num="4.3.9" prev="1"/><vers num="4.4.0" prev="1"/><vers num="4.4.1" prev="1"/><vers num="4.4.2" prev="1"/><vers num="4.4.3" prev="1"/><vers num="4.4.4" prev="1"/><vers num="4.4.5" prev="1"/><vers num="4.4.6" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="1.9" CVSS_exploit_subscore="3.4" CVSS_impact_subscore="2.9" CVSS_score="1.9" CVSS_vector="(AV:L/AC:M/Au:N/C:N/I:N/A:P)" CVSS_version="2.0" modified="2008-01-02" name="CVE-2007-1476" published="2007-03-16" seq="2007-1476" severity="Low" type="CVE"><desc><descript source="cve">The SymTDI device driver (SYMTDI.SYS) in Symantec Norton Personal Firewall 2006 9.1.1.7 and earlier, Internet Security 2005 and 2006, AntiVirus Corporate Edition 3.0.x through 10.1.x, and other Norton products, allows local users to cause a denial of service (system crash) by sending crafted data to the driver&apos;s \Device file, which triggers invalid memory access, a different vulnerability than CVE-2006-4855.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><local/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/462926/100/0/threaded">20070315 Norton Insufficient validation of &apos;SymTDI&apos; driver input buffer</ref><ref adv="1" source="" url="http://www.matousec.com/info/advisories/Norton-Insufficient-validation-of-SymTDI-driver-input-buffer.php"></ref><ref source="BID" url="http://www.securityfocus.com/bid/22977">22977</ref><ref source="FULLDISC" url="http://marc.info/?l=full-disclosure&amp;m=117396596027148&amp;w=2">20070315 Norton Insufficient validation of &apos;SymTDI&apos; driver</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33003">symantec-firewall-symtdi-dos(33003)</ref><ref source="" url="http://www.symantec.com/avcenter/security/Content/2007.09.05.html"></ref><ref source="SECTRACK" url="http://securitytracker.com/id?1018656">1018656</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2438">2438</ref></refs><vuln_soft><prod name="Norton Personal Firewall" vendor="Symantec"><vers num="2006 9.1.0.33"/><vers num="2006 9.1.1.7"/></prod><prod name="Norton AntiVirus Corporate Edition" vendor="Symantec"><vers num=""/></prod><prod name="Norton Internet Security" vendor="Symantec"><vers num="2005"/><vers num="2006"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-08-02" name="CVE-2007-1477" published="2007-03-16" seq="2007-1477" severity="High" type="CVE"><desc><descript source="cve">** DISPUTED **  Directory traversal vulnerability in index.php in PHP Point Of Sale for osCommerce 1.1 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the cfg_language parameter. NOTE: this issue has been disputed by CVE, since the cfg_language variable is configured upon proper product installation.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/462970/100/0/threaded">20070312 PHP Point Of Sale for osCommerce &lt;= (index.php) Remote File Include Vuln</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33006">pos-index-file-include(33006)</ref><ref source="VIM" url="http://attrition.org/pipermail/vim/2007-April/001564.html">20070427 FALSE -&gt; PHP Point of Sale (osCommerce) LFI</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2426">2426</ref></refs><vuln_soft><prod name="PHP Point of Sale" vendor="osCommerce"><vers num="1.1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.4" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="4.9" CVSS_score="6.4" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_version="2.0" modified="2007-03-19" name="CVE-2007-1478" published="2007-03-16" seq="2007-1478" severity="Medium" type="CVE"><desc><descript source="cve">download.php in McGallery 0.5b allows remote attackers to read arbitrary files and obtain script source code via the filename parameter.</descript></desc><loss_types><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3494">3494</ref><ref source="BID" url="http://www.securityfocus.com/bid/22989">22989</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1003">
ADV-2007-1003</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33004">
mcgallery-download-information-disclosure(33004)</ref></refs><vuln_soft><prod name="McGallery" vendor="SourceForge"><vers num="0.5b"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" modified="2007-03-19" name="CVE-2007-1479" published="2007-03-16" seq="2007-1479" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in Guestbook.php in Creative Guestbook 1.0 allows remote attackers to inject arbitrary web script or HTML via an unspecified parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3489">3489</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24536">
24536</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33015">
creative-schreiben-xss(33015)</ref></refs><vuln_soft><prod name="Creative Guestbook" vendor="Creative Guestbook"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-05-22" name="CVE-2007-1480" published="2007-03-16" seq="2007-1480" severity="High" type="CVE"><desc><descript source="cve">Creative Guestbook 1.0 allows remote attackers to add an administrative account via a direct request to createadmin.php with Name, Email, and PASSWORD parameters set.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3489">3489</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24536">24536</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33014">creative-createadmin-authentication-bypass(33014)</ref></refs><vuln_soft><prod name="Creative Guestbook" vendor="Creative Guestbook"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-03-19" name="CVE-2007-1481" published="2007-03-16" seq="2007-1481" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in index.php in WBBlog allows remote attackers to execute arbitrary SQL commands via the e_id parameter in a viewentry cmd.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3490">3490</ref><ref source="BID" url="http://www.securityfocus.com/bid/22998">
22998</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1001">
ADV-2007-1001</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24532">
24532</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33010">
wbblog-viewentry-sql-injection(33010)</ref></refs><vuln_soft><prod name="wbblog" vendor="wbblog"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-03-19" name="CVE-2007-1482" published="2007-03-16" seq="2007-1482" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in index.php in WBBlog allows remote attackers to inject arbitrary web script or HTML via the e_id parameter in a viewentry cmd.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3490">3490</ref><ref source="BID" url="http://www.securityfocus.com/bid/22998">
22998</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1001">
ADV-2007-1001</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24532">
24532</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33011">
wbblog-viewentry-xss(33011)</ref></refs><vuln_soft><prod name="WBBlog" vendor="LIQUA Web Solutions"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" CVSS_score="9.3" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-03-19" name="CVE-2007-1483" published="2007-03-16" seq="2007-1483" severity="High" type="CVE"><desc><descript source="cve">Multiple PHP remote file inclusion vulnerabilities in WebCalendar 0.9.45 allow remote attackers to execute arbitrary PHP code via a URL in the includedir parameter to (1) login.php, (2) get_reminders.php, or (3) get_events.php.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/462957/100/0/threaded">20070315 WebCalendar v0.9.45 (13 Dec 2004) (login.php) Remote File include</ref><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3492">3492</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/463288">
20070320 Re: WebCalendar v0.9.45 (13 Dec 2004) (login.php) Remote File include</ref><ref source="MLIST" url="http://sourceforge.net/mailarchive/forum.php?thread_id=31840112&amp;forum_id=46247">
[webcalendar-announce] 20070304 Announce: Release 1.0.5 (security patch)</ref><ref source="BID" url="http://www.securityfocus.com/bid/23054">
23054</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33008">
webcalendar-multiple-file-include(33008)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2425">2425</ref><ref source="MLIST" url="http://sourceforge.net/mailarchive/forum.php?thread_name=45EAF486.9080902%40k5n.us&amp;forum_name=webcalendar-announce">[webcalendar-announce] 20070304 Announce: Release 1.0.5 (security patch)</ref></refs><vuln_soft><prod name="WebCalendar" vendor="k5n"><vers num="0.9.45"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-04-23" name="CVE-2007-1484" published="2007-03-16" seq="2007-1484" severity="Medium" type="CVE"><desc><descript source="cve">The array_user_key_compare function in PHP 4.4.6 and earlier, and 5.x up to 5.2.1, makes erroneous calls to zval_dtor, which triggers memory corruption and allows local users to bypass safe_mode and execute arbitrary code via a certain unset operation after array_user_key_compare has been called.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/><input/></vuln_types><range><local/></range><refs><ref source="" url="http://www.php-security.org/MOPB/MOPB-24-2007.html"></ref><ref source="SECUNIA" url="http://secunia.com/advisories/24542">24542</ref><ref source="UBUNTU" url="http://www.ubuntu.com/usn/usn-455-1">
USN-455-1</ref><ref source="" url="http://us2.php.net/releases/4_4_7.php"></ref><ref source="" url="http://us2.php.net/releases/5_2_2.php"></ref><ref source="SECUNIA" url="http://secunia.com/advisories/25057">
25057</ref><ref source="" url="http://docs.info.apple.com/article.html?artnum=306172"></ref><ref source="APPLE" url="http://lists.apple.com/archives/security-announce//2007/Jul/msg00004.html">APPLE-SA-2007-07-31</ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200705-19.xml">GLSA-200705-19</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2007_32_php.html">SUSE-SA:2007:032</ref><ref source="BID" url="http://www.securityfocus.com/bid/22990">22990</ref><ref source="BID" url="http://www.securityfocus.com/bid/25159">25159</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/2732">ADV-2007-2732</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25056">25056</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25445">25445</ref><ref source="SECUNIA" url="http://secunia.com/advisories/26235">26235</ref></refs><vuln_soft><prod name="PHP" vendor="PHP"><vers num="4.4.6" prev="1"/><vers num="5.0 candidate 1" prev="1"/><vers num="5.0 candidate 2" prev="1"/><vers num="5.0 candidate 3" prev="1"/><vers num="5.0.0" prev="1"/><vers num="5.0.0 Beta1" prev="1"/><vers num="5.0.0 Beta2" prev="1"/><vers num="5.0.0 Beta3" prev="1"/><vers num="5.0.0 Beta4" prev="1"/><vers num="5.0.0 RC1" prev="1"/><vers num="5.0.0 RC2" prev="1"/><vers num="5.0.0 RC3" prev="1"/><vers num="5.0.1" prev="1"/><vers num="5.0.2" prev="1"/><vers num="5.0.3" prev="1"/><vers num="5.0.4" prev="1"/><vers num="5.0.5" prev="1"/><vers num="5.1" prev="1"/><vers num="5.1.0" prev="1"/><vers num="5.1.1" prev="1"/><vers num="5.1.2" prev="1"/><vers num="5.1.3" prev="1"/><vers num="5.1.4" prev="1"/><vers num="5.1.5" prev="1"/><vers num="5.1.6" prev="1"/><vers num="5.2.0" prev="1"/><vers num="5.2.1" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-03-19" name="CVE-2007-1485" published="2007-03-16" seq="2007-1485" severity="High" type="CVE"><desc><descript source="cve">** DISPUTED **  Buffer overflow in the set_umask function in QFTP in LIBFtp 3.1-1 allows local users to execute arbitrary code via a long -m argument. NOTE: CVE disputes this issue because QFTP is not setuid, and it is unlikely that there are web interfaces to QFTP that would accept untrusted command line arguments.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/462952/100/0/threaded">20070315 QFTP (LIBFtp 3.1-1) (command line) sprintf() local buffer overflow</ref><ref source="BID" url="http://www.securityfocus.com/bid/22986">22986</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2443">2443</ref></refs><vuln_soft><prod name="ftplib" vendor="ftplib"><vers num="3.1-1"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-03-21" name="CVE-2007-1486" published="2007-03-16" seq="2007-1486" severity="High" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in template.class.php in Carbonize Lazarus Guestbook before 1.7.3 allows remote attackers to execute arbitrary PHP code via a URL in the include_path parameter to admin.php, probably due to a dynamic variable evaluation vulnerability.</descript></desc><sols><sol source="nvd">This vulnerability has been addressed by the vendor with a product update: 
http://carbonize.co.uk/Lazarus/downloads.php</sol></sols><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/462183/100/100/threaded">20070307 Lazarus Guestbook (admin.php)Remote File Include Expliot</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/462235/100/100/threaded">20070308 Re: [Bogus] Lazarus Guestbook (admin.php)Remote File Include Expliot -</ref><ref source="" url="http://carbonize.co.uk/Lazarus/Forum/index.php?topic=1164.0"></ref><ref source="VIM" url="http://www.attrition.org/pipermail/vim/2007-March/001417.html">20070307 Bogus - [c_r_ck at hotmail.com: Lazarus Guestbook (admin.php)Remote File Include Expliot]</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0874">ADV-2007-0874</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/463041/100/0/threaded">
20070316 Re: [Bogus] Lazarus Guestbook (admin.php)Remote File Include Expliot</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/469218/100/0/threaded">20070520 Re: Re: [Bogus] Lazarus Guestbook (admin.php)Remote File Include Expliot -</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2432">2432</ref></refs><vuln_soft><prod name="Lazarus Guestbook" vendor="Carbonize"><vers num="1.7.2" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0" modified="2007-03-21" name="CVE-2007-1487" published="2007-03-16" seq="2007-1487" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in index.php in Sascha Schroeder (aka CyberTeddy or Cyber-inside) WebLog allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter in a showarticles action.</descript></desc><loss_types><conf/></loss_types><vuln_types><access/><input/></vuln_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3484">3484</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0967">ADV-2007-0967</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24521">24521</ref><ref source="BID" url="http://www.securityfocus.com/bid/22995">
22995</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32998">
weblog-index-directory-traversal(32998)</ref></refs><vuln_soft><prod name="WebLog" vendor="CyberTeddy"><vers num=""/></prod><prod name="WebLog" vendor="Cyber Inside"><vers num=""/></prod><prod name="WebLog" vendor="Sascha Schroeder"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-04-10" name="CVE-2007-1488" published="2007-03-16" seq="2007-1488" severity="High" type="CVE"><desc><descript source="cve">Unspecified vulnerability in Sun Java System Web Server 6.0 and 6.1 before 20070315 allows remote attackers to &quot;gain unauthorized access to data&quot;, possibly involving a sample application.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102833-1">102833</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/22993">22993</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0972">ADV-2007-0972</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/24545">24545</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017788">1017788</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33016">sun-java-url-information-disclosure(33016)</ref></refs><vuln_soft><prod name="Java System Web Server" vendor="Sun"><vers num="6.0"/><vers num="6.0 SP1"/><vers num="6.0 SP10"/><vers num="6.0 SP2"/><vers num="6.0 SP3"/><vers num="6.0 SP4"/><vers num="6.0 SP5"/><vers num="6.0 SP6"/><vers num="6.0 SP7"/><vers num="6.0 SP8"/><vers num="6.0 SP9"/><vers num="6.1"/><vers num="6.1 SP1"/><vers num="6.1 SP2"/><vers num="6.1 SP3"/><vers num="6.1 SP4"/><vers num="6.1 SP5"/><vers num="6.1 SP6"/></prod></vuln_soft></entry><entry CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" CVSS_score="9.3" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-04-10" name="CVE-2007-1489" published="2007-03-16" seq="2007-1489" severity="High" type="CVE"><desc><descript source="cve">Unspecified vulnerability in web-app.org Web Automated Perl Portal (WebAPP) 0.9.9.4 to 0.9.9.6 allows remote attackers to obtain admin access by modifying cookies and performing &quot;certain consecutive actions,&quot; possibly due to a cross-site request forgery (CSRF) vulnerability.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref patch="1" source="" url="http://www.web-app.org/cgi-bin/index.cgi?action=downloadinfo&amp;cat=crip&amp;id=2"></ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24540">24540</ref><ref source="" url="http://www.web-app.org/cgi-bin/index.cgi?action=viewnews&amp;id=256"></ref><ref source="VIM" url="http://www.attrition.org/pipermail/vim/2007-March/001446.html">20070320 WebAPP Audit</ref><ref source="" url="http://www.web-app.org/cgi-bin/index.cgi?action=viewnews&amp;id=259"></ref></refs><vuln_soft><prod name="WebAPP" vendor="Web-APP.org"><vers num="0.9.9.6" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.0" CVSS_exploit_subscore="6.8" CVSS_impact_subscore="6.4" CVSS_score="6.0" CVSS_vector="(AV:N/AC:M/Au:S/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-03-20" name="CVE-2007-1490" published="2007-03-16" seq="2007-1490" severity="Medium" type="CVE"><desc><descript source="cve">Unspecified maintenance web pages in Avaya S87XX, S8500, and S8300 before CM 3.1.3, and Avaya SES allow remote authenticated users to execute arbitrary commands via shell metacharacters in unspecified vectors (aka &quot;shell command injection&quot;).</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="" url="http://support.avaya.com/elmodocs2/security/ASA-2007-052.htm"></ref><ref source="SECUNIA" url="http://secunia.com/advisories/24434">24434</ref><ref source="OSVDB" url="http://www.osvdb.org/33300">
33300</ref></refs><vuln_soft><prod name="Communication Manager" vendor="Avaya"><vers num="3.1.3" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.2" CVSS_exploit_subscore="5.1" CVSS_impact_subscore="6.4" CVSS_score="5.2" CVSS_vector="(AV:A/AC:L/Au:S/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-03-20" name="CVE-2007-1491" published="2007-03-16" seq="2007-1491" severity="Medium" type="CVE"><desc><descript source="cve">Apache Tomcat in Avaya S87XX, S8500, and S8300 before CM 3.1.3, and Avaya SES allows connections from external interfaces via port 8009, which exposes it to attacks from outside parties.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/><design/></vuln_types><range><local_network/></range><refs><ref adv="1" source="" url="http://support.avaya.com/elmodocs2/security/ASA-2007-051.htm"></ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24434">24434</ref><ref source="OSVDB" url="http://www.osvdb.org/33346">
33346</ref></refs><vuln_soft><prod name="SIP Enablement Services" vendor="Avaya"><vers num=""/></prod><prod name="S8300" vendor="Avaya"><vers num="CM 3.1.2" prev="1"/></prod><prod name="S8500" vendor="Avaya"><vers num="CM 3.1.2" prev="1"/></prod><prod name="S8700 Series" vendor="Avaya"><vers num="CM 3.1.2" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.1" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.9" CVSS_score="7.1" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:C)" CVSS_version="2.0" modified="2007-03-20" name="CVE-2007-1492" published="2007-03-16" seq="2007-1492" severity="High" type="CVE"><desc><descript source="cve">winmm.dll in Microsoft Windows XP allows user-assisted remote attackers to cause a denial of service (infinite loop) via a large cch argument value to the mmioRead function, as demonstrated by a crafted WAV file.</descript></desc><loss_types><avail/></loss_types><vuln_types><input buffer="1"/><exception/></vuln_types><range><network/><user_init/></range><refs><ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2007-q1/0063.html">20070310 Windows Multimedia mmioRead Denial of Service Vulnerability</ref><ref source="BID" url="http://www.securityfocus.com/bid/22938">22938</ref></refs><vuln_soft><prod name="Windows XP" vendor="Microsoft"><vers edition="Professional" num="SP1"/><vers edition="Media Center" num="SP1"/><vers edition="Home" num="SP1"/><vers edition="Gold" num="SP1"/><vers edition="64-bit 2003" num="SP1"/><vers edition="Tablet PC" num="SP1"/><vers edition="Tablet PC" num="SP2"/><vers edition="Professional" num="SP2"/><vers edition="Media Center" num="SP2"/><vers edition="Home" num="SP2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-03-20" name="CVE-2007-1493" published="2007-03-16" seq="2007-1493" severity="High" type="CVE"><desc><descript source="cve">nukesentinel.php in NukeSentinel 2.5.06 and earlier uses a permissive regular expression to validate an IP address, which allows remote attackers to execute arbitrary SQL commands via the Client-IP HTTP header, due to an incomplete patch for CVE-2007-1172.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/462453/100/0/threaded">20070310 NukeSentinel &lt;= 2.5.06 SQL Injection (mysql &gt;= 4.0.24) Exploit</ref><ref source="VIM" url="http://attrition.org/pipermail/vim/2007-March/001429.html">20070314 SQL injection (x2) in NukeSentinel</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2430">2430</ref></refs><vuln_soft><prod name="NukeSentinel" vendor="NukeScripts"><vers num="2.5.06" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-03-20" name="CVE-2007-1494" published="2007-03-16" seq="2007-1494" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in NukeSentinel before 2.5.06 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors related to the &quot;filters for https:// and http://&quot;.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><range><network/></range><refs><ref patch="1" source="" url="http://www.nukescripts.net/modules.php?name=Downloads&amp;op=getit&amp;lid=1055"></ref></refs><vuln_soft><prod name="NukeSentinel" vendor="NukeScripts"><vers num="2.5.05" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.9" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.9" CVSS_score="4.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:C)" CVSS_version="2.0" modified="2007-03-20" name="CVE-2007-1495" published="2007-03-16" seq="2007-1495" severity="Medium" type="CVE"><desc><descript source="cve">The \Device\SymEvent driver in Symantec Norton Personal Firewall 2006 9.1.1.7, and possibly other products using symevent.sys 12.0.0.20, allows local users to cause a denial of service (system crash) via invalid data, as demonstrated by calling DeviceIoControl to send the data, a reintroduction of CVE-2006-4855.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><local/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/462792/100/0/threaded">20070314 SymEvent Driver Local Access System Denial of Service</ref><ref source="BID" url="http://www.securityfocus.com/bid/22961">22961</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2445">2445</ref></refs><vuln_soft><prod name="Norton Personal Firewall" vendor="Symantec"><vers num="2006 9.1.1.7"/></prod></vuln_soft></entry><entry CVSS_base_score="4.9" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.9" CVSS_score="4.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:C)" CVSS_version="2.0" modified="2007-10-03" name="CVE-2007-1496" published="2007-03-16" seq="2007-1496" severity="Medium" type="CVE"><desc><descript source="cve">nfnetlink_log in netfilter in the Linux kernel before 2.6.20.3 allows attackers to cause a denial of service (crash) via unspecified vectors involving the (1) nfulnl_recv_config function, (2) using &quot;multiple packets per netlink message&quot;, and (3) bridged packets, which trigger a NULL pointer dereference.</descript></desc><loss_types><avail/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref source="" url="http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.20.3"></ref><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/22946">22946</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24492">24492</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0944">ADV-2007-0944</ref><ref source="DEBIAN" url="http://www.debian.org/security/2007/dsa-1289">DSA-1289</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2007-0347.html">RHSA-2007:0347</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25228">25228</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25288">25288</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:171">MDKSA-2007:171</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2007_43_kernel.html">SUSE-SA:2007:043</ref><ref source="UBUNTU" url="http://www.ubuntu.com/usn/usn-464-1">USN-464-1</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25392">25392</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25961">25961</ref><ref source="SECUNIA" url="http://secunia.com/advisories/26620">26620</ref></refs><vuln_soft><prod name="Kernel" vendor="Linux"><vers num="2.6.20.2" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0" modified="2007-10-03" name="CVE-2007-1497" published="2007-03-16" seq="2007-1497" severity="Medium" type="CVE"><desc><descript source="cve">nf_conntrack in netfilter in the Linux kernel before 2.6.20.3 does not set nfctinfo during reassembly of fragmented packets, which leaves the default value as IP_CT_ESTABLISHED and might allow remote attackers to bypass certain rulesets using IPv6 fragments.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref source="" url="http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.20.3"></ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/24492">24492</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0944">ADV-2007-0944</ref><ref source="OSVDB" url="http://www.osvdb.org/33028">33028</ref><ref source="DEBIAN" url="http://www.debian.org/security/2007/dsa-1289">DSA-1289</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2007-0347.html">RHSA-2007:0347</ref><ref source="BID" url="http://www.securityfocus.com/bid/23976">23976</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25228">25228</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25288">25288</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:171">MDKSA-2007:171</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:196">MDKSA-2007:196</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2007_43_kernel.html">SUSE-SA:2007:043</ref><ref source="UBUNTU" url="http://www.ubuntu.com/usn/usn-464-1">USN-464-1</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25392">25392</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25961">25961</ref><ref source="SECUNIA" url="http://secunia.com/advisories/26620">26620</ref></refs><vuln_soft><prod name="Kernel" vendor="Linux"><vers num="2.6.20.2" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" CVSS_score="9.3" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-04-02" name="CVE-2007-1498" published="2007-03-16" seq="2007-1498" severity="High" type="CVE"><desc><descript source="cve">Multiple stack-based buffer overflows in the SiteManager.SiteMgr.1 ActiveX control (SiteManager.dll) in the ePO management console in McAfee ePolicy Orchestrator (ePO) before 3.6.1 Patch 1 and ProtectionPilot (PRP) before 1.5.0 HotFix allow remote attackers to execute arbitrary code via a long argument to the (1) ExportSiteList and (2) VerifyPackageCatalog functions, and (3) unspecified vectors involving a swprintf function call.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/><user_init/></range><refs><ref patch="1" source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2007-March/052960.html">20070314 [Advisory]McAfee ePolicy Orchestrator Multiple Remote Buffer Overflow Vulnerabilities</ref><ref patch="1" source="" url="https://knowledge.mcafee.com/article/25/612495_f.SAL_Public.html"></ref><ref patch="1" source="" url="https://knowledge.mcafee.com/article/26/612496_f.SAL_Public.html"></ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/22952">22952</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0931">ADV-2007-0931</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/24466">24466</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/714593">VU#714593</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017757">1017757</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2444">2444</ref></refs><vuln_soft><prod name="ProtectionPilot" vendor="McAfee"><vers num="1.1.1 Patch 3"/><vers num="1.5.0"/></prod><prod name="ePolicy Orchestrator" vendor="McAfee"><vers num="3.5.0"/><vers num="3.5.0 Patch 6"/><vers num="3.6.0"/><vers num="3.6.1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" modified="2008-01-02" name="CVE-2007-1499" published="2007-03-17" seq="2007-1499" severity="Medium" type="CVE"><desc><descript source="cve">Microsoft Internet Explorer 7.0 on Windows XP and Vista allows remote attackers to conduct phishing attacks and possibly execute arbitrary code via a res: URI to navcancl.htm with an arbitrary URL as an argument, which displays the URL in the location bar of the &quot;Navigation Canceled&quot; page and injects the script into the &quot;Refresh the page&quot; link, aka Navigation Cancel Page Spoofing Vulnerability.&quot;</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/462833/100/0/threaded">20070314 Phishing using IE7 local resource vulnerability</ref><ref adv="1" source="" url="http://aviv.raffon.net/2007/03/14/PhishingUsingIE7LocalResourceVulnerability.aspx"></ref><ref source="" url="http://news.com.com/2100-1002_3-6167410.html"></ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/462945/100/0/threaded">20070315 RE: Phishing using IE7 local resource vulnerability</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/462939/100/0/threaded">20070315 Re: Phishing using IE7 local resource vulnerability</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0946">ADV-2007-0946</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24535">24535</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33026">ie-navcancl-xss(33026)</ref><ref source="HP" url="http://www.securityfocus.com/archive/1/archive/1/471947/100/0/threaded">HPSBST02231</ref><ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms07-033.mspx">MS07-033</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA07-163A.html">TA07-163A</ref><ref source="BID" url="http://www.securityfocus.com/bid/22966">22966</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/2153">ADV-2007-2153</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1715">oval:org.mitre.oval:def:1715</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1018235">1018235</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/25627">25627</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2448">2448</ref></refs><vuln_soft><prod name="Internet Explorer" vendor="Microsoft"><vers edition="Vista" num="7.0"/><vers edition="Vista" num="7.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="3.1" CVSS_impact_subscore="6.4" CVSS_score="4.3" CVSS_vector="(AV:L/AC:L/Au:S/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-03-20" name="CVE-2007-1500" published="2007-03-19" seq="2007-1500" severity="Medium" type="CVE"><desc><descript source="cve">The Linux Security Auditing Tool (LSAT) allows local users to overwrite arbitrary files via a symlink attack on temporary files, as demonstrated using /tmp/lsat1.lsat.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><access/><design/></vuln_types><range><local/></range><refs><ref source="" url="http://bugs.gentoo.org/show_bug.cgi?id=159542"></ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200703-20.xml">GLSA-200703-20</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24526">24526</ref><ref source="BID" url="http://www.securityfocus.com/bid/23014">
23014</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33057">
gentoo-lsat-symlink(33057)</ref></refs><vuln_soft><prod name="Linux" vendor="Gentoo"><vers num="" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" CVSS_score="9.3" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-03-20" name="CVE-2007-1501" published="2007-03-19" seq="2007-1501" severity="High" type="CVE"><desc><descript source="cve">Stack-based buffer overflow in Avant Browser 11.0 build 26 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long Content-Type HTTP header.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3514">3514</ref><ref source="BID" url="http://www.securityfocus.com/bid/23002">23002</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33049">
avantbrowser-contenttype-dos(33049)</ref></refs><vuln_soft><prod name="Avant Browser" vendor="Avant Force"><vers num="11.0 build 26"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-03-20" name="CVE-2007-1502" published="2007-03-19" seq="2007-1502" severity="Medium" type="CVE"><desc><descript source="cve">Multiple buffer overflows in Rhapsody IRC 0.28b allow remote attackers to execute arbitrary code via a (1) long command, (2) long server argument to the (a) connect or (b) server commands, (3) long nick argument to the (c) nick command, or a long (4) nick or (5) message argument to the (d) ctcp, (e) chat, (f) notice, (g) message (msg), or (h) query commands.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/463092/100/0/threaded">20070317 Rhapsody IRC 0.28b (NICK) Multiple fs and bof vulnerability</ref><ref source="BID" url="http://www.securityfocus.com/bid/23011">23011</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2447">2447</ref></refs><vuln_soft><prod name="Rhapsody IRC" vendor="Rhapsody IRC"><vers num="0.28b"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-03-21" name="CVE-2007-1503" published="2007-03-19" seq="2007-1503" severity="High" type="CVE"><desc><descript source="cve">Multiple format string vulnerabilities in comm.c in Rhapsody IRC 0.28b allow remote attackers to execute arbitrary code via format string specifiers to the create_ctcp_message function using the message argument to the (1) me or (2) ctcp commands, and possibly related vectors involving the (3) whois, (4) mode, and (5) topic commands.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/463092/100/0/threaded">20070317 Rhapsody IRC 0.28b (NICK) Multiple fs and bof vulnerability</ref><ref source="BID" url="http://www.securityfocus.com/bid/23011">23011</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2447">2447</ref></refs><vuln_soft><prod name="Rhapsody IRC" vendor="Rhapsody IRC"><vers num="0.28b"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" modified="2007-03-21" name="CVE-2007-1504" published="2007-03-19" seq="2007-1504" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in the Servlet Service in Fujitsu Interstage Application Server (IJServer) 8.0.2 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, possibly involving web.xml and HTTP 404 and 500 status codes.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref source="" url="http://jvn.jp/jp/JVN%2383832818/index.html"></ref><ref source="" url="http://software.fujitsu.com/jp/security/vulnerabilities/jvn-83832818.html"></ref><ref source="" url="http://www.fujitsu.com/global/support/software/security/products-f/interstage-200701e.html"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0996">ADV-2007-0996</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24508">24508</ref><ref source="BID" url="http://www.securityfocus.com/bid/23020">
23020</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33099">
interstage-application-servlet-xss(33099)</ref></refs><vuln_soft><prod name="Interstage Application Server" vendor="Fujitsu"><vers edition="Standard" num="3.0"/><vers edition="Enterprise" num="3.0"/><vers edition="Standard" num="4.0"/><vers edition="Enterprise" num="4.0"/><vers edition="Web_J" num="4.0"/><vers edition="Standard" num="5.0"/><vers edition="Enterprise" num="5.0"/><vers edition="Web_J" num="5.0"/><vers edition="Enterprise" num="5.0.1"/><vers edition="Enterprise" num="6.0"/><vers edition="Enterprise" num="7.0"/><vers edition="Standard" num="7.0"/><vers edition="Plus" num="7.0"/><vers edition="Enterprise" num="7.0.1"/><vers edition="Plus" num="7.0.1"/><vers edition="Enterprise" num="8.0.0"/><vers edition="Enterprise" num="8.0.2"/><vers edition="Standard_J" num="8.0.0"/><vers edition="Standard_J" num="8.0.2"/></prod><prod name="Interstage Apworks" vendor="Fujitsu"><vers edition="Japanese" num="6.0"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0" modified="2007-03-21" name="CVE-2007-1505" published="2007-03-19" seq="2007-1505" severity="Low" type="CVE"><desc><descript source="cve">Fujistu FENCE-Pro before V5L01, and Systemwalker Desktop Encryption V12.0L10, V12.0L10A, V12.0L10B, V12.0L20 and V13.0.0 allows local users to obtain sensitive information by extracting the decoding password from certain &quot;self-decoding&quot; file types.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref source="" url="http://jvn.jp/jp/JVN%2319795972/index.html"></ref><ref source="" url="http://segroup.fujitsu.com/secure/products/fence/notice/alert20070316.html"></ref><ref source="" url="http://software.fujitsu.com/jp/security/products-fujitsu/solution/systemwalker_dte_200701.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/23001">23001</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/24537">24537</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/24549">24549</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33029">
systemwalker-selfdecoding-info-disclosure(33029)</ref></refs><vuln_soft><prod name="Systemwalker Desktop Encryption" vendor="Fujitsu"><vers num="V12.0L10"/><vers num="V12.0L10A"/><vers num="V12.0L10B"/><vers num="V12.0L20"/><vers num="V13.0.0"/></prod><prod name="FENCE" vendor="Fujitsu"><vers edition="Pro" num="2"/><vers edition="Pro" num="3"/><vers edition="Pro" num="4"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" modified="2007-03-21" name="CVE-2007-1506" published="2007-03-19" seq="2007-1506" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in PORTAL.wwv_main.render_warning_screen in the Oracle Portal 10g allows remote attackers to inject arbitrary web script or HTML via the (1) p_oldurl and (2) p_newurl parameters.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/463012/100/0/threaded">20070316 Oracle Portal PORTAL.wwv_main.render_warning_screen XSS</ref><ref source="BID" url="http://www.securityfocus.com/bid/22999">22999</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33028">
oracleportal-portalwarning-xss(33028)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2463">2463</ref></refs><vuln_soft><prod name="Application Server Portal 10g" vendor="Oracle"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-04-10" name="CVE-2007-1507" published="2007-03-20" seq="2007-1507" severity="High" type="CVE"><desc><descript source="cve">The default configuration in OpenAFS 1.4.x before 1.4.4 and 1.5.x before 1.5.17 supports setuid programs within the local cell, which might allow attackers to gain privileges by spoofing a response to an AFS cache manager FetchStatus request, and setting setuid and root ownership for files in the cache.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" source="MLIST" url="http://www.openafs.org/pipermail/openafs-announce/2007/000185.html">[OpenAFS-announce] 20070319 OpenAFS 1.4.4 available</ref><ref adv="1" patch="1" source="MLIST" url="http://www.openafs.org/pipermail/openafs-announce/2007/000186.html">[OpenAFS-announce] 20070319 OpenAFS 1.5.17 release available</ref><ref source="MLIST" url="http://www.openafs.org/pipermail/openafs-announce/2007/000187.html">[OpenAFS-announce] 20070320 OpenAFS Security Advisory 2007-001: privilege escalation in Unix-based clients</ref><ref adv="1" source="DEBIAN" url="http://www.debian.org/security/2007/dsa-1271">DSA-1271</ref><ref adv="1" source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2007:066">MDKSA-2007:066</ref><ref source="BID" url="http://www.securityfocus.com/bid/23060">23060</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1033">ADV-2007-1033</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017807">1017807</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24582">24582</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24599">24599</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24607">24607</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33180">openafs-setuid-privilege-escalation(33180)</ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200704-03.xml">
GLSA-200704-03</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24720">
24720</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:066">MDKSA-2007:066</ref></refs><vuln_soft><prod name="OpenAFS" vendor="OpenAFS"><vers num="1.4.3"/><vers num="1.5"/><vers num="1.4.4"/><vers num="1.5.16"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" modified="2007-03-21" name="CVE-2007-1508" published="2007-03-20" seq="2007-1508" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in CMD_USER_STATS in DirectAdmin allows remote attackers to inject arbitrary web script or HTML via the RESULT parameter, a different vector than CVE-2006-5983.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/463003/100/0/threaded">20070315 DirectAdmin Cross Site Scripting XSS</ref><ref source="BID" url="http://www.securityfocus.com/bid/22996">22996</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1037">
ADV-2007-1037</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24551">
24551</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33023">
directadmin-cmduserstats-xss(33023)</ref></refs><vuln_soft><prod name="DirectAdmin" vendor="JBMC Software"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)" CVSS_version="2.0" modified="2007-03-21" name="CVE-2007-1509" published="2007-03-20" seq="2007-1509" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in enkrypt.php in Sascha Schroeder krypt (aka Holtstraeter Rot 13) allows remote attackers to read arbitrary files via a .. (dot dot) in the datei parameter.</descript></desc><loss_types><conf/></loss_types><vuln_types><access/><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/463011/100/0/threaded">20070316 Rot 13 &lt;= (enkrypt.php) Remote File Disclosure Vulnerability</ref><ref source="BID" url="http://www.securityfocus.com/bid/22997">22997</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33027">
rot-enkrypt-directory-traversal(33027)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2458">2458</ref></refs><vuln_soft><prod name="ROT 13" vendor="Holtstraeter"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-03-21" name="CVE-2007-1510" published="2007-03-20" seq="2007-1510" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in post.php in Particle Blogger 1.0.0 through 1.2.0 allows remote attackers to execute arbitrary SQL commands via the postid parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/463027/100/0/threaded">20070316 Particle Blogger All Version Post.PHP (PostID) Remote SQL Injection Exploit</ref><ref source="BID" url="http://www.securityfocus.com/bid/23005">23005</ref><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3500">
3500</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1006">
ADV-2007-1006</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24559">
24559</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33030">
particle-post-sql-injection(33030)</ref><ref source="" url="http://forums.particlesoft.net/viewtopic.php?t=675"></ref><ref source="SREASON" url="http://securityreason.com/securityalert/2460">2460</ref></refs><vuln_soft><prod name="Particle Blogger" vendor="Particle Blogger"><vers num="1.2.0"/><vers num="1.0.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.1" CVSS_vector="(AV:N/AC:H/Au:S/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-03-21" name="CVE-2007-1511" published="2007-03-20" seq="2007-1511" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in FrontBase Relational Database Server 4.2.7 and earlier allows remote authenticated users, with privileges for creating a stored procedure, to execute arbitrary code via a CREATE PROCEDURE request with a long procedure name.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/463042/100/0/threade">20070316 [NETRAGARD-20070316 SECURITY ADVISORY][FrontBase Database &lt;= 4.2.7 ALL PLATFORMS][REMOTE BUFFER OVERFLOW CONDITION][LEVEL: EASY][RISK:MEDIUM]</ref><ref source="BID" url="http://www.securityfocus.com/bid/23007">23007</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0999">
ADV-2007-0999</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24555">
24555</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2470">2470</ref></refs><vuln_soft><prod name="Relational Database Server" vendor="FrontBase"><vers num="4.2.7" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-03-21" name="CVE-2007-1512" published="2007-03-20" seq="2007-1512" severity="High" type="CVE"><desc><descript source="cve">Stack-based buffer overflow in the AfxOleSetEditMenu function in the MFC component in Microsoft Windows 2000 SP4, XP SP2, and Server 2003 Gold and SP1, and Visual Studio .NET 2002 Gold and SP1, and 2003 Gold and SP1 allows user-assisted remote attackers to have an unknown impact (probably crash) via an RTF file with a malformed OLE object, which results in writing two 0x00 characters past the end of szBuffer, aka the &quot;MFC42u.dll Off-by-Two Overflow.&quot; NOTE: this issue is due to an incomplete patch (MS07-012) for CVE-2007-0025.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/463009/100/0/threaded">20070316 MS07-012 Not Fixed</ref></refs><vuln_soft><prod name="Visual Studio .NET" vendor="Microsoft"><vers edition="Gold" num="2002"/><vers edition="SP1" num="2002"/><vers edition="Gold" num="2003"/><vers edition="SP1" num="2003"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-03-21" name="CVE-2007-1513" published="2007-03-20" seq="2007-1513" severity="Medium" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in comanda.php in GraFX Company WebSite Builder (CWB) PRO 1.9.8, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the INCLUDE_PATH parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/462917/100/0/threaded">20070315 [ECHO_ADV_76$2007] Company WebSite Builder PRO (INCLUDE_PATH) Remote File Inclusion Vulnerability</ref><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3485">3485</ref><ref source="" url="http://advisories.echo.or.id/adv/adv76-theday-2007.txt"></ref><ref source="BID" url="http://www.securityfocus.com/bid/22974">22974</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33035">
cwb-comanda-file-include(33035)</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0994">ADV-2007-0994</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2452">2452</ref></refs><vuln_soft><prod name="Company Website Builder Pro" vendor="GraFX"><vers num="1.9.8"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-03-21" name="CVE-2007-1514" published="2007-03-20" seq="2007-1514" severity="Medium" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in index.php in ViperWeb Portal alpha 0.1 allows remote attackers to execute arbitrary PHP code via a URL in the modpath parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/462930/100/0/threaded">20070315 Remote File Inclusion in ViperWeb</ref><ref source="BID" url="http://www.securityfocus.com/bid/22979">22979</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33034">
viperweb-index-file-include(33034)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2449">2449</ref></refs><vuln_soft><prod name="Portal" vendor="ViperWeb"><vers num="0.1 Alpha"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" modified="2007-03-21" name="CVE-2007-1515" published="2007-03-20" seq="2007-1515" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Horde IMP H3 4.1.3, and possibly earlier, allow remote attackers to inject arbitrary web script or HTML via (1) the email Subject header in thread.php, (2) the edit_query parameter in search.php, or other unspecified parameters in search.php.  NOTE: some of these details are obtained from third party information.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/462914/100/0/threaded">20070315 Horde IMP Webmail Client version H3 (4.1.4) fixes multiple XSS issues</ref><ref adv="1" source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2007-March/052977.html">20071315 Horde IMP Webmail Client version H3 (4.1.4) fixes multiple XSS issues</ref><ref adv="1" patch="1" source="MLIST" url="http://lists.horde.org/archives/announce/2007/000316.html">[announce] 20070314 IMP H3 (4.1.4) (final)</ref><ref source="BID" url="http://www.securityfocus.com/bid/22975">22975</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24541">24541</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0964">
ADV-2007-0964</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017774">
1017774</ref></refs><vuln_soft><prod name="IMP" vendor="Horde"><vers num="4.1.3" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-03-21" name="CVE-2007-1516" published="2007-03-20" seq="2007-1516" severity="Medium" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in functions/update.php in Cicoandcico CcMail 1.0 allows remote attackers to execute arbitrary PHP code via a URL in the functions_dir parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/><input/></vuln_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3487">3487</ref><ref source="BID" url="http://www.securityfocus.com/bid/22983">22983</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1000">
ADV-2007-1000</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32999">
ccmail-update-file-include(32999)</ref></refs><vuln_soft><prod name="CcMail" vendor="Cicoandcico"><vers num="1.0.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-03-21" name="CVE-2007-1517" published="2007-03-20" seq="2007-1517" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in comments.php in WSN Guest 1.02 and 1.21 allows remote attackers to execute arbitrary SQL commands via the id parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/462814/100/0/threaded">20070314 WSN Guest 1.21 Version Comments.PHP </ref><ref source="BID" url="http://www.securityfocus.com/bid/22969">22969</ref><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3477">
3477</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0968">
ADV-2007-0968</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32983">
wsnguest-comments-sql-injection(32983)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2451">2451</ref></refs><vuln_soft><prod name="WSN Guest" vendor="Paul Knierim"><vers num="1.21"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-03-21" name="CVE-2007-1518" published="2007-03-20" seq="2007-1518" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in usergroups.php in Woltlab Burning Board (wBB) 2.x allows remote attackers to execute arbitrary SQL commands via the array index of the applicationids array.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/462860/100/0/threaded">20070314 Woltab Burning Board SQL Injection usergroups.php</ref><ref source="BID" url="http://www.securityfocus.com/bid/22970">22970</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/463002/100/0/threaded">
20070315 Re: [Full-disclosure] Woltab Burning Board SQL Injection usergroups.php</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2455">2455</ref></refs><vuln_soft><prod name="Burning Board" vendor="Woltlab"><vers num="2.0"/><vers num="2.0 Beta 3"/><vers num="2.0 Beta 4"/><vers num="2.0 Beta 5"/><vers num="2.0 RC1"/><vers num="2.0 RC2"/><vers num="2.0.3"/><vers num="2.1.5"/><vers num="2.1.6"/><vers num="2.2.1"/><vers num="2.2.2"/><vers num="2.2.3"/><vers num="2.3.0"/><vers num="2.3.1"/><vers num="2.3.2"/><vers num="2.3.3"/><vers num="2.3.4"/><vers num="2.3.5"/><vers num="2.3.6"/><vers num="2.4"/><vers num="2.5"/><vers num="2.6"/><vers num="2.7"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" modified="2008-01-02" name="CVE-2007-1519" published="2007-03-20" seq="2007-1519" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in modules.php in PHP-Nuke 8.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the query parameter in a search operation in the Downloads module, a different product than CVE-2006-3948.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/462308/100/100/threaded">20070309 Php Nuke POST XSS on steroids</ref><ref source="" url="http://phpfi.com/214668"></ref><ref source="" url="http://www.ush.it/2007/03/09/php-nuke-wild-post-xss/"></ref><ref source="" url="http://www.wisec.it/ush/phpnukexss.html"></ref><ref source="SECUNIA" url="http://secunia.com/advisories/24629">24629</ref></refs><vuln_soft><prod name="PHP-Nuke" vendor="PHP-Nuke"><vers num="8.0" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" modified="2008-01-02" name="CVE-2007-1520" published="2007-03-20" seq="2007-1520" severity="Medium" type="CVE"><desc><descript source="cve">The cross-site request forgery (CSRF) protection in PHP-Nuke 8.0 and earlier does not ensure the SERVER superglobal is an array before validating the HTTP_REFERER, which allows remote attackers to conduct CSRF attacks.</descript></desc><loss_types><int/></loss_types><vuln_types><access/><input/></vuln_types><range><network/><user_init/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/462308/100/100/threaded">20070309 Php Nuke POST XSS on steroids</ref><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/462575/100/0/threaded">20070311 Re: Php Nuke POST XSS on steroids</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/462727/100/0/threaded">20070313 Re: Php Nuke POST XSS on steroids</ref><ref source="" url="http://phpfi.com/214668"></ref><ref source="" url="http://www.ush.it/2007/03/09/php-nuke-wild-post-xss/"></ref><ref source="" url="http://www.wisec.it/ush/phpnukexss.html"></ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24629">24629</ref></refs><vuln_soft><prod name="PHP-Nuke" vendor="PHP-Nuke"><vers num="8.0" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-08-02" name="CVE-2007-1521" published="2007-03-20" seq="2007-1521" severity="Medium" type="CVE"><desc><descript source="cve">Double free vulnerability in PHP before 4.4.7, and 5.x before 5.2.2, allows context-dependent attackers to execute arbitrary code by interrupting the session_regenerate_id function, as demonstrated by calling a userspace error handler or triggering a memory limit violation.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input bound="1"/><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="" url="http://www.php-security.org/MOPB/MOPB-22-2007.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/22968">22968</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0960">ADV-2007-0960</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24505">24505</ref><ref source="DEBIAN" url="http://www.debian.org/security/2007/dsa-1282">DSA-1282</ref><ref source="DEBIAN" url="http://www.debian.org/security/2007/dsa-1283">DSA-1283</ref><ref source="UBUNTU" url="http://www.ubuntu.com/usn/usn-455-1">USN-455-1</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/25025">25025</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/25062">25062</ref><ref source="" url="http://us2.php.net/releases/4_4_7.php"></ref><ref source="" url="http://us2.php.net/releases/5_2_2.php"></ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/25057">25057</ref><ref source="" url="http://docs.info.apple.com/article.html?artnum=306172"></ref><ref source="APPLE" url="http://lists.apple.com/archives/security-announce//2007/Jul/msg00004.html">APPLE-SA-2007-07-31</ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200705-19.xml">GLSA-200705-19</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2007_32_php.html">SUSE-SA:2007:032</ref><ref source="BID" url="http://www.securityfocus.com/bid/25159">25159</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/2732">ADV-2007-2732</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25056">25056</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25445">25445</ref><ref source="SECUNIA" url="http://secunia.com/advisories/26235">26235</ref></refs><vuln_soft><prod name="PHP" vendor="PHP"><vers num="5.2.1" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-03-21" name="CVE-2007-1522" published="2007-03-20" seq="2007-1522" severity="Medium" type="CVE"><desc><descript source="cve">Double free vulnerability in the session extension in PHP 5.2.0 and 5.2.1 allows context-dependent attackers to execute arbitrary code via illegal characters in a session identifier, which is rejected by an internal session storage module, which calls the session identifier generator with an improper environment, leading to code execution when the generator is interrupted, as demonstrated by triggering a memory limit violation or certain PHP errors.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="" url="http://www.php-security.org/MOPB/MOPB-23-2007.html"></ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0960">
ADV-2007-0960</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24505">
24505</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2007_32_php.html">SUSE-SA:2007:032</ref><ref source="BID" url="http://www.securityfocus.com/bid/22971">22971</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25056">25056</ref></refs><vuln_soft><prod name="PHP" vendor="PHP"><vers num="5.2.0"/><vers num="5.2.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-03-21" name="CVE-2007-1523" published="2007-03-20" seq="2007-1523" severity="High" type="CVE"><desc><descript source="cve">Heap-based buffer overflow in the kernel in NetBSD 3.0, certain versions of FreeBSD and OpenBSD, and possibly other BSD derived operating systems allows local users to have an unknown impact.  NOTE: this information is based upon a vague pre-advisory with no actionable information. Details will be updated after 20070329.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="" url="http://kernelwars.blogspot.com/2007/01/alive.html"></ref><ref adv="1" source="" url="http://www.blackhat.com/html/bh-europe-07/bh-eu-07-speakers.html#Eriksson"></ref><ref source="BID" url="http://www.securityfocus.com/bid/22945">22945</ref></refs><vuln_soft><prod name="NetBSD" vendor="NetBSD"><vers num="3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0" modified="2007-03-21" name="CVE-2007-1524" published="2007-03-20" seq="2007-1524" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in themes/default/ in ZomPlog 3.7.6 and earlier allows remote attackers to include arbitrary local files via a .. (dot dot) in the settings[skin] parameter, as demonstrated by injecting PHP code into an Apache HTTP Server log file, which can then included via themes/default/.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3476">3467</ref><ref source="BID" url="http://www.securityfocus.com/bid/22157">22157</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0966">
ADV-2007-0966</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24520">
24520</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32982">
zomplog-index-file-include(32982)</ref></refs><vuln_soft><prod name="Zomplog" vendor="Zomplog"><vers num="3.7.6"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-03-21" name="CVE-2007-1525" published="2007-03-20" seq="2007-1525" severity="Medium" type="CVE"><desc><descript source="cve">Direct static code injection vulnerability in postpost.php in Dayfox Blog (dfblog) 4 allows remote attackers to execute arbitrary PHP code via the cat parameter, which can be executed via a request to posts.php.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3478">3478</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0969">
ADV-2007-0969</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24534">
24534</ref><ref source="" url="http://infusion.110mb.com/enter/dfblog4.zip"></ref><ref source="BID" url="http://www.securityfocus.com/bid/22972">22972</ref></refs><vuln_soft><prod name="Dayfox Blog" vendor="Dayfox Designs"><vers num="4"/></prod></vuln_soft></entry><entry CVSS_base_score="6.0" CVSS_exploit_subscore="6.8" CVSS_impact_subscore="6.4" CVSS_score="6.0" CVSS_vector="(AV:N/AC:M/Au:S/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-03-21" name="CVE-2007-1526" published="2007-03-20" seq="2007-1526" severity="Medium" type="CVE"><desc><descript source="cve">Sun Java System Web Server 6.1 before 20070314 allows remote authenticated users with revoked client certificates to bypass the Certificate Revocation List (CRL) authorization control and access secure web server instances running under an account different from that used for the admin server via unspecified vectors.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102822-1">102822</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0958">
ADV-2007-0958</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017777">
1017777</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24531">
24531</ref></refs><vuln_soft><prod name="Java System Web Server" vendor="Sun"><vers num="6.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" modified="2007-03-21" name="CVE-2007-1527" published="2007-03-20" seq="2007-1527" severity="Medium" type="CVE"><desc><descript source="cve">The LLTD Mapper in Microsoft Windows Vista does not verify that an IP address in a TLV type 0x07 field in a HELLO packet corresponds to a valid IP address for the local network, which allows remote attackers to trick users into communicating with an external host by sending a HELLO packet with the MW characteristic and a spoofed TLV type 0x07 field, aka the &quot;Spoof and Management URL IP Redirect&quot; attack.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/462793/100/0/threaded">20070313 New report on Windows Vista network attack surface</ref><ref adv="1" source="" url="http://www.symantec.com/avcenter/reference/Vista_Network_Attack_Surface_RTM.pdf"></ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/464617/100/0/threaded">
20070403 Nine Vista CVEs, including Microsoft inaccurate Teredo use case documentation</ref><ref source="" url="http://www.symantec.com/enterprise/security_response/weblog/2007/04/microsofts_inaccurate_teredo_d.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/23279">
23279</ref></refs><vuln_soft><prod name="Windows Vista" vendor="Microsoft"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" modified="2007-03-21" name="CVE-2007-1528" published="2007-03-20" seq="2007-1528" severity="Medium" type="CVE"><desc><descript source="cve">The LLTD Mapper in Microsoft Windows Vista allows remote attackers to spoof hosts, and nonexistent bridge relationships, into the network topology map by using a MAC address that differs from the MAC address provided in the Real Source field of the LLTD BASE header of a HELLO packet, aka the &quot;Spoof on Bridge&quot; attack.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/462793/100/0/threaded">20070313 New report on Windows Vista network attack surface</ref><ref adv="1" source="" url="http://www.symantec.com/avcenter/reference/Vista_Network_Attack_Surface_RTM.pdf"></ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/464617/100/0/threaded">
20070403 Nine Vista CVEs, including Microsoft inaccurate Teredo use case documentation</ref><ref source="" url="http://www.symantec.com/enterprise/security_response/weblog/2007/04/microsofts_inaccurate_teredo_d.html"></ref></refs><vuln_soft><prod name="Windows Vista" vendor="Microsoft"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" modified="2007-03-21" name="CVE-2007-1529" published="2007-03-20" seq="2007-1529" severity="Medium" type="CVE"><desc><descript source="cve">The LLTD Responder in Microsoft Windows Vista does not send the Mapper a response to a DISCOVERY packet if another host has sent a spoofed response first, which allows remote attackers to spoof arbitrary hosts via a network-based race condition, aka the &quot;Total Spoof&quot; attack.</descript></desc><loss_types><int/></loss_types><vuln_types><race/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/462793/100/0/threaded">20070313 New report on Windows Vista network attack surface</ref><ref source="" url="http://www.symantec.com/avcenter/reference/Vista_Network_Attack_Surface_RTM.pdf"></ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/464617/100/0/threaded">
20070403 Nine Vista CVEs, including Microsoft inaccurate Teredo use case documentation</ref><ref source="" url="http://www.symantec.com/enterprise/security_response/weblog/2007/04/microsofts_inaccurate_teredo_d.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/23263">
23263</ref></refs><vuln_soft><prod name="Windows Vista" vendor="Microsoft"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0" modified="2007-03-21" name="CVE-2007-1530" published="2007-03-20" seq="2007-1530" severity="Medium" type="CVE"><desc><descript source="cve">The LLTD Mapper in Microsoft Windows Vista does not properly gather responses to EMIT packets, which allows remote attackers to cause a denial of service (mapping failure) by omitting an ACK response, which triggers an XML syntax error.</descript></desc><loss_types><avail/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/462793/100/0/threaded">20070313 New report on Windows Vista network attack surface</ref><ref source="" url="http://www.symantec.com/avcenter/reference/Vista_Network_Attack_Surface_RTM.pdf"></ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/464617/100/0/threaded">
20070403 Nine Vista CVEs, including Microsoft inaccurate Teredo use case documentation</ref><ref source="" url="http://www.symantec.com/enterprise/security_response/weblog/2007/04/microsofts_inaccurate_teredo_d.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/23271">
23271</ref></refs><vuln_soft><prod name="Windows Vista" vendor="Microsoft"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0" modified="2007-04-13" name="CVE-2007-1531" published="2007-03-20" seq="2007-1531" severity="Medium" type="CVE"><desc><descript source="cve">Microsoft Windows XP and Vista overwrites ARP table entries included in gratuitous ARP, which allows remote attackers to cause a denial of service (loss of network access) by sending a gratuitous ARP for the address of the Vista host.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/><design/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/462793/100/0/threaded">20070313 New report on Windows Vista network attack surface</ref><ref source="" url="http://www.symantec.com/avcenter/reference/Vista_Network_Attack_Surface_RTM.pdf"></ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/464617/100/0/threaded">20070403 Nine Vista CVEs, including Microsoft inaccurate Teredo use case documentation</ref><ref source="" url="http://www.symantec.com/enterprise/security_response/weblog/2007/04/microsofts_inaccurate_teredo_d.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/23266">
23266</ref></refs><vuln_soft><prod name="Windows Vista" vendor="Microsoft"><vers num=""/></prod><prod name="Windows XP" vendor="Microsoft"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="6.4" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="4.9" CVSS_score="6.4" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_version="2.0" modified="2007-03-21" name="CVE-2007-1532" published="2007-03-20" seq="2007-1532" severity="Medium" type="CVE"><desc><descript source="cve">The neighbor discovery implementation in Microsoft Windows Vista allows remote attackers to conduct a redirect attack by (1) responding to queries by sending spoofed Neighbor Advertisements or (2) blindly sending Neighbor Advertisements.</descript></desc><loss_types><conf/><int/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/462793/100/0/threaded">20070313 New report on Windows Vista network attack surface</ref><ref source="" url="http://www.symantec.com/avcenter/reference/Vista_Network_Attack_Surface_RTM.pdf"></ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/464617/100/0/threaded">
20070403 Nine Vista CVEs, including Microsoft inaccurate Teredo use case documentation</ref><ref source="" url="http://www.symantec.com/enterprise/security_response/weblog/2007/04/microsofts_inaccurate_teredo_d.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/23293">
23293</ref></refs><vuln_soft><prod name="Windows Vista" vendor="Microsoft"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" modified="2007-03-21" name="CVE-2007-1533" published="2007-03-20" seq="2007-1533" severity="Medium" type="CVE"><desc><descript source="cve">The Teredo implementation in Microsoft Windows Vista uses the same nonce for communication with different UDP ports within a solicitation session, which makes it easier for remote attackers to spoof the nonce through brute force attacks.</descript></desc><loss_types><int/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/462793/100/0/threaded">20070313 New report on Windows Vista network attack surface</ref><ref source="" url="http://www.symantec.com/avcenter/reference/Vista_Network_Attack_Surface_RTM.pdf"></ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/464617/100/0/threaded">
20070403 Nine Vista CVEs, including Microsoft inaccurate Teredo use case documentation</ref><ref source="" url="http://www.symantec.com/enterprise/security_response/weblog/2007/04/microsofts_inaccurate_teredo_d.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/23301">
23301</ref></refs><vuln_soft><prod name="Windows Vista" vendor="Microsoft"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" CVSS_score="9.3" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-06-29" name="CVE-2007-1534" published="2007-03-20" seq="2007-1534" severity="High" type="CVE"><desc><descript source="cve">DFSR.exe in Windows Meeting Space in Microsoft Windows Vista remains available for remote connections on TCP port 5722 for 2 minutes after Windows Meeting Space is closed, which allows remote attackers to have an unknown impact by connecting to this port during the time window.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><design/><race/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/462793/100/0/threaded">20070313 New report on Windows Vista network attack surface</ref><ref source="" url="http://www.symantec.com/avcenter/reference/Vista_Network_Attack_Surface_RTM.pdf"></ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/464617/100/0/threaded">20070403 Nine Vista CVEs, including Microsoft inaccurate Teredo use case documentation</ref><ref source="" url="http://www.symantec.com/enterprise/security_response/weblog/2007/04/microsofts_inaccurate_teredo_d.html"></ref></refs><vuln_soft><prod name="Windows Vista" vendor="Microsoft"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-05-03" name="CVE-2007-1535" published="2007-03-20" seq="2007-1535" severity="High" type="CVE"><desc><descript source="cve">Microsoft Windows Vista establishes a Teredo address without user action upon connection to the Internet, contrary to documentation that Teredo is inactive without user action, which increases the attack surface and allows remote attackers to communicate via Teredo.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><design/><config/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/462793/100/0/threaded">20070313 New report on Windows Vista network attack surface</ref><ref source="" url="http://www.symantec.com/avcenter/reference/Vista_Network_Attack_Surface_RTM.pdf"></ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/464617/100/0/threaded">20070403 Nine Vista CVEs, including Microsoft inaccurate Teredo use case documentation</ref><ref source="" url="http://www.symantec.com/enterprise/security_response/weblog/2007/04/microsofts_inaccurate_teredo_d.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/23267">23267</ref></refs><vuln_soft><prod name="Windows Vista" vendor="Microsoft"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" CVSS_score="9.3" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-06-27" name="CVE-2007-1536" published="2007-03-20" seq="2007-1536" severity="High" type="CVE"><desc><descript source="cve">Integer underflow in the file_printf function in the &quot;file&quot; program before 4.20 allows user-assisted attackers to execute arbitrary code via a file that triggers a heap-based buffer overflow.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/><user_init/></range><refs><ref patch="1" source="MLIST" url="http://mx.gw.com/pipermail/file/2007/000161.html">[file] 20070302 file-4.20 is now available</ref><ref source="" url="https://bugs.gentoo.org/show_bug.cgi?id=171452"></ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/24548">24548</ref><ref source="" url="https://issues.rpath.com/browse/RPL-1148"></ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2007:067">MDKSA-2007:067</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2007-0124.html">RHSA-2007:0124</ref><ref source="UBUNTU" url="http://www.ubuntu.com/usn/usn-439-1">USN-439-1</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/606700">VU#606700</ref><ref source="BID" url="http://www.securityfocus.com/bid/23021">23021</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1040">ADV-2007-1040</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017796">1017796</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24604">24604</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24616">24616</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24617">24617</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24592">24592</ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200703-26.xml">GLSA-200703-26</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24608">24608</ref><ref source="DEBIAN" url="http://www.debian.org/security/2007/dsa-1274">DSA-1274</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2007_5_sr.html">SUSE-SR:2007:005</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24723">24723</ref><ref source="SLACKWARE" url="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2007&amp;m=slackware-security.512926">SSA:2007-093-01</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24754">24754</ref><ref source="" url="http://support.avaya.com/elmodocs2/security/ASA-2007-179.htm"></ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/25133">25133</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/477861/100/0/threaded">20070825 OpenBSD 4.1 - Heap overflow vulnerabillity</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/477950/100/0/threaded">20070828 Re: OpenBSD 4.1 - Heap overflow vulnerabillity</ref><ref source="" url="http://docs.info.apple.com/article.html?artnum=305530"></ref><ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2007/May/msg00004.html">APPLE-SA-2007-05-24</ref><ref source="FREEBSD" url="http://security.freebsd.org/advisories/FreeBSD-SA-07:04.file.asc">FreeBSD-SA-07:04</ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200710-19.xml">GLSA-200710-19</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:067">MDKSA-2007:067</ref><ref source="OPENBSD" url="http://openbsd.org/errata40.html#015_file">[4.0] 20070709 015: SECURITY FIX: July 9, 2007</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2007_40_file.html">SUSE-SA:2007:040</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1939">ADV-2007-1939</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25393">25393</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25402">25402</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25931">25931</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25989">25989</ref><ref source="SECUNIA" url="http://secunia.com/advisories/27307">27307</ref><ref source="SECUNIA" url="http://secunia.com/advisories/27314">27314</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/36283">openbsd-file-bo(36283)</ref><ref source="NETBSD" url="ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2008-001.txt.asc">NetBSD-SA2008-001</ref><ref source="SECUNIA" url="http://secunia.com/advisories/29179">29179</ref></refs><vuln_soft><prod name="file" vendor="file"><vers num="4.19" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="3.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="4.9" CVSS_score="3.6" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:P)" CVSS_version="2.0" modified="2007-04-10" name="CVE-2007-1537" published="2007-03-20" seq="2007-1537" severity="Low" type="CVE"><desc><descript source="cve">\Device\NdisTapi (NDISTAPI.sys) in Microsoft Windows XP SP2 and 2003 SP1 uses weak permissions, which allows local users to write to the device and cause a denial of service, as demonstrated by using an IRQL to acquire a spinlock on paged memory via the NdisTapiDispatch function.</descript></desc><loss_types><avail/><int/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/463208/100/0/threaded">20070319 [Reversemode Advisory] Microsoft Windows Ndistapi.sys IRQL escalation</ref><ref source="" url="http://www.reversemode.com/index.php?option=com_remository&amp;Itemid=2&amp;func=fileinfo&amp;id=47"></ref><ref source="BID" url="http://www.securityfocus.com/bid/23025">23025</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1031">ADV-2007-1031</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24598">24598</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33086">windows-ndistapi-dos(33086)</ref><ref source="OSVDB" url="http://www.osvdb.org/33628">
33628</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2471">2471</ref></refs><vuln_soft><prod name="Windows XP" vendor="Microsoft"><vers num="SP2"/></prod><prod name="Windows 2003" vendor="Microsoft"><vers num="SP1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-03-21" name="CVE-2007-1538" published="2007-03-20" seq="2007-1538" severity="High" type="CVE"><desc><descript source="cve">** DISPUTED **  McAfee VirusScan Enterprise 8.5.0.i uses insecure permissions for certain Windows Registry keys, which allows local users to bypass local password protection via the UIP value in (1) HKEY_LOCAL_MACHINE\SOFTWARE\McAfee\DesktopProtection or (2) HKEY_LOCAL_MACHINE\SOFTWARE\Network Associates\TVD\VirusScan Entreprise\CurrentVersion.  NOTE: this issue has been disputed by third-party researchers, stating that the default permissions for HKEY_LOCAL_MACHINE\SOFTWARE does not allow for write access and the product does not modify the inherited permissions. There might be an interaction error with another product.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/463074/100/0/threaded">20070317 Bypassing Mcafee Entreprise Password Protection</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/463091/100/0/threaded">20070317 Re: Bypassing Mcafee Entreprise Password Protection</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/463187/100/0/threaded">20070319 RE: Bypassing Mcafee Entreprise Password Protection</ref><ref source="" url="http://homepage.mac.com/adonismac/Advisory/bypass_mcafee_entreprise_password.html"></ref><ref source="" url="http://homepage.mac.com/adonismac/Advisory/crack_mcafee_password_protection.html"></ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017791">1017791</ref><ref source="OSVDB" url="http://www.osvdb.org/33800">
33800</ref></refs><vuln_soft><prod name="VirusScan Enterprise" vendor="McAfee"><vers num="8.5.0.i"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)" CVSS_version="2.0" modified="2007-03-22" name="CVE-2007-1539" published="2007-03-20" seq="2007-1539" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in inc/map.func.php in pragmaMX Landkarten 2.1 module allows remote attackers to include arbitrary files via a .. (dot dot) sequence in the module_name parameter, as demonstrated via a static PHP code injection attack in an Apache log file.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MILW0RM" url="http://milw0rm.com/exploits/3521">3521</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24589">24589</ref><ref source="BID" url="http://www.securityfocus.com/bid/23044">
23044</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1030">
ADV-2007-1030</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33084">
pragma-mapfunc-file-include(33084)</ref></refs><vuln_soft><prod name="Landkarten" vendor="PragmaMX"><vers num="2.1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)" CVSS_version="2.0" modified="2007-04-13" name="CVE-2007-1540" published="2007-03-20" seq="2007-1540" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in am.pl in (1) SQL-Ledger 2.6.27 and earlier, and (2) LedgerSMB before 1.2.0, allows remote attackers to run arbitrary executables and bypass authentication via a .. (dot dot) sequence and trailing NULL (%00) in the login parameter.  NOTE: this issue was reportedly addressed in SQL-Ledger 2.6.27, however third-party researchers claim that the file is still executed even though an error is generated.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/463175/100/0/threaded">20070318 Full Disclosure: Arbitrary execution vulnerability in SQL-Ledger and LedgerSMB</ref><ref patch="1" source="" url="http://sourceforge.net/project/shownotes.php?release_id=494462&amp;group_id=175965"></ref><ref adv="1" source="" url="http://sql-ledger.com/cgi-bin/nav.pl?page=news.html&amp;title=What&apos;s%20New"></ref><ref source="BID" url="http://www.securityfocus.com/bid/23034">23034</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24560">24560</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24585">24585</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1024">ADV-2007-1024</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1025">ADV-2007-1025</ref><ref source="OSVDB" url="http://www.osvdb.org/33624">33624</ref></refs><vuln_soft><prod name="SQL-Ledger" vendor="SQL-Ledger"><vers num="2.6.27" prev="1"/></prod><prod name="LedgerSMB" vendor="LedgerSMB"><vers num="1.1.8" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-03-22" name="CVE-2007-1541" published="2007-03-20" seq="2007-1541" severity="High" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in am.pl in SQL-Ledger 2.6.27 only checks for the presence of a NULL (%00) character to protect against directory traversal attacks, which allows remote attackers to run arbitrary executables and bypass authentication via a .. (dot dot) sequence in the login parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/463175/100/0/threaded">20070318 Full Disclosure: Arbitrary execution vulnerability in SQL-Ledger and LedgerSMB</ref><ref patch="1" source="" url="http://sql-ledger.com/cgi-bin/nav.pl?page=news.html&amp;title=What&apos;s%20New"></ref><ref source="BID" url="http://www.securityfocus.com/bid/23034">23034</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24560">24560</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1025">
ADV-2007-1025</ref></refs><vuln_soft><prod name="SQL-Ledger" vendor="SQL-Ledger"><vers num="2.6.27"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0" modified="2007-03-22" name="CVE-2007-1542" published="2007-03-20" seq="2007-1542" severity="Medium" type="CVE"><desc><descript source="cve">Unspecified vulnerability in the Cisco IP Phone 7940 and 7960 running firmware before POS8-6-0 allows remote attackers to cause a denial of service via the Remote-Party-ID sipURI field in a SIP INVITE request. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BID" url="http://www.securityfocus.com/bid/23047">23047</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1023">ADV-2007-1023</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24600">24600</ref><ref source="CISCO" url="http://www.cisco.com/en/US/products/products_security_response09186a00808075ad.html">

20070320 Cisco IP Phone 7940/7960 SIP INVITE Denial of Service</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017797">
1017797</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33098">
cisco-ipphone-sip-invite-dos(33098)</ref></refs><vuln_soft><prod name="7960" vendor="Cisco"><vers num=""/></prod><prod name="7940" vendor="Cisco"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-03-22" name="CVE-2007-1543" published="2007-03-20" seq="2007-1543" severity="High" type="CVE"><desc><descript source="cve">Stack-based buffer overflow in the accept_att_local function in server/os/connection.c in Network Audio System (NAS) before 1.8a SVN 237 allows remote attackers to execute arbitrary code via a long path slave name in a USL socket connection.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="" url="http://aluigi.altervista.org/adv/nasbugs-adv.txt"></ref><ref source="BID" url="http://www.securityfocus.com/bid/23017">23017</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0997">ADV-2007-0997</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24527">24527</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33047">nas-uslsocket-bo(33047)</ref><ref source="DEBIAN" url="http://www.debian.org/security/2007/dsa-1273">
DSA-1273</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:065">
MDKSA-2007:065</ref><ref source="UBUNTU" url="http://www.ubuntu.com/usn/usn-446-1">
USN-446-1</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24601">
24601</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24628">
24628</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24638">
24638</ref><ref source="" url="http://www.radscan.com/nas/HISTORY"></ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017822">
1017822</ref><ref source="" url="https://issues.rpath.com/browse/RPL-1155"></ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200704-20.xml">
GLSA-200704-20</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24980">
24980</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24783">
24783</ref></refs><vuln_soft><prod name="Network Audio System" vendor="Radscan"><vers num="1.8a"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0" modified="2007-03-22" name="CVE-2007-1544" published="2007-03-20" seq="2007-1544" severity="Medium" type="CVE"><desc><descript source="cve">Integer overflow in the ProcAuWriteElement function in server/dia/audispatch.c in Network Audio System (NAS) before 1.8a SVN 237 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a large max_samples value.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="" url="http://aluigi.altervista.org/adv/nasbugs-adv.txt"></ref><ref source="BID" url="http://www.securityfocus.com/bid/23017">23017</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0997">ADV-2007-0997</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24527">24527</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33051">nas-procauwriteelement-dos(33051)</ref><ref source="DEBIAN" url="http://www.debian.org/security/2007/dsa-1273">
DSA-1273</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:065">
MDKSA-2007:065</ref><ref source="UBUNTU" url="http://www.ubuntu.com/usn/usn-446-1">
USN-446-1</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24601">
24601</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24628">
24628</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24638">
24638</ref><ref source="" url="http://www.radscan.com/nas/HISTORY"></ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017822">
1017822</ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200704-20.xml">
GLSA-200704-20</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24980">
24980</ref></refs><vuln_soft><prod name="Network Audio System" vendor="Radscan"><vers num="1.8a"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0" modified="2007-03-22" name="CVE-2007-1545" published="2007-03-20" seq="2007-1545" severity="Medium" type="CVE"><desc><descript source="cve">The AddResource function in server/dia/resource.c in Network Audio System (NAS) before 1.8a SVN 237 allows remote attackers to cause a denial of service (server crash) via a nonexistent client ID.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="" url="http://aluigi.altervista.org/adv/nasbugs-adv.txt"></ref><ref source="BID" url="http://www.securityfocus.com/bid/23017">23017</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0997">ADV-2007-0997</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24527">24527</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33050">nas-addresource-dos(33050)</ref><ref source="DEBIAN" url="http://www.debian.org/security/2007/dsa-1273">
DSA-1273</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:065">
MDKSA-2007:065</ref><ref source="UBUNTU" url="http://www.ubuntu.com/usn/usn-446-1">
USN-446-1</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24601">
24601</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24628">
24628</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24638">
24638</ref><ref source="" url="http://www.radscan.com/nas/HISTORY"></ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017822">
1017822</ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200704-20.xml">
GLSA-200704-20</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24980">
24980</ref></refs><vuln_soft><prod name="Network Audio System" vendor="Radscan"><vers num="1.8a"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0" modified="2007-03-22" name="CVE-2007-1546" published="2007-03-20" seq="2007-1546" severity="Medium" type="CVE"><desc><descript source="cve">Array index error in Network Audio System (NAS) before 1.8a SVN 237 allows remote attackers to cause a denial of service (crash) via (1) large num_action values in the ProcAuSetElements function in server/dia/audispatch.c or (2) a large inputNum parameter to the compileInputs function in server/dia/auutil.c.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="" url="http://aluigi.altervista.org/adv/nasbugs-adv.txt"></ref><ref source="BID" url="http://www.securityfocus.com/bid/23017">23017</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0997">ADV-2007-0997</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24527">24527</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33054">nas-procausetelements-dos(33054)</ref><ref source="DEBIAN" url="http://www.debian.org/security/2007/dsa-1273">
DSA-1273</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:065">
MDKSA-2007:065</ref><ref source="UBUNTU" url="http://www.ubuntu.com/usn/usn-446-1">
USN-446-1</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24601">
24601</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24628">
24628</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24638">
24638</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33055">
nas-compileinputs-dos(33055)</ref><ref source="" url="http://www.radscan.com/nas/HISTORY"></ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017822">
1017822</ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200704-20.xml">
GLSA-200704-20</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24980">
24980</ref></refs><vuln_soft><prod name="Network Audio System" vendor="Radscan"><vers num="1.8a"/></prod></vuln_soft></entry><entry CVSS_base_score="7.8" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.9" CVSS_score="7.8" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_version="2.0" modified="2007-03-22" name="CVE-2007-1547" published="2007-03-20" seq="2007-1547" severity="High" type="CVE"><desc><descript source="cve">The ReadRequestFromClient function in server/os/io.c in Network Audio System (NAS) before 1.8a SVN 237 allows remote attackers to cause a denial of service (crash) via multiple simultaneous connections, which triggers a NULL pointer dereference.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="" url="http://aluigi.altervista.org/adv/nasbugs-adv.txt"></ref><ref source="BID" url="http://www.securityfocus.com/bid/23017">23017</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0997">ADV-2007-0997</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24527">24527</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33059">nas-readrequestfromclient-dos(33059)</ref><ref source="DEBIAN" url="http://www.debian.org/security/2007/dsa-1273">
DSA-1273</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:065">
MDKSA-2007:065</ref><ref source="UBUNTU" url="http://www.ubuntu.com/usn/usn-446-1">
USN-446-1</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24601">
24601</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24628">
24628</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24638">
24638</ref><ref source="" url="http://www.radscan.com/nas/HISTORY"></ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017822">
1017822</ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200704-20.xml">
GLSA-200704-20</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24980">
24980</ref></refs><vuln_soft><prod name="Network Audio System" vendor="Radscan"><vers num="1.8a"/><vers num="1.8a"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2008-08-18" name="CVE-2007-1548" published="2007-03-20" seq="2007-1548" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in functions/functions_filters.asp in Web Wiz Forums before 8.05a (MySQL version) does not properly filter certain characters in SQL commands, which allows remote attackers to execute arbitrary SQL commands via \&quot;&apos; (backslash double-quote quote) sequences, which are collapsed into \&apos;, as demonstrated via the name parameter to forum/pop_up_member_search.asp.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/463287/100/0/threaded">20070320 Web Wiz Forums 8.05 (MySQL version) SQL Injection</ref><ref source="" url="http://ifsec.blogspot.com/2007/03/web-wiz-forums-805-mysql-version-sql.html"></ref><ref patch="1" source="" url="http://www.webwizguide.info/web_wiz_forums/Version%20History.txt"></ref><ref source="BID" url="http://www.securityfocus.com/bid/23051">23051</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1061">ADV-2007-1061</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24561">24561</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33095">webwizforums-popupmember-sql-injection(33095)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2456">2456</ref></refs><vuln_soft><prod name="Web Wiz Forums" vendor="Web Wiz Forums"><vers num="8.04" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-03-22" name="CVE-2007-1549" published="2007-03-20" seq="2007-1549" severity="Medium" type="CVE"><desc><descript source="cve">Unrestricted file upload vulnerability in gallery.php in phpx 3.5.15 allows remote attackers to upload and execute arbitrary PHP scripts via an addImage action, which places scripts into the gallery/shelties/ directory.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/463192/100/0/threaded">20070319 phpx 3.5.15 multiples vulnerabilities</ref><ref source="BID" url="http://www.securityfocus.com/bid/23033">23033</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33151">
phpx-gallery-file-upload(33151)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2457">2457</ref></refs><vuln_soft><prod name="PHPX" vendor="PHPX"><vers num="3.5.9" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-03-22" name="CVE-2007-1550" published="2007-03-20" seq="2007-1550" severity="High" type="CVE"><desc><descript source="cve">Multiple SQL injection vulnerabilities in phpx 3.5.15 allow remote attackers to execute arbitrary SQL commands via the (1) image_id or (2) cat_id parameter to (a) gallery.php; the (3) news_id parameter to (b) news.php or (c) print.php; (4) the news_cat_id parameter to news.php; the (5) cat_id, (6) topic_id, or (7) post_id parameter to (d) forums.php; or (8) the user_id parameter to (e) users.php.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/463192/100/0/threaded">20070319 phpx 3.5.15 multiples vulnerabilities</ref><ref source="BID" url="http://www.securityfocus.com/bid/23033">23033</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1087">
ADV-2007-1087</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24565">
24565</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33155">
phpx-multiple-sql-injection(33155)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2457">2457</ref></refs><vuln_soft><prod name="PHPX" vendor="PHPX"><vers num="3.5.15" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" modified="2007-03-22" name="CVE-2007-1551" published="2007-03-20" seq="2007-1551" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in phpx 3.5.15 allow remote attackers to inject arbitrary web script or HTML via (1) the signature in &quot;dans profile,&quot; or (2) search.php.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/463192/100/0/threaded">20070319 phpx 3.5.15 multiples vulnerabilities</ref><ref source="BID" url="http://www.securityfocus.com/bid/23033">23033</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1087">
ADV-2007-1087</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24565">
24565</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33153">
phpx-signature-xss(33153)</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33154">
phpx-search-xss(33154)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2457">2457</ref></refs><vuln_soft><prod name="PHPX" vendor="PHPX"><vers num="3.5.15"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-03-22" name="CVE-2007-1552" published="2007-03-20" seq="2007-1552" severity="High" type="CVE"><desc><descript source="cve">Unrestricted file upload vulnerability in usercp.php in MetaForum 0.513 Beta restricts file types based on the MIME type in the Content-type HTTP header, which allows remote attackers to upload and execute arbitrary scripts via an image MIME type with a filename containing an executable extension such as .php.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/463178/100/0/threaded">20070318 MetaForum &lt;= 0.513 Beta - Remote file upload Vulnerability</ref><ref source="" url="http://www.aeroxteam.fr/exploit-MetaForum-0.513b.txt"></ref><ref source="BID" url="http://www.securityfocus.com/bid/23032">23032</ref><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3516">
3516</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33097">
metaforum-mime-file-upload(33097)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2454">2454</ref></refs><vuln_soft><prod name="MetaForum" vendor="MetaForum"><vers num="0.513 Beta"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" modified="2007-03-22" name="CVE-2007-1553" published="2007-03-20" seq="2007-1553" severity="Medium" type="CVE"><desc><descript source="cve">admin/configuration.php in Guestbara 1.2 and earlier allows remote attackers to modify the e-mail, name, and password of the admin account by setting the zapis parameter to &quot;ok&quot; and providing modified admin_mail, login, and pass parameters.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3506">3506</ref></refs><vuln_soft><prod name="Guestbara" vendor="Guestbara"><vers num="1.2" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-03-22" name="CVE-2007-1554" published="2007-03-20" seq="2007-1554" severity="Medium" type="CVE"><desc><descript source="cve">Direct static code injection vulnerability in admin/configuration.php in Guestbara 1.2 and earlier allows remote authenticated users to inject arbitrary PHP code into config.php via the (1) admin_mail, (2) emotpatch, (3) login, (4) pass, and unspecified other parameters. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1010">ADV-2007-1010</ref><ref source="OSVDB" url="http://www.osvdb.org/33783">
33783</ref></refs><vuln_soft><prod name="Guestbara" vendor="Guestbara"><vers num="1.2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-03-22" name="CVE-2007-1555" published="2007-03-20" seq="2007-1555" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in forum.php in the Minerva mod 2.0.21 build 238a and earlier for phpBB allows remote attackers to execute arbitrary SQL commands via the c parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3519">3519</ref><ref source="BID" url="http://www.securityfocus.com/bid/23036">23036</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1028">
ADV-2007-1028</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33082">
minerva-forum-sql-injection(33082)</ref><ref source="OSVDB" url="http://www.osvdb.org/33748">
33748</ref></refs><vuln_soft><prod name="Minerva" vendor="Minerva"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-03-22" name="CVE-2007-1556" published="2007-03-20" seq="2007-1556" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in kommentare.php in Creative Files 1.2 allows remote attackers to execute arbitrary SQL commands via the dlid parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3498">3498</ref><ref source="BID" url="http://www.securityfocus.com/bid/23000">23000</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33021">creative-kommentare-sql-injection(33021)</ref></refs><vuln_soft><prod name="Creative Files" vendor="thecreativeheads.de"><vers num="1.2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-03-22" name="CVE-2007-1557" published="2007-03-20" seq="2007-1557" severity="High" type="CVE"><desc><descript source="cve">Format string vulnerability in F-Secure Anti-Virus Client Security 6.02 allows local users to cause a denial of service and possibly gain privileges via format string specifiers in the Management Server name field on the Communication settings page.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input/></vuln_types><range><local/></range><refs><ref patch="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/463190/100/0/threaded">20070319 Layered Defense Research Advisory: F-Secure Anti-Virus Client Security 6.02 Format String Vulnerability</ref><ref adv="1" patch="1" source="" url="http://www.layereddefense.com/F-SecureMar18.html"></ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/23023">23023</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1055">
ADV-2007-1055</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2472">2472</ref></refs><vuln_soft><prod name="F-Secure Anti-Virus" vendor="F-Secure"><vers edition="Client Security" num="6.02"/></prod></vuln_soft></entry><entry CVSS_base_score="2.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="2.9" CVSS_score="2.6" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:N/A:N)" CVSS_version="2.0" modified="2008-01-02" name="CVE-2007-1558" published="2007-04-16" seq="2007-1558" severity="Low" type="CVE"><desc><descript source="cve">The APOP protocol allows remote attackers to guess the first 3 characters of a password via man-in-the-middle (MITM) attacks that use crafted message IDs and MD5 collisions.  NOTE: this design-level issue potentially affects all products that use APOP, including (1) Thunderbird 1.x before 1.5.0.12 and 2.x before 2.0.0.4, (2) Evolution, (3) mutt, (4) fetchmail, (5) SeaMonkey 1.0.x before 1.0.9 and 1.1.x before 1.1.2, (6) Balsa 2.3.16 and earlier, and possibly other products.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/2788">ADV-2007-2788</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25353">25353</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25402">25402</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25476">25476</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25529">25529</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25546">25546</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25496">25496</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25559">25559</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25534">25534</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25664">25664</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25750">25750</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25798">25798</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25894">25894</ref><ref source="SECUNIA" url="http://secunia.com/advisories/26083">26083</ref><ref source="SECUNIA" url="http://secunia.com/advisories/26415">26415</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25858">25858</ref><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/464477/30/0/threaded">20070402 APOP vulnerability</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/464569/100/0/threaded">20070403 Re: APOP vulnerability</ref><ref source="" url="http://fetchmail.berlios.de/fetchmail-SA-2007-01.txt"></ref><ref source="" url="http://sourceforge.net/forum/forum.php?forum_id=683706"></ref><ref source="" url="http://sylpheed.sraoss.jp/en/news.html"></ref><ref source="" url="http://www.claws-mail.org/news.php"></ref><ref source="BID" url="http://www.securityfocus.com/bid/23257">23257</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1466">ADV-2007-1466</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1467">ADV-2007-1467</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1468">ADV-2007-1468</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1480">ADV-2007-1480</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2007:105">MDKSA-2007:105</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2007-0353.html">RHSA-2007:0353</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1018008">1018008</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/471455/100/0/threaded">20070615 rPSA-2007-0122-1 evolution-data-server</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/471720/100/0/threaded">20070619 FLEA-2007-0026-1: evolution-data-server</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/470172/100/200/threaded">20070531 FLEA-2007-0023-1: firefox</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/471842/100/0/threaded">20070620 FLEA-2007-0027-1: thunderbird</ref><ref source="MLIST" url="http://mail.gnome.org/archives/balsa-list/2007-July/msg00000.html">[balsa-list] 20070704 balsa-2.3.17 released</ref><ref source="" url="http://docs.info.apple.com/article.html?artnum=305530"></ref><ref source="" url="http://www.mozilla.org/security/announce/2007/mfsa2007-15.html"></ref><ref source="" url="https://issues.rpath.com/browse/RPL-1424"></ref><ref source="" url="https://issues.rpath.com/browse/RPL-1232"></ref><ref source="" url="https://issues.rpath.com/browse/RPL-1231"></ref><ref source="" url="http://balsa.gnome.org/download.html"></ref><ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2007/May/msg00004.html">APPLE-SA-2007-05-24</ref><ref source="DEBIAN" url="http://www.debian.org/security/2007/dsa-1300">DSA-1300</ref><ref source="DEBIAN" url="http://www.debian.org/security/2007/dsa-1305">DSA-1305</ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200706-06.xml">GLSA-200706-06</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:105">MDKSA-2007:105</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:107">MDKSA-2007:107</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:113">MDKSA-2007:113</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:119">MDKSA-2007:119</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:131">MDKSA-2007:131</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2007-0344.html">RHSA-2007:0344</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2007-0386.html">RHSA-2007:0386</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2007-0385.html">RHSA-2007:0385</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2007-0401.html">RHSA-2007:0401</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2007-0402.html">RHSA-2007:0402</ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20070602-01-P.asc">20070602-01-P</ref><ref source="SLACKWARE" url="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2007&amp;m=slackware-security.571857">SSA:2007-152-02</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2007_36_mozilla.html">SUSE-SA:2007:036</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2007_14_sr.html">SUSE-SR:2007:014</ref><ref source="TRUSTIX" url="http://www.trustix.org/errata/2007/0019/">2007-0019</ref><ref source="TRUSTIX" url="http://www.trustix.org/errata/2007/0024/">2007-0024</ref><ref source="UBUNTU" url="http://www.ubuntu.com/usn/usn-469-1">USN-469-1</ref><ref source="UBUNTU" url="http://www.ubuntu.com/usn/usn-520-1">USN-520-1</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA07-151A.html">TA07-151A</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1939">ADV-2007-1939</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1994">ADV-2007-1994</ref><ref source="HP" url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00771742">HPSBUX02153</ref><ref source="HP" url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00774579">HPSBUX02156</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/0082">ADV-2008-0082</ref></refs><vuln_soft><prod name="APOP Protocol" vendor="APOP Protocol"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" CVSS_score="9.3" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-04-17" name="CVE-2007-1559" published="2007-04-11" seq="2007-1559" severity="High" type="CVE"><desc><descript source="cve">Stack-based buffer overflow in SonicDVDDashVRNav.dll in Roxio CinePlayer 3.2 allows remote attackers to execute arbitrary code via unspecified properties and methods in the SonicDVDDashVRNav.dll ActiveX control.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" source="" url="http://secunia.com/secunia_research/2007-46/advisory/"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1337">ADV-2007-1337</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/22251">22251</ref><ref source="BID" url="http://www.securityfocus.com/bid/23412">
23412</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017906">
1017906</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33590">
cineplayer-sonicmediaplayer-bo(33590)</ref></refs><vuln_soft><prod name="CinePlayer" vendor="Roxio"><vers num="3.2"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0" modified="2007-04-02" name="CVE-2007-1560" published="2007-03-21" seq="2007-1560" severity="Medium" type="CVE"><desc><descript source="cve">The clientProcessRequest() function in src/client_side.c in Squid 2.6 before 2.6.STABLE12 allows remote attackers to cause a denial of service (daemon crash) via crafted TRACE requests that trigger an assertion error.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="" url="http://www.squid-cache.org/Advisories/SQUID-2007_1.txt"></ref><ref source="" url="http://www.squid-cache.org/Versions/v2/2.6/changesets/11349.patch"></ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1035">ADV-2007-1035</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/24611">24611</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2007:068">MDKSA-2007:068</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017805">1017805</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24614">24614</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24625">24625</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33124">squid-clientprocessrequest-dos(33124)</ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200703-27.xml">
GLSA-200703-27</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24662">
24662</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2007_5_sr.html">
SUSE-SR:2007:005</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2007-0131.html">
RHSA-2007:0131</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24911">
24911</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:068">MDKSA-2007:068</ref><ref source="UBUNTU" url="http://www.ubuntu.com/usn/usn-441-1">USN-441-1</ref><ref source="BID" url="http://www.securityfocus.com/bid/23085">23085</ref></refs><vuln_soft><prod name="Squid" vendor="Squid"><vers num="2.6.STABLE1"/><vers num="2.6.STABLE10"/><vers num="2.6.STABLE11"/><vers num="2.6.STABLE2"/><vers num="2.6.STABLE3"/><vers num="2.6.STABLE4"/><vers num="2.6.STABLE5"/><vers num="2.6.STABLE6"/><vers num="2.6.STABLE7"/><vers num="2.6.STABLE8"/><vers num="2.6.STABLE9"/></prod></vuln_soft></entry><entry CVSS_base_score="7.8" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.9" CVSS_score="7.8" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_version="2.0" modified="2007-04-09" name="CVE-2007-1561" published="2007-03-21" seq="2007-1561" severity="High" type="CVE"><desc><descript source="cve">The channel driver in Asterisk before 1.2.17 and 1.4.x before 1.4.2 allows remote attackers to cause a denial of service (crash) via a SIP INVITE message with an SDP containing one valid and one invalid IP address.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="FULLDISC" url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=117432783011737&amp;w=2">20070319 Asterisk SDP DOS vulnerability</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/23031">23031</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1039">ADV-2007-1039</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017794">1017794</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33068">asterisk-sip-invite-dos(33068)</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/463434/100/0/threaded">20070321 Two new DoS Vulnerabilities in Asterisk Fixed</ref><ref source="MLIST" url="http://voipsa.org/pipermail/voipsec_voipsa.org/2007-March/002275.html">[VOIPSEC] 20070319 Asterisk SDP DOS vulnerability</ref><ref source="" url="http://asterisk.org/node/48339"></ref><ref source="" url="http://www.sineapps.com/news.php?rssid=1707"></ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200704-01.xml">
GLSA-200704-01</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24719">
24719</ref><ref source="DEBIAN" url="http://www.debian.org/security/2007/dsa-1358">DSA-1358</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2007_34_asterisk.html">SUSE-SA:2007:034</ref><ref source="OSVDB" url="http://www.osvdb.org/34479">34479</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25582">25582</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24564">24564</ref></refs><vuln_soft><prod name="Asterisk" vendor="Asterisk"><vers num="1.2.14"/><vers num="1.2.15"/><vers num="1.2.16"/><vers num="1.4.1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-04-09" name="CVE-2007-1562" published="2007-03-21" seq="2007-1562" severity="Medium" type="CVE"><desc><descript source="cve">The FTP protocol implementation in Mozilla Firefox before 1.5.0.11 and 2.x before 2.0.0.3 allows remote attackers to force the client to connect to other servers, perform a proxied port scan, or obtain sensitive information by specifying an alternate server address in an FTP PASV response.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input/><design/></vuln_types><range><network/><user_init/></range><refs><ref source="" url="http://bindshell.net/papers/ftppasv/ftp-client-pasv-manipulation.pdf"></ref><ref source="" url="https://bugzilla.mozilla.org/show_bug.cgi?id=370559"></ref><ref source="" url="http://www.mozilla.org/security/announce/2007/mfsa2007-11.html"></ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1034">ADV-2007-1034</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/463501/100/0/threaded">20070322 FLEA-2007-0001-1: firefox</ref><ref source="UBUNTU" url="http://www.ubuntu.com/usn/usn-443-1">USN-443-1</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33119">firefox-nsftpstate-information-disclosure(33119)</ref><ref source="" url="https://issues.rpath.com/browse/RPL-1157"></ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/470172/100/200/threaded">20070531 FLEA-2007-0023-1: firefox</ref><ref source="" url="https://issues.rpath.com/browse/RPL-1424"></ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2007-0400.html">RHSA-2007:0400</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2007-0402.html">RHSA-2007:0402</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2007_36_mozilla.html">SUSE-SA:2007:036</ref><ref source="BID" url="http://www.securityfocus.com/bid/23082">23082</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017800">1017800</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25476">25476</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25490">25490</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25858">25858</ref><ref source="HP" url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00771742">HPSBUX02153</ref></refs><vuln_soft><prod name="Firefox" vendor="Mozilla"><vers num="2.0.0.2" prev="1"/><vers num="1.5.0.10" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-04-09" name="CVE-2007-1563" published="2007-03-21" seq="2007-1563" severity="Medium" type="CVE"><desc><descript source="cve">The FTP protocol implementation in Opera 9.10 allows remote attackers to allows remote servers to force the client to connect to other servers, perform a proxied port scan, or obtain sensitive information by specifying an alternate server address in an FTP PASV response.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input/><design/></vuln_types><range><network/><user_init/></range><refs><ref source="" url="http://bindshell.net/papers/ftppasv/ftp-client-pasv-manipulation.pdf"></ref><ref source="BID" url="http://www.securityfocus.com/bid/23089">23089</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1075">ADV-2007-1075</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2007_28_opera.html">
SUSE-SA:2007:028</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25027">
25027</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017802">1017802</ref></refs><vuln_soft><prod name="Opera" vendor="Opera Software"><vers num="9.10"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-04-09" name="CVE-2007-1564" published="2007-03-21" seq="2007-1564" severity="Medium" type="CVE"><desc><descript source="cve">The FTP protocol implementation in Konqueror 3.5.5 allows remote servers to force the client to connect to other servers, perform a proxied port scan, or obtain sensitive information by specifying an alternate server address in an FTP PASV response.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input/><design/></vuln_types><range><network/><user_init/></range><refs><ref source="" url="http://bindshell.net/papers/ftppasv/ftp-client-pasv-manipulation.pdf"></ref><ref source="UBUNTU" url="http://www.ubuntu.com/usn/usn-447-1">USN-447-1</ref><ref source="BID" url="http://www.securityfocus.com/bid/23091">23091</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1076">ADV-2007-1076</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1017801">1017801</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2007:072">
MDKSA-2007:072</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2007_6_sr.html">
SUSE-SR:2007:006</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24889">
24889</ref><ref source="" url="https://issues.rpath.com/browse/RPL-1201"></ref><ref source="" url="http://www.kde.org/info/security/advisory-20070326-1.txt"></ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:072">MDKSA-2007:072</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2007-0909.html">RHSA-2007:0909</ref><ref source="SECUNIA" url="http://secunia.com/advisories/27108">27108</ref></refs><vuln_soft><prod name="Konqueror" vendor="KDE"><vers num="3.5.5"/></prod></vuln_soft></entry><entry CVSS_base_score="7.8" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.9" CVSS_score="7.8" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_version="2.0" modified="2007-03-22" name="CVE-2007-1565" published="2007-03-21" seq="2007-1565" severity="High" type="CVE"><desc><descript source="cve">Konqueror 3.5.5 allows remote attackers to cause a denial of service (crash) by using JavaScript to read a child iframe having an ftp:// URI.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="" url="http://bindshell.net/papers/ftppasv/ftp-client-pasv-manipulation.pdf"></ref></refs><vuln_soft><prod name="Konqueror" vendor="KDE"><vers num="3.5.5"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-03-22" name="CVE-2007-1566" published="2007-03-21" seq="2007-1566" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in News/page.asp in NetVIOS Portal allows remote attackers to execute arbitrary SQL commands via the NewsID parameter.  NOTE: this issue might be the same as CVE-2006-5954.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3520">3520</ref><ref source="BID" url="http://www.securityfocus.com/bid/23045">23045</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33072">netviosportal-page-sql-injection(33072)</ref></refs><vuln_soft><prod name="NetVIOS" vendor="NetVIOS"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-03-22" name="CVE-2007-1567" published="2007-03-21" seq="2007-1567" severity="High" type="CVE"><desc><descript source="cve">Stack-based buffer overflow in War FTP Daemon 1.65, and possibly earlier, allows remote attackers to cause a denial of service or execute arbitrary code via unspecified vectors, as demonstrated by warftp_165.tar by Immunity.  NOTE: this might be the same issue as CVE-1999-0256, CVE-2000-0131, or CVE-2006-2171, but due to Immunity&apos;s lack of details, this cannot be certain.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref patch="1" source="" url="https://www.immunityinc.com/downloads/immpartners/warftp_165.tar"></ref><ref source="BID" url="http://www.securityfocus.com/bid/22944">22944</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0933">ADV-2007-0933</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24494">24494</ref></refs><vuln_soft><prod name="War FTP Daemon" vendor="War FTP Daemon"><vers num="1.65" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-03-22" name="CVE-2007-1568" published="2007-03-21" seq="2007-1568" severity="High" type="CVE"><desc><descript source="cve">Stack-based buffer overflow in DaanSystems NewsReactor 20070220.21 allows remote attackers to execute arbitrary code via a yEnc (yEncode) encoded article with a long filename.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3462">3462</ref><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3463">3463</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0934">ADV-2007-0934</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24487">24487</ref></refs><vuln_soft><prod name="NewsReactor" vendor="DaanSystems"><vers num="2007-02-21"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-03-22" name="CVE-2007-1569" published="2007-03-21" seq="2007-1569" severity="High" type="CVE"><desc><descript source="cve">Stack-based buffer overflow in NewsBin Pro 4.32 allows remote attackers to cause a denial of service or execute arbitrary code via a yEnc (yEncode) encoded article with a long filename, as demonstrated using a .nzb file.  NOTE: some of these details are obtained from third party information.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3464">3464</ref><ref source="BID" url="http://www.securityfocus.com/bid/22940">22940</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0935">ADV-2007-0935</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24491">24491</ref></refs><vuln_soft><prod name="NewsBin Pro" vendor="NewsBin Pro"><vers num="4.3.2"/></prod></vuln_soft></entry><entry modified="2007-04-18" name="CVE-2007-1570" published="2007-03-21" reject="1" seq="2007-1570" type="CVE"><desc><descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2007-1438.  Reason: This candidate is a duplicate of CVE-2007-1438.  Notes: All CVE users should reference CVE-2007-1438 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs/></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-03-22" name="CVE-2007-1571" published="2007-03-21" seq="2007-1571" severity="Medium" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in includes/base.php in Radical Designs Activist Mobilization Platform (AMP) 3.2, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the base_path parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3471">3471</ref><ref source="" url="http://advisories.echo.or.id/adv/adv71-theday-2007.txt"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0939">ADV-2007-0939</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/462805/100/100/threaded">20070314 [ECHO_ADV_71$2007] AMP v3.2 (base_path) Remote File Inclusion Vulnerability</ref></refs><vuln_soft><prod name="Activist Mobilization Platform" vendor="Radical Designs"><vers num="3.2" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-03-22" name="CVE-2007-1572" published="2007-03-21" seq="2007-1572" severity="Medium" type="CVE"><desc><descript source="cve">SQL injection vulnerability in search.asp in JGBBS 3.0 Beta 1 and earlier allows remote attackers to execute arbitrary SQL commands via the title parameter, a different vector than CVE-2007-1440.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0940">ADV-2007-0940</ref></refs><vuln_soft><prod name="JGBBS" vendor="SourceForge"><vers edition="beta 1" num="3.0" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.0" CVSS_exploit_subscore="6.8" CVSS_impact_subscore="6.4" CVSS_score="6.0" CVSS_vector="(AV:N/AC:M/Au:S/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-04-09" name="CVE-2007-1573" published="2007-03-21" seq="2007-1573" severity="Medium" type="CVE"><desc><descript source="cve">SQL injection vulnerability in admincp/attachment.php in Jelsoft vBulletin 3.6.5 allows remote authenticated administrators to execute arbitrary SQL commands via the &quot;Attached Before&quot; field.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24503">24503</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/462963/100/0/threaded">20070313 vbulletin admincp sql injection</ref><ref source="" url="http://www.vbulletin.com/forum/project.php?issueid=21615"></ref></refs><vuln_soft><prod name="vBulletin" vendor="Jelsoft"><vers num="3.6.5" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0" modified="2007-03-23" name="CVE-2007-1574" published="2007-03-21" seq="2007-1574" severity="Medium" type="CVE"><desc><descript source="cve">CARE2X 2.2, and possibly earlier, allows remote attackers to obtain configuration information via a direct request to phpinfo.php, which calls the phpinfo function.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript></desc><loss_types><conf/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref source="SECUNIA" url="http://secunia.com/advisories/24481">24481</ref></refs><vuln_soft><prod name="CARE2X" vendor="CARE2X"><vers num="2.2" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-03-23" name="CVE-2007-1575" published="2007-03-21" seq="2007-1575" severity="High" type="CVE"><desc><descript source="cve">Multiple SQL injection vulnerabilities in PHProjekt 5.2.0, when magic_quotes_gpc is disabled, allow remote authenticated users to execute arbitrary SQL commands via (1) unspecified vectors to the (a) calendar and (2) search modules, and an (2) unspecified cookie when the user logs out.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/462789/100/0/threaded">20070314 n.runs-SA-2007.003 - PHProjekt 5.2.0 - SQL Injection</ref><ref adv="1" source="" url="http://www.nruns.com/security_advisory_phprojekt_sql_injection.php"></ref><ref adv="1" patch="1" source="" url="http://www.phprojekt.com/index.php?name=News&amp;file=article&amp;sid=276"></ref><ref source="BID" url="http://www.securityfocus.com/bid/22955">22955</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24509">24509</ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200706-07.xml">GLSA-200706-07</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25748">25748</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2466">2466</ref></refs><vuln_soft><prod name="PHProjekt" vendor="PHProjekt"><vers num="5.1"/><vers num="5.1.1"/><vers num="5.1.2"/><vers num="5.2"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" modified="2007-03-23" name="CVE-2007-1576" published="2007-03-21" seq="2007-1576" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in PHProjekt 5.2.0, when magic_quotes_gpc is disabled, allow remote authenticated users to inject arbitrary web script or HTML via unspecified vectors to the (1) Projects, (2) Contacts, (3) Helpdesk, (4) Search (only Gecko engine driven Browsers), and (5) Notes modules; the (6) Mail summary page; and unspecified other files.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/462788/100/0/threaded">20070314 n.runs-SA-2007.004 - PHProjekt 5.2.0 - Cross Site Scripting and Filter Evasion</ref><ref adv="1" source="" url="http://www.nruns.de/security_advisory_phprojekt_xss_and_filter_evasion.php"></ref><ref adv="1" patch="1" source="" url="http://www.phprojekt.com/index.php?name=News&amp;file=article&amp;sid=276"></ref><ref source="BID" url="http://www.securityfocus.com/bid/22957">22957</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24509">24509</ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200706-07.xml">GLSA-200706-07</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25748">25748</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2459">2459</ref></refs><vuln_soft><prod name="PHProjekt" vendor="PHProjekt"><vers num="5.2"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0" modified="2007-03-23" name="CVE-2007-1577" published="2007-03-21" seq="2007-1577" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in index.php in GeBlog 0.1 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the GLOBALS[tplname] parameter, as demonstrated by injecting PHP sequences into an Apache HTTP Server log file, which is then included by index.php.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3522">3522</ref><ref source="BID" url="http://www.securityfocus.com/bid/23052">23052</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33089">geblog-index-file-include(33089)</ref><ref source="OSVDB" url="http://www.osvdb.org/33776">
33776</ref></refs><vuln_soft><prod name="Geblog" vendor="Geblog"><vers num="0.1"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-05-01" name="CVE-2007-1578" published="2007-03-21" seq="2007-1578" severity="High" type="CVE"><desc><descript source="cve">Multiple integer signedness errors in the NTLM implementation in Atrium MERCUR IMAPD (mcrimap4.exe) 5.00.14, with SP4, allow remote attackers to execute arbitrary code via a long NTLMSSP argument that triggers a stack-based buffer overflow.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref source="FULLDISC" url="http://archives.neohapsis.com/archives/fulldisclosure/2007-03/0280.html">20070320 Mercur SP4 IMAPD</ref><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3527">3527</ref><ref source="" url="http://www.digit-labs.org/files/exploits/mercur-v1.pl"></ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/23058">23058</ref><ref adv="1" source="SECTRACK" url="http://securitytracker.com/id?1017798">1017798</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24596">24596</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33120">mercur-imap-ntlm-bo(33120)</ref><ref source="OSVDB" url="http://www.osvdb.org/33545">33545</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1053">ADV-2007-1053</ref></refs><vuln_soft><prod name="Mercur IMAPD" vendor="Atrium Software"><vers edition="SP4" num="5.00.14"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-04-09" name="CVE-2007-1579" published="2007-03-21" seq="2007-1579" severity="High" type="CVE"><desc><descript source="cve">Stack-based buffer overflow in Atrium MERCUR IMAPD allows remote attackers to have an unknown impact via a certain SUBSCRIBE command.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref source="" url="http://www.immunitysec.com/partners-index.shtml"></ref><ref source="" url="https://www.immunityinc.com/downloads/immpartners/MercurImapSubscribe.tar"></ref><ref source="BID" url="http://www.securityfocus.com/bid/23050">23050</ref><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3537">3537</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1092">ADV-2007-1092</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24619">24619</ref><ref source="OSVDB" url="http://www.osvdb.org/33546">
33546</ref></refs><vuln_soft><prod name="MERCUR Messaging 2005" vendor="Atrium Software"><vers edition="Standard" num="5.0 SP3"/><vers edition="Lite" num="5.0 SP3"/><vers edition="Enterprise" num="5.0 SP3"/><vers num="SP4"/></prod><prod name="Mercur IMAPD" vendor="Atrium Software"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="6.3" CVSS_exploit_subscore="6.8" CVSS_impact_subscore="6.9" CVSS_score="6.3" CVSS_vector="(AV:N/AC:M/Au:S/C:N/I:N/A:C)" CVSS_version="2.0" modified="2007-04-09" name="CVE-2007-1580" published="2007-03-21" seq="2007-1580" severity="Medium" type="CVE"><desc><descript source="cve">FTPDMIN 0.96 allows remote attackers to cause a denial of service (daemon crash) via a LIST command for a Windows drive letter, as demonstrated using &quot;//A:&quot;.  NOTE: this has been reported as a buffer overflow by some sources, but there is not a long argument.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3523">3523</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/23049">23049</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/33091">ftpdmin-list-dos(33091)</ref></refs><vuln_soft><prod name="FTPDMIN" vendor="FTPDMIN"><vers num="0.96"/></prod></vuln_soft></entry><entry CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" CVSS_score="9.3" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-03-27" name="CVE-2007-1581" published="2007-03-21" seq="2007-1581" severity="High" type="CVE"><desc><descript source="cve">The resource system in PHP 5.0.0 through 5.2.1 allows context-dependent attackers to execute arbitrary code by interrupting the hash_update_file function via a userspace (1) error or (2) stream handler, which can then be used to destroy and modify internal resources.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3529">3529</ref><ref source="" url="http://www.php-security.org/MOPB/MOPB-28-2007.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/23062">23062</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24542">
24542</ref></refs><vuln_soft><prod name="PHP" vendor="PHP"><vers num="5.0 candidate 1"/><vers num="5.0 candidate 2"/><vers num="5.0 candidate 3"/><vers num="5.0.0"/><vers num="5.0.1"/><vers num="5.0.2"/><vers num="5.0.3"/><vers num="5.0.4"/><vers num="5.0.5"/><vers num="5.1"/><vers num="5.1.0"/><vers num="5.1.1"/><vers num="5.1.2"/><vers num="5.1.3"/><vers num="5.1.4"/><vers num="5.1.5"/><vers num="5.1.6"/><vers num="5.2.0"/><vers num="5.2.1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-07-03" name="CVE-2007-1582" published="2007-03-21" seq="2007-1582" severity="Medium" type="CVE"><desc><descript source="cve">The resource system in PHP 4.0.0 through 4.4.6 and 5.0.0 through 5.2.1 allows context-dependent attackers to execute arbitrary code by interrupting certain functions in the GD (ext/gd) extension and unspecified other extensions via a userspace error handler, which can be used to destroy and modify internal resources.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3525">3525</ref><ref adv="1" source="" url="http://www.php-security.org/MOPB/MOPB-27-2007.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/23046">23046</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24542">24542</ref></refs><vuln_soft><prod name="PHP" vendor="PHP"><vers num="4.0"/><vers num="4.0 Beta 1"/><vers num="4.0 Beta 2"/><vers num="4.0 Beta 3"/><vers num="4.0 Beta 4"/><vers num="4.0 Beta 4 Patch Level 1"/><vers num="4.0 RC1"/><vers num="4.0 RC2"/><vers num="4.0.0"/><vers num="4.0.1"/><vers num="4.0.1 pl1"/><vers num="4.0.1 pl2"/><vers num="4.0.2"/><vers num="4.0.3"/><vers num="4.0.3 pl1"/><vers num="4.0.4"/><vers num="4.0.4 pl1"/><vers num="4.0.5"/><vers num="4.0.6"/><vers num="4.0.7"/><vers num="4.0.7 RC1"/><vers num="4.0.7 RC2"/><vers num="4.0.7 RC3"/><vers num="4.1.0"/><vers num="4.1.1"/><vers num="4.1.2"/><vers num="4.1.2"/><vers edition="Dev" num="4.2"/><vers edition="Dev" num="4.2"/><vers num="4.2.0"/><vers num="4.2.0"/><vers num="4.2.1"/><vers num="4.2.1"/><vers num="4.2.2"/><vers num="4.2.2"/><vers num="4.2.3"/><vers num="4.2.3"/><vers num="4.3"/><vers num="4.3"/><vers num="4.3.1"/><vers num="4.3.10"/><vers num="4.3.1"/><vers num="4.3.11"/><vers num="4.3.10"/><vers num="4.3.2"/><vers num="4.3.11"/><vers num="4.3.2"/><vers num="4.3.3"/><vers num="4.3.3"/><vers num="4.3.4"/><vers num="4.3.5"/><vers num="4.3.4"/><vers num="4.3.6"/><vers num="4.3.7"/><vers num="4.3.5"/><vers num="4.3.8"/><vers num="4.3.6"/><vers num="4.3.9"/><vers num="4.3.7"/><vers num="4.4.0"/><vers num="4.4.1"/><vers num="4.3.8"/><vers num="4.4.2"/><vers num="4.3.9"/><vers num="4.4.3"/><vers num="4.4.4"/><vers num="4.4.0"/><vers num="4.4.5"/><vers num="4.4.1"/><vers num="4.4.6"/><vers num="4.4.2"/><vers num="5.0 candidate 1"/><vers num="5.0 candidate 2"/><vers num="4.4.3"/><vers num="5.0 candidate 3"/><vers num="4.4.4"/><vers num="5.0.0"/><vers num="5.0.0 Beta1"/><vers num="4.4.5"/><vers num="5.0.0 Beta2"/><vers num="5.0.0 Beta3"/><vers num="5.0.0 Beta4"/><vers num="4.4.6"/><vers num="5.0 candidate 1"/><vers num="5.0 candidate 2"/><vers num="5.0 candidate 3"/><vers num="5.0.0"/><vers num="5.0.0 RC1"/><vers num="5.0.0 RC2"/><vers num="5.0.0 RC3"/><vers num="5.0.1"/><vers num="5.0.2"/><vers num="5.0.3"/><vers num="5.0.4"/><vers num="5.0.5"/><vers num="5.1"/><vers num="5.0.0 RC1"/><vers num="5.1.0"/><vers num="5.0.0 RC2"/><vers num="5.1.1"/><vers num="5.0.0 RC3"/><vers num="5.1.2"/><vers num="5.0.1"/><vers num="5.1.3"/><vers num="5.0.2"/><vers num="5.1.4"/><vers num="5.0.3"/><vers num="5.1.5"/><vers num="5.0.4"/><vers num="5.1.6"/><vers num="5.2.0"/><vers num="5.0.5"/><vers num="5.1"/><vers num="5.2.1"/><vers num="5.1.0"/><vers num="5.1.1"/><vers num="5.1.2"/><vers num="5.1.3"/><vers num="5.1.4"/><vers num="5.1.5"/><vers num="5.1.6"/><vers num="5.2.1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-03-27" name="CVE-2007-1583" published="2007-03-21" seq="2007-1583" severity="Medium" type="CVE"><desc><descript source="cve">The mb_parse_str function in PHP 4.0.0 through 4.4.6 and 5.0.0 through 5.2.1 sets the internal register_globals flag and does not disable it in certain cases when a script terminates, which allows remote attackers to invoke available PHP scripts with register_globals functionality that is not detectable by these scripts, as demonstrated by forcing a memory_limit violation.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="" url="http://www.php-security.org/MOPB/MOPB-26-2007.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/23016">23016</ref><ref source="REDHAT" url="http://rhn.redhat.com/errata/RHSA-2007-0155.html">
RHSA-2007:0155</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24924">
24924</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/466166/100/0/threaded">

20070418 rPSA-2007-0073-1 php php-mysql php-pgsql</ref><ref source="" url="https://issues.rpath.com/browse/RPL-1268"></ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2007-0153.html">
RHSA-2007:0153</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2007-0162.html">
RHSA-2007:0162</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24965">
24965</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24945">
24945</ref><ref source="DEBIAN" url="http://www.debian.org/security/2007/dsa-1283">
DSA-1283</ref><ref source="UBUNTU" url="http://www.ubuntu.com/usn/usn-455-1">
USN-455-1</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25062">
25062</ref><ref source="" url="http://us2.php.net/releases/4_4_7.php"></ref><ref source="" url="http://us2.php.net/releases/5_2_2.php"></ref><ref source="SECUNIA" url="http://secunia.com/advisories/25057">
25057</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2007:088">
MDKSA-2007:088</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2007:089">
MDKSA-2007:089</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24909">
24909</ref><ref source="" url="http://docs.info.apple.com/article.html?artnum=306172"></ref><ref source="APPLE" url="http://lists.apple.com/archives/security-announce//2007/Jul/msg00004.html">APPLE-SA-2007-07-31</ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200705-19.xml">GLSA-200705-19</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:088">MDKSA-2007:088</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:089">MDKSA-2007:089</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:090">MDKSA-2007:090</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2007_32_php.html">SUSE-SA:2007:032</ref><ref source="BID" url="http://www.securityfocus.com/bid/25159">25159</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/2732">ADV-2007-2732</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25056">25056</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25445">25445</ref><ref source="SECUNIA" url="http://secunia.com/advisories/26235">26235</ref></refs><vuln_soft><prod name="PHP" vendor="PHP"><vers num="4.0"/><vers num="4.0 Beta 1"/><vers num="4.0 Beta 2"/><vers num="4.0 Beta 3"/><vers num="4.0 Beta 4"/><vers num="4.0 Beta 4 Patch Level 1"/><vers num="4.0 RC1"/><vers num="4.0 RC2"/><vers num="4.0.0"/><vers num="4.0.1"/><vers num="4.0.1 pl1"/><vers num="4.0.1 pl2"/><vers num="4.0.2"/><vers num="4.0.3"/><vers num="4.0.3 pl1"/><vers num="4.0.4"/><vers num="4.0.4 pl1"/><vers num="4.0.5"/><vers num="4.0.6"/><vers num="4.0.7"/><vers num="4.0.7 RC1"/><vers num="4.0.7 RC2"/><vers num="4.0.7 RC3"/><vers num="4.1.0"/><vers num="4.1.1"/><vers num="4.1.2"/><vers edition="Dev" num="4.2"/><vers num="4.2.0"/><vers num="4.2.1"/><vers num="4.2.2"/><vers num="4.2.3"/><vers num="4.3"/><vers num="4.3.1"/><vers num="4.3.10"/><vers num="4.3.11"/><vers num="4.3.2"/><vers num="4.3.3"/><vers num="4.3.4"/><vers num="4.3.5"/><vers num="4.3.6"/><vers num="4.3.7"/><vers num="4.3.8"/><vers num="4.3.9"/><vers num="4.4.0"/><vers num="4.4.1"/><vers num="4.4.2"/><vers num="4.4.3"/><vers num="4.4.4"/><vers num="4.4.5"/><vers num="4.4.6"/><vers num="5.0 candidate 1"/><vers num="5.0 candidate 2"/><vers num="5.0 candidate 3"/><vers num="5.0.0"/><vers num="5.0.0 Beta1"/><vers num="5.0.0 Beta2"/><vers num="5.0.0 Beta3"/><vers num="5.0.0 Beta4"/><vers num="5.0.0 RC1"/><vers num="5.0.0 RC2"/><vers num="5.0.0 RC3"/><vers num="5.0.1"/><vers num="5.0.2"/><vers num="5.0.3"/><vers num="5.0.4"/><vers num="5.0.5"/><vers num="5.1"/><vers num="5.1.0"/><vers num="5.1.1"/><vers num="5.1.2"/><vers num="5.1.3"/><vers num="5.1.4"/><vers num="5.1.5"/><vers num="5.1.6"/><vers num="5.2.0"/><vers num="5.2.1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-03-27" name="CVE-2007-1584" published="2007-03-21" seq="2007-1584" severity="Medium" type="CVE"><desc><descript source="cve">Buffer underflow in the header function in PHP 5.2.0 allows context-dependent attackers to execute arbitrary code by passing an all-whitespace string to this function, which causes it to write &apos;\0&apos; characters in whitespace that precedes the string.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3517">3517</ref><ref adv="1" source="" url="http://www.php-security.org/MOPB/MOPB-25-2007.html"></ref></refs><vuln_soft><prod name="PHP" vendor="PHP"><vers num="5.2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0" modified="2007-04-10" name="CVE-2007-1585" published="2007-03-21" seq="2007-1585" severity="Medium" type="CVE"><desc><descript source="cve">The Linksys WAG200G with firmware 1.01.01, WRT54GC 2 with firmware 1.00.7, and WRT54GC 1 with firmware 1.03.0 and earlier allow remote attackers to obtain sensitive information (passwords and configuration data) via a packet to UDP port 916. NOTE: some of these details are obtained from third party information.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/463342/100/0/threaded">20070320 Linksys WAG200G - Information disclosure</ref><ref source="BID" url="http://www.securityfocus.com/bid/23063">23063</ref><ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=117492736903388&amp;w=2">20070325 Re: Linksys WAG200G - Information disclosure</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24658">24658</ref></refs><vuln_soft><prod name="WRT54GC" vendor="Linksys"><vers num="1.03.0" prev="1"/><vers num="1.00.7"/></prod><prod name="WAG200G" vendor="Linksys"><vers num="firmware 1.01.01"/></prod></vuln_soft></entry><entry CVSS_base_score="7.8" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.9" CVSS_score="7.8" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_version="2.0" modified="2007-03-27" name="CVE-2007-1586" published="2007-03-21" seq="2007-1586" severity="High" type="CVE"><desc><descript source="cve">ZynOS 3.40 allows remote attackers to cause a denial of service (link restart) by sending a request for the name \M via the SMB Mail Slot Protocol.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/463238/100/0/threaded">20070319 ZynOS v3.40 One packet killer</ref><ref source="BID" url="http://www.securityfocus.com/bid/23061">23061</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1017795">1017795</ref></refs><vuln_soft><prod name="ZyNOS" vendor="ZyXEL"><vers num="3.40"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-03-27" name="CVE-2007-1587" published="2007-03-21" seq="2007-1587" severity="High" type="CVE"><desc><descript source="cve">templates/config/mail.tpl in Tim Soderstrom StatsDawg 0.92 allows remote attackers to execute arbitrary programs by specifying the program name in the qshapeLocation parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref patch="1" source="" url="http://www.statsdawg.org/"></ref></refs><vuln_soft><prod name="StatsDawg" vendor="Tim Soderstrom"><vers num="0.92"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-03-27" name="CVE-2007-1588" published="2007-03-21" seq="2007-1588" severity="High" type="CVE"><desc><descript source="cve">server.cpp in MyServer 0.8.5 calls Process::setuid before calling Process::setgid and thus does not properly drop privileges, which might allow remote attackers to execute CGI programs with unintended privileges.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref patch="1" source="MLIST" url="http://sourceforge.net/mailarchive/forum.php?thread_id=31631045&amp;forum_id=47875">[myserver-commit] 20070210 SF.net SVN: myserver: [2183] trunk/myserver/source/server.cpp</ref><ref adv="1" source="" url="http://www.myserverproject.net/news.php"></ref></refs><vuln_soft><prod name="myServer" vendor="myServer"><vers num="0.8.5"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0" modified="2007-03-27" name="CVE-2007-1589" published="2007-03-21" seq="2007-1589" severity="Low" type="CVE"><desc><descript source="cve">TrueCrypt before 4.3, when set-euid mode is used on Linux, allows local users to cause a denial of service (filesystem unavailability) by dismounting a volume mounted by a different user.</descript></desc><loss_types><avail/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="" url="http://www.truecrypt.org/docs/?s=version-history"></ref><ref source="BID" url="http://www.securityfocus.com/bid/23128">
23128</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1103">
ADV-2007-1103</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24627">
24627</ref></refs><vuln_soft><prod name="TrueCrypt" vendor="TrueCrypt Foundation"><vers num="4.0"/><vers num="4.1"/><vers num="4.2"/><vers num="4.2a"/></prod></vuln_soft></entry><entry CVSS_base_score="7.8" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.9" CVSS_score="7.8" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_version="2.0" modified="2007-03-27" name="CVE-2007-1590" published="2007-03-21" seq="2007-1590" severity="High" type="CVE"><desc><descript source="cve">The Grandstream BudgeTone 200 IP phone, with program 1.1.1.14 and bootloader 1.1.1.5, allows remote attackers to cause a denial of service (device crash) via SIP (1) INVITE, (2) CANCEL, or unspecified other messages with a WWW-Authenticate header containing a crafted Digest domain.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2007-March/053099.html">20070321 Grandstream Budge Tone-200 denial of service vulnerability</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1054">ADV-2007-1054</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24538">24538</ref><ref source="BID" url="http://www.securityfocus.com/bid/23075">23075</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017804">1017804</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33108">grandstream-wwwauthenticate-dos(33108)</ref></refs><vuln_soft><prod name="BudgeTone 200" vendor="Grandstream"><vers num="1.1.1.5"/><vers num="1.1.1.14"/></prod></vuln_soft></entry><entry CVSS_base_score="7.8" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.9" CVSS_score="7.8" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_version="2.0" modified="2007-03-27" name="CVE-2007-1591" published="2007-03-22" seq="2007-1591" severity="High" type="CVE"><desc><descript source="cve">VsapiNT.sys in the Scan Engine 8.0 for Trend Micro AntiVirus 14.10.1041, and other products, allows remote attackers to cause a denial of service (kernel fault and system crash) via a crafted UPX file with a certain field that triggers a divide-by-zero error.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="IDEFENSE" url="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=488">20070314 Trend Micro Antivirus UPX Parsing Kernel Divide by Zero Vulnerability</ref><ref adv="1" patch="1" source="" url="http://esupport.trendmicro.com/support/viewxml.do?ContentID=EN-1034587"></ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/463007/100/100/threaded">
20070316 RE: [VulnWatch] iDefense Security Advisory 03.14.07: Trend Micro Antivirus UPX Parsing Kernel Divide by Zero Vulnerability</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0959">
ADV-2007-0959</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017768">
1017768</ref></refs><vuln_soft><prod name="Trend Micro AntiVirus" vendor="Trend Micro"><vers num="14.10.1041"/></prod></vuln_soft></entry><entry CVSS_base_score="4.9" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.9" CVSS_score="4.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:C)" CVSS_version="2.0" modified="2008-02-26" name="CVE-2007-1592" published="2007-03-22" seq="2007-1592" severity="Medium" type="CVE"><desc><descript source="cve">net/ipv6/tcp_ipv6.c in Linux kernel 2.6.x up to 2.6.21-rc3 inadvertently copies the ipv6_fl_socklist from a listening TCP socket to child sockets, which allows local users to cause a denial of service (OOPS) or double free by opening a listening IPv6 socket, attaching a flow label, and connecting to that socket.</descript></desc><sols><sol source="nvd">The vendor has addressed this vulnerability by releasing a patch for the Linux Kernel 2.6.21-rc3: http://www.kernel.org/pub/linux/kernel/v2.6/testing/patch-2.6.21-rc6.bz2 </sol></sols><loss_types><avail/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref patch="1" source="MLIST" url="http://marc.info/?l=linux-netdev&amp;m=117406721731891&amp;w=2">[linux-netdev] 20070316 [PATCH 2.6.21-rc3] IPV6: ipv6_fl_socklist is inadvertently shared.</ref><ref patch="1" source="" url="http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=d35690beda1429544d46c8eb34b2e3a8c37ab299"></ref><ref source="" url="http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.20.4"></ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/23104">23104</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1084">ADV-2007-1084</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24618">24618</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2007:078">MDKSA-2007:078</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24777">24777</ref><ref source="DEBIAN" url="http://www.debian.org/security/2007/dsa-1286">DSA-1286</ref><ref source="SUSE" url="http://lists.suse.com/archive/suse-security-announce/2007-May/0001.html">SUSE-SA:2007:029</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/25078">25078</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/25099">25099</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2007_30_kernel.html">SUSE-SA:2007:030</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2007-0347.html">RHSA-2007:0347</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/25288">25288</ref><ref source="" url="http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=233478"></ref><ref source="" url="http://support.avaya.com/elmodocs2/security/ASA-2007-404.htm"></ref><ref source="DEBIAN" url="http://www.debian.org/security/2007/dsa-1304">DSA-1304</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:078">MDKSA-2007:078</ref><ref source="REDHAT" url="http://rhn.redhat.com/errata/RHSA-2007-0436.html">RHSA-2007:0436</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2007-0673.html">RHSA-2007:0673</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2007-0672.html">RHSA-2007:0672</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2007_35_kernel.html">SUSE-SA:2007:035</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2007_43_kernel.html">SUSE-SA:2007:043</ref><ref source="UBUNTU" url="http://www.ubuntu.com/usn/usn-464-1">USN-464-1</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/25392">25392</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/25630">25630</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/25683">25683</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/25714">25714</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/25961">25961</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/26379">26379</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/25226">25226</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/27528">27528</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33176">kernel-tcpv6synrecvsoc-dos(33176)</ref><ref source="DEBIAN" url="http://www.debian.org/security/2008/dsa-1503">DSA-1503</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/29058">29058</ref></refs><vuln_soft><prod name="Kernel" vendor="Linux"><vers num="2.4.0"/><vers num="2.6"/><vers edition="64-bit x86" num="2.6"/><vers edition="Itanium IA64 Montecito" num="2.6"/><vers num="2.6 test1"/><vers num="2.6 test10"/><vers num="2.6 test11"/><vers num="2.6 test2"/><vers num="2.6 test3"/><vers num="2.6 test4"/><vers num="2.6 test5"/><vers num="2.6 test6"/><vers num="2.6 test7"/><vers num="2.6 test8"/><vers num="2.6 test9"/><vers num="2.6 test9 CVS"/><vers num="2.6.0"/><vers num="2.6.1"/><vers num="2.6.1 rc1"/><vers num="2.6.1 rc2"/><vers num="2.6.1 rc3"/><vers num="2.6.10"/><vers num="2.6.10 rc1"/><vers num="2.6.10 rc2"/><vers num="2.6.10 rc3"/><vers num="2.6.11"/><vers num="2.6.11.5"/><vers num="2.6.11.6"/><vers num="2.6.11.7"/><vers num="2.6.11.8"/><vers edition="x86_64" num="2.6.11"/><vers num="2.6.11 rc1"/><vers num="2.6.11 rc1 bk6"/><vers num="2.6.11 rc2"/><vers num="2.6.11 rc3"/><vers num="2.6.11 rc4"/><vers num="2.6.11 rc5"/><vers num="2.6.11.1"/><vers num="2.6.11.10"/><vers num="2.6.11.11"/><vers num="2.6.11.12"/><vers num="2.6.11.2"/><vers num="2.6.11.3"/><vers num="2.6.11.4"/><vers num="2.6.11.9"/><vers num="2.6.12"/><vers num="2.6.12.1"/><vers num="2.6.12.2"/><vers num="2.6.12.3"/><vers num="2.6.12.4"/><vers num="2.6.12.5"/><vers num="2.6.12.6"/><vers num="2.6.12 rc1"/><vers num="2.6.12 rc2"/><vers num="2.6.12 rc3"/><vers num="2.6.12 rc4"/><vers num="2.6.12 rc5"/><vers num="2.6.12 rc6"/><vers num="2.6.12.12"/><vers num="2.6.12.22"/><vers num="2.6.13"/><vers num="2.6.13.1"/><vers num="2.6.13.2"/><vers num="2.6.13.3"/><vers num="2.6.13.4"/><vers num="2.6.13 rc1"/><vers num="2.6.13 rc2"/><vers num="2.6.13 rc3"/><vers num="2.6.13 rc4"/><vers num="2.6.13 rc5"/><vers num="2.6.13 rc6"/><vers num="2.6.13 rc7"/><vers num="2.6.13.5"/><vers num="2.6.14"/><vers num="2.6.14.1"/><vers num="2.6.14.2"/><vers num="2.6.14.3"/><vers num="2.6.14.4"/><vers num="2.6.14.5"/><vers num="2.6.14 rc1"/><vers num="2.6.14 rc2"/><vers num="2.6.14 rc3"/><vers num="2.6.14 rc4"/><vers num="2.6.14 rc5"/><vers num="2.6.14.6"/><vers num="2.6.14.7"/><vers num="2.6.15"/><vers num="2.6.15.1"/><vers num="2.6.15.2"/><vers num="2.6.15.3"/><vers num="2.6.15.4"/><vers num="2.6.15 rc1"/><vers num="2.6.15 rc2"/><vers num="2.6.15 rc3"/><vers num="2.6.15 rc4"/><vers num="2.6.15 rc5"/><vers num="2.6.15 rc6"/><vers num="2.6.15 rc7"/><vers num="2.6.15.11"/><vers num="2.6.15.5"/><vers num="2.6.15.6"/><vers num="2.6.15.7"/><vers num="2.6.16"/><vers num="2.6.16.1"/><vers num="2.6.16.11"/><vers num="2.6.16.12"/><vers num="2.6.16.19"/><vers num="2.6.16.23"/><vers num="2.6.16.7"/><vers num="2.6.16.9"/><vers num="2.6.16.13"/><vers num="2.6.16.27"/><vers num="2.6.16 rc1"/><vers num="2.6.16 rc2"/><vers num="2.6.16 rc3"/><vers num="2.6.16 rc4"/><vers num="2.6.16 rc5"/><vers num="2.6.16 rc6"/><vers num="2.6.16 rc7"/><vers num="2.6.16.10"/><vers num="2.6.16.14"/><vers num="2.6.16.15"/><vers num="2.6.16.16"/><vers num="2.6.16.17"/><vers num="2.6.16.18"/><vers num="2.6.16.2"/><vers num="2.6.16.20"/><vers num="2.6.16.21"/><vers num="2.6.16.22"/><vers num="2.6.16.24"/><vers num="2.6.16.25"/><vers num="2.6.16.26"/><vers num="2.6.16.28"/><vers num="2.6.16.29"/><vers num="2.6.16.3"/><vers num="2.6.16.30"/><vers num="2.6.16.31"/><vers num="2.6.16.32"/><vers num="2.6.16.33"/><vers num="2.6.16.34"/><vers num="2.6.16.35"/><vers num="2.6.16.36"/><vers num="2.6.16.37"/><vers num="2.6.16.38"/><vers num="2.6.16.39"/><vers num="2.6.16.4"/><vers num="2.6.16.40"/><vers num="2.6.16.41"/><vers num="2.6.16.5"/><vers num="2.6.16.6"/><vers num="2.6.16.8"/><vers num="2.6.17"/><vers num="2.6.17.1"/><vers num="2.6.17.10"/><vers num="2.6.17.11"/><vers num="2.6.17.12"/><vers num="2.6.17.13"/><vers num="2.6.17.14"/><vers num="2.6.17.3"/><vers num="2.6.17.5"/><vers num="2.6.17.6"/><vers num="2.6.17.7"/><vers num="2.6.17.8"/><vers num="2.6.17 rc1"/><vers num="2.6.17 rc2"/><vers num="2.6.17 rc3"/><vers num="2.6.17 rc4"/><vers num="2.6.17 rc5"/><vers num="2.6.17 rc6"/><vers num="2.6.17.2"/><vers num="2.6.17.4"/><vers num="2.6.17.9"/><vers num="2.6.18"/><vers num="2.6.18.1"/><vers num="2.6.18 rc1"/><vers num="2.6.18 rc2"/><vers num="2.6.18 rc5"/><vers num="2.6.18.2"/><vers num="2.6.18.3"/><vers num="2.6.18.4"/><vers num="2.6.18.5"/><vers num="2.6.18.6"/><vers num="2.6.18 rc3"/><vers num="2.6.18 rc4"/><vers num="2.6.18 rc6"/><vers num="2.6.18 rc7"/><vers num="2.6.18 stable"/><vers num="2.6.19"/><vers num="2.6.19 rc1"/><vers num="2.6.19.1"/><vers num="2.6.19.2"/><vers num="2.6.19.3"/><vers num="2.6.19 rc2"/><vers num="2.6.19 rc3"/><vers num="2.6.19 rc4"/><vers num="2.6.2"/><vers num="2.6.2 rc1"/><vers num="2.6.2 rc2"/><vers num="2.6.2 rc3"/><vers num="2.6.20"/><vers num="2.6.20.1"/><vers num="2.6.20.2"/><vers num="2.6.3"/><vers num="2.6.3 rc1"/><vers num="2.6.3 rc2"/><vers num="2.6.3 rc3"/><vers num="2.6.3 rc4"/><vers num="2.6.4"/><vers num="2.6.4 rc1"/><vers num="2.6.4 rc2"/><vers num="2.6.4 rc3"/><vers num="2.6.5"/><vers num="2.6.5 rc1"/><vers num="2.6.5 rc2"/><vers num="2.6.5 rc3"/><vers num="2.6.6"/><vers num="2.6.6 rc1"/><vers num="2.6.6 rc2"/><vers num="2.6.6 rc3"/><vers num="2.6.7"/><vers num="2.6.7 rc1"/><vers num="2.6.7 rc2"/><vers num="2.6.7 rc3"/><vers num="2.6.8"/><vers num="2.6.8 rc1"/><vers num="2.6.8 rc2"/><vers num="2.6.8 rc3"/><vers num="2.6.8 rc4"/><vers num="2.6.8.1"/><vers num="2.6.8.1.5"/><vers edition="386" num="2.6.8.1.5"/><vers edition="686" num="2.6.8.1.5"/><vers edition="686_smp" num="2.6.8.1.5"/><vers edition="AMD64" num="2.6.8.1.5"/><vers edition="AMD64_K8" num="2.6.8.1.5"/><vers edition="AMD64_K8_smp" num="2.6.8.1.5"/><vers edition="AMD64_Xeon" num="2.6.8.1.5"/><vers edition="K7" num="2.6.8.1.5"/><vers edition="K7_smp" num="2.6.8.1.5"/><vers edition="Power3" num="2.6.8.1.5"/><vers edition="Power3_smp" num="2.6.8.1.5"/><vers edition="Power4" num="2.6.8.1.5"/><vers edition="Power4_smp" num="2.6.8.1.5"/><vers edition="PowerPC" num="2.6.8.1.5"/><vers edition="PowerPC_smp" num="2.6.8.1.5"/><vers num="2.6.9"/><vers num="2.6.9 final"/><vers num="2.6.9 rc1"/><vers num="2.6.9 rc2"/><vers num="2.6.9 rc3"/><vers num="2.6.9 rc4"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0" modified="2007-12-28" name="CVE-2007-1593" published="2007-06-04" seq="2007-1593" severity="Medium" type="CVE"><desc><descript source="cve">The administrative service in Symantec Veritas Volume Replicator (VVR) for Windows 3.1 through 4.3, and VVR for Unix 3.5 through 5.0, in Symantec Storage Foundation products allows remote attackers to cause a denial of service (memory consumption and service crash) via a crafted packet to the service port (8199/tcp) that triggers a request for more memory than available, which causes the service to write to an invalid pointer.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="IDEFENSE" url="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=539">20070601 Symantec VERITAS Storage Foundation Administration Service DoS Vulnerability</ref><ref patch="1" source="" url="http://www.symantec.com/avcenter/security/Content/2007.06.01a.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/24160">24160</ref><ref source="" url="http://cirt.dk/advisories/cirt-53-advisory.txt"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/2036">ADV-2007-2036</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1018184">1018184</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/25516">25516</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/34676">symantec-vvr-dos(34676)</ref></refs><vuln_soft><prod name="Veritas Volume Replicator" vendor="Symantec"><vers edition="Unix" num="3.5"/><vers edition="Unix" num="4.0"/><vers edition="Unix" num="4.1"/><vers edition="Unix" num="5.0"/><vers edition="Windows" num="3.1"/><vers edition="Windows" num="4.1"/><vers edition="Windows" num="4.1RP1"/><vers edition="Windows" num="4.2"/><vers edition="Windows" num="4.2RP1"/><vers edition="Windows" num="4.2RP2"/><vers edition="Windows" num="4.3"/><vers edition="Windows" num="4.3MP1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.8" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.9" CVSS_score="7.8" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_version="2.0" modified="2007-04-30" name="CVE-2007-1594" published="2007-03-22" seq="2007-1594" severity="High" type="CVE"><desc><descript source="cve">The handle_response function in chan_sip.c in Asterisk before 1.2.17 and 1.4.x before 1.4.2 allows remote attackers to cause a denial of service (crash) via a SIP Response code 0 in a SIP packet.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/463434/100/0/threaded">20070321 Two new DoS Vulnerabilities in Asterisk Fixed</ref><ref adv="1" source="MLIST" url="http://voipsa.org/pipermail/voipsec_voipsa.org/2007-March/002275.html">[VOIPSEC] 20070319 Asterisk SDP DOS vulnerability</ref><ref adv="1" source="" url="http://bugs.digium.com/view.php?id=9313"></ref><ref source="" url="http://svn.digium.com/view/asterisk/trunk/channels/chan_sip.c?r1=58907&amp;r2=59038"></ref><ref patch="1" source="" url="http://asterisk.org/node/48339"></ref><ref adv="1" source="" url="http://www.sineapps.com/news.php?rssid=1707"></ref><ref source="BID" url="http://www.securityfocus.com/bid/23093">23093</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/24579">24579</ref><ref source="" url="http://www.asterisk.org/node/48338"></ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1077">ADV-2007-1077</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017809">1017809</ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200704-01.xml">GLSA-200704-01</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24719">24719</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2007_34_asterisk.html">SUSE-SA:2007:034</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25582">25582</ref></refs><vuln_soft><prod name="Asterisk" vendor="Asterisk"><vers num="0.1.11"/><vers num="1.2.15"/><vers num="1.2.16"/><vers num="1.4.1"/><vers num="0.1.7"/><vers num="0.1.8"/><vers num="0.1.9"/><vers num="0.1.9_1"/><vers num="0.2"/><vers num="0.3"/><vers num="0.4"/><vers num="0.7.0"/><vers num="0.7.1"/><vers num="0.7.2"/><vers num="0.9.0"/><vers num="1.0"/><vers num="1.0.10"/><vers num="1.0.11"/><vers num="1.0.12"/><vers num="1.0.6"/><vers num="1.0.7"/><vers num="1.0.8"/><vers num="1.0.9"/><vers num="1.2.0 Beta2"/><vers num="1.2.10"/><vers num="1.2.11"/><vers num="1.2.12"/><vers num="1.2.13"/><vers num="1.2.14"/><vers num="1.2.17"/><vers num="1.2.5"/><vers num="1.2.6"/><vers num="1.2.7"/><vers num="1.2.8"/><vers num="1.2.9"/><vers num="1.4 Beta"/><vers num="1.2.0 Beta1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-03-26" name="CVE-2007-1595" published="2007-03-22" seq="2007-1595" severity="High" type="CVE"><desc><descript source="cve">The Asterisk Extension Language (AEL) in pbx/pbx_ael.c in Asterisk does not properly generate extensions, which allows remote attackers to execute arbitrary extensions and have an unknown impact by specifying an invalid extension in a certain form.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="" url="http://bugs.digium.com/view.php?id=9316"></ref><ref patch="1" source="" url="http://svn.digium.com/view/asterisk?rev=59073&amp;view=rev"></ref><ref source="SECUNIA" url="http://secunia.com/advisories/24694">
24694</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2007_34_asterisk.html">SUSE-SA:2007:034</ref><ref source="BID" url="http://www.securityfocus.com/bid/23155">23155</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1123">ADV-2007-1123</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25582">25582</ref></refs><vuln_soft><prod name="Asterisk" vendor="Asterisk"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" CVSS_score="9.3" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-03-26" name="CVE-2007-1596" published="2007-03-22" seq="2007-1596" severity="High" type="CVE"><desc><descript source="cve">Multiple PHP remote file inclusion vulnerabilities in the NFN Address Book (com_nfn_addressbook) 0.4 component for Mambo and Joomla! allow remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter to (1) components/com_nfn_addressbook/nfnaddressbook.php or (2) administrator/components/com_nfn_addressbook/nfnaddressbook.php.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3539">3539</ref><ref source="BID" url="http://www.securityfocus.com/bid/23092">23092</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1073">
ADV-2007-1073</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33133">
nfnaddressbook-nfnaddressbook-file-include(33133)</ref></refs><vuln_soft><prod name="NFN Address Book" vendor="Mambo"><vers num="0.4"/></prod><prod name="NFN Address Book" vendor="Joomla"><vers num="0.4"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0" modified="2007-03-26" name="CVE-2007-1597" published="2007-03-22" seq="2007-1597" severity="Medium" type="CVE"><desc><descript source="cve">Unclassified NewsBoard 1.6.3 stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain (1) the board log via a direct request for logs/board-YYYY-MM-DD.log, (2) the mail and private message (PM) log via a direct request for logs/email-YY-MM-DD-HH-MM-SS.log, (3) the SQL error message log via a direct request for logs/error-YY-MM.log, and (4) the IP log via a direct request for logs/ip.log.</descript></desc><loss_types><conf/></loss_types><vuln_types><access/><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/463186/100/0/threaded">20070319 Unclassified NewsBoard 1.6.3 multiples logs disclosure</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33150">
unb-log-information-disclosure(33150)</ref></refs><vuln_soft><prod name="Unclassified NewsBoard" vendor="Unclassified NewsBoard"><vers num="1.6.3"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-03-26" name="CVE-2007-1598" published="2007-03-22" seq="2007-1598" severity="Medium" type="CVE"><desc><descript source="cve">Stack-based buffer overflow in InterVations FileCOPA FTP Server 1.01 allows remote attackers to execute arbitrary code via unspecified vectors, as demonstrated by filecopa.tar by Immunity.  NOTE: some of these details are obtained from third party information.  NOTE: As of 20070322, this disclosure has no actionable information. However, since it is from a reliable researcher, it is being assigned a CVE identifier for tracking purposes.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref source="" url="http://www.immunitysec.com/partners-index.shtml"></ref><ref source="" url="https://www.immunityinc.com/downloads/immpartners/filecopa.tar"></ref><ref source="BID" url="http://www.securityfocus.com/bid/23056">23056</ref></refs><vuln_soft><prod name="FileCOPA" vendor="InterVations"><vers num="1.01"/></prod></vuln_soft></entry><entry CVSS_base_score="6.5" CVSS_exploit_subscore="8.0" CVSS_impact_subscore="6.4" CVSS_score="6.5" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-03-26" name="CVE-2007-1599" published="2007-03-22" seq="2007-1599" severity="Medium" type="CVE"><desc><descript source="cve">wp-login.php in WordPress allows remote attackers to redirect authenticated users to other websites and potentially obtain sensitive information via the redirect_to parameter.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/463291/100/0/threaded">20070320 Advisory - Redirection Vulnerability in wp-login.php.</ref><ref adv="1" source="" url="http://www.metaeye.org/advisories/40"></ref><ref source="DEBIAN" url="http://www.debian.org/security/2008/dsa-1601">DSA-1601</ref><ref source="SECUNIA" url="http://secunia.com/advisories/30960">30960</ref></refs><vuln_soft><prod name="WordPress" vendor="WordPress"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" CVSS_score="9.3" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-03-26" name="CVE-2007-1600" published="2007-03-22" seq="2007-1600" severity="High" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in module.php in Digital Eye Gallery 1.1 Beta (aka 0.1.1b) allows remote attackers to execute arbitrary PHP code via a URL in the menu parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3533">3533</ref><ref source="BID" url="http://www.securityfocus.com/bid/23083">23083</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1070">
ADV-2007-1070</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33115">
digital-eye-module-file-include(33115)</ref></refs><vuln_soft><prod name="Digital Eye Gallery" vendor="Digital Eye Gallery"><vers num="0.1.1b"/><vers num="1.1 Beta"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0" modified="2007-03-26" name="CVE-2007-1601" published="2007-03-22" seq="2007-1601" severity="Medium" type="CVE"><desc><descript source="cve">** DISPUTED **  Directory traversal vulnerability in check_vote.php in Weekly Drawing Contest 0.0.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the order parameter.  NOTE: another researcher disputes this vulnerability, noting that the order variable is not used in any context that allows opening files.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/462702/100/100/threaded">20070313 Re: Weekly Drawing Contest &lt;= (check_vote.php) Remote File Disclosure Vuln</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/462663/100/100/threaded">20070313 Weekly Drawing Contest &lt;= (check_vote.php) Remote File Disclosure Vuln</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2453">2453</ref></refs><vuln_soft><prod name="Weekly Drawing Contest" vendor="Weekly Drawing Contest"><vers num="0.0.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-03-26" name="CVE-2007-1602" published="2007-03-22" seq="2007-1602" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in check_vote.php in Weekly Drawing Contest 0.0.1 allows remote attackers to execute arbitrary SQL commands via the order parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/462702/100/100/threaded">20070313 Re: Weekly Drawing Contest &lt;= (check_vote.php) Remote File Disclosure Vuln</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2453">2453</ref></refs><vuln_soft><prod name="Weekly Drawing Contest" vendor="Weekly Drawing Contest"><vers num="0.0.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-03-26" name="CVE-2007-1603" published="2007-03-22" seq="2007-1603" severity="High" type="CVE"><desc><descript source="cve">admin/contest.php in Weekly Drawing Contest 0.0.1 allows remote attackers to bypass authentication, and insert new contest information into a database, via a direct POST request.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/462702/100/100/threaded">20070313 Re: Weekly Drawing Contest &lt;= (check_vote.php) Remote File Disclosure Vuln</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2453">2453</ref></refs><vuln_soft><prod name="Weekly Drawing Contest" vendor="Weekly Drawing Contest"><vers num="0.0.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-03-26" name="CVE-2007-1604" published="2007-03-22" seq="2007-1604" severity="High" type="CVE"><desc><descript source="cve">Multiple unrestricted file upload vulnerabilities in w-Agora (Web-Agora) allow remote attackers to upload and execute arbitrary PHP code (1) via a forum message with an attached file, which is stored under forums/hello/hello/notes/ or (2) by using browse_avatar.php to upload a file with a double extension, as demonstrated by .php.jpg.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/463286/100/0/threaded">20070320 w-agora [multiples file upload,xss,full path disclosure,error sql]</ref><ref source="BID" url="http://www.securityfocus.com/bid/23055">23055</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24605">24605</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33173">
wagora-browseavatar-file-upload(33173)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2462">2462</ref></refs><vuln_soft><prod name="W-Agora" vendor="W-Agora"><vers num="4.2.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0" modified="2007-03-26" name="CVE-2007-1605" published="2007-03-22" seq="2007-1605" severity="Medium" type="CVE"><desc><descript source="cve">w-Agora (Web-Agora) allows remote attackers to obtain sensitive information via a request to rss.php with an invalid (1) site or (2) bn parameter, (3) a certain value of the site[] parameter, or (4) an empty value of the bn[] parameter; a request to index.php with a certain value of the (5) site[] or (6) sort[] parameter; (7) a request to profile.php with an empty value of the site[] parameter; or a request to search.php with (8) an empty value of the bn[] parameter or a certain value of the (9) pattern[] or (10) search_date[] parameter, which reveal the path in various error messages, probably related to variable type inconsistencies.  NOTE: the bn[] parameter to index.php is already covered by CVE-2007-0606.1.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/><design/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/463286/100/0/threaded">20070320 w-agora [multiples file upload,xss,full path disclosure,error sql]</ref><ref source="BID" url="http://www.securityfocus.com/bid/23057">23057</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24605">24605</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33174">
wagora-multiple-path-disclosure(33174)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2462">2462</ref></refs><vuln_soft><prod name="W-Agora" vendor="W-Agora"><vers num="4.2.1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" modified="2007-03-23" name="CVE-2007-1606" published="2007-03-22" seq="2007-1606" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in w-Agora (Web-Agora) allow remote attackers to inject arbitrary web script or HTML via (1) the showuser parameter to profile.php, the (2) search_forum or (3) search_user parameter to search.php, or (4) the userid parameter to change_password.php.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/463286/100/0/threaded">20070320 w-agora [multiples file upload,xss,full path disclosure,error sql]</ref><ref source="BID" url="http://www.securityfocus.com/bid/23057">23057</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24605">24605</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33175">
wagora-multiple-xss(33175)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2462">2462</ref></refs><vuln_soft><prod name="W-Agora" vendor="W-Agora"><vers num="4.2.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0" modified="2007-03-26" name="CVE-2007-1607" published="2007-03-22" seq="2007-1607" severity="Medium" type="CVE"><desc><descript source="cve">search.php in w-Agora (Web-Agora) allows remote attackers to obtain potentially sensitive information via a &apos; (quote) value followed by certain SQL sequences in the (1) search_forum or (2) search_user parameter, which force a SQL error.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/463286/100/0/threaded">20070320 w-agora [multiples file upload,xss,full path disclosure,error sql]</ref><ref source="BID" url="http://www.securityfocus.com/bid/23057">23057</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24605">24605</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33177">
wagora-search-sql-injection(33177)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2462">2462</ref></refs><vuln_soft><prod name="W-Agora" vendor="W-Agora"><vers num="4.2.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-03-26" name="CVE-2007-1608" published="2007-03-22" seq="2007-1608" severity="High" type="CVE"><desc><descript source="cve">CRLF injection vulnerability in IBM WebSphere Application Server (WAS) before 6.0.2.19 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via a single CRLF sequence in a context that is not a valid multi-line header.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="AIXAPAR" url="http://www-1.ibm.com/support/docview.wss?uid=swg1PK39732">39732</ref><ref source="BID" url="http://www.securityfocus.com/bid/23086">23086</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24552">24552</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1062">
ADV-2007-1062</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017806">
1017806</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33123">
websphere-unspecified-response-splitting(33123)</ref></refs><vuln_soft><prod name="WebSphere Application Server" vendor="IBM"><vers num="6.0.2.15" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" modified="2007-03-26" name="CVE-2007-1609" published="2007-03-22" seq="2007-1609" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in servlet/Spy in Dynamic Monitoring Services (DMS) in Oracle Application Server (OAS) 10g 10.1.2.0.0 allows remote attackers to inject arbitrary web script or HTML via the table parameter.  NOTE: This may be related to CVE-2002-0563.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/463285/100/0/threaded">20070320 Oracle 10g Dynamic Monitoring Services XSS /servlet/Spy</ref><ref source="BID" url="http://www.securityfocus.com/bid/23102">
23102</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1078">
ADV-2007-1078</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24554">
24554</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33146">
oracle-dynamicmonitoring-xss(33146)</ref><ref source="OSVDB" url="http://www.osvdb.org/33521">
33521</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2474">2474</ref></refs><vuln_soft><prod name="Oracle10g Application Server" vendor="Oracle"><vers num="10.1.2.0.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" modified="2007-03-26" name="CVE-2007-1610" published="2007-03-22" seq="2007-1610" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in the RSS reader in Glue Software NewsGlue before 1.3.4 allows remote attackers to inject arbitrary web script or HTML via a feed.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref source="" url="http://jvn.jp/jp/JVN%2364227086/index.html"></ref><ref source="" url="http://www.gluesoft.co.jp/NewsGlue/Update.aspx"></ref><ref source="BID" url="http://www.securityfocus.com/bid/23094">
23094</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1074">
ADV-2007-1074</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24603">
24603</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33166">
newsglue-rss-feed-xss(33166)</ref></refs><vuln_soft><prod name="NewsGlue" vendor="Glue Software"><vers num="1.3.3" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" modified="2007-03-23" name="CVE-2007-1611" published="2007-03-22" seq="2007-1611" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in the RSS reader in a certain SOURCENEXT product, probably IKANARI JIJYOU 1.0.0 and 1.0.1, allows remote attackers to inject arbitrary web script or HTML via the title of an article in a feed.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref source="" url="http://jvn.jp/jp/JVN%2364227086/index.html"></ref><ref source="" url="http://www.sourcenext.info/download/jijou.html"></ref></refs><vuln_soft><prod name="IKANARI JIJYOU" vendor="SourceNext"><vers num="1.0.0"/><vers num="1.0.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-03-23" name="CVE-2007-1612" published="2007-03-22" seq="2007-1612" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in index.php in Katalog Plyt Audio 1.0 and earlier allows remote attackers to execute arbitrary SQL commands via the kolumna parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MILW0RM" url="http://milw0rm.com/exploits/3513">3513</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24539">24539</ref><ref source="BID" url="http://www.securityfocus.com/bid/23024">
23024</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1015">
ADV-2007-1015</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33048">
katalog-index-sql-injection(33048)</ref></refs><vuln_soft><prod name="Katalog Plyt Audio" vendor="Katalog Plyt Audio"><vers num="1.0" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-04-09" name="CVE-2007-1613" published="2007-03-22" seq="2007-1613" severity="High" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in view.php in MPM Chat 2.5 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the logi parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BID" url="http://www.securityfocus.com/bid/23009">23009</ref><ref adv="1" source="MILW0RM" url="http://milw0rm.com/exploits/3503">3503</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1008">ADV-2007-1008</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24576">24576</ref></refs><vuln_soft><prod name="MPM Chat" vendor="MPM Chat"><vers num="2.5"/></prod></vuln_soft></entry><entry CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" CVSS_score="9.3" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-03-23" name="CVE-2007-1614" published="2007-03-22" seq="2007-1614" severity="High" type="CVE"><desc><descript source="cve">Stack-based buffer overflow in the zzip_open_shared_io function in zzip/file.c in ZZIPlib Library before 0.13.49 allows user-assisted remote attackers to cause a denial of service (application crash) or execute arbitrary code via a long filename.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/><user_init/></range><refs><ref source="" url="http://www.securitylab.ru/forum/read.php?FID=21&amp;TID=40858&amp;MID=326187"></ref><ref patch="1" source="" url="http://sourceforge.net/project/shownotes.php?group_id=6389&amp;release_id=494587"></ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0998">ADV-2007-0998</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/24586">24586</ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200704-05.xml">
GLSA-200704-05</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24708">
24708</ref><ref source="BID" url="http://www.securityfocus.com/bid/23013">
23013</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2007:093">
MDKSA-2007:093</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:093">MDKSA-2007:093</ref></refs><vuln_soft><prod name="ZZipLib" vendor="ZZipLib"><vers num="0.13.45" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-03-26" name="CVE-2007-1615" published="2007-03-22" seq="2007-1615" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in index.php in ScriptMagix Jokes 2.0 and earlier allows remote attackers to execute arbitrary SQL commands via the catid parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MILW0RM" url="http://milw0rm.com/exploits/3509">3509</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24595">24595</ref><ref source="BID" url="http://www.securityfocus.com/bid/23015">
23015</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1012">
ADV-2007-1012</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33063">
scriptmagixjokes-index-sql-injection(33063)</ref></refs><vuln_soft><prod name="Scriptmagix Jokes" vendor="ScriptMagix"><vers num="2.0" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-03-26" name="CVE-2007-1616" published="2007-03-22" seq="2007-1616" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in index.php in ScriptMagix Lyrics 2.0 and earlier allows remote attackers to execute arbitrary SQL commands via the recid parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MILW0RM" url="http://milw0rm.com/exploits/3515">3515</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24563">24563</ref><ref source="BID" url="http://www.securityfocus.com/bid/23019">
23019</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1016">
ADV-2007-1016</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33056">
scriptmagixlyrics-index-sql-injection(33056)</ref></refs><vuln_soft><prod name="ScriptMagix Lyrics" vendor="ScriptMagix"><vers num="2.0" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-03-26" name="CVE-2007-1617" published="2007-03-22" seq="2007-1617" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in index.php in ScriptMagix Recipes 2.0 and earlier allows remote attackers to execute arbitrary SQL commands via the catid parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MILW0RM" url="http://milw0rm.com/exploits/3510">3510</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1013">ADV-2007-1013</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24594">24594</ref></refs><vuln_soft><prod name="ScriptMagix Recipes" vendor="ScriptMagix"><vers num="2.0" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-03-26" name="CVE-2007-1618" published="2007-03-22" seq="2007-1618" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in index.php in ScriptMagix FAQ Builder 2.0 and earlier allows remote attackers to execute arbitrary SQL commands via the catid parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3507">3507</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1011">ADV-2007-1011</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24704">
24704</ref></refs><vuln_soft><prod name="ScriptMagix FAQ Builder" vendor="ScriptMagix"><vers num="2.0" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-03-26" name="CVE-2007-1619" published="2007-03-22" seq="2007-1619" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in viewcomments.php in ScriptMagix Photo Rating 2.0 and earlier allows remote attackers to execute arbitrary SQL commands via the phid parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3511">3511</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1014">ADV-2007-1014</ref><ref source="BID" url="http://www.securityfocus.com/bid/23018">
23018</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24698">
24698</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33061">
scriptmagixphoto-viewcomments-sql-injection(33061)</ref></refs><vuln_soft><prod name="ScriptMagix Photo Rating" vendor="ScriptMagix"><vers num="2.0" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-03-26" name="CVE-2007-1620" published="2007-03-22" seq="2007-1620" severity="High" type="CVE"><desc><descript source="cve">Multiple PHP remote file inclusion vulnerabilities in PHP DB Designer 1.02 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the (1) _SESSION[SITE_PATH] parameter to (a) wind/help.php or (b) wind/about.php, or the (2) _SESSION[DRIVER] parameter to (c) db/session.php.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3501">3501</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1007">ADV-2007-1007</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33033">phpdbdesigner-multiple-script-file-include(33033)</ref></refs><vuln_soft><prod name="PHP DB Designer" vendor="PHP DB Designer"><vers num="1.02" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-03-26" name="CVE-2007-1621" published="2007-03-22" seq="2007-1621" severity="High" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in templates/head.php in Active PHP Bookmark Notes (APB) 0.2.5 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the APB_SETTINGS[template_path] parameter.  NOTE: this issue might be related to CVE-2003-1254.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3504">3504</ref><ref source="BID" url="http://www.securityfocus.com/bid/23010">23010</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1009">ADV-2007-1009</ref></refs><vuln_soft><prod name="Active PHP Bookmark Notes" vendor="lbstone"><vers num="0.2.5" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" discovered="2007-03-08" modified="2007-03-26" name="CVE-2007-1622" published="2007-03-22" seq="2007-1622" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in wp-admin/vars.php in WordPress before 2.0.10 RC2, and before 2.1.3 RC2 in the 2.1 series, allows remote authenticated users with theme privileges to inject arbitrary web script or HTML via the PATH_INFO in the administration interface, related to loose regular expression processing of PHP_SELF.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref source="" url="http://sla.ckers.org/forum/read.php?2,7935#msg-8006"></ref><ref adv="1" patch="1" source="" url="http://www.buayacorp.com/files/wordpress/wordpress-advisory.txt"></ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1005">ADV-2007-1005</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24567">24567</ref><ref source="DEBIAN" url="http://www.debian.org/security/2007/dsa-1285">
DSA-1285</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25108">
25108</ref><ref source="BID" url="http://www.securityfocus.com/bid/23027">
23027</ref></refs><vuln_soft><prod name="WordPress" vendor="WordPress"><vers num="2.0"/><vers num="2.0.1"/><vers num="2.0.10"/><vers num="2.0.10 RC1"/><vers num="2.0.2"/><vers num="2.0.3"/><vers num="2.0.4"/><vers num="2.0.5"/><vers num="2.0.6"/><vers num="2.0.7"/><vers num="2.1"/><vers num="2.1.1"/><vers num="2.1.2"/><vers num="2.1.3 RC1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" modified="2007-03-26" name="CVE-2007-1623" published="2007-03-23" seq="2007-1623" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in realGuestbook 5.01, when register_globals is enabled, allow remote attackers to inject arbitrary web script or HTML via the (1) bg_color_1, (2) fs_menu, (3) fc_menu, (4) ff_menu, (5) bg_color_2, (6) fs_normal, (7) fc_normal, and (8) ff_normal parameters to welcome_admin.php; and possibly unspecified other parameters and files.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24602">24602</ref><ref source="OSVDB" url="http://www.osvdb.org/34341">

34341</ref></refs><vuln_soft><prod name="realGuestbook" vendor="realGuestbook"><vers num="5.01"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-03-26" name="CVE-2007-1624" published="2007-03-23" seq="2007-1624" severity="High" type="CVE"><desc><descript source="cve">Multiple SQL injection vulnerabilities in realGuestbook 5.01 allow remote attackers to execute arbitrary SQL commands via the (1) name, (2) email, (3) homepage, and (4) text parameters to save_entry.php, as reachable through add_entry.php; and possibly other unspecified parameters and files.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BID" url="http://www.securityfocus.com/bid/23072">23072</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24602">24602</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1060">
ADV-2007-1060</ref><ref source="OSVDB" url="http://www.osvdb.org/34342">
34342</ref></refs><vuln_soft><prod name="realGuestbook" vendor="realGuestbook"><vers num="5.01"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" modified="2007-03-26" name="CVE-2007-1625" published="2007-03-23" seq="2007-1625" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in save_entry.php in realGuestbook 5.01 allows remote attackers to inject arbitrary web script or HTML via the homepage parameter, as reachable through add_entry.php.  NOTE: the original report stated that the vulnerability was in add_entry.php, which does not receive the input data.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref source="" url="http://trew.icenetx.net/toolz/advisory-realGuestbook_V5-en.txt"></ref><ref source="BID" url="http://www.securityfocus.com/bid/23072">23072</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24602">24602</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1060">
ADV-2007-1060</ref><ref source="OSVDB" url="http://www.osvdb.org/34343">
34343</ref></refs><vuln_soft><prod name="realGuestbook" vendor="realGuestbook"><vers num="5.01"/></prod></vuln_soft></entry><entry CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" CVSS_score="9.3" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-03-26" name="CVE-2007-1626" published="2007-03-23" seq="2007-1626" severity="High" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in iframe.php in the iFrame Module for PHP-NUKE allows remote attackers to execute arbitrary PHP code via a URL in the file parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3512">3512</ref><ref source="BID" url="http://www.securityfocus.com/bid/23038">23038</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33060">iframe-iframe-file-include(33060)</ref></refs><vuln_soft><prod name="PHP-Nuke iFrame Module" vendor="PHP-Nuke"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-12-12" name="CVE-2007-1627" published="2007-03-23" reject="1" seq="2007-1627" severity="High" type="CVE"><desc><descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2006-4606.  Reason: This candidate is a duplicate of CVE-2006-4606.  Notes: All CVE users should reference CVE-2006-4606 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs/></entry><entry CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" CVSS_score="9.3" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-07-03" name="CVE-2007-1628" published="2007-03-23" seq="2007-1628" severity="High" type="CVE"><desc><descript source="cve">Multiple PHP remote file inclusion vulnerabilities in Study planner (Studiewijzer) 0.15 and earlier, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the SPL_CFG[dirroot] parameter to (1) service.alert.inc.php or (2) settings.ses.php in inc/; (3) db/mysql/db.inc.php; (4) integration/shortstat/configuration.php; (5) ali.class.php or (6) cat.class.php in methodology/traditional/class/; (7) cat_browse.inc.php, (8) chr_browse.inc.php, (9) chr_display.inc.php, or (10) dash_browse.inc.php in methodology/traditional/ui/inc/; (11) spl.webservice.php or (12) konfabulator/gateway_admin.php in ws/; or other unspecified files.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3532">3532</ref><ref adv="1" source="" url="http://advisories.echo.or.id/adv/adv77-K-159-2007.txt"></ref><ref source="BID" url="http://www.securityfocus.com/bid/23076">23076</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/463491/100/0/threaded">20070322 [ECHO_ADV_77$2007] Study planner (Studiewijzer) &lt;= 0.15 Remote File Inclusion Vulnerability</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1069">ADV-2007-1069</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33128">studyplanner-multiple-scripts-file-include(33128)</ref></refs><vuln_soft><prod name="Studiewijzer" vendor="Studiewijzer"><vers num="0.13"/><vers num="0.14"/><vers num="0.15"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-03-26" name="CVE-2007-1629" published="2007-03-23" seq="2007-1629" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in default.asp in ActiveWebSoftwares Active Photo Gallery allows remote attackers to execute arbitrary SQL commands via the catid parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3536">3536</ref><ref source="BID" url="http://www.securityfocus.com/bid/23077">23077</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1072">
ADV-2007-1072</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24568">
24568</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33129">
active-default-sql-injection(33129)</ref></refs><vuln_soft><prod name="Active Photo Gallery" vendor="Active Web Softwares"><vers num="6.2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-03-26" name="CVE-2007-1630" published="2007-03-23" seq="2007-1630" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in default.asp in ActiveWebSoftwares Active Link Engine allows remote attackers to execute arbitrary SQL commands via the catid parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3534">3534</ref><ref source="BID" url="http://www.securityfocus.com/bid/23080">23080</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1071">
ADV-2007-1071</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24574">
24574</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33111">
active-link-default-sql-injection(33111)</ref><ref source="OSVDB" url="http://www.osvdb.org/34364">34364</ref></refs><vuln_soft><prod name="Active Link Engine" vendor="Active Web Softwares"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-03-26" name="CVE-2007-1631" published="2007-03-23" seq="2007-1631" severity="High" type="CVE"><desc><descript source="cve">** DISPUTED **  PHP remote file inclusion vulnerability in signup.php in CLBOX 1.01 allows remote attackers to execute arbitrary PHP code via a URL in the header parameter.  NOTE: this issue has been disputed by a reliable third party, stating that header is defined through an include file before use.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/463076/100/0/threaded">20070317 CLBOX &lt;= (signup.php header) Remote File Include Vulnerability</ref><ref source="VIM" url="http://www.attrition.org/pipermail/vim/2007-March/001443.html">20070319 Bogus - [CLBOX &lt;= (signup.php header) Remote File Include Vulnerability]</ref><ref source="OSVDB" url="http://www.osvdb.org/33503">
33503</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2469">2469</ref></refs><vuln_soft><prod name="CLBOX" vendor="CLBOX"><vers num="1.01"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-09-17" name="CVE-2007-1632" published="2007-03-23" seq="2007-1632" severity="High" type="CVE"><desc><descript source="cve">Unspecified vulnerability in TYPOlight webCMS before 2.2 Build 5 has unknown impact and attack vectors related to a &quot;major security hole.&quot;</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs><ref source="" url="http://www.typolight.org/changelog.html"></ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/24546">24546</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1026">ADV-2007-1026</ref><ref source="OSVDB" url="http://www.osvdb.org/33303">33303</ref></refs><vuln_soft><prod name="TYPOlight webCMS" vendor="TYPOlight"><vers num="2.2 Build 0"/><vers num="2.2 Build 1"/><vers num="2.2 Build 2"/><vers num="2.2 Build 3"/><vers num="2.2 Build 4"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-03-27" name="CVE-2007-1633" published="2007-03-23" seq="2007-1633" severity="High" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in bbcode_ref.php in the Giorgio Ciranni Splatt Forum 4.0 RC1 module for PHP-Nuke allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the name parameter, as demonstrated by injecting PHP sequences into an Apache HTTP Server log file, which is then included by bbcode_ref.php.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3518">3518</ref><ref source="BID" url="http://www.securityfocus.com/bid/23035">23035</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1027">ADV-2007-1027</ref></refs><vuln_soft><prod name="Splatt Forum" vendor="Giorgio Ciranni"><vers num="4.0 rc1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-03-27" name="CVE-2007-1634" published="2007-03-23" seq="2007-1634" severity="High" type="CVE"><desc><descript source="cve">Variable extraction vulnerability in grab_globals.php in Net Portal Dynamic System (NPDS) 5.10 and earlier allows remote attackers to conduct SQL injection attacks via the _FILES[DB][tmp_name] parameter to print.php, which overwrites the $DB variable with dynamic variable evaluation.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/463176/100/0/threaded">20070318 Net Portal Dynamic System (NPDS) &lt;= 5.10 Remote Code Execution 0day</ref><ref source="VIM" url="http://www.attrition.org/pipermail/vim/2007-March/001460.html">20070323 Root cause of NPDS SQL injection is variable extraction/evaluation</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24571">24571</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2473">2473</ref></refs><vuln_soft><prod name="Net Portal Dynamic System" vendor="Net Portal Dynamic System"><vers num="5.10" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="9.0" CVSS_exploit_subscore="8.0" CVSS_impact_subscore="10.0" CVSS_score="9.0" CVSS_vector="(AV:N/AC:L/Au:S/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-03-27" name="CVE-2007-1635" published="2007-03-23" seq="2007-1635" severity="High" type="CVE"><desc><descript source="cve">Static code injection vulnerability in admin/settings.php in Net Portal Dynamic System (NPDS) 5.10 and earlier allows remote authenticated users to inject arbitrary PHP code via the xtop parameter in a &quot;ConfigSave&quot; op to admin.php, which can later be accessed via a &quot;Configure&quot; op to admin.php.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/463176/100/0/threaded">20070318 Net Portal Dynamic System (NPDS) &lt;= 5.10 Remote Code Execution 0day</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24571">24571</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2473">2473</ref></refs><vuln_soft><prod name="Net Portal Dynamic System" vendor="Net Portal Dynamic System"><vers num="5.10" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-04-05" name="CVE-2007-1636" published="2007-03-23" seq="2007-1636" severity="High" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in index.php in RoseOnlineCMS 3 B1 allows remote attackers to include arbitrary files via a .. (dot dot) sequence in the op parameter, as demonstrated by injecting PHP code into Apache log files via the URL and User-Agent HTTP header.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3548">3548</ref><ref source="BID" url="http://www.securityfocus.com/bid/23108">23108</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1094">ADV-2007-1094</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33185">roseonlinecms-index-file-include(33185)</ref></refs><vuln_soft><prod name="RoseOnlineCMS" vendor="RoseOnlineCMS"><vers num="3 B1"/></prod></vuln_soft></entry><entry CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" CVSS_score="9.3" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-03-27" name="CVE-2007-1637" published="2007-03-23" seq="2007-1637" severity="High" type="CVE"><desc><descript source="cve">Multiple buffer overflows in the IMAILAPILib ActiveX control (IMailAPI.dll) in Ipswitch IMail Server before 2006.2 allow remote attackers to execute arbitrary code via the (1) WebConnect and (2) Connect members in the (a) IMailServer control; (3) Sync3 and (4) Init3 members in the (b) IMailLDAPService control; and the (5) SetReplyTo member in the (c) IMailUserCollection control.</descript></desc><sols><sol source="nvd">Upgrade to version 2006.2.</sol></sols><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/><user_init/></range><refs><ref source="IDEFENSE" url="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=487">20070307 Ipswitch IMail Server 2006 Multiple ActiveX Control Buffer Overflow Vulnerabilitie</ref><ref source="" url="http://support.ipswitch.com/kb/IM-20070305-JH01.htm"></ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0853">ADV-2007-0853</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017737">1017737</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24422">24422</ref></refs><vuln_soft><prod name="IMail Plus" vendor="Ipswitch"><vers num="2006"/></prod><prod name="IMail Premium" vendor="Ipswitch"><vers num="2006"/></prod><prod name="Ipswitch Collaboration Suite" vendor="Ipswitch"><vers num="2006 Standard"/></prod><prod name="IMail" vendor="Ipswitch"><vers num="2006"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-03-27" name="CVE-2007-1638" published="2007-03-23" seq="2007-1638" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site request forgery (CSRF) vulnerabilities in the check_csrftoken function in lib/lib.inc.php in PHProjekt 5.2.0, when magic_quotes_gpc is disabled, allow remote attackers to perform unauthorized actions as an arbitrary user via the (1) Projects, (2) Contacts, (3) Helpdesk, (4) Notes, (5) Search, (6) Mail, or (7) Filemanager module; the (9) summary page; or unspecified other files.</descript></desc><impacts><impact source="nvd">Successful exploitation requires that variable &quot;magic_quotes_gpc&quot; is disabled.</impact></impacts><sols><sol source="nvd">Upgrade to version 5.2.1,</sol></sols><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/462786/100/100/threaded">20070314 n.runs-SA-2007.005 - PHProjekt 5.2.0 - Cross Site Request Forgery</ref><ref source="" url="http://www.nruns.de/security_advisory_phprojekt_csrf.php"></ref><ref source="" url="http://www.phprojekt.com/index.php?name=News&amp;file=article&amp;sid=276"></ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/24509">24509</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32989">phprojekt-multiple-modules-csrf(32989)</ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200706-07.xml">GLSA-200706-07</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25748">25748</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2477">2477</ref></refs><vuln_soft><prod name="PHPProjekt" vendor="PHPProjekt"><vers num="5.2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:N/AC:H/Au:S/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-07-03" name="CVE-2007-1639" published="2007-03-23" seq="2007-1639" severity="Medium" type="CVE"><desc><descript source="cve">Unrestricted file upload vulnerability in PHProjekt 5.2.0, when magic_quotes_gpc is disabled, allows remote authenticated users to upload and execute arbitrary PHP code via a file with an executable extension, which is then accessed by the (1) calendar or (2) file management module, or possibly unspecified other files.</descript></desc><impacts><impact source="nvd">Successful exploitation requires that variable &quot;magic_quotes_gpc&quot; is disabled.</impact></impacts><sols><sol source="nvd">Upgrade to version 5.2.1.</sol></sols><loss_types><avail/><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/462785/100/100/threaded">20070314 n.runs-SA-2007.006 - PHProjekt 5.2.0 - Privilege escalation</ref><ref source="" url="http://www.nruns.de/security_advisory_phprojekt_privilege_escalation.php"></ref><ref source="" url="http://www.phprojekt.com/index.php?name=News&amp;file=article&amp;sid=276"></ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/22956">22956</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/24509">24509</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/32995">phprojekt-calendarfile-file-upload(32995)</ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200706-07.xml">GLSA-200706-07</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25748">25748</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2476">2476</ref></refs><vuln_soft><prod name="PHPProjekt" vendor="PHPProjekt"><vers num="5.2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-03-27" name="CVE-2007-1640" published="2007-03-23" seq="2007-1640" severity="High" type="CVE"><desc><descript source="cve">Multiple PHP remote file inclusion vulnerabilities in ClassWeb 2.03 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the BASE parameter to (1) language.php and (2) phpadmin/survey.php.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3542">3542</ref><ref source="BID" url="http://www.securityfocus.com/bid/23095">23095</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1085">
ADV-2007-1085</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33162">
classweb-languagesurvey-file-include(33162)</ref></refs><vuln_soft><prod name="ClassWeb" vendor="ClassWeb"><vers num="2.03" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-03-27" name="CVE-2007-1641" published="2007-03-23" seq="2007-1641" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in index.php in PortailPHP 2.0 allows remote attackers to execute arbitrary SQL commands via the idnews parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3543">3543</ref><ref source="BID" url="http://www.securityfocus.com/bid/23096">23096</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24620">
24620</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33145">
portailphp-idnews-sql-injection(33145)</ref></refs><vuln_soft><prod name="PortailPHP" vendor="PortailPHP"><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.0" CVSS_exploit_subscore="8.0" CVSS_impact_subscore="2.9" CVSS_score="4.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:N/A:N)" CVSS_version="2.0" modified="2007-04-10" name="CVE-2007-1642" published="2007-03-23" seq="2007-1642" severity="Medium" type="CVE"><desc><descript source="cve">Unspecified vulnerability in ManageEngine Firewall Analyzer allows remote authenticated users to &quot;access any common file&quot; via a direct URL request.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/463509/100/0/threaded">20070322 ManageEngine Firewall Analyzer arbitrary file disclosure to authorized user</ref><ref source="BID" url="http://www.securityfocus.com/bid/23097">23097</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/464154/100/0/threaded">20070329 Re: ManageEngine Firewall Analyzer arbitrary file disclosure to authorized user</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/464271/100/0/threaded">20070330 Re: ManageEngine Firewall Analyzer arbitrary file disclosure to authorized user</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24707">24707</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33319">
manageengine-unspecified-info-disclosure(33319)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2479">2479</ref></refs><vuln_soft><prod name="Firewall Analyzer" vendor="ManageEngine"><vers num="4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-04-05" name="CVE-2007-1643" published="2007-03-23" seq="2007-1643" severity="High" type="CVE"><desc><descript source="cve">Multiple PHP remote file inclusion vulnerabilities in LAN Management System (LMS) 1.8.9 Vala and earlier allow remote attackers to execute arbitrary PHP code via a URL in (1) the CONFIG[directories][userpanel_dir] parameter to userpanel.php or the (2) _LIB_DIR parameter to welcome.php.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3545">3545</ref><ref source="BID" url="http://www.securityfocus.com/bid/23099">23099</ref><ref source="BID" url="http://www.securityfocus.com/bid/23100">23100</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1086">ADV-2007-1086</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24621">24621</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33158">lms-userpanelwelcome-file-include(33158)</ref><ref source="VIM" url="http://www.attrition.org/pipermail/vim/2007-April/001560.html">
20070426 true: 2 distinct LMS RFI, one old, one new; and vague ACK</ref></refs><vuln_soft><prod name="LAN Management System" vendor="LAN Management System"><vers edition="Vala" num="1.8.9" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-04-26" name="CVE-2007-1644" published="2007-03-23" seq="2007-1644" severity="High" type="CVE"><desc><descript source="cve">The dynamic DNS update mechanism in the DNS Server service on Microsoft Windows does not properly authenticate clients in certain deployments or configurations, which allows remote attackers to change DNS records for a web proxy server and conduct man-in-the-middle (MITM) attacks on web traffic, conduct pharming attacks by poisoning DNS records, and cause a denial of service (erroneous name resolution).</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3544">3544</ref></refs><vuln_soft><prod name="ALL Windows" vendor="Microsoft"><vers num="Abstract CPE"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-03-27" name="CVE-2007-1645" published="2007-03-23" seq="2007-1645" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in FutureSoft TFTP Server 2000 on Microsoft Windows 2000 SP4 allows remote attackers to execute arbitrary code via a long request on UDP port 69.  NOTE: this issue might overlap CVE-2006-4781 or CVE-2005-1812.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3541">3541</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33188">
futuresoft-seh-bo(33188)</ref></refs><vuln_soft><prod name="TFTP Server 2000" vendor="FutureSoft"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" modified="2007-03-26" name="CVE-2007-1646" published="2007-03-23" seq="2007-1646" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in SubHub 2.3.0 allow remote attackers to inject arbitrary web script or HTML via (1) the searchtext parameter to (a) /search, or the (2) message parameter to (b) /calendar or (c) /subscribe.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/463488/100/0/threaded">20070321 **SubHub v2.3.0**</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33161">
subhub-search-xss(33161)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2475">2475</ref></refs><vuln_soft><prod name="SubHub" vendor="SubHub"><vers num="2.3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.8" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.9" CVSS_score="7.8" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:N/A:N)" CVSS_version="2.0" modified="2007-03-26" name="CVE-2007-1647" published="2007-03-23" seq="2007-1647" severity="High" type="CVE"><desc><descript source="cve">Moodle 1.5.2 and earlier stores sensitive information under the web root with insufficient access control, and provides directory listings, which allows remote attackers to obtain user names, password hashes, and other sensitive information via a direct request for session (sess_*) files in moodledata/sessions/.</descript></desc><loss_types><conf/></loss_types><vuln_types><access/><design/></vuln_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3508">3508</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33147">moodle-sessions-information-disclosure(33147)</ref></refs><vuln_soft><prod name="Moodle" vendor="Moodle"><vers num="1.5.2" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.8" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.9" CVSS_score="7.8" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_version="2.0" modified="2007-03-26" name="CVE-2007-1648" published="2007-03-23" seq="2007-1648" severity="High" type="CVE"><desc><descript source="cve">0irc 1345 build 20060823 allows remote attackers to cause a denial of service (application crash) by operating an IRC server that sends a long string to a client, which triggers a NULL pointer dereference.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3547">3547</ref><ref source="BID" url="http://www.securityfocus.com/bid/23101">23101</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33224">
oircclient-null-pointer-dos(33224)</ref></refs><vuln_soft><prod name="0irc" vendor="dev0.de"><vers num="1345 Build 2006-08-23"/></prod></vuln_soft></entry><entry CVSS_base_score="7.8" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.9" CVSS_score="7.8" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:N/A:N)" CVSS_version="2.0" modified="2007-03-26" name="CVE-2007-1649" published="2007-03-23" seq="2007-1649" severity="High" type="CVE"><desc><descript source="cve">PHP 5.2.1 allows context-dependent attackers to read portions of heap memory by executing certain scripts with a serialized data input string beginning with S:, which does not properly track the number of input bytes being processed.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://www.php-security.org/MOPB/MOPB-29-2007.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/23105">
23105</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24630">
24630</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33170">
php-unserialize-information-disclosure(33170)</ref><ref source="" url="http://us2.php.net/releases/5_2_2.php"></ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDVSA-2008:126">MDVSA-2008:126</ref></refs><vuln_soft><prod name="PHP" vendor="PHP"><vers num="5.2.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.8" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.9" CVSS_score="7.8" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_version="2.0" modified="2007-03-26" name="CVE-2007-1650" published="2007-03-23" seq="2007-1650" severity="High" type="CVE"><desc><descript source="cve">pcapsipdump.cpp in pcapsipdump before 0.1.3 allows remote attackers to cause a denial of service (application crash) via a malformed SIP packet, which results in a NULL pointer dereference.</descript></desc><sols><sol source="nvd">Update to version 0.1.3.</sol></sols><loss_types><avail/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref source="" url="http://sourceforge.net/project/shownotes.php?release_id=495646&amp;group_id=173277"></ref></refs><vuln_soft><prod name="pcapsipdump" vendor="pcapsipdump"><vers num="0.1.1"/><vers num="0.1.2" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-03-26" name="CVE-2007-1651" published="2007-03-23" seq="2007-1651" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site request forgery (CSRF) vulnerability in OpenID allows remote attackers to restore the login session of a user on an OpenID enabled site via unspecified vectors related to an arbitrary remote web site and cached tokens, after the user has signed into an OpenID server, logged into the OpenID enabled site, and then logged out of the OpenID enabled site.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/><design/></vuln_types><range><network/><user_init/></range><refs><ref source="MLIST" url="http://openid.net/pipermail/security/2007-March/000286.html">[security] 20070321 MyOpenID</ref><ref source="MLIST" url="http://openid.net/pipermail/security/2007-March/000288.html">[security] 20070321 MyOpenID</ref><ref source="MLIST" url="http://openid.net/pipermail/security/2007-March/000291.html">[security] 20070321 MyOpenID</ref><ref source="MLIST" url="http://openid.net/pipermail/security/2007-March/000306.html">[security] 20070321 MyOpenID</ref><ref source="MLIST" url="http://openid.net/pipermail/security/2007-March/000311.html">[security] 20070322 MyOpenID</ref><ref source="" url="http://janrain.com/blog/2007/03/22/myopenid-security-fix/"></ref></refs><vuln_soft><prod name="OpenID" vendor="OpenID"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-03-26" name="CVE-2007-1652" published="2007-03-23" seq="2007-1652" severity="High" type="CVE"><desc><descript source="cve">OpenID allows remote attackers to forcibly log a user into an OpenID enabled site, divulge the user&apos;s personal information to this site, and add it site to the trusted sites list via a crafted web page, related to cached tokens.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref source="MLIST" url="http://openid.net/pipermail/security/2007-March/000286.html">[security] 20070321 MyOpenID</ref><ref source="MLIST" url="http://openid.net/pipermail/security/2007-March/000288.html">[security] 20070321 MyOpenID</ref><ref source="MLIST" url="http://openid.net/pipermail/security/2007-March/000291.html">[security] 20070321 MyOpenID</ref><ref source="MLIST" url="http://openid.net/pipermail/security/2007-March/000306.html">[security] 20070321 MyOpenID</ref><ref source="MLIST" url="http://openid.net/pipermail/security/2007-March/000311.html">[security] 20070322 MyOpenID</ref><ref source="" url="http://janrain.com/blog/2007/03/22/myopenid-security-fix/"></ref></refs><vuln_soft><prod name="OpenID" vendor="OpenID"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.8" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.9" CVSS_score="7.8" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_version="2.0" modified="2007-03-26" name="CVE-2007-1653" published="2007-03-23" seq="2007-1653" severity="High" type="CVE"><desc><descript source="cve">GlowWorm FW before 1.5.3b4 allows remote attackers to cause a denial of service (kernel panic) via certain DNS responses that trigger infinite recursion in TrueDNS packet parsing, as originally observed with certain login.yahoo.com responses.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref source="" url="http://glowworm.us/history/release_1_5_3_b4.html"></ref></refs><vuln_soft><prod name="GlowWorm" vendor="GlowWorm"><vers num="1.5.3b3" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" CVSS_score="9.3" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-06-27" name="CVE-2007-1654" published="2007-03-23" seq="2007-1654" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in the Ne7sshSftp::addOpenHandle function in ne7ssh_sftp.cpp in NetSieben SSH Library (ne7ssh) before 1.2.1 allows user-assisted remote SFTP servers to cause a denial of service (crash) or possibly execute arbitrary code via multiple file transfers, related to multiple open file handles in SFTP (1) put and (2) get operations.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/><user_init/></range><refs><ref source="" url="http://netsieben.com/files/CHANGELOG"></ref></refs><vuln_soft><prod name="NetSieben SSH Library" vendor="NetSieben"><vers num="1.03"/><vers num="1.1"/><vers num="1.1.5"/><vers num="1.1.6"/><vers num="1.2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-03-26" name="CVE-2007-1655" published="2007-03-23" seq="2007-1655" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in the fun_ladd function in funmath.cpp in TinyMUX before 20070126 might allow remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via unspecified vectors related to lists of numbers.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref source="" url="http://code.google.com/p/tinymux/issues/detail?id=282&amp;can=2&amp;q="></ref><ref source="" url="http://www.tinymux.org/changes.txt"></ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1213">
ADV-2007-1213</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24733">
24733</ref><ref source="BID" url="http://www.securityfocus.com/bid/23292">
23292</ref><ref source="DEBIAN" url="http://www.debian.org/security/2007/dsa-1317">DSA-1317</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25784">25784</ref></refs><vuln_soft><prod name="TinyMUX" vendor="TinyMUX"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-03-26" name="CVE-2007-1656" published="2007-03-23" seq="2007-1656" severity="High" type="CVE"><desc><descript source="cve">Multiple SQL injection vulnerabilities in index.php in Katalog Plyt Audio 1.0 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) fraza and (2) litera parameters, different vectors than CVE-2007-1612.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1015">ADV-2007-1015</ref></refs><vuln_soft><prod name="Katalog Plyt Audio" vendor="Katalog Plyt Audio"><vers num="1.0" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-03-26" name="CVE-2007-1657" published="2007-03-23" seq="2007-1657" severity="High" type="CVE"><desc><descript source="cve">Stack-based buffer overflow in the file_compress function in minigzip (Modules/zlib) in Python 2.5 allows context-dependent attackers to execute arbitrary code via a long file argument.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/462799/100/0/threaded">20070314 Fwd: Python 2.5 (Modules/zlib) minigzip local buffer overflow vulnerability</ref><ref source="VIM" url="http://attrition.org/pipermail/vim/2007-March/001430.html">20070314 [TRUE] Python 2.5 (Modules/zlib) minigzip local buffer overflow vulnerability</ref><ref source="BID" url="http://www.securityfocus.com/bid/22964">22964</ref></refs><vuln_soft><prod name="Python" vendor="Python Software Foundation"><vers num="2.5"/></prod></vuln_soft></entry><entry CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" CVSS_score="9.3" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-06-14" name="CVE-2007-1658" published="2007-03-24" seq="2007-1658" severity="High" type="CVE"><desc><descript source="cve">Windows Mail in Microsoft Windows Vista might allow user-assisted remote attackers to execute certain programs via a link to a (1) local file or (2) UNC share pathname in which there is a directory with the same base name as an executable program at the same level, as demonstrated using C:/windows/system32/winrm (winrm.cmd) and migwiz (migwiz.exe).</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><range><network/><user_init/></range><refs><ref source="FULLDISC" url="http://archives.neohapsis.com/archives/fulldisclosure/2007-03/0344.html">20070323 Microsoft Windows Vista - Windows Mail Client Side Code Execution Vulnerability</ref><ref source="FULLDISC" url="http://archives.neohapsis.com/archives/fulldisclosure/2007-03/0345.html">20070323 Re: Microsoft Windows Vista - Windows Mail Client Side Code Execution Vulnerability</ref><ref source="FULLDISC" url="http://archives.neohapsis.com/archives/fulldisclosure/2007-03/0346.html">20070323 Re: Microsoft Windows Vista - Windows Mail Client Side Code Execution Vulnerability</ref><ref source="BID" url="http://www.securityfocus.com/bid/23103">23103</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33167">windows-mail-code-execution(33167)</ref><ref source="" url="http://isc.sans.org/diary.html?storyid=2507"></ref><ref source="" url="http://news.com.com/2100-1002_3-6170133.html"></ref><ref source="" url="http://www.computerworld.com/action/article.do?command=viewArticleBasic&amp;articleId=9014194"></ref><ref source="HP" url="http://www.securityfocus.com/archive/1/archive/1/471947/100/0/threaded">HPSBST02231</ref><ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms07-034.mspx">MS07-034</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA07-163A.html">TA07-163A</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/2154">ADV-2007-2154</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1861">oval:org.mitre.oval:def:1861</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017816">1017816</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25639">25639</ref></refs><vuln_soft><prod name="Windows Vista" vendor="Microsoft"><vers num="Business"/><vers num="Enterprise"/><vers num="Home Basic"/><vers num="Home Premium"/><vers edition="32 bit" num="Ultimate"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2008-03-25" name="CVE-2007-1659" published="2007-11-07" seq="2007-1659" severity="Medium" type="CVE"><desc><descript source="cve">Perl-Compatible Regular Expression (PCRE) library before 7.3 allows context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via regex patterns containing unmatched &quot;\Q\E&quot; sequences with orphan &quot;\E&quot; codes.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><range><network/></range><refs><ref source="" url="http://www.pcre.org/changelog.txt"></ref><ref patch="1" source="DEBIAN" url="http://www.debian.org/security/2007/dsa-1399">DSA-1399</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/3725">ADV-2007-3725</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/483357/100/0/threaded">20071106 rPSA-2007-0231-1 pcre</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/483579/100/0/threaded">20071112 FLEA-2007-0064-1 pcre</ref><ref source="MLIST" url="http://mail.gnome.org/archives/gtk-devel-list/2007-November/msg00022.html">[gtk-devel-list] 20071107 GLib 2.14.3</ref><ref source="" url="https://issues.rpath.com/browse/RPL-1738"></ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200711-30.xml">GLSA-200711-30</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:211">MDKSA-2007:211</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:212">MDKSA-2007:212</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2007-0967.html">RHSA-2007:0967</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2007-1068.html">RHSA-2007:1068</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2007_62_pcre.html">SUSE-SA:2007:062</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2007_25_sr.html">SUSE-SR:2007:025</ref><ref source="UBUNTU" url="http://www.ubuntulinux.org/support/documentation/usn/usn-547-1">USN-547-1</ref><ref source="BID" url="http://www.securityfocus.com/bid/26346">26346</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/3790">ADV-2007-3790</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1018895">1018895</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/27598">27598</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/27538">27538</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/27543">27543</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/27547">27547</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/27554">27554</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/27741">27741</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/27773">27773</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/27697">27697</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/38272">pcre-regex-code-execution(38272)</ref><ref source="" url="http://support.avaya.com/elmodocs2/security/ASA-2007-505.htm"></ref><ref source="" url="http://docs.info.apple.com/article.html?artnum=307179"></ref><ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2007/Dec/msg00002.html">APPLE-SA-2007-12-17</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA07-352A.html">TA07-352A</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/4238">ADV-2007-4238</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/28041">28041</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/27965">27965</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/28136">28136</ref><ref source="" url="http://bugs.gentoo.org/show_bug.cgi?id=198976"></ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200801-02.xml">GLSA-200801-02</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/28406">28406</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/28414">28414</ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200801-18.xml">GLSA-200801-18</ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200801-19.xml">GLSA-200801-19</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDVSA-2008:030">MDVSA-2008:030</ref><ref source="SUSE" url="http://lists.opensuse.org/opensuse-security-announce/2008-01/msg00006.html">SUSE-SA:2008:004</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/28658">28658</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/28714">28714</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/28720">28720</ref><ref source="FEDORA" url="https://www.redhat.com/archives/fedora-package-announce/2008-March/msg00181.html">FEDORA-2008-1842</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/29267">29267</ref><ref source="" url="http://docs.info.apple.com/article.html?artnum=307562"></ref><ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2008/Mar/msg00001.html">APPLE-SA-2008-03-18</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/0924/references">ADV-2008-0924</ref><ref source="SECUNIA" url="http://secunia.com/advisories/29420">29420</ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200805-11.xml">GLSA-200805-11</ref><ref source="SECUNIA" url="http://secunia.com/advisories/30155">30155</ref><ref source="SECUNIA" url="http://secunia.com/advisories/30219">30219</ref></refs><vuln_soft><prod name="PCRE" vendor="PCRE"><vers num="7.3" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2008-03-12" name="CVE-2007-1660" published="2007-11-07" seq="2007-1660" severity="Medium" type="CVE"><desc><descript source="cve">Perl-Compatible Regular Expression (PCRE) library before 7.0 does not properly calculate sizes for unspecified &quot;multiple forms of character class&quot;, which triggers a buffer overflow that allows context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><range><network/></range><refs><ref patch="1" source="DEBIAN" url="http://www.debian.org/security/2007/dsa-1399">DSA-1399</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/3725">ADV-2007-3725</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/483357/100/0/threaded">20071106 rPSA-2007-0231-1 pcre</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/483579/100/0/threaded">20071112 FLEA-2007-0064-1 pcre</ref><ref source="MLIST" url="http://mail.gnome.org/archives/gtk-devel-list/2007-November/msg00022.html">[gtk-devel-list] 20071107 GLib 2.14.3</ref><ref source="" url="https://issues.rpath.com/browse/RPL-1738"></ref><ref source="" url="http://support.avaya.com/elmodocs2/security/ASA-2007-488.htm"></ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200711-30.xml">GLSA-200711-30</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:211">MDKSA-2007:211</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:212">MDKSA-2007:212</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:213">MDKSA-2007:213</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2007-0967.html">RHSA-2007:0967</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2007-0968.html">RHSA-2007:0968</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2007-1063.html">RHSA-2007:1063</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2007-1065.html">RHSA-2007:1065</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2007_62_pcre.html">SUSE-SA:2007:062</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2007_25_sr.html">SUSE-SR:2007:025</ref><ref source="UBUNTU" url="http://www.ubuntulinux.org/support/documentation/usn/usn-547-1">USN-547-1</ref><ref source="BID" url="http://www.securityfocus.com/bid/26346">26346</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/3790">ADV-2007-3790</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1018895">1018895</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/27598">27598</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/27538">27538</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/27543">27543</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/27547">27547</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/27554">27554</ref><ref source="SECUNIA" url="http://secunia.com/advisories/27741">27741</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/27773">27773</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/27697">27697</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/27862">27862</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/27776">27776</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/38273">pcre-character-class-dos(38273)</ref><ref source="" url="http://docs.info.apple.com/article.html?artnum=307179"></ref><ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2007/Dec/msg00002.html">APPLE-SA-2007-12-17</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA07-352A.html">TA07-352A</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/4238">ADV-2007-4238</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/27965">27965</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/28136">28136</ref><ref source="" url="http://bugs.gentoo.org/show_bug.cgi?id=198976"></ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200801-02.xml">GLSA-200801-02</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/28406">28406</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/28414">28414</ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200801-18.xml">GLSA-200801-18</ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200801-19.xml">GLSA-200801-19</ref><ref source="SUSE" url="http://lists.opensuse.org/opensuse-security-announce/2008-01/msg00006.html">SUSE-SA:2008:004</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/28658">28658</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/28714">28714</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/28720">28720</ref><ref source="" url="http://docs.info.apple.com/article.html?artnum=307562"></ref><ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2008/Mar/msg00001.html">APPLE-SA-2008-03-18</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/0924/references">ADV-2008-0924</ref><ref source="SECUNIA" url="http://secunia.com/advisories/29420">29420</ref><ref source="MLIST" url="http://lists.vmware.com/pipermail/security-announce/2008/000014.html">[Security-announce] 20080415 VMSA-2008-0007 Moderate Updated Service Console packages pcre, net-snmp, and OpenPegasus</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/1234/references">ADV-2008-1234</ref><ref source="SECUNIA" url="http://secunia.com/advisories/29785">29785</ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200805-11.xml">GLSA-200805-11</ref><ref source="SECUNIA" url="http://secunia.com/advisories/30155">30155</ref><ref source="SECUNIA" url="http://secunia.com/advisories/30219">30219</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2008-0546.html">RHSA-2008:0546</ref><ref source="SECUNIA" url="http://secunia.com/advisories/31124">31124</ref></refs><vuln_soft><prod name="PCRE" vendor="PCRE"><vers num="6.9" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.4" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="4.9" CVSS_score="6.4" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:P)" CVSS_version="2.0" modified="2007-11-08" name="CVE-2007-1661" published="2007-11-07" seq="2007-1661" severity="Medium" type="CVE"><desc><descript source="cve">Perl-Compatible Regular Expression (PCRE) library before 7.3 backtracks too far when matching certain input bytes against some regex patterns in non-UTF-8 mode, which allows context-dependent attackers to obtain sensitive information or cause a denial of service (crash), as demonstrated by the &quot;\X?\d&quot; and &quot;\P{L}?\d&quot; patterns.</descript></desc><loss_types><avail/><conf/></loss_types><range><network/></range><refs><ref source="" url="http://www.pcre.org/changelog.txt"></ref><ref patch="1" source="DEBIAN" url="http://www.debian.org/security/2007/dsa-1399">DSA-1399</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/3725">ADV-2007-3725</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/483357/100/0/threaded">20071106 rPSA-2007-0231-1 pcre</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/483579/100/0/threaded">20071112 FLEA-2007-0064-1 pcre</ref><ref source="MLIST" url="http://mail.gnome.org/archives/gtk-devel-list/2007-November/msg00022.html">[gtk-devel-list] 20071107 GLib 2.14.3</ref><ref source="" url="https://issues.rpath.com/browse/RPL-1738"></ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200711-30.xml">GLSA-200711-30</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:211">MDKSA-2007:211</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2007_62_pcre.html">SUSE-SA:2007:062</ref><ref source="UBUNTU" url="http://www.ubuntulinux.org/support/documentation/usn/usn-547-1">USN-547-1</ref><ref source="BID" url="http://www.securityfocus.com/bid/26346">26346</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/3790">ADV-2007-3790</ref><ref source="SECUNIA" url="http://secunia.com/advisories/27538">27538</ref><ref source="SECUNIA" url="http://secunia.com/advisories/27543">27543</ref><ref source="SECUNIA" url="http://secunia.com/advisories/27554">27554</ref><ref source="SECUNIA" url="http://secunia.com/advisories/27741">27741</ref><ref source="SECUNIA" url="http://secunia.com/advisories/27773">27773</ref><ref source="SECUNIA" url="http://secunia.com/advisories/27697">27697</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/38274">pcre-nonutf8-dos(38274)</ref><ref source="" url="http://docs.info.apple.com/article.html?artnum=307179"></ref><ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2007/Dec/msg00002.html">APPLE-SA-2007-12-17</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA07-352A.html">TA07-352A</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/4238">ADV-2007-4238</ref><ref source="SECUNIA" url="http://secunia.com/advisories/28136">28136</ref><ref source="" url="http://bugs.gentoo.org/show_bug.cgi?id=198976"></ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200801-02.xml">GLSA-200801-02</ref><ref source="SECUNIA" url="http://secunia.com/advisories/28406">28406</ref><ref source="SECUNIA" url="http://secunia.com/advisories/28414">28414</ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200801-18.xml">GLSA-200801-18</ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200801-19.xml">GLSA-200801-19</ref><ref source="SECUNIA" url="http://secunia.com/advisories/28714">28714</ref><ref source="SECUNIA" url="http://secunia.com/advisories/28720">28720</ref><ref source="FEDORA" url="https://www.redhat.com/archives/fedora-package-announce/2008-March/msg00181.html">FEDORA-2008-1842</ref><ref source="SECUNIA" url="http://secunia.com/advisories/29267">29267</ref><ref source="" url="http://docs.info.apple.com/article.html?artnum=307562"></ref><ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2008/Mar/msg00001.html">APPLE-SA-2008-03-18</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/0924/references">ADV-2008-0924</ref><ref source="SECUNIA" url="http://secunia.com/advisories/29420">29420</ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200805-11.xml">GLSA-200805-11</ref><ref source="SECUNIA" url="http://secunia.com/advisories/30155">30155</ref><ref source="SECUNIA" url="http://secunia.com/advisories/30219">30219</ref></refs><vuln_soft><prod name="PCRE" vendor="PCRE"><vers num="7.3" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0" modified="2007-11-08" name="CVE-2007-1662" published="2007-11-07" seq="2007-1662" severity="Medium" type="CVE"><desc><descript source="cve">Perl-Compatible Regular Expression (PCRE) library before 7.3 reads past the end of the string when searching for unmatched brackets and parentheses, which allows context-dependent attackers to cause a denial of service (crash), possibly involving forward references.</descript></desc><loss_types><avail/></loss_types><range><network/></range><refs><ref source="" url="http://www.pcre.org/changelog.txt"></ref><ref patch="1" source="DEBIAN" url="http://www.debian.org/security/2007/dsa-1399">DSA-1399</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/3725">ADV-2007-3725</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/483357/100/0/threaded">20071106 rPSA-2007-0231-1 pcre</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/483579/100/0/threaded">20071112 FLEA-2007-0064-1 pcre</ref><ref source="MLIST" url="http://mail.gnome.org/archives/gtk-devel-list/2007-November/msg00022.html">[gtk-devel-list] 20071107 GLib 2.14.3</ref><ref source="" url="https://issues.rpath.com/browse/RPL-1738"></ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200711-30.xml">GLSA-200711-30</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:211">MDKSA-2007:211</ref><ref source="UBUNTU" url="http://www.ubuntulinux.org/support/documentation/usn/usn-547-1">USN-547-1</ref><ref source="BID" url="http://www.securityfocus.com/bid/26346">26346</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/3790">ADV-2007-3790</ref><ref source="SECUNIA" url="http://secunia.com/advisories/27538">27538</ref><ref source="SECUNIA" url="http://secunia.com/advisories/27543">27543</ref><ref source="SECUNIA" url="http://secunia.com/advisories/27554">27554</ref><ref source="SECUNIA" url="http://secunia.com/advisories/27741">27741</ref><ref source="SECUNIA" url="http://secunia.com/advisories/27697">27697</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/38275">pcre-unmatched-dos(38275)</ref><ref source="" url="http://docs.info.apple.com/article.html?artnum=307179"></ref><ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2007/Dec/msg00002.html">APPLE-SA-2007-12-17</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA07-352A.html">TA07-352A</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/4238">ADV-2007-4238</ref><ref source="SECUNIA" url="http://secunia.com/advisories/28136">28136</ref><ref source="" url="http://bugs.gentoo.org/show_bug.cgi?id=198976"></ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200801-02.xml">GLSA-200801-02</ref><ref source="SECUNIA" url="http://secunia.com/advisories/28406">28406</ref><ref source="SECUNIA" url="http://secunia.com/advisories/28414">28414</ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200801-18.xml">GLSA-200801-18</ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200801-19.xml">GLSA-200801-19</ref><ref source="SECUNIA" url="http://secunia.com/advisories/28714">28714</ref><ref source="SECUNIA" url="http://secunia.com/advisories/28720">28720</ref><ref source="FEDORA" url="https://www.redhat.com/archives/fedora-package-announce/2008-March/msg00181.html">FEDORA-2008-1842</ref><ref source="SECUNIA" url="http://secunia.com/advisories/29267">29267</ref><ref source="" url="http://docs.info.apple.com/article.html?artnum=307562"></ref><ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2008/Mar/msg00001.html">APPLE-SA-2008-03-18</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/0924/references">ADV-2008-0924</ref><ref source="SECUNIA" url="http://secunia.com/advisories/29420">29420</ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200805-11.xml">GLSA-200805-11</ref><ref source="SECUNIA" url="http://secunia.com/advisories/30155">30155</ref><ref source="SECUNIA" url="http://secunia.com/advisories/30219">30219</ref></refs><vuln_soft><prod name="PCRE" vendor="PCRE"><vers num="7.3" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0" modified="2007-06-28" name="CVE-2007-1663" published="2007-06-26" seq="2007-1663" severity="Medium" type="CVE"><desc><descript source="cve">Memory leak in the image message functionality in ekg before 1:1.7~rc2-1etch1 on Debian GNU/Linux Etch allows remote attackers to cause a denial of service.</descript></desc><loss_types><avail/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="DEBIAN" url="http://www.debian.org/security/2007/dsa-1318">DSA-1318</ref><ref source="BID" url="http://www.securityfocus.com/bid/24600">24600</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/35134">ekg-image-message-dos(35134)</ref></refs><vuln_soft><prod name="ekg" vendor="ekg"><vers num="2005-04-11"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0" modified="2007-06-28" name="CVE-2007-1664" published="2007-06-26" seq="2007-1664" severity="Medium" type="CVE"><desc><descript source="cve">ekg before 1:1.7~rc2-1etch1 on Debian GNU/Linux Etch allows remote attackers to cause a denial of service (NULL pointer dereference) via a vector related to the token OCR functionality.</descript></desc><loss_types><avail/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="DEBIAN" url="http://www.debian.org/security/2007/dsa-1318">DSA-1318</ref><ref source="BID" url="http://www.securityfocus.com/bid/24600">24600</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/35135">ekg-token-ocr-dos(35135)</ref></refs><vuln_soft><prod name="ekg" vendor="ekg"><vers num="2005-04-11"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0" modified="2007-06-28" name="CVE-2007-1665" published="2007-06-26" seq="2007-1665" severity="Medium" type="CVE"><desc><descript source="cve">Memory leak in the token OCR functionality in ekg before 1:1.7~rc2-1etch1 on Debian GNU/Linux Etch allows remote attackers to cause a denial of service.</descript></desc><loss_types><avail/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="DEBIAN" url="http://www.debian.org/security/2007/dsa-1318">DSA-1318</ref><ref source="BID" url="http://www.securityfocus.com/bid/24600">24600</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/35136">ekg-ocr-function-dos(35136)</ref></refs><vuln_soft><prod name="ekg" vendor="ekg"><vers num="2005-04-11"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-04-05" name="CVE-2007-1666" published="2007-03-24" seq="2007-1666" severity="High" type="CVE"><desc><descript source="cve">The processor_request function in the debugger server for DataRescue IDA Pro 5.0 and 5.1 does not verify that authentication has taken place before invoking the perform_request function, which allows remote attackers to perform unauthorized actions.</descript></desc><sols><sol source="nvd">This vulnerability has been addressed in the following product updates. 

DataRescue IDA Pro 5.0 

DataRescue ida_remdeb_fix_22032007.zip
http://www.datarescue.com/freefiles/ida_remdeb_fix_22032007.zip


DataRescue IDA Pro 5.1 

DataRescue ida_remdeb_fix_22032007.zip
http://www.datarescue.com/freefiles/ida_remdeb_fix_22032007.zip
</sol></sols><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref source="IDEFENSE" url="http://labs.idefense.com/intelligence/vulnerabilities/">20070323 DataRescue IDA Pro Remote Debugger Server Authentication Bypass Vulnerability</ref><ref patch="1" source="" url="http://www.datarescue.com/freefiles/ida_remdeb_fix_22032007.zip"></ref><ref source="BID" url="http://www.securityfocus.com/bid/23114">23114</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1089">ADV-2007-1089</ref><ref source="OSVDB" url="http://www.osvdb.org/33523">33523</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017815">1017815</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24635">24635</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33190">idapro-processorrequest-code-execution(33190)</ref></refs><vuln_soft><prod name="IDA Pro" vendor="DataRescue"><vers num="5.0"/><vers num="5.1"/></prod></vuln_soft></entry><entry CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" CVSS_score="9.3" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-09-12" name="CVE-2007-1667" published="2007-03-24" seq="2007-1667" severity="High" type="CVE"><desc><descript source="cve">Multiple integer overflows in (1) the XGetPixel function in ImUtil.c in X.Org libx11 before 1.0.3, and (2) XInitImage function in xwd.c for ImageMagick, allow user-assisted remote attackers to cause a denial of service (crash) or obtain sensitive information via crafted images with large or negative values that trigger a buffer overflow.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/><user_init/></range><refs><ref source="" url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=414045"></ref><ref source="" url="https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=231684"></ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/464686/100/0/threaded">20070404 rPSA-2007-0065-1 freetype xorg-x11 xorg-x11-fonts xorg-x11-tools xorg-x11-xfs</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/464816/100/0/threaded">20070405 FLEA-2007-0009-1: xorg-x11 freetype</ref><ref source="MLIST" url="http://lists.freedesktop.org/archives/xorg-announce/2007-April/000286.html">[xorg-announce] 20070403 various integer overflow vulnerabilites in xserver, libX11 and libXfont</ref><ref source="" url="http://issues.foresightlinux.org/browse/FL-223"></ref><ref source="" url="https://issues.rpath.com/browse/RPL-1213"></ref><ref adv="1" source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2007:079">MDKSA-2007:079</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2007-0126.html">RHSA-2007:0126</ref><ref source="REDHAT" url="http://rhn.redhat.com/errata/RHSA-2007-0125.html">RHSA-2007:0125</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1217">ADV-2007-1217</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24741">24741</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24756">24756</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24745">24745</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24758">24758</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24765">24765</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24771">24771</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24791">24791</ref><ref source="" url="https://issues.rpath.com/browse/RPL-1211"></ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017864">1017864</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24739">24739</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2007-0157.html">RHSA-2007:0157</ref><ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102888-1">102888</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2007_27_x.html">SUSE-SA:2007:027</ref><ref source="UBUNTU" url="http://www.ubuntu.com/usn/usn-453-1">USN-453-1</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1531">ADV-2007-1531</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24953">24953</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25004">25004</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24975">24975</ref><ref source="OPENBSD" url="http://www.openbsd.org/errata39.html#021_xorg">[3.9] 021: SECURITY FIX: April 4, 2007</ref><ref source="OPENBSD" url="http://www.openbsd.org/errata40.html#011_xorg">[4.0] 011: SECURITY FIX: April 4, 2007</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2007_8_sr.html">SUSE-SR:2007:008</ref><ref source="BID" url="http://www.securityfocus.com/bid/23300">23300</ref><ref source="" url="http://support.avaya.com/elmodocs2/security/ASA-2007-176.htm"></ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200705-06.xml">GLSA-200705-06</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25112">25112</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25072">25072</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25131">25131</ref><ref source="DEBIAN" url="http://www.debian.org/security/2007/dsa-1294">DSA-1294</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:079">MDKSA-2007:079</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:147">MDKSA-2007:147</ref><ref source="UBUNTU" url="http://www.ubuntu.com/usn/usn-453-2">USN-453-2</ref><ref source="UBUNTU" url="http://www.ubuntu.com/usn/usn-481-1">USN-481-1</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1693">oval:org.mitre.oval:def:1693</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25305">25305</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25992">25992</ref><ref source="SECUNIA" url="http://secunia.com/advisories/26177">26177</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200805-07.xml">GLSA-200805-07</ref><ref source="SECUNIA" url="http://secunia.com/advisories/30161">30161</ref></refs><vuln_soft><prod name="libX11" vendor="X.Org"><vers num="1.0.2" prev="1"/></prod><prod name="ImageMagick" vendor="ImageMagick"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.8" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.9" CVSS_score="7.8" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_version="2.0" modified="2007-12-31" name="CVE-2007-1669" published="2007-05-08" seq="2007-1669" severity="High" type="CVE"><desc><descript source="cve">zoo decoder 2.10 (zoo-2.10), as used in multiple products including (1) Barracuda Spam Firewall 3.4 and later with virusdef before 2.0.6399, (2) Spam Firewall before 3.4 20070319 with virusdef before 2.0.6399o, and (3) AMaViS 2.4.1 and earlier, allows remote attackers to cause a denial of service (infinite loop) via a ZOO archive with a direntry structure that points to a previous file.</descript></desc><loss_types><avail/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/467646/100/0/threaded">20070504 Multiple vendors ZOO file decompression infinite loop DoS</ref><ref source="BID" url="http://www.securityfocus.com/bid/23823">23823</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/34080">multiple-vendor-zoo-dos(34080)</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1699">ADV-2007-1699</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/25122">25122</ref><ref source="" url="http://www.amavis.org/security/asa-2007-2.txt"></ref><ref source="VIM" url="http://www.attrition.org/pipermail/vim/2007-July/001725.html">20070724 zoo - amavis - barracuda cross-ref problems</ref><ref source="OSVDB" url="http://www.osvdb.org/35795">35795</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/25315">25315</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2680">2680</ref></refs><vuln_soft><prod name="Amavis" vendor="AMaViS"><vers num="2.4.1" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.8" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.9" CVSS_score="7.8" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_version="2.0" modified="2007-05-22" name="CVE-2007-1670" published="2007-05-08" seq="2007-1670" severity="High" type="CVE"><desc><descript source="cve">Panda Software Antivirus before 20070402 allows remote attackers to cause a denial of service (infinite loop) via a ZOO archive with a direntry structure that points to a previous file.</descript></desc><loss_types><avail/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/467646/100/0/threaded">20070504 Multiple vendors ZOO file decompression infinite loop DoS</ref><ref source="BID" url="http://www.securityfocus.com/bid/23823">23823</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/34080">multiple-vendor-zoo-dos(34080)</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1700">ADV-2007-1700</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/25152">25152</ref></refs><vuln_soft><prod name="Panda Titanium 2005 Antivirus" vendor="Panda"><vers num=""/></prod><prod name="Panda AntiVirus" vendor="Panda"><vers edition="NetWare" num="2.0"/><vers edition="Platinum" num="2.0"/></prod><prod name="Panda ActiveScan" vendor="Panda"><vers num="5.0"/><vers num="5.53.00"/><vers num="5.54.1"/></prod><prod name="Panda Platinum 2006 Internet Security" vendor="Panda"><vers num=""/></prod><prod name="Panda Titanium 2006 Antivirus + Antispyware" vendor="Panda"><vers num=""/></prod><prod name="Panda Platinum 2007 Internet Security" vendor="Panda"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.8" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.9" CVSS_score="7.8" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_version="2.0" modified="2007-05-10" name="CVE-2007-1671" published="2007-05-08" seq="2007-1671" severity="High" type="CVE"><desc><descript source="cve">avpack32.dll before 7.3.0.6 in Avira AntiVir allows remote attackers to cause a denial of service (infinite loop) via a ZOO archive with a direntry structure that points to a previous file.</descript></desc><loss_types><avail/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref patch="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/467646/100/0/threaded">20070504 Multiple vendors ZOO file decompression infinite loop DoS</ref><ref source="BID" url="http://www.securityfocus.com/bid/23823">23823</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/34080">multiple-vendor-zoo-dos(34080)</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1702">ADV-2007-1702</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/25140">25140</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2680">2680</ref></refs><vuln_soft><prod name="Antivir Personal" vendor="AVIRA"><vers num="7.3.0.5" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.8" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.9" CVSS_score="7.8" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_version="2.0" modified="2007-05-10" name="CVE-2007-1672" published="2007-05-08" seq="2007-1672" severity="High" type="CVE"><desc><descript source="cve">avast! antivirus before 4.7.981 allows remote attackers to cause a denial of service (infinite loop) via a ZOO archive with a direntry structure that points to a previous file.</descript></desc><loss_types><avail/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref patch="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/467646/100/0/threaded">20070504 Multiple vendors ZOO file decompression infinite loop DoS</ref><ref source="BID" url="http://www.securityfocus.com/bid/23823">23823</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/34080">multiple-vendor-zoo-dos(34080)</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1701">ADV-2007-1701</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/25137">25137</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2680">2680</ref></refs><vuln_soft><prod name="Avast Antivirus" vendor="Avast"><vers num="4.7.980" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.8" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.9" CVSS_score="7.8" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_version="2.0" modified="2007-12-31" name="CVE-2007-1673" published="2007-05-08" seq="2007-1673" severity="High" type="CVE"><desc><descript source="cve">unzoo.c, as used in multiple products including AMaViS 2.4.1 and earlier, allows remote attackers to cause a denial of service (infinite loop) via a ZOO archive with a direntry structure that points to a previous file.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/467646/100/0/threaded">20070504 Multiple vendors ZOO file decompression infinite loop DoS</ref><ref source="BID" url="http://www.securityfocus.com/bid/23823">23823</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/34080">multiple-vendor-zoo-dos(34080)</ref><ref source="" url="http://www.amavis.org/security/asa-2007-2.txt"></ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/25315">25315</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2680">2680</ref></refs><vuln_soft><prod name="Amavis" vendor="AMaViS"><vers num="2.4.1" prev="1"/></prod><prod name="unzoo" vendor="unzoo"><vers num="4.4-2"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-04-18" name="CVE-2007-1674" published="2007-04-17" seq="2007-1674" severity="High" type="CVE"><desc><descript source="cve">Stack-based buffer overflow in the Alert Service (aolnsrvr.exe) in LANDesk Management Suite 8.7 allows remote attackers to execute arbitrary code via a crafted packet to port 65535/UDP.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/465643/100/0/threaded">20070413 TSRT-07-04: LANDesk Management Suite Alert Service Stack Overflow Vulnerability</ref><ref patch="1" source="" url="http://www.tippingpoint.com/security/advisories/TSRT-07-04.html"></ref><ref patch="1" source="" url="http://kb.landesk.com/display/4n/kb/article.asp?aid=4142"></ref><ref source="BID" url="http://www.securityfocus.com/bid/23483">23483</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1391">ADV-2007-1391</ref><ref adv="1" source="SECTRACK" url="http://www.securitytracker.com/id?1017912">1017912</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24892">24892</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33657">
landesk-aolnsrvr-bo(33657)</ref></refs><vuln_soft><prod name="LANDesk Management Suite" vendor="LANDesk Software"><vers num="8.7"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-04-02" name="CVE-2007-1675" published="2007-03-28" seq="2007-1675" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in the CRAM-MD5 authentication mechanism in the IMAP server (nimap.exe) in IBM Lotus Domino before 6.5.6 and 7.x before 7.0.2 FP1 allows remote attackers to cause a denial of service via a long username.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref source="" url="http://www.zerodayinitiative.com/advisories/ZDI-07-011.html"></ref><ref patch="1" source="" url="http://www-1.ibm.com/support/docview.wss?uid=swg21257028"></ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/23173">23173</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1133">ADV-2007-1133</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24633">24633</ref><ref source="BID" url="http://www.securityfocus.com/bid/23172">23172</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017823">1017823</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33276">domino-imap-dos(33276)</ref></refs><vuln_soft><prod name="Lotus Domino" vendor="IBM"><vers num="6.5.0"/><vers num="6.5.1"/><vers num="6.5.2"/><vers num="6.5.3"/><vers num="6.5.4"/><vers num="6.5.4 FP 1"/><vers num="6.5.4 FP 2"/><vers num="6.5.5"/><vers num="6.5.5 FP1"/><vers num="6.5.5 FP2"/><vers num="7.0"/><vers num="7.0.1"/><vers num="7.0.2"/></prod></vuln_soft></entry><entry CVSS_base_score="6.6" CVSS_exploit_subscore="2.7" CVSS_impact_subscore="10.0" CVSS_score="6.6" CVSS_vector="(AV:L/AC:M/Au:S/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-04-02" name="CVE-2007-1677" published="2007-03-29" seq="2007-1677" severity="Medium" type="CVE"><desc><descript source="cve">Multiple buffer overflows in the ISO network protocol support in the NetBSD kernel 2.0 through 4.0_BETA2, and NetBSD-current before 20070329, allow local users to execute arbitrary code via long parameters to certain functions, as demonstrated by a long sockaddr structure argument to the clnp_route function.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input bound="1"/></vuln_types><range><local/></range><refs><ref source="NETBSD" url="ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2007-004.txt.asc">2007-004</ref><ref source="BID" url="http://www.securityfocus.com/bid/23193">23193</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1159">
ADV-2007-1159</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017832">
1017832</ref></refs><vuln_soft><prod name="Navision Financials Server" vendor="Navision Software"><vers num="3.0"/></prod><prod name="NetBSD" vendor="NetBSD"><vers num="2.0"/><vers num="2.0.1"/><vers num="2.0.2"/><vers num="2.0.3"/><vers num="3.0.1"/><vers num="3.0.2"/><vers num="3.1"/><vers num="3.1 RC1"/><vers num="3.1 RC3"/><vers num="4.0"/><vers num="4.0 Beta"/><vers num="4.0 Beta 2"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" modified="2007-03-27" name="CVE-2007-1678" published="2007-03-26" seq="2007-1678" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in the Fizzle 0.5 extension for Firefox allows remote attackers to inject arbitrary web script or HTML via RSS feeds, which are executed by the chrome: URI handler.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/463816/100/0/threaded">20070324 Fizzle : Firefox Extension Vulnerability</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24654">24654</ref><ref source="BID" url="http://www.securityfocus.com/bid/23144">
23144</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1112">
ADV-2007-1112</ref><ref source="OSVDB" url="http://www.osvdb.org/33522">
33522</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33227">
fizzle-rssfeed-xss(33227)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2480">2480</ref></refs><vuln_soft><prod name="Fizzle" vendor="Fizzle"><vers num="0.5"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" modified="2007-04-02" name="CVE-2007-1679" published="2007-03-26" seq="2007-1679" severity="Medium" type="CVE"><desc><descript source="cve">** DISPUTED **  Multiple cross-site scripting (XSS) vulnerabilities in Horde Groupware Webmail 1.0 allow remote authenticated users to inject arbitrary web script or HTML via unspecified vectors in (1) imp/search.php and (2) ingo/rule.php. NOTE: this issue has been disputed by the vendor, noting that the search.php issue was resolved in CVE-2006-4255, and attackers can only use rule.php to inject XSS into their own pages.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/463819/100/0/threaded">20070325 Horde Webmail Multiple HTML Injection vulnerability</ref><ref source="BID" url="http://www.securityfocus.com/bid/23136">23136</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/463911/100/0/threaded">20070326 Re: Horde Webmail Multiple HTML Injection vulnerability</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33228">horde-search-rule-xss(33228)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2487">2487</ref></refs><vuln_soft><prod name="Groupware" vendor="Horde"><vers edition="Webmail" num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" CVSS_score="9.3" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-04-10" name="CVE-2007-1680" published="2007-04-05" seq="2007-1680" severity="High" type="CVE"><desc><descript source="cve">Stack-based buffer overflow in the createAndJoinConference function in the AudioConf ActiveX control (yacscom.dll) in Yahoo! Messenger before 20070313 allows remote attackers to execute arbitrary code via long (1) socksHostname and (2) hostname properties.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/><user_init/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/464607/100/0/threaded">20070403 ZDI-07-012: Yahoo! Messenger AudioConf ActiveX Control Buffer Overflow</ref><ref adv="1" patch="1" source="" url="http://www.zerodayinitiative.com/advisories/ZDI-07-012.html"></ref><ref patch="1" source="" url="http://messenger.yahoo.com/security_update.php?id=031207"></ref><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/23291">23291</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1219">ADV-2007-1219</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/24742">24742</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/388377">
VU#388377</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017867">
1017867</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33408">
yahoo-yahooaudioconf-activex-bo(33408)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2523">2523</ref></refs><vuln_soft><prod name="Messenger" vendor="Yahoo"><vers num="8.0"/><vers num="8.0_2005.1.1.4"/><vers num="8.0.0.863"/><vers num="8.1.0.209"/><vers num="8.1.0.239"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-04-23" name="CVE-2007-1681" published="2007-04-19" seq="2007-1681" severity="High" type="CVE"><desc><descript source="cve">Format string vulnerability in libwebconsole_services.so in Sun Java Web Console 2.2.2 through 2.2.5 allows remote attackers to cause a denial of service (application crash), obtain sensitive information, and possibly execute arbitrary code via unspecified vectors during a failed login attempt, related to syslog.</descript></desc><impacts><impact source="nvd">Root level code execution is only possible if the web console is running as root, which it does not by default.</impact></impacts><sols><sol source="nvd">The vendor has addressed this issue through multiple product updates: 

Sun Java Web Console 2.2.2
http://www.sun.com/download/products.xml?id=461d58be


Sun Java Web Console x86 2.2.2 
http://www.sun.com/download/products.xml?id=461d58be


Sun Java Web Console x86 2.2.3 
http://www.sun.com/download/products.xml?id=461d58be


Sun Java Web Console 2.2.3 
http://www.sun.com/download/products.xml?id=461d58be


Sun Java Web Console x86 2.2.4 
http://www.sun.com/download/products.xml?id=461d58be


Sun Java Web Console 2.2.4 
http://www.sun.com/download/products.xml?id=461d58be


Sun Java Web Console x86 2.2.5 
http://www.sun.com/download/products.xml?id=461d58be


Sun Java Web Console 2.2.5 
http://www.sun.com/download/products.xml?id=461d58be
</sol></sols><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/466048/100/0/threaded">20070417 n.runs-SA-2007.007 - Sun Solaris 10 - Format string vulnerability</ref><ref source="" url="http://www.nruns.com/security_advisory_sun_java_format_string.php"></ref><ref adv="1" source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102854-1">102854</ref><ref source="BID" url="http://www.securityfocus.com/bid/23539">23539</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1443">ADV-2007-1443</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017930">
1017930</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24927">
24927</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33731">
javawebconsole-libcsyslog-format-string(33731)</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1252">oval:org.mitre.oval:def:1252</ref></refs><vuln_soft><prod name="Java Web Console" vendor="Sun"><vers edition="x86" num="2.2.2"/><vers edition="x86" num="2.2.3"/><vers edition="x86" num="2.2.4"/><vers edition="x86" num="2.2.5"/><vers edition="x86" num="2.2.2"/><vers edition="x86" num="2.2.3"/><vers edition="x86" num="2.2.4"/><vers edition="x86" num="2.2.5"/></prod><prod name="Solaris" vendor="Sun"><vers edition="x86" num="10.0"/><vers edition="HW2" num="10.0"/></prod></vuln_soft></entry><entry CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" CVSS_score="9.3" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2008-08-27" name="CVE-2007-1682" published="2008-08-27" seq="2007-1682" severity="High" type="CVE"><desc><descript source="cve">Multiple stack-based buffer overflows in the FileManager ActiveX control in SAFmgPws.dll in SoftArtisans XFile before 2.4.0 allow remote attackers to execute arbitrary code via unspecified calls to the (1) BuildPath, (2) GetDriveName, (3) DriveExists, or (4) DeleteFile method.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><range><network/><user_init/></range><refs><ref source="" url="http://support.softartisans.com/Support-114.aspx"></ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/914785">VU#914785</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/31615">31615</ref></refs><vuln_soft><prod name="xfile" vendor="SoftArtisans"><vers num="1.0"/><vers num="1.0.6"/><vers num="1.0.7"/><vers num="1.0.8"/><vers num="1.01"/><vers num="1.1"/><vers num="1.1.1"/><vers num="1.1.2"/><vers num="1.1.3"/><vers num="1.1.4"/><vers num="1.1.5"/><vers num="1.1.6"/><vers num="1.1.7"/><vers num="2.0"/><vers num="2.0.2"/><vers num="2.0.3"/><vers num="2.1.3"/><vers num="2.1.4"/><vers num="2.1.5"/><vers num="2.1.6"/><vers num="2.1.7"/><vers num="2.2.3"/><vers num="2.2.4"/><vers num="2.3.4" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-04-27" name="CVE-2007-1683" published="2007-04-26" seq="2007-1683" severity="Medium" type="CVE"><desc><descript source="cve">Stack-based buffer overflow in the DoWebMenuAction function in the IncrediMail IMMenuShellExt ActiveX control (ImShExt.dll) allows remote attackers to execute arbitrary code via unspecified vectors.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/906777">VU#906777</ref><ref source="BID" url="http://www.securityfocus.com/bid/23674">
23674</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25051">
25051</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33928">
incredimail-immenushellext-bo(33928)</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1551">
ADV-2007-1551</ref></refs><vuln_soft><prod name="IMMenuShellExt ActiveX control" vendor="IncrediMail"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" CVSS_score="9.3" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-04-10" name="CVE-2007-1684" published="2007-04-05" seq="2007-1684" severity="High" type="CVE"><desc><descript source="cve">The Run function in SolidWorks sldimdownload ActiveX control in sldimdownload.dll before 16.0.0.6 allows remote attackers to execute arbitrary commands via the (1) installerpath and (2) applicationarguments arguments.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" patch="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/556801">VU#556801</ref><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/23290">23290</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1216">ADV-2007-1216</ref><ref adv="1" source="SECTRACK" url="http://www.securitytracker.com/id?1017855">1017855</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/24762">24762</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33428">
solidworks-activex-command-execution(33428)</ref></refs><vuln_soft><prod name="sldimdownload ActiveX control" vendor="SolidWorks"><vers num="16.0.0.5"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-06-11" name="CVE-2007-1685" published="2007-06-08" seq="2007-1685" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in k9filter.exe in BlueCoat K9 Web Protection 3.2.36, and probably other versions before 3.2.44, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long HTTP GET request to port 2372.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref source="" url="http://www.csis.dk/dk/forside/Bluecoat-k9.pdf"></ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/470836/100/0/threaded">20070608 CSIS Advisory: BlueCoat K9 Web Protection 3.2.36 Overflow</ref><ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2007-June/063848.html">20070608 CSIS Advisory: BlueCoat K9 Web Protection 3.2.36 Overflow</ref><ref source="BID" url="http://www.securityfocus.com/bid/24373">24373</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/2104">ADV-2007-2104</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1018210">1018210</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25593">25593</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/34773">bluecoat-management-interface-bo(34773)</ref></refs><vuln_soft><prod name="K9 Web Protection" vendor="Blue Coat Systems"><vers num="3.2.36"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-04-10" name="CVE-2007-1687" published="2007-04-10" seq="2007-1687" severity="High" type="CVE"><desc><descript source="cve">Multiple buffer overflows in the Internet Pictures Corporation iPIX Image Well ActiveX control (iPIX-ImageWell-ipix.dll) allow remote attackers to execute arbitrary code via unspecified vectors.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/958609">VU#958609</ref><ref source="BID" url="http://www.securityfocus.com/bid/23379">
23379</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1309">
ADV-2007-1309</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017888">
1017888</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24816">
24816</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33543">
ipix-imagewell-activex-unspecified-bo(33543)</ref></refs><vuln_soft><prod name="iPIX Image Well" vendor="Internet Pictures Corporation"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" CVSS_score="9.3" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-09-17" name="CVE-2007-1688" published="2007-09-13" seq="2007-1688" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in the PhPInfo ActiveX control in PhPCtrl.dll in Callisto PhotoParade Player allows remote attackers to execute arbitrary code via the FileVersionof property.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/><user_init/></range><refs><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/171449">VU#171449</ref><ref source="BID" url="http://www.securityfocus.com/bid/25654">25654</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/3138">ADV-2007-3138</ref><ref source="SECUNIA" url="http://secunia.com/advisories/26789">26789</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/36588">photoparade-phpinfo-bo(36588)</ref></refs><vuln_soft><prod name="PhotoParade Player" vendor="Callisto"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-05-24" name="CVE-2007-1689" published="2007-05-16" seq="2007-1689" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in the ISAlertDataCOM ActiveX control in ISLALERT.DLL for Norton Personal Firewall 2004 and Internet Security 2004 allows remote attackers to execute arbitrary code via long arguments to the (1) Get and (2) Set functions.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="" url="http://www.symantec.com/avcenter/security/Content/2007.05.16.html"></ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/468779/100/0/threaded">20070516 Symantec Product Security: Norton Personal Firewall 2004 ActiveX Control vulnerability</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/983953">VU#983953</ref><ref source="BID" url="http://www.securityfocus.com/bid/23936">23936</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1843">ADV-2007-1843</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1018073">1018073</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/25290">25290</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/34328">symantec-islalert-bo(34328)</ref></refs><vuln_soft><prod name="Norton Personal Firewall" vendor="Symantec"><vers num="2004"/></prod><prod name="Norton Internet Security" vendor="Symantec"><vers num="2004"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-04-19" name="CVE-2007-1690" published="2007-04-19" seq="2007-1690" severity="Medium" type="CVE"><desc><descript source="cve">Multiple stack-based buffer overflows in Second Sight Software ActiveGS ActiveX control (ActiveGS.ocx) allow remote attackers to execute arbitrary code via unspecified vectors.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/118737">VU#118737</ref><ref source="BID" url="http://www.securityfocus.com/bid/23554">
23554</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1454">
ADV-2007-1454</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24960">
24960</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33759">activegs-unspecified-bo(33759)</ref></refs><vuln_soft><prod name="ActiveGS" vendor="Second Sight Software"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-04-19" name="CVE-2007-1691" published="2007-04-19" seq="2007-1691" severity="Medium" type="CVE"><desc><descript source="cve">Stack-based buffer overflow in Second Sight Software ActiveMod ActiveX control (ActiveMod.ocx) allows remote attackers to execute arbitrary code via unspecified vectors.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/962305">VU#962305</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33757">
activemod-unspecified-bo(33757)</ref><ref source="BID" url="http://www.securityfocus.com/bid/23554">
23554</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1454">
ADV-2007-1454</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24928">
24928</ref></refs><vuln_soft><prod name="ActiveMod" vendor="Second Sight Software"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-04-02" name="CVE-2007-1692" published="2007-03-26" seq="2007-1692" severity="High" type="CVE"><desc><descript source="cve">The default configuration of Microsoft Windows uses the Web Proxy Autodiscovery Protocol (WPAD) without static WPAD entries, which might allow remote attackers to intercept web traffic by registering a proxy server using WINS or DNS, then responding to WPAD requests, as demonstrated using Internet Explorer.  NOTE: it could be argued that if an attacker already has control over WINS/DNS, then web traffic could already be intercepted by modifying WINS or DNS records, so this would not cross privilege boundaries and would not be a vulnerability.  It has also been reported that DHCP is an alternate attack vector.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><config/></vuln_types><range><network/></range><refs><ref source="MLIST" url="http://archives.neohapsis.com/archives/isn/2007-q1/0418.html">[ISN] 20070326 Windows weakness can lead to network traffic hijacks</ref><ref source="" url="http://news.com.com/Windows+weakness+can+lead+to+network+traffic+hijacks/2100-10"></ref><ref source="MSKB" url="http://support.microsoft.com/kb/934864">934864</ref><ref source="" url="http://isc.sans.org/diary.html?storyid=2517"></ref><ref source="" url="http://news.com.com/Windows+weakness+can+lead+to+network+traffic+hijacks/2100-1002_3-6170229.html"></ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1115">ADV-2007-1115</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33244">windows-wpad-information-disclosure(33244)</ref></refs><vuln_soft><prod name="Small Business Server" vendor="Microsoft"><vers num="2000"/></prod><prod name="Windows Server 2003" vendor="Microsoft"><vers edition="Datacenter 64-bit" num="R2"/></prod><prod name="Windows 2000" vendor="Microsoft"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.8" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.9" CVSS_score="7.8" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_version="2.0" modified="2007-05-21" name="CVE-2007-1693" published="2007-05-17" seq="2007-1693" severity="High" type="CVE"><desc><descript source="cve">The SIP channel module in Yet Another Telephony Engine (Yate) before 1.2.0 sets the caller_info_uri parameter using a incorrect variable that can be NULL, which allows remote attackers to cause a denial of service (NULL dereference and application crash) via a Call-Info header without a purpose parameter.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/467289/100/200/threaded">20070501 Radware Security Advisory - Yate 1.1.0 Denial of Service Vulnerability</ref><ref source="" url="http://voip.null.ro/cgi-bin/cvsweb.cgi/yate/modules/ysipchan.cpp"></ref><ref source="BID" url="http://www.securityfocus.com/bid/23746">23746</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2716">2716</ref></refs><vuln_soft><prod name="Yet Another Telephony Engine" vendor="Yet Another Telephony Engine"><vers num="1.1.0" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-03-27" name="CVE-2007-1695" published="2007-03-26" seq="2007-1695" severity="High" type="CVE"><desc><descript source="cve">** DISPUTED **  PHP remote file inclusion vulnerability in includes/usercp_register.php in phpBB 2.0.19 allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.  NOTE: this issue has been disputed by third-party researchers, stating that the file checks for a global constant and cannot be accessed directly.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/463817/100/0/threaded">20070324 BOGUS: Remote File Include In phpBB-2.0.19</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/463718/100/0/threaded">20070324 Remote File Include In phpBB-2.0.19</ref></refs><vuln_soft><prod name="phpBB" vendor="phpBB Group"><vers num="2.0.19"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-03-28" name="CVE-2007-1696" published="2007-03-26" seq="2007-1696" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in ViewNewspapers.asp in Active Newsletter 4.3 and earlier allows remote attackers to execute arbitrary SQL commands via the NewsPaperID parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3556">3556</ref><ref source="BID" url="http://www.securityfocus.com/bid/23115">23115</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1098">ADV-2007-1098</ref><ref source="OSVDB" url="http://www.osvdb.org/34491">34491</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24640">24640</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33197">activenewsletter-newspaperid-sql-injection(33197)</ref></refs><vuln_soft><prod name="Active Newsletter" vendor="Active Web Softwares"><vers num="4.3" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-03-28" name="CVE-2007-1697" published="2007-03-26" seq="2007-1697" severity="High" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in header.inc.php in Philex 0.2.3 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the CssFile parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3552">3552</ref><ref source="BID" url="http://www.securityfocus.com/bid/23111">23111</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1099">
ADV-2007-1099</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33179">
philex-header-file-include(33179)</ref></refs><vuln_soft><prod name="Philex" vendor="Philex"><vers num="0.2.3" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0" modified="2007-03-28" name="CVE-2007-1698" published="2007-03-26" seq="2007-1698" severity="Medium" type="CVE"><desc><descript source="cve">download.php in Philex 0.2.3 and earlier allows remote attackers to read arbitrary files and source code, and obtain sensitive information via the file parameter.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3552">3552</ref><ref source="BID" url="http://www.securityfocus.com/bid/23111">23111</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1099">
ADV-2007-1099</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33181">
philex-download-file-disclosure(33181)</ref></refs><vuln_soft><prod name="Philex" vendor="Philex"><vers num="0.2.3" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-03-28" name="CVE-2007-1699" published="2007-03-26" seq="2007-1699" severity="High" type="CVE"><desc><descript source="cve">Multiple PHP remote file inclusion vulnerabilities in the SWmenu (com_swmenupro and com_swmenufree) 4.0 component for Mambo and Joomla! allow remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter to ImageManager/Classes/ImageManager.php under the (1) components/ or (2) administrator/components/ directory trees.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3557">3557</ref><ref source="BID" url="http://www.securityfocus.com/bid/23116">23116</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1100">ADV-2007-1100</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33204">swmenufree-imagemanager-file-include(33204)</ref></refs><vuln_soft><prod name="SWmenu Component" vendor="Joomla"><vers num="4.0"/></prod><prod name="SWmenu Component" vendor="Mambo"><vers num="4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-04-03" name="CVE-2007-1700" published="2007-03-26" seq="2007-1700" severity="High" type="CVE"><desc><descript source="cve">The session extension in PHP 4 before 4.4.5, and PHP 5 before 5.2.1, calculates the reference count for the session variables without considering the internal pointer from the session globals, which allows context-dependent attackers to execute arbitrary code via a crafted string in the session_register after unsetting HTTP_SESSION_VARS and _SESSION, which destroys the session data Hashtable.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref source="" url="http://www.php-security.org/MOPB/MOPB-30-2007.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/23119">23119</ref><ref source="DEBIAN" url="http://www.debian.org/security/2007/dsa-1283">
DSA-1283</ref><ref source="UBUNTU" url="http://www.ubuntu.com/usn/usn-455-1">
USN-455-1</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25062">
25062</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25057">
25057</ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200705-19.xml">GLSA-200705-19</ref><ref source="HP" url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&amp;cc=us&amp;objectID=c01056506">HPSBMA02215</ref><ref source="HP" url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&amp;cc=us&amp;objectID=c01086137">HPSBTU02232</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2007_32_php.html">SUSE-SA:2007:032</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1991">ADV-2007-1991</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/2374">ADV-2007-2374</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25056">25056</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25445">25445</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25423">25423</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25850">25850</ref></refs><vuln_soft><prod name="PHP" vendor="PHP"><vers num="4.0"/><vers num="4.0 Beta 1"/><vers num="4.0 Beta 2"/><vers num="4.0 Beta 3"/><vers num="4.0 Beta 4"/><vers num="4.0 Beta 4 Patch Level 1"/><vers num="4.0 RC1"/><vers num="4.0 RC2"/><vers num="4.0.0"/><vers num="4.0.1"/><vers num="4.0.1 pl1"/><vers num="4.0.1 pl2"/><vers num="4.0.2"/><vers num="4.0.3"/><vers num="4.0.3 pl1"/><vers num="4.0.4"/><vers num="4.0.4 pl1"/><vers num="4.0.5"/><vers num="4.0.6"/><vers num="4.0.7"/><vers num="4.0.7 RC1"/><vers num="4.0.7 RC2"/><vers num="4.0.7 RC3"/><vers num="4.1.0"/><vers num="4.1.1"/><vers num="4.1.2"/><vers edition="Dev" num="4.2"/><vers num="4.2.0"/><vers num="4.2.1"/><vers num="4.2.2"/><vers num="4.2.3"/><vers num="4.3"/><vers num="4.3.1"/><vers num="4.3.10"/><vers num="4.3.11"/><vers num="4.3.2"/><vers num="4.3.3"/><vers num="4.3.4"/><vers num="4.3.5"/><vers num="4.3.6"/><vers num="4.3.7"/><vers num="4.3.8"/><vers num="4.3.9"/><vers num="4.4.0"/><vers num="4.4.1"/><vers num="4.4.2"/><vers num="4.4.3"/><vers num="4.4.4"/><vers num="5.0 candidate 1"/><vers num="5.0 candidate 2"/><vers num="5.0 candidate 3"/><vers num="5.0.0"/><vers num="5.0.0 Beta1"/><vers num="5.0.0 Beta2"/><vers num="5.0.0 Beta3"/><vers num="5.0.0 Beta4"/><vers num="5.0.0 RC1"/><vers num="5.0.0 RC2"/><vers num="5.0.0 RC3"/><vers num="5.0.1"/><vers num="5.0.2"/><vers num="5.0.3"/><vers num="5.0.4"/><vers num="5.0.5"/><vers num="5.1"/><vers num="5.1.0"/><vers num="5.1.1"/><vers num="5.1.2"/><vers num="5.1.3"/><vers num="5.1.4"/><vers num="5.1.5"/><vers num="5.1.6"/><vers num="5.2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-04-19" name="CVE-2007-1701" published="2007-03-26" seq="2007-1701" severity="Medium" type="CVE"><desc><descript source="cve">PHP 4 before 4.4.5, and PHP 5 before 5.2.1, when register_globals is enabled, allows context-dependent attackers to execute arbitrary code via deserialization of session data, which overwrites arbitrary global variables, as demonstrated by calling session_decode on a string beginning with &quot;_SESSION|s:39:&quot;.</descript></desc><impacts><impact source="nvd">Successful exploitation requires that variable &quot;register_globals&quot; is enabled.</impact></impacts><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://www.php-security.org/MOPB/MOPB-31-2007.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/23120">23120</ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200705-19.xml">GLSA-200705-19</ref><ref source="HP" url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&amp;cc=us&amp;objectID=c01056506">HPSBMA02215</ref><ref source="HP" url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&amp;cc=us&amp;objectID=c01086137">HPSBTU02232</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1991">ADV-2007-1991</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/2374">ADV-2007-2374</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25445">25445</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25423">25423</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25850">25850</ref></refs><vuln_soft><prod name="PHP" vendor="PHP"><vers num="4.4.4" prev="1"/><vers num="5.2.0" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-03-28" name="CVE-2007-1702" published="2007-03-26" seq="2007-1702" severity="Medium" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in mod_flatmenu.php in the Flatmenu 1.07 and earlier Mambo module allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3567">3567</ref><ref source="VIM" url="http://www.attrition.org/pipermail/vim/2007-March/001472.html">20070326 Confirm - Mambo 4.5.1 Modules Flatmenu &lt;= 1.07 Remote File Include Exploit</ref><ref source="BID" url="http://www.securityfocus.com/bid/23125">23125</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1106">ADV-2007-1106</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33200">flatmenu-modflatmenu-file-include(33200)</ref></refs><vuln_soft><prod name="Flatmenu" vendor="Mambo"><vers num="1.7" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-03-28" name="CVE-2007-1703" published="2007-03-26" seq="2007-1703" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in index.php in the RWCards (com_rwcards) 2.4.3 and earlier component for Joomla! allows remote attackers to execute arbitrary SQL commands via the category_id parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3565">3565</ref><ref source="BID" url="http://www.securityfocus.com/bid/23126">23126</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1105">ADV-2007-1105</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33194">rwcards-index-sql-injection(33194)</ref></refs><vuln_soft><prod name="RWCards Component" vendor="Joomla"><vers num="2.4.3" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-03-28" name="CVE-2007-1704" published="2007-03-26" seq="2007-1704" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in index.php in the Car Manager (com_resman) 1.1 and earlier component for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3564">3564</ref><ref source="BID" url="http://www.securityfocus.com/bid/23131">23131</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1104">ADV-2007-1104</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33193">carmanager-index-sql-injection(33193)</ref></refs><vuln_soft><prod name="Car Manager" vendor="Joomla"><vers num="1.1" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-03-28" name="CVE-2007-1705" published="2007-03-26" seq="2007-1705" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in default.asp in Active Trade 2 allows remote attackers to execute arbitrary SQL commands via the catid parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3549">3549</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24631">24631</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1095">ADV-2007-1095</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33184">activetrade-default-sql-injection(33184)</ref></refs><vuln_soft><prod name="Active Trade" vendor="Active Trade"><vers num="2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-03-28" name="CVE-2007-1706" published="2007-03-26" seq="2007-1706" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in eWebQuiz.asp in eWebQuiz 8 allows remote attackers to execute arbitrary SQL commands via the QuizID parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3558">3558</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24653">24653</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1101">ADV-2007-1101</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33195">ewebquiz-ewebquiz-sql-injection(33195)</ref></refs><vuln_soft><prod name="eWebQuiz" vendor="eWebQuiz"><vers num="8"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-03-28" name="CVE-2007-1707" published="2007-03-26" seq="2007-1707" severity="High" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in index.php in Net Side Content Management System (Net-Side.net CMS) allows remote attackers to execute arbitrary PHP code via a URL in the cms parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3562">3562</ref><ref source="BID" url="http://www.securityfocus.com/bid/23130">
23130</ref></refs><vuln_soft><prod name="Net Side Content Management System" vendor="Net-Side.net"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-03-28" name="CVE-2007-1708" published="2007-03-26" seq="2007-1708" severity="High" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in lib/db/ez_sql.php in ttCMS 4 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the lib_path parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3563">3563</ref><ref source="BID" url="http://www.securityfocus.com/bid/23139">
23139</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1102">
ADV-2007-1102</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33202">
ttcms-ezsql-file-include(33202)</ref></refs><vuln_soft><prod name="ttForum" vendor="ttCMS"><vers num="1"/><vers num="2"/><vers num="3"/><vers num="4"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="3.1" CVSS_impact_subscore="6.4" CVSS_score="4.3" CVSS_vector="(AV:L/AC:L/Au:S/C:P/I:P/A:P)" CVSS_version="2.0" modified="2008-04-04" name="CVE-2007-1709" published="2007-03-26" seq="2007-1709" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in the confirm_phpdoc_compiled function in the phpDOC extension (PECL phpDOC) in PHP 5.2.1 allows context-dependent attackers to execute arbitrary code via a long argument string.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3576">3576</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/463843/100/0/threaded">20070325 PHP 5.2.1 with PECL phpDOC local buffer overflow</ref><ref source="" url="http://retrogod.altervista.org/php521_phpdoc_bof.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/23124">23124</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33236">phpdoc-confirmcompiled-bo(33236)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2512">2512</ref></refs><vuln_soft><prod name="PHP" vendor="PHP"><vers num="5.2.1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="3.1" CVSS_impact_subscore="6.4" CVSS_score="4.3" CVSS_vector="(AV:L/AC:L/Au:S/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-03-28" name="CVE-2007-1710" published="2007-03-26" seq="2007-1710" severity="Medium" type="CVE"><desc><descript source="cve">The readfile function in PHP 4.4.4, 5.1.6, and 5.2.1 allows context-dependent attackers to bypass safe_mode restrictions and read arbitrary files by referring to local files with a certain URL syntax instead of a pathname syntax, as demonstrated by a filename preceded a &quot;php://../../&quot; sequence.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3573">3573</ref><ref source="HP" url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&amp;cc=us&amp;objectID=c01056506">HPSBMA02215</ref><ref source="HP" url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&amp;cc=us&amp;objectID=c01086137">HPSBTU02232</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1991">ADV-2007-1991</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/2374">ADV-2007-2374</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25423">25423</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25850">25850</ref></refs><vuln_soft><prod name="PHP" vendor="PHP"><vers num="4.4.4"/><vers num="5.1.6"/><vers num="5.2.1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-05-21" name="CVE-2007-1711" published="2007-03-26" seq="2007-1711" severity="Medium" type="CVE"><desc><descript source="cve">Double free vulnerability in the unserializer in PHP 4.4.5 and 4.4.6 allows context-dependent attackers to execute arbitrary code by overwriting variables pointing to (1) the GLOBALS array or (2) the session data in _SESSION.  NOTE: this issue was introduced when attempting to patch CVE-2007-1701 (MOPB-31-2007).</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref source="" url="http://www.php-security.org/MOPB/MOPB-32-2007.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/23121">23121</ref><ref source="REDHAT" url="http://rhn.redhat.com/errata/RHSA-2007-0154.html">RHSA-2007:0154</ref><ref source="REDHAT" url="http://rhn.redhat.com/errata/RHSA-2007-0155.html">RHSA-2007:0155</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24910">24910</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24924">24924</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/466166/100/0/threaded">20070418 rPSA-2007-0073-1 php php-mysql php-pgsql</ref><ref source="" url="https://issues.rpath.com/browse/RPL-1268"></ref><ref source="REDHAT" url="http://rhn.redhat.com/errata/RHSA-2007-0163.html">RHSA-2007:0163</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24945">24945</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24941">24941</ref><ref source="DEBIAN" url="http://www.debian.org/security/2007/dsa-1282">DSA-1282</ref><ref source="DEBIAN" url="http://www.debian.org/security/2007/dsa-1283">DSA-1283</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25025">25025</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25062">25062</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2007:087">MDKSA-2007:087</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2007:088">MDKSA-2007:088</ref><ref source="" url="http://docs.info.apple.com/article.html?artnum=306172"></ref><ref source="APPLE" url="http://lists.apple.com/archives/security-announce//2007/Jul/msg00004.html">APPLE-SA-2007-07-31</ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200705-19.xml">GLSA-200705-19</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:087">MDKSA-2007:087</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:088">MDKSA-2007:088</ref><ref source="BID" url="http://www.securityfocus.com/bid/25159">25159</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/2732">ADV-2007-2732</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25445">25445</ref><ref source="SECUNIA" url="http://secunia.com/advisories/26235">26235</ref></refs><vuln_soft><prod name="PHP" vendor="PHP"><vers num="4.4.5"/><vers num="4.4.6"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-03-29" name="CVE-2007-1712" published="2007-03-27" seq="2007-1712" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in default.asp in ActiveWebSoftwares Active Auction Pro 7.1 allows remote attackers to execute arbitrary SQL commands via the catid parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MILW0RM" url="http://milw0rm.com/exploits/3551">3551</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1097">ADV-2007-1097</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24626">24626</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33182">
activeauctionpro-default-sql-injection(33182)</ref><ref source="OSVDB" url="http://www.osvdb.org/34420">34420</ref></refs><vuln_soft><prod name="Active Auction House" vendor="Active Web Softwares"><vers edition="Pro" num="7.1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.4" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="4.9" CVSS_score="6.4" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_version="2.0" modified="2007-05-22" name="CVE-2007-1713" published="2007-03-27" seq="2007-1713" severity="Medium" type="CVE"><desc><descript source="cve">CRLF injection vulnerability in BSMTP.DLL in B21Soft BASP21 2003.0211, and BASP21 Pro 1.0.702.27 and earlier, allows remote attackers to inject arbitrary headers into e-mail messages via CRLF sequences in Subject lines.</descript></desc><loss_types><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://jvn.jp/jp/JVN%2386092776/index.html"></ref><ref source="" url="http://www.hi-ho.ne.jp/babaq/basp21.html"></ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24652">24652</ref><ref source="BID" url="http://www.securityfocus.com/bid/23134">23134</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1113">ADV-2007-1113</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33211">basp21-bsmtp-mail-relay(33211)</ref></refs><vuln_soft><prod name="BASP21" vendor="B21Soft"><vers num="2003.0211"/><vers edition="Pro" num="1.0.702.27" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-03-29" name="CVE-2007-1714" published="2007-03-27" seq="2007-1714" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in index.php in CcCounter 2.0 allows remote attackers to inject arbitrary web script or HTML via dir parameter.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/463820/100/0/threaded">20070324 CcCounter 2.0 cross-site scripting vulnerability</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/23135">23135</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1120">
ADV-2007-1120</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24655">
24655</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33213">
cccounter-index-xss(33213)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2481">2481</ref></refs><vuln_soft><prod name="CcCounter" vendor="CcCounter"><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-03-29" name="CVE-2007-1715" published="2007-03-27" seq="2007-1715" severity="High" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in frontpage.php in Free Image Hosting 2.0 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the AD_BODY_TEMP parameter.  NOTE: the forgot_pass.php vector is already covered by CVE-2006-5670, and the login.php vector overlaps CVE-2006-5763.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3568">3568</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/33196">freeimagehosting-adbodytemp-file-include(33196)</ref></refs><vuln_soft><prod name="Free Image Hosting" vendor="Free PHP Scripts"><vers num="1.0"/><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="3.4" CVSS_exploit_subscore="1.2" CVSS_impact_subscore="6.4" CVSS_score="3.4" CVSS_vector="(AV:L/AC:H/Au:M/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-08-13" name="CVE-2007-1716" published="2007-03-27" seq="2007-1716" severity="Low" type="CVE"><desc><descript source="cve">pam_console does not properly restore ownership for certain console devices when there are multiple users logged into the console and one user logs out, which might allow local users to gain privileges.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref source="" url="https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=230823"></ref><ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2007-September/065902.html">20070920 VMSA-2007-0006 Critical security updates for all supported versions of VMware ESX Server, VMware Server, VMware Workstation, VMware ACE, and VMware Player</ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200711-23.xml">GLSA-200711-23</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2007-0465.html">RHSA-2007:0465</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2007-0555.html">RHSA-2007:0555</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2007-0737.html">RHSA-2007:0737</ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20070602-01-P.asc">20070602-01-P</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/3229">ADV-2007-3229</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25631">25631</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25894">25894</ref><ref source="SECUNIA" url="http://secunia.com/advisories/27590">27590</ref><ref source="SECUNIA" url="http://secunia.com/advisories/26909">26909</ref><ref source="SECUNIA" url="http://secunia.com/advisories/27706">27706</ref><ref source="" url="http://support.avaya.com/elmodocs2/security/ASA-2007-526.htm"></ref><ref source="SECUNIA" url="http://secunia.com/advisories/28319">28319</ref></refs><vuln_soft><prod name="Enterprise Linux" vendor="Red Hat"><vers num="4.4"/></prod></vuln_soft></entry><entry CVSS_base_score="7.8" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.9" CVSS_score="7.8" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:C/A:N)" CVSS_version="2.0" modified="2007-03-29" name="CVE-2007-1717" published="2007-03-27" seq="2007-1717" severity="High" type="CVE"><desc><descript source="cve">The mail function in PHP 4.0.0 through 4.4.6 and 5.0.0 through 5.2.1 truncates e-mail messages at the first ASCIIZ (&apos;\0&apos;) byte, which might allow context-dependent attackers to prevent intended information from being delivered in e-mail messages.  NOTE: this issue might be security-relevant in cases when the trailing contents of e-mail messages are important, such as logging information or if the message is expected to be well-formed.</descript></desc><loss_types><int/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref source="" url="http://www.php-security.org/MOPB/MOPB-33-2007.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/23146">23146</ref><ref source="" url="http://us2.php.net/releases/4_4_7.php"></ref><ref source="" url="http://us2.php.net/releases/5_2_2.php"></ref><ref source="" url="http://docs.info.apple.com/article.html?artnum=306172"></ref><ref source="APPLE" url="http://lists.apple.com/archives/security-announce//2007/Jul/msg00004.html">APPLE-SA-2007-07-31</ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200705-19.xml">GLSA-200705-19</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2007_32_php.html">SUSE-SA:2007:032</ref><ref source="BID" url="http://www.securityfocus.com/bid/25159">25159</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/2732">ADV-2007-2732</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25056">25056</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25445">25445</ref><ref source="SECUNIA" url="http://secunia.com/advisories/26235">26235</ref></refs><vuln_soft><prod name="PHP" vendor="PHP"><vers num=""/><vers num="4.0"/><vers num="4.0 Beta 1"/><vers num="4.0 Beta 2"/><vers num="4.0 Beta 3"/><vers num="4.0 Beta 4"/><vers num="4.0 Beta 4 Patch Level 1"/><vers num="4.0 RC1"/><vers num="4.0 RC2"/><vers num="4.0.0"/><vers num="4.0.1"/><vers num="4.0.1 pl1"/><vers num="4.0.1 pl2"/><vers num="4.0.2"/><vers num="4.0.3"/><vers num="4.0.3 pl1"/><vers num="4.0.4"/><vers num="4.0.4 pl1"/><vers num="4.0.5"/><vers num="4.0.6"/><vers num="4.0.7"/><vers num="4.0.7 RC1"/><vers num="4.0.7 RC2"/><vers num="4.0.7 RC3"/><vers num="4.1.0"/><vers num="4.1.1"/><vers num="4.1.2"/><vers edition="Dev" num="4.2"/><vers num="4.2.0"/><vers num="4.2.1"/><vers num="4.2.2"/><vers num="4.2.3"/><vers num="4.3"/><vers num="4.3.1"/><vers num="4.3.10"/><vers num="4.3.11"/><vers num="4.3.2"/><vers num="4.3.3"/><vers num="4.3.4"/><vers num="4.3.5"/><vers num="4.3.6"/><vers num="4.3.7"/><vers num="4.3.8"/><vers num="4.3.9"/><vers num="4.4.0"/><vers num="4.4.1"/><vers num="4.4.2"/><vers num="4.4.3"/><vers num="4.4.4"/><vers num="4.4.5"/><vers num="4.4.6"/><vers num="5.0 candidate 1"/><vers num="5.0 candidate 2"/><vers num="5.0 candidate 3"/><vers num="5.0.0"/><vers num="5.0.0 Beta1"/><vers num="5.0.0 Beta2"/><vers num="5.0.0 Beta3"/><vers num="5.0.0 Beta4"/><vers num="5.0.0 RC1"/><vers num="5.0.0 RC2"/><vers num="5.0.0 RC3"/><vers num="5.0.1"/><vers num="5.0.2"/><vers num="5.0.3"/><vers num="5.0.4"/><vers num="5.0.5"/><vers num="5.1"/><vers num="5.1.0"/><vers num="5.1.1"/><vers num="5.1.2"/><vers num="5.1.3"/><vers num="5.1.4"/><vers num="5.1.5"/><vers num="5.1.5"/><vers num="5.1.6"/><vers num="5.1.6"/><vers num="5.2.0"/><vers num="5.2.1"/><vers num="5.2.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.8" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.9" CVSS_score="7.8" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:C/A:N)" CVSS_version="2.0" modified="2007-03-29" name="CVE-2007-1718" published="2007-03-27" seq="2007-1718" severity="High" type="CVE"><desc><descript source="cve">CRLF injection vulnerability in the mail function in PHP 4.0.0 through 4.4.6 and 5.0.0 through 5.2.1 allows remote attackers to inject arbitrary e-mail headers and possibly conduct spam attacks via a control character immediately following folding of the (1) Subject or (2) To parameter, as demonstrated by a parameter containing a &quot;\r\n\t\n&quot; sequence, related to an increment bug in the SKIP_LONG_HEADER_SEP macro.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://www.php-security.org/MOPB/MOPB-34-2007.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/23145">23145</ref><ref source="REDHAT" url="http://rhn.redhat.com/errata/RHSA-2007-0155.html">
RHSA-2007:0155</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24924">
24924</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2007-0153.html">
RHSA-2007:0153</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2007-0162.html">
RHSA-2007:0162</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017946">
1017946</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24965">
24965</ref><ref source="DEBIAN" url="http://www.debian.org/security/2007/dsa-1282">
DSA-1282</ref><ref source="DEBIAN" url="http://www.debian.org/security/2007/dsa-1283">
DSA-1283</ref><ref source="UBUNTU" url="http://www.ubuntu.com/usn/usn-455-1">
USN-455-1</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25025">
25025</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25062">
25062</ref><ref source="" url="http://us2.php.net/releases/5_2_2.php"></ref><ref source="SECUNIA" url="http://secunia.com/advisories/25057">
25057</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2007:087">
MDKSA-2007:087</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2007:088">
MDKSA-2007:088</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2007:089">
MDKSA-2007:089</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24909">
24909</ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200705-19.xml">GLSA-200705-19</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:087">MDKSA-2007:087</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:088">MDKSA-2007:088</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:089">MDKSA-2007:089</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:090">MDKSA-2007:090</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2007_32_php.html">SUSE-SA:2007:032</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25056">25056</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25445">25445</ref></refs><vuln_soft><prod name="PHP" vendor="PHP"><vers num="4.0"/><vers num="4.0 Beta 1"/><vers num="4.0 Beta 2"/><vers num="4.0 Beta 3"/><vers num="4.0 Beta 4"/><vers num="4.0 Beta 4 Patch Level 1"/><vers num="4.0 RC1"/><vers num="4.0 RC2"/><vers num="4.0.0"/><vers num="4.0.1"/><vers num="4.0.1 pl1"/><vers num="4.0.1 pl2"/><vers num="4.0.2"/><vers num="4.0.3"/><vers num="4.0.3 pl1"/><vers num="4.0.4"/><vers num="4.0.4 pl1"/><vers num="4.0.5"/><vers num="4.0.6"/><vers num="4.0.7"/><vers num="4.0.7 RC1"/><vers num="4.0.7 RC2"/><vers num="4.0.7 RC3"/><vers num="4.1.0"/><vers num="4.1.1"/><vers num="4.1.2"/><vers edition="Dev" num="4.2"/><vers num="4.2.0"/><vers num="4.2.1"/><vers num="4.2.2"/><vers num="4.2.3"/><vers num="4.3"/><vers num="4.3.1"/><vers num="4.3.10"/><vers num="4.3.11"/><vers num="4.3.2"/><vers num="4.3.3"/><vers num="4.3.4"/><vers num="4.3.5"/><vers num="4.3.6"/><vers num="4.3.7"/><vers num="4.3.8"/><vers num="4.3.9"/><vers num="4.4.0"/><vers num="4.4.1"/><vers num="4.4.2"/><vers num="4.4.3"/><vers num="4.4.4"/><vers num="4.4.5"/><vers num="4.4.6"/><vers num="5.0 candidate 1"/><vers num="5.0 candidate 2"/><vers num="5.0 candidate 3"/><vers num="5.0.0"/><vers num="5.0.0 Beta1"/><vers num="5.0.0 Beta2"/><vers num="5.0.0 Beta3"/><vers num="5.0.0 Beta4"/><vers num="5.0.0 RC1"/><vers num="5.0.0 RC2"/><vers num="5.0.0 RC3"/><vers num="5.0.1"/><vers num="5.0.2"/><vers num="5.0.3"/><vers num="5.0.4"/><vers num="5.0.5"/><vers num="5.1"/><vers num="5.1.0"/><vers num="5.1.1"/><vers num="5.1.2"/><vers num="5.1.3"/><vers num="5.1.4"/><vers num="5.1.5"/><vers num="5.1.6"/><vers num="5.2.0"/><vers num="5.2.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-03-29" name="CVE-2007-1719" published="2007-03-27" seq="2007-1719" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in eject.c in Jason W. Bacon mcweject 0.9 on FreeBSD, and possibly other versions, allows local users to execute arbitrary code via a long command line argument, possibly involving the device name.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input/></vuln_types><range><local/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3578">3578</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1125">ADV-2007-1125</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24641">24641</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33212">freebsd-eject-bo(33212)</ref></refs><vuln_soft><prod name="mcweject" vendor="Jason W. Bacon"><vers num="0.9"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-03-29" name="CVE-2007-1720" published="2007-03-27" seq="2007-1720" severity="High" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in addressbook.php in the Addressbook 1.2 module for PHP-Nuke allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the module_name parameter, as demonstrated by injecting PHP sequences into an Apache HTTP Server log file.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3582">3582</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33243">
addressbook-addressbook-file-include(33243)</ref><ref source="BID" url="http://www.securityfocus.com/bid/23156">
23156</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1118">
ADV-2007-1118</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24697">
24697</ref></refs><vuln_soft><prod name="Addressbook" vendor="SB-WebSoft"><vers num="1.2"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-03-29" name="CVE-2007-1721" published="2007-03-27" seq="2007-1721" severity="High" type="CVE"><desc><descript source="cve">Multiple PHP remote file inclusion vulnerabilities in C-Arbre 0.6PR7 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the root_path parameter to (1) Richtxt_functions.inc.php, (2) adddocfile.php, (3) auth_check.php, (4) browse_current_category.inc.php, (5) docfile_details.php, (6) main.php, (7) mainarticle.php, (8) maindocfile.php, (9) modify.php, (10) new.php, (11) resource_details.php, or (12) smallsearch.php in lib/; or (13) mwiki/LocalSettings.php.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3583">3583</ref><ref source="" url="http://advisories.echo.or.id/adv/adv78-K-159-2007.txt"></ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/463925/100/0/threaded">

20070327 [ECHO_ADV_78$2007] C-Arbre &lt;= 0.6PR7 (root_path) Remote File Inclusion Vulnerability</ref><ref source="BID" url="http://www.securityfocus.com/bid/23154">
23154</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1119">
ADV-2007-1119</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33238">
carbre-rootpath-file-include(33238)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2491">2491</ref></refs><vuln_soft><prod name="C-Arbre" vendor="Realink"><vers num="0.6 PR7" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-03-29" name="CVE-2007-1722" published="2007-03-27" seq="2007-1722" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in the DownloadCertificateExt function in SignKorea SKCommAX ActiveX control module 7.2.0.2 and 3280 6.6.0.1 allows remote attackers to execute arbitrary code via a long pszUserID argument.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref source="FULLDISC" url="http://marc.info/?l=full-disclosure&amp;m=117497124018827&amp;w=2">20070327 SignKorea&apos;s ActiveX Buffer Overflow Vulnerability</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1114">ADV-2007-1114</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24587">24587</ref><ref source="BID" url="http://www.securityfocus.com/bid/23149">
23149</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33245">
skcommax-downloadcertificate-bo(33245)</ref></refs><vuln_soft><prod name="SKCommAX ActiveX Control" vendor="SignKorea"><vers num="7.2.0.2"/><vers num="6.6.0.1 3280"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-04-05" name="CVE-2007-1723" published="2007-03-27" seq="2007-1723" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in the administration console in Secure Computing CipherTrust IronMail 6.1.1 allow remote attackers to inject arbitrary web script or HTML via the (1) network, (2) defRouterIp, (3) hostName, (4) domainName, (5) ipAddress, (6) defaultRouter, (7) dns1, or (8) dns2 parameter to (a) admin/system_IronMail.do; the (9) ipAddress parameter to (b) admin/systemOutOfBand.do; the (10) password or (11) confirmPassword parameter to (c) admin/systemBackup.do; the (12) Klicense parameter to (d) admin/systemLicenseManager.do; the (13) rows[1].attrValueStr or (14) rows[2].attrValueStr parameter to (e) admin/systemWebAdminConfig.do; the (15) rows[0].attrValueStr, rows[1].attrValueStr, (16) rows[2].attrValue, or (17) rows[2].attrValueStrClone parameter to (f) admin/ldap_ConfigureServiceProperties.do; the (18) input1 parameter to (g) admin/mailFirewall_MailRoutingInternal.do; or the (19) rows[2].attrValueStr, (20) rows[3].attrValueStr, (21) rows[5].attrValueStr, or (22) rows[6].attrValueStr parameter to (h) admin/mailIdsConfig.do.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/463827/100/0/threaded">20070326 Multiple XSS in IronMail</ref><ref source="" url="http://www.514.es/2007/03/siaadv07004_multiples_vulnerab.html"></ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1164">
ADV-2007-1164</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017821">
1017821</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24657">
24657</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2484">2484</ref></refs><vuln_soft><prod name="IronMail" vendor="CipherTrust"><vers num="6.1.1"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-03-29" name="CVE-2007-1724" published="2007-03-27" seq="2007-1724" severity="High" type="CVE"><desc><descript source="cve">Unspecified vulnerability in ReactOS 0.3.1 has unknown impact and attack vectors, related to a fix for &quot;dozens of win32k bugs and failures,&quot; in which the fix itself introduces a vulnerability, possibly related to user-mode and kernel-mode copy failures.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs><ref source="" url="http://www.reactos.org/wiki/index.php/ChangeLog-0.3.1"></ref></refs><vuln_soft><prod name="ReactOS" vendor="ReactOS"><vers num="0.3.1"/></prod></vuln_soft></entry><entry CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" CVSS_score="9.3" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-03-29" name="CVE-2007-1725" published="2007-03-28" seq="2007-1725" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in index.php in IceBB 1.0-rc5 allows remote authenticated users to execute arbitrary SQL commands via the filename of an uploaded file to the avatar function, as demonstrated by setting admin privileges.</descript></desc><impacts><impact source="nvd">Successful exploitation allows an attacker to gain administrator privileges, but requires that &quot;magic_quotes_gpc&quot; is disabled.</impact></impacts><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MILW0RM" url="http://milw0rm.com/exploits/3580">3580</ref><ref source="MILW0RM" url="http://milw0rm.com/exploits/3581">3581</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1116">ADV-2007-1116</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24644">24644</ref><ref source="BID" url="http://www.securityfocus.com/bid/23158">
23158</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33240">
icebb-index-sql-injection(33240)</ref></refs><vuln_soft><prod name="IceBB" vendor="IceBB"><vers num="1.0 RC 5"/></prod></vuln_soft></entry><entry CVSS_base_score="6.5" CVSS_exploit_subscore="8.0" CVSS_impact_subscore="6.4" CVSS_score="6.5" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-03-29" name="CVE-2007-1726" published="2007-03-28" seq="2007-1726" severity="Medium" type="CVE"><desc><descript source="cve">Unrestricted file upload vulnerability in index.php in IceBB 1.0-rc5 allows remote authenticated users to upload arbitrary files via the avatar function, which can later be accessed in uploads/.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MILW0RM" url="http://milw0rm.com/exploits/3581">3581</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1116">ADV-2007-1116</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24644">24644</ref><ref source="BID" url="http://www.securityfocus.com/bid/23151">
23151</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33242">
icebb-index-file-upload(33242)</ref></refs><vuln_soft><prod name="IceBB" vendor="IceBB"><vers num="1.0 RC 5"/></prod></vuln_soft></entry><entry CVSS_base_score="6.5" CVSS_exploit_subscore="8.0" CVSS_impact_subscore="6.4" CVSS_score="6.5" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-03-29" name="CVE-2007-1727" published="2007-03-28" seq="2007-1727" severity="Medium" type="CVE"><desc><descript source="cve">Unspecified vulnerability in HP OpenView Network Node Manager (OV NNM) 6.20, 6.4x, 7.01, 7.50, and 7.51 allows remote authenticated users to access certain privileged &quot;facilities&quot; via unspecified vectors.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref source="HP" url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=c00854999">HPSBMA02198</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1121">ADV-2007-1121</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017817">1017817</ref><ref source="BID" url="http://www.securityfocus.com/bid/23163">
23163</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33241">
hp-openview-nnm-unspecified-security-bypass(33241)</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24746">
24746</ref></refs><vuln_soft><prod name="OpenView Network Node Manager" vendor="HP"><vers num="6.2"/><vers num="6.4"/><vers num="7.0.1"/><vers num="7.50"/><vers num="7.51"/></prod></vuln_soft></entry><entry CVSS_base_score="7.8" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.9" CVSS_score="7.8" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_version="2.0" modified="2007-03-29" name="CVE-2007-1728" published="2007-03-28" seq="2007-1728" severity="High" type="CVE"><desc><descript source="cve">The Remote Play feature in Sony Playstation 3 (PS3) 1.60 and Playstation Portable (PSP) 3.10 OE-A allows remote attackers to cause a denial of service via a flood of UDP packets.</descript></desc><loss_types><avail/></loss_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/463847/100/0/threaded">20070326 Playstation 3 </ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33503">
ps3-psp-udp-dos(33503)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2485">2485</ref></refs><vuln_soft><prod name="PSP" vendor="Sony"><vers num="3.10 OE-A"/></prod><prod name="PlayStation 3" vendor="Sony"><vers num="1.60"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-03-29" name="CVE-2007-1729" published="2007-03-28" seq="2007-1729" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in includes/start.php in Flexbb 1.0.0 10005 Beta Release 1 allows remote attackers to execute arbitrary SQL commands via the flexbb_lang_id COOKIE parameter to index.php.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/463917/100/0/threaded">20070327 [KAPDA::#64] - Flexbb Sql Injection</ref><ref source="" url="http://www.kapda.ir/advisory-481.html"></ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33250">
flexbb-index-sql-injection(33250)</ref><ref source="BID" url="http://www.securityfocus.com/bid/23161">
23161</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1141">
ADV-2007-1141</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2486">2486</ref></refs><vuln_soft><prod name="FlexBB" vendor="revolutionProducts"><vers num="1.0.0 10005 Beta 1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="9.2" CVSS_score="6.6" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:N/A:C)" CVSS_version="2.0" modified="2007-03-29" name="CVE-2007-1730" published="2007-03-28" seq="2007-1730" severity="Medium" type="CVE"><desc><descript source="cve">Integer signedness error in the DCCP support in the do_dccp_getsockopt function in net/dccp/proto.c in Linux kernel 2.6.20 and later allows local users to read kernel memory or cause a denial of service (oops) via a negative optlen value.</descript></desc><loss_types><avail/><conf/></loss_types><vuln_types><other/></vuln_types><range><local/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/463934/100/0/threaded">20070327 Linux Kernel DCCP Memory Disclosure Vulnerability</ref><ref source="BID" url="http://www.securityfocus.com/bid/23162">
23162</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017820">
1017820</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/464144/100/0/threaded">
20070329 Re: Re: [Full-disclosure] Linux Kernel DCCP Memory Disclosure Vulnerability</ref><ref source="MLIST" url="http://marc.info/?l=dccp&amp;m=117509584316267&amp;w=2">
[dccp] 20070328 [PATCH 1/1] getsockopt: Fix DCCP_SOCKOPT_[SEND,RECV]_CSCOV</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1143">
ADV-2007-1143</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33274">
kernel-dccp-information-disclosure(33274)</ref><ref source="UBUNTU" url="http://www.ubuntu.com/usn/usn-464-1">USN-464-1</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25392">25392</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2482">2482</ref></refs><vuln_soft><prod name="Kernel" vendor="Linux"><vers num="2.6.20"/><vers num="2.6.20.1"/><vers num="2.6.20.2"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-03-29" name="CVE-2007-1731" published="2007-03-28" seq="2007-1731" severity="High" type="CVE"><desc><descript source="cve">Multiple stack-based buffer overflows in High Performance Anonymous FTP Server (hpaftpd) 1.01 allow remote attackers to execute arbitrary code via long arguments to the (1) USER, (2) PASS, (3) CWD, (4) MKD, (5) RMD, (6) DELE, (7) RNFR, or (8) RNTO FTP command.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://www.securiteam.com/securitynews/5AP0L1PKUU.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/23147">23147</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1142">
ADV-2007-1142</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33288">
hpaftpd-multiple-commands-bo(33288)</ref></refs><vuln_soft><prod name="Hpaftpd" vendor="Hpaftpd"><vers num="1.01"/></prod></vuln_soft></entry><entry CVSS_base_score="3.5" CVSS_exploit_subscore="6.8" CVSS_impact_subscore="2.9" CVSS_score="3.5" CVSS_vector="(AV:N/AC:M/Au:S/C:N/I:P/A:N)" CVSS_version="2.0" modified="2007-04-03" name="CVE-2007-1732" published="2007-03-28" seq="2007-1732" severity="Low" type="CVE"><desc><descript source="cve">** DISPUTED **  Cross-site scripting (XSS) vulnerability in an mt import in wp-admin/admin.php in WordPress 2.1.2 allows remote authenticated administrators to inject arbitrary web script or HTML via the demo parameter.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. NOTE: another researcher disputes this issue, stating that this is legitimate functionality for administrators.  However, it has been patched by at least one vendor.</descript></desc><impacts><impact source="nvd">Successful exploitation requires that the target user is logged in as administrator.</impact></impacts><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref source="FULLDISC" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=117319839710382&amp;w=2">20070306 Re: Wordpress &lt;= v2.1.0</ref><ref source="" url="http://codex.wordpress.org/Roles_and_Capabilities"></ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200703-23.xml">GLSA-200703-23</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24430">24430</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24566">24566</ref></refs><vuln_soft><prod name="WordPress" vendor="WordPress"><vers num="2.1.2"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-04-02" name="CVE-2007-1733" published="2007-03-28" seq="2007-1733" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in InterVations NaviCOPA HTTP Server 2.01 allows remote attackers to execute arbitrary code via a long (1) /cgi-bin/ or (2) /cgi/ pathname in an HTTP GET request, probably a different issue than CVE-2006-5112.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/463931/100/0/threaded">20070327 Buffer Overflow in InterVetions&apos; NaviCopa HTTP server 2.01</ref><ref patch="1" source="" url="http://www.skilltube.com/index.php?option=com_content&amp;task=view&amp;id=13&amp;Itemid=37"></ref><ref source="BID" url="http://www.securityfocus.com/bid/23179">23179</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1137">ADV-2007-1137</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24673">24673</ref><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3589">
3589</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33296">
navicopa-cgi-bo(33296)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2483">2483</ref></refs><vuln_soft><prod name="NaviCOPA Web Server" vendor="InterVations"><vers num="2.01"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-04-02" name="CVE-2007-1734" published="2007-03-28" seq="2007-1734" severity="High" type="CVE"><desc><descript source="cve">The DCCP support in the do_dccp_getsockopt function in net/dccp/proto.c in Linux kernel 2.6.20 and later does not verify the upper bounds of the optlen value, which allows local users running on certain architectures to read kernel memory or cause a denial of service (oops), a related issue to CVE-2007-1730.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><access/><input bound="1"/></vuln_types><range><local/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/463969/100/0/threaded">20070327 Re: [Full-disclosure] Linux Kernel DCCP Memory Disclosure Vulnerability</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017820">1017820</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33274">
kernel-dccp-information-disclosure(33274)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2511">2511</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/43321">linux-kernel-dccp-info-disclosure(43321)</ref></refs><vuln_soft><prod name="Kernel" vendor="Linux"><vers num="2.6.20"/><vers num="2.6.20.1"/><vers num="2.6.20.2"/></prod></vuln_soft></entry><entry CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" CVSS_score="9.3" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-04-04" name="CVE-2007-1735" published="2007-03-28" seq="2007-1735" severity="High" type="CVE"><desc><descript source="cve">Stack-based buffer overflow in Corel WordPerfect Office X3 (13.0.0.565) allows user-assisted remote attackers to execute arbitrary code via a long printer selection (PRS) name in a Wordperfect document.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/><user_init/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/464046/100/0/threaded">20070328 Corel Wordperfect Office X3 Stack Overflow</ref><ref adv="1" source="" url="http://www.nop-art.net/advisories/wpwinX3.txt"></ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/23177">23177</ref><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3593">3593</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1145">ADV-2007-1145</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24664">24664</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33286">wordperfect-printer-selection-bo(33286)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2489">2489</ref></refs><vuln_soft><prod name="WordPerfect Office" vendor="Corel"><vers num="13.0.0.565"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-04-02" name="CVE-2007-1736" published="2007-03-28" seq="2007-1736" severity="High" type="CVE"><desc><descript source="cve">Mozilla Firefox 2.0.0.3 does not check URLs embedded in (1) object or (2) iframe HTML tags against the phishing site blacklist, which allows remote attackers to bypass phishing protection.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/464041/100/0/threaded">20070328 Bypass phishing protection in Firefox / Opera</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2488">2488</ref></refs><vuln_soft><prod name="Firefox" vendor="Mozilla"><vers num="2.0.0.3"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-03-30" name="CVE-2007-1737" published="2007-03-28" seq="2007-1737" severity="High" type="CVE"><desc><descript source="cve">Opera 9.10 does not check URLs embedded in (1) object or (2) iframe HTML tags against the phishing site blacklist, which allows remote attackers to bypass phishing protection.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input/><design/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/464041/100/0/threaded">20070328 Bypass phishing protection in Firefox / Opera</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2488">2488</ref></refs><vuln_soft><prod name="Opera" vendor="Opera Software"><vers num="9.10"/></prod></vuln_soft></entry><entry CVSS_base_score="6.9" CVSS_exploit_subscore="3.4" CVSS_impact_subscore="10.0" CVSS_score="6.9" CVSS_vector="(AV:L/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-04-05" name="CVE-2007-1738" published="2007-03-28" seq="2007-1738" severity="Medium" type="CVE"><desc><descript source="cve">TrueCrypt 4.3, when installed setuid root, allows local users to cause a denial of service (filesystem unavailability) or gain privileges by mounting a crafted TrueCrypt volume, as demonstrated using (1) /usr/bin or (2) another user&apos;s home directory, a different issue than CVE-2007-1589.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><exception/></vuln_types><range><local/></range><refs><ref source="BID" url="http://www.securityfocus.com/bid/23180">23180</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24643">24643</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/464064/100/0/threaded">20070328 Denial of Service Vulnerabilities in TrueCrypt 4.3 Linux (re. bid 23180)</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/464472/100/100/threaded">
20070401 Re: Denial of Service Vulnerabilities in TrueCrypt 4.3 Linux (re. bid 23180)</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/464722/100/0/threaded">
20070404 Re: Denial of Service Vulnerabilities in TrueCrypt 4.3 Linux (re. bid 23180)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2492">2492</ref></refs><vuln_soft><prod name="TrueCrypt" vendor="TrueCrypt Foundation"><vers num="3.0"/><vers num="4.0"/><vers num="4.1"/><vers num="4.2"/><vers num="4.3"/></prod></vuln_soft></entry><entry CVSS_base_score="7.8" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.9" CVSS_score="7.8" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_version="2.0" modified="2007-03-30" name="CVE-2007-1739" published="2007-03-28" seq="2007-1739" severity="High" type="CVE"><desc><descript source="cve">Heap-based buffer overflow in the LDAP server in IBM Lotus Domino before 6.5.6 and 7.x before 7.0.2 FP1 allows remote attackers to cause a denial of service (crash) via a long, malformed DN request, which causes only the lower 16 bits of the string length to be used in memory allocation.</descript></desc><loss_types><avail/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="IDEFENSE" url="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=494">20070328 IBM Lotus Domino Server LDAP Request Invalid DN Message Heap Overflow Vulnerability</ref><ref source="" url="http://www-1.ibm.com/support/docview.wss?uid=swg21257248"></ref><ref source="BID" url="http://www.securityfocus.com/bid/23173">23173</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1133">ADV-2007-1133</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24633">24633</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/927988">
VU#927988</ref><ref source="BID" url="http://www.securityfocus.com/bid/23174">
23174</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017825">
1017825</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33278">
domino-ldap-bo(33278)</ref></refs><vuln_soft><prod name="Lotus Domino" vendor="IBM"><vers num="7.0"/><vers num="7.0.1"/><vers num="7.0.2"/></prod></vuln_soft></entry><entry modified="2007-03-30" name="CVE-2007-1740" published="2007-03-28" reject="1" seq="2007-1740" type="CVE"><desc><descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2006-4843.  Reason: This candidate is a duplicate of CVE-2006-4843.  Notes: All CVE users should reference CVE-2006-4843 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</descript></desc><sols><sol source="nvd">This vulnerability is addressed in the following product release: Lotus Domino 6.5.6 and 7.0.2 Fix Pack 1 (FP1). For more information consult the following URL: http://www-1.ibm.com/support/docview.wss?uid=swg21257026 

</sol></sols><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs/><vuln_soft><prod name="Lotus Domino" vendor="IBM"><vers num="6.5.0"/><vers num="6.5.1"/><vers num="6.5.2"/><vers num="6.5.3"/><vers num="6.5.4"/><vers num="6.5.4 FP 1"/><vers num="6.5.4 FP 2"/><vers num="6.5.5"/><vers num="6.5.5 FP1"/><vers num="6.5.5 FP2"/><vers num="7.0"/><vers num="7.0.1"/><vers num="7.0.2"/></prod></vuln_soft></entry><entry CVSS_base_score="6.2" CVSS_exploit_subscore="1.9" CVSS_impact_subscore="10.0" CVSS_score="6.2" CVSS_vector="(AV:L/AC:H/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-08-02" name="CVE-2007-1741" published="2007-04-13" seq="2007-1741" severity="Medium" type="CVE"><desc><descript source="cve">Multiple race conditions in suexec in Apache HTTP Server (httpd) 2.2.3 between directory and file validation, and their usage, allow local users to gain privileges and execute arbitrary code by renaming directories or performing symlink attacks. NOTE: the researcher, who is reliable, claims that the vendor disputes the issue because &quot;the attacks described rely on an insecure server configuration&quot; in which the user &quot;has write access to the document root.&quot;</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><race/></vuln_types><range><local/></range><refs><ref adv="1" source="IDEFENSE" url="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=511">20070411 Apache HTTPD suEXEC Multiple Vulnerabilities</ref><ref adv="1" source="MLIST" url="http://marc.info/?l=apache-httpd-dev&amp;m=117511568709063&amp;w=2">[apache-http-dev] 20070328 [Fwd: iDefense Final Notice [IDEF1445]]</ref><ref source="MLIST" url="http://marc.info/?l=apache-httpd-dev&amp;m=117511834512138&amp;w=2">[apache-http-dev] 20070328 Re: [Fwd: iDefense Final Notice [IDEF1445]]</ref><ref source="BID" url="http://www.securityfocus.com/bid/23438">23438</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017904">1017904</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33584">apache-suexec-privilege-escalation(33584)</ref></refs><vuln_soft><prod name="Apache HTTP Server" vendor="Apache Software Foundation"><vers num="2.2.3"/></prod></vuln_soft></entry><entry CVSS_base_score="3.7" CVSS_exploit_subscore="1.9" CVSS_impact_subscore="6.4" CVSS_score="3.7" CVSS_vector="(AV:L/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-04-16" name="CVE-2007-1742" published="2007-04-13" seq="2007-1742" severity="Low" type="CVE"><desc><descript source="cve">suexec in Apache HTTP Server (httpd) 2.2.3 uses a partial comparison for verifying whether the current directory is within the document root, which might allow local users to perform unauthorized operations on incorrect directories, as demonstrated using &quot;html_backup&quot; and &quot;htmleditor&quot; under an &quot;html&quot; directory.  NOTE: the researcher, who is reliable, claims that the vendor disputes the issue because &quot;the attacks described rely on an insecure server configuration&quot; in which the user &quot;has write access to the document root.&quot;</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><design/><config/></vuln_types><range><local/></range><refs><ref source="IDEFENSE" url="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=511">20070411 Apache HTTPD suEXEC Multiple Vulnerabilities</ref><ref source="MLIST" url="http://marc.info/?l=apache-httpd-dev&amp;m=117511568709063&amp;w=2">[apache-http-dev] 20070328 [Fwd: iDefense Final Notice [IDEF1445]]</ref><ref source="MLIST" url="http://marc.info/?l=apache-httpd-dev&amp;m=117511834512138&amp;w=2">[apache-http-dev] 20070328 Re: [Fwd: iDefense Final Notice [IDEF1445]]</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017904">1017904</ref></refs><vuln_soft><prod name="Apache HTTP Server" vendor="Apache Software Foundation"><vers num="2.2.3"/></prod></vuln_soft></entry><entry CVSS_base_score="4.4" CVSS_exploit_subscore="3.4" CVSS_impact_subscore="6.4" CVSS_score="4.4" CVSS_vector="(AV:L/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-04-17" name="CVE-2007-1743" published="2007-04-13" seq="2007-1743" severity="Medium" type="CVE"><desc><descript source="cve">suexec in Apache HTTP Server (httpd) 2.2.3 does not verify combinations of user and group IDs on the command line, which might allow local users to leverage other vulnerabilities to create arbitrary UID/GID owned files if /proc is mounted.  NOTE: the researcher, who is reliable, claims that the vendor disputes the issue because &quot;the attacks described rely on an insecure server configuration&quot; in which the user &quot;has write access to the document root.&quot;  In addition, because this is dependent on other vulnerabilities, perhaps this is resultant and should not be included in CVE.</descript></desc><impacts><impact source="nvd">From the vendor:
&quot;The attacks described rely on an insecure server configuration - that
the unprivileged user the server runs as has write access to the
document root. The suexec tool cannot detect all possible insecure
configurations, nor can it protect against privilege &quot;escalation&quot; in
all such cases.

It is important to note that to be able to invoke suexec, the attacker
must also first gain the ability to execute arbitrary code as the
unprivileged server user.&quot;
</impact></impacts><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/><input/><race/></vuln_types><range><local/></range><refs><ref source="IDEFENSE" url="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=511">20070411 Apache HTTPD suEXEC Multiple Vulnerabilities</ref><ref source="MLIST" url="http://marc.info/?l=apache-httpd-dev&amp;m=117511568709063&amp;w=2">[apache-http-dev] 20070328 [Fwd: iDefense Final Notice [IDEF1445]]</ref><ref source="MLIST" url="http://marc.info/?l=apache-httpd-dev&amp;m=117511834512138&amp;w=2">[apache-http-dev] 20070328 Re: [Fwd: iDefense Final Notice [IDEF1445]]</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017904">1017904</ref></refs><vuln_soft><prod name="Apache HTTP Server" vendor="Apache Software Foundation"><vers num="2.2.3"/></prod></vuln_soft></entry><entry CVSS_base_score="6.3" CVSS_exploit_subscore="3.4" CVSS_impact_subscore="9.2" CVSS_score="6.3" CVSS_vector="(AV:L/AC:M/Au:N/C:C/I:C/A:N)" CVSS_version="2.0" modified="2007-05-04" name="CVE-2007-1744" published="2007-05-02" seq="2007-1744" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in the Shared Folders feature for VMware Workstation before 5.5.4, when a folder is shared, allows users on the guest system to write to arbitrary files on the host system via the &quot;Backdoor I/O Port&quot; interface.</descript></desc><impacts><impact source="nvd">Successful exploitation requires that a folder is shared.  Although the &quot;Shared Folders&quot; feature is enabled by default, no folders are shared by default.</impact></impacts><loss_types><conf/><int/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref source="IDEFENSE" url="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=521">20070427 VMware Workstation Shared Folders Directory Traversal Vulnerability</ref><ref patch="1" source="" url="http://www.vmware.com/support/ws55/doc/releasenotes_ws55.html#554"></ref><ref source="BID" url="http://www.securityfocus.com/bid/23721">23721</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017980">1017980</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25079">
25079</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1592">ADV-2007-1592</ref></refs><vuln_soft><prod name="VMWare Workstation" vendor="VMWare"><vers num="5.5.3" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.1" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.9" CVSS_score="7.1" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:C)" CVSS_version="2.0" modified="2007-04-17" name="CVE-2007-1745" published="2007-04-16" seq="2007-1745" severity="High" type="CVE"><desc><descript source="cve">The chm_decompress_stream function in libclamav/chmunpack.c in Clam AntiVirus (ClamAV) before 0.90.2 leaks file descriptors, which has unknown impact and attack vectors involving a crafted CHM file, a different vulnerability than CVE-2007-0897.  NOTE: some of these details are obtained from third party information.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://sourceforge.net/project/shownotes.php?release_id=500765"></ref><ref source="BID" url="http://www.securityfocus.com/bid/23473">23473</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1378">ADV-2007-1378</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24891">24891</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33636">clamav-chmdecompressstream-dos(33636)</ref><ref source="" url="http://support.novell.com/techcenter/psdb/50a5cb718f20761dd7e0b6b4e0935c52.html"></ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200704-21.xml">
GLSA-200704-21</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2007_26_clamav.html">
SUSE-SA:2007:026</ref><ref source="TRUSTIX" url="http://www.trustix.org/errata/2007/0013/">
2007-0013</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24920">
24920</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24946">
24946</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24996">
24996</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25022">
25022</ref><ref source="DEBIAN" url="http://www.debian.org/security/2007/dsa-1281">
DSA-1281</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25028">
25028</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2007:098">
MDKSA-2007:098</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25189">
25189</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:098">MDKSA-2007:098</ref><ref source="" url="http://docs.info.apple.com/article.html?artnum=307562"></ref><ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2008/Mar/msg00001.html">APPLE-SA-2008-03-18</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/0924/references">ADV-2008-0924</ref><ref source="SECUNIA" url="http://secunia.com/advisories/29420">29420</ref></refs><vuln_soft><prod name="ifenslave" vendor="ifenslave"><vers num="0.88"/></prod><prod name="ClamAV" vendor="Clam Anti-Virus"><vers num="0.90.1" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" CVSS_score="9.3" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2008-02-22" name="CVE-2007-1747" published="2007-05-08" seq="2007-1747" severity="High" type="CVE"><desc><descript source="cve">Unspecified vulnerability in MSO.dll in Microsoft Office 2000 SP3, 2002 SP3, 2003 SP2, 2004 for Mac, and 2007 allows user-assisted remote attackers to execute arbitrary code via a malformed drawing object, which triggers memory corruption.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref patch="1" source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms07-025.mspx">MS07-025</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/853184">VU#853184</ref><ref source="BID" url="http://www.securityfocus.com/bid/23826">23826</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1710">ADV-2007-1710</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1018014">1018014</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/25178">25178</ref><ref source="HP" url="http://www.securityfocus.com/archive/1/archive/1/468871/100/200/threaded">HPSBST02214</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA07-128A.html">TA07-128A</ref><ref source="OSVDB" url="http://www.osvdb.org/34396">34396</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2051">oval:org.mitre.oval:def:2051</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33908">office-drawing-code-execution(33908)</ref></refs><vuln_soft><prod name="Office" vendor="Microsoft"><vers edition="Mac" num="2004"/><vers num="2000 SP3"/><vers num="XP SP3"/><vers num="2003 SP2"/><vers num="2007"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-08-02" name="CVE-2007-1748" published="2007-04-13" seq="2007-1748" severity="High" type="CVE"><desc><descript source="cve">Stack-based buffer overflow in the RPC interface in the Domain Name System (DNS) Server Service in Microsoft Windows 2000 Server SP 4, Server 2003 SP 1, and Server 2003 SP 2 allows remote attackers to execute arbitrary code via a long zone name containing character constants represented by escape sequences.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref source="" url="http://blogs.technet.com/msrc/archive/2007/04/12/microsoft-security-advisory-935964-posted.aspx"></ref><ref adv="1" source="" url="http://www.microsoft.com/technet/security/advisory/935964.mspx"></ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/555920">VU#555920</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24871">24871</ref><ref source="" url="http://metasploit.com/svn/framework3/trunk/modules/exploits/windows/dcerpc/msdns_zonename.rb"></ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA07-103A.html">TA07-103A</ref><ref source="BID" url="http://www.securityfocus.com/bid/23470">23470</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1366">ADV-2007-1366</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017910">1017910</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33629">win-dns-rpc-bo(33629)</ref><ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms07-029.mspx">MS07-029</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/465863/100/100/threaded">20070415 Re: [exploits] RPC vuln in DNS Server (fwd)</ref><ref source="HP" url="http://www.securityfocus.com/archive/1/archive/1/468871/100/200/threaded">HPSBST02214</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA07-128A.html">TA07-128A</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1228">oval:org.mitre.oval:def:1228</ref></refs><vuln_soft><prod name="Windows Server 2003" vendor="Microsoft"><vers num="SP1"/><vers num="SP2"/><vers edition="Itanium" num="SP1"/><vers edition="Itanium" num="SP2"/><vers edition="x64" num="SP1"/><vers edition="x64" num="SP2"/></prod><prod name="Windows Server 2000" vendor="Microsoft"><vers num="SP4"/></prod></vuln_soft></entry><entry CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" CVSS_score="9.3" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-08-16" name="CVE-2007-1749" published="2007-08-14" seq="2007-1749" severity="High" type="CVE"><desc><descript source="cve">Integer underflow in the CDownloadSink class code in the Vector Markup Language (VML) component (VGX.DLL), as used in Internet Explorer 5.01, 6, and 7 allows remote attackers to execute arbitrary code via compressed content with an invalid buffer size, which triggers a heap-based buffer overflow.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/><user_init/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/476498/100/0/threaded">20070814 EEYE: VGX.DLL Compressed Content Heap Overflow Vulnerability</ref><ref source="" url="http://research.eeye.com/html/advisories/published/AD20070814a.html"></ref><ref patch="1" source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms07-050.mspx">MS07-050</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/468800">VU#468800</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/25310">25310</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1018568">1018568</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/26409">26409</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA07-226A.html">TA07-226A</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/2874">ADV-2007-2874</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1784">oval:org.mitre.oval:def:1784</ref><ref source="SREASON" url="http://securityreason.com/securityalert/3020">3020</ref></refs><vuln_soft><prod name="Internet Explorer" vendor="Microsoft"><vers num="5.01"/><vers num="6"/><vers num="7"/></prod></vuln_soft></entry><entry CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" CVSS_score="9.3" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-06-14" name="CVE-2007-1750" published="2007-06-12" seq="2007-1750" severity="High" type="CVE"><desc><descript source="cve">Unspecified vulnerability in Microsoft Internet Explorer 6 allows remote attackers to execute arbitrary code via a crafted Cascading Style Sheets (CSS) tag that triggers memory corruption.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input bound="1"/><exception/></vuln_types><range><network/><user_init/></range><refs><ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms07-033.mspx">MS07-033</ref><ref source="HP" url="http://www.securityfocus.com/archive/1/archive/1/471947/100/0/threaded">HPSBST02231</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA07-163A.html">TA07-163A</ref><ref source="BID" url="http://www.securityfocus.com/bid/24423">24423</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/2153">ADV-2007-2153</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1396">oval:org.mitre.oval:def:1396</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1018235">1018235</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25627">25627</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/34619">ie-css-tag-code-execution(34619)</ref></refs><vuln_soft><prod name="Internet Explorer" vendor="Microsoft"><vers num="5.01 SP4"/><vers num="6 SP1"/><vers num="6"/><vers num="7.0"/><vers num="6"/><vers num="7.0"/><vers num="7.0"/></prod></vuln_soft></entry><entry CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" CVSS_score="9.3" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-12-27" name="CVE-2007-1751" published="2007-06-12" seq="2007-1751" severity="High" type="CVE"><desc><descript source="cve">Microsoft Internet Explorer 5.01, 6, and 7 allows remote attackers to execute arbitrary code by causing Internet Explorer to access an uninitialized or deleted object, related to prototype variables and table cells, aka &quot;Uninitialized Memory Corruption Vulnerability.&quot;</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input bound="1"/><exception/></vuln_types><range><network/><user_init/></range><refs><ref patch="1" source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms07-033.mspx">MS07-033</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/471210/100/0/threaded">20070612 ZDI-07-038: Microsoft Internet Explorer Prototype Dereference Code Execution Vulnerability</ref><ref source="" url="http://www.zerodayinitiative.com/advisories/ZDI-07-038.html"></ref><ref source="HP" url="http://www.securityfocus.com/archive/1/archive/1/471947/100/0/threaded">HPSBST02231</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA07-163A.html">TA07-163A</ref><ref source="BID" url="http://www.securityfocus.com/bid/24418">24418</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/2153">ADV-2007-2153</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1978">oval:org.mitre.oval:def:1978</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1018235">1018235</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/25627">25627</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/34626">ie-uninitialized-object-code-execution(34626)</ref></refs><vuln_soft><prod name="Internet Explorer" vendor="Microsoft"><vers num="5.01 SP4"/><vers num="6 SP1"/><vers num="6"/><vers num="7.0"/><vers num="6"/><vers num="7.0"/><vers num="7.0"/></prod></vuln_soft></entry><entry CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" CVSS_score="9.3" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-12-12" name="CVE-2007-1752" published="2007-06-12" reject="1" seq="2007-1752" severity="High" type="CVE"><desc><descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2007-1499.  Reason: This candidate is a duplicate of CVE-2007-1499.  Notes: All CVE users should reference CVE-2007-1499 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input bound="1"/><exception/></vuln_types><range><network/><user_init/></range><refs/></entry><entry CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" CVSS_score="9.3" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-12-21" name="CVE-2007-1754" published="2007-07-10" seq="2007-1754" severity="High" type="CVE"><desc><descript source="cve">PUBCONV.DLL in Microsoft Office Publisher 2007 does not properly clear memory when transferring data from disk to memory, which allows user-assisted remote attackers to execute arbitrary code via a malformed .pub page via a certain negative value, which bypasses a sanitization procedure that initializes critical pointers to NULL, aka the &quot;Publisher Invalid Memory Reference Vulnerability&quot;.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/><exception/></vuln_types><range><network/><user_init/></range><refs><ref source="MS" url="http://www.microsoft.com/technet/security/Bulletin/ms07-037.mspx">MS07-037</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/473309/100/0/threaded">20070710 EEYE: Microsoft Publisher 2007 Arbitrary Pointer Dereference</ref><ref source="" url="http://research.eeye.com/html/advisories/published/AD20070710.html"></ref><ref source="HP" url="http://archive.cert.uni-stuttgart.de/bugtraq/2007/07/msg00254.html">SSRT071446</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA07-191A.html">TA07-191A</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/2479">ADV-2007-2479</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1871">oval:org.mitre.oval:def:1871</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1018353">1018353</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/25988">25988</ref></refs><vuln_soft><prod name="Publisher" vendor="Microsoft"><vers num="2007"/></prod></vuln_soft></entry><entry CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" CVSS_score="9.3" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-07-13" name="CVE-2007-1756" published="2007-07-10" seq="2007-1756" severity="High" type="CVE"><desc><descript source="cve">Microsoft Excel 2000 SP3, 2002 SP3, 2003 SP2, 2003 Viewer, and Office Excel 2007 does not properly validate version information, which allows user-assisted remote attackers to execute arbitrary code via a crafted Excel file, aka &quot;Calculation Error Vulnerability&quot;.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" patch="1" source="MS" url="http://www.microsoft.com/technet/security/Bulletin/ms07-036.mspx">MS07-036</ref><ref source="HP" url="http://archive.cert.uni-stuttgart.de/bugtraq/2007/07/msg00254.html">SSRT071446</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA07-191A.html">TA07-191A</ref><ref source="BID" url="http://www.securityfocus.com/bid/24801">24801</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/2478">ADV-2007-2478</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2123">oval:org.mitre.oval:def:2123</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1018352">1018352</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25995">25995</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/35210">excel-version-code-execution(35210)</ref></refs><vuln_soft><prod name="Office" vendor="Microsoft"><vers num="2000 SP3"/><vers num="2002 SP3"/><vers num="2003 SP2"/><vers num="2003 Viewer"/><vers num="2007"/></prod><prod name="Excel" vendor="Microsoft"><vers num="2000 sp3"/><vers num="2002 sp3"/><vers num="2003 sp2"/><vers num="2003 Viewer"/><vers num="2007"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" modified="2007-03-31" name="CVE-2007-1762" published="2007-03-29" seq="2007-1762" severity="Medium" type="CVE"><desc><descript source="cve">Mozilla Firefox 2.0.0.1 through 2.0.0.3 does not canonicalize URLs before checking them against the phishing site blacklist, which allows remote attackers to bypass phishing protection via multiple / (slash) characters in the URL.</descript></desc><loss_types><int/></loss_types><vuln_types><input/><design/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/464149/100/0/threaded">20070329 Re: Bypass phishing protection in Firefox / Opera</ref></refs><vuln_soft><prod name="Firefox" vendor="Mozilla"><vers num="2.0.0.1"/><vers num="2.0.0.2"/><vers num="2.0.0.3"/></prod></vuln_soft></entry><entry CVSS_base_score="7.1" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.9" CVSS_score="7.1" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:C)" CVSS_version="2.0" modified="2007-04-02" name="CVE-2007-1763" published="2007-03-29" seq="2007-1763" severity="High" type="CVE"><desc><descript source="cve">The ATI kernel driver (atikmdag.sys) in Microsoft Windows Vista allows user-assisted remote attackers to cause a denial of service (crash) via a crafted JPG image, as demonstrated by a slideshow, possibly due to a buffer overflow.</descript></desc><loss_types><avail/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/><user_init/></range><refs><ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2007-q1/0077.html">20070325 Microsoft Windows Vista Slideshow Unspecified Blue Screen Of Death Vulnerability</ref><ref source="" url="http://securityvulns.com/news/Microsoft/Vista/ATI.html"></ref><ref source="" url="http://leovilletownsquare.com/fusionbb/showtopic.php?fid/27/tid/17600/"></ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1160">
ADV-2007-1160</ref><ref source="OSVDB" url="http://www.osvdb.org/33635">
33635</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24667">
24667</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33300">
windows-atikmdag-dos(33300)</ref></refs><vuln_soft><prod name="Windows Vista" vendor="Microsoft"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="6.0" CVSS_exploit_subscore="6.8" CVSS_impact_subscore="6.4" CVSS_score="6.0" CVSS_vector="(AV:N/AC:M/Au:S/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-04-02" name="CVE-2007-1764" published="2007-03-29" seq="2007-1764" severity="Medium" type="CVE"><desc><descript source="cve">Stack-based buffer overflow in FastStone Image Viewer 2.8 allows user-assisted remote attackers to execute arbitrary code via a crafted JPG image.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/><user_init/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/464148/100/0/threaded">20070329 Re: [VulnWatch] Microsoft Windows Vista Slideshow Unspecified Blue Screen Of Death Vulnerability</ref><ref source="BID" url="http://www.securityfocus.com/bid/23196">
23196</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2510">2510</ref></refs><vuln_soft><prod name="Image Viewer" vendor="FastStone"><vers num="2.8"/></prod></vuln_soft></entry><entry CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" CVSS_score="9.3" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-04-05" name="CVE-2007-1765" published="2007-03-29" seq="2007-1765" severity="High" type="CVE"><desc><descript source="cve">Unspecified vulnerability in Microsoft Windows 2000 SP4 through Vista allows remote attackers to execute arbitrary code or cause a denial of service (persistent reboot) via a malformed ANI file, which results in memory corruption when processing cursors, animated cursors, and icons, a similar issue to CVE-2005-0416, as originally demonstrated using Internet Explorer 6 and 7.  NOTE: this issue might be a duplicate of CVE-2007-0038; if so, then use CVE-2007-0038 instead of this identifier.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref source="" url="http://vil.nai.com/vil/content/v_141860.htm"></ref><ref source="" url="http://www.avertlabs.com/research/blog/?p=230"></ref><ref source="" url="http://www.avertlabs.com/research/blog/?p=233"></ref><ref adv="1" source="MICROSOFT" url="http://www.microsoft.com/technet/security/advisory/935423.mspx">935423</ref><ref source="BID" url="http://www.securityfocus.com/bid/23194">23194</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1151">ADV-2007-1151</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017827">1017827</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/464287/100/0/threaded">

20070330 ANI Zeroday, Third Party Patch</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/464345/100/0/threaded">
20070331 Windows .ANI Stack Overflow Exploit</ref><ref source="" url="http://asert.arbornetworks.com/2007/03/any-ani-file-could-infect-you/"></ref><ref source="" url="http://research.eeye.com/html/alerts/zeroday/20070328.html"></ref></refs><vuln_soft><prod name="S8100 Media Servers" vendor="Avaya"><vers num="" prev="1"/></prod><prod name="Internet Explorer" vendor="Microsoft"><vers num="6" prev="1"/><vers edition="Vista" num="7.0"/></prod><prod name="S3400 Message Application Server" vendor="Avaya"><vers num="" prev="1"/></prod><prod name="DefinityOne Media Servers" vendor="Avaya"><vers num="" prev="1"/></prod><prod name="Windows Server 2003" vendor="Microsoft"><vers num="Datacenter" prev="1"/><vers num="Enterprise" prev="1"/><vers num="Standard" prev="1"/><vers num="Web Edition" prev="1"/></prod><prod name="IP600 Media Servers" vendor="Avaya"><vers num="" prev="1"/></prod><prod name="Windows Vista" vendor="Microsoft"><vers num="Beta" prev="1"/><vers num="Beta 1" prev="1"/><vers num="Beta 2" prev="1"/><vers num="Business" prev="1"/><vers num="December CTP" prev="1"/><vers num="Enterprise" prev="1"/><vers num="Home Basic" prev="1"/><vers num="Home Premium" prev="1"/><vers edition="32 bit" num="Ultimate" prev="1"/></prod><prod name="Windows XP" vendor="Microsoft"><vers edition="SP2" num="Home"/><vers edition="SP2" num="Media Center"/><vers edition="SP2" num="Professional"/><vers edition="SP2" num="Tablet PC"/></prod><prod name="Windows 2000" vendor="Microsoft"><vers num="Server Japanese Edition"/><vers num="Server SP4" prev="1"/><vers num="Advanced Server"/><vers num="Advanced Server SP1"/><vers num="Advanced Server SP2"/><vers num="Advanced Server SP3"/><vers num="Advanced Server SP4"/><vers num="Datacenter Server"/><vers num="Datacenter Server SP1"/><vers num="Datacenter Server SP2"/><vers num="Datacenter Server SP3"/><vers num="Datacenter Server SP4"/><vers num="Professional"/><vers num="Professional SP1"/><vers num="Professional SP2"/><vers num="Professional SP3"/><vers num="Professional SP4"/><vers num="Server SP1"/><vers num="Server SP2"/><vers num="Server SP3"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-04-02" name="CVE-2007-1766" published="2007-03-29" seq="2007-1766" severity="High" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in login/engine/db/profiledit.php in Advanced Login 0.76 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the root parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/464147/100/0/threaded">20070329 Advanced Login &lt;= 0.7 (root) Remote File Inclusion Vulnerability</ref><ref source="MILW0RM" url="http://milw0rm.com/exploits/3608">
3608</ref><ref source="BID" url="http://www.securityfocus.com/bid/23197">
23197</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24695">
24695</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1179">
ADV-2007-1179</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33321">
advanced-profiledit-file-include(33321)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2508">2508</ref></refs><vuln_soft><prod name="Advanced Login" vendor="MsxStudios"><vers num="0.76" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.8" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.9" CVSS_score="7.8" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_version="2.0" modified="2007-04-02" name="CVE-2007-1767" published="2007-03-29" seq="2007-1767" severity="High" type="CVE"><desc><descript source="cve">Unspecified vulnerability in (1) Deskbar.dll and (2) Toolbar.dll in AOL 9.0 before February 2007 allows remote attackers to cause a denial of service (browser crash) via unknown vectors.</descript></desc><loss_types><avail/></loss_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2007-03/0392.html">20070329 AOL 9.0 Deskbar.dll/Toolbar.dll DoS Vulnerability</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33309">
aol-deskbar-toolbar-dos(33309)</ref></refs><vuln_soft><prod name="AOL Client Software" vendor="AOL"><vers num="9.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" modified="2007-03-31" name="CVE-2007-1768" published="2007-03-29" seq="2007-1768" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in app/helpers/application_helper.rb in Mephisto 0.7.3 and Mephisto Edge 20070325 allows remote attackers to inject arbitrary web script or HTML via the author name field in a comment.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/463825/100/0/threaded">20070325 Mephisto blog is vulnerable to XSS</ref><ref source="BID" url="http://www.securityfocus.com/bid/23137">23137</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33230">mephisto-authorname-xss(33230)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2490">2490</ref></refs><vuln_soft><prod name="Mephisto Edge" vendor="Mephisto"><vers num="2007-03-25"/></prod><prod name="Mephisto" vendor="Mephisto"><vers num="0.7.3"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" modified="2007-12-12" name="CVE-2007-1769" published="2007-03-29" reject="1" seq="2007-1769" severity="Medium" type="CVE"><desc><descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2007-1873.  Reason: This candidate is a duplicate of CVE-2007-1873.  Notes: All CVE users should reference CVE-2007-1873 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs/></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-04-13" name="CVE-2007-1770" published="2007-03-29" seq="2007-1770" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in the ArcSDE service (giomgr) in Environmental Systems Research Institute (ESRI) ArcGIS before 9.2 Service Pack 2, when using three tiered ArcSDE configurations, allows remote attackers to cause a denial of service (giomgr crash) and execute arbitrary code via long parameters in crafted requests.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref source="" url="http://support.esri.com/index.cfm?fa=downloads.patchesServicePacks.viewPatch&amp;PID=19&amp;MetaID=1260"></ref><ref source="" url="http://support.esri.com/index.cfm?fa=downloads.patchesServicePacks.viewPatch&amp;PID=19&amp;MetaID=1261"></ref><ref source="" url="http://support.esri.com/index.cfm?fa=downloads.patchesServicePacks.viewPatch&amp;PID=19&amp;MetaID=1262"></ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24639">24639</ref><ref source="BID" url="http://www.securityfocus.com/bid/23175">23175</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1140">ADV-2007-1140</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33282">arcsde-three-tiered-dos(33282)</ref><ref source="IDEFENSE" url="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=507">20070404 ESRI ArcSDE Buffer Overflow Vulnerability</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017874">1017874</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33457">arcsde-tcpport-bo(33457)</ref></refs><vuln_soft><prod name="ArcGIS" vendor="ESRI"><vers num="9.2 SP 1" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" CVSS_score="9.3" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-03-31" name="CVE-2007-1771" published="2007-03-29" seq="2007-1771" severity="High" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in manage/javascript/formjavascript.php in Ay System Solutions Web Content System (WCS) 2.7.1 allows remote attackers to execute arbitrary PHP code via a URL in the path[JavascriptEdit] parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3592">3592</ref><ref source="BID" url="http://www.securityfocus.com/bid/23171">23171</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24663">24663</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1139">
ADV-2007-1139</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33281">
wcs-formjavascript-file-include(33281)</ref></refs><vuln_soft><prod name="Web Content System" vendor="Ay System Solutions"><vers num="2.7.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.1" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.9" CVSS_score="7.1" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:C)" CVSS_version="2.0" modified="2007-03-31" name="CVE-2007-1772" published="2007-03-29" seq="2007-1772" severity="High" type="CVE"><desc><descript source="cve">The FTP service in HP JetDirect print servers allows remote attackers to cause a denial of service (engine crash) via a RETR command with a long pathname.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref source="FULLDISC" url="http://marc.info/?l=full-disclosure&amp;m=117502315312302&amp;w=2">20070327 Remote DOS HP JetDirect Print Servers</ref><ref source="BID" url="http://www.securityfocus.com/bid/23168">23168</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33273">
hp-jetdirect-rert-dos(33273)</ref></refs><vuln_soft><prod name="JetDirect" vendor="HP"><vers num="" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="2.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="2.9" CVSS_score="2.6" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:N/A:N)" CVSS_version="2.0" modified="2007-04-13" name="CVE-2007-1773" published="2007-03-29" seq="2007-1773" severity="Low" type="CVE"><desc><descript source="cve">Multiple directory traversal vulnerabilities in aBitWhizzy allow remote attackers to list arbitrary directories via a .. (dot dot) in the d parameter to (1) whizzery/whizzypic.php or (2) whizzery/whizzylink.php, different vectors than CVE-2006-6384.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref source="" url="http://downloads.securityfocus.com/vulnerabilities/exploits/23167.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/23167">23167</ref><ref source="" url="http://lostmon.blogspot.com/2007/03/abitwhizzy-traversal-folder-enumeration.html"></ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1136">ADV-2007-1136</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24679">24679</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33277">abitwhizzy-multiple-directory-traversal(33277)</ref><ref source="OSVDB" url="http://www.osvdb.org/34505">34505</ref><ref source="OSVDB" url="http://www.osvdb.org/34506">34506</ref></refs><vuln_soft><prod name="aBitWhizzy" vendor="unverse.net"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" modified="2007-04-13" name="CVE-2007-1774" published="2007-03-29" seq="2007-1774" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in aBitWhizzy allow remote attackers to inject arbitrary web script or HTML via the d parameter to (1) whizzery/whizzypic.php or (2) whizzery/whizzylink.php.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref source="" url="http://downloads.securityfocus.com/vulnerabilities/exploits/23167.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/23167">23167</ref><ref source="" url="http://lostmon.blogspot.com/2007/03/abitwhizzy-traversal-folder-enumeration.html"></ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1136">ADV-2007-1136</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24679">24679</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33279">abitwhizzy-multiple-xss(33279)</ref><ref source="OSVDB" url="http://www.osvdb.org/34507">34507</ref><ref source="OSVDB" url="http://www.osvdb.org/34508">34508</ref></refs><vuln_soft><prod name="aBitWhizzy" vendor="unverse.net"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-03-31" name="CVE-2007-1775" published="2007-03-29" seq="2007-1775" severity="Medium" type="CVE"><desc><descript source="cve">Unrestricted file upload vulnerability in upload.php3 in JBrowser 2.4 and earlier allows remote attackers to upload and execute arbitrary PHP code via unspecified vectors.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BID" url="http://www.securityfocus.com/bid/23166">23166</ref></refs><vuln_soft><prod name="JBrowser" vendor="JBrowser"><vers num="2.4" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-04-10" name="CVE-2007-1776" published="2007-03-29" seq="2007-1776" severity="Medium" type="CVE"><desc><descript source="cve">SQL injection vulnerability in index.php in the DesignForJoomla.com D4J eZine (com_ezine) 2.8 and earlier component for Joomla! allows remote attackers to execute arbitrary SQL commands via the article parameter in a read action.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3590">3590</ref><ref source="BID" url="http://www.securityfocus.com/bid/23165">23165</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1135">ADV-2007-1135</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24675">24675</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33249">d4jezine-index-sql-injection(33249)</ref></refs><vuln_soft><prod name="D4J eZine" vendor="Design for Joomla"><vers num="2.8" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-03-31" name="CVE-2007-1777" published="2007-03-29" seq="2007-1777" severity="High" type="CVE"><desc><descript source="cve">Integer overflow in the zip_read_entry function in PHP 4 before 4.4.5 allows remote attackers to execute arbitrary code via a ZIP archive that contains an entry with a length value of 0xffffffff, which is incremented before use in an emalloc call, triggering a heap overflow.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="" url="http://www.php-security.org/MOPB/MOPB-35-2007.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/23169">23169</ref><ref source="DEBIAN" url="http://www.debian.org/security/2007/dsa-1282">
DSA-1282</ref><ref source="DEBIAN" url="http://www.debian.org/security/2007/dsa-1283">
DSA-1283</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25025">
25025</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25062">
25062</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDVSA-2008:130">MDVSA-2008:130</ref></refs><vuln_soft><prod name="PHP" vendor="PHP"><vers num="3.0"/><vers num="3.0.1"/><vers num="3.0.10"/><vers num="3.0.11"/><vers num="3.0.12"/><vers num="3.0.13"/><vers num="3.0.14"/><vers num="3.0.15"/><vers num="3.0.16"/><vers num="3.0.17"/><vers num="3.0.18"/><vers num="3.0.2"/><vers num="3.0.3"/><vers num="3.0.4"/><vers num="3.0.5"/><vers num="3.0.6"/><vers num="3.0.7"/><vers num="3.0.8"/><vers num="3.0.9"/><vers num="4.0.0"/><vers num="4.0.1"/><vers num="4.0.1 pl1"/><vers num="4.0.1 pl2"/><vers num="4.0.2"/><vers num="4.0.3"/><vers num="4.0.3 pl1"/><vers num="4.0.4"/><vers num="4.0.4 pl1"/><vers num="4.0.5"/><vers num="4.0.6"/><vers num="4.0.7"/><vers num="4.0.7 RC1"/><vers num="4.0.7 RC2"/><vers num="4.0.7 RC3"/><vers num="4.1.0"/><vers num="4.1.1"/><vers num="4.1.2"/><vers edition="Dev" num="4.2"/><vers num="4.2.0"/><vers num="4.2.1"/><vers num="4.2.2"/><vers num="4.2.3"/><vers num="4.3"/><vers num="4.3.1"/><vers num="4.3.10"/><vers num="4.3.11"/><vers num="4.3.2"/><vers num="4.3.3"/><vers num="4.3.4"/><vers num="4.3.5"/><vers num="4.3.6"/><vers num="4.3.7"/><vers num="4.3.8"/><vers num="4.3.9"/><vers num="4.4.0"/><vers num="4.4.1"/><vers num="4.4.2"/><vers num="4.4.3"/><vers num="4.4.4"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-03-31" name="CVE-2007-1778" published="2007-03-29" seq="2007-1778" severity="High" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in db/mysql.php in the Eve-Nuke 0.1 (EN-Forums) module for PHP-Nuke allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3591">3591</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1138">ADV-2007-1138</ref><ref source="BID" url="http://www.securityfocus.com/bid/23176">
23176</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33285">
evenuke-mysql-file-include(33285)</ref></refs><vuln_soft><prod name="Eve-Nuke Forum" vendor="Eve-Nuke"><vers num="0.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-03-31" name="CVE-2007-1779" published="2007-03-29" seq="2007-1779" severity="High" type="CVE"><desc><descript source="cve">Multiple SQL injection vulnerabilities in the MySQL back-end in Advanced Website Creator (AWC) before 1.9.0 might allow remote attackers to execute arbitrary SQL commands via unspecified parameters, related to use of mysql_escape_string instead of mysql_real_escape_string.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://forums.awcreator.com/viewtopic.php?t=45"></ref><ref source="BID" url="http://www.securityfocus.com/bid/23268">
23268</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24685">
24685</ref></refs><vuln_soft><prod name="Advanced Website Creator" vendor="Advanced Website Creator"><vers num="0.1"/><vers num="0.2"/><vers num="0.3"/><vers num="1.0 BETA 1"/><vers num="1.1 BETA 1"/><vers num="1.2"/><vers num="1.3"/><vers num="1.4.1"/><vers num="1.4.2"/><vers num="1.5.0"/><vers num="1.6.0"/><vers num="1.6.1"/><vers num="1.7.0"/><vers num="1.8.0"/><vers num="1.8.1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" modified="2007-03-31" name="CVE-2007-1780" published="2007-03-30" seq="2007-1780" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in the DHT shell (owdhtshell) in Overlay Weaver 0.5.9 to 0.5.11, when invoked with the -x option, allows remote attackers to inject arbitrary web script or HTML via fields in certain input forms.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref source="" url="http://overlayweaver.sourceforge.net/news/"></ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24669">24669</ref><ref source="" url="http://jvn.jp/jp/JVN%2362399483/index.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/23195">
23195</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1167">
ADV-2007-1167</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33340">
overlay-weaver-owdhtshell-xss(33340)</ref></refs><vuln_soft><prod name="Overlay Weaver" vendor="Overlay Weaver"><vers num="0.5.10"/><vers num="0.5.11"/><vers num="0.5.9"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-03-31" name="CVE-2007-1781" published="2007-03-30" seq="2007-1781" severity="Medium" type="CVE"><desc><descript source="cve">Minna De Office 1.x and 2.x does not properly restrict user access to certain privileged actions, which allows local users to change the configuration or have other unspecified impact.  NOTE: some of these details are obtained from third party information.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref source="" url="http://jvn.jp/jp/JVN%2373258608/index.html"></ref><ref source="" url="http://www.aisantec.co.jp/mof/index.html"></ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24691">24691</ref><ref source="BID" url="http://www.securityfocus.com/bid/23198">
23198</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1162">
ADV-2007-1162</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33341">
aisan-unspecified-privilege-escalation(33341)</ref></refs><vuln_soft><prod name="Minna De Office" vendor="Minna De Office"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-03-31" name="CVE-2007-1782" published="2007-03-30" seq="2007-1782" severity="Medium" type="CVE"><desc><descript source="cve">CruiseWorks 1.09e and earlier does not properly restrict user access to certain privileged actions, which allows local users to change the configuration or have other unspecified impact.  NOTE: some of these details are obtained from third party information.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref source="" url="http://jvn.jp/jp/JVN%2373258608/index.html"></ref><ref source="" url="http://www.kynos.co.jp/cws-support/index.html"></ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24674">24674</ref><ref source="BID" url="http://www.securityfocus.com/bid/23198">
23198</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1163">
ADV-2007-1163</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33323">
cruiseworks-security-bypass(33323)</ref></refs><vuln_soft><prod name="CruiseWorks" vendor="CruiseWorks"><vers num="1.09e" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" CVSS_score="9.3" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-04-03" name="CVE-2007-1784" published="2007-03-30" seq="2007-1784" severity="High" type="CVE"><desc><descript source="cve">The JNILoader ActiveX control (STJNILoader.ocx) 3.1.0.26 in IBM Lotus Notes Sametime before 7.5 allows remote attackers to load arbitrary DLL libraries and execute arbitrary code via arbitrary arguments to the loadLibrary function.</descript></desc><sols><sol source="nvd">This vulnerability is addressed in the following product advisory: 
http://www-1.ibm.com/support/docview.wss?uid=swg21257029  </sol></sols><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref source="IDEFENSE" url="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=495">20070329 IBM Lotus Sametime JNILoader Arbitrary DLL Load Vulnerability</ref><ref adv="1" source="" url="http://www-1.ibm.com/support/docview.wss?uid=swg21257029"></ref><ref source="BID" url="http://www.securityfocus.com/bid/23201">23201</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017828">1017828</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33314">
sametime-stjniloader-code-execution(33314)</ref></refs><vuln_soft><prod name="Lotus Notes Sametime STJNILoader.ocx" vendor="IBM"><vers num="3.1.26"/></prod><prod name="Lotus Notes Sametime" vendor="IBM"><vers num="7.0" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.1" CVSS_vector="(AV:N/AC:H/Au:S/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-04-03" name="CVE-2007-1785" published="2007-03-30" seq="2007-1785" severity="High" type="CVE"><desc><descript source="cve">The RPC service in mediasvr.exe in CA BrightStor ARCserve Backup 11.5 SP2 build 4237 allows remote attackers to execute arbitrary code via crafted xdr_handle_t data in RPC packets, which is used in calculating an address for a function call, as demonstrated using the 191 (0xbf) RPC request.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/464270/100/0/threaded">20070330 CA Brightstor Backup Mediasvr.exe Remote Code Vulnerability</ref><ref source="" url="http://www.shirkdog.us/camediasvrremote.py"></ref><ref source="" url="http://www.shirkdog.us/shk-004.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/23209">23209</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1161">ADV-2007-1161</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24682">24682</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/464343/100/0/threaded">
20070331 CA BrightStor ARCserve Backup Mediasvr.exe vulnerability</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/151305">
VU#151305</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017830">
1017830</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33316">
brightstor-mediasvr-code-execution(33316)</ref><ref source="" url="http://supportconnectw.ca.com/public/storage/infodocs/babmedser-secnotice.asp"></ref><ref source="SREASON" url="http://securityreason.com/securityalert/2509">2509</ref></refs><vuln_soft><prod name="BrightStor ARCServe Backup" vendor="Computer Associates"><vers num="11.1"/><vers num="11.5"/><vers num="11.5 SP1"/><vers num="11.5 SP2"/><vers num="9.01"/><vers edition="Windows" num="11.0"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-04-03" name="CVE-2007-1786" published="2007-03-31" seq="2007-1786" severity="Medium" type="CVE"><desc><descript source="cve">SQL injection vulnerability in Hitachi Collaboration - Online Community Management 01-00 through 01-30, as used in Groupmax Collaboration Portal, Groupmax Collaboration Web Client, uCosminexus Collaboration Portal, Cosminexus Collaboration Portal, and uCosminexus Content Manager, allows remote attackers to execute arbitrary SQL commands via unspecified vectors.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="" url="http://www.hitachi-support.com/security_e/vuls_e/HS07-008_e/index-e.html"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1168">ADV-2007-1168</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24693">24693</ref><ref source="BID" url="http://www.securityfocus.com/bid/23208">
23208</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33348">
hitachi-collaboration-sql-injection(33348)</ref></refs><vuln_soft><prod name="uCosminexus Content Manager" vendor="Hitachi"><vers num=""/></prod><prod name="Cosminexus Collaboration Portal" vendor="Hitachi"><vers num=""/></prod><prod name="Groupmax Collaboration Portal" vendor="Hitachi"><vers num=""/></prod><prod name="Groupmax Collaboration Web Client" vendor="Hitachi"><vers num=""/></prod><prod name="uCosminexus Collaboration Portal" vendor="Hitachi"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" CVSS_score="9.3" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-04-03" name="CVE-2007-1787" published="2007-03-31" seq="2007-1787" severity="High" type="CVE"><desc><descript source="cve">Multiple PHP remote file inclusion vulnerabilities in lib/timesheet.class.php in Softerra Time-Assistant 6.2 and earlier, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the (1) inc_dir or (2) lib_dir parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3600">3600</ref><ref adv="1" source="" url="http://advisories.echo.or.id/adv/adv80-K-159-2007.txt"></ref><ref source="BID" url="http://www.securityfocus.com/bid/23203">23203</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/464281/100/0/threaded">

20070330 [ECHO_ADV_80$2007] Softerra Time-Assistant &lt;= 6.2 (inc_dir) Remote File Inclusion Vulnerability</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33327">
softerra-timesheetclass-file-include(33327)</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1193">
ADV-2007-1193</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24729">
24729</ref></refs><vuln_soft><prod name="Time-Assistant" vendor="Softerra"><vers num="6.2" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-04-03" name="CVE-2007-1788" published="2007-03-31" seq="2007-1788" severity="Medium" type="CVE"><desc><descript source="cve">Flyspray 0.9.9, when output_buffering is disabled or &quot;set to a low value,&quot; allows remote attackers to bypass authentication via a crafted post request.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/><input/></vuln_types><range><network/></range><refs><ref source="" url="http://www.flyspray.org/fsa:1"></ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24702">24702</ref><ref source="BID" url="http://www.securityfocus.com/bid/23214">
23214</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1181">
ADV-2007-1181</ref></refs><vuln_soft><prod name="Flyspray" vendor="Flyspray"><vers num="0.9.9"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-04-03" name="CVE-2007-1789" published="2007-03-31" seq="2007-1789" severity="Medium" type="CVE"><desc><descript source="cve">Flyspray 0.9.9 allows remote attackers to obtain sensitive information (private project summaries) via direct requests.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref source="" url="http://www.flyspray.org/changelog"></ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24702">24702</ref><ref source="BID" url="http://www.securityfocus.com/bid/23214">
23214</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1181">
ADV-2007-1181</ref></refs><vuln_soft><prod name="Flyspray" vendor="Flyspray"><vers num="0.9.9"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-04-10" name="CVE-2007-1790" published="2007-03-31" seq="2007-1790" severity="Medium" type="CVE"><desc><descript source="cve">Multiple PHP remote file inclusion vulnerabilities in Kaqoo Auction Software Free Edition allow remote attackers to execute arbitrary PHP code via a URL in the install_root parameter to (1) support.inc.php, (2) function.inc.php, (3) rdal_object.inc.php, (4) rdal_editor.inc.php. (5) login.inc.php, (6) request.inc.php, and (7) categories.inc.php in include/core/; (8) save.inc.php, (9) preview.inc.php, (10) edit_item.inc.php, (11) new_item.inc.php, and (12) item_info.inc.php in include/display/item/; (13) search.inc.php, (14) item_edit.inc.php, (15) register_succsess.inc.php, (16) context_menu.inc.php, (17) item_repost.inc.php, (18) balance.inc.php, (19) featured.inc.php, (20) user.inc.php, (21) buynow.inc.php, (22) install_complete.inc.php, (23) fees_info.inc.php, (24) user_feedback.inc.php, (25) admin_balance.inc.php, (26) activate.inc.php, (27) user_info.inc.php, (28) member.inc.php, (29) add_bid.inc.php, (30) items_filter.inc.php, (31) my_info.inc.php, (32) register.inc.php, (33) leave_feedback.inc.php, and (34) user_auctions.inc.php in include/display/; and (35) design/form.inc.php, (36) processor.inc.php, (37) interfaces.inc.php (38) left_menu.inc.php, (39) login.inc.php, and (40) categories.inc.php in include/.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3607">3607</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24696">24696</ref><ref source="BID" url="http://www.securityfocus.com/bid/23211">23211</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1180">ADV-2007-1180</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33335">
kaqoo-installroot-file-include(33335)</ref><ref source="OSVDB" url="http://www.osvdb.org/34557">
34557</ref><ref source="OSVDB" url="http://www.osvdb.org/34558">
34558</ref><ref source="OSVDB" url="http://www.osvdb.org/34559">
34559</ref><ref source="OSVDB" url="http://www.osvdb.org/34561">
34561</ref><ref source="OSVDB" url="http://www.osvdb.org/34571">
34571</ref><ref source="OSVDB" url="http://www.osvdb.org/34572">
34572</ref><ref source="OSVDB" url="http://www.osvdb.org/34573">
34573</ref><ref source="OSVDB" url="http://www.osvdb.org/34574">
34574</ref><ref source="OSVDB" url="http://www.osvdb.org/34575">
34575</ref><ref source="OSVDB" url="http://www.osvdb.org/34576">
34576</ref><ref source="OSVDB" url="http://www.osvdb.org/34579">
34579</ref><ref source="OSVDB" url="http://www.osvdb.org/34580">
34580</ref><ref source="OSVDB" url="http://www.osvdb.org/34581">
34581</ref><ref source="OSVDB" url="http://www.osvdb.org/34582">
34582</ref><ref source="OSVDB" url="http://www.osvdb.org/34545">
34545</ref><ref source="OSVDB" url="http://www.osvdb.org/34546">
34546</ref><ref source="OSVDB" url="http://www.osvdb.org/34547">
34547</ref><ref source="OSVDB" url="http://www.osvdb.org/34548">
34548</ref><ref source="OSVDB" url="http://www.osvdb.org/34549">
34549</ref><ref source="OSVDB" url="http://www.osvdb.org/34550">
34550</ref><ref source="OSVDB" url="http://www.osvdb.org/34551">
34551</ref><ref source="OSVDB" url="http://www.osvdb.org/34552">
34552</ref><ref source="OSVDB" url="http://www.osvdb.org/34553">
34553</ref><ref source="OSVDB" url="http://www.osvdb.org/34554">
34554</ref><ref source="OSVDB" url="http://www.osvdb.org/34555">
34555</ref><ref source="OSVDB" url="http://www.osvdb.org/34556">
34556</ref><ref source="OSVDB" url="http://www.osvdb.org/34560">
34560</ref><ref source="OSVDB" url="http://www.osvdb.org/34562">
34562</ref><ref source="OSVDB" url="http://www.osvdb.org/34563">
34563</ref><ref source="OSVDB" url="http://www.osvdb.org/34564">
34564</ref><ref source="OSVDB" url="http://www.osvdb.org/34565">
34565</ref><ref source="OSVDB" url="http://www.osvdb.org/34566">
34566</ref><ref source="OSVDB" url="http://www.osvdb.org/34567">
34567</ref><ref source="OSVDB" url="http://www.osvdb.org/34568">
34568</ref><ref source="OSVDB" url="http://www.osvdb.org/34569">
34569</ref><ref source="OSVDB" url="http://www.osvdb.org/34570">
34570</ref><ref source="OSVDB" url="http://www.osvdb.org/34577">
34577</ref><ref source="OSVDB" url="http://www.osvdb.org/34578">
34578</ref><ref source="OSVDB" url="http://www.osvdb.org/34583">
34583</ref><ref source="OSVDB" url="http://www.osvdb.org/34584">
34584</ref></refs><vuln_soft><prod name="Kaqoo Auction Software" vendor="Kaqoo"><vers edition="Free" num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-04-03" name="CVE-2007-1791" published="2007-03-31" seq="2007-1791" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in wall.php in Picture-Engine 1.2.0 and earlier allows remote attackers to execute arbitrary SQL commands via the cat parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3605">3605</ref><ref source="BID" url="http://www.securityfocus.com/bid/23205">23205</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33325">
pictureengine-wall-sql-injection(33325)</ref></refs><vuln_soft><prod name="Picture-Engine" vendor="Alexscriptengine"><vers num="1.2.0" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.8" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.9" CVSS_score="7.8" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_version="2.0" modified="2007-06-29" name="CVE-2007-1792" published="2007-06-27" seq="2007-1792" severity="High" type="CVE"><desc><descript source="cve">libdayzero.dll in the Filter Hub Service (filter-hub.exe) in Symantec Mail Security for SMTP before 5.0.1 Patch 181 and Mail Security Appliance before 5.0.0-36 allows remote attackers to cause a denial of service (crash) via a crafted executable attachment in an e-mail, involving the detection of &quot;PE-Shield v0.2&quot; and &quot;ASPack v1.00-1.08.02&quot;.</descript></desc><loss_types><avail/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="" url="http://secunia.com/secunia_research/2007-48/advisory/"></ref><ref patch="1" source="" url="http://securityresponse.symantec.com/avcenter/security/Content/2007.06.26.html"></ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/2335">ADV-2007-2335</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/24632">24632</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/472440/100/0/threaded">20070628 Secunia Research: Symantec Mail Security for SMTP Boundary Errors</ref><ref source="BID" url="http://www.securityfocus.com/bid/24625">24625</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1018301">1018301</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/35105">symantec-mailsecurity-attachment-dos(35105)</ref></refs><vuln_soft><prod name="Mail Security" vendor="Symantec"><vers edition="SMTP" num="5.0.0"/><vers edition="SMTP" num="5.0.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2008-01-02" name="CVE-2007-1793" published="2007-04-02" seq="2007-1793" severity="High" type="CVE"><desc><descript source="cve">SPBBCDrv.sys in Symantec Norton Personal Firewall 2006 9.1.0.33 and 9.1.1.7 does not validate certain arguments before being passed to hooked SSDT function handlers, which allows local users to cause a denial of service (crash) or possibly execute arbitrary code via crafted arguments to the (1) NtCreateMutant and (2) NtOpenEvent functions.  NOTE: it was later reported that Norton Internet Security 2008 15.0.0.60, and possibly other versions back to 2006, are also affected.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input/></vuln_types><range><local/></range><refs><ref adv="1" source="" url="http://www.matousec.com/info/advisories/Norton-Multiple-insufficient-argument-validation-of-hooked-SSDT-functions.php"></ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24677">24677</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/464456/100/0/threaded">20070401 Norton Multiple insufficient argument validation of hooked SSDT function Vulnerability</ref><ref source="BID" url="http://www.securityfocus.com/bid/23241">23241</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1192">ADV-2007-1192</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017837">1017837</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017838">1017838</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33352">symantec-firewall-ssdt-dos(33352)</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/479830/100/0/threaded">20070918 Plague in (security) software drivers &amp; BSDOhook utility</ref><ref source="" url="http://www.matousec.com/info/advisories/plague-in-security-software-drivers.php"></ref><ref source="" url="http://www.matousec.com/projects/windows-personal-firewall-analysis/plague-in-security-software-drivers.php"></ref></refs><vuln_soft><prod name="Norton Personal Firewall" vendor="Symantec"><vers num="2006 9.1.0.33"/><vers num="2006 9.1.1.7"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-04-03" name="CVE-2007-1794" published="2007-04-02" seq="2007-1794" severity="High" type="CVE"><desc><descript source="cve">The Javascript engine in Mozilla 1.7 and earlier on Sun Solaris 8, 9, and 10 might allow remote attackers to execute arbitrary code via vectors involving garbage collection that causes deletion of a temporary object that is still being used.  NOTE: this issue might be related to CVE-2006-3805.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102865-1">102865</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1178">ADV-2007-1178</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/24624">24624</ref></refs><vuln_soft><prod name="Mozilla" vendor="Mozilla"><vers num="1.7" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-04-03" name="CVE-2007-1795" published="2007-04-02" seq="2007-1795" severity="High" type="CVE"><desc><descript source="cve">JCcorp URLshrink 1.3.1 allows remote attackers to execute arbitrary PHP code via the email address field in an HTML link.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref patch="1" source="" url="http://developers.jccorp.net/modules/newbb/viewtopic.php?topic_id=33&amp;forum=8"></ref><ref source="BID" url="http://www.securityfocus.com/bid/23217">23217</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33320">urlshrink-email-code-execution(33320)</ref></refs><vuln_soft><prod name="URLshrink" vendor="JCcorp"><vers num="1.3.1"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2008-03-03" name="CVE-2007-1796" published="2007-04-02" seq="2007-1796" severity="High" type="CVE"><desc><descript source="cve">Multiple unspecified vulnerabilities in JCcorp URLshrink before 1.3.2 have unspecified attack vectors and impact.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><range><network/></range><refs><ref patch="1" source="" url="http://developers.jccorp.net/modules/newbb/viewtopic.php?topic_id=33&amp;forum=8"></ref></refs><vuln_soft><prod name="URLshrink" vendor="JCcorp"><vers num="1.3.1" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2008-05-21" name="CVE-2007-1797" published="2007-04-02" seq="2007-1797" severity="Medium" type="CVE"><desc><descript source="cve">Multiple integer overflows in ImageMagick before 6.3.3-5 allow remote attackers to execute arbitrary code via (1) a crafted DCM image, which results in a heap-based overflow in the ReadDCMImage function, or (2) the (a) colors or (b) comments field in a crafted XWD image, which results in a heap-based overflow in the ReadXWDImage function, different issues than CVE-2007-1667.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" patch="1" source="IDEFENSE" url="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=496">20070331 Multiple Vendor ImageMagick DCM and XWD Buffer Overflow Vulnerabilities</ref><ref source="" url="http://www.imagemagick.org/script/changelog.php"></ref><ref source="BID" url="http://www.securityfocus.com/bid/23347">23347</ref><ref source="" url="https://issues.foresightlinux.org/browse/FL-222"></ref><ref source="" url="https://issues.rpath.com/browse/RPL-1205"></ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1200">ADV-2007-1200</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017839">1017839</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24721">24721</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24739">24739</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33376">imagemagick-readdcmimage-bo(33376)</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33377">imagemagick-readxwdimage-bo(33377)</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2007_8_sr.html">SUSE-SR:2007:008</ref><ref source="BID" url="http://www.securityfocus.com/bid/23252">23252</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25072">25072</ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200705-13.xml">GLSA-200705-13</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25206">25206</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:147">MDKSA-2007:147</ref><ref source="UBUNTU" url="http://www.ubuntu.com/usn/usn-481-1">USN-481-1</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25992">25992</ref><ref source="SECUNIA" url="http://secunia.com/advisories/26177">26177</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2008-0145.html">RHSA-2008:0145</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2008-0165.html">RHSA-2008:0165</ref><ref source="SECUNIA" url="http://secunia.com/advisories/29786">29786</ref><ref source="SECUNIA" url="http://secunia.com/advisories/29857">29857</ref></refs><vuln_soft><prod name="ImageMagick" vendor="ImageMagick"><vers num="6.3.0.0"/><vers num="6.3.0.1"/><vers num="6.3.0.2"/><vers num="6.3.0.3"/><vers num="6.3.0.4"/><vers num="6.3.0.5"/><vers num="6.3.0.7"/><vers num="6.3.0.8"/><vers num="6.3.1.0"/><vers num="6.3.1.1"/><vers num="6.3.1.2."/><vers num="6.3.1.3"/><vers num="6.3.1.5"/><vers num="6.3.1.4"/><vers num="6.3.1.6"/><vers num="6.3.1.7"/><vers num="6.3.2.0"/><vers num="6.3.2.1"/><vers num="6.3.2.2"/><vers num="6.3.2.3"/><vers num="6.3.2.4"/><vers num="6.3.2.5"/><vers num="6.3.2.6"/><vers num="6.3.2.7"/><vers num="6.3.2.8"/><vers num="6.3.3.0"/><vers num="6.3.3.1"/><vers num="6.3.3.2"/><vers num="6.3.3.3"/><vers num="6.3.3.4"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-04-13" name="CVE-2007-1798" published="2007-04-02" seq="2007-1798" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in the drmgr command in IBM AIX 5.2 and 5.3 allows local users to cause a denial of service (crash) and possibly execute arbitrary code via a long path name.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input/></vuln_types><range><local/></range><refs><ref source="AIXAPAR" url="http://www-1.ibm.com/support/docview.wss?uid=isg1IY96772">IY96772</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1186">ADV-2007-1186</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33354">ibmaix-drmgr-bo(33354)</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017841">1017841</ref><ref source="AIXAPAR" url="http://www-1.ibm.com/support/docview.wss?uid=isg1IY95054">IY95054</ref><ref source="AIXAPAR" url="http://www-1.ibm.com/support/docview.wss?uid=isg1IY96753">IY96753</ref></refs><vuln_soft><prod name="AIX" vendor="IBM"><vers num="5.2"/><vers num="5.3"/></prod></vuln_soft></entry><entry CVSS_base_score="6.4" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="4.9" CVSS_score="6.4" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:P)" CVSS_version="2.0" modified="2007-04-03" name="CVE-2007-1799" published="2007-04-02" seq="2007-1799" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in torrent.cpp in KTorrent before 2.1.3 only checks for the &quot;..&quot; string, which allows remote attackers to overwrite arbitrary files via modified &quot;..&quot; sequences in a torrent filename, as demonstrated by &quot;../&quot; sequences, due to an incomplete fix for CVE-2007-1384.</descript></desc><loss_types><avail/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://bugs.kde.org/show_bug.cgi?id=143637"></ref><ref source="" url="https://bugs.gentoo.org/show_bug.cgi?id=170303"></ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2007_007_suse.html">
SUSE-SR:2007:007</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24995">
24995</ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200705-01.xml">
GLSA-200705-01</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:095">
MDKSA-2007:095</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25097">
25097</ref><ref source="UBUNTU" url="http://www.ubuntu.com/usn/usn-436-2">
USN-436-2</ref><ref source="BID" url="http://www.securityfocus.com/bid/23745">
23745</ref><ref source="DEBIAN" url="http://www.debian.org/security/2007/dsa-1373">DSA-1373</ref><ref source="SECUNIA" url="http://secunia.com/advisories/26773">26773</ref></refs><vuln_soft><prod name="KTorrent" vendor="Joris Guisson"><vers num="2.1.1"/><vers num="2.1.2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-04-03" name="CVE-2007-1800" published="2007-04-02" seq="2007-1800" severity="High" type="CVE"><desc><descript source="cve">Cisco Secure ACS does not require authentication when Cisco Trust Agent (CTA) transmits posture information, which might allow remote attackers to gain network access via a spoofed Network Endpoint Assessment posture, aka &quot;NACATTACK.&quot; NOTE: this attack might be limited to authenticated users and devices.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref source="" url="http://www.blackhat.com/html/bh-europe-07/bh-eu-07-speakers.html#Dror"></ref><ref source="CISCO" url="http://www.cisco.com/en/US/products/products_security_response09186a00808110da.html">20070330 NACATTACK Presentation</ref></refs><vuln_soft><prod name="Trust Agent" vendor="Cisco"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-04-03" name="CVE-2007-1801" published="2007-04-02" seq="2007-1801" severity="High" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in inc/lang.php in sBLOG 0.7.3 Beta allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the conf_lang_default parameter, as demonstrated by injecting PHP sequences into an Apache HTTP Server log file, which is then included by inc/lang.php.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3601">3601</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/23206">23206</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33326">sblog-inclang-file-include(33326)</ref></refs><vuln_soft><prod name="sBLOG" vendor="sBLOG"><vers num="0.7.3 Beta"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-04-03" name="CVE-2007-1802" published="2007-04-02" seq="2007-1802" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in MailDwarf 3.01 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://jvn.jp/jp/JVN%2340511721/index.html"></ref><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/23207">23207</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1166">ADV-2007-1166</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24681">24681</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33322">maildwarf-unspecified-xss(33322)</ref></refs><vuln_soft><prod name="MailDwarf" vendor="MailDwarf"><vers num="3.01" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" modified="2008-03-28" name="CVE-2007-1803" published="2007-04-02" seq="2007-1803" severity="Medium" type="CVE"><desc><descript source="cve">Unspecified vulnerability in MailDwarf 3.01 and earlier allows remote attackers to send e-mail to addresses different from the configured addresses.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://jvn.jp/jp/JVN%2308951968/index.html"></ref><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/23207">23207</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1166">ADV-2007-1166</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24681">24681</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33324">maildwarf-unspecified-security-bypass(33324)</ref></refs><vuln_soft><prod name="MailDwarf" vendor="MailDwarf"><vers num="3.01" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.8" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.9" CVSS_score="7.8" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_version="2.0" modified="2007-04-03" name="CVE-2007-1804" published="2007-04-02" seq="2007-1804" severity="High" type="CVE"><desc><descript source="cve">PulseAudio 0.9.5 allows remote attackers to cause a denial of service (daemon crash) via (1) a PA_PSTREAM_DESCRIPTOR_LENGTH value of FRAME_SIZE_MAX_ALLOW sent on TCP port 9875, which triggers a p-&gt;export assertion failure in do_read; (2) a PA_PSTREAM_DESCRIPTOR_LENGTH value of 0 sent on TCP port 9875, which triggers a length assertion failure in pa_memblock_new; or (3) an empty packet on UDP port 9875, which triggers a t assertion failure in pa_sdp_parse; and allows remote authenticated users to cause a denial of service (daemon crash) via a crafted packet on TCP port 9875 that (4) triggers a maxlength assertion failure in pa_memblockq_new, (5) triggers a size assertion failure in pa_xmalloc, or (6) plays a certain sound file.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref patch="1" source="" url="http://aluigi.altervista.org/adv/pulsex-adv.txt"></ref><ref source="" url="http://aluigi.org/poc/pulsex.zip"></ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33315">pulseaudio-assert-dos(33315)</ref><ref source="BID" url="http://www.securityfocus.com/bid/23240">
23240</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1214">
ADV-2007-1214</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2007_13_sr.html">SUSE-SR:2007:013</ref><ref source="UBUNTU" url="http://www.ubuntu.com/usn/usn-465-1">USN-465-1</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25431">25431</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25787">25787</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDVSA-2008:065">MDVSA-2008:065</ref></refs><vuln_soft><prod name="PulseAudio" vendor="PulseAudio"><vers num="0.9.5"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-04-03" name="CVE-2007-1805" published="2007-04-02" seq="2007-1805" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in genre.php in the debaser 0.92 and earlier module for Xoops allows remote attackers to execute arbitrary SQL commands via the genreid parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3630">3630</ref><ref source="BID" url="http://www.securityfocus.com/bid/23253">
23253</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33372">
xoops-debaser-genre-sql-injection(33372)</ref></refs><vuln_soft><prod name="debaser" vendor="myXOOPS"><vers num="0.92" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-04-03" name="CVE-2007-1806" published="2007-04-02" seq="2007-1806" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in categos.php in the RM+Soft Gallery (rmgallery) 1.0 module for Xoops allows remote attackers to execute arbitrary SQL commands via the idcat parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3633">3633</ref><ref source="BID" url="http://www.securityfocus.com/bid/23250">
23250</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24709">
24709</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33370">
xoops-rmsoft-categos-sql-injection(33370)</ref></refs><vuln_soft><prod name="RM+Soft Gallery" vendor="Red Mexico"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-04-03" name="CVE-2007-1807" published="2007-04-02" seq="2007-1807" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in modules/myalbum/viewcat.php in the myAlbum-P 2.0 and earlier module for Xoops allows remote attackers to execute arbitrary SQL commands via the cid parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3632">3632</ref><ref source="BID" url="http://www.securityfocus.com/bid/23229">
23229</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1202">
ADV-2007-1202</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33371">
xoops-myalbump-viewcat-sql-injection(33371)</ref></refs><vuln_soft><prod name="myAlbum_P" vendor="PEAK XOOPS"><vers num="2.0" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-04-03" name="CVE-2007-1808" published="2007-04-02" seq="2007-1808" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in show.php in the Camportail 1.1 and earlier module for Xoops allows remote attackers to execute arbitrary SQL commands via the camid parameter in a showcam action.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3629">3629</ref><ref source="BID" url="http://www.securityfocus.com/bid/23245">
23245</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1201">
ADV-2007-1201</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24748">
24748</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33373">
xoops-camportail-show-sql-injection(33373)</ref></refs><vuln_soft><prod name="Camportail" vendor="Camportail"><vers num="1.1" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-04-03" name="CVE-2007-1809" published="2007-04-02" seq="2007-1809" severity="High" type="CVE"><desc><descript source="cve">Multiple PHP remote file inclusion vulnerabilities in GraFX Company WebSite Builder (CWB) PRO 1.5 allow remote attackers to execute arbitrary PHP code via a URL in the INCLUDE_PATH parameter to (1) cls_headline_prod.php, (2) cls_listorders.php, or (3) cls_viewpastorders.php in include/, different vectors than CVE-2007-1513.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3628">3628</ref><ref source="VIM" url="http://www.attrition.org/pipermail/vim/2007-April/001482.html">20070402 [true] CWB pro 1.5 INCLUDE_PATH RFI</ref><ref source="BID" url="http://www.securityfocus.com/bid/23242">
23242</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33351">
cwb-includepath-file-include(33351)</ref></refs><vuln_soft><prod name="Company Website Builder" vendor="GraFX Software"><vers edition="Pro" num="1.5"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-04-03" name="CVE-2007-1810" published="2007-04-02" seq="2007-1810" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in product_details.php in the Kshop 1.17 and earlier module for Xoops allows remote attackers to execute arbitrary SQL commands via the id parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3626">3626</ref><ref source="BID" url="http://www.securityfocus.com/bid/23272">
23272</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1211">
ADV-2007-1211</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24749">
24749</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33374">
xoops-kshop-productdetails-sql-injection(33374)</ref></refs><vuln_soft><prod name="Kshop" vendor="Kaotik"><vers num="1.17" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-04-03" name="CVE-2007-1811" published="2007-04-02" seq="2007-1811" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in index.php in the Tiny Event (tinyevent) 1.01 and earlier module for Xoops allows remote attackers to execute arbitrary SQL commands via the id parameter in a show action.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3625">3625</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33359">
xoops-tinyevent-index-sql-injection(33359)</ref></refs><vuln_soft><prod name="Tiny Event" vendor="Chapi"><vers num="1.01" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-04-03" name="CVE-2007-1812" published="2007-04-02" seq="2007-1812" severity="High" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in utilitaires/gestion_sondage.php in BT-Sondage 112 allows remote attackers to execute arbitrary PHP code via a URL in the repertoire_visiteur parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3624">3624</ref><ref source="VIM" url="http://www.attrition.org/pipermail/vim/2007-April/001483.html">20070402 [true] BT-Sondage-v112 RFI</ref><ref source="BID" url="http://www.securityfocus.com/bid/23248">
23248</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1183">
ADV-2007-1183</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24701">
24701</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33363">
btsondage-gestionsondage-file-include(33363)</ref></refs><vuln_soft><prod name="BT-Sondage" vendor="BT-Sondage"><vers num="1.12"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-04-03" name="CVE-2007-1813" published="2007-04-02" seq="2007-1813" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in display.php in the eCal 2.24 and earlier module for Xoops allows remote attackers to execute arbitrary SQL commands via the katid parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3623">3623</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33369">
xoops-ecal-display-sql-injection(33369)</ref></refs><vuln_soft><prod name="eCal" vendor="Inconnueteam"><vers num="2.24"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-04-03" name="CVE-2007-1814" published="2007-04-02" seq="2007-1814" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in viewcat.php in the Core module for Xoops allows remote attackers to execute arbitrary SQL commands via the cid parameter, a different vector than CVE-2007-0377.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3620">3620</ref><ref source="BID" url="http://www.securityfocus.com/bid/23229">
23229</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33350">
xoops-core-viewcat-sql-injection(33350)</ref></refs><vuln_soft><prod name="Core Module" vendor="Xoops"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-04-03" name="CVE-2007-1815" published="2007-04-02" seq="2007-1815" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in viewcat.php in the Library module for Xoops allows remote attackers to execute arbitrary SQL commands via the cid parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3619">3619</ref><ref source="BID" url="http://www.securityfocus.com/bid/23229">
23229</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33366">
xoops-library-viewcat-sql-injection(33366)</ref></refs><vuln_soft><prod name="Library Module" vendor="Xoops"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-04-03" name="CVE-2007-1816" published="2007-04-02" seq="2007-1816" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in viewcat.php in the Tutoriais module for Xoops allows remote attackers to execute arbitrary SQL commands via the cid parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3621">3621</ref><ref source="BID" url="http://www.securityfocus.com/bid/23229">
23229</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33367">
xoops-tutoriais-viewcat-sql-injection(33367)</ref></refs><vuln_soft><prod name="Tutoriais Module" vendor="Xoops"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-04-03" name="CVE-2007-1817" published="2007-04-02" seq="2007-1817" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in index.php in the Lykos Reviews (lykos_reviews) 1.00 module for Xoops allows remote attackers to execute arbitrary SQL commands via the uid parameter in a u action.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3618">3618</ref><ref source="BID" url="http://www.securityfocus.com/bid/23232">
23232</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1189">
ADV-2007-1189</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33365">
xoops-lykos-reviews-sql-injection(33365)</ref></refs><vuln_soft><prod name="Lykos Reviews Module" vendor="Lykoszine"><vers num="1.00"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-04-03" name="CVE-2007-1818" published="2007-04-02" seq="2007-1818" severity="High" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in MOD_forum_fields_parse.php in the Forum picture and META tags 1.7 module for phpBB allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3613">3613</ref><ref source="BID" url="http://www.securityfocus.com/bid/23222">
23222</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1188">
ADV-2007-1188</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33346">
phpbb-modforumfieldsparse-file-include(33346)</ref></refs><vuln_soft><prod name="Forum picture and META tags" vendor="Forum picture and META tags"><vers num="1.7"/></prod></vuln_soft></entry><entry CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" CVSS_score="9.3" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-04-13" name="CVE-2007-1819" published="2007-04-02" seq="2007-1819" severity="High" type="CVE"><desc><descript source="cve">Stack-based buffer overflow in the SPIDERLib.Loader ActiveX control (Spider90.ocx) 9.1.0.4353 in TestDirector (TD) for Mercury Quality Center 9.0 before Patch 12.1, and 8.2 SP1 before Patch 32, allows remote attackers to execute arbitrary code via a long ProgColor property.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/><user_init/></range><refs><ref source="" url="http://webnotes.merc-int.com/patches.nsf/c4d68388a23535dc422567d0004bbae2/cf109e434c7765eac22572a4006c6e94?OpenDocument"></ref><ref source="" url="http://webnotes.merc-int.com/patches.nsf/c4d68388a23535dc422567d0004bbae2/7a0f7f0efc7905fdc225729f004cf387?OpenDocument"></ref><ref source="HP" url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00901872">HPSBGN02199</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/589097">VU#589097</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1017835">1017835</ref><ref source="IDEFENSE" url="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=497">20070402 Hewlett-Packard Mercury Quality Center ActiveX Control ProgColor Buffer Overflow Vulnerability</ref><ref source="BID" url="http://www.securityfocus.com/bid/23239">23239</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1185">ADV-2007-1185</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24692">24692</ref></refs><vuln_soft><prod name="Mercury Quality Center" vendor="HP"><vers num="8.2 SP1"/><vers num="9.0"/></prod></vuln_soft></entry><entry CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" CVSS_score="9.3" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-04-03" name="CVE-2007-1820" published="2007-04-02" seq="2007-1820" severity="High" type="CVE"><desc><descript source="cve">Nortel Networks CallPilot and Meridian Mail voicemail systems, when a mailbox has auto logon enabled, allow remote attackers to retrieve or remove messages, or reconfigure the mailbox, by spoofing Calling Number Identification (CNID, aka Caller ID).</descript></desc><impacts><impact source="nvd">Access complexity set to Medium because Nortel Networks voicemail systems do not hard code or default to this behavior.</impact></impacts><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref source="" url="http://www.kb.cert.org/vuls/id/AAMN-5N2QFX"></ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/726548">VU#726548</ref></refs><vuln_soft><prod name="Meridian Mail" vendor="Nortel"><vers num=""/></prod><prod name="CallPilot" vendor="Nortel"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-04-10" name="CVE-2007-1821" published="2007-04-02" seq="2007-1821" severity="High" type="CVE"><desc><descript source="cve">Sprint Nextel Sprint voice mail systems allow remote attackers to retrieve or remove messages, or reconfigure mailboxes, by spoofing Calling Number Identification (CNID, aka Caller ID).</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/726548">VU#726548</ref></refs><vuln_soft><prod name="Sprint Voice" vendor="Sprint"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-04-09" name="CVE-2007-1822" published="2007-04-02" seq="2007-1822" severity="High" type="CVE"><desc><descript source="cve">Alcatel-Lucent Lucent Technologies voice mail systems allow remote attackers to retrieve or remove messages, or reconfigure mailboxes, by spoofing Calling Number Identification (CNID, aka Caller ID).</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/726548">VU#726548</ref></refs><vuln_soft><prod name="Voice Mail System" vendor="Alcatel-Lucent"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-04-09" name="CVE-2007-1823" published="2007-04-02" seq="2007-1823" severity="High" type="CVE"><desc><descript source="cve">T-Mobile voice mail systems allow remote attackers to retrieve or remove messages, or reconfigure mailboxes, by spoofing Calling Number Identification (CNID, aka Caller ID).</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/726548">VU#726548</ref></refs><vuln_soft><prod name="Voice Mail Systems" vendor="T-Mobile"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.1" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="6.4" CVSS_score="5.1" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-04-27" name="CVE-2007-1824" published="2007-04-02" seq="2007-1824" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in the php_stream_filter_create function in PHP 5 before 5.2.1 allows remote attackers to cause a denial of service (application crash) via a php://filter/ URL that has a name ending in the &apos;.&apos; character.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref source="" url="http://www.php-security.org/MOPB/MOPB-42-2007.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/23237">23237</ref><ref source="DEBIAN" url="http://www.debian.org/security/2007/dsa-1283">
DSA-1283</ref><ref source="UBUNTU" url="http://www.ubuntu.com/usn/usn-455-1">
USN-455-1</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25062">
25062</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25057">
25057</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2007_32_php.html">SUSE-SA:2007:032</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25056">25056</ref></refs><vuln_soft><prod name="PHP" vendor="PHP"><vers num="5.0.1"/><vers num="5.0.2"/><vers num="5.0.3"/><vers num="5.0.4"/><vers num="5.0.5"/><vers num="5.1.0"/><vers num="5.1.1"/><vers num="5.1.2"/><vers num="5.1.3"/><vers num="5.1.4"/><vers num="5.1.5"/><vers num="5.1.6"/><vers num="5.2.0"/><vers num="5.0.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-08-02" name="CVE-2007-1825" published="2007-04-02" seq="2007-1825" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in the imap_mail_compose function in PHP 5 before 5.2.1, and PHP 4 before 4.4.5, allows remote attackers to execute arbitrary code via a long boundary string in a type.parameters field. NOTE: as of 20070411, it appears that this issue might be subsumed by CVE-2007-0906.3.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref source="" url="http://www.php-security.org/MOPB/MOPB-40-2007.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/23234">23234</ref></refs><vuln_soft><prod name="PHP" vendor="PHP"><vers num="4.0.0"/><vers num="4.0.1"/><vers num="4.0.1 pl1"/><vers num="4.0.1 pl2"/><vers num="4.0.2"/><vers num="4.0.3"/><vers num="4.0.3 pl1"/><vers num="4.0.4"/><vers num="4.0.4 pl1"/><vers num="4.0.5"/><vers num="4.0.6"/><vers num="4.0.7"/><vers num="4.0.7 RC1"/><vers num="4.0.7 RC2"/><vers num="4.0.7 RC3"/><vers num="4.1.0"/><vers num="4.1.1"/><vers num="4.1.2"/><vers edition="Dev" num="4.2"/><vers num="4.2.0"/><vers num="4.2.1"/><vers num="4.2.2"/><vers num="4.2.3"/><vers num="4.3"/><vers num="4.3.1"/><vers num="4.3.10"/><vers num="4.3.11"/><vers num="4.3.2"/><vers num="4.3.3"/><vers num="4.3.4"/><vers num="4.3.5"/><vers num="4.3.6"/><vers num="4.3.7"/><vers num="4.3.8"/><vers num="4.3.9"/><vers num="4.4.0"/><vers num="4.4.1"/><vers num="4.4.2"/><vers num="4.4.3"/><vers num="4.4.4"/><vers num="5.0 candidate 1"/><vers num="5.0 candidate 2"/><vers num="5.0 candidate 3"/><vers num="5.0.0"/><vers num="5.0.1"/><vers num="5.0.2"/><vers num="5.0.3"/><vers num="5.0.4"/><vers num="5.0.5"/><vers num="5.1"/><vers num="5.1.0"/><vers num="5.1.1"/><vers num="5.1.2"/><vers num="5.1.3"/><vers num="5.1.4"/><vers num="5.1.5"/><vers num="5.1.6"/></prod></vuln_soft></entry><entry CVSS_base_score="7.8" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.9" CVSS_score="7.8" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_version="2.0" modified="2007-04-04" name="CVE-2007-1826" published="2007-04-02" seq="2007-1826" severity="High" type="CVE"><desc><descript source="cve">Unspecified vulnerability in the IPSec Manager Service for Cisco Unified CallManager (CUCM) 5.0 before 5.0(4a)SU1 and Cisco Unified Presence Server (CUPS) 1.0 before 1.0(3) allows remote attackers to cause a denial of service (loss of cluster services) via a &quot;specific UDP packet&quot; to UDP port 8500, aka bug ID CSCsg60949.</descript></desc><loss_types><avail/></loss_types><range><network/></range><refs><ref adv="1" patch="1" source="CISCO" url="http://www.cisco.com/warp/public/707/cisco-sa-20070328-voip.shtml">20070328 Multiple Cisco Unified CallManager and Presence Server Denial of Service Vulnerabilities</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/23181">23181</ref><ref patch="1" source="SECTRACK" url="http://securitytracker.com/id?1017826">1017826</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/24690">24690</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1144">
ADV-2007-1144</ref></refs><vuln_soft><prod name="Unified CallManager" vendor="Cisco"><vers num="5.0"/><vers num="5.0(1)"/><vers num="5.0(2)"/><vers num="5.0(3)"/><vers num="5.0(3a)"/><vers num="5.0(4)"/></prod><prod name="Unified Presence Server" vendor="Cisco"><vers num="1.0"/><vers num="1.0(1)"/><vers num="1.0(2)"/></prod></vuln_soft></entry><entry CVSS_base_score="6.0" CVSS_exploit_subscore="6.8" CVSS_impact_subscore="6.4" CVSS_score="6.0" CVSS_vector="(AV:N/AC:M/Au:S/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-04-06" name="CVE-2007-1827" published="2007-04-02" seq="2007-1827" severity="Medium" type="CVE"><desc><descript source="cve">Multiple unspecified vulnerabilities in form input validation in web-app.org WebAPP before 0.9.9.6 allow remote authenticated users to corrupt data files, gain access to private files, and execute arbitrary code via &quot;certain characters.&quot;</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref patch="1" source="" url="http://www.web-app.org/cgi-bin/index.cgi?action=viewnews&amp;id=252"></ref><ref patch="1" source="" url="http://www.web-app.org/cgi-bin/index.cgi?action=viewnews&amp;id=254"></ref><ref patch="1" source="VIM" url="http://www.attrition.org/pipermail/vim/2007-March/001455.html">20070322 WebAPP Audit</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0720">ADV-2007-0720</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/24227">24227</ref></refs><vuln_soft><prod name="WebAPP" vendor="Web-APP.org"><vers num="0.9.9"/><vers num="0.9.9.1"/><vers num="0.9.9.2"/><vers num="0.9.9.2.1"/><vers num="0.9.9.3"/><vers num="0.9.9.3.1"/><vers num="0.9.9.3.2"/><vers num="0.9.9.3.3"/><vers num="0.9.9.3.4"/><vers num="0.9.9.3.5"/><vers num="0.9.9.4"/><vers num="0.9.9.5"/></prod></vuln_soft></entry><entry CVSS_base_score="3.5" CVSS_exploit_subscore="6.8" CVSS_impact_subscore="2.9" CVSS_score="3.5" CVSS_vector="(AV:N/AC:M/Au:S/C:N/I:P/A:N)" CVSS_version="2.0" modified="2007-04-06" name="CVE-2007-1828" published="2007-04-02" seq="2007-1828" severity="Low" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in web-app.org WebAPP before 0.9.9.6 allow remote authenticated users to inject arbitrary web script or HTML via (1) the QUERY_STRING corresponding to drop downs or (2) various forms.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref patch="1" source="" url="http://www.web-app.org/cgi-bin/index.cgi?action=viewnews&amp;id=252"></ref><ref patch="1" source="" url="http://www.web-app.org/cgi-bin/index.cgi?action=viewnews&amp;id=254"></ref><ref patch="1" source="VIM" url="http://www.attrition.org/pipermail/vim/2007-March/001455.html">20070322 WebAPP Audit</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0720">ADV-2007-0720</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24227">24227</ref></refs><vuln_soft><prod name="WebAPP" vendor="Web-APP.org"><vers num="0.9.9.1"/><vers num="0.9.9.2"/><vers num="0.9.9.2.1"/><vers num="0.9.9.2.2"/><vers num="0.9.9.3"/><vers num="0.9.9.3.1"/><vers num="0.9.9.3.2"/><vers num="0.9.9.3.3"/><vers num="0.9.9.3.4"/><vers num="0.9.9.3.5"/><vers num="0.9.9.4"/><vers num="0.9.9.5"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-04-06" name="CVE-2007-1829" published="2007-04-02" seq="2007-1829" severity="High" type="CVE"><desc><descript source="cve">Multiple unspecified vulnerabilities in web-app.net WebAPP have unknown impact and attack vectors, described as &quot;[having] other [security] issues too, not as bad as letting users take over your admin account, but bad too.&quot;</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><range><network/></range><refs><ref source="" url="http://www.web-app.net/cgi-bin/index.cgi?action=forum&amp;board=public_security&amp;op=display&amp;num=10380"></ref></refs><vuln_soft><prod name="WebAPP" vendor="Web-APP.net"><vers num="0.9.9.6"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" modified="2007-07-03" name="CVE-2007-1830" published="2007-04-02" seq="2007-1830" severity="Medium" type="CVE"><desc><descript source="cve">Unspecified vulnerability in the Username Hijacking Patch 20070312 for web-app.org WebAPP 0.9.9.6 allows remote attackers to obtain administrative access via unknown vectors, related to &quot;something overlooked in the original that was still overlooked in the patch&quot;, and possibly related to copying files to the user-lib and the &quot;XSS and cookies exploit.&quot;</descript></desc><loss_types><int/></loss_types><range><network/></range><refs><ref source="" url="http://www.web-app.org/cgi-bin/index.cgi?action=viewnews&amp;id=259"></ref></refs><vuln_soft><prod name="WebAPP" vendor="Web-APP.org"><vers num="0.9.9.6"/></prod></vuln_soft></entry><entry CVSS_base_score="6.0" CVSS_exploit_subscore="6.8" CVSS_impact_subscore="6.4" CVSS_score="6.0" CVSS_vector="(AV:N/AC:M/Au:S/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-04-04" name="CVE-2007-1831" published="2007-04-02" seq="2007-1831" severity="Medium" type="CVE"><desc><descript source="cve">web-app.org WebAPP before 0.9.9.6 allows remote authenticated users to open files and write &quot;wrong data&quot; via a crafted QUERY_STRING.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://www.web-app.org/cgi-bin/index.cgi?action=viewnews&amp;id=252"></ref><ref source="" url="http://www.web-app.org/cgi-bin/index.cgi?action=viewnews&amp;id=254"></ref><ref source="VIM" url="http://www.attrition.org/pipermail/vim/2007-March/001455.html">20070322 WebAPP Audit</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0720">ADV-2007-0720</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/24227">24227</ref></refs><vuln_soft><prod name="WebAPP" vendor="Web-APP.org"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" modified="2007-06-27" name="CVE-2007-1832" published="2007-04-02" seq="2007-1832" severity="Medium" type="CVE"><desc><descript source="cve">web-app.org WebAPP before 0.9.9.6 allows remote authenticated users to upload certain files (1) via a crafted filename or (2) by &quot;using percent encoding in forms.&quot;</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref source="" url="http://www.web-app.org/cgi-bin/index.cgi?action=viewnews&amp;id=252"></ref><ref source="" url="http://www.web-app.org/cgi-bin/index.cgi?action=viewnews&amp;id=254"></ref><ref source="VIM" url="http://www.attrition.org/pipermail/vim/2007-March/001455.html">20070322 WebAPP Audit</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0720">ADV-2007-0720</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/24227">24227</ref></refs><vuln_soft><prod name="WebAPP" vendor="Web-APP.org"><vers num="0.9.9.5" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0" modified="2007-04-04" name="CVE-2007-1833" published="2007-04-02" seq="2007-1833" severity="Medium" type="CVE"><desc><descript source="cve">The Skinny Call Control Protocol (SCCP) implementation in Cisco Unified CallManager (CUCM) 3.3 before 3.3(5)SR2a, 4.1 before 4.1(3)SR4, 4.2 before 4.2(3)SR1, and 5.0 before 5.0(4a)SU1 allows remote attackers to cause a denial of service (loss of voice services) by sending crafted packets to the (1) SCCP (2000/tcp) or (2) SCCPS (2443/tcp) port.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="CISCO" url="http://www.cisco.com/warp/public/707/cisco-sa-20070328-voip.shtml">20070328 Multiple Cisco Unified CallManager and Presence Server Denial of Service Vulnerabilities</ref><ref source="BID" url="http://www.securityfocus.com/bid/23181">23181</ref><ref patch="1" source="SECTRACK" url="http://securitytracker.com/id?1017826">1017826</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/24665">24665</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1144">
ADV-2007-1144</ref></refs><vuln_soft><prod name="Unified CallManager" vendor="Cisco"><vers num="3.3"/><vers num="3.3(2)"/><vers num="3.3(2) spB"/><vers num="3.3(2) spC"/><vers num="3.3(3)"/><vers num="3.3(3) SR1"/><vers num="3.3(3) SR4"/><vers num="3.3(4)"/><vers num="3.3(4) SR1a"/><vers num="3.3(5)"/><vers num="3.3(5) SR1"/><vers num="3.3(5) SR1a"/><vers num="4.1"/><vers num="4.1(2)"/><vers num="4.1(3)"/><vers num="4.1(3) SR1"/><vers num="4.1(3) SR2"/><vers num="4.1(3) SR3"/><vers num="4.2"/><vers num="5.0"/><vers num="5.0(1)"/><vers num="5.0(2)"/><vers num="5.0(3)"/><vers num="5.0(3a)"/><vers num="5.0(4)"/></prod></vuln_soft></entry><entry CVSS_base_score="7.8" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.9" CVSS_score="7.8" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_version="2.0" modified="2007-04-04" name="CVE-2007-1834" published="2007-04-02" seq="2007-1834" severity="High" type="CVE"><desc><descript source="cve">Cisco Unified CallManager (CUCM) 5.0 before 5.0(4a)SU1 and Cisco Unified Presence Server (CUPS) 1.0 before 1.0(3) allow remote attackers to cause a denial of service (loss of voice services) via a flood of ICMP echo requests, aka bug ID CSCsf12698.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="CISCO" url="http://www.cisco.com/warp/public/707/cisco-sa-20070328-voip.shtml">20070328 Multiple Cisco Unified CallManager and Presence Server Denial of Service Vulnerabilities</ref><ref source="BID" url="http://www.securityfocus.com/bid/23181">23181</ref><ref patch="1" source="SECTRACK" url="http://securitytracker.com/id?1017826">1017826</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/24690">24690</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1144">
ADV-2007-1144</ref></refs><vuln_soft><prod name="Unified CallManager" vendor="Cisco"><vers num="5.0"/><vers num="5.0(1)"/><vers num="5.0(2)"/><vers num="5.0(3)"/><vers num="5.0(3a)"/><vers num="5.0(4)"/></prod><prod name="Unified Presence Server" vendor="Cisco"><vers num="1.0"/><vers num="1.0(1)"/><vers num="1.0(2)"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-04-06" name="CVE-2007-1835" published="2007-04-02" seq="2007-1835" severity="Medium" type="CVE"><desc><descript source="cve">PHP 4 before 4.4.5 and PHP 5 before 5.2.1, when using an empty session save path (session.save_path), uses the TMPDIR default after checking the restrictions, which allows local users to bypass open_basedir restrictions.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref source="" url="http://www.php-security.org/MOPB/MOPB-36-2007.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/23183">23183</ref><ref source="HP" url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&amp;cc=us&amp;objectID=c01056506">HPSBMA02215</ref><ref source="HP" url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&amp;cc=us&amp;objectID=c01086137">HPSBTU02232</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1991">ADV-2007-1991</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/2374">ADV-2007-2374</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25423">25423</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25850">25850</ref></refs><vuln_soft><prod name="PHP" vendor="PHP"><vers num="4.0"/><vers num="4.0 Beta 1"/><vers num="4.0 Beta 2"/><vers num="4.0 Beta 3"/><vers num="4.0 Beta 4"/><vers num="4.0 Beta 4 Patch Level 1"/><vers num="4.0 RC1"/><vers num="4.0 RC2"/><vers num="4.0.0"/><vers num="4.0.1"/><vers num="4.0.1 pl1"/><vers num="4.0.1 pl2"/><vers num="4.0.2"/><vers num="4.0.3"/><vers num="4.0.3 pl1"/><vers num="4.0.4"/><vers num="4.0.4 pl1"/><vers num="4.0.5"/><vers num="4.0.6"/><vers num="4.0.7"/><vers num="4.0.7 RC1"/><vers num="4.0.7 RC2"/><vers num="4.0.7 RC3"/><vers num="4.1.0"/><vers num="4.1.1"/><vers num="4.1.2"/><vers edition="Dev" num="4.2"/><vers num="4.2.0"/><vers num="4.2.1"/><vers num="4.2.2"/><vers num="4.2.3"/><vers num="4.3"/><vers num="4.3.1"/><vers num="4.3.10"/><vers num="4.3.11"/><vers num="4.3.2"/><vers num="4.3.3"/><vers num="4.3.4"/><vers num="4.3.5"/><vers num="4.3.6"/><vers num="4.3.7"/><vers num="4.3.8"/><vers num="4.3.9"/><vers num="4.4.0"/><vers num="4.4.1"/><vers num="4.4.2"/><vers num="4.4.3"/><vers num="4.4.4"/><vers num="4.4.5"/><vers num="4.4.6"/><vers num="5.0 candidate 1"/><vers num="5.0 candidate 2"/><vers num="5.0 candidate 3"/><vers num="5.0.0"/><vers num="5.0.0 Beta1"/><vers num="5.0.0 Beta2"/><vers num="5.0.0 Beta3"/><vers num="5.0.0 Beta4"/><vers num="5.0.0 RC1"/><vers num="5.0.0 RC2"/><vers num="5.0.0 RC3"/><vers num="5.0.1"/><vers num="5.0.2"/><vers num="5.0.3"/><vers num="5.0.4"/><vers num="5.0.5"/><vers num="5.1"/><vers num="5.1.0"/><vers num="5.1.1"/><vers num="5.1.2"/><vers num="5.1.3"/><vers num="5.1.4"/><vers num="5.1.5"/><vers num="5.1.6"/><vers num="5.2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="9.0" CVSS_exploit_subscore="8.0" CVSS_impact_subscore="10.0" CVSS_score="9.0" CVSS_vector="(AV:N/AC:L/Au:S/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-04-06" name="CVE-2007-1836" published="2007-04-02" seq="2007-1836" severity="High" type="CVE"><desc><descript source="cve">The command line administration interface in Data Domain OS before 4.0.3.6 allows remote authenticated users to execute arbitrary commands via shell metacharacters in certain arguments to various commands, as demonstrated by the interface argument to the (1) ifconfig and (2) ping commands.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/464085/100/0/threaded">20070328 Arbitrary Command Execution in DataDomain Administrator Interface</ref><ref source="BID" url="http://www.securityfocus.com/bid/23182">23182</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24666">
24666</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2516">2516</ref></refs><vuln_soft><prod name="Data Domain OS" vendor="Data Domain"><vers num="4.0.3.5" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-04-06" name="CVE-2007-1837" published="2007-04-02" seq="2007-1837" severity="High" type="CVE"><desc><descript source="cve">Multiple PHP remote file inclusion vulnerabilities in MangoBery CMS 0.5.5 allow remote attackers to execute arbitrary PHP code via a URL in the Site_Path parameter to (1) boxes/quotes.php or (2) templates/mangobery/footer.sample.php.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3598">3598</ref><ref patch="1" source="" url="http://mangobery.svn.sourceforge.net/viewvc/mangobery?view=rev&amp;revision=70"></ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24686">24686</ref><ref source="BID" url="http://www.securityfocus.com/bid/23187">
23187</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1147">
ADV-2007-1147</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33290">
mangoberycms-quotes-file-include(33290)</ref></refs><vuln_soft><prod name="MangoBery CMS" vendor="MangoBery CMS"><vers num="0.5.5"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-04-06" name="CVE-2007-1838" published="2007-04-02" seq="2007-1838" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in view.php in the Friendfinder 3.3 and earlier module for Xoops allows remote attackers to execute arbitrary SQL commands via the id parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3597">3597</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/23184">23184</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/464153/100/0/threaded">

20070329 Xoops Module Friendfinder &lt;= 3.3 (view.php id) BLIND SQL Injection Exploit</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1146">
ADV-2007-1146</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33292">
xoops-friendfinder-view-sql-injection(33292)</ref></refs><vuln_soft><prod name="FriendFinder Module" vendor="Xoops"><vers num="3.3" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-04-06" name="CVE-2007-1839" published="2007-04-02" seq="2007-1839" severity="High" type="CVE"><desc><descript source="cve">Multiple PHP remote file inclusion vulnerabilities in CodeBB 1.1b3 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter to (1) pass_code.php or (2) lang_select.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3599">3599</ref><ref source="BID" url="http://www.securityfocus.com/bid/23185">
23185</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1148">
ADV-2007-1148</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33293">
codebb-passcode-file-include(33293)</ref></refs><vuln_soft><prod name="CodeBB" vendor="CodeBB"><vers num="1.1 Beta 3" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" modified="2007-04-06" name="CVE-2007-1840" published="2007-04-02" seq="2007-1840" severity="Medium" type="CVE"><desc><descript source="cve">lib/modules.inc in LDAP Account Manager (LAM) before 1.3.0 does not escape HTML special characters in LDAP data, which allows remote attackers to have an unknown impact, probably cross-site scripting (XSS).</descript></desc><loss_types><int/></loss_types><vuln_types><design/></vuln_types><range><network/><user_init/></range><refs><ref patch="1" source="" url="http://lam.cvs.sourceforge.net/lam/lam/lib/modules.inc?r1=1.173&amp;r2=1.174"></ref><ref adv="1" source="" url="http://lam.sourceforge.net/changelog/index.htm"></ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1149">
ADV-2007-1149</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24687">
24687</ref><ref source="DEBIAN" url="http://www.us.debian.org/security/2007/dsa-1287">
DSA-1287</ref><ref source="BID" url="http://www.securityfocus.com/bid/23190">
23190</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25157">
25157</ref></refs><vuln_soft><prod name="LDAP Account Manager" vendor="LDAP Account Manager"><vers num="1.0 RC2" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:P)" CVSS_version="2.0" modified="2007-10-03" name="CVE-2007-1841" published="2007-04-10" seq="2007-1841" severity="Medium" type="CVE"><desc><descript source="cve">The isakmp_info_recv function in src/racoon/isakmp_inf.c in racoon in Ipsec-tools before 0.6.7 allows remote attackers to cause a denial of service (tunnel crash) via crafted (1) DELETE (ISAKMP_NPTYPE_D) and (2) NOTIFY (ISAKMP_NPTYPE_N) messages.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="MLIST" url="http://sourceforge.net/mailarchive/message.php?msg_name=20070406123739.GA1546%40zen.inc">[Ipsec-tools-devel] 20070406 Ipsec-tools 0.6.7 released</ref><ref source="" url="http://sourceforge.net/project/shownotes.php?release_id=499192&amp;group_id=74601"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1310">ADV-2007-1310</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24815">24815</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2007:084">MDKSA-2007:084</ref><ref source="UBUNTU" url="http://www.ubuntu.com/usn/usn-450-1">USN-450-1</ref><ref source="BID" url="http://www.securityfocus.com/bid/23394">23394</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24833">24833</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24826">24826</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33541">ipsectools-isakmpinforecv-dos(33541)</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2007_8_sr.html">SUSE-SR:2007:008</ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200705-09.xml">GLSA-200705-09</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25072">25072</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25142">25142</ref><ref source="REDHAT" url="https://rhn.redhat.com/errata/RHSA-2007-0342.html">RHSA-2007:0342</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25322">25322</ref><ref source="DEBIAN" url="http://www.debian.org/security/2007/dsa-1299">DSA-1299</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:084">MDKSA-2007:084</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1018086">1018086</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25560">25560</ref></refs><vuln_soft><prod name="IPsec-Tools" vendor="IPsec-Tools"><vers num="0.6.2" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-04-05" name="CVE-2007-1842" published="2007-04-03" seq="2007-1842" severity="High" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in login.php in JSBoard before 2.0.12 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the table parameter, as demonstrated by injecting PHP sequences into an Apache HTTP Server log file, a related issue to CVE-2006-2019.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3614">3614</ref><ref source="" url="http://kldp.net/plugins/scmcvs/cvsweb.php/jsboard-2/login.php.diff?r1=1.8;r2=1.9;cvsroot=jsboard"></ref><ref source="BID" url="http://www.securityfocus.com/bid/23223">23223</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1182">ADV-2007-1182</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33338">
jsboard-login-file-include(33338)</ref></refs><vuln_soft><prod name="JSBoard" vendor="JSBoard"><vers num="2.0.11" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-08-02" name="CVE-2007-1843" published="2007-04-03" seq="2007-1843" severity="Medium" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in gmapfactory/params.php in MapLab 2.2.1, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the gszAppPath parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24715">24715</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/464462/100/0/threaded">20070402 Maplab &lt;= 2.2.1 (gszAppPath) Remote File Inclusion Vulnerability</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/464503/100/0/threaded">20070402 Re: Maplab &lt;= 2.2.1 (gszAppPath) Remote File Inclusion Vulnerability</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/464490/100/0/threaded">20070402 Re: Maplab &lt;= 2.2.1 (gszAppPath) Remote File InclusionVulnerability</ref><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3638">3638</ref><ref source="BID" url="http://www.securityfocus.com/bid/23249">23249</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1203">ADV-2007-1203</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33360">maplab-params-file-include(33360)</ref></refs><vuln_soft><prod name="MapLab" vendor="MapLab"><vers num="2.2.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-04-05" name="CVE-2007-1844" published="2007-04-03" seq="2007-1844" severity="High" type="CVE"><desc><descript source="cve">Multiple PHP remote file inclusion vulnerabilities in Aardvark Topsites PHP 5 allow remote attackers to execute arbitrary PHP code via a URL in the path parameter to (1) button/settings_sql.php, (2) settings_sql.php, and (3) sources/misc/new_day.php.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/464351/100/0/threaded">20070331 Remot File Include In Aardvark Topsites PHP 5</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33342">
aardvark-settingssql-newday-file-include(33342)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2515">2515</ref></refs><vuln_soft><prod name="Aardvark Topsites PHP" vendor="Avatic"><vers num="5"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-04-05" name="CVE-2007-1845" published="2007-04-03" seq="2007-1845" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in show_event.php in the Expanded Calendar (calendar_panel) 2.00 module for PHP-Fusion allows remote attackers to execute arbitrary SQL commands via the m_month parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/464348/100/0/threaded">20070331 PHP-Fusion &apos;Calendar_Panel&apos; Module show_event.PHP (m_month) SQL Injection Exploit And PoC</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/23225">23225</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24718">24718</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1191">
ADV-2007-1191</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33336">
phpfusion-showevent-sql-injection(33336)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2514">2514</ref></refs><vuln_soft><prod name="Expanded Calendar Module" vendor="PHP_Fusion"><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-04-05" name="CVE-2007-1846" published="2007-04-03" seq="2007-1846" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in index.php in the MyAds 2.04jp and earlier module for Xoops allows remote attackers to execute arbitrary SQL commands via the cid parameter, different vectors than CVE-2006-3341.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MILW0RM" url="http://milw0rm.com/exploits/3603">3603</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/23212">23212</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/33334">xoops-myads-index-sql-injection(33334)</ref></refs><vuln_soft><prod name="Malaika System MyAds Module" vendor="Xoops"><vers num="2.04" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-04-05" name="CVE-2007-1847" published="2007-04-03" seq="2007-1847" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in viewcat.php in the Repository module for Xoops allows remote attackers to execute arbitrary SQL commands via the cid parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3612">3612</ref><ref source="BID" url="http://www.securityfocus.com/bid/23221">23221</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33344">
xoops-viewcatphp-sql-injection(33344)</ref></refs><vuln_soft><prod name="Repository Module" vendor="Xoops"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" modified="2007-04-05" name="CVE-2007-1848" published="2007-04-03" seq="2007-1848" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in admin/classes/ui.dta.php in Drake CMS allows remote attackers to inject arbitrary web script or HTML via the desc[][title] field.  NOTE: Drake CMS has only a beta version available, and the vendor has previously stated &quot;We do not consider security reports valid until the first official release of Drake CMS.&quot;</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/464272/100/0/threaded">20070330 DrakeCMS multiple vulerabilities</ref><ref source="BID" url="http://www.securityfocus.com/bid/23216">23216</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33332">drakecms-uidta-xss(33332)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2522">2522</ref></refs><vuln_soft><prod name="Drake CMS" vendor="Drake Team"><vers num="0.3.7"/><vers num="0.3.7 beta"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-04-05" name="CVE-2007-1849" published="2007-04-03" seq="2007-1849" severity="High" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in 404.php in Drake CMS allows remote attackers to include and execute arbitrary local arbitrary files via a .. (dot dot) in the d_private parameter.  NOTE: some of these details are obtained from third party information.  NOTE: Drake CMS has only a beta version available, and the vendor has previously stated &quot;We do not consider security reports valid until the first official release of Drake CMS.&quot;</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/464272">20070330 DrakeCMS multiple vulerabilities</ref><ref source="BID" url="http://www.securityfocus.com/bid/23215">23215</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33331">drakecms-dprivate-file-include(33331)</ref></refs><vuln_soft><prod name="Drake CMS" vendor="Drake Team"><vers num="0.3.7"/><vers num="0.3.7 beta"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0" modified="2007-04-05" name="CVE-2007-1850" published="2007-04-03" seq="2007-1850" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in classes/captcha/captcha.jpg.php in Drake CMS allows remote attackers to read arbitrary files or list arbitrary directories, and obtain the installation path, via a .. (dot dot) in the d_private parameter.  NOTE: Drake CMS has only a beta version available, and the vendor has previously stated &quot;We do not consider security reports valid until the first official release of Drake CMS.&quot;</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/464272/100/0/threaded">20070330 DrakeCMS multiple vulerabilities</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33333">drakecms-dprivate-directory-traversal(33333)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2522">2522</ref></refs><vuln_soft><prod name="Drake CMS" vendor="Drake Team"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-04-05" name="CVE-2007-1851" published="2007-04-03" seq="2007-1851" severity="High" type="CVE"><desc><descript source="cve">Multiple directory traversal vulnerabilities in Really Simple PHP and Ajax (RSPA) 2007-03-23 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the __class parameter to (1) Controller_v4.php or (2) Controller_v5.php.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3641">3641</ref><ref source="" url="http://www.bugtraq.ir/articles/advisory/RSPA_File_Inclusion/6"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1190">ADV-2007-1190</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24671">24671</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33357">
rspa-class-file-include(33357)</ref></refs><vuln_soft><prod name="Really Simple PHP and Ajax" vendor="Really Simple PHP and Ajax"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-07-03" name="CVE-2007-1852" published="2007-04-03" seq="2007-1852" severity="Medium" type="CVE"><desc><descript source="cve">** DISPUTED **  Multiple PHP remote file inclusion vulnerabilities in 2BGal 3.1.1 allow remote attackers to execute arbitrary PHP code via a URL in the lang_filename parameter to (1) index.php or (2) backupdb.inc.php in admin/, or other unspecified files, different vectors than CVE-2006-5505. NOTE: this issue has been disputed by CVE, since the lang_filename variable is defined before it is used.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/464458/100/0/threaded">20070331 2BGal 3.1.1 &lt;= (admin/index.php) Remote File Include Vulnerability</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33375">2bgal-langfilename-file-include(33375)</ref><ref source="VIM" url="http://attrition.org/pipermail/vim/2007-April/001565.html">20070427 FALSE -&gt; 2bgal RFI</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2517">2517</ref></refs><vuln_soft><prod name="2Bgal" vendor="ben3w"><vers num="3.1.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0" modified="2007-04-05" name="CVE-2007-1853" published="2007-04-03" seq="2007-1853" severity="Medium" type="CVE"><desc><descript source="cve">Unspecified vulnerability in Hitachi JP1/HiCommand DeviceManager, Global Link Availability Manager, Replication Monitor, Tiered Storage Manager, and Tuning Manager allows local users to obtain authentication information via unspecified vectors.</descript></desc><loss_types><conf/></loss_types><range><network/></range><refs><ref source="" url="http://www.hitachi-support.com/security_e/vuls_e/HS07-007_e/index-e.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/23210">23210</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1169">ADV-2007-1169</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24684">24684</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33328">hitachi-hicommand-information-disclosure(33328)</ref></refs><vuln_soft><prod name="JP1-HiCommand Global Link Availability Manager" vendor="Hitachi"><vers num="05_00"/><vers num="05_10"/><vers num="05_20"/><vers num="05_30"/><vers num="05_40"/><vers num="05_50"/><vers num="05_60"/></prod><prod name="JP1-HiCommand Tuning Manager" vendor="Hitachi"><vers num="04_00"/><vers num="05_00"/><vers num="05_10"/><vers num="05_20"/><vers num="05_30"/><vers num="05_40"/><vers num="05_50"/></prod><prod name="JP1-HiCommand Replication Monitor" vendor="Hitachi"><vers edition="Windows" num="04_00"/><vers edition="Windows" num="05_00"/><vers num="05_10"/><vers num="05_20"/><vers num="05_30"/><vers num="05_40"/><vers edition="Windows" num="05_50"/><vers num="05_50_01"/><vers num="05_50_02"/><vers num="05_60"/></prod><prod name="JP1-HiCommand Tiered Storage Manager" vendor="Hitachi"><vers edition="Solaris" num="04_00"/><vers edition="Solaris" num="05_00"/><vers num="05_10"/><vers num="05_20"/><vers num="05_30"/><vers num="05_40"/><vers edition="Windows" num="05_50"/><vers num="05_50_01"/><vers num="05_50_02"/></prod><prod name="JP1-HiCommand Device Manager" vendor="Hitachi"><vers num="05_00"/><vers num="05_10"/><vers num="05_10_01"/><vers num="05_10_02"/><vers num="05_10_03"/><vers num="05_10_04"/><vers num="05_10_05"/><vers num="05_50"/><vers num="05_50_01"/><vers num="05_50_02"/><vers num="05_60"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0" modified="2007-04-05" name="CVE-2007-1854" published="2007-04-03" seq="2007-1854" severity="Medium" type="CVE"><desc><descript source="cve">Unspecified vulnerability in Hitachi Cosminexus Component Container 07-00 through 07-00-10, and 07-10 through 07-10-03, as used in uCosminexus Application Server Enterprise and Standard; uCosminexus Service Platform; uCosminexus Developer Standard and Professional; uCosminexus Service Architect; Electronic Form Workflow Standard Set, Professional Library Set, and Developer Client Set; and uCosminexus ERP Integrator, does not properly manage session information, which has an unspecified impact related to &quot;unintended other requests.&quot;</descript></desc><loss_types><conf/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref source="" url="http://www.hitachi-support.com/security_e/vuls_e/HS07-006_e/index-e.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/23213">23213</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1170">ADV-2007-1170</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24683">24683</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33318">hitachi-container-information-disclosure(33318)</ref></refs><vuln_soft><prod name="uCosminexus Application Server" vendor="Hitachi"><vers edition="Enterprise" num=""/><vers edition="Standard" num=""/></prod><prod name="uCosminexus ERP Integrator" vendor="Hitachi"><vers num=""/></prod><prod name="uCosminexus Developer" vendor="Hitachi"><vers edition="Standard" num=""/><vers edition="Professional" num=""/></prod><prod name="Electronic Form Workflow" vendor="Hitachi"><vers edition="Standard Set" num=""/><vers edition="Professional Library Set" num=""/><vers edition="Developer Client Set" num=""/></prod><prod name="Cosminexus Component Container" vendor="Hitachi"><vers edition="Windows" num="07_10_04"/><vers edition="Linux" num="07_10_04"/><vers edition="Linux IPF" num="07_10_04"/><vers edition="HP-UX IPF" num="07_10_04"/><vers edition="AIX" num="07_10_04"/><vers edition="HP-UX" num="07_10_04"/><vers edition="Windows" num="07_00_11"/><vers edition="AIX" num="07_00_11"/><vers edition="Linux" num="07_00_11"/><vers edition="HP-UX IPF" num="07_00_11"/><vers edition="Windows" num="07_00_11"/><vers edition="AIX" num="07_00_11"/><vers edition="Linux" num="07_00_11"/><vers edition="HP-UX IPF" num="07_00_11"/><vers edition="Windows" num="07_10_04"/><vers edition="Linux" num="07_10_04"/><vers edition="Linux IPF" num="07_10_04"/><vers edition="HP-UX IPF" num="07_10_04"/><vers edition="AIX" num="07_10_04"/><vers edition="HP-UX" num="07_10_04"/><vers edition="Windows" num="07_00_11"/><vers edition="AIX" num="07_00_11"/><vers edition="Linux" num="07_00_11"/><vers edition="HP-UX IPF" num="07_00_11"/><vers edition="Windows" num="07_10_04"/><vers edition="Linux" num="07_10_04"/><vers edition="Linux IPF" num="07_10_04"/><vers edition="HP-UX IPF" num="07_10_04"/><vers edition="AIX" num="07_10_04"/><vers edition="HP-UX" num="07_10_04"/><vers edition="Windows" num="07_00_11"/><vers edition="AIX" num="07_00_11"/><vers edition="Linux" num="07_00_11"/><vers edition="HP-UX IPF" num="07_00_11"/><vers edition="Windows" num="07_10_04"/><vers edition="Linux" num="07_10_04"/><vers edition="Linux IPF" num="07_10_04"/><vers edition="HP-UX IPF" num="07_10_04"/><vers edition="AIX" num="07_10_04"/><vers edition="HP-UX" num="07_10_04"/><vers edition="Windows" num="07_00_11"/><vers edition="AIX" num="07_00_11"/><vers edition="Linux" num="07_00_11"/><vers edition="HP-UX IPF" num="07_00_11"/><vers edition="Windows" num="07_10_04"/><vers edition="Linux" num="07_10_04"/><vers edition="Linux IPF" num="07_10_04"/><vers edition="HP-UX IPF" num="07_10_04"/><vers edition="AIX" num="07_10_04"/><vers edition="HP-UX" num="07_10_04"/><vers edition="Windows" num="07_00_11"/><vers edition="AIX" num="07_00_11"/><vers edition="Linux" num="07_00_11"/><vers edition="HP-UX IPF" num="07_00_11"/><vers edition="Windows" num="07_10_04"/><vers edition="Linux" num="07_10_04"/><vers edition="Linux IPF" num="07_10_04"/><vers edition="HP-UX IPF" num="07_10_04"/><vers edition="AIX" num="07_10_04"/><vers edition="HP-UX" num="07_10_04"/></prod><prod name="uCosminexus Service Platform" vendor="Hitachi"><vers num=""/></prod><prod name="uCosminexus Service Architect" vendor="Hitachi"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-04-05" name="CVE-2007-1855" published="2007-04-03" seq="2007-1855" severity="High" type="CVE"><desc><descript source="cve">Multiple PHP remote file inclusion vulnerabilities in smarty/smarty_class.php in Shop-Script FREE allow remote attackers to execute arbitrary PHP code via a URL in the (1) _smarty_compile_path, (2) smarty_compile_path, (3) get_plugin_filepath, (4) smarty_dir, and (5) filename parameters.  NOTE: this issue might be related to CVE-2006-7105.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/464350/100/0/threaded">20070331 Remot File Include In Shop-SCRIPT FREE</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33339">
shopscriptfree-smarty-file-include(33339)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2520">2520</ref></refs><vuln_soft><prod name="Shop-Script" vendor="WebAsyst LLC"><vers edition="FREE" num=""/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0" modified="2007-04-18" name="CVE-2007-1856" published="2007-04-17" seq="2007-1856" severity="Low" type="CVE"><desc><descript source="cve">Vixie Cron before 4.1-r10 on Gentoo Linux is installed with insecure permissions, which allows local users to cause a denial of service (cron failure) by creating hard links, which results in a failed st_nlink check in database.c.</descript></desc><loss_types><avail/></loss_types><vuln_types><access/><config/></vuln_types><range><local/></range><refs><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200704-11.xml">GLSA-200704-11</ref><ref source="BID" url="http://www.securityfocus.com/bid/23520">23520</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2007_007_suse.html">
SUSE-SR:2007:007</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24905">
24905</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24995">
24995</ref><ref source="REDHAT" url="http://rhn.redhat.com/errata/RHSA-2007-0345.html">
RHSA-2007:0345</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25321">
25321</ref><ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2007-September/065902.html">20070920 VMSA-2007-0006 Critical security updates for all supported versions of VMware ESX Server, VMware Server, VMware Workstation, VMware ACE, and VMware Player</ref><ref source="" url="http://support.avaya.com/elmodocs2/security/ASA-2007-261.htm"></ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:234">MDKSA-2007:234</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/3229">ADV-2007-3229</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1018081">1018081</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25723">25723</ref><ref source="SECUNIA" url="http://secunia.com/advisories/26909">26909</ref><ref source="SECUNIA" url="http://secunia.com/advisories/27706">27706</ref><ref source="SECUNIA" url="http://secunia.com/advisories/27886">27886</ref></refs><vuln_soft><prod name="Vixie Cron" vendor="Paul Vixie"><vers num="4.1" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="2.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="2.9" CVSS_score="2.6" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:N/A:N)" CVSS_version="2.0" modified="2007-10-03" name="CVE-2007-1858" published="2007-05-09" seq="2007-1858" severity="Low" type="CVE"><desc><descript source="cve">The default SSL cipher configuration in Apache Tomcat 4.1.28 through 4.1.31, 5.0.0 through 5.0.30, and 5.5.0 through 5.5.17 uses certain insecure ciphers, including the anonymous cipher, which allows remote attackers to obtain sensitive information or have other, unspecified impacts.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref patch="1" source="" url="http://tomcat.apache.org/security-4.html"></ref><ref patch="1" source="" url="http://tomcat.apache.org/security-5.html"></ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1729">ADV-2007-1729</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/34212">tomcat-ssl-security-bypass(34212)</ref><ref source="" url="http://support.avaya.com/elmodocs2/security/ASA-2007-206.htm"></ref><ref source="SUSE" url="http://lists.opensuse.org/opensuse-security-announce/2008-03/msg00008.html">SUSE-SR:2008:007</ref><ref source="BID" url="http://www.securityfocus.com/bid/28482">28482</ref><ref source="SECUNIA" url="http://secunia.com/advisories/29392">29392</ref></refs><vuln_soft><prod name="Tomcat" vendor="Apache Software Foundation"><vers num="4.1.28"/><vers num="4.1.31"/><vers num="5.0.0"/><vers num="5.0.1"/><vers num="5.0.10"/><vers num="5.0.11"/><vers num="5.0.12"/><vers num="5.0.13"/><vers num="5.0.14"/><vers num="5.0.15"/><vers num="5.0.16"/><vers num="5.0.17"/><vers num="5.0.18"/><vers num="5.0.19"/><vers num="5.0.2"/><vers num="5.0.21"/><vers num="5.0.22"/><vers num="5.0.23"/><vers num="5.0.24"/><vers num="5.0.25"/><vers num="5.0.26"/><vers num="5.0.27"/><vers num="5.0.28"/><vers num="5.0.29"/><vers num="5.0.30"/><vers num="5.5.0"/><vers num="5.5.1"/><vers num="5.5.2"/><vers num="5.5.3"/><vers num="5.5.4"/><vers num="5.5.5"/><vers num="5.5.6"/><vers num="5.5.7"/><vers num="5.5.8"/><vers num="5.5.9"/><vers num="5.5.10"/><vers num="5.5.11"/><vers num="5.5.12"/><vers num="5.5.13"/><vers num="5.5.14"/><vers num="5.5.15"/><vers num="5.5.16"/><vers num="5.5.17"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-12-31" name="CVE-2007-1859" published="2007-05-02" seq="2007-1859" severity="Medium" type="CVE"><desc><descript source="cve">XScreenSaver 4.10, when using a remote directory service for credentials, does not properly handle the results from the getpwuid function in drivers/lock.c when there is no network connectivity, which causes XScreenSaver to crash and unlock the screen and allows local users to bypass authentication.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2007-0322.html">RHSA-2007:0322</ref><ref source="" url="https://issues.rpath.com/browse/RPL-1293"></ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:097">MDKSA-2007:097</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2007_9_sr.html">SUSE-SR:2007:009</ref><ref source="BID" url="http://www.securityfocus.com/bid/23783">23783</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017996">1017996</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/25065">25065</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/25105">25105</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/25118">25118</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/25116">25116</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/25119">25119</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/34054">xscreensaver-getpwuid-authentication-bypass(34054)</ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200705-14.xml">GLSA-200705-14</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/25225">25225</ref><ref source="UBUNTU" url="http://www.ubuntu.com/usn/usn-474-1">USN-474-1</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/25610">25610</ref></refs><vuln_soft><prod name="Xscreensaver" vendor="Xscreensaver"><vers num="4.10"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0" modified="2007-12-29" name="CVE-2007-1860" published="2007-05-25" seq="2007-1860" severity="Medium" type="CVE"><desc><descript source="cve">mod_jk in Apache Tomcat JK Web Server Connector 1.2.x before 1.2.23 decodes request URLs within the Apache HTTP Server before passing the URL to Tomcat, which allows remote attackers to access protected pages via a crafted prefix JkMount, possibly involving double-encoded .. (dot dot) sequences and directory traversal, a related issue to CVE-2007-0450.</descript></desc><loss_types><conf/></loss_types><vuln_types><access/><input/></vuln_types><range><network/></range><refs><ref patch="1" source="" url="http://tomcat.apache.org/connectors-doc/news/20070301.html#20070518.1"></ref><ref patch="1" source="" url="http://tomcat.apache.org/security-jk.html"></ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/25383">25383</ref><ref source="" url="http://docs.info.apple.com/article.html?artnum=306172"></ref><ref source="APPLE" url="http://lists.apple.com/archives/security-announce//2007/Jul/msg00004.html">APPLE-SA-2007-07-31</ref><ref source="DEBIAN" url="http://www.debian.org/security/2007/dsa-1312">DSA-1312</ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200708-15.xml">GLSA-200708-15</ref><ref source="HP" url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01178795">HPSBUX02262</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2007-0379.html">RHSA-2007:0379</ref><ref source="BID" url="http://www.securityfocus.com/bid/24147">24147</ref><ref source="BID" url="http://www.securityfocus.com/bid/25159">25159</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1941">ADV-2007-1941</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/2732">ADV-2007-2732</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/3386">ADV-2007-3386</ref><ref source="OSVDB" url="http://www.osvdb.org/34877">34877</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1018138">1018138</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/25701">25701</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/26235">26235</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/26512">26512</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/27037">27037</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/34496">tomcat-jkconnector-security-bypass(34496)</ref><ref source="SUSE" url="http://lists.opensuse.org/opensuse-security-announce/2008-03/msg00001.html">SUSE-SR:2008:005</ref><ref source="SECUNIA" url="http://secunia.com/advisories/29242">29242</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2008-0261.html">RHSA-2008:0261</ref></refs><vuln_soft><prod name="Tomcat JK Web Server Connector" vendor="Apache Software Foundation"><vers num="1.2.22" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.9" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.9" CVSS_score="4.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:C)" CVSS_version="2.0" modified="2007-10-05" name="CVE-2007-1861" published="2007-05-07" seq="2007-1861" severity="Medium" type="CVE"><desc><descript source="cve">The nl_fib_lookup function in net/ipv4/fib_frontend.c in Linux Kernel before 2.6.20.8 allows attackers to cause a denial of service (kernel panic) via NETLINK_FIB_LOOKUP replies, which trigger infinite recursion and a stack overflow.</descript></desc><loss_types><avail/></loss_types><vuln_types><input bound="1"/></vuln_types><range><local/></range><refs><ref patch="1" source="" url="https://issues.rpath.com/browse/RPL-1309"></ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/25083">25083</ref><ref source="" url="http://kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.20.8"></ref><ref source="" url="https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=237913"></ref><ref source="BID" url="http://www.securityfocus.com/bid/23677">23677</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1595">ADV-2007-1595</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/25030">25030</ref><ref source="DEBIAN" url="http://www.debian.org/security/2007/dsa-1289">DSA-1289</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2007-0347.html">RHSA-2007:0347</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/25228">25228</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/25288">25288</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/471457">20070615 rPSA-2007-0124-1 kernel xen</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:171">MDKSA-2007:171</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2007_43_kernel.html">SUSE-SA:2007:043</ref><ref source="UBUNTU" url="http://www.ubuntu.com/usn/usn-486-1">USN-486-1</ref><ref source="UBUNTU" url="http://www.ubuntu.com/usn/usn-489-1">USN-489-1</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25691">25691</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25961">25961</ref><ref source="SECUNIA" url="http://secunia.com/advisories/26133">26133</ref><ref source="SECUNIA" url="http://secunia.com/advisories/26139">26139</ref><ref source="SECUNIA" url="http://secunia.com/advisories/26620">26620</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/34014">kernel-netlinkfiblookup-dos(34014)</ref></refs><vuln_soft><prod name="Kernel" vendor="Linux"><vers num="2.6.19" prev="1"/></prod><prod name="rPath Linux" vendor="rPath"><vers num="1"/><vers num="1.0.1"/><vers num="1.0.2"/><vers num="1.0.3"/><vers num="1.0.4"/><vers num="1.0.5"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0" modified="2007-06-06" name="CVE-2007-1862" published="2007-06-04" seq="2007-1862" severity="Medium" type="CVE"><desc><descript source="cve">The recall_headers function in mod_mem_cache in Apache 2.2.4 does not properly copy all levels of header data, which can cause Apache to return HTTP headers containing previously used data, which could be used by remote attackers to obtain potentially sensitive information.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref source="" url="http://issues.apache.org/bugzilla/show_bug.cgi?id=41551"></ref><ref source="" url="http://people.apache.org/~covener/2.2.x-mod_memcache-poolmgmt.diff"></ref><ref source="" url="http://httpd.apache.org/security/vulnerabilities_22.html"></ref><ref source="" url="http://bugs.gentoo.org/show_bug.cgi?id=186219"></ref><ref source="FEDORA" url="http://www.redhat.com/archives/fedora-package-announce/2007-September/msg00320.html">FEDORA-2007-2214</ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200711-06.xml">GLSA-200711-06</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:127">MDKSA-2007:127</ref><ref source="BID" url="http://www.securityfocus.com/bid/24553">24553</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/2231">ADV-2007-2231</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/2727">ADV-2007-2727</ref><ref source="SECUNIA" url="http://secunia.com/advisories/26273">26273</ref><ref source="SECUNIA" url="http://secunia.com/advisories/26842">26842</ref><ref source="SECUNIA" url="http://secunia.com/advisories/27563">27563</ref></refs><vuln_soft><prod name="Apache HTTP Server" vendor="Apache Software Foundation"><vers num="2.2.4"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0" modified="2007-07-03" name="CVE-2007-1863" published="2007-06-27" seq="2007-1863" severity="Medium" type="CVE"><desc><descript source="cve">cache_util.c in the mod_cache module in Apache HTTP Server (httpd), when caching is enabled and a threaded Multi-Processing Module (MPM) is used, allows remote attackers to cause a denial of service (child processing handler crash) via a request with the (1) s-maxage, (2) max-age, (3) min-fresh, or (4) max-stale Cache-Control headers without a value.</descript></desc><loss_types><avail/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref source="" url="http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=244658"></ref><ref source="" url="http://svn.apache.org/viewvc?view=rev&amp;revision=535617"></ref><ref source="REDHAT" url="http://rhn.redhat.com/errata/RHSA-2007-0534.html">RHSA-2007:0534</ref><ref source="REDHAT" url="http://rhn.redhat.com/errata/RHSA-2007-0556.html">RHSA-2007:0556</ref><ref source="BID" url="http://www.securityfocus.com/bid/24649">24649</ref><ref source="" url="https://issues.rpath.com/browse/RPL-1500"></ref><ref source="" url="http://httpd.apache.org/security/vulnerabilities_20.html"></ref><ref source="" url="http://httpd.apache.org/security/vulnerabilities_22.html"></ref><ref source="" url="http://support.avaya.com/elmodocs2/security/ASA-2007-353.htm"></ref><ref source="" url="http://bugs.gentoo.org/show_bug.cgi?id=186219"></ref><ref source="AIXAPAR" url="http://www-1.ibm.com/support/docview.wss?uid=swg1PK49355">PK49355</ref><ref source="AIXAPAR" url="http://www-1.ibm.com/support/docview.wss?uid=swg1PK52702">PK52702</ref><ref source="FEDORA" url="http://www.redhat.com/archives/fedora-package-announce/2007-September/msg00320.html">FEDORA-2007-2214</ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200711-06.xml">GLSA-200711-06</ref><ref source="HP" url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01178795">HPSBUX02262</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:140">MDKSA-2007:140</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:141">MDKSA-2007:141</ref><ref source="REDHAT" url="https://rhn.redhat.com/errata/RHSA-2007-0533.html">RHSA-2007:0533</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2007-0557.html">RHSA-2007:0557</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2007_61_apache2.html">SUSE-SA:2007:061</ref><ref source="TRUSTIX" url="http://www.trustix.org/errata/2007/0026/">2007-0026</ref><ref source="UBUNTU" url="http://www.ubuntu.com/usn/usn-499-1">USN-499-1</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/2727">ADV-2007-2727</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/3283">ADV-2007-3283</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/3386">ADV-2007-3386</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1018303">1018303</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25830">25830</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25873">25873</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25920">25920</ref><ref source="SECUNIA" url="http://secunia.com/advisories/26273">26273</ref><ref source="SECUNIA" url="http://secunia.com/advisories/26443">26443</ref><ref source="SECUNIA" url="http://secunia.com/advisories/26508">26508</ref><ref source="SECUNIA" url="http://secunia.com/advisories/26822">26822</ref><ref source="SECUNIA" url="http://secunia.com/advisories/26842">26842</ref><ref source="SECUNIA" url="http://secunia.com/advisories/26993">26993</ref><ref source="SECUNIA" url="http://secunia.com/advisories/27037">27037</ref><ref source="SECUNIA" url="http://secunia.com/advisories/27563">27563</ref><ref source="SECUNIA" url="http://secunia.com/advisories/27732">27732</ref><ref source="" url="http://www.fujitsu.com/global/support/software/security/products-f/interstage-200802e.html"></ref><ref source="SECUNIA" url="http://secunia.com/advisories/28606">28606</ref><ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2008//May/msg00001.html">APPLE-SA-2008-05-28</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA08-150A.html">TA08-150A</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/1697">ADV-2008-1697</ref><ref source="SECUNIA" url="http://secunia.com/advisories/30430">30430</ref></refs><vuln_soft><prod name="Mac OS X Server" vendor="Apple"><vers num="10.0"/><vers num="10.1"/><vers num="10.1.1"/><vers num="10.1.2"/><vers num="10.1.3"/><vers num="10.1.4"/><vers num="10.1.5"/><vers num="10.2"/><vers num="10.2.1"/><vers num="10.2.2"/><vers num="10.2.3"/><vers num="10.2.4"/><vers num="10.2.5"/><vers num="10.2.6"/><vers num="10.2.7"/><vers num="10.2.8"/><vers num="10.3"/><vers num="10.3.1"/><vers num="10.3.1"/><vers num="10.3.2"/><vers num="10.3.2"/><vers num="10.3.3"/><vers num="10.3.3"/><vers num="10.3.4"/><vers num="10.3.4"/><vers num="10.3.5"/><vers num="10.3.5"/><vers num="10.3.6"/><vers num="10.3.6"/><vers num="10.3.7"/><vers num="10.3.7"/><vers num="10.3.8"/><vers num="10.3.8"/><vers num="10.3.9"/><vers num="10.3.9"/><vers num="10.4"/><vers num="10.4"/><vers num="10.4.1"/><vers num="10.4.1"/><vers num="10.4.2"/><vers num="10.4.2"/><vers num="10.4.3"/><vers num="10.4.3"/><vers num="10.4.4"/><vers num="10.4.4"/><vers num="10.4.5"/><vers num="10.4.5"/><vers num="10.4.6"/><vers num="10.4.6"/><vers num="10.4.6"/><vers num="10.4.7"/><vers num="10.4.7"/><vers num="10.4.7"/><vers num="10.4.8"/><vers num="10.4.8"/><vers num="10.4.8"/><vers num="10.4.9"/><vers num="10.4.9"/><vers num="10.4.9"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-10-05" name="CVE-2007-1864" published="2007-05-08" seq="2007-1864" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in the bundled libxmlrpc library in PHP before 4.4.7, and 5.x before 5.2.2, has unknown impact and remote attack vectors.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref patch="1" source="" url="http://us2.php.net/releases/4_4_7.php"></ref><ref patch="1" source="" url="http://us2.php.net/releases/5_2_2.php"></ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2007:102">MDKSA-2007:102</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2007:103">MDKSA-2007:103</ref><ref source="REDHAT" url="https://rhn.redhat.com/errata/RHSA-2007-0348.html">RHSA-2007:0348</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2007-0349.html">RHSA-2007:0349</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2007-0355.html">RHSA-2007:0355</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1018024">1018024</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/25187">25187</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/25191">25191</ref><ref source="TRUSTIX" url="http://www.trustix.org/errata/2007/0017/">2007-0017</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/25255">25255</ref><ref source="" url="http://support.avaya.com/elmodocs2/security/ASA-2007-231.htm"></ref><ref source="" url="https://issues.rpath.com/browse/RPL-1693"></ref><ref source="DEBIAN" url="http://www.debian.org/security/2007/dsa-1330">DSA-1330</ref><ref source="DEBIAN" url="http://www.debian.org/security/2007/dsa-1331">DSA-1331</ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200705-19.xml">GLSA-200705-19</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:102">MDKSA-2007:102</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:103">MDKSA-2007:103</ref><ref source="SUSE" url="http://lists.opensuse.org/opensuse-security-announce/2007-07/msg00006.html">SUSE-SA:2007:044</ref><ref source="UBUNTU" url="http://www.ubuntu.com/usn/usn-485-1">USN-485-1</ref><ref source="BID" url="http://www.securityfocus.com/bid/23813">23813</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/2187">ADV-2007-2187</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25445">25445</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25660">25660</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25938">25938</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25945">25945</ref><ref source="SECUNIA" url="http://secunia.com/advisories/26048">26048</ref><ref source="SECUNIA" url="http://secunia.com/advisories/26102">26102</ref><ref source="SECUNIA" url="http://secunia.com/advisories/27377">27377</ref></refs><vuln_soft><prod name="PHP" vendor="PHP"><vers num="4.4.6" prev="1"/><vers num="5.2.1" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="1.9" CVSS_exploit_subscore="3.4" CVSS_impact_subscore="2.9" CVSS_score="1.9" CVSS_vector="(AV:L/AC:M/Au:N/C:P/I:N/A:N)" CVSS_version="2.0" modified="2007-10-03" name="CVE-2007-1865" published="2007-09-18" seq="2007-1865" severity="Low" type="CVE"><desc><descript source="cve">** DISPUTED **  The ipv6_getsockopt_sticky function in the kernel in Red Hat Enterprise Linux (RHEL) Beta 5.1.0 allows local users to obtain sensitive information (kernel memory contents) via a negative value of the len parameter.  NOTE: this issue has been disputed in a bug comment, stating that &quot;len is ignored when copying header info to the user&apos;s buffer.&quot;</descript></desc><loss_types><conf/></loss_types><range><local/></range><refs><ref source="" url="https://bugzilla.redhat.com/show_bug.cgi?id=232045"></ref></refs><vuln_soft><prod name="enterprise_linux" vendor="redhat"><vers num="5.1.0 Beta"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-04-06" name="CVE-2007-1866" published="2007-04-04" seq="2007-1866" severity="High" type="CVE"><desc><descript source="cve">Stack-based buffer overflow in the dns_decode_reverse_name function in dns_decode.c in dproxy-nexgen allows remote attackers to execute arbitrary code by sending a crafted packet to port 53/udp, a different issue than CVE-2007-1465.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2007-March/053302.html">20070331 Re: dproxy-nexgen remote</ref><ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2007-March/053289.html">20070331 dproxy-nexgen remote</ref><ref source="" url="http://dproxy.cvs.sourceforge.net/dproxy/dproxy-nexgen/dns_decode.c?revision=1.10&amp;view=markup"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1194">ADV-2007-1194</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24688">24688</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2518">2518</ref></refs><vuln_soft><prod name="dproxy" vendor="dproxy"><vers num="nexgen"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-04-06" name="CVE-2007-1867" published="2007-04-04" seq="2007-1867" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in IrfanView 3.99 allows remote attackers to execute arbitrary code via a crafted animated cursor (ANI) file.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref source="MILW0RM" url="http://milw0rm.com/exploits/3648">3648</ref><ref source="BID" url="http://www.securityfocus.com/bid/23262">23262</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1210">ADV-2007-1210</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24725">24725</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33386">
irfanview-ani-bo(33386)</ref></refs><vuln_soft><prod name="IrfanView" vendor="IrfanView"><vers num="3.99"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-04-06" name="CVE-2007-1868" published="2007-04-04" seq="2007-1868" severity="High" type="CVE"><desc><descript source="cve">The management service in IBM Tivoli Provisioning Manager for OS Deployment before 5.1 Fix Pack 2 does not properly handle multipart/form-data in HTTP POST requests, which allows remote attackers to execute arbitrary code or cause a denial of service (daemon crash) via crafted POST requests to port 8080/tcp or 443/tcp.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><access/><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="IDEFENSE" url="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=498">20070331 IBM Tivoli Provisioning Manager for OS Deployment Multiple Vulnerabilities</ref><ref patch="1" source="" url="http://www-1.ibm.com/support/docview.wss?uid=swg24015347"></ref><ref source="BID" url="http://www.securityfocus.com/bid/23264">23264</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1199">ADV-2007-1199</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/24717">24717</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017840">
1017840</ref></refs><vuln_soft><prod name="Tivoli Provisioning Manager OS Deployment" vendor="IBM"><vers num="5.1.0.116"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0" modified="2007-04-18" name="CVE-2007-1869" published="2007-04-17" seq="2007-1869" severity="Medium" type="CVE"><desc><descript source="cve">lighttpd 1.4.12 and 1.4.13 allows remote attackers to cause a denial of service (cpu and resource consumption) by disconnecting while lighttpd is parsing CRLF sequences, which triggers an infinite loop and file descriptor consumption.</descript></desc><loss_types><avail/></loss_types><vuln_types><design/><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="" url="http://www.lighttpd.net/assets/2007/4/13/lighttpd_sa2007_01.txt"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1399">ADV-2007-1399</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24886">24886</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2007_007_suse.html">
SUSE-SR:2007:007</ref><ref source="BID" url="http://www.securityfocus.com/bid/23515">
23515</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24995">
24995</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33671">
lighttpd-rnrn-dos(33671)</ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200705-07.xml">
GLSA-200705-07</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25166">
25166</ref><ref source="" url="https://issues.rpath.com/browse/RPL-1218"></ref><ref source="SECUNIA" url="http://secunia.com/advisories/24947">
24947</ref><ref source="DEBIAN" url="http://www.debian.org/security/2007/dsa-1303">DSA-1303</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25613">25613</ref></refs><vuln_soft><prod name="lighttpd" vendor="lighttpd"><vers num="1.4.12"/><vers num="1.4.13"/></prod></vuln_soft></entry><entry CVSS_base_score="7.8" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.9" CVSS_score="7.8" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_version="2.0" modified="2007-04-18" name="CVE-2007-1870" published="2007-04-17" seq="2007-1870" severity="High" type="CVE"><desc><descript source="cve">lighttpd before 1.4.14 allows attackers to cause a denial of service (crash) via a request to a file whose mtime is 0, which results in a NULL pointer dereference.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref source="" url="http://www.lighttpd.net/assets/2007/4/13/lighttpd_sa2007_02.txt"></ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1399">ADV-2007-1399</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/24886">24886</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2007_007_suse.html">
SUSE-SR:2007:007</ref><ref source="BID" url="http://www.securityfocus.com/bid/23515">
23515</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24995">
24995</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33678">
lighttpd-mtime-dos(33678)</ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200705-07.xml">
GLSA-200705-07</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25166">
25166</ref><ref source="" url="https://issues.rpath.com/browse/RPL-1218"></ref><ref source="SECUNIA" url="http://secunia.com/advisories/24947">
24947</ref><ref source="DEBIAN" url="http://www.debian.org/security/2007/dsa-1303">DSA-1303</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25613">25613</ref></refs><vuln_soft><prod name="lighttpd" vendor="lighttpd"><vers num="1.3.0"/><vers num="1.3.1"/><vers num="1.3.10"/><vers num="1.3.11"/><vers num="1.3.12"/><vers num="1.3.13"/><vers num="1.3.14"/><vers num="1.3.15"/><vers num="1.3.16"/><vers num="1.3.2"/><vers num="1.3.3"/><vers num="1.3.4"/><vers num="1.3.5"/><vers num="1.3.6"/><vers num="1.3.7"/><vers num="1.3.8"/><vers num="1.3.9"/><vers num="1.4.0"/><vers num="1.4.1"/><vers num="1.4.10"/><vers num="1.4.12"/><vers num="1.4.13"/><vers num="1.4.2"/><vers num="1.4.3"/><vers num="1.4.4"/><vers num="1.4.5"/><vers num="1.4.6"/><vers num="1.4.7"/><vers num="1.4.8"/><vers num="1.4.9"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" modified="2007-04-17" name="CVE-2007-1871" published="2007-04-13" seq="2007-1871" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in chcounter 3.1.3 allows remote attackers to inject arbitrary web script or HTML via the login_name parameter to /stats/.</descript></desc><impacts><impact source="nvd">Successful exploitation requires that the target user is not logged in.</impact></impacts><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/465486/100/0/threaded">20070411 CVE-2007-1871: Cross site scripting in chcounter 3.1.3</ref><ref source="" url="http://int21.de/cve/CVE-2007-1871-chcounter.txt"></ref><ref source="BID" url="http://www.securityfocus.com/bid/23462">23462</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1371">ADV-2007-1371</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24879">24879</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2569">2569</ref></refs><vuln_soft><prod name="chCounter" vendor="chCounter"><vers num="3.1.3"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" modified="2007-04-17" name="CVE-2007-1872" published="2007-04-13" seq="2007-1872" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in toendaCMS 1.5.3 allows remote attackers to inject arbitrary web script or HTML via the searchword parameter in a search id.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/465487/100/0/threaded">20070411 CVE-2007-1872: Cross site scripting in toendaCMS 1.5.3</ref><ref source="" url="http://int21.de/cve/CVE-2007-1872-toendacms.txt"></ref><ref source="BID" url="http://www.securityfocus.com/bid/23453">23453</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1372">ADV-2007-1372</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24869">24869</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33622">
toendacms-search-xss(33622)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2568">2568</ref></refs><vuln_soft><prod name="toendaCMS" vendor="Toenda Software Development"><vers num="1.5.3"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" modified="2007-04-17" name="CVE-2007-1873" published="2007-04-13" seq="2007-1873" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in mephisto 0.7.3 allows remote attackers to inject arbitrary web script or HTML via the q parameter to the search script.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/465484/100/0/threaded">20070411 Cross site scripting in mephisto 0.7.3</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/465548/100/0/threaded">20070412 Re: Cross site scripting in mephisto 0.7.3</ref><ref source="" url="http://int21.de/cve/CVE-2007-1873-mephisto.txt"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1373">ADV-2007-1373</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24870">
24870</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33620">
mephisto-search-xss(33620)</ref><ref source="BID" url="http://www.securityfocus.com/bid/23141">23141</ref></refs><vuln_soft><prod name="Mephisto" vendor="Mephisto"><vers num="0.7.3"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-04-17" name="CVE-2007-1874" published="2007-04-11" seq="2007-1874" severity="High" type="CVE"><desc><descript source="cve">Adobe ColdFusion MX 7 for Linux and Solaris uses insecure permissions for certain scripts and directories, which allows local users to execute arbitrary code or obtain sensitive information via the (1) CFMX7DreamWeaverExtensions.mxp, (2) CFReportBuilderInstaller.exe, (3) .com.zerog.registry.xml, (4) uninstall.lax, (5) license.txt, (6) Readme.htm, (7) .com.zerog.registry.xml, (8) k2adminstop, or (9) k2adminstart files; or (10) certain files in lib/wsconfig/.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="" url="http://www.adobe.com/support/security/bulletins/apsb07-08.html"></ref><ref adv="1" source="IDEFENSE" url="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=510">20070410 Adobe Macromedia ColdFusion MX7 Insecure File Permissions Vulnerability</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24850">24850</ref><ref source="BID" url="http://www.securityfocus.com/bid/23405">
23405</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1341">
ADV-2007-1341</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017899">
1017899</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33571">
coldfusion-verity-privilege-escalation(33571)</ref></refs><vuln_soft><prod name="ColdFusion MX" vendor="Adobe"><vers edition="Linux" num="7.0"/><vers edition="Solaris" num="7.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-05-25" name="CVE-2007-1876" published="2007-05-02" seq="2007-1876" severity="High" type="CVE"><desc><descript source="cve">VMware Workstation before 5.5.4, when running a 64-bit Windows guest on a 64-bit host, allows local users to &quot;corrupt the virtual machine&apos;s register context&quot; by debugging a local program and stepping into a &quot;syscall instruction.&quot;</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><other/></vuln_types><range><local/></range><refs><ref patch="1" source="" url="http://www.vmware.com/support/ws55/doc/releasenotes_ws55.html#554"></ref><ref source="SECUNIA" url="http://secunia.com/advisories/25079">25079</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33993">vmware-windebugging-unspecified(33993)</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1018011">1018011</ref><ref source="BID" url="http://www.securityfocus.com/bid/23732">23732</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1592">ADV-2007-1592</ref></refs><vuln_soft><prod name="VMWare Workstation" vendor="VMWare"><vers num="5.5.3" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.8" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.9" CVSS_score="7.8" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_version="2.0" modified="2007-05-04" name="CVE-2007-1877" published="2007-05-02" seq="2007-1877" severity="High" type="CVE"><desc><descript source="cve">VMware Workstation before 5.5.4 allows attackers to cause a denial of service against the guest OS by causing the virtual machine process (VMX) to store malformed configuration information.</descript></desc><loss_types><avail/></loss_types><vuln_types><design/><config/></vuln_types><range><network/></range><refs><ref patch="1" source="" url="http://www.vmware.com/support/ws55/doc/releasenotes_ws55.html#554"></ref><ref source="SECUNIA" url="http://secunia.com/advisories/25079">
25079</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33992">
vmware-vmx-dos(33992)</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1018011">
1018011</ref><ref source="BID" url="http://www.securityfocus.com/bid/23732">23732</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1592">ADV-2007-1592</ref></refs><vuln_soft><prod name="VMWare Workstation" vendor="VMWare"><vers num="5.5.3" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-04-12" name="CVE-2007-1878" published="2007-04-05" seq="2007-1878" severity="Medium" type="CVE"><desc><descript source="cve">Cross-zone scripting vulnerability in the DOM templates (domplates) used by the console.log function in the Firebug extension before 1.03 for Mozilla Firefox allows remote attackers to bypass zone restrictions, read arbitrary file:// URIs, or execute arbitrary code in the browser chrome, as demonstrated via the runFile function, related to lack of HTML escaping in the property name.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><access/></vuln_types><range><network/><user_init/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/464740/100/0/threaded">20070404 Firefox extensions go Evil - Critical Vulnerabilities in Firefox/Firebug</ref><ref source="" url="http://www.gnucitizen.org/blog/firebug-goes-evil"></ref><ref patch="1" source="" url="http://www.getfirebug.com/blog/2007/04/04/security-update/"></ref><ref source="BID" url="http://www.securityfocus.com/bid/23315">23315</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/464786/100/0/threaded">20070404 Re: [WEB SECURITY] Firefox extensions go Evil - Critical Vulnerabilities in Firefox/Firebug</ref><ref source="" url="http://larholm.com/2007/04/06/0day-vulnerability-in-firebug/"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1272">ADV-2007-1272</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24743">24743</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33451">firefox-firebug-console-security-bypass(33451)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2525">2525</ref></refs><vuln_soft><prod name="Firebug" vendor="Parakey Inc."><vers num="1.01"/><vers num="1.02"/></prod></vuln_soft></entry><entry CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" CVSS_score="9.3" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-04-09" name="CVE-2007-1879" published="2007-04-05" seq="2007-1879" severity="High" type="CVE"><desc><descript source="cve">The StartUploading function in KL.SysInfo ActiveX control (AxKLSysInfo.dll) in Kaspersky Anti-Virus 6.0 and Internet Security 6.0 before Maintenance Pack 2 build 6.0.2.614 allows remote attackers to read arbitrary files by triggering an outbound anonymous FTP session that invokes the PUT command.  NOTE: this issue might be related to CVE-2007-1112.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><design/></vuln_types><range><network/><user_init/></range><refs><ref source="IDEFENSE" url="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=504">20070404 Kaspersky AntiVirus SysInfo ActiveX Control Information Disclosure Vulnerability</ref><ref adv="1" source="" url="http://www.kaspersky.com/technews?id=203038694"></ref><ref source="BID" url="http://www.securityfocus.com/bid/23325">23325</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1268">ADV-2007-1268</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017871">1017871</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24778">24778</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33464">
kaspersky-startuploading-info-disclosure(33464)</ref></refs><vuln_soft><prod name="Kaspersky Internet Security" vendor="Kaspersky Lab"><vers num="6.0.1.411" prev="1"/></prod><prod name="Kaspersky Anti-Virus" vendor="Kaspersky Lab"><vers num="6.0"/></prod></vuln_soft></entry><entry CVSS_base_score="6.6" CVSS_exploit_subscore="2.7" CVSS_impact_subscore="10.0" CVSS_score="6.6" CVSS_vector="(AV:L/AC:M/Au:S/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-04-09" name="CVE-2007-1880" published="2007-04-05" seq="2007-1880" severity="Medium" type="CVE"><desc><descript source="cve">Integer overflow in the _NtSetValueKey function in klif.sys in Kaspersky Anti-Virus, Anti-Virus for Workstations, Anti-Virus for File Server 6.0, and Internet Security 6.0 before Maintenance Pack 2 build 6.0.2.614 allows context-dependent attackers to execute arbitrary code via a large, unsigned &quot;data size argument,&quot; which results in a heap overflow.</descript></desc><sols><sol source="nvd">The vendor has addressed this vulnerability within Maintenance Pack 2. More information is available from the following link: 
http://www.kaspersky.com/technews?id=203038693 

</sol></sols><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input bound="1"/></vuln_types><range><local/></range><refs><ref adv="1" source="IDEFENSE" url="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=505">20070404 Kaspersky Internet Security Suite klif.sys Heap Overflow Vulnerability</ref><ref source="" url="http://www.kaspersky.com/technews?id=203038693"></ref><ref source="" url="http://www.kaspersky.com/technews?id=203038694"></ref><ref source="BID" url="http://www.securityfocus.com/bid/23326">23326</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1268">ADV-2007-1268</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017873">1017873</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24778">24778</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017872">
1017872</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33460">
kaspersky-klif-bo(33460)</ref><ref source="OSVDB" url="http://www.osvdb.org/33851">
33851</ref></refs><vuln_soft><prod name="Kaspersky Internet Security" vendor="Kaspersky Lab"><vers num="6.0.1.411" prev="1"/></prod><prod name="Kaspersky Anti-Virus" vendor="Kaspersky Lab"><vers edition="Windows Workstation" num="6.0" prev="1"/><vers edition="File Servers" num="6.0" prev="1"/><vers num="6.0"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="3.1" CVSS_impact_subscore="10.0" CVSS_score="6.8" CVSS_vector="(AV:L/AC:L/Au:S/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-04-09" name="CVE-2007-1881" published="2007-04-05" seq="2007-1881" severity="Medium" type="CVE"><desc><descript source="cve">Unspecified vulnerability in KLIF (klif.sys) in Kaspersky Anti-Virus, Anti-Virus for Workstations, and Anti-Virus for File Servers 6.0, and Internet Security 6.0 before Maintenance Pack 2 build 6.0.2.614 allows local users to gain Ring-0 privileges via unspecified vectors.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><range><local/></range><refs><ref source="" url="http://www.kaspersky.com/technews?id=203038693"></ref><ref source="" url="http://www.kaspersky.com/technews?id=203038694"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1268">ADV-2007-1268</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24778">24778</ref><ref source="OSVDB" url="http://www.osvdb.org/33852">
33852</ref></refs><vuln_soft><prod name="Kaspersky Internet Security" vendor="Kaspersky Lab"><vers num="6.0.1.411" prev="1"/></prod><prod name="Kaspersky Anti-Virus" vendor="Kaspersky Lab"><vers edition="Workstations" num="6.0" prev="1"/><vers edition="File Servers" num="6.0" prev="1"/><vers num="6.0"/></prod></vuln_soft></entry><entry CVSS_base_score="6.5" CVSS_exploit_subscore="8.0" CVSS_impact_subscore="6.4" CVSS_score="6.5" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-04-10" name="CVE-2007-1882" published="2007-04-05" seq="2007-1882" severity="Medium" type="CVE"><desc><descript source="cve">qcbin/servlet/tdservlet/TDAPI_GeneralWebTreatment in HP Mercury Quality Center 9.0 build 9.1.0.4352 allows remote authenticated users to execute arbitrary SQL commands via the RunQuery method.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2007-April/053406.html">20070403 HP Mercury Quality Center Any SQL execution</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1246">ADV-2007-1246</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017842">1017842</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24730">24730</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33385">hpmercuryquality-sql-command-execution(33385)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2527">2527</ref></refs><vuln_soft><prod name="Mercury Quality Center" vendor="HP"><vers num="9.0 build 9.1.0.4352"/></prod></vuln_soft></entry><entry CVSS_base_score="7.8" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.9" CVSS_score="7.8" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:N/A:N)" CVSS_version="2.0" modified="2007-04-10" name="CVE-2007-1883" published="2007-04-05" seq="2007-1883" severity="High" type="CVE"><desc><descript source="cve">PHP 4.0.0 through 4.4.6 and 5.0.0 through 5.2.1 allows context-dependent attackers to read arbitrary memory locations via an interruption that triggers a user space error handler that changes a parameter to an arbitrary pointer, as demonstrated via the iptcembed function, which calls certain convert_to_* functions with its input parameters.</descript></desc><loss_types><conf/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="" url="http://www.php-security.org/MOPB/MOPB-37-2007.html"></ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24542">24542</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200710-02.xml">GLSA-200710-02</ref><ref source="SECUNIA" url="http://secunia.com/advisories/27102">27102</ref></refs><vuln_soft><prod name="PHP" vendor="PHP"><vers num="4.0.0"/><vers num="4.0.1"/><vers num="4.0.1 pl1"/><vers num="4.0.1 pl2"/><vers num="4.0.2"/><vers num="4.0.3"/><vers num="4.0.3 pl1"/><vers num="4.0.4"/><vers num="4.0.4 pl1"/><vers num="4.0.5"/><vers num="4.0.6"/><vers num="4.0.7"/><vers num="4.0.7 RC1"/><vers num="4.0.7 RC2"/><vers num="4.0.7 RC3"/><vers num="4.1.0"/><vers num="4.1.1"/><vers num="4.1.2"/><vers edition="Dev" num="4.2"/><vers num="4.2.0"/><vers num="4.2.1"/><vers num="4.2.2"/><vers num="4.2.3"/><vers num="4.3"/><vers num="4.3.1"/><vers num="4.3.10"/><vers num="4.3.11"/><vers num="4.3.2"/><vers num="4.3.3"/><vers num="4.3.4"/><vers num="4.3.5"/><vers num="4.3.6"/><vers num="4.3.7"/><vers num="4.3.8"/><vers num="4.3.9"/><vers num="4.4.0"/><vers num="4.4.1"/><vers num="4.4.2"/><vers num="4.4.3"/><vers num="4.4.4"/><vers num="4.4.5"/><vers num="4.4.6"/><vers num="5.0 candidate 1"/><vers num="5.0 candidate 2"/><vers num="5.0 candidate 3"/><vers num="5.0.0"/><vers num="5.0.0 Beta1"/><vers num="5.0.0 Beta2"/><vers num="5.0.0 Beta3"/><vers num="5.0.0 Beta4"/><vers num="5.0.0 RC1"/><vers num="5.0.0 RC2"/><vers num="5.0.0 RC3"/><vers num="5.0.1"/><vers num="5.0.2"/><vers num="5.0.3"/><vers num="5.0.4"/><vers num="5.0.5"/><vers num="5.1"/><vers num="5.1.0"/><vers num="5.1.1"/><vers num="5.1.2"/><vers num="5.1.3"/><vers num="5.1.4"/><vers num="5.1.5"/><vers num="5.1.6"/><vers num="5.2.0"/><vers num="5.2.1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-04-10" name="CVE-2007-1884" published="2007-04-05" seq="2007-1884" severity="Medium" type="CVE"><desc><descript source="cve">Multiple integer signedness errors in the printf function family in PHP 4 before 4.4.5 and PHP 5 before 5.2.1 on 64 bit machines allow context-dependent attackers to execute arbitrary code via (1) certain negative argument numbers that arise in the php_formatted_print function because of 64 to 32 bit truncation, and bypass a check for the maximum allowable value; and (2) a width and precision of -1, which make it possible for the php_sprintf_appendstring function to place an internal buffer at an arbitrary memory location.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="" url="http://www.php-security.org/MOPB/MOPB-38-2007.html"></ref><ref patch="1" source="" url="http://www.php.net/releases/5_2_1.php"></ref><ref source="BID" url="http://www.securityfocus.com/bid/23219">23219</ref><ref source="OSVDB" url="http://www.osvdb.org/33955">
33955</ref><ref source="HP" url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&amp;cc=us&amp;objectID=c01056506">HPSBMA02215</ref><ref source="HP" url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&amp;cc=us&amp;objectID=c01086137">HPSBTU02232</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1991">ADV-2007-1991</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/2374">ADV-2007-2374</ref><ref source="OSVDB" url="http://www.osvdb.org/34767">34767</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25423">25423</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25850">25850</ref></refs><vuln_soft><prod name="PHP" vendor="PHP"><vers num="4.0"/><vers num="4.0 Beta 1"/><vers num="4.0 Beta 2"/><vers num="4.0 Beta 3"/><vers num="4.0 Beta 4"/><vers num="4.0 Beta 4 Patch Level 1"/><vers num="4.0 RC1"/><vers num="4.0 RC2"/><vers num="4.0.0"/><vers num="4.0.1"/><vers num="4.0.1 pl1"/><vers num="4.0.1 pl2"/><vers num="4.0.2"/><vers num="4.0.3"/><vers num="4.0.3 pl1"/><vers num="4.0.4"/><vers num="4.0.4 pl1"/><vers num="4.0.5"/><vers num="4.0.6"/><vers num="4.0.7"/><vers num="4.0.7 RC1"/><vers num="4.0.7 RC2"/><vers num="4.0.7 RC3"/><vers num="4.1.0"/><vers num="4.1.1"/><vers num="4.1.2"/><vers edition="Dev" num="4.2"/><vers num="4.2.0"/><vers num="4.2.1"/><vers num="4.2.2"/><vers num="4.2.3"/><vers num="4.3"/><vers num="4.3.1"/><vers num="4.3.10"/><vers num="4.3.11"/><vers num="4.3.2"/><vers num="4.3.3"/><vers num="4.3.4"/><vers num="4.3.5"/><vers num="4.3.6"/><vers num="4.3.7"/><vers num="4.3.8"/><vers num="4.3.9"/><vers num="4.4.0"/><vers num="4.4.1"/><vers num="4.4.2"/><vers num="4.4.3"/><vers num="4.4.4"/><vers num="5.0 candidate 1"/><vers num="5.0 candidate 2"/><vers num="5.0 candidate 3"/><vers num="5.0.0"/><vers num="5.0.0 Beta1"/><vers num="5.0.0 Beta2"/><vers num="5.0.0 Beta3"/><vers num="5.0.0 Beta4"/><vers num="5.0.0 RC1"/><vers num="5.0.0 RC2"/><vers num="5.0.0 RC3"/><vers num="5.0.1"/><vers num="5.0.2"/><vers num="5.0.3"/><vers num="5.0.4"/><vers num="5.0.5"/><vers num="5.1"/><vers num="5.1.0"/><vers num="5.1.1"/><vers num="5.1.2"/><vers num="5.1.3"/><vers num="5.1.4"/><vers num="5.1.5"/><vers num="5.1.6"/><vers num="5.2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-04-10" name="CVE-2007-1885" published="2007-04-05" seq="2007-1885" severity="High" type="CVE"><desc><descript source="cve">Integer overflow in the str_replace function in PHP 4 before 4.4.5 and PHP 5 before 5.2.1 allows context-dependent attackers to execute arbitrary code via a single character search string in conjunction with a long replacement string, which overflows a 32 bit length counter.  NOTE: this is probably the same issue as CVE-2007-0906.6.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="" url="http://www.php-security.org/MOPB/MOPB-39-2007.html"></ref><ref source="" url="http://www.php.net/releases/5_2_1.php"></ref><ref source="BID" url="http://www.securityfocus.com/bid/23233">23233</ref><ref source="HP" url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&amp;cc=us&amp;objectID=c01056506">HPSBMA02215</ref><ref source="HP" url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&amp;cc=us&amp;objectID=c01086137">HPSBTU02232</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1991">ADV-2007-1991</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/2374">ADV-2007-2374</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25423">25423</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25850">25850</ref></refs><vuln_soft><prod name="PHP" vendor="PHP"><vers num="4.0.0"/><vers num="4.0.1"/><vers num="4.0.1 pl1"/><vers num="4.0.1 pl2"/><vers num="4.0.2"/><vers num="4.0.3"/><vers num="4.0.3 pl1"/><vers num="4.0.4"/><vers num="4.0.4 pl1"/><vers num="4.0.5"/><vers num="4.0.6"/><vers num="4.0.7"/><vers num="4.0.7 RC1"/><vers num="4.0.7 RC2"/><vers num="4.0.7 RC3"/><vers num="4.1.0"/><vers num="4.1.1"/><vers num="4.1.2"/><vers edition="Dev" num="4.2"/><vers num="4.2.0"/><vers num="4.2.1"/><vers num="4.2.2"/><vers num="4.2.3"/><vers num="4.3"/><vers num="4.3.1"/><vers num="4.3.10"/><vers num="4.3.11"/><vers num="4.3.2"/><vers num="4.3.3"/><vers num="4.3.4"/><vers num="4.3.5"/><vers num="4.3.6"/><vers num="4.3.7"/><vers num="4.3.8"/><vers num="4.3.9"/><vers num="4.4.0"/><vers num="4.4.1"/><vers num="4.4.2"/><vers num="4.4.3"/><vers num="4.4.4"/><vers num="4.4.5"/><vers num="4.4.6"/><vers num="5.0 candidate 1"/><vers num="5.0 candidate 2"/><vers num="5.0 candidate 3"/><vers num="5.0.0"/><vers num="5.0.0 Beta1"/><vers num="5.0.0 Beta2"/><vers num="5.0.0 Beta3"/><vers num="5.0.0 Beta4"/><vers num="5.0.0 RC1"/><vers num="5.0.0 RC2"/><vers num="5.0.0 RC3"/><vers num="5.0.1"/><vers num="5.0.2"/><vers num="5.0.3"/><vers num="5.0.4"/><vers num="5.0.5"/><vers num="5.1"/><vers num="5.1.0"/><vers num="5.1.1"/><vers num="5.1.2"/><vers num="5.1.3"/><vers num="5.1.4"/><vers num="5.1.5"/><vers num="5.1.6"/><vers num="5.2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-04-10" name="CVE-2007-1886" published="2007-04-05" seq="2007-1886" severity="Medium" type="CVE"><desc><descript source="cve">Integer overflow in the str_replace function in PHP 4.4.5 and PHP 5.2.1 allows context-dependent attackers to have an unknown impact via a single character search string in conjunction with a single character replacement string, which causes an &quot;off by one overflow.&quot;</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="" url="http://www.php-security.org/MOPB/MOPB-39-2007.html"></ref><ref source="HP" url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&amp;cc=us&amp;objectID=c01056506">HPSBMA02215</ref><ref source="HP" url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&amp;cc=us&amp;objectID=c01086137">HPSBTU02232</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1991">ADV-2007-1991</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/2374">ADV-2007-2374</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25423">25423</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25850">25850</ref></refs><vuln_soft><prod name="PHP" vendor="PHP"><vers num="4.4.5"/><vers num="5.2.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-04-10" name="CVE-2007-1887" published="2007-04-05" seq="2007-1887" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in the sqlite_decode_binary function in the bundled sqlite library in PHP 4 before 4.4.5 and PHP 5 before 5.2.1 allows context-dependent attackers to execute arbitrary code via an empty value of the in parameter, as demonstrated by calling the sqlite_udf_decode_binary function with a 0x01 character.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="" url="http://www.php-security.org/MOPB/MOPB-41-2007.html"></ref><ref patch="1" source="" url="http://www.php.net/releases/5_2_1.php"></ref><ref source="BID" url="http://www.securityfocus.com/bid/23235">23235</ref><ref source="DEBIAN" url="http://www.debian.org/security/2007/dsa-1283">
DSA-1283</ref><ref source="UBUNTU" url="http://www.ubuntu.com/usn/usn-455-1">
USN-455-1</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25062">
25062</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25057">
25057</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2007:088">
MDKSA-2007:088</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2007:089">
MDKSA-2007:089</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24909">
24909</ref><ref source="" url="http://www.php.net/releases/5_2_3.php"></ref><ref source="FEDORA" url="https://www.redhat.com/archives/fedora-package-announce/2007-September/msg00397.html">FEDORA-2007-2215</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200710-02.xml">GLSA-200710-02</ref><ref source="HP" url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01178795">HPSBUX02262</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:088">MDKSA-2007:088</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:089">MDKSA-2007:089</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/2016">ADV-2007-2016</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/3386">ADV-2007-3386</ref><ref source="SECUNIA" url="http://secunia.com/advisories/27037">27037</ref><ref source="SECUNIA" url="http://secunia.com/advisories/27110">27110</ref><ref source="SECUNIA" url="http://secunia.com/advisories/27102">27102</ref></refs><vuln_soft><prod name="PHP" vendor="PHP"><vers num="4.0"/><vers num="4.0 Beta 1"/><vers num="4.0 Beta 2"/><vers num="4.0 Beta 3"/><vers num="4.0 Beta 4"/><vers num="4.0 Beta 4 Patch Level 1"/><vers num="4.0 RC1"/><vers num="4.0 RC2"/><vers num="4.0.0"/><vers num="4.0.1"/><vers num="4.0.1 pl1"/><vers num="4.0.1 pl2"/><vers num="4.0.2"/><vers num="4.0.3"/><vers num="4.0.3 pl1"/><vers num="4.0.4"/><vers num="4.0.4 pl1"/><vers num="4.0.5"/><vers num="4.0.6"/><vers num="4.0.7"/><vers num="4.0.7 RC1"/><vers num="4.0.7 RC2"/><vers num="4.0.7 RC3"/><vers num="4.1.0"/><vers num="4.1.1"/><vers num="4.1.2"/><vers edition="Dev" num="4.2"/><vers num="4.2.0"/><vers num="4.2.1"/><vers num="4.2.2"/><vers num="4.2.3"/><vers num="4.3"/><vers num="4.3.1"/><vers num="4.3.10"/><vers num="4.3.11"/><vers num="4.3.2"/><vers num="4.3.3"/><vers num="4.3.4"/><vers num="4.3.5"/><vers num="4.3.6"/><vers num="4.3.7"/><vers num="4.3.8"/><vers num="4.3.9"/><vers num="4.4.0"/><vers num="4.4.1"/><vers num="4.4.2"/><vers num="4.4.3"/><vers num="4.4.4"/><vers num="5.0 candidate 1"/><vers num="5.0 candidate 2"/><vers num="5.0 candidate 3"/><vers num="5.0.0"/><vers num="5.0.0 Beta1"/><vers num="5.0.0 Beta2"/><vers num="5.0.0 Beta3"/><vers num="5.0.0 Beta4"/><vers num="5.0.0 RC1"/><vers num="5.0.0 RC2"/><vers num="5.0.0 RC3"/><vers num="5.0.1"/><vers num="5.0.2"/><vers num="5.0.3"/><vers num="5.0.4"/><vers num="5.0.5"/><vers num="5.1"/><vers num="5.1.0"/><vers num="5.1.1"/><vers num="5.1.2"/><vers num="5.1.3"/><vers num="5.1.4"/><vers num="5.1.5"/><vers num="5.1.6"/><vers num="5.2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-08-02" name="CVE-2007-1888" published="2007-04-05" seq="2007-1888" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in the sqlite_decode_binary function in src/encode.c in SQLite 2, as used by PHP 4.x through 5.x and other applications, allows context-dependent attackers to execute arbitrary code via an empty value of the in parameter.  NOTE: some PHP installations use a bundled version of sqlite without this vulnerability.  The SQLite developer has argued that this issue could be due to a misuse of the sqlite_decode_binary() API.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="" url="http://www.php-security.org/MOPB/MOPB-41-2007.html"></ref><ref source="" url="http://www.sqlite.org/cvstrac/rlog?f=sqlite/src/encode.c"></ref><ref source="VIM" url="http://www.attrition.org/pipermail/vim/2007-April/001540.html">20070422 vendor ack/clarification for CVE-2007-1888 (SQLite)</ref><ref source="UBUNTU" url="http://www.ubuntu.com/usn/usn-455-1">USN-455-1</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25057">25057</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2007:091">MDKSA-2007:091</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:091">MDKSA-2007:091</ref></refs><vuln_soft><prod name="PHP" vendor="PHP"><vers num="4.0"/><vers num="4.0 Beta 1"/><vers num="4.0 Beta 2"/><vers num="4.0 Beta 3"/><vers num="4.0 Beta 4"/><vers num="4.0 Beta 4 Patch Level 1"/><vers num="4.0 RC1"/><vers num="4.0 RC2"/><vers num="4.0.0"/><vers num="4.0.1"/><vers num="4.0.1 pl1"/><vers num="4.0.1 pl2"/><vers num="4.0.2"/><vers num="4.0.3"/><vers num="4.0.3 pl1"/><vers num="4.0.4"/><vers num="4.0.4 pl1"/><vers num="4.0.5"/><vers num="4.0.6"/><vers num="4.0.7"/><vers num="4.0.7 RC1"/><vers num="4.0.7 RC2"/><vers num="4.0.7 RC3"/><vers num="4.1.0"/><vers num="4.1.1"/><vers num="4.1.2"/><vers edition="Dev" num="4.2"/><vers num="4.2.0"/><vers num="4.2.1"/><vers num="4.2.2"/><vers num="4.2.3"/><vers num="4.3"/><vers num="4.3.1"/><vers num="4.3.10"/><vers num="4.3.11"/><vers num="4.3.2"/><vers num="4.3.3"/><vers num="4.3.4"/><vers num="4.3.5"/><vers num="4.3.6"/><vers num="4.3.7"/><vers num="4.3.7"/><vers num="4.3.8"/><vers num="4.3.8"/><vers num="4.3.9"/><vers num="4.3.9"/><vers num="4.4.0"/><vers num="4.4.0"/><vers num="4.4.1"/><vers num="4.4.1"/><vers num="4.4.2"/><vers num="4.4.3"/><vers num="4.4.2"/><vers num="4.4.4"/><vers num="4.4.5"/><vers num="4.4.3"/><vers num="4.4.6"/><vers num="4.4.4"/><vers num="5.0 candidate 1"/><vers num="4.4.5"/><vers num="5.0 candidate 2"/><vers num="4.4.6"/><vers num="5.0 candidate 3"/><vers num="5.0 candidate 1"/><vers num="5.0 candidate 2"/><vers num="5.0.0"/><vers num="5.0 candidate 3"/><vers num="5.0.0 Beta1"/><vers num="5.0.0"/><vers num="5.0.0 Beta2"/><vers num="5.0.0 Beta3"/><vers num="5.0.0 Beta4"/><vers num="5.0.0 RC1"/><vers num="5.0.0 RC2"/><vers num="5.0.0 RC1"/><vers num="5.0.0 RC3"/><vers num="5.0.0 RC2"/><vers num="5.0.1"/><vers num="5.0.0 RC3"/><vers num="5.0.2"/><vers num="5.0.1"/><vers num="5.0.3"/><vers num="5.0.2"/><vers num="5.0.4"/><vers num="5.0.3"/><vers num="5.0.5"/><vers num="5.0.4"/><vers num="5.1"/><vers num="5.0.5"/><vers num="5.1.0"/><vers num="5.1"/><vers num="5.1.1"/><vers num="5.1.0"/><vers num="5.1.2"/><vers num="5.1.1"/><vers num="5.1.3"/><vers num="5.1.2"/><vers num="5.1.4"/><vers num="5.1.3"/><vers num="5.1.5"/><vers num="5.1.4"/><vers num="5.1.6"/><vers num="5.2.0"/><vers num="5.1.5"/><vers num="5.2.1"/><vers num="5.1.6"/><vers num="5.4.0"/><vers num="5.2.1"/><vers num="5.4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-04-10" name="CVE-2007-1889" published="2007-04-05" seq="2007-1889" severity="High" type="CVE"><desc><descript source="cve">Integer signedness error in the _zend_mm_alloc_int function in the Zend Memory Manager in PHP 5.2.0 allows remote attackers to execute arbitrary code via a large emalloc request, related to an incorrect signed long cast, as demonstrated via the HTTP SOAP client in PHP, and via a call to msg_receive with the largest positive integer value of maxsize.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="" url="http://www.php-security.org/MOPB/MOPB-43-2007.html"></ref><ref adv="1" source="" url="http://www.php-security.org/MOPB/MOPB-44-2007.html"></ref><ref source="DEBIAN" url="http://www.debian.org/security/2007/dsa-1283">
DSA-1283</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25062">
25062</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2007_32_php.html">SUSE-SA:2007:032</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25056">25056</ref></refs><vuln_soft><prod name="PHP" vendor="PHP"><vers num="5.2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-04-10" name="CVE-2007-1890" published="2007-04-05" seq="2007-1890" severity="High" type="CVE"><desc><descript source="cve">Integer overflow in the msg_receive function in PHP 4 before 4.4.5 and PHP 5 before 5.2.1, on FreeBSD and possibly other platforms, allows context-dependent attackers to execute arbitrary code via certain maxsize values, as demonstrated by 0xffffffff.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="" url="http://www.php-security.org/MOPB/MOPB-43-2007.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/23236">23236</ref></refs><vuln_soft><prod name="PHP" vendor="PHP"><vers num="4.0.0"/><vers num="4.0.1"/><vers num="4.0.1 pl1"/><vers num="4.0.1 pl2"/><vers num="4.0.2"/><vers num="4.0.3"/><vers num="4.0.3 pl1"/><vers num="4.0.4"/><vers num="4.0.4 pl1"/><vers num="4.0.5"/><vers num="4.0.6"/><vers num="4.0.7"/><vers num="4.0.7 RC1"/><vers num="4.0.7 RC2"/><vers num="4.0.7 RC3"/><vers num="4.1.0"/><vers num="4.1.1"/><vers num="4.1.2"/><vers edition="Dev" num="4.2"/><vers num="4.2.0"/><vers num="4.2.1"/><vers num="4.2.2"/><vers num="4.2.3"/><vers num="4.3"/><vers num="4.3.1"/><vers num="4.3.10"/><vers num="4.3.11"/><vers num="4.3.2"/><vers num="4.3.3"/><vers num="4.3.4"/><vers num="4.3.5"/><vers num="4.3.6"/><vers num="4.3.7"/><vers num="4.3.8"/><vers num="4.3.9"/><vers num="4.4.0"/><vers num="4.4.1"/><vers num="4.4.2"/><vers num="4.4.3"/><vers num="4.4.4"/><vers num="5.0 candidate 1"/><vers num="5.0 candidate 2"/><vers num="5.0 candidate 3"/><vers num="5.0.0"/><vers num="5.0.0 Beta1"/><vers num="5.0.0 Beta2"/><vers num="5.0.0 Beta3"/><vers num="5.0.0 Beta4"/><vers num="5.0.0 RC1"/><vers num="5.0.0 RC2"/><vers num="5.0.0 RC3"/><vers num="5.0.1"/><vers num="5.0.2"/><vers num="5.0.3"/><vers num="5.0.4"/><vers num="5.0.5"/><vers num="5.1"/><vers num="5.1.0"/><vers num="5.1.1"/><vers num="5.1.2"/><vers num="5.1.3"/><vers num="5.1.4"/><vers num="5.1.5"/><vers num="5.1.6"/><vers num="5.2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" CVSS_score="9.3" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-04-23" name="CVE-2007-1891" published="2007-04-17" seq="2007-1891" severity="High" type="CVE"><desc><descript source="cve">Stack-based buffer overflow in the GetPrivateProfileSectionW function in Akamai Technologies Download Manager ActiveX Control (DownloadManagerV2.ocx) after 2.0.4.4 but before 2.2.1.0 allows remote attackers to execute arbitrary code, related to misinterpretation of the nSize parameter as a byte count instead of a wide character count.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="IDEFENSE" url="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=514">20070416 Akamai Download Manager ActiveX Stack Buffer Overflow Vulnerability</ref><ref adv="1" patch="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/465908/100/0/threaded">20070416 Akamai Technologies Security Advisory 2007-0001</ref><ref source="BID" url="http://www.securityfocus.com/bid/23522">23522</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/120241">
VU#120241</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1415">
ADV-2007-1415</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017925">
1017925</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24900">
24900</ref><ref source="OSVDB" url="http://www.osvdb.org/34323">
34323</ref></refs><vuln_soft><prod name="Download Manager" vendor="Akamai Technologies"><vers num="2.2.0.0"/></prod></vuln_soft></entry><entry CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" CVSS_score="9.3" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-04-23" name="CVE-2007-1892" published="2007-04-17" seq="2007-1892" severity="High" type="CVE"><desc><descript source="cve">Stack-based buffer overflow in Akamai Technologies Download Manager ActiveX Control (DownloadManagerV2.ocx) before 2.2.1.0 allows remote attackers to execute arbitrary code via unspecified vectors, a different issue than CVE-2007-1891.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/465908/100/0/threaded">20070416 Akamai Technologies Security Advisory 2007-0001</ref><ref source="BID" url="http://www.securityfocus.com/bid/23522">23522</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1415">
ADV-2007-1415</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24900">
24900</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33697">
akamai-download-manager-bo(33697)</ref><ref source="OSVDB" url="http://www.osvdb.org/34324">
34324</ref></refs><vuln_soft><prod name="Download Manager" vendor="Akamai Technologies"><vers num="2.2.0.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.9" CVSS_exploit_subscore="4.4" CVSS_impact_subscore="6.4" CVSS_score="4.9" CVSS_vector="(AV:A/AC:M/Au:S/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-04-12" name="CVE-2007-1893" published="2007-04-09" seq="2007-1893" severity="Medium" type="CVE"><desc><descript source="cve">xmlrpc (xmlrpc.php) in WordPress 2.1.2, and probably earlier, allows remote authenticated users with the contributor role to bypass intended access restrictions and invoke the publish_posts functionality, which can be used to &quot;publish a previously saved post.&quot;</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/></vuln_types><range><local_network/></range><refs><ref source="" url="http://www.notsosecure.com/folder2/2007/04/03/wordpress-212-xmlrpc-security-issues/"></ref><ref source="" url="http://trac.wordpress.org/ticket/4091"></ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/24751">24751</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33470">wordpress-xmlrpc-security-bypass(33470)</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1245">
ADV-2007-1245</ref><ref source="DEBIAN" url="http://www.debian.org/security/2007/dsa-1285">
DSA-1285</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25108">
25108</ref></refs><vuln_soft><prod name="WordPress" vendor="WordPress"><vers num="2.1.2" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" modified="2007-04-10" name="CVE-2007-1894" published="2007-04-09" seq="2007-1894" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in wp-includes/general-template.php in WordPress before 20070309 allows remote attackers to inject arbitrary web script or HTML via the year parameter in the wp_title function.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/462374/100/0/threaded">20070309 WordPress XSS under function wp_title()</ref><ref adv="1" source="" url="http://chxsecurity.org/advisories/adv-1-mid.txt"></ref><ref source="" url="http://trac.wordpress.org/changeset/5003"></ref><ref source="" url="http://trac.wordpress.org/ticket/4093"></ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/22902">22902</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/24485">24485</ref><ref source="DEBIAN" url="http://www.debian.org/security/2007/dsa-1285">
DSA-1285</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25108">
25108</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2526">2526</ref></refs><vuln_soft><prod name="WordPress" vendor="WordPress"><vers num="2.0"/><vers num="2.0.1"/><vers num="2.0.2"/><vers num="2.0.3"/><vers num="2.0.4"/><vers num="2.0.5"/><vers num="2.0.6"/><vers num="2.0.7"/><vers num="2.1"/><vers num="2.1.1"/><vers num="2.1.2"/><vers num="2.2 Revision5002"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-04-10" name="CVE-2007-1895" published="2007-04-09" seq="2007-1895" severity="Medium" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in chat.php in Sky GUNNING MySpeach 3.0.7 and earlier, when used with PHP 5, allows remote attackers to execute arbitrary PHP code via an ftp URL in a my_ms[root] cookie, a different vector than CVE-2007-0491 and CVE-2006-4630.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3657">3657</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1261">
ADV-2007-1261</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24760">
24760</ref></refs><vuln_soft><prod name="MySpeach" vendor="Sky Gunning"><vers num="3.0.7" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="4.9" CVSS_score="5.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:N)" CVSS_version="2.0" modified="2007-04-10" name="CVE-2007-1896" published="2007-04-09" seq="2007-1896" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in chat.php in Sky GUNNING MySpeach 3.0.7 and earlier allows remote attackers to include arbitrary local files via a .. (dot dot) and trailing %00 (NULL) in a my_ms[root] cookie.</descript></desc><loss_types><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3657">3657</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1261">
ADV-2007-1261</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24760">
24760</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24766">
24766</ref></refs><vuln_soft><prod name="MySpeach" vendor="Sky Gunning"><vers num="2.1 Beta"/><vers num="3.0.2"/><vers num="3.0.6"/><vers num="3.0.7"/></prod></vuln_soft></entry><entry CVSS_base_score="6.5" CVSS_exploit_subscore="8.0" CVSS_impact_subscore="6.4" CVSS_score="6.5" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-04-12" name="CVE-2007-1897" published="2007-04-09" seq="2007-1897" severity="Medium" type="CVE"><desc><descript source="cve">SQL injection vulnerability in xmlrpc (xmlrpc.php) in WordPress 2.1.2, and probably earlier, allows remote authenticated users to execute arbitrary SQL commands via a string parameter value in an XML RPC mt.setPostCategories method call, related to the post_id variable.</descript></desc><sols><sol source="nvd">This vulnerability has been addressed by the vendor with the release of the following product update: http://wordpress.org/development/2007/04/wordpress-213-and-2010/</sol></sols><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3656">3656</ref><ref adv="1" source="" url="http://www.notsosecure.com/folder2/2007/04/03/wordpress-212-xmlrpc-security-issues/"></ref><ref source="" url="http://trac.wordpress.org/ticket/4091"></ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/23294">23294</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/24751">24751</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1245">
ADV-2007-1245</ref><ref source="DEBIAN" url="http://www.debian.org/security/2007/dsa-1285">
DSA-1285</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25108">
25108</ref></refs><vuln_soft><prod name="WordPress" vendor="WordPress"><vers num="2.1"/><vers num="2.1.1"/><vers num="2.1.2" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="4.9" CVSS_score="5.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:N)" CVSS_version="2.0" modified="2007-05-24" name="CVE-2007-1898" published="2007-05-16" seq="2007-1898" severity="Medium" type="CVE"><desc><descript source="cve">formmail.php in Jetbox CMS 2.1 allows remote attackers to send arbitrary e-mails (spam) via modified recipient, _SETTINGS[allowed_email_hosts][], and subject parameters.</descript></desc><loss_types><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/468644/100/0/threaded">20070515 Jetbox CMS version 2.1 E-Mail Injection Vulnerability</ref><ref adv="1" source="" url="http://www.netvigilance.com/advisory0026"></ref><ref source="BID" url="http://www.securityfocus.com/bid/23989">23989</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1831">ADV-2007-1831</ref><ref adv="1" source="OSVDB" url="http://www.osvdb.org/34088">34088</ref><ref adv="1" source="SECTRACK" url="http://www.securitytracker.com/id?1018063">1018063</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/34292">jetbox-formmail-mail-relay(34292)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2710">2710</ref></refs><vuln_soft><prod name="Jetbox CMS" vendor="Jetbox"><vers num="2.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.1" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="6.4" CVSS_score="5.1" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2008-09-04" name="CVE-2007-1899" published="2008-07-08" seq="2007-1899" severity="Medium" type="CVE"><desc><descript source="cve">Multiple SQL injection vulnerabilities in myWebland myBloggie 2.1.6 allow remote attackers to execute arbitrary SQL commands via (1) the user_id parameter in a viewuser action to index.php, and allow remote authenticated administrators to execute arbitrary SQL commands via (2) the post_id parameter in an edit action to admin.php.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/5975">5975</ref><ref source="" url="http://descriptions.securescout.com/tc/17969"></ref><ref source="" url="http://www.netvigilance.com/advisory0040"></ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/30892">30892</ref></refs><vuln_soft><prod name="myBloggie" vendor="myWebland"><vers num="2.1.6"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" modified="2007-04-10" name="CVE-2007-1900" published="2007-04-10" seq="2007-1900" severity="Medium" type="CVE"><desc><descript source="cve">CRLF injection vulnerability in the FILTER_VALIDATE_EMAIL filter in ext/filter in PHP 5.2.0 and 5.2.1 allows context-dependent attackers to inject arbitrary e-mail headers via an e-mail address with a &apos;\n&apos; character, which causes a regular expression to ignore the subsequent part of the address string.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="" url="http://www.php-security.org/MOPB/PMOPB-45-2007.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/23359">23359</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24824">24824</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33510">
php-filtervalidateemail-header-injection(33510)</ref><ref source="DEBIAN" url="http://www.debian.org/security/2007/dsa-1283">
DSA-1283</ref><ref source="UBUNTU" url="http://www.ubuntu.com/usn/usn-455-1">
USN-455-1</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25062">
25062</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25057">
25057</ref><ref source="OSVDB" url="http://www.osvdb.org/33962">
33962</ref><ref source="" url="http://www.php.net/releases/5_2_3.php"></ref><ref source="FEDORA" url="https://www.redhat.com/archives/fedora-package-announce/2007-September/msg00397.html">FEDORA-2007-2215</ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200705-19.xml">GLSA-200705-19</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200710-02.xml">GLSA-200710-02</ref><ref source="HP" url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01178795">HPSBUX02262</ref><ref source="SLACKWARE" url="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2007&amp;m=slackware-security.482863">SSA:2007-152-01</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2007_32_php.html">SUSE-SA:2007:032</ref><ref source="TRUSTIX" url="http://www.trustix.org/errata/2007/0023/">2007-0023</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/2016">ADV-2007-2016</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/3386">ADV-2007-3386</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25056">25056</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25445">25445</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25535">25535</ref><ref source="SECUNIA" url="http://secunia.com/advisories/26231">26231</ref><ref source="SECUNIA" url="http://secunia.com/advisories/27037">27037</ref><ref source="SECUNIA" url="http://secunia.com/advisories/27110">27110</ref><ref source="SECUNIA" url="http://secunia.com/advisories/27102">27102</ref></refs><vuln_soft><prod name="PHP" vendor="PHP"><vers num="5.2.0"/><vers num="5.2.1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)" CVSS_version="2.0" modified="2007-05-15" name="CVE-2007-1901" published="2007-05-14" seq="2007-1901" severity="Medium" type="CVE"><desc><descript source="cve">SonicBB 1.0 allows remote attackers to obtain sensitive information via the (1) by[] parameter to search.php, (2) p[] parameter to viewforum.php, and the (3) id parameter to (a) viewforum.php or (b) members.php, which reveal the installation path in the resulting error message.</descript></desc><impacts><impact source="nvd">Successful exploitation requires that &quot;magic_quotes_gpc&quot; is disabled.</impact></impacts><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref source="FULLDISC" url="http://marc.info/?l=full-disclosure&amp;m=117914586003786&amp;w=2">20070514 SonicBB version 1.0 Multiple Path Disclosure Vulnerabilities</ref><ref adv="1" source="" url="http://www.netvigilance.com/advisory0018"></ref><ref source="OSVDB" url="http://www.osvdb.org/33906">33906</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/468535/100/0/threaded">

20070514 SonicBB version 1.0 Multiple Path Disclosure Vulnerabilities</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1816">
ADV-2007-1816</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25279">
25279</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/34259">
sonicbb-multiple-path-disclosure(34259)</ref></refs><vuln_soft><prod name="SonicBB" vendor="SonicBB"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-05-15" name="CVE-2007-1902" published="2007-05-14" seq="2007-1902" severity="Medium" type="CVE"><desc><descript source="cve">Multiple SQL injection vulnerabilities in SonicBB 1.0 allow remote attackers to execute arbitrary SQL commands via the (1) part and (2) by parameters to (a) search.php, or the (2) id parameter to (b) viewforum.php.</descript></desc><impacts><impact source="nvd">Successful exploitation requires that &quot;magic_quotes_gpc&quot; is disabled.</impact></impacts><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="FULLDISC" url="http://marc.info/?l=full-disclosure&amp;m=117914598917534&amp;w=2">20070514 SonicBB version 1.0 Multiple SQL Injection Vulnerabilities</ref><ref adv="1" source="" url="http://www.netvigilance.com/advisory0019"></ref><ref source="OSVDB" url="http://www.osvdb.org/33907">33907</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/468536/100/0/threaded">

20070514 SonicBB version 1.0 Multiple SQL Injection Vulnerabilities</ref><ref source="BID" url="http://www.securityfocus.com/bid/23964">
23964</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1816">
ADV-2007-1816</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25279">
25279</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/34258">
sonicbb-search-sql-injection(34258)</ref></refs><vuln_soft><prod name="SonicBB" vendor="SonicBB"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="2.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="2.9" CVSS_score="2.6" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" modified="2007-05-18" name="CVE-2007-1903" published="2007-05-14" seq="2007-1903" severity="Low" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in search.php in SonicBB 1.0 allows remote attackers to inject arbitrary web script or HTML via the part parameter.</descript></desc><impacts><impact source="nvd">Successful exploitation requires that &quot;magic_quotes_gpc&quot; is disabled.</impact></impacts><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref source="FULLDISC" url="http://marc.info/?l=full-disclosure&amp;m=117914615830702&amp;w=2">20070514 SonicBB version 1.0 XSS Attack Vulnerabilities</ref><ref adv="1" source="" url="http://www.netvigilance.com/advisory0020"></ref><ref source="OSVDB" url="http://www.osvdb.org/34042">34042</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/468537/100/0/threaded">

20070514 SonicBB version 1.0 XSS Attack Vulnerabilities</ref><ref source="BID" url="http://www.securityfocus.com/bid/23963">
23963</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1816">
ADV-2007-1816</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25279">
25279</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/34256">
sonicbb-search-xss(34256)</ref></refs><vuln_soft><prod name="SonicBB" vendor="SonicBB"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)" CVSS_version="2.0" modified="2007-04-11" name="CVE-2007-1904" published="2007-04-10" seq="2007-1904" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in AOL Instant Messenger (AIM) 5.9 and earlier, and ICQ 5.1 and probably earlier, allows user-assisted remote attackers to write files to arbitrary locations via a .. (dot dot) in a filename in a file transfer operation.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" source="IDEFENSE" url="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=508">20070409 AOL AIM and ICQ File Transfer Path-Traversal Vulnerability</ref><ref source="BID" url="http://www.securityfocus.com/bid/23391">23391</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1306">
ADV-2007-1306</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1307">
ADV-2007-1307</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017890">
1017890</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017891">
1017891</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24747">
24747</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24803">
24803</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33538">
aim-icq-filetransfer-directory-traversal(33538)</ref></refs><vuln_soft><prod name="Instant Messenger" vendor="AOL"><vers num="5.9.3861" prev="1"/></prod><prod name="ICQ" vendor="AOL"><vers num="5.1" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" modified="2008-08-18" name="CVE-2007-1905" published="2007-04-10" seq="2007-1905" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in auth.php in Pineapple Technologies QuizShock 1.6.1 and earlier allows remote attackers to inject arbitrary web script or HTML via encoded special characters in the forward_to parameter, as demonstrated using &quot;&lt;&quot;&lt;&quot;.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2007-04/0144.html">20070408 QuizShock 1.6.1 - Cross-Site Scripting Vulnerability</ref><ref source="BID" url="http://www.securityfocus.com/bid/23368">23368</ref><ref source="" url="http://john-martinelli.com/work/quizshock.txt"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1319">ADV-2007-1319</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24831">24831</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33523">quizshock-auth-xss(33523)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2554">2554</ref></refs><vuln_soft><prod name="QuizShock" vendor="Pineapple Technologies"><vers num="1.6.1" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-04-11" name="CVE-2007-1906" published="2007-04-10" seq="2007-1906" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in richedit/keyboard.php in eCardMAX HotEditor (Hot Editor) 4.0, and the HotEditor plugin for MyBB, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the first parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/465094/100/0/threaded">20070409 Hot Editor v4.0 Local File Inclusion</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/465092/100/0/threaded">20070409 Mybb Hot Editor Plugin Local File Inclusion</ref><ref source="" url="http://www.expw0rm.com/hot-editor-v40-local-file-inclusion_no113.html"></ref><ref source="" url="http://www.expw0rm.com/mybb-hot-editor-plugin-local-file-inclusion_no114.html"></ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/23377">23377</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33521">hoteditor-keyboard-file-include(33521)</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1315">
ADV-2007-1315</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24825">
24825</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2533">2533</ref></refs><vuln_soft><prod name="Hot Editor" vendor="eCardMAX.com"><vers num="4.0"/></prod><prod name="MyBB Hot Editor Plugin" vendor="MyBB"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-04-11" name="CVE-2007-1907" published="2007-04-10" seq="2007-1907" severity="Medium" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in warn.php in Pathos Content Management System (CMS) 0.92-2 allows remote attackers to execute arbitrary PHP code via a URL in the file parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3696">3696</ref><ref source="BID" url="http://www.securityfocus.com/bid/23393">
23393</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1321">
ADV-2007-1321</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33536">
pathoscms-warn-file-include(33536)</ref></refs><vuln_soft><prod name="Content Management System" vendor="Pathos"><vers num="0.92.2"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-04-11" name="CVE-2007-1908" published="2007-04-10" seq="2007-1908" severity="Medium" type="CVE"><desc><descript source="cve">PHP file inclusion vulnerability in php121db.php in PHP121 Instant Messenger 2.2 allows remote attackers to execute arbitrary PHP code via a UNC share pathname or a local file pathname in the php121dir parameter, which is accessed by the file_exists function.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3694">3694</ref><ref source="BID" url="http://www.securityfocus.com/bid/23392">
23392</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1314">
ADV-2007-1314</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24818">
24818</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33525">
php121-php121db-file-include(33525)</ref></refs><vuln_soft><prod name="PHP121 Instant Messenger" vendor="PHP121"><vers num="2.2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-04-11" name="CVE-2007-1909" published="2007-04-10" seq="2007-1909" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in login.php in Ryan Haudenschilt Battle.net Clan Script for PHP 1.5.1 and earlier allows remote attackers to execute arbitrary SQL commands via the (1) user or (2) pass parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3691">3691</ref><ref source="BID" url="http://www.securityfocus.com/bid/23383">23383</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1313">
ADV-2007-1313</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24838">
24838</ref></refs><vuln_soft><prod name="Battle.Net Clan Script" vendor="Ryan Haudenschilt"><vers edition="PHP" num=""/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-04-11" name="CVE-2007-1910" published="2007-04-10" seq="2007-1910" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in wwlib.dll in Microsoft Word 2007 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted document, as demonstrated by file789-1.doc.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/><user_init/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3690">3690</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/23380">23380</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017902">
1017902</ref></refs><vuln_soft><prod name="Word" vendor="Microsoft"><vers num="2007"/></prod></vuln_soft></entry><entry CVSS_base_score="7.1" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.9" CVSS_score="7.1" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:C)" CVSS_version="2.0" modified="2007-04-11" name="CVE-2007-1911" published="2007-04-10" seq="2007-1911" severity="High" type="CVE"><desc><descript source="cve">Multiple unspecified vulnerabilities in Microsoft Word 2007 allow remote attackers to cause a denial of service (CPU consumption) via crafted documents, as demonstrated by (1) file798-1.doc and (2) file613-1.doc, possibly related to a buffer overflow.</descript></desc><loss_types><avail/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/><user_init/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3690">3690</ref></refs><vuln_soft><prod name="Word" vendor="Microsoft"><vers num="2007"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-04-11" name="CVE-2007-1912" published="2007-04-10" seq="2007-1912" severity="Medium" type="CVE"><desc><descript source="cve">Heap-based buffer overflow in Microsoft Windows allows user-assisted remote attackers to have an unknown impact via a crafted .HLP file.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/><user_init/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3693">3693</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/23382">23382</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017901">
1017901</ref></refs><vuln_soft><prod name="Windows NT" vendor="Microsoft"><vers num=""/></prod><prod name="Windows XP" vendor="Microsoft"><vers num=""/></prod><prod name="Windows Server 2003" vendor="Microsoft"><vers num=""/></prod><prod name="Windows 2000" vendor="Microsoft"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0" modified="2007-04-11" name="CVE-2007-1913" published="2007-04-10" seq="2007-1913" severity="Medium" type="CVE"><desc><descript source="cve">The TRUSTED_SYSTEM_SECURITY function in the SAP RFC Library 6.40 and 7.00 before 20061211 allows remote attackers to verify the existence of users and groups on systems and domains via unspecified vectors, a different vulnerability than CVE-2006-6010.  NOTE: This information is based upon a vague initial disclosure. Details will be updated after the grace period has ended.</descript></desc><loss_types><conf/></loss_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/464669/100/0/threaded">20070404 CYBSEC Pre-Advisory: SAP TRUSTED_SYSTEM_SECURITY RFC Function Information Disclosure</ref><ref source="" url="http://www.cybsec.com/vuln/CYBSEC-Security_Advisory_SAP_TRUSTED_SYSTEM_SECURITY_RFC_Function_Information_Disclosure.pdf"></ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/23305">23305</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1270">ADV-2007-1270</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24722">24722</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33423">sap-rfc-syssecurity-information-disclosure(33423)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2535">2535</ref></refs><vuln_soft><prod name="RFC Library" vendor="SAP"><vers num="6.4"/><vers num="7.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.8" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.9" CVSS_score="7.8" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:N/A:N)" CVSS_version="2.0" modified="2007-04-11" name="CVE-2007-1914" published="2007-04-10" seq="2007-1914" severity="High" type="CVE"><desc><descript source="cve">The RFC_START_PROGRAM function in the SAP RFC Library 6.40 and 7.00 before 20061211 allows remote attackers to obtain sensitive information (external RFC server configuration data) via unspecified vectors, a different vulnerability than CVE-2006-6010.  NOTE: This information is based upon a vague initial disclosure. Details will be updated after the grace period has ended.</descript></desc><loss_types><conf/></loss_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/464678/100/0/threaded">20070404 CYBSEC Security Pre-Advisory: SAP RFC_START_PROGRAM RFC Function Multiple Vulnerabilities</ref><ref patch="1" source="" url="http://www.cybsec.com/vuln/CYBSEC-Security_Advisory_SAP_RFC_START_PROGRAM_RFC_Function_Multiple_Vulnerabilities.pdf"></ref><ref source="BID" url="http://www.securityfocus.com/bid/23313">23313</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1270">ADV-2007-1270</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24722">24722</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33422">sap-rfc-startprogram-information-disclosure(33422)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2538">2538</ref></refs><vuln_soft><prod name="RFC Library" vendor="SAP"><vers num="6.4"/><vers num="7.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-04-11" name="CVE-2007-1915" published="2007-04-10" seq="2007-1915" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in the RFC_START_PROGRAM function in the SAP RFC Library 6.40 and 7.00 before 20061211 allows remote attackers to execute arbitrary code via unspecified vectors.  NOTE: This information is based upon a vague initial disclosure. Details will be updated after the grace period has ended.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/464678/100/0/threaded">20070404 CYBSEC Security Pre-Advisory: SAP RFC_START_PROGRAM RFC Function Multiple Vulnerabilities</ref><ref source="" url="http://www.cybsec.com/vuln/CYBSEC-Security_Advisory_SAP_RFC_START_PROGRAM_RFC_Function_Multiple_Vulnerabilities.pdf"></ref><ref source="BID" url="http://www.securityfocus.com/bid/23313">23313</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1270">ADV-2007-1270</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24722">24722</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33421">sap-rfc-startprogram-bo(33421)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2538">2538</ref></refs><vuln_soft><prod name="RFC Library" vendor="SAP"><vers num="6.4"/><vers num="7.0"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-04-11" name="CVE-2007-1916" published="2007-04-10" seq="2007-1916" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in the RFC_START_GUI function in the SAP RFC Library 6.40 and 7.00 before 20061211 allows remote attackers to execute arbitrary code via unspecified vectors.  NOTE: This information is based upon a vague initial disclosure. Details will be updated after the grace period has ended.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/464680/100/0/threaded">20070404 CYBSEC Security Pre-Advisory: SAP RFC_START_GUI RFC Function Buffer Overflow</ref><ref source="" url="http://www.cybsec.com/vuln/CYBSEC-Security_Advisory_SAP_RFC_START_GUI_RFC_Function_Buffer_Overflow.pdf"></ref><ref source="BID" url="http://www.securityfocus.com/bid/23304">23304</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1270">ADV-2007-1270</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24722">24722</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33420">sap-rfc-startgui-bo(33420)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2537">2537</ref></refs><vuln_soft><prod name="RFC Library" vendor="SAP"><vers num="6.4"/><vers num="7.0"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-04-11" name="CVE-2007-1917" published="2007-04-10" seq="2007-1917" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in the SYSTEM_CREATE_INSTANCE function in the SAP RFC Library 6.40 and 7.00 before 20061211 allows remote attackers to execute arbitrary code via unspecified vectors.  NOTE: This information is based upon a vague initial disclosure. Details will be updated after the grace period has ended.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/464683/100/0/threaded">20070404 CYBSEC Security Pre-Advisory: SAP SYSTEM_CREATE_INSTANCE RFC Function Buffer Overflow</ref><ref source="" url="http://www.cybsec.com/vuln/CYBSEC-Security_Advisory_SAP_SYSTEM_CREATE_INSTANCE_RFC_Function_Buffer_Overflow.pdf"></ref><ref source="BID" url="http://www.securityfocus.com/bid/23307">23307</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1270">ADV-2007-1270</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24722">24722</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33416">sap-rfc-createinstance-bo(33416)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2536">2536</ref></refs><vuln_soft><prod name="RFC Library" vendor="SAP"><vers num="6.4"/><vers num="7.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0" modified="2007-04-11" name="CVE-2007-1918" published="2007-04-10" seq="2007-1918" severity="Medium" type="CVE"><desc><descript source="cve">The RFC_SET_REG_SERVER_PROPERTY function in the SAP RFC Library 6.40 and 7.00 before 20070109 implements an option for exclusive access to an RFC server, which allows remote attackers to cause a denial of service (client lockout) via unspecified vectors.  NOTE: This information is based upon a vague initial disclosure. Details will be updated after the grace period has ended.</descript></desc><loss_types><avail/></loss_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/464685/100/0/threaded">20070404 CYBSEC Security Pre-Advisory: SAP RFC_SET_REG_SERVER_PROPERTY RFC Function Denial Of Service</ref><ref source="" url="http://www.cybsec.com/vuln/CYBSEC-Security_Advisory_SAP_RFC_SET_REG_SERVER_PROPERTY_RFC_Function_Denial_of_Service.pdf"></ref><ref source="BID" url="http://www.securityfocus.com/bid/23309">23309</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1270">ADV-2007-1270</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24722">24722</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33418">sap-rfc-setregserverproperty-dos(33418)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2540">2540</ref></refs><vuln_soft><prod name="RFC Library" vendor="SAP"><vers num="6.4"/><vers num="7.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" modified="2007-06-27" name="CVE-2007-1919" published="2007-04-10" seq="2007-1919" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in index.php in Arizona Dream Livre d&apos;or (livor) 2.5 allows remote attackers to inject arbitrary web script or HTML via the page parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/464888/100/0/threaded">20070406 livor 2.5 Cross-Site Scripting Vulnerability</ref><ref source="BID" url="http://www.securityfocus.com/bid/23353">23353</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33490">livor-index-xss(33490)</ref></refs><vuln_soft><prod name="Livre d&apos;or Livor" vendor="Arizona-Dream"><vers num="2.5"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-08-02" name="CVE-2007-1920" published="2007-04-10" seq="2007-1920" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in index.php in the aktualnosci module in SmodBIP 1.06 and earlier allows remote attackers to execute arbitrary SQL commands via the zoom parameter, possibly related to home.php.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3678">3678</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/23356">23356</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33476">smodbip-index-sql-injection(33476)</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1298">ADV-2007-1298</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24802">24802</ref></refs><vuln_soft><prod name="SmodBIP" vendor="SmodBIP"><vers num="1.06" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" CVSS_score="9.3" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-04-11" name="CVE-2007-1921" published="2007-04-10" seq="2007-1921" severity="High" type="CVE"><desc><descript source="cve">LIBSNDFILE.DLL, as used by AOL Nullsoft Winamp 5.33 and possibly other products, allows remote attackers to execute arbitrary code via a crafted .MAT (MATLAB sound) file that contains a value that is used as an offset, which triggers memory corruption.</descript></desc><impacts><impact source="nvd">To exploit this issue, an attacker must entice an unsuspecting user to use the affected application to open a specially crafted file.</impact></impacts><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/464889/100/0/threaded">20070406 AOL Nullsoft Winamp LIBSNDFILE.DLL Remote Memory Corruption (Off By Zero)</ref><ref source="" url="http://www.piotrbania.com/all/adv/nullsoft-winamp-libsndfile-adv.txt"></ref><ref source="BID" url="http://www.securityfocus.com/bid/23351">23351</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1286">ADV-2007-1286</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017886">
1017886</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24766">
24766</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33481">
winamp-libsndfile-code-execution(33481)</ref><ref source="MLIST" url="http://marc.info/?l=dailydave&amp;m=117589848432659&amp;w=2">
[dailydave] 20070406 AOL Nullsoft Winamp LIBSNDFILE.DLL Remote Memory Corruption (Off By Zero)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2541">2541</ref></refs><vuln_soft><prod name="Winamp" vendor="NullSoft"><vers num="5.33"/></prod></vuln_soft></entry><entry CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" CVSS_score="9.3" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-09-05" name="CVE-2007-1922" published="2007-04-10" seq="2007-1922" severity="High" type="CVE"><desc><descript source="cve">The Impulse Tracker (IT) and ScreamTracker 3 (S3M) modules in IN_MOD.DLL in AOL Nullsoft Winamp 5.33 allows remote attackers to execute arbitrary code via a crafted (1) .IT or (2) .S3M file containing integer values that are used as memory offsets, which triggers memory corruption.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input/><design/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/464893/100/0/threaded">20070406 AOL Nullsoft Winamp IT Module </ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/464890/100/0/threaded">20070406 AOL Nullsoft Winamp S3M Module </ref><ref adv="1" patch="1" source="" url="http://www.piotrbania.com/all/adv/nullsoft-winamp-it_module-in_mod-adv.txt"></ref><ref source="BID" url="http://www.securityfocus.com/bid/23350">23350</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1286">ADV-2007-1286</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017886">1017886</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33480">winamp-inmod-code-execution(33480)</ref><ref source="MLIST" url="http://marc.info/?l=dailydave&amp;m=117589949000906&amp;w=2">[dailydave] 20070406 AOL Nullsoft Winamp IT Module </ref><ref source="MLIST" url="http://marc.info/?l=dailydave&amp;m=117590046601511&amp;w=2">[dailydave] 20070406 AOL Nullsoft Winamp S3M Module </ref><ref source="" url="http://www.piotrbania.com/all/adv/nullsoft-winamp-s3m_module-in_mod-adv.txt"></ref><ref source="SREASON" url="http://securityreason.com/securityalert/2532">2532</ref></refs><vuln_soft><prod name="Winamp" vendor="NullSoft"><vers num="5.33"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-04-11" name="CVE-2007-1923" published="2007-04-10" seq="2007-1923" severity="High" type="CVE"><desc><descript source="cve">(1) LedgerSMB and (2) DWS Systems SQL-Ledger implement access control lists by changing the set of URLs linked from menus, which allows remote attackers to access restricted functionality via direct requests.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/464880/100/0/threaded">20070406 ACLS ineffective in SQL-Ledger and LedgerSMB</ref><ref source="BID" url="http://www.securityfocus.com/bid/23352">23352</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33494">
sqlledger-acl-weak-security(33494)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2552">2552</ref></refs><vuln_soft><prod name="LedgerSMB" vendor="LedgerSMB"><vers num=""/></prod><prod name="SQL-Ledger" vendor="DWS Systems Inc."><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-04-11" name="CVE-2007-1924" published="2007-04-10" seq="2007-1924" severity="Medium" type="CVE"><desc><descript source="cve">** DISPUTED **  Multiple PHP remote file inclusion vulnerabilities in phpContact allow remote attackers to execute arbitrary PHP code via a URL in the include_path parameter to (1) contact_business.php or (2) contact_person.php.  NOTE: this issue is disputed by CVE and a reliable third party, because include_path is initialized to a fixed value before use.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/464877/100/0/threaded">20070406 phpContact Multiple Remote File Inclusion Vulnerabilities</ref><ref source="VIM" url="http://www.attrition.org/pipermail/vim/2007-April/001495.html">20070406 false: phpContact Multiple Remote File Inclusion Vulnerabilities</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2528">2528</ref></refs><vuln_soft><prod name="phpContact" vendor="phpContact"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="6.5" CVSS_exploit_subscore="8.0" CVSS_impact_subscore="6.4" CVSS_score="6.5" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-04-11" name="CVE-2007-1925" published="2007-04-10" seq="2007-1925" severity="Medium" type="CVE"><desc><descript source="cve">The borrado function in modules/Your_Account/index.php in Tru-Zone Nuke ET 3.4 before fix 7 does not verify that account deletion requests come from the account owner, which allows remote authenticated users to delete arbitrary accounts via a modified cookie.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref patch="1" source="" url="http://truzone.org/modules.php?name=Forums&amp;file=viewtopic&amp;p=287012"></ref><ref source="" url="http://truzone.org/modules.php?name=News&amp;file=article&amp;sid=1613"></ref><ref source="BID" url="http://www.securityfocus.com/bid/23354">23354</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1285">ADV-2007-1285</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24800">24800</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33483">nukeet-youraccount-data-manipulation(33483)</ref></refs><vuln_soft><prod name="NukeET" vendor="Tru-Zone"><vers num="3.4" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-04-11" name="CVE-2007-1926" published="2007-04-10" seq="2007-1926" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in JBMC Software DirectAdmin before 1.293 does not properly display log files, which allows remote authenticated users to inject arbitrary web script or HTML via (1) http or (2) ftp requests logged in /var/log/directadmin/security.log; (3) allows context-dependent attackers to inject arbitrary web script or HTML into /var/log/messages via a PHP script that invokes /usr/bin/logger; (4) allows local users to inject arbitrary web script or HTML into /var/log/messages by invoking /usr/bin/logger at the command line; and allows remote attackers to inject arbitrary web script or HTML via remote requests logged in the (5) /var/log/exim/rejectlog, (6) /var/log/exim/mainlog, (7) /var/log/proftpd/auth.log, (8) /var/log/httpd/error_log, (9) /var/log/httpd/access_log, (10) /var/log/directadmin/error.log, and (11) /var/log/directadmin/security.log files.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/464471/100/100/threaded">20070401 DirectAdmin persistant XSS [takeover an Administrator`s account]</ref><ref source="" url="http://www.directadmin.com/features.php?id=760"></ref><ref patch="1" source="" url="http://www.directadmin.com/versions.php"></ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/24728">24728</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2534">2534</ref></refs><vuln_soft><prod name="DirectAdmin" vendor="JBMC Software"><vers num="1.293" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" modified="2007-04-11" name="CVE-2007-1927" published="2007-04-10" seq="2007-1927" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in signup.asp in CmailServer WebMail 5.3.4 and earlier allows remote attackers to inject arbitrary web script or HTML via the POP3Mail parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/464966/100/0/threaded">20070407 CmailServer WebMail &lt;= V.5.3.4 (signup) Remote XSS Exploit</ref><ref source="BID" url="http://www.securityfocus.com/bid/23360">23360</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24812">
24812</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33501">
cmailserver-signup-xss(33501)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2529">2529</ref></refs><vuln_soft><prod name="CMailServer" vendor="YoungZSoft"><vers num="5.3.4" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-04-11" name="CVE-2007-1928" published="2007-04-10" seq="2007-1928" severity="High" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in index.php in witshare 0.9 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the menu parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/464969/100/0/threaded">20070407 witshare 0.9 Remote File Include Vulnerabilitiy</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/23358">23358</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1303">
ADV-2007-1303</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24813">
24813</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33496">
witshare-index-file-include(33496)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2539">2539</ref></refs><vuln_soft><prod name="WitShare" vendor="WitShare"><vers num="0.9"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0" modified="2007-06-26" name="CVE-2007-1929" published="2007-04-10" seq="2007-1929" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in downloadpic.php in Beryo 2.0, and possibly other versions including 2.4, allows remote atatckers to read arbitrary files via a .. (dot dot) in the chemin parameter.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3676">3676</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1296">ADV-2007-1296</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33479">beryo-downloadpic-directory-traversal(33479)</ref><ref source="BID" url="http://www.securityfocus.com/bid/23387">23387</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24811">24811</ref></refs><vuln_soft><prod name="Beryo" vendor="Gna"><vers num="2.0"/><vers num="2.4"/></prod></vuln_soft></entry><entry CVSS_base_score="7.8" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.9" CVSS_score="7.8" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:N/A:N)" CVSS_version="2.0" modified="2007-08-02" name="CVE-2007-1930" published="2007-04-10" seq="2007-1930" severity="High" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in download2.php in cattaDoc 2.21, and possibly other versions including 3.0, allows remote attackers to read arbitrary files via a .. (dot dot) in the fn1 parameter.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3677">3677</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1297">ADV-2007-1297</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33474">cattadoc-download2-directory-traversal(33474)</ref><ref source="BID" url="http://www.securityfocus.com/bid/23390">23390</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24807">24807</ref></refs><vuln_soft><prod name="cattaDoc" vendor="cattaDoc"><vers num="2.21"/><vers num="3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-04-11" name="CVE-2007-1931" published="2007-04-10" seq="2007-1931" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in index.php in the slownik module in SmodCMS 2.10 and earlier allows remote attackers to execute arbitrary SQL commands via the ssid parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3679">3679</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1299">ADV-2007-1299</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33477">smodcms-ssid-sql-injection(33477)</ref></refs><vuln_soft><prod name="SmodCMS" vendor="SmodCMS"><vers num="2.10" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-04-11" name="CVE-2007-1932" published="2007-04-10" seq="2007-1932" severity="High" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in scarnews.inc.php in ScarNews 1.2.1 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the sn_admin_dir parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3687">3687</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1304">ADV-2007-1304</ref><ref source="BID" url="http://www.securityfocus.com/bid/23375">
23375</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24796">
24796</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33492">
scarnews-scarnewsinc-file-include(33492)</ref></refs><vuln_soft><prod name="ScarNews" vendor="Scar4U"><vers num="1.2.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-05-22" name="CVE-2007-1933" published="2007-04-10" seq="2007-1933" severity="High" type="CVE"><desc><descript source="cve">Multiple directory traversal vulnerabilities in PcP-Guestbook (PcP-Book) 3.0 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the lang parameter to (1) index.php, (2) gb.php, or (3) faq.php.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33491">pcpguestbook-lang-file-include(33491)</ref></refs><vuln_soft><prod name="PcP-Guestbook" vendor="DreamCodes"><vers num="3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-04-11" name="CVE-2007-1934" published="2007-04-10" seq="2007-1934" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in member.php in the eBoard 1.0.7 module for PHP-Nuke allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the GLOBALS[name] parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3683">3683</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1301">ADV-2007-1301</ref><ref source="BID" url="http://www.securityfocus.com/bid/23365">
23365</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24806">
24806</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33493">
eboard-member-file-include(33493)</ref></refs><vuln_soft><prod name="eBoard Module" vendor="PHP-Nuke"><vers num="1.0.7"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-04-11" name="CVE-2007-1935" published="2007-04-10" seq="2007-1935" severity="Medium" type="CVE"><desc><descript source="cve">PHP file inclusion vulnerability in admin/index.php in ScarAdControl (ScarAdController) 1.1 allows remote attackers to execute arbitrary PHP code via a UNC share pathname or a local file pathname in the site parameter, which is accessed by the file_exists function.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3682">3682</ref></refs><vuln_soft><prod name="ScarAdController" vendor="Scar4U.de"><vers num="1.1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-04-11" name="CVE-2007-1936" published="2007-04-10" seq="2007-1936" severity="Medium" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in scaradcontrol.php in ScarAdControl (ScarAdController) 1.1 allows remote attackers to execute arbitrary PHP code via a URL in the sac_config_dir parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3682">3682</ref></refs><vuln_soft><prod name="ScarAdController" vendor="Scar4U.de"><vers num="1.1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-04-11" name="CVE-2007-1937" published="2007-04-10" seq="2007-1937" severity="Medium" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in smilies.php in Scorp Book 1.0 allows remote attackers to execute arbitrary PHP code via a URL in the config parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3681">3681</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1300">ADV-2007-1300</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/465079/100/0/threaded">

20070408 Scorp Book &lt;== v1.0 (smilies.php) Remote File Include Exploit</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24809">
24809</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33495">
scorp-smilies-file-include(33495)</ref></refs><vuln_soft><prod name="Scorp Book" vendor="DreamCodes"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" modified="2008-01-02" name="CVE-2007-1938" published="2007-04-10" seq="2007-1938" severity="Medium" type="CVE"><desc><descript source="cve">Ichitaro 2005 through 2007, and possibly related products, allows remote attackers to have an unknown impact via unspecified vectors in a document distributed through e-mail or a web site, possibly due to a buffer overflow or cross-site scripting (XSS).</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref source="" url="http://www.justsystem.co.jp/info/pd7002.html"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1287">ADV-2007-1287</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24780">24780</ref><ref source="BID" url="http://www.securityfocus.com/bid/23386">23386</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017887">1017887</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33507">ichitaro-unspecified-code-execution(33507)</ref><ref source="" url="http://vil.mcafeesecurity.com/vil/content/v_141950.htm"></ref></refs><vuln_soft><prod name="Ichitaro" vendor="Ichitaro"><vers num="2005"/><vers num="2006"/><vers num="2007"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-08-02" name="CVE-2007-1939" published="2007-04-10" seq="2007-1939" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in the embedded webserver in Daniel Naber LanguageTool before 0.8.9 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors involving an error message, possibly the demultiplex method in HTTPServer.java.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://www.danielnaber.de/languagetool/download/CHANGES.txt"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1759">ADV-2007-1759</ref></refs><vuln_soft><prod name="LanguageTool" vendor="Daniel Naber"><vers num="0.8.8" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.9" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.9" CVSS_score="4.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:N/A:N)" CVSS_version="2.0" modified="2007-04-11" name="CVE-2007-1940" published="2007-04-10" seq="2007-1940" severity="Medium" type="CVE"><desc><descript source="cve">IBM Tivoli Business Service Manager (TBSM) 4.1 before Interim Fix 1 logs passwords in plaintext, which allows local users to obtain sensitive information by reading (1) ncisetup.db or (2) msi.log.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref source="AIXAPAR" url="http://www-1.ibm.com/support/docview.wss?uid=swg24015473">IY96572</ref><ref source="BID" url="http://www.securityfocus.com/bid/23298">23298</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1248">ADV-2007-1248</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017869">1017869</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24763">24763</ref></refs><vuln_soft><prod name="Tivoli Business Service Manager" vendor="IBM"><vers num="4.1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)" CVSS_version="2.0" modified="2007-04-11" name="CVE-2007-1941" published="2007-04-10" seq="2007-1941" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in the Active Content Filter feature in Domino Web Access (DWA) in IBM Lotus Notes before 6.5.6 and 7.x before 7.0.2 FP1 allows remote attackers to inject arbitrary web script or HTML via a multipart/related e-mail message, a different issue than CVE-2006-4843.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://www.intrinsec.com/Advisory_DWA_XSS_200704.txt"></ref><ref adv="1" source="" url="http://www-1.ibm.com/support/docview.wss?rs=477&amp;uid=swg21247201"></ref><ref adv="1" source="SECTRACK" url="http://www.securitytracker.com/id?1017870">1017870</ref><ref source="BID" url="http://www.securityfocus.com/bid/23421">
23421</ref></refs><vuln_soft><prod name="Lotus Notes" vendor="IBM"><vers num="6.5.5"/><vers num="7.0"/><vers num="7.0.1"/></prod></vuln_soft></entry><entry CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" CVSS_score="9.3" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-04-12" name="CVE-2007-1942" published="2007-04-10" seq="2007-1942" severity="High" type="CVE"><desc><descript source="cve">Integer overflow in FastStone Image Viewer 2.9 allows context-dependent attackers to cause a denial of service and possibly execute arbitrary code via a crafted BMP image, as demonstrated by wh3intof.bmp and wh4intof.bmp.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><design/><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/464726/100/0/threaded">20070404 Several Windows image viewers vulnerabilities</ref><ref adv="1" source="" url="http://ifsec.blogspot.com/2007/04/several-windows-image-viewers.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/23312">23312</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24784">24784</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2558">2558</ref></refs><vuln_soft><prod name="Image Viewer" vendor="FastStone"><vers num="2.9"/></prod></vuln_soft></entry><entry CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" CVSS_score="9.3" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-04-12" name="CVE-2007-1943" published="2007-04-10" seq="2007-1943" severity="High" type="CVE"><desc><descript source="cve">Integer overflow in ACDSee Photo Manager 9.0 allows context-dependent attackers to cause a denial of service and possibly execute arbitrary code via large width image sizes in a crafted BMP image, as demonstrated by w3intof.bmp and w4intof.bmp.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input/><design/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/464726/100/0/threaded">20070404 Several Windows image viewers vulnerabilities</ref><ref adv="1" source="" url="http://ifsec.blogspot.com/2007/04/several-windows-image-viewers.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/23317">23317</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1283">ADV-2007-1283</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24779">24779</ref><ref source="" url="http://www.acdsee.com/support/knowledgebase/article?id=2800"></ref><ref source="SREASON" url="http://securityreason.com/securityalert/2558">2558</ref></refs><vuln_soft><prod name="ACDSee Photo Manager" vendor="ACD Systems"><vers num="9.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0" modified="2008-02-26" name="CVE-2007-1944" published="2007-04-10" seq="2007-1944" severity="Medium" type="CVE"><desc><descript source="cve">The Java Message Service (JMS) in IBM WebSphere Application Server (WAS) before 6.1.0.7 allows attackers to cause a denial of service via unknown vectors involving the &quot;double release [of] a bytebuffer input stream,&quot; possibly a double free vulnerability.</descript></desc><loss_types><avail/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref patch="1" source="" url="http://www-1.ibm.com/support/docview.wss?rs=180&amp;uid=swg27007951#6107"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1282">ADV-2007-1282</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24852">24852</ref></refs><vuln_soft><prod name="WebSphere Application Server" vendor="IBM"><vers num="6.1.0.1" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-04-12" name="CVE-2007-1945" published="2007-04-10" seq="2007-1945" severity="High" type="CVE"><desc><descript source="cve">Unspecified vulnerability in the Servlet Engine/Web Container in IBM WebSphere Application Server (WAS) before 6.1.0.7 has unknown impact and attack vectors.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><range><network/></range><refs><ref patch="1" source="" url="http://www-1.ibm.com/support/docview.wss?rs=180&amp;uid=swg27007951#6107"></ref><ref patch="1" source="AIXAPAR" url="http://www-1.ibm.com/support/search.wss?rs=0&amp;q=PK36447&amp;apar=only">PK36447</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1282">ADV-2007-1282</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33471">websphere-servlet-information-disclosure(33471)</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24852">
24852</ref></refs><vuln_soft><prod name="WebSphere Application Server" vendor="IBM"><vers num="6.1.0.1" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-04-12" name="CVE-2007-1946" published="2007-04-10" seq="2007-1946" severity="High" type="CVE"><desc><descript source="cve">Integer overflow in Windows Explorer in Microsoft Windows XP SP1 might allow user-assisted remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a large width dimension in a crafted BMP image, as demonstrated by w4intof.bmp.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input/><design/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/464726/100/0/threaded">20070404 Several Windows image viewers vulnerabilities</ref><ref adv="1" source="" url="http://ifsec.blogspot.com/2007/04/several-windows-image-viewers.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/23321">23321</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2558">2558</ref></refs><vuln_soft><prod name="Windows XP" vendor="Microsoft"><vers num="SP1"/></prod></vuln_soft></entry><entry CVSS_base_score="3.5" CVSS_exploit_subscore="6.8" CVSS_impact_subscore="2.9" CVSS_score="3.5" CVSS_vector="(AV:N/AC:M/Au:S/C:N/I:P/A:N)" CVSS_version="2.0" modified="2007-04-12" name="CVE-2007-1947" published="2007-04-10" seq="2007-1947" severity="Low" type="CVE"><desc><descript source="cve">Cross-zone scripting vulnerability in the DOM templates (domplates) used by the console.log function in the Firebug extension before 1.04 for Mozilla Firefox allows remote attackers to bypass zone restrictions, read arbitrary file:// URIs, or execute arbitrary code in the browser chrome by overwriting the toString function via a certain function declaration, related to incorrect identification of anonymous JavaScript functions, a different issue than CVE-2007-1878.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/464875/100/0/threaded">20070406 Re: Firefox extensions go Evil - Critical Vulnerabilities in Firefox/Firebug</ref><ref adv="1" source="" url="http://larholm.com/2007/04/06/more-0day-in-firebug/"></ref><ref adv="1" patch="1" source="" url="http://larholm.com/2007/04/06/more-0day-in-firebug/#comment-6"></ref></refs><vuln_soft><prod name="Firebug" vendor="Parakey Inc."><vers num="1.03" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" CVSS_score="9.3" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-04-12" name="CVE-2007-1948" published="2007-04-10" seq="2007-1948" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in IrfanView 3.99 allows context-dependent attackers to cause a denial of service and possibly execute arbitrary code via the (1) xoffset or (2) yoffset RLE command, or (3) large non-RLE encoded blocks in a crafted BMP image, as demonstrated by rle8of3.bmp and rle8of4.bmp.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input/><design/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/464726/100/0/threaded">20070404 Several Windows image viewers vulnerabilities</ref><ref adv="1" source="" url="http://ifsec.blogspot.com/2007/04/several-windows-image-viewers.html"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1284">ADV-2007-1284</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2558">2558</ref></refs><vuln_soft><prod name="IrfanView" vendor="IrfanView"><vers num="3.99"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" discovered="2007-03-30" modified="2007-04-12" name="CVE-2007-1949" published="2007-04-10" seq="2007-1949" severity="High" type="CVE"><desc><descript source="cve">Session fixation vulnerability in WebBlizzard CMS allows remote attackers to hijack web sessions by setting a PHPSESSID cookie.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/464959/100/0/threaded">20070407 [MajorSecurity Advisory #42]webblizzard CMS - Cross Site Scripting and Session fixation Issues</ref><ref adv="1" source="" url="http://www.majorsecurity.de/index_2.php?major_rls=major_rls42"></ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33499">
webblizzardcms-cookie-session-hijack(33499)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2557">2557</ref></refs><vuln_soft><prod name="Content Management System" vendor="WebBlizzard"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" modified="2007-04-12" name="CVE-2007-1950" published="2007-04-10" seq="2007-1950" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in index_cms.php in WebBlizzard CMS allows remote attackers to inject arbitrary web script or HTML via the Suchzeile parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/464959/100/0/threaded">20070407 [MajorSecurity Advisory #42]webblizzard CMS - Cross Site Scripting and Session fixation Issues</ref><ref adv="1" patch="1" source="" url="http://www.majorsecurity.de/index_2.php?major_rls=major_rls42"></ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33498">
webblizzardcms-indexcms-xss(33498)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2557">2557</ref></refs><vuln_soft><prod name="Content Management System" vendor="WebBlizzard"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-04-12" name="CVE-2007-1951" published="2007-04-10" seq="2007-1951" severity="High" type="CVE"><desc><descript source="cve">Session fixation vulnerability in onelook obo Shop allows remote attackers to hijack web sessions by setting a PHPSESSID cookie.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/464886/100/0/threaded">20070406 [MajorSecurity Advisory #40]onelook oboShop - Session fixation Issue</ref><ref adv="1" source="" url="http://www.majorsecurity.de/index_2.php?major_rls=major_rls40"></ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33500">
oboshop-phpsessid-security-bypass(33500)</ref></refs><vuln_soft><prod name="oboShop" vendor="Onelook"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" discovered="2007-03-30" modified="2007-04-12" name="CVE-2007-1952" published="2007-04-10" seq="2007-1952" severity="High" type="CVE"><desc><descript source="cve">Session fixation vulnerability in onelook onebyone CMS allows remote attackers to hijack web sessions by setting a PHPSESSID cookie.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/464884/100/0/threaded">20070406 [MajorSecurity Advisory #39]onelook onebyone CMS - Session fixation Issue</ref><ref adv="1" source="" url="http://www.majorsecurity.de/index_2.php?major_rls=major_rls39"></ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33497">
onebyonecms-phpsessid-security-bypass(33497)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2546">2546</ref></refs><vuln_soft><prod name="onebyone CMS" vendor="Onelook"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" discovered="2007-03-30" modified="2007-04-12" name="CVE-2007-1953" published="2007-04-10" seq="2007-1953" severity="High" type="CVE"><desc><descript source="cve">Session fixation vulnerability in onelook courts on-line allows remote attackers to hijack web sessions by setting a PHPSESSID cookie.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/464887/100/0/threaded">20070406 [MajorSecurity Advisory #41]onelook courts online - Session fixation Issue</ref><ref adv="1" source="" url="http://www.majorsecurity.de/index_2.php?major_rls=major_rls41"></ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33502">
courtsonline-phpsessid-security-bypass(33502)</ref></refs><vuln_soft><prod name="courts online" vendor="Onelook"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-04-12" name="CVE-2007-1954" published="2007-04-10" seq="2007-1954" severity="High" type="CVE"><desc><descript source="cve">Multiple directory traversal vulnerabilities in ArchiveXpert 2.02 build 80 allow remote attackers to create files in arbitrary directories via a .. (dot dot) in a (1) .gz, (2) .jar, (3) .rar, (4) .tar.gz, (5) .zip, or (6) .tar file.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://www.bugtraq.ir/articles/advisory/archivexpert_directory_traversal/8"></ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24827">24827</ref><ref source="BID" url="http://www.securityfocus.com/bid/23372">
23372</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1311">
ADV-2007-1311</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33539">
archivexpert-archive-directory-traversal(33539)</ref></refs><vuln_soft><prod name="ArchiveXpert" vendor="ArchiveXpert"><vers num="2.02 Build 80"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-04-12" name="CVE-2007-1955" published="2007-04-10" seq="2007-1955" severity="High" type="CVE"><desc><descript source="cve">Multiple stack-based buffer overflows in the SignKorea SKCrypAX ActiveX control module 5.4.1.2 allow remote attackers to execute arbitrary code via a long string in unspecified arguments to the (1) DownloadCert, (2) DecryptFileByKey, and (3) EncryptFileByKey functions, a different module and vectors than CVE-2007-1722.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24820">24820</ref><ref source="BID" url="http://www.securityfocus.com/bid/23374">

23374</ref></refs><vuln_soft><prod name="SKCommAX ActiveX Control" vendor="SignKorea"><vers num="5.4.1.2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-04-12" name="CVE-2007-1956" published="2007-04-10" seq="2007-1956" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in ubbthreads.php in Groupee UBB.threads 6.1.1 and earlier allows remote attackers to execute arbitrary SQL commands via the C parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/465076/100/0/threaded">20070408 UBB.threads (&lt;= 6.1.1) SQL Injection Vulnerability</ref><ref source="BID" url="http://www.securityfocus.com/bid/23369">
23369</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33509">
ubbthreads-ubbthreads-sql-injection(33509)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2545">2545</ref></refs><vuln_soft><prod name="UBB.threads" vendor="UBBCentral"><vers num="6.1.1" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-04-12" name="CVE-2007-1957" published="2007-04-10" seq="2007-1957" severity="Medium" type="CVE"><desc><descript source="cve">Multiple PHP remote file inclusion vulnerabilities in Guernion Sylvain Portail Web Php (aka Gsylvain35 Portail Web, PwP) allow remote attackers to execute arbitrary PHP code via a URL in the pageAll parameter to index.php in (1) template/Vert/, or (2) template/Noir/.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/465083/100/0/threaded">20070408 Gsylvain35 Portail Web Remote File Include Vulnerabilities</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2543">2543</ref></refs><vuln_soft><prod name="Web Php" vendor="Guernion Sylvain Portail"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0" modified="2007-04-12" name="CVE-2007-1958" published="2007-04-11" seq="2007-1958" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in TinyMUX before 2.4 allows attackers to cause a denial of service via unspecified vectors related to &quot;too many substring matches in a regexp $-command.&quot; NOTE: some of these details are obtained from third party information.</descript></desc><loss_types><avail/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref source="" url="http://www.tinymux.org/changes.txt"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1213">ADV-2007-1213</ref></refs><vuln_soft><prod name="TinyMUX" vendor="TinyMUX"><vers num="2.3" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-04-12" name="CVE-2007-1959" published="2007-04-11" seq="2007-1959" severity="High" type="CVE"><desc><descript source="cve">Unspecified vulnerability in the process_cmdent function in command.cpp in TinyMUX before 2.4 has unknown impact and attack vectors, related to lack of the &quot;&apos;other half&apos; of buffer overflow protection.&quot;</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs><ref source="" url="http://www.tinymux.org/changes.txt"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1213">ADV-2007-1213</ref></refs><vuln_soft><prod name="TinyMUX" vendor="TinyMUX"><vers num="2.3" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-08-02" name="CVE-2007-1960" published="2007-04-11" seq="2007-1960" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in visit.php in the Rha7 Downloads (rha7downloads) 1.0 module for XOOPS, and possibly other versions up to 1.10, allows remote attackers to execute arbitrary SQL commands via the lid parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3666">3666</ref><ref source="BID" url="http://www.securityfocus.com/bid/23320">23320</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24790">24790</ref></refs><vuln_soft><prod name="Rha7 Downloads Module" vendor="Xoops"><vers num="1.0"/><vers num="1.10"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-04-12" name="CVE-2007-1961" published="2007-04-11" seq="2007-1961" severity="High" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in mutant_functions.php in the Mutant 0.9.2 portal for phpBB 2.2 allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3665">3665</ref><ref source="BID" url="http://www.securityfocus.com/bid/23319">23319</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1265">
ADV-2007-1265</ref></refs><vuln_soft><prod name="Mutant" vendor="phpBB"><vers num="0.9.2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-08-02" name="CVE-2007-1962" published="2007-04-11" seq="2007-1962" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in index.php in the WF-Snippets 1.02 and earlier module for XOOPS allows remote attackers to execute arbitrary SQL commands via the c parameter in a cat action.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3663">3663</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33425">xoops-wfsnippets-index-sql-injection(33425)</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1263">ADV-2007-1263</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24781">24781</ref></refs><vuln_soft><prod name="WF-Snippets" vendor="Xoops"><vers num="1.02" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-04-12" name="CVE-2007-1963" published="2007-04-11" seq="2007-1963" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in the create_session function in class_session.php in MyBB (aka MyBulletinBoard) 1.2.3 and earlier allows remote attackers to execute arbitrary SQL commands via the Client-IP HTTP header, as utilized by index.php, a related issue to CVE-2006-3775.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/464563/100/0/threaded">20070403 MyBulletinBoard (MyBB) &lt;= 1.2.3 Remote Code Execution Exploit</ref><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3653">3653</ref><ref source="" url="http://community.mybboard.net/attachment.php?aid=5842"></ref><ref source="" url="http://community.mybboard.net/showthread.php?tid=18002"></ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1244">ADV-2007-1244</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/24689">24689</ref></refs><vuln_soft><prod name="MyBB" vendor="MyBB"><vers num="1.2.3" prev="1"/></prod><prod name="MyBulletinBoard" vendor="MyBulletinBoard"><vers num="1.2.3" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.0" CVSS_exploit_subscore="6.8" CVSS_impact_subscore="6.4" CVSS_score="6.0" CVSS_vector="(AV:N/AC:M/Au:S/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-04-12" name="CVE-2007-1964" published="2007-04-11" seq="2007-1964" severity="Medium" type="CVE"><desc><descript source="cve">member.php in MyBB (aka MyBulletinBoard), when debug mode is available, allows remote authenticated users to change the password of any account by providing the account&apos;s registered e-mail address in a debug request for a do_lostpw action, which prints the change password verification code in the debug output.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/><design/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/464267/100/100/threaded">20070330 Mybb Change Password Vulnerability</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2544">2544</ref></refs><vuln_soft><prod name="MyBB" vendor="MyBB"><vers num=""/></prod><prod name="MyBulletinBoard" vendor="MyBulletinBoard"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" discovered="2007-04-01" modified="2007-04-12" name="CVE-2007-1965" published="2007-04-11" seq="2007-1965" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in eXV2 CMS 2.0.4.3 and earlier allow remote attackers to inject arbitrary web script or HTML via the set_lang parameter to (1) archive.php, (2) article.php, (3) index.php, or (4) topics.php.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=117570977117962&amp;w=2">20070404 [MajorSecurity Advisory #38]eXV2 CMS - Session fixation and Cross-Site-Scripting Issues</ref><ref adv="1" source="" url="http://www.majorsecurity.de/index_2.php?major_rls=major_rls38"></ref><ref source="BID" url="http://www.securityfocus.com/bid/23314">23314</ref></refs><vuln_soft><prod name="Content Management System" vendor="exV2"><vers num="2.0.4.3" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" modified="2007-04-12" name="CVE-2007-1966" published="2007-04-11" seq="2007-1966" severity="Medium" type="CVE"><desc><descript source="cve">Session fixation vulnerability in eXV2 CMS 2.0.4.3 and earlier allows remote attackers to hijack web sessions by setting the PHPSESSID cookie.</descript></desc><loss_types><int/></loss_types><vuln_types><access/><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=117570977117962&amp;w=2">20070404 [MajorSecurity Advisory #38]eXV2 CMS - Session fixation and Cross-Site-Scripting Issues</ref><ref adv="1" patch="1" source="" url="http://www.majorsecurity.de/index_2.php?major_rls=major_rls38"></ref></refs><vuln_soft><prod name="Content Management System" vendor="exV2"><vers num="2.0.4.3"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-08-02" name="CVE-2007-1967" published="2007-04-11" seq="2007-1967" severity="Medium" type="CVE"><desc><descript source="cve">** DISPUTED **  PHP remote file inclusion vulnerability in index.php in stat12 allows remote attackers to execute arbitrary PHP code via a URL in the langpath parameter.  NOTE: this issue was published by an unreliable researcher, and there is little information to determine which product is actually affected.  This is probably an invalid report based on analysis by CVE and a third party.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/464582/100/0/threaded">20070403 Remote File Include In Script stat12</ref><ref source="VIM" url="http://www.attrition.org/pipermail/vim/2007-April/001488.html">20070403 [false] Remote File Include In Script stat12</ref><ref source="VIM" url="http://www.attrition.org/pipermail/vim/2007-April/001508.html">20070411 [false] Remote File Include In Script stat12</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2555">2555</ref></refs><vuln_soft><prod name="Stat12" vendor="Stat12"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-04-12" name="CVE-2007-1968" published="2007-04-11" seq="2007-1968" severity="Medium" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in games.php in Sam Crew MyBlog, possibly 1.0 through 1.6, allows remote attackers to execute arbitrary PHP code via a URL in the scoreid parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/464716/100/0/threaded">20070404 MyBlog: PHP and MySQL Blog/CMS software Remote File Include Vulnerabilitiy</ref><ref source="VIM" url="http://www.attrition.org/pipermail/vim/2007-April/001503.html">20070410 True: MyBlog games.php RFI</ref><ref source="BID" url="http://www.securityfocus.com/bid/23311">23311</ref><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3685">
3685</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1302">
ADV-2007-1302</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2548">2548</ref></refs><vuln_soft><prod name="MyBlog" vendor="Sam Crew"><vers num="1.0"/><vers num="1.1"/><vers num="1.2"/><vers num="1.3"/><vers num="1.4"/><vers num="1.5"/><vers num="1.6"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" modified="2007-04-12" name="CVE-2007-1969" published="2007-04-11" seq="2007-1969" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in admin/modify.php in Sam Crew MyBlog remote attackers to inject arbitrary web script or HTML via the id parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/464712/100/0/threaded">20070404 MyBlog: PHP and MySQL Blog/CMS software Cross-Site Scripting Vulnerabilitiy</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2549">2549</ref></refs><vuln_soft><prod name="MyBlog" vendor="Sam Crew"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0" modified="2007-04-12" name="CVE-2007-1970" published="2007-04-11" seq="2007-1970" severity="Medium" type="CVE"><desc><descript source="cve">Mozilla Firefox does not warn the user about HTTP elements on an HTTPS page when the HTTP elements are dynamically created by a delayed document.write, which allows remote attackers to supply unauthenticated content and conduct phishing attacks.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/464719/100/0/threaded">20070404 Mozilla Firefox Insecure Element Stealth Injection Vulnerability</ref></refs><vuln_soft><prod name="Firefox" vendor="Mozilla"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-04-17" name="CVE-2007-1971" published="2007-04-11" seq="2007-1971" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in fotokategori.asp in Gazi Okul Sitesi 2007 allows remote attackers to execute arbitrary SQL commands via the query string.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/464738/100/0/threaded">20070404 Gazi Okul Sitesi 2007(tr)(fotokategori.asp) Remote SQL Injection</ref><ref source="BID" url="http://www.securityfocus.com/bid/23316">23316</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2547">2547</ref></refs><vuln_soft><prod name="Gazi Okul Sitesi" vendor="Gazi Okul Sitesi"><vers num="2007"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-04-23" name="CVE-2007-1972" published="2007-04-22" seq="2007-1972" severity="High" type="CVE"><desc><descript source="cve">** DISPUTED **  PatrolAgent.exe in BMC Performance Manager does not require authentication for requests to modify configuration files, which allows remote attackers to execute arbitrary code via a request on TCP port 3181 for modification of the masterAgentName and masterAgentStartLine SNMP parameters.  NOTE: the vendor disputes this vulnerability, stating that it does not exist when the system is properly configured.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><access/><design/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/466223/100/0/threaded">20070418 ZDI-07-020: BMC Performance Manager SNMP Command Execution Vulnerability</ref><ref adv="1" source="" url="http://www.zerodayinitiative.com/advisories/ZDI-07-020.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/23559">23559</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1458">ADV-2007-1458</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/466274/100/0/threaded">
20070419 Re: ZDI-07-020: BMC Performance Manager SNMP Command Execution Vulnerability</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017935">
1017935</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2599">2599</ref></refs><vuln_soft><prod name="Performance Manager" vendor="BMC Software"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="6.9" CVSS_exploit_subscore="3.4" CVSS_impact_subscore="10.0" CVSS_score="6.9" CVSS_vector="(AV:L/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-04-17" name="CVE-2007-1973" published="2007-04-11" seq="2007-1973" severity="Medium" type="CVE"><desc><descript source="cve">Race condition in the Virtual DOS Machine (VDM) in the Windows Kernel in Microsoft Windows NT 4.0 allows local users to modify memory and gain privileges via the temporary \Device\PhysicalMemory section handle, a related issue to CVE-2007-1206.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><race/></vuln_types><range><local/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/465232/100/0/threaded">20070410 EEYE: Windows VDM Zero Page Race Condition Privilege Escalation</ref><ref adv="1" source="" url="http://research.eeye.com/html/advisories/published/AD20070410a.html"></ref><ref source="SREASON" url="http://securityreason.com/securityalert/2563">2563</ref></refs><vuln_soft><prod name="Windows NT" vendor="Microsoft"><vers num="4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-04-17" name="CVE-2007-1974" published="2007-04-11" seq="2007-1974" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in the getArticle function in class/wfsarticle.php in WF-Section (aka WF-Sections) 1.0.1, as used in Xoops modules such as (1) Zmagazine 1.0, (2) Happy Linux XFsection 1.07 and earlier, and possibly other modules, allows remote attackers to execute arbitrary SQL commands via the articleid parameter to print.php.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3644">3644</ref><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3645">3645</ref><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3646">3646</ref><ref adv="1" source="" url="http://www.xoops.org/modules/newbb/viewtopic.php?viewmode=flat&amp;order=ASC&amp;topic_id=58229&amp;forum=4&amp;move=next&amp;topic_time=1176217411"></ref><ref adv="1" patch="1" source="" url="http://www.xoops.org/modules/news/article.php?storyid=3717"></ref><ref patch="1" source="" url="http://addons.zarilia.com/index.php?page_type=static&amp;id=43"></ref><ref adv="1" source="VIM" url="http://www.attrition.org/pipermail/vim/2007-April/001507.html">20070411 WF-Sections SQL injection vendor ack; shows up in other modules</ref><ref source="BID" url="http://www.securityfocus.com/bid/23258">23258</ref><ref source="BID" url="http://www.securityfocus.com/bid/23259">23259</ref><ref source="BID" url="http://www.securityfocus.com/bid/23261">23261</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1207">ADV-2007-1207</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1208">ADV-2007-1208</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1209">ADV-2007-1209</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33378">xoops-wfsection-print-sql-injection(33378)</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33379">xoops-zmagazine-print-sql-injection(33379)</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33380">xoops-xfsection-print-sql-injection(33380)</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/488317/100/0/threaded">20080218 XOOPS Module section SQL Injection(articleid)</ref></refs><vuln_soft><prod name="ZMagazine Module" vendor="Xoops"><vers num="1.0"/></prod><prod name="WF-Sections" vendor="WF-Sections"><vers num="1.0.1"/></prod><prod name="Happy Linux XFsection Module" vendor="Xoops"><vers num="1.07" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-04-17" name="CVE-2007-1975" published="2007-04-11" seq="2007-1975" severity="High" type="CVE"><desc><descript source="cve">Multiple PHP remote file inclusion vulnerabilities in SLAED CMS 2 allow remote attackers to execute arbitrary PHP code via a URL in the (1) path parameter to admin/admin.php or the (2) modpath parameter to index.php.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/464349/100/0/threaded">20070331 Remot File Include In SLAED_CMS_2</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33343">slaed-index-admin-file-include(33343)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2567">2567</ref></refs><vuln_soft><prod name="SLAED CMS" vendor="SLAED"><vers num="2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-04-17" name="CVE-2007-1976" published="2007-04-11" seq="2007-1976" severity="High" type="CVE"><desc><descript source="cve">** DISPUTED **  PHP remote file inclusion vulnerability in index.php in the Virii Info 1.10 and earlier module for Xoops allows remote attackers to execute arbitrary PHP code via a URL in the xoopsConfig[root_path] parameter. NOTE: the issue has been disputed by a reliable third party, stating that the application&apos;s checkSuperglobals function defends against the attack.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3642">3642</ref><ref source="VIM" url="http://www.attrition.org/pipermail/vim/2007-April/001489.html">20070403 Bogus - [Xoops Module Virii Info &lt;= 1.10 (index.php) Remote File Include Exploit]</ref><ref source="VIM" url="http://www.attrition.org/pipermail/vim/2007-April/001490.html">20070403 Bogus - [Xoops Module Virii Info &lt;= 1.10 (index.php) Remote File Include Exploit]</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1206">ADV-2007-1206</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33368">xoops-virii-index-file-include(33368)</ref></refs><vuln_soft><prod name="Xoops Virii Info Module" vendor="Xoops"><vers num="1.10" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" modified="2007-04-16" name="CVE-2007-1977" published="2007-04-11" seq="2007-1977" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in index_cms.php in holaCMS 1.4.10 allows remote attackers to inject arbitrary web script or HTML via the acuparam parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref source="" url="http://www.majorsecurity.de/index_2.php?major_rls=major_rls37"></ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24656">24656</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/464572/100/200/threaded">

20070403 [MajorSecurity Advisory #37]HolaCMS - Cross Site Scripting Issue</ref><ref source="BID" url="http://www.securityfocus.com/bid/23288">
23288</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33392">
holacms-indexcms-xss(33392)</ref></refs><vuln_soft><prod name="holaCMS" vendor="holaCMS"><vers num="1.4.10"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-04-16" name="CVE-2007-1978" published="2007-04-11" seq="2007-1978" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in index.php in the Arcade 1.00 module for PHP-Fusion allows remote attackers to execute arbitrary SQL commands via the cid parameter in a view_game_list action.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3640">3640</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1205">ADV-2007-1205</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33361">phpfusion-arcade-index-sql-injection(33361)</ref></refs><vuln_soft><prod name="Arcade Module" vendor="PHP_Fusion"><vers num="1.00"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-04-16" name="CVE-2007-1979" published="2007-04-11" seq="2007-1979" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in index.php in the PopnupBlog 2.52 and earlier module for Xoops allows remote attackers to execute arbitrary SQL commands via the postid parameter, possibly involving the get_blogid_from_postid function in class/PopnupBlogUtils.php.  NOTE: later versions such as 3.03 and 3.05 might also be affected.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3655">3655</ref><ref source="BID" url="http://www.securityfocus.com/bid/23286">23286</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1206">ADV-2007-1206</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24761">24761</ref></refs><vuln_soft><prod name="Xoops PopnupBlog" vendor="Xoops"><vers num="2.52" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-04-16" name="CVE-2007-1980" published="2007-04-11" seq="2007-1980" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in index.php in the Topliste 1.0 module for PHP-Fusion allows remote attackers to execute arbitrary SQL commands via the cid parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3639">3639</ref><ref source="BID" url="http://www.securityfocus.com/bid/23256">23256</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1204">ADV-2007-1204</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33364">phpfusion-topliste-index-sql-injection(33364)</ref></refs><vuln_soft><prod name="Topliste Module" vendor="Nick Jones"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.8" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.9" CVSS_score="7.8" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_version="2.0" modified="2007-04-16" name="CVE-2007-1981" published="2007-04-11" seq="2007-1981" severity="High" type="CVE"><desc><descript source="cve">The safevoid_vsnprintf function in Metamod-P 1.19p29 and earlier on Windows allows remote attackers to cause a denial of service (daemon crash) via a long meta list command.</descript></desc><loss_types><avail/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref patch="1" source="" url="http://sourceforge.net/forum/forum.php?forum_id=681753"></ref><ref source="" url="http://sourceforge.net/project/shownotes.php?release_id=498782"></ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1247">ADV-2007-1247</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24738">24738</ref></refs><vuln_soft><prod name="Metamod-P" vendor="Metamod-P"><vers num="1.19 p29" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-04-16" name="CVE-2007-1982" published="2007-04-11" seq="2007-1982" severity="High" type="CVE"><desc><descript source="cve">Multiple PHP remote file inclusion vulnerabilities in Really Simple PHP and Ajax (RSPA) 2007-03-23 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the (1) __IncludeFilePHPClass, (2) __ClassPath, and (3) __class parameters to (a) rspa/framework/Controller_v5.php, and (b) rspa/framework/Controller_v4.php.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3641">3641</ref><ref source="" url="http://www.bugtraq.ir/articles/advisory/RSPA_File_Inclusion/6"></ref><ref source="BID" url="http://www.securityfocus.com/bid/23246">23246</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1190">ADV-2007-1190</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24671">24671</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33356">rspa-controller-file-include(33356)</ref></refs><vuln_soft><prod name="Really Simple PHP and Ajax" vendor="Really Simple PHP and Ajax"><vers num="2007-03-23" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-04-16" name="CVE-2007-1983" published="2007-04-11" seq="2007-1983" severity="High" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in include/default_header.php in Cyboards PHP Lite 1.21 allows remote attackers to execute arbitrary PHP code via a URL in the script_path parameter, a different vector than CVE-2006-2871.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3660">3660</ref><ref source="VIM" url="http://www.attrition.org/pipermail/vim/2007-April/001509.html">20070411 Cyboards PHP RFI: true for 1.21, fixed in at least 1.25</ref><ref source="BID" url="http://www.securityfocus.com/bid/23306">23306</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33406">cyboards-defaultheader-file-include(33406)</ref></refs><vuln_soft><prod name="Cyboards PHP Lite" vendor="Cyboards"><vers num="1.21"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-04-16" name="CVE-2007-1984" published="2007-04-11" seq="2007-1984" severity="High" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in index.php in lite-cms 0.2.1 allows remote attackers to execute arbitrary PHP code via a URL in the inc parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/464672/100/0/threaded">20070404 lite-cms-0.2.1 Remote File Include Vulnerabilities</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2559">2559</ref></refs><vuln_soft><prod name="lite-cms" vendor="lite-cms"><vers num="0.2.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-04-12" name="CVE-2007-1985" published="2007-04-11" seq="2007-1985" severity="High" type="CVE"><desc><descript source="cve">Multiple PHP remote file inclusion vulnerabilities in phpexplorator.php in phpexplorator 2.0 allow remote attackers to execute arbitrary PHP code via a URL in the (1) cmd or (2) lang_path parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/464695/100/0/threaded">20070404 Remot File Include In phpexplorator_2_0</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2564">2564</ref></refs><vuln_soft><prod name="phpexplorator" vendor="phpexplorator"><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-04-16" name="CVE-2007-1986" published="2007-04-11" seq="2007-1986" severity="High" type="CVE"><desc><descript source="cve">Multiple PHP remote file inclusion vulnerabilities in barnraiser AROUNDMe 0.7.7 allow remote attackers to execute arbitrary PHP code via a URL in the (1) language_path_core parameter to inc/core_profile.header.php, the (2) template_path_core parameter to template/barnraiser_01/maint_contact_view.tpl.php, and the (3) template_path parameter to template/barnraiser_01/default.tpl.php. NOTE: this issue might overlap CVE-2006-5533.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3659">3659</ref><ref source="BID" url="http://www.securityfocus.com/bid/23303">23303</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1262">
ADV-2007-1262</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24773">
24773</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33427">
aroundme-multiple-file-include(33427)</ref></refs><vuln_soft><prod name="AROUNDMe" vendor="Barnraiser"><vers num="0.7.7"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-04-16" name="CVE-2007-1987" published="2007-04-11" seq="2007-1987" severity="High" type="CVE"><desc><descript source="cve">** DISPUTED **  Multiple PHP remote file inclusion vulnerabilities in PHPEcho CMS 2.0 allow remote attackers to execute arbitrary PHP code via a URL in the (1) _plugin_file parameter to smarty/internals/core.load_pulgins.php or the (2) root_path parameter to index.php.  NOTE: CVE disputes (1) because the inclusion occurs within a function that is not called during a direct request. CVE disputes (2) because root_path is defined in config.php before use.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/464709/100/0/threaded">20070404 phpechocms2 Remote File Include Vulnerabilities</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2551">2551</ref></refs><vuln_soft><prod name="PHPEcho CMS" vendor="PHPEcho CMS"><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" modified="2007-04-12" name="CVE-2007-1988" published="2007-04-11" seq="2007-1988" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in kernel/filters.inc.php in PHPEcho CMS 2.0 allows remote attackers to inject arbitrary web script or HTML via the id parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/464707/100/0/threaded">20070404 phpechocms v.2 Cross-Site Scripting Vulnerabilitiy</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2550">2550</ref></refs><vuln_soft><prod name="PHPEcho CMS" vendor="PHPEcho CMS"><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" modified="2007-04-13" name="CVE-2007-1989" published="2007-04-12" seq="2007-1989" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in DotClear before 1.2.6 allow remote attackers to inject arbitrary web script or HTML via the (1) post_id parameter to ecrire/trackback.php or the (2) tool_url parameter to tools/thememng/index.php.  NOTE: some of these details are obtained from third party information.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref patch="1" source="" url="http://www.dotclear.net/forum/viewtopic.php?id=26573"></ref><ref adv="1" patch="1" source="" url="http://www.dotclear.net/log/post/2007/04/10/Dotclear-126"></ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24829">24829</ref><ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2007-April/053720.html">

20070412 Dotclear 1.* Cross Site Scripting Vulnerability</ref><ref source="BID" url="http://www.securityfocus.com/bid/23411">
23411</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1338">
ADV-2007-1338</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33616">
dotclear-tools-xss(33616)</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33615">
dotclear-trackback-xss(33615)</ref></refs><vuln_soft><prod name="DotClear" vendor="DotClear"><vers num="1.2.5" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-04-12" name="CVE-2007-1990" published="2007-04-12" seq="2007-1990" severity="High" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in games.php in Sam Crew MyBlog, possibly 1.0 through 1.6, allows remote attackers to execute arbitrary PHP code via a URL in the id parameter, a different vector than CVE-2007-1968.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1302">ADV-2007-1302</ref></refs><vuln_soft><prod name="MyBlog" vendor="Sam Crew"><vers num="1.0"/><vers num="1.1"/><vers num="1.2"/><vers num="1.3"/><vers num="1.4"/><vers num="1.5"/><vers num="1.6"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" modified="2007-04-12" name="CVE-2007-1991" published="2007-04-12" seq="2007-1991" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in mail/signup.asp in CmailServer WebMail 5.4.3, and possibly earlier, allows remote attackers to inject arbitrary web script or HTML via the Comment parameter, a different vector than CVE-2007-1927.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref source="BID" url="http://www.securityfocus.com/bid/23363">23363</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24812">24812</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33501">cmailserver-signup-xss(33501)</ref></refs><vuln_soft><prod name="CMailServer" vendor="YoungZSoft"><vers num="5.4.3" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-04-12" name="CVE-2007-1992" published="2007-04-12" seq="2007-1992" severity="High" type="CVE"><desc><descript source="cve">Multiple PHP remote file inclusion vulnerabilities in the com_zoom 2.5 beta 2 and earlier module for Mambo allow remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter to (1) EXIF_Makernote.php or (2) EXIF.php in classes/iptc/.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3706">3706</ref><ref source="BID" url="http://www.securityfocus.com/bid/23415">23415</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1353">
ADV-2007-1353</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33580">
zmg-exif-file-include(33580)</ref></refs><vuln_soft><prod name="com_zoom" vendor="MamboXChange"><vers num="2.5 beta 2" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-08-02" name="CVE-2007-1993" published="2007-04-12" seq="2007-1993" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in the pfs_mountd.rpc RPC daemon in the Portable File System (PFS) in HP-UX B.11.00, B.11.11, and B.11.23 allows remote attackers to execute arbitrary code by sending &quot;a call to procedure 5, followed by a crafted payload to procedure 2.&quot;</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref source="HP" url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00913684">HPSBUX02203</ref><ref source="BID" url="http://www.securityfocus.com/bid/23401">23401</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1343">ADV-2007-1343</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017893">1017893</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24855">24855</ref><ref source="IDEFENSE" url="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=512">20070412 Hewlett Packard HP-UX Remote pfs_mountd.rpc Buffer Overflow Vulnerability</ref></refs><vuln_soft><prod name="Portable File System" vendor="HP"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="4.9" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.9" CVSS_score="4.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:C)" CVSS_version="2.0" modified="2007-04-13" name="CVE-2007-1994" published="2007-04-12" seq="2007-1994" severity="Medium" type="CVE"><desc><descript source="cve">Unspecified vulnerability in the Address and Routing Parameter Area (ARPA) transport functionality in HP-UX B.11.00 allows local users to cause a denial of service via unknown vectors.  NOTE: due to lack of vendor details, it is not clear whether this is the same as CVE-2007-0916.</descript></desc><loss_types><avail/></loss_types><range><local/></range><refs><ref patch="1" source="HP" url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00944467">HPSBUX02205</ref><ref source="BID" url="http://www.securityfocus.com/bid/23410">23410</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017892">1017892</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1358">
ADV-2007-1358</ref></refs><vuln_soft><prod name="HP-UX" vendor="HP"><vers num="B.11.00"/></prod></vuln_soft></entry><entry CVSS_base_score="6.3" CVSS_exploit_subscore="6.8" CVSS_impact_subscore="6.9" CVSS_score="6.3" CVSS_vector="(AV:N/AC:M/Au:S/C:N/I:N/A:C)" CVSS_version="2.0" modified="2007-10-05" name="CVE-2007-1995" published="2007-04-12" seq="2007-1995" severity="Medium" type="CVE"><desc><descript source="cve">bgpd/bgp_attr.c in Quagga 0.98.6 and earlier, and 0.99.6 and earlier 0.99 versions, does not validate length values in the MP_REACH_NLRI and MP_UNREACH_NLRI attributes, which allows remote attackers to cause a denial of service (daemon crash or exit) via crafted UPDATE messages that trigger an assertion error or out of bounds read.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://bugzilla.quagga.net/show_bug.cgi?id=354"></ref><ref source="" url="http://bugzilla.quagga.net/show_bug.cgi?id=355"></ref><ref source="" url="http://www.quagga.net/news2.php?y=2007&amp;m=4&amp;d=8#id1176073740"></ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1336">ADV-2007-1336</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24808">24808</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33547">quagga-bgpattributes-dos(33547)</ref><ref source="BID" url="http://www.securityfocus.com/bid/23417">23417</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2007:096">MDKSA-2007:096</ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200705-05.xml">GLSA-200705-05</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2007_9_sr.html">SUSE-SR:2007:009</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25084">25084</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25119">25119</ref><ref source="DEBIAN" url="http://www.debian.org/security/2007/dsa-1293">DSA-1293</ref><ref source="TRUSTIX" url="http://www.trustix.org/errata/2007/0017/">2007-0017</ref><ref source="UBUNTU" url="http://www.ubuntu.com/usn/usn-461-1">USN-461-1</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25255">25255</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25312">25312</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25293">25293</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:096">MDKSA-2007:096</ref><ref source="OPENPKG" url="http://www.openpkg.com/security/advisories/OpenPKG-SA-2007.015.html">OpenPKG-SA-2007.015</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2007-0389.html">RHSA-2007:0389</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1018142">1018142</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25428">25428</ref><ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-236141-1">236141</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/1195/references">ADV-2008-1195</ref><ref source="SECUNIA" url="http://secunia.com/advisories/29743">29743</ref></refs><vuln_soft><prod name="Quagga Routing Software Suite" vendor="Quagga"><vers num="0.98.6" prev="1"/><vers num="0.99.6" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-08-02" name="CVE-2007-1996" published="2007-04-12" seq="2007-1996" severity="Medium" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in codebreak.php in CodeBreak, probably 1.1.2 and earlier, allows remote attackers to execute arbitrary PHP code via a URL in the process_method parameter.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/465382/100/0/threaded">20070411 CodeBreak (codebreak.php process_method) - Remote File Inclusion Vulnerability</ref><ref source="BID" url="http://www.securityfocus.com/bid/23425">23425</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1355">ADV-2007-1355</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24846">24846</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2562">2562</ref></refs><vuln_soft><prod name="CodeBreak" vendor="CodeBreak"><vers num="1.1.2" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-04-17" name="CVE-2007-1997" published="2007-04-16" seq="2007-1997" severity="High" type="CVE"><desc><descript source="cve">Integer signedness error in the (1) cab_unstore and (2) cab_extract functions in libclamav/cab.c in Clam AntiVirus (ClamAV) before 0.90.2 allow remote attackers to execute arbitrary code via a crafted CHM file that contains a negative integer, which passes a signed comparison and leads to a stack-based buffer overflow.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="IDEFENSE" url="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=513">20070416 Clam AntiVirus ClamAV CAB File Unstore Buffer Overflow Vulnerability</ref><ref patch="1" source="" url="http://sourceforge.net/project/shownotes.php?release_id=500765"></ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/23473">23473</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1378">ADV-2007-1378</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/24891">24891</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33637">clamav-cabunstore-cabextract-bo(33637)</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017921">
1017921</ref><ref source="" url="http://support.novell.com/techcenter/psdb/50a5cb718f20761dd7e0b6b4e0935c52.html"></ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200704-21.xml">
GLSA-200704-21</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2007_26_clamav.html">
SUSE-SA:2007:026</ref><ref source="TRUSTIX" url="http://www.trustix.org/errata/2007/0013/">
2007-0013</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24920">
24920</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24946">
24946</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24996">
24996</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25022">
25022</ref><ref source="DEBIAN" url="http://www.debian.org/security/2007/dsa-1281">
DSA-1281</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25028">
25028</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2007:098">
MDKSA-2007:098</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25189">
25189</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:098">MDKSA-2007:098</ref><ref source="" url="http://docs.info.apple.com/article.html?artnum=307562"></ref><ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2008/Mar/msg00001.html">APPLE-SA-2008-03-18</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/0924/references">ADV-2008-0924</ref><ref source="SECUNIA" url="http://secunia.com/advisories/29420">29420</ref></refs><vuln_soft><prod name="ClamAV" vendor="Clam Anti-Virus"><vers num="0.90"/><vers num="0.90 rc1.1"/><vers num="0.90 rc2"/><vers num="0.90 rc3"/><vers num="0.90.1"/><vers num="0.90.2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-04-13" name="CVE-2007-1998" published="2007-04-12" seq="2007-1998" severity="High" type="CVE"><desc><descript source="cve">Direct static code injection vulnerability in HIOX Guest Book (HGB) 4.0 allows remote attackers to inject arbitrary PHP code via the Email field, which results in code execution through a direct request to gb.php.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3697">3697</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24835">
24835</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33540">
hgb-gb-command-execution(33540)</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1333">
ADV-2007-1333</ref></refs><vuln_soft><prod name="Guest Book" vendor="HIOX INDIA"><vers num="4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-04-13" name="CVE-2007-1999" published="2007-04-12" seq="2007-1999" severity="High" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in index.php in Weatimages 1.7.1 and earlier, when weatimages.ini is missing, allows remote attackers to execute arbitrary PHP code via a URL in the ini[langpack] parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3700">3700</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1335">
ADV-2007-1335</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24863">
24863</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33553">
weatimages-index-file-include(33553)</ref></refs><vuln_soft><prod name="Weatimages" vendor="nazarkin.name"><vers num="1.7.1" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-04-13" name="CVE-2007-2000" published="2007-04-12" seq="2007-2000" severity="High" type="CVE"><desc><descript source="cve">Multiple SQL injection vulnerabilities in admin/admin.php in Crea-Book 1.0 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) pseudo or (2) passe parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3701">3701</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1344">
ADV-2007-1344</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33555">
creabook-admin-sql-injection(33555)</ref><ref source="OSVDB" url="http://www.osvdb.org/34816">34816</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24862">24862</ref></refs><vuln_soft><prod name="Crea-Book" vendor="Rapha&amp;#xeb;l Limbach"><vers num="1.0" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.5" CVSS_exploit_subscore="8.0" CVSS_impact_subscore="6.4" CVSS_score="6.5" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-04-13" name="CVE-2007-2001" published="2007-04-12" seq="2007-2001" severity="Medium" type="CVE"><desc><descript source="cve">Multiple direct static code injection vulnerabilities in admin/configurer2.php in Crea-Book 1.0 and earlier allow remote authenticated administrators to execute arbitrary PHP code via the &quot;Fond de la page&quot; (background color) field and other unspecified fields, which injects into config.inc.php3.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3701">3701</ref><ref source="OSVDB" url="http://www.osvdb.org/34817">34817</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24862">24862</ref></refs><vuln_soft><prod name="Crea-Book" vendor="Crea-Book"><vers num="1.0" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-04-13" name="CVE-2007-2002" published="2007-04-12" seq="2007-2002" severity="Medium" type="CVE"><desc><descript source="cve">InoutMailingListManager 3.1 and earlier allows remote attackers to access certain restricted functionality, and upload and execute arbitrary PHP code, by setting an arbitrary admin cookie.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3702">3702</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1345">
ADV-2007-1345</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24842">
24842</ref></refs><vuln_soft><prod name="InoutMailingListManager" vendor="InoutMailingListManager"><vers num="3.1" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-04-13" name="CVE-2007-2003" published="2007-04-12" seq="2007-2003" severity="Medium" type="CVE"><desc><descript source="cve">InoutMailingListManager 3.1 and earlier sends a Location redirect header but does not exit after an authorization check fails, which allows remote attackers to access certain restricted functionality, and upload and execute arbitrary PHP code, by ignoring the redirect.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/><design/></vuln_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3702">3702</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1345">
ADV-2007-1345</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24842">
24842</ref></refs><vuln_soft><prod name="InoutMailingListManager" vendor="InoutMailingListManager"><vers num="3.1" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-04-13" name="CVE-2007-2004" published="2007-04-12" seq="2007-2004" severity="High" type="CVE"><desc><descript source="cve">Multiple SQL injection vulnerabilities in InoutMailingListManager 3.1 and earlier allow remote attackers to execute arbitrary SQL commands via the id parameter to changename.php and other unspecified vectors.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3702">3702</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1345">
ADV-2007-1345</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24842">
24842</ref></refs><vuln_soft><prod name="InoutMailingListManager" vendor="InoutMailingListManager"><vers num="3.1" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-10-01" name="CVE-2007-2005" published="2007-04-12" seq="2007-2005" severity="Medium" type="CVE"><desc><descript source="cve">Multiple PHP remote file inclusion vulnerabilities in the Taskhopper 1.1 component for Mambo and Joomla! allow remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter to (1) contact_type.php, (2) itemstatus_type.php, (3) projectstatus_type.php, (4) request_type.php, (5) responses_type.php, (6) timelog_type.php, or (7) urgency_type.php in inc/.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3703">3703</ref><ref source="BID" url="http://www.securityfocus.com/bid/23408">23408</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1346">ADV-2007-1346</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33552">taskhopper-mosconfigabsolute-file-include(33552)</ref><ref source="VIM" url="http://attrition.org/pipermail/vim/2007-April/001504.html">20070411 Confirm: Joomla/Mambo Component Taskhopper 1.1 RFI Vulnerabilities</ref><ref source="OSVDB" url="http://www.osvdb.org/34795">34795</ref><ref source="OSVDB" url="http://www.osvdb.org/34796">34796</ref><ref source="OSVDB" url="http://www.osvdb.org/34797">34797</ref><ref source="OSVDB" url="http://www.osvdb.org/34798">34798</ref><ref source="OSVDB" url="http://www.osvdb.org/34799">34799</ref><ref source="OSVDB" url="http://www.osvdb.org/34800">34800</ref><ref source="OSVDB" url="http://www.osvdb.org/34801">34801</ref></refs><vuln_soft><prod name="Taskhopper Component" vendor="Mambo"><vers num="1.1"/></prod><prod name="Taskhopper Component" vendor="Joomla"><vers num="1.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-04-13" name="CVE-2007-2006" published="2007-04-12" seq="2007-2006" severity="High" type="CVE"><desc><descript source="cve">Multiple SQL injection vulnerabilities in login.php in pL-PHP beta 0.9 allow remote attackers to execute arbitrary SQL commands via the (1) login or (2) pass parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3704">3704</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/465340/100/0/threaded">

20070411 pL-PHP beta 0.9 - Multiple Vulnerabilities</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1352">
ADV-2007-1352</ref></refs><vuln_soft><prod name="pL-PHP" vendor="pL-PHP"><vers num="0.9 Beta" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-04-13" name="CVE-2007-2007" published="2007-04-12" seq="2007-2007" severity="High" type="CVE"><desc><descript source="cve">admin.php in pL-PHP beta 0.9 allows remote attackers to bypass authentication by setting the is_admin parameter to 1.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/><input/></vuln_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3704">3704</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/465340/100/0/threaded">

20070411 pL-PHP beta 0.9 - Multiple Vulnerabilities</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1352">
ADV-2007-1352</ref></refs><vuln_soft><prod name="pL-PHP" vendor="pL-PHP"><vers num="0.9 Beta"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-04-13" name="CVE-2007-2008" published="2007-04-12" seq="2007-2008" severity="High" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in admin.php in pL-PHP beta 0.9 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the lang parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3704">3704</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/465340/100/0/threaded">

20070411 pL-PHP beta 0.9 - Multiple Vulnerabilities</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1352">
ADV-2007-1352</ref></refs><vuln_soft><prod name="pL-PHP" vendor="pL-PHP"><vers num="0.9 Beta"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-04-13" name="CVE-2007-2009" published="2007-04-12" seq="2007-2009" severity="Medium" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in index.php in SimpCMS Light 04.10.2007 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the site parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3705">3705</ref><ref source="VIM" url="http://www.attrition.org/pipermail/vim/2007-April/001513.html">20070412 true: SimpCMS Light RFI</ref><ref source="BID" url="http://www.securityfocus.com/bid/23439">
23439</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1348">
ADV-2007-1348</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24851">
24851</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33572">
simpcms-index-file-include(33572)</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/465343/100/100/threaded">

20070411 New bug :)</ref></refs><vuln_soft><prod name="SimpCMS" vendor="SimpCMS"><vers edition="Lite" num="2007-04-10"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.0" CVSS_impact_subscore="6.9" CVSS_score="6.8" CVSS_vector="(AV:N/AC:L/Au:S/C:N/I:N/A:C)" CVSS_version="2.0" modified="2008-02-26" name="CVE-2007-2010" published="2007-04-12" seq="2007-2010" severity="Medium" type="CVE"><desc><descript source="cve">Double free vulnerability in bftpd before 1.8 allows remote authenticated users to cause a denial of service (daemon crash) via a (1) get or (2) mget command.</descript></desc><loss_types><avail/></loss_types><vuln_types><other/></vuln_types><range><network/></range><refs><ref source="" url="http://bftpd.sourceforge.net/downloads/CHANGELOG"></ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/24864">24864</ref><ref source="" url="http://bftpd.sourceforge.net/"></ref><ref source="BID" url="http://www.securityfocus.com/bid/23406">23406</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1347">ADV-2007-1347</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33594">bftpd-getmget-dos(33594)</ref></refs><vuln_soft><prod name="bftpd" vendor="bftpd"><vers num="1.7.2" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" modified="2007-04-13" name="CVE-2007-2011" published="2007-04-12" seq="2007-2011" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in login.php in DeskPro 2.0.1 allows remote attackers to inject arbitrary web script or HTML via the username parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/465089/100/0/threaded">20070408 DeskPRO v2.0.1 - Cross-Site Scripting Vulnerability</ref><ref source="BID" url="http://www.securityfocus.com/bid/23381">23381</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24844">24844</ref><ref source="" url="http://john-martinelli.com/work/deskpro.txt"></ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1320">
ADV-2007-1320</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2556">2556</ref></refs><vuln_soft><prod name="DeskPRO" vendor="DeskPRO"><vers num="2.0.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="4.9" CVSS_score="5.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:N)" CVSS_version="2.0" modified="2007-04-13" name="CVE-2007-2012" published="2007-04-12" seq="2007-2012" severity="Medium" type="CVE"><desc><descript source="cve">Multiple directory traversal vulnerabilities in MimarSinan CompreXX 4.1 allow remote attackers to create files in arbitrary directories via a .. (dot dot) in a (1) .rar, (2) .jar or (3) .zip archive.</descript></desc><loss_types><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://www.bugtraq.ir/articles/advisory/comprexx_directory_traversal/7"></ref><ref source="BID" url="http://www.securityfocus.com/bid/23362">23362</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1312">ADV-2007-1312</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24840">24840</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33551">
comprexx-archive-directory-traversal(33551)</ref></refs><vuln_soft><prod name="CompreXX" vendor="MimarSinan"><vers num="4.1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" modified="2007-04-13" name="CVE-2007-2013" published="2007-04-12" seq="2007-2013" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in index.php in JEx-Treme Einfacher Passworschutz allows remote attackers to inject arbitrary web script or HTML via the msg parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref source="" url="http://hackberry.ath.cx/research/1.txt"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1316">ADV-2007-1316</ref><ref source="BID" url="http://www.securityfocus.com/bid/23395">
23395</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24922">
24922</ref></refs><vuln_soft><prod name="Einfacher Passworschutz" vendor="JEX-Treme"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-04-13" name="CVE-2007-2014" published="2007-04-12" seq="2007-2014" severity="High" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in include/blocks/week_events.php in MyNews 4.2.2 allows remote attackers to execute arbitrary PHP code via a URL in the myNewsConf[path][sys][index] parameter, a different vector than CVE-2007-0633.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://hackberry.ath.cx/research/3.txt"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1317">ADV-2007-1317</ref></refs><vuln_soft><prod name="MyNews" vendor="MyNews"><vers num="4.2.2"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-04-13" name="CVE-2007-2015" published="2007-04-12" seq="2007-2015" severity="Medium" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in index.php in Request It 1.0b allows remote attackers to execute arbitrary PHP code via a URL in the id parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/465081/100/0/threaded">20070409 Request It : Song Request System 1.0b - remote file inclusion</ref><ref source="" url="http://hackberry.ath.cx/research/2.txt"></ref><ref source="VIM" url="http://www.attrition.org/pipermail/vim/2007-April/001514.html">20070411 true: Request It : Song Request System 1.0b RFI</ref><ref source="BID" url="http://www.securityfocus.com/bid/23370">23370</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1318">ADV-2007-1318</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24832">24832</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2553">2553</ref></refs><vuln_soft><prod name="Request It" vendor="Request It"><vers num="1.0b"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" modified="2007-04-13" name="CVE-2007-2016" published="2007-04-12" seq="2007-2016" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in mysql/phpinfo.php in phpMyAdmin 2.6.1 allows remote attackers to inject arbitrary web script or HTML via the lang[] parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/465082/100/0/threaded">20070408 phpMyAdmin 2.6.1 Local Cross Site Scripting</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2560">2560</ref></refs><vuln_soft><prod name="phpMyAdmin" vendor="phpMyAdmin"><vers num="2.6.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-04-13" name="CVE-2007-2017" published="2007-04-12" seq="2007-2017" severity="High" type="CVE"><desc><descript source="cve">siteadmin/useredit.php in AlstraSoft Video Share Enterprise does not check authentication, which allows remote attackers to obtain or modify user information via a direct request.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><access/><input/></vuln_types><range><network/></range><refs><ref source="" url="http://pridels.blogspot.com/2007/03/alstrasoft-video-share-enterprise.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/23409">23409</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1331">ADV-2007-1331</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24836">24836</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33548">
alstrasoft-vse-useredit-insecure-permissions(33548)</ref><ref source="" url="http://pridels0.blogspot.com/2007/03/alstrasoft-video-share-enterprise.html"></ref><ref source="" url="http://www.alstrasoft.com/videoshare_fix.zip"></ref><ref source="VIM" url="http://www.attrition.org/pipermail/vim/2007-July/001707.html">20070710 Vendor ACK: CVE-2007-2017 (AlstraSoft useredit.php auth bypass)</ref></refs><vuln_soft><prod name="Video Share Enterprise" vendor="AlstraSoft"><vers num="4.1" prev="1"/><vers num="4.2" prev="1"/><vers num="4.3" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.5" CVSS_exploit_subscore="8.0" CVSS_impact_subscore="6.4" CVSS_score="6.5" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-04-13" name="CVE-2007-2018" published="2007-04-12" seq="2007-2018" severity="Medium" type="CVE"><desc><descript source="cve">SQL injection vulnerability in msg.php in AlstraSoft Video Share Enterprise allows remote authenticated users to execute arbitrary SQL commands via the id parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://pridels.blogspot.com/2007/03/alstrasoft-video-share-enterprise.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/23409">23409</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1331">ADV-2007-1331</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24836">24836</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33546">
alstrasoft-vse-msg-sql-injection(33546)</ref><ref source="" url="http://pridels0.blogspot.com/2007/03/alstrasoft-video-share-enterprise.html"></ref></refs><vuln_soft><prod name="Video Share Enterprise" vendor="AlstraSoft"><vers num="4.1" prev="1"/><vers num="4.2" prev="1"/><vers num="4.3" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-04-13" name="CVE-2007-2019" published="2007-04-12" seq="2007-2019" severity="High" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in init.gallery.php in phpGalleryScript 1.0 allows remote attackers to execute arbitrary PHP code via a URL in the include_class parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/465200/100/0/threaded">20070409 phpGalleryScript 1.0 - File Inclusion Vulnerabilities</ref><ref source="VIM" url="http://www.attrition.org/pipermail/vim/2007-April/001501.html">20070410 false: phpGalleryScript 1.0 - File Inclusion Vulnerabilities</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1334">
ADV-2007-1334</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24860">
24860</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33545">
phpgalleryscript-gallery-file-include(33545)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2566">2566</ref></refs><vuln_soft><prod name="phpGalleryScript" vendor="Tomex"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-04-13" name="CVE-2007-2020" published="2007-04-12" seq="2007-2020" severity="High" type="CVE"><desc><descript source="cve">** DISPUTED **  Unspecified vulnerability in administration.php in xodagallery allows remote attackers to execute arbitrary code via the cmd parameter. NOTE: CVE disputes this vulnerability because administration.php does not use the cmd parameter for inclusion.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/465088/100/0/threaded">20070408 xodagallery Remote Code Execution Vulnerability</ref><ref source="VIM" url="http://www.attrition.org/pipermail/vim/2007-April/001516.html">20070412 probably false: xodagallery execution claim</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/33522">xodagallery-administration-code-execution(33522)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2561">2561</ref></refs><vuln_soft><prod name="XodaGallery" vendor="XodaGallery"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-04-13" name="CVE-2007-2021" published="2007-04-12" seq="2007-2021" severity="High" type="CVE"><desc><descript source="cve">Multiple PHP remote file inclusion vulnerabilities in Pineapple Technologies Lore 1 allow remote attackers to execute arbitrary PHP code via a URL in the (1) lang_path parameter to third_party/phpmailer/class.phpmailer.php or the (2) get_plugin_file_path parameter to third_party/smarty/libs/plugins/function.html_checkboxes.php.  NOTE: the affected files might be from other software packages, so this might not be a vulnerability in Lore itself.  NOTE: (1) might be the same issue as CVE-2006-5734.4.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/465086/100/0/threaded">20070408 Remot File Include In Script Lore v1</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2565">2565</ref></refs><vuln_soft><prod name="Lore" vendor="Pineapple Technologies"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2008-01-02" name="CVE-2007-2022" published="2007-04-13" seq="2007-2022" severity="Medium" type="CVE"><desc><descript source="cve">Adobe Macromedia Flash Player 7 and 9, when used with Opera before 9.20 or Konqueror before 20070613, allows remote attackers to obtain sensitive information (browser keystrokes), which are leaked to the Flash Player applet.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><other/></vuln_types><range><network/><user_init/></range><refs><ref source="" url="http://www.adobe.com/support/security/advisories/apsa07-03.html"></ref><ref source="" url="http://www.opera.com/support/search/view/858/"></ref><ref source="BID" url="http://www.securityfocus.com/bid/23437">23437</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1361">ADV-2007-1361</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017903">1017903</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24877">24877</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33595">opera-flash-player-unspecified(33595)</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2007_28_opera.html">SUSE-SA:2007:028</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/25027">25027</ref><ref source="" url="http://www.adobe.com/support/security/bulletins/apsb07-12.html"></ref><ref source="" url="https://issues.rpath.com/browse/RPL-1462"></ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200708-01.xml">GLSA-200708-01</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:138">MDKSA-2007:138</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2007-0494.html">RHSA-2007:0494</ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20070602-01-P.asc">20070602-01-P</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2007_12_sr.html">SUSE-SR:2007:012</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2007_46_flashplayer.html">SUSE-SA:2007:046</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA07-192A.html">TA07-192A</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/2497">ADV-2007-2497</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/25432">25432</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/25662">25662</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/25669">25669</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/25894">25894</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/25933">25933</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/26027">26027</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/26118">26118</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/26357">26357</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/26860">26860</ref><ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-103167-1">103167</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/4190">ADV-2007-4190</ref><ref source="SECUNIA" url="http://secunia.com/advisories/28068">28068</ref><ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-66-201506-1">201506</ref></refs><vuln_soft><prod name="Opera Web Browser" vendor="Opera Software"><vers num="6.0"/><vers num="6.0.1"/><vers num="6.0.6"/><vers num="7.10"/><vers num="7.11"/><vers num="7.20"/><vers num="7.21"/><vers num="7.22"/><vers num="7.23"/><vers num="7.50"/><vers num="7.51"/><vers num="7.52"/><vers num="7.53"/><vers num="7.54"/><vers num="8.0"/><vers num="8.0 Beta 3"/><vers num="8.01"/><vers num="8.02"/><vers num="8.50"/><vers num="8.51"/><vers num="8.52"/><vers num="8.53"/><vers num="8.54"/><vers num="9"/><vers num="9.01"/><vers num="9.02"/><vers num="9.10"/></prod><prod name="Flash Player" vendor="Adobe"><vers num="7.0.25"/><vers num="8.0"/><vers num="9.0.18d60"/><vers num="9.0.20"/><vers num="9.0.28"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-04-17" name="CVE-2007-2023" published="2007-04-13" seq="2007-2023" severity="High" type="CVE"><desc><descript source="cve">USB20.dll in Secustick USB flash drive decouples the authorization and file access routines, which allows local users to bypass authentication requirements by altering the return value of the VerifyPassWord function.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><access/><design/></vuln_types><range><local/></range><refs><ref source="" url="http://tweakers.net/reviews/682"></ref><ref source="" url="http://tweakers.net/reviews/683"></ref></refs><vuln_soft><prod name="Secustick USB flash drive" vendor="Secustick"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-04-17" name="CVE-2007-2024" published="2007-04-13" seq="2007-2024" severity="Medium" type="CVE"><desc><descript source="cve">Unrestricted file upload vulnerability in the UpLoad feature (lib/plugin/UpLoad.php) in PhpWiki 1.3.x allows remote attackers to upload arbitrary PHP files with a (1) php3, (2) php4, or (3) php5 extension.</descript></desc><impacts><impact source="nvd">&quot;Successful exploitation requires being logged in and that the webserver is configured to execute PHP scripts with such extensions. In the default configuration of PhpWiki, no registration or validation is necessary to log in.&quot;
</impact></impacts><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/465489/100/0/threaded">20070412 Critical phpwiki c99shell exploit</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/465550/100/0/threaded">20070412 RE: Critical phpwiki c99shell exploit</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/465514/100/0/threaded">20070412 Re: Critical phpwiki c99shell exploit</ref><ref source="MLIST" url="http://www.nabble.com/Fwd%3A-Critical-phpwiki-c99shell-exploit-t3571197.html">[phpwiki-talk] 20070413 Fwd: Critical phpwiki c99shell exploit</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/914793">VU#914793</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24888">24888</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1400">
ADV-2007-1400</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200705-16.xml">
GLSA-200705-16</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25307">
25307</ref><ref source="DEBIAN" url="http://www.debian.org/security/2007/dsa-1371">DSA-1371</ref><ref source="SECUNIA" url="http://secunia.com/advisories/26784">26784</ref></refs><vuln_soft><prod name="PhpWiki" vendor="PhpWiki"><vers num="1.3.x"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-04-17" name="CVE-2007-2025" published="2007-04-13" seq="2007-2025" severity="High" type="CVE"><desc><descript source="cve">Unrestricted file upload vulnerability in the UpLoad feature (lib/plugin/UpLoad.php) in PhpWiki 1.3.11p1 allows remote attackers to upload arbitrary PHP files with a double extension, as demonstrated by .php.3, which is interpreted by Apache as being a valid PHP file.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MLIST" url="http://www.nabble.com/Important-UpLoad-security-fix%21-was--Fwd%3A--phpwiki---Open-Discussion--RE%3A-upload-security-risk--t3543463.html">[phpwiki-talk] 20070408 Important UpLoad security fix! was [Fwd: [phpwiki - Open Discussion] RE: upload security risk]</ref><ref source="" url="https://sourceforge.net/forum/message.php?msg_id=4249177"></ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200705-16.xml">
GLSA-200705-16</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25307">
25307</ref><ref source="DEBIAN" url="http://www.debian.org/security/2007/dsa-1371">DSA-1371</ref><ref source="SECUNIA" url="http://secunia.com/advisories/26784">26784</ref></refs><vuln_soft><prod name="PhpWiki" vendor="PhpWiki"><vers num="1.3.11p1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.8" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.9" CVSS_score="7.8" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_version="2.0" modified="2007-04-17" name="CVE-2007-2026" published="2007-04-13" seq="2007-2026" severity="High" type="CVE"><desc><descript source="cve">The gnu regular expression code in file 4.20 allows context-dependent attackers to cause a denial of service (CPU consumption) via a crafted document with a large number of line feed characters, which is not well handled by OS/2 REXX regular expressions that use wildcards, as originally reported for AMaViS.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/><exception/></vuln_types><range><network/></range><refs><ref source="" url="http://sourceforge.net/mailarchive/forum.php?thread_name=755AF709E5B77E6EA58479D5%40foxx.lsit.ucsb.edu&amp;forum_name=amavis-user"></ref><ref source="" url="https://bugs.gentoo.org/show_bug.cgi?id=174217"></ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200704-13.xml">
GLSA-200704-13</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24918">
24918</ref><ref source="" url="https://issues.rpath.com/browse/RPL-1311"></ref><ref source="" url="http://www.amavis.org/security/asa-2007-3.txt"></ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:114">MDKSA-2007:114</ref><ref source="BID" url="http://www.securityfocus.com/bid/24146">24146</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/2071">ADV-2007-2071</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25394">25394</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25544">25544</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25578">25578</ref></refs><vuln_soft><prod name="Gentoo Security" vendor="Gentoo"><vers num="File 4.20"/></prod><prod name="Virus Scanner" vendor="AMaViS"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="4.4" CVSS_exploit_subscore="3.4" CVSS_impact_subscore="6.4" CVSS_score="4.4" CVSS_vector="(AV:L/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-08-02" name="CVE-2007-2027" published="2007-04-13" seq="2007-2027" severity="Medium" type="CVE"><desc><descript source="cve">Untrusted search path vulnerability in the add_filename_to_string function in intl/gettext/loadmsgcat.c for Elinks 0.11.1 allows local users to cause Elinks to use an untrusted gettext message catalog (.po file) in a &quot;../po&quot; directory, which can be leveraged to conduct format string attacks.</descript></desc><impacts><impact source="nvd">An untrusted message catalog might lead to a format-string attack when an
attacker tricks user into launching links from a particular directory.
</impact></impacts><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><local/></range><refs><ref source="" url="https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=235411"></ref><ref source="" url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=417789"></ref><ref source="UBUNTU" url="http://www.ubuntu.com/usn/usn-457-1">USN-457-1</ref><ref source="BID" url="http://www.securityfocus.com/bid/23844">23844</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1686">ADV-2007-1686</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/25169">25169</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/25198">25198</ref><ref source="TRUSTIX" url="http://www.trustix.org/errata/2007/0017/">2007-0017</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/25255">25255</ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200706-03.xml">GLSA-200706-03</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25550">25550</ref></refs><vuln_soft><prod name="Elinks" vendor="Elinks"><vers num="0.11.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0" modified="2007-04-17" name="CVE-2007-2028" published="2007-04-13" seq="2007-2028" severity="Medium" type="CVE"><desc><descript source="cve">Memory leak in freeRADIUS 1.1.5 and earlier allows remote attackers to cause a denial of service (memory consumption) via a large number of EAP-TTLS tunnel connections using malformed Diameter format attributes, which causes the authentication request to be rejected but does not reclaim VALUE_PAIR data structures.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref source="" url="http://www.freeradius.org/security.html"></ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2007:085">
MDKSA-2007:085</ref><ref source="BID" url="http://www.securityfocus.com/bid/23466">
23466</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1369">
ADV-2007-1369</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24849">
24849</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24907">
24907</ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200704-14.xml">
GLSA-200704-14</ref><ref source="TRUSTIX" url="http://www.trustix.org/errata/2007/0013/">
2007-0013</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24917">
24917</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24996">
24996</ref><ref source="REDHAT" url="http://rhn.redhat.com/errata/RHSA-2007-0338.html">
RHSA-2007:0338</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2007_10_sr.html">
SUSE-SR:2007:010</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1018042">
1018042</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25201">
25201</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25220">
25220</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:085">MDKSA-2007:085</ref></refs><vuln_soft><prod name="FreeRADIUS" vendor="FreeRADIUS"><vers num="1.1.5" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.8" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.9" CVSS_score="7.8" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_version="2.0" modified="2007-08-02" name="CVE-2007-2029" published="2007-04-30" seq="2007-2029" severity="High" type="CVE"><desc><descript source="cve">File descriptor leak in the PDF handler in Clam AntiVirus (ClamAV) allows remote attackers to cause a denial of service via a crafted PDF file.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="DEBIAN" url="http://www.debian.org/security/2007/dsa-1281">DSA-1281</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/23656">23656</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/25028">25028</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2007:098">MDKSA-2007:098</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25189">25189</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:098">MDKSA-2007:098</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/34083">clamav-pdfhandler-dos(34083)</ref></refs><vuln_soft><prod name="ClamAV" vendor="Clam Anti-Virus"><vers num="0.84 rc2"/></prod></vuln_soft></entry><entry CVSS_base_score="4.9" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.9" CVSS_score="4.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:N/A:N)" CVSS_version="2.0" modified="2007-04-17" name="CVE-2007-2030" published="2007-04-16" seq="2007-2030" severity="Medium" type="CVE"><desc><descript source="cve">lharc.c in lha does not securely create temporary files, which might allow local users to read or write files by creating a file before LHA is invoked.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref source="" url="https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=236585"></ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:117">MDKSA-2007:117</ref><ref source="BID" url="http://www.securityfocus.com/bid/24336">24336</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25519">25519</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/34063">lha-lharc-symlink(34063)</ref></refs><vuln_soft><prod name="Enterprise Linux" vendor="Red Hat"><vers num="2.1"/><vers num="3.0"/><vers num="4.0"/></prod><prod name="Fedora" vendor="Red Hat"><vers num="Core 5.0"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-04-17" name="CVE-2007-2031" published="2007-04-16" seq="2007-2031" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in the HTTP proxy service for 3proxy 0.5 to 0.5.3g, and 0.6b-devel before 20070413, might allow remote attackers to execute arbitrary code via crafted transparent requests.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref patch="1" source="" url="http://3proxy.ru/0.5.3h/Changelog.txt"></ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200704-17.xml">
GLSA-200704-17</ref><ref source="BID" url="http://www.securityfocus.com/bid/23545">
23545</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1442">
ADV-2007-1442</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24961">
24961</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25001">
25001</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/466650/100/100/threaded">

20070423 3proxy 0.5.3i bugfix release</ref></refs><vuln_soft><prod name="3proxy" vendor="3proxy"><vers num="0.5.3g" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-04-17" name="CVE-2007-2032" published="2007-04-16" seq="2007-2032" severity="High" type="CVE"><desc><descript source="cve">Cisco Wireless Control System (WCS) before 4.0.96.0 has a hard-coded FTP username and password for backup operations, which allows remote attackers to read and modify arbitrary files via unspecified vectors related to &quot;properties of the FTP server,&quot; aka Bug ID CSCse93014.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/><design/></vuln_types><range><network/></range><refs><ref patch="1" source="CISCO" url="http://www.cisco.com/warp/public/707/cisco-sa-20070412-wcs.shtml">20070412 Multiple Vulnerabilities in the Cisco Wireless Control System</ref><ref source="BID" url="http://www.securityfocus.com/bid/23460">23460</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1367">ADV-2007-1367</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1017907">1017907</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24865">24865</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33614">cisco-wcs-ftp-unauthorized-access(33614)</ref><ref source="OSVDB" url="http://www.osvdb.org/34132">34132</ref></refs><vuln_soft><prod name="Wireless Control System" vendor="Cisco"><vers num="4.0"/><vers num="4.0.95"/></prod></vuln_soft></entry><entry CVSS_base_score="6.5" CVSS_exploit_subscore="8.0" CVSS_impact_subscore="6.4" CVSS_score="6.5" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-04-17" name="CVE-2007-2033" published="2007-04-16" seq="2007-2033" severity="Medium" type="CVE"><desc><descript source="cve">Unspecified vulnerability in Cisco Wireless Control System (WCS) before 4.0.81.0 allows remote authenticated users to read any configuration page by changing the group membership of user accounts, aka Bug ID CSCse78596.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref source="CISCO" url="http://www.cisco.com/warp/public/707/cisco-sa-20070412-wcs.shtml">20070412 Multiple Vulnerabilities in the Cisco Wireless Control System</ref><ref source="BID" url="http://www.securityfocus.com/bid/23460">23460</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1367">ADV-2007-1367</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1017907">1017907</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24865">24865</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33612">cisco-wcs-account-privilege-escalation(33612)</ref><ref source="OSVDB" url="http://www.osvdb.org/34129">34129</ref></refs><vuln_soft><prod name="Wireless Control System" vendor="Cisco"><vers num="4.0.95" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="9.0" CVSS_exploit_subscore="8.0" CVSS_impact_subscore="10.0" CVSS_score="9.0" CVSS_vector="(AV:N/AC:L/Au:S/C:C/I:C/A:C)" CVSS_version="2.0" modified="2008-01-02" name="CVE-2007-2034" published="2007-04-16" seq="2007-2034" severity="High" type="CVE"><desc><descript source="cve">Unspecified vulnerability in Cisco Wireless Control System (WCS) before 4.0.87.0 allows remote authenticated users to gain the privileges of the SuperUsers group, and manage the application and its networks, related to the group membership of user accounts, aka Bug ID CSCsg05190.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref source="CISCO" url="http://www.cisco.com/warp/public/707/cisco-sa-20070412-wcs.shtml">20070412 Multiple Vulnerabilities in the Cisco Wireless Control System</ref><ref source="BID" url="http://www.securityfocus.com/bid/23460">23460</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1367">ADV-2007-1367</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1017907">1017907</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24865">24865</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33612">cisco-wcs-account-privilege-escalation(33612)</ref><ref source="OSVDB" url="http://www.osvdb.org/34130">34130</ref></refs><vuln_soft><prod name="Wireless Control System" vendor="Cisco"><vers num="4.0.95" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.8" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.9" CVSS_score="7.8" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:N/A:N)" CVSS_version="2.0" modified="2007-04-17" name="CVE-2007-2035" published="2007-04-16" seq="2007-2035" severity="High" type="CVE"><desc><descript source="cve">Cisco Wireless Control System (WCS) before 4.0.66.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain network organization data via a direct request for files in certain directories, aka Bug ID CSCsg04301.</descript></desc><loss_types><conf/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref source="CISCO" url="http://www.cisco.com/warp/public/707/cisco-sa-20070412-wcs.shtml">20070412 Multiple Vulnerabilities in the Cisco Wireless Control System</ref><ref source="BID" url="http://www.securityfocus.com/bid/23460">23460</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1367">ADV-2007-1367</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1017907">1017907</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24865">24865</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33606">cisco-wcs-password-information-disclosure(33606)</ref><ref source="OSVDB" url="http://www.osvdb.org/34131">34131</ref></refs><vuln_soft><prod name="Wireless Control System" vendor="Cisco"><vers num="4.0.95" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-04-18" name="CVE-2007-2036" published="2007-04-16" seq="2007-2036" severity="High" type="CVE"><desc><descript source="cve">The SNMP implementation in the Cisco Wireless LAN Controller (WLC) before 20070419 uses the default read-only community public, and the default read-write community private, which allows remote attackers to read and modify SNMP variables, aka Bug ID CSCse02384.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><config/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="CISCO" url="http://www.cisco.com/warp/public/707/cisco-sa-20070412-wlc.shtml">20070412 Multiple Vulnerabilities in the Cisco Wireless LAN Controller and Cisco Lightweight Access Points</ref><ref source="BID" url="http://www.securityfocus.com/bid/23461">23461</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1368">ADV-2007-1368</ref><ref adv="1" source="SECTRACK" url="http://securitytracker.com/id?1017908">1017908</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33604">cisco-wlc-default-snmp(33604)</ref><ref source="OSVDB" url="http://www.osvdb.org/34134">34134</ref></refs><vuln_soft><prod name="Wireless LAN Controller" vendor="Cisco"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="2.9" CVSS_exploit_subscore="5.5" CVSS_impact_subscore="2.9" CVSS_score="2.9" CVSS_vector="(AV:A/AC:M/Au:N/C:N/I:N/A:P)" CVSS_version="2.0" modified="2007-04-18" name="CVE-2007-2037" published="2007-04-16" seq="2007-2037" severity="Low" type="CVE"><desc><descript source="cve">Cisco Wireless LAN Controller (WLC) before 3.2.116.21, and 4.0.x before 4.0.155.0, allows remote attackers on a local network to cause a denial of service (device crash) via malformed Ethernet traffic.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><local_network/></range><refs><ref adv="1" patch="1" source="CISCO" url="http://www.cisco.com/warp/public/707/cisco-sa-20070412-wlc.shtml">20070412 Multiple Vulnerabilities in the Cisco Wireless LAN Controller and Cisco Lightweight Access Points</ref><ref source="BID" url="http://www.securityfocus.com/bid/23461">23461</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1368">ADV-2007-1368</ref><ref adv="1" source="SECTRACK" url="http://securitytracker.com/id?1017908">1017908</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33607">cisco-wlc-ethernet-traffic-dos(33607)</ref><ref source="OSVDB" url="http://www.osvdb.org/34135">34135</ref></refs><vuln_soft><prod name="Wireless LAN Controller" vendor="Cisco"><vers num="3.2" prev="1"/><vers num="4.0" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.1" CVSS_exploit_subscore="6.5" CVSS_impact_subscore="6.9" CVSS_score="6.1" CVSS_vector="(AV:A/AC:L/Au:N/C:N/I:N/A:C)" CVSS_version="2.0" modified="2007-04-18" name="CVE-2007-2038" published="2007-04-16" seq="2007-2038" severity="Medium" type="CVE"><desc><descript source="cve">The Network Processing Unit (NPU) in the Cisco Wireless LAN Controller (WLC) before 3.2.193.5, 4.0.x before 4.0.206.0, and 4.1.x allows remote attackers on a local wireless network to cause a denial of service (loss of packet forwarding) via (1) crafted SNAP packets, (2) malformed 802.11 traffic, or (3) packets with certain header length values, aka Bug ID CSCsg36361.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><local_network/></range><refs><ref adv="1" source="CISCO" url="http://www.cisco.com/warp/public/707/cisco-sa-20070412-wlc.shtml">20070412 Multiple Vulnerabilities in the Cisco Wireless LAN Controller and Cisco Lightweight Access Points</ref><ref source="BID" url="http://www.securityfocus.com/bid/23461">23461</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1368">ADV-2007-1368</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1017908">1017908</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33609">cisco-wlc-npu-traffic-dos(33609)</ref><ref source="OSVDB" url="http://www.osvdb.org/34136">34136</ref></refs><vuln_soft><prod name="2000 Series Wireless LAN Controller" vendor="Cisco"><vers num=""/></prod><prod name="2100 Series Wireless LAN Controller" vendor="Cisco"><vers num=""/></prod><prod name="4400 Series Wireless LAN Controller" vendor="Cisco"><vers num=""/></prod><prod name="4100 Series Wireless LAN Controller" vendor="Cisco"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="6.1" CVSS_exploit_subscore="6.5" CVSS_impact_subscore="6.9" CVSS_score="6.1" CVSS_vector="(AV:A/AC:L/Au:N/C:N/I:N/A:C)" CVSS_version="2.0" modified="2007-04-18" name="CVE-2007-2039" published="2007-04-16" seq="2007-2039" severity="Medium" type="CVE"><desc><descript source="cve">The Network Processing Unit (NPU) in the Cisco Wireless LAN Controller (WLC) before 3.2.171.5, 4.0.x before 4.0.206.0, and 4.1.x allows remote attackers on a local wireless network to cause a denial of service (loss of packet forwarding) via (1) crafted SNAP packets, (2) malformed 802.11 traffic, or (3) packets with certain header length values, aka Bug IDs CSCsg15901 and CSCsh10841.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><local_network/></range><refs><ref adv="1" patch="1" source="CISCO" url="http://www.cisco.com/warp/public/707/cisco-sa-20070412-wlc.shtml">20070412 Multiple Vulnerabilities in the Cisco Wireless LAN Controller and Cisco Lightweight Access Points</ref><ref source="BID" url="http://www.securityfocus.com/bid/23461">23461</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1368">ADV-2007-1368</ref><ref adv="1" source="SECTRACK" url="http://securitytracker.com/id?1017908">1017908</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33609">cisco-wlc-npu-traffic-dos(33609)</ref><ref source="OSVDB" url="http://www.osvdb.org/34137">34137</ref><ref source="OSVDB" url="http://www.osvdb.org/34139">34139</ref></refs><vuln_soft><prod name="Wireless LAN Controller" vendor="Cisco"><vers num="3.2" prev="1"/><vers num="4.0" prev="1"/><vers num="4.1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.2" CVSS_exploit_subscore="1.9" CVSS_impact_subscore="10.0" CVSS_score="6.2" CVSS_vector="(AV:L/AC:H/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-04-18" name="CVE-2007-2040" published="2007-04-16" seq="2007-2040" severity="Medium" type="CVE"><desc><descript source="cve">Cisco Aironet 1000 Series and 1500 Series Lightweight Access Points before 3.2.185.0, and 4.0.x before 4.0.206.0, have a hard-coded password, which allows attackers with physical access to perform arbitrary actions on the device, aka Bug ID CSCsg15192.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><access/><config/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="CISCO" url="http://www.cisco.com/warp/public/707/cisco-sa-20070412-wlc.shtml">20070412 Multiple Vulnerabilities in the Cisco Wireless LAN Controller and Cisco Lightweight Access Points</ref><ref source="BID" url="http://www.securityfocus.com/bid/23461">23461</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1368">ADV-2007-1368</ref><ref adv="1" source="SECTRACK" url="http://securitytracker.com/id?1017908">1017908</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33610">
cisco-aironet-default-password(33610)</ref><ref source="OSVDB" url="http://www.osvdb.org/34133">34133</ref></refs><vuln_soft><prod name="Wireless LAN Controller" vendor="Cisco"><vers num="3.2" prev="1"/><vers num="4.0" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.0" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="4.9" CVSS_score="4.0" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:N)" CVSS_version="2.0" modified="2007-04-18" name="CVE-2007-2041" published="2007-04-16" seq="2007-2041" severity="Medium" type="CVE"><desc><descript source="cve">Cisco Wireless LAN Controller (WLC) before 4.0.206.0 saves the WLAN ACL configuration with an invalid checksum, which prevents WLAN ACLs from being loaded at boot time, and might allow remote attackers to bypass intended access restrictions, aka Bug ID CSCse58195.</descript></desc><loss_types><conf/><int/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" source="CISCO" url="http://www.cisco.com/warp/public/707/cisco-sa-20070412-wlc.shtml">20070412 Multiple Vulnerabilities in the Cisco Wireless LAN Controller and Cisco Lightweight Access Points</ref><ref source="BID" url="http://www.securityfocus.com/bid/23461">23461</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1368">ADV-2007-1368</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1017908">1017908</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33611">cisco-wlc-acl-weak-security(33611)</ref><ref source="OSVDB" url="http://www.osvdb.org/34138">34138</ref></refs><vuln_soft><prod name="4400 Series Wireless LAN Controller" vendor="Cisco"><vers num=""/></prod><prod name="2100 Series Wireless LAN Controller" vendor="Cisco"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-04-18" name="CVE-2007-2042" published="2007-04-16" seq="2007-2042" severity="Medium" type="CVE"><desc><descript source="cve">Multiple PHP remote file inclusion vulnerabilities in the Avant-Garde Solutions MOSMedia Lite 1.0.6 and earlier module for Mambo allow remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter to (1) support.html.php or (2) info.html.php.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1357">ADV-2007-1357</ref></refs><vuln_soft><prod name="MOSMedia" vendor="Avant-Garde Solutions"><vers edition="Lite" num="1.0.6"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-04-18" name="CVE-2007-2043" published="2007-04-16" seq="2007-2043" severity="High" type="CVE"><desc><descript source="cve">Multiple PHP remote file inclusion vulnerabilities in the Avant-Garde Solutions MOSMedia (com_mosmedia) 1.08 and earlier module for Mambo and Joomla! allow remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter to (1) media.tab.php or (2) media.divs.php.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3714">3714</ref><ref source="BID" url="http://www.securityfocus.com/bid/23432">23432</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1357">ADV-2007-1357</ref></refs><vuln_soft><prod name="MOSMedia" vendor="Avant-Garde Solutions"><vers num="1.0.8" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-04-18" name="CVE-2007-2044" published="2007-04-16" seq="2007-2044" severity="High" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in mod_weather.php in the Antonis Ventouris Weather module for Mambo and Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the absolute_path parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3712">3712</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1356">ADV-2007-1356</ref></refs><vuln_soft><prod name="Weather Module" vendor="Antonis Ventouris"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0" modified="2007-04-18" name="CVE-2007-2045" published="2007-04-16" seq="2007-2045" severity="Medium" type="CVE"><desc><descript source="cve">Unspecified vulnerability in the IP implementation in Sun Solaris 8 and 9 allows remote attackers to cause a denial of service (CPU consumption) via crafted IP packets, probably related to fragmented packets with duplicate or missing fragments.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102866-1">102866</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1375">
ADV-2007-1375</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017911">
1017911</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24857">
24857</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33597">
solaris-ip-packet-dos(33597)</ref><ref source="" url="http://support.avaya.com/elmodocs2/security/ASA-2007-165.htm"></ref><ref source="BID" url="http://www.securityfocus.com/bid/23468">
23468</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24987">
24987</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9127">oval:org.mitre.oval:def:9127</ref></refs><vuln_soft><prod name="Solaris" vendor="Sun"><vers num="8.0"/><vers num="9.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-04-18" name="CVE-2007-2046" published="2007-04-16" seq="2007-2046" severity="High" type="CVE"><desc><descript source="cve">Multiple CRLF injection vulnerabilities in adclick.php in (a) Openads (phpAdsNew) 2.0.11 and earlier and (b) Openads for PostgreSQL (phpPgAds) 2.0.11 and earlier allow remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via CRLF sequences in (1) the dest parameter and (2) the Referer HTTP header.  NOTE: some of these details are obtained from third party information.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref patch="1" source="" url="http://forum.openads.org/index.php?showtopic=503413399&amp;pid=39136"></ref><ref source="" url="http://sourceforge.net/forum/forum.php?forum_id=685278"></ref><ref source="" url="http://sourceforge.net/project/shownotes.php?release_id=500343"></ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1364">ADV-2007-1364</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/24876">24876</ref></refs><vuln_soft><prod name="Openads" vendor="Openads"><vers edition="PostgreSQL" num="2.0.11" prev="1"/><vers num="2.0.11" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-04-18" name="CVE-2007-2047" published="2007-04-16" seq="2007-2047" severity="High" type="CVE"><desc><descript source="cve">CRLF injection vulnerability in www/delivery/ck.php in Openads 2.3 (aka Max Media Manager, MMM) before 0.3.31-alpha-pr3 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via CRLF sequences in the destination parameter. NOTE: some of these details are obtained from third party information.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="" url="http://forum.openads.org/index.php?showtopic=503413399&amp;pid=39136"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1365">ADV-2007-1365</ref></refs><vuln_soft><prod name="Openads" vendor="Openads"><vers num="2.3.30"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0" discovered="2007-03-20" modified="2007-04-18" name="CVE-2007-2048" published="2007-04-16" seq="2007-2048" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in /console in the Management Console in webMethods Glue 6.5.1 and earlier allows remote attackers to read arbitrary system files via a .. (dot dot) in the resource parameter.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/465332/100/0/threaded">20070411 webMethods Glue Management Console Directory Traversal</ref><ref source="" url="http://www.aushack.com/advisories/200704-webmethods.txt"></ref><ref source="BID" url="http://www.securityfocus.com/bid/23423">23423</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1363">ADV-2007-1363</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/465993/100/0/threaded">
20070417 webMethods Security Advisory: Glue console directory traversal vulnerability</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017926">
1017926</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24933">
24933</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2589">2589</ref></refs><vuln_soft><prod name="Glue" vendor="webMethods"><vers num="4.0"/><vers num="5.0"/><vers num="6.5.1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-04-18" name="CVE-2007-2049" published="2007-04-16" seq="2007-2049" severity="Medium" type="CVE"><desc><descript source="cve">Multiple PHP remote file inclusion vulnerabilities in the Calendar Module (com_calendar) 1.5.5 for Mambo allow remote attackers to execute arbitrary PHP code via a URL in the absolute_path parameter to (1) com_calendar.php or (2) mod_calendar.php.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3713">3713</ref><ref source="BID" url="http://www.securityfocus.com/bid/23435">23435</ref></refs><vuln_soft><prod name="Mambo Calendar" vendor="Mambo"><vers num="1.5.5"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0" modified="2007-04-18" name="CVE-2007-2050" published="2007-04-16" seq="2007-2050" severity="Medium" type="CVE"><desc><descript source="cve">Multiple directory traversal vulnerabilities in header.php in RicarGBooK 1.2.1 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in (1) a lang cookie or (2) the language parameter.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3718">3718</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24858">24858</ref><ref source="BID" url="http://www.securityfocus.com/bid/23450">
23450</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1370">
ADV-2007-1370</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33596">
ricargbook-header-file-include(33596)</ref></refs><vuln_soft><prod name="RicarGBooK" vendor="RicarGBooK"><vers num="1.2.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0" modified="2007-04-18" name="CVE-2007-2051" published="2007-04-16" seq="2007-2051" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in the parsecmd function in bftpd before 1.8 has unknown impact and attack vectors related to the confstr variable.</descript></desc><loss_types><avail/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref patch="1" source="" url="http://sourceforge.net/project/shownotes.php?release_id=500238&amp;group_id=32077"></ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1347">ADV-2007-1347</ref></refs><vuln_soft><prod name="bftpd" vendor="bftpd"><vers num="1.6"/><vers num="1.7"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0" modified="2008-02-11" name="CVE-2007-2052" published="2007-04-16" seq="2007-2052" severity="Medium" type="CVE"><desc><descript source="cve">Off-by-one error in the PyLocale_strxfrm function in Modules/_localemodule.c for Python 2.4 and 2.5 causes an incorrect buffer size to be used for the strxfrm function, which allows context-dependent attackers to read portions of memory via unknown manipulations that trigger a buffer over-read due to missing null termination.</descript></desc><loss_types><conf/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref source="" url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=416934"></ref><ref source="" url="https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=235093"></ref><ref source="" url="http://www.python.org/download/releases/2.5.1/NEWS.txt"></ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2007:099">MDKSA-2007:099</ref><ref source="BID" url="http://www.securityfocus.com/bid/23887">23887</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25190">25190</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25217">25217</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1465">ADV-2007-1465</ref><ref source="" url="https://issues.rpath.com/browse/RPL-1358"></ref><ref source="SECUNIA" url="http://secunia.com/advisories/25233">25233</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:099">MDKSA-2007:099</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2007-1076.html">RHSA-2007:1076</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2007-1077.html">RHSA-2007:1077</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2007_13_sr.html">SUSE-SR:2007:013</ref><ref source="TRUSTIX" url="http://www.trustix.org/errata/2007/0019/">2007-0019</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25353">25353</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25787">25787</ref><ref source="SECUNIA" url="http://secunia.com/advisories/28027">28027</ref><ref source="SECUNIA" url="http://secunia.com/advisories/28050">28050</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/488457/100/0/threaded">20080221 VMSA-2008-0003 Moderate: Updated aacraid driver and samba and python service console updates</ref><ref source="MLIST" url="http://lists.vmware.com/pipermail/security-announce/2008/000005.html">[Security-announce] 20080221 VMSA-2008-0003 Moderate: Updated aacraid driver and samba and python service console updates</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/0637">ADV-2008-0637</ref><ref source="SECUNIA" url="http://secunia.com/advisories/29032">29032</ref><ref source="UBUNTU" url="http://www.ubuntu.com/usn/usn-585-1">USN-585-1</ref><ref source="SECUNIA" url="http://secunia.com/advisories/29303">29303</ref><ref source="DEBIAN" url="http://www.debian.org/security/2008/dsa-1551">DSA-1551</ref><ref source="SECUNIA" url="http://secunia.com/advisories/29889">29889</ref></refs><vuln_soft><prod name="Python" vendor="Python Software Foundation"><vers num="2.4"/><vers num="2.5"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-05-01" name="CVE-2007-2053" published="2007-04-30" seq="2007-2053" severity="High" type="CVE"><desc><descript source="cve">Multiple stack-based buffer overflows in AFFLIB before 2.2.6 allow remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via (1) a long LastModified value in an S3 XML response in lib/s3.cpp; (2) a long (a) path or (b) bucket in an S3 URL in lib/vnode_s3.cpp; or (3) a long (c) EFW, (d) AFD, or (c) aimage file path.  NOTE: the aimage vector (3c) has since been recalled from the researcher&apos;s original advisory, since the code is not called in any version of AFFLIB.</descript></desc><sols><sol source="nvd">The vendor has addressed this issue through a product update:
http://www.afflib.org/downloads/
</sol></sols><loss_types><avail/><conf/><int/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/467038/100/0/threaded">20070427 AFFLIB(TM): Multiple Buffer Overflows</ref><ref adv="1" patch="1" source="" url="http://www.vsecurity.com/bulletins/advisories/2007/afflib-overflows.txt"></ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/23695">23695</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33961">
afflib-multiple-bo(33961)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2655">2655</ref></refs><vuln_soft><prod name="AFFLIB" vendor="AFFLIB"><vers num="2.2.0" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-05-01" name="CVE-2007-2054" published="2007-04-30" seq="2007-2054" severity="High" type="CVE"><desc><descript source="cve">Multiple format string vulnerabilities in AFFLIB before 2.2.6 allow remote attackers to execute arbitrary code via certain command line parameters, which are used in (1) warn and (2) err calls in (a) lib/s3.cpp, (b) tools/afconvert.cpp, (c) tools/afcopy.cpp, (d) tools/afinfo.cpp, (e) aimage/aimage.cpp, (f) aimage/imager.cpp, and (g) tools/afxml.cpp.  NOTE: the aimage.cpp vector (e) has since been recalled from the researcher&apos;s original advisory, since the code is not called in any version of AFFLIB.</descript></desc><sols><sol source="nvd">The vendor has addressed this issue through the following product update: http://www.afflib.org/downloads/
</sol></sols><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/467040/100/0/threaded">20070427 AFFLIB(TM): Multiple Format String Injections</ref><ref adv="1" patch="1" source="" url="http://www.vsecurity.com/bulletins/advisories/2007/afflib-fmtstr.txt"></ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33969">
afflib-multiple-format-string(33969)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2657">2657</ref></refs><vuln_soft><prod name="AFFLIB" vendor="AFFLIB"><vers num="2.2.0" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-05-01" name="CVE-2007-2055" published="2007-04-30" seq="2007-2055" severity="High" type="CVE"><desc><descript source="cve">AFFLIB 2.2.8 and earlier allows attackers to execute arbitrary commands via shell metacharacters involving (1) certain command line parameters in tools/afconvert.cpp and (2) arguments to the get_parameter function in aimage/ident.cpp.  NOTE: it is unknown if the get_parameter vector (2) is ever called.</descript></desc><sols><sol source="nvd">The vendor has addressed this issue through a product update which can be found at: http://www.afflib.org/downloads/ </sol></sols><loss_types><avail/><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/467041/100/0/threaded">20070427 AFFLIB(TM): Multiple Shell Metacharacter Injections</ref><ref source="" url="http://www.vsecurity.com/bulletins/advisories/2007/afflib-shellinject.txt"></ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33964">
afflib-multiple-command-execution(33964)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2656">2656</ref></refs><vuln_soft><prod name="AFFLIB" vendor="AFFLIB"><vers num="2.2.8" prev="1"/></prod></vuln_soft></entry><entry modified="2007-05-04" name="CVE-2007-2056" published="2007-04-30" reject="1" seq="2007-2056" type="CVE"><desc><descript source="cve">** REJECT **  The getlock function in aimage/aimage.cpp in AFFLIB 2.2.8 and earlier allows local users to overwrite arbitrary files via a symlink attack on temporary lock files (aka &quot;time-of-check-time-of-use file race&quot;). NOTE: the researcher has retracted the original advisory, stating that &quot;the portion of vulnerable code is not called in any current version of AFFLIB and is therefore not exploitable.&quot;</descript></desc><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/467037/100/0/threaded">

20070427 AFFLIB(TM): Time-of-Check-Time-of-Use File Race</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/467181/100/0/threaded">
20070428 please retract CVE-2007-2056 &quot;Time-of-Check-Time-of-Use File Race in AFFLIB&quot;</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/467182/100/0/threaded">
20070429 Re: please retract CVE-2007-2056 &quot;Time-of-Check-Time-of-Use File Race in AFFLIB&quot;</ref><ref source="" url="http://www.vsecurity.com/bulletins/advisories/2007/afflib-toctou.txt"></ref><ref source="BID" url="http://www.securityfocus.com/bid/23696">
23696</ref></refs></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-04-18" name="CVE-2007-2057" published="2007-04-17" seq="2007-2057" severity="High" type="CVE"><desc><descript source="cve">Stack-based buffer overflow in aircrack-ng airodump-ng 0.7 allows remote attackers to execute arbitrary code via crafted 802.11 authentication packets.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/465552/100/0/threaded">20070412 Aircrack-ng (airodump-ng) remote buffer overflow vulnerability</ref><ref adv="1" source="" url="http://www.nop-art.net/advisories/airodump-ng.txt"></ref><ref source="BID" url="http://www.securityfocus.com/bid/23467">23467</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1379">ADV-2007-1379</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24880">24880</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33626">aircrackng-airodumpng-bo(33626)</ref><ref source="DEBIAN" url="http://www.debian.org/security/2007/dsa-1280">
DSA-1280</ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200704-16.xml">
GLSA-200704-16</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/349828">
VU#349828</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24964">
24964</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24982">
24982</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2584">2584</ref></refs><vuln_soft><prod name="airodump-ng" vendor="Aircrack-ng"><vers num="0.7"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-04-18" name="CVE-2007-2058" published="2007-04-17" seq="2007-2058" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in Acubix PicoZip 4.02 allows user-assisted remote attackers to overwrite arbitrary files via a .. (dot dot) sequence in the file path in an (1) GZ, (2) TAR, (3) RAR, (4) JAR, or (5) ZIP archive.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref source="" url="http://www.bugtraq.ir/articles/advisory/picozip_directory_traversal/9"></ref><ref source="BID" url="http://www.securityfocus.com/bid/23471">23471</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1377">ADV-2007-1377</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24868">24868</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33639">picozip-archive-directory-traversal(33639)</ref></refs><vuln_soft><prod name="PicoZip" vendor="PicoZip"><vers num="4.02"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-04-18" name="CVE-2007-2059" published="2007-04-17" seq="2007-2059" severity="High" type="CVE"><desc><descript source="cve">Multiple buffer overflows in the ESA protocol implementation in eIQnetworks Enterprise Security Analyzer (ESA) 2.5 allow remote attackers to execute arbitrary code via a long parameter to the (1) DELETESEARCHFOLDER, (2) DELTASK, (3) HMGR_CHECKHOSTSCSV, (4) TASKUPDATEDUSER, (5) VERIFYUSERKEY, or (6) VERIFYPWD command.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/465488/100/0/threaded">20070412 INFIGO-2007-04-05: Enterprise Security Analyzer server remotebuffer overflows</ref><ref adv="1" source="" url="http://www.infigo.hr/en/in_focus/advisories/INFIGO-2007-04-05"></ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1380">ADV-2007-1380</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/24881">24881</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33646">eiqnetworks-esa-multiple-commands-bo(33646)</ref></refs><vuln_soft><prod name="Enterprise Security Analyzer" vendor="eIQnetworks"><vers num="2.5"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-04-18" name="CVE-2007-2060" published="2007-04-17" seq="2007-2060" severity="Medium" type="CVE"><desc><descript source="cve">Cross-zone scripting vulnerability in the Wizz RSS Reader before 2.1.9 extension to Mozilla Firefox allows remote attackers to execute arbitrary Javascript in the browser chrome via the RSS feed DOM.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref source="" url="https://addons.mozilla.org/en-US/firefox/addon/424"></ref><ref patch="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/319464">VU#319464</ref><ref source="BID" url="http://www.securityfocus.com/bid/23523">
23523</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1425">
ADV-2007-1425</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24913">
24913</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33693">
firefox-wizz-rssfeed-xss(33693)</ref></refs><vuln_soft><prod name="Wizz RSS Reader" vendor="Wizz Computers"><vers num="2.1.8" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" discovered="2007-04-05" modified="2007-04-18" name="CVE-2007-2061" published="2007-04-17" seq="2007-2061" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in check_login.asp in AfterLogic MailBee WebMail Pro 3.4 allows remote attackers to inject arbitrary web script or HTML via the username parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/465611/100/0/threaded">20070413 [MajorSecurity Advisory #44]MailBee WebMail Pro - Cross Site Scripting Issue</ref><ref adv="1" source="" url="http://www.majorsecurity.de/index_2.php?major_rls=major_rls44"></ref><ref source="BID" url="http://www.securityfocus.com/bid/23481">23481</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33645">mailbee-checklogin-xss(33645)</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1416">
ADV-2007-1416</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24882">
24882</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2572">2572</ref></refs><vuln_soft><prod name="MailBee WebMail" vendor="AfterLogic"><vers edition="Pro" num="3.4"/></prod></vuln_soft></entry><entry CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" CVSS_score="9.3" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-04-18" name="CVE-2007-2062" published="2007-04-17" seq="2007-2062" severity="High" type="CVE"><desc><descript source="cve">Stack-based buffer overflow in VCDGear 3.55 and 3.56 BETA allows user-assisted remote attackers to execute arbitrary code via a long FILE argument in a CUE file.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/><user_init/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/465725/100/0/threaded">20070414 VCDGear &lt;= 3.56 Build 050213 (FILE) Local Code Execution Exploit</ref><ref source="MILW0RM" url="http://milw0rm.com/exploits/3727">3727</ref><ref source="BID" url="http://www.securityfocus.com/bid/23475">23475</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24884">24884</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33642">vcdgear-seh-bo(33642)</ref></refs><vuln_soft><prod name="VCDGear" vendor="VCDGear"><vers num="3.55"/><vers num="3.56 BETA"/></prod></vuln_soft></entry><entry CVSS_base_score="4.4" CVSS_exploit_subscore="3.4" CVSS_impact_subscore="6.4" CVSS_score="4.4" CVSS_vector="(AV:L/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2008-01-02" name="CVE-2007-2063" published="2007-04-17" seq="2007-2063" severity="Medium" type="CVE"><desc><descript source="cve">SSH Tectia Server for IBM z/OS before 5.4.0 uses insecure world-writable permissions for (1) the server pid file, which allows local users to cause arbitrary processes to be stopped, or (2) when _BPX_BATCH_UMASK is missing from the environment, creates HFS files with insecure permissions, which allows local users to read or modify these files and have other unknown impact.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref source="" url="http://www.ssh.com/documents/33/SSH_Tectia_Server_5.4.0_zOS_releasenotes.txt"></ref><ref source="BID" url="http://www.securityfocus.com/bid/23508">23508</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1017913">1017913</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/24916">24916</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1414">ADV-2007-1414</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33699">ssh-tectia-pid-hfs-privilege-escalation(33699)</ref><ref source="OSVDB" url="http://www.osvdb.org/35014">35014</ref></refs><vuln_soft><prod name="SSH Tectia Server" vendor="SSH Communications Security"><vers edition="IBM zOS" num="5.3.0" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-04-18" name="CVE-2007-2064" published="2007-04-17" seq="2007-2064" severity="High" type="CVE"><desc><descript source="cve">Multiple PHP remote file inclusion vulnerabilities in Robert Ladstaetter ActionPoll 1.1.0, and possibly 1.1.1, allow remote attackers to execute arbitrary PHP code via a URL in (1) the CONFIG_POLLDB parameter to actionpoll.php or (2) the CONFIG_DB parameter to db/DataReaderWriter.php, different vectors than CVE-2001-1297.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/465871/100/0/threaded">20070415 ActionPoll Script (actionpoll.php) Remote File Include // starhack.org</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/20788">20788</ref><ref source="BID" url="http://www.securityfocus.com/bid/23504">23504</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33691">
actionpoll-multiple-file-include(33691)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2587">2587</ref></refs><vuln_soft><prod name="Actionpoll" vendor="Actionpoll"><vers num="1.1.0"/><vers num="1.1.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-04-18" name="CVE-2007-2065" published="2007-04-17" seq="2007-2065" severity="High" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in db/PollDB.php in Robert Ladstaetter ActionPoll 1.1.1 allows remote attackers to execute arbitrary PHP code via a URL in the CONFIG_DATAREADERWRITER parameter, a different vector than CVE-2001-1297.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/20788">20788</ref></refs><vuln_soft><prod name="Actionpoll" vendor="Actionpoll"><vers num="1.1.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0" modified="2007-04-18" name="CVE-2007-2066" published="2007-04-17" seq="2007-2066" severity="Medium" type="CVE"><desc><descript source="cve">UseBB before 1.0.6 allows remote attackers to obtain sensitive information via a request with unspecified GET or POST parameters to an unspecified script, which reveals the path in an error message.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="" url="http://www.netvigilance.com/advisory0016"></ref><ref source="" url="http://www.usebb.net/community/topic.php?id=1541"></ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24837">24837</ref></refs><vuln_soft><prod name="UseBB" vendor="UseBB"><vers num="1.0"/><vers num="1.0.1"/><vers num="1.0.2"/><vers num="1.0.3"/><vers num="1.0.4"/><vers num="1.0.5"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-04-18" name="CVE-2007-2067" published="2007-04-17" seq="2007-2067" severity="High" type="CVE"><desc><descript source="cve">Multiple PHP remote file inclusion vulnerabilities in Marco Antonio Islas Cruz Web Slider (WebSlider) 0.6 allow remote attackers to execute arbitrary PHP code via a URL in the path parameter to (1) index.php, (2) modules/pdf.php, (3) plugins/highlight.php, or (4) include/modules.php.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3745">3745</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1397">ADV-2007-1397</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33689">webslider-path-file-include(33689)</ref></refs><vuln_soft><prod name="WebSlider" vendor="WebSlider"><vers num="0.6"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-04-18" name="CVE-2007-2068" published="2007-04-17" seq="2007-2068" severity="Medium" type="CVE"><desc><descript source="cve">Multiple PHP remote file inclusion vulnerabilities in the StoreFront mods for Gallery allow remote attackers to execute arbitrary PHP code via a URL in the GALLERY_BASEDIR parameter to (1) mods/business_functions.php or (2) mods/ui_functions.php.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3749">3749</ref><ref source="BID" url="http://www.securityfocus.com/bid/23516">23516</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1423">
ADV-2007-1423</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24890">
24890</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33701">
storefront-functions-file-include(33701)</ref></refs><vuln_soft><prod name="StoreFront Gallery" vendor="StoreFront for Gallery"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-04-18" name="CVE-2007-2069" published="2007-04-17" seq="2007-2069" severity="High" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in scr/soustab.php in openMairie 1.11 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the dsn[phptype] parameter.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3747">3747</ref><ref source="BID" url="http://www.securityfocus.com/bid/23505">23505</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1421">
ADV-2007-1421</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33700">
openmairie-soustab-file-include(33700)</ref></refs><vuln_soft><prod name="openMairie" vendor="openMairie"><vers num="1.11" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-08-02" name="CVE-2007-2070" published="2007-04-17" seq="2007-2070" severity="High" type="CVE"><desc><descript source="cve">Multiple PHP remote file inclusion vulnerabilities in Turnkey Web Tools SunShop Shopping Cart before 3.5.1 allow remote attackers to execute arbitrary PHP code via a URL in the abs_path parameter to (1) index.php or (2) checkout.php.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3748">3748</ref><ref source="BID" url="http://www.securityfocus.com/bid/23511">23511</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1422">ADV-2007-1422</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33670">sunshop-index-checkout-file-include(33670)</ref></refs><vuln_soft><prod name="SunShop Shopping Cart" vendor="Turnkey Web Tools"><vers num="3.5"/><vers num="4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" modified="2007-04-18" name="CVE-2007-2071" published="2007-04-17" seq="2007-2071" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Open-gorotto 2.0a 2006/02/08 edition, 2006/03/19 edition, and 2006/04/07 edition before 20070416 allow remote attackers to inject arbitrary web script or HTML via unspecified parameters to (1) pub/modules/d/_top.html; (2) /pub/modules/a/_access.html; (3) _circletop.html or (4) _cir66.html in pub/modules/ci/; or (5) _fri66.html, (6) _inv66.html, (7) _top.html, (8) _friends.html, or (9) _fri33.html in pub/modules/f/.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref source="" url="http://jvn.jp/jp/JVN%2384646028/index.html"></ref><ref source="" url="http://release.open-gorotto.jp/"></ref><ref source="" url="http://release.open-gorotto.jp/openg_patch_20070416.tar.gz"></ref><ref source="BID" url="http://www.securityfocus.com/bid/23507">23507</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1398">ADV-2007-1398</ref></refs><vuln_soft><prod name="Open-gorotto" vendor="Open-gorotto"><vers num="2.0 a"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-04-18" name="CVE-2007-2072" published="2007-04-17" seq="2007-2072" severity="High" type="CVE"><desc><descript source="cve">** DISPUTED **  PHP remote file inclusion vulnerability in index.php in Ivan Gallery Script 0.1 allows remote attackers to execute arbitrary PHP code via a URL in the dir parameter.  NOTE: this issue has been disputed by third party researchers for 0.3, stating that the dir variable is properly initialized before use.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/465897/100/0/threaded">20070416 Ivan Gallery Script V.0.1 (index.php) Remote File Include Exploit</ref><ref source="VIM" url="http://attrition.org/pipermail/vim/2007-April/001534.html">20070417 Not Quite: Ivan Gallery Script V.0.1 (index.php) Remote File Include Exploit</ref><ref source="BID" url="http://www.securityfocus.com/bid/23519">23519</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2580">2580</ref></refs><vuln_soft><prod name="Ivan Gallery Script" vendor="Ivan Gallery Script"><vers num="0.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-04-18" name="CVE-2007-2073" published="2007-04-17" seq="2007-2073" severity="High" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in index.php in Ivan Gallery Script 0.3 allows remote attackers to execute arbitrary PHP code via a URL in the gallery parameter in a new session.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="VIM" url="http://attrition.org/pipermail/vim/2007-April/001534.html">20070417 Not Quite: Ivan Gallery Script V.0.1 (index.php) Remote File Include Exploit</ref></refs><vuln_soft><prod name="Ivan Gallery Script" vendor="Ivan Gallery Script"><vers num="0.3"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-04-18" name="CVE-2007-2074" published="2007-04-17" seq="2007-2074" severity="Medium" type="CVE"><desc><descript source="cve">Certain programs in containers in ScramDisk 4 Linux before 1.0-1 execute with SUID permissions, which allows local users to gain privileges via mounted containers.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref source="" url="http://sourceforge.net/tracker/index.php?func=detail&amp;aid=1696777&amp;group_id=101952&amp;atid=630783"></ref><ref source="BID" url="http://www.securityfocus.com/bid/23495">23495</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1418">ADV-2007-1418</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24903">24903</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33674">
scramdisk-mount-privilege-escalation(33674)</ref></refs><vuln_soft><prod name="ScramDisk 4 Linux" vendor="ScramDisk 4 Linux"><vers num="1.0.0" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.9" CVSS_exploit_subscore="3.4" CVSS_impact_subscore="10.0" CVSS_score="6.9" CVSS_vector="(AV:L/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-04-18" name="CVE-2007-2075" published="2007-04-17" seq="2007-2075" severity="Medium" type="CVE"><desc><descript source="cve">ScramDisk 4 Linux before 1.0-1 does not perform permission checks on mount points, which allows local users to gain privileges by using a system directory as a mount point for a container.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref patch="1" source="" url="http://sourceforge.net/tracker/index.php?func=detail&amp;aid=1696780&amp;group_id=101952&amp;atid=630783"></ref><ref source="BID" url="http://www.securityfocus.com/bid/23495">23495</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1418">ADV-2007-1418</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24903">24903</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33677">
scramdisk-directory-privilege-escalation(33677)</ref></refs><vuln_soft><prod name="ScramDisk 4 Linux" vendor="ScramDisk 4 Linux"><vers num="1.0.0" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-04-18" name="CVE-2007-2076" published="2007-04-17" seq="2007-2076" severity="Medium" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in index.php in Maian Gallery 1.0 allows remote attackers to execute arbitrary PHP code via a URL in the path_to_folder parameter.  NOTE: this issue was disputed by a third party researcher, but confirmed by the vendor, stating &quot;this problem existed only briefly in v1.0.&quot;</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/465732/100/0/threaded">20070414 Maian Gallery v1.0</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/465853/100/0/threaded">20070414 Re: Maian Gallery v1.0</ref><ref source="VIM" url="http://attrition.org/pipermail/vim/2007-April/001530.html">20070415 false: Maian Gallery v1.0</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33692">maiangallery-pathtofolder-file-include(33692)</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2007-04/0244.html">
20070415 Re: phpMyChat-0.14.5</ref><ref source="OSVDB" url="http://www.osvdb.org/34149">
34149</ref></refs><vuln_soft><prod name="Gallery" vendor="Maian"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-04-18" name="CVE-2007-2077" published="2007-04-17" seq="2007-2077" severity="High" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in search.php in Maian Search 1.1 allows remote attackers to execute arbitrary PHP code via a URL in the path_to_folder parameter.  NOTE: this issue was disputed by a third party researcher, but confirmed by the vendor, stating &quot;this issue was fixed last year and [no] is longer a problem.&quot;</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/465731/100/0/threaded">20070414 Maian Search v1.1</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/465857/100/0/threaded">20070414 Re: Maian Search v1.1</ref><ref source="VIM" url="http://attrition.org/pipermail/vim/2007-April/001524.html">20070414 false: Maian Search v1.1</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2007-04/0244.html">
20070415 Re: phpMyChat-0.14.5</ref><ref source="OSVDB" url="http://www.osvdb.org/34150">
34150</ref></refs><vuln_soft><prod name="Search" vendor="Maian"><vers num="1.1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-04-18" name="CVE-2007-2078" published="2007-04-17" seq="2007-2078" severity="Medium" type="CVE"><desc><descript source="cve">** DISPUTED **  PHP remote file inclusion vulnerability in index.php in Maian Weblog 3.1 allows remote attackers to execute arbitrary PHP code via a URL in the path_to_folder parameter.  NOTE: this issue was disputed by a third party researcher, since the path_to_folder variable is initialized before use.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/465735/100/0/threaded">20070414 Maian Weblog v3.1</ref><ref source="VIM" url="http://attrition.org/pipermail/vim/2007-April/001527.html">20070415 false: Maian Weblog v3.1</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2007-04/0244.html">
20070415 Re: phpMyChat-0.14.5</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33708">
maianweblog-pathtofolder-file-include(33708)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2582">2582</ref></refs><vuln_soft><prod name="Weblog" vendor="Maian"><vers num="3.1"/></prod></vuln_soft></entry><entry CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" CVSS_score="9.3" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-07-10" name="CVE-2007-2079" published="2007-04-17" seq="2007-2079" severity="High" type="CVE"><desc><descript source="cve">The ADONewConnection Connect function in adodb.php in XAMPP 1.6.0a and earlier for Windows uses untrusted input for the database server hostname, which allows remote attackers to trigger a library buffer overflow and execute arbitrary code via a long host parameter, or have other unspecified impact.  NOTE: it could be argued that this is an issue in mssql_connect (CVE-2007-1411.1) in PHP, or an issue in the ADOdb Library, and the proper fix should be in one of these products; if so, then this should not be treated as a vulnerability in XAMPP.</descript></desc><impacts><impact source="nvd">Failed exploit attempts will likely crash the webserver, denying service to legitimate users.  Additionally, this issue is remotely exploitable only if the installation is not secured as described in the manual.</impact></impacts><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3738">3738</ref><ref source="BID" url="http://www.securityfocus.com/bid/23491">23491</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33683">xampp-mssqlconnect-bo(33683)</ref></refs><vuln_soft><prod name="Apache Distribution" vendor="XAMPP"><vers edition="Windows" num="1.6.0a" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-04-18" name="CVE-2007-2080" published="2007-04-17" seq="2007-2080" severity="High" type="CVE"><desc><descript source="cve">Multiple SQL injection vulnerabilities in XAMPP 1.6.0a for Windows allow remote attackers to execute arbitrary SQL commands via unspecified vectors in certain test scripts.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3738">3738</ref></refs><vuln_soft><prod name="Apache Distribution" vendor="XAMPP"><vers edition="Windows" num="1.6.0a"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-04-18" name="CVE-2007-2081" published="2007-04-17" seq="2007-2081" severity="High" type="CVE"><desc><descript source="cve">MyBlog 0.9.8 and earlier allows remote attackers to bypass authentication requirements via the admin cookie parameter to certain admin files, as demonstrated by admin/settings.php.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/465873/100/0/threaded">20070415 MyBlog &lt;= 0.9.8 Remote Command Execution Exploit</ref><ref source="BID" url="http://www.securityfocus.com/bid/23521">23521</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2581">2581</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/34025">myblog-admin-cookie-authentication-bypass(34025)</ref></refs><vuln_soft><prod name="MyBlog" vendor="MyBlog"><vers num="0.9.8" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.5" CVSS_exploit_subscore="8.0" CVSS_impact_subscore="6.4" CVSS_score="6.5" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-04-18" name="CVE-2007-2082" published="2007-04-17" seq="2007-2082" severity="Medium" type="CVE"><desc><descript source="cve">Direct static code injection vulnerability in admin/settings.php in MyBlog 0.9.8 and earlier allows remote authenticated admin users to inject arbitrary PHP code via the content parameter, which can be executed by accessing index.php.  NOTE: a separate vulnerability could be leveraged to make this issue exploitable by remote unauthenticated attackers.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/465873/100/0/threaded">20070415 MyBlog &lt;= 0.9.8 Remote Command Execution Exploit</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33707">
myblog-settings-code-execution(33707)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2581">2581</ref></refs><vuln_soft><prod name="MyBlog" vendor="MyBlog"><vers num="0.9.8" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.9" CVSS_exploit_subscore="3.4" CVSS_impact_subscore="10.0" CVSS_score="6.9" CVSS_vector="(AV:L/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-04-18" name="CVE-2007-2083" published="2007-04-17" seq="2007-2083" severity="Medium" type="CVE"><desc><descript source="cve">vsdatant.sys in Check Point Zone Labs ZoneAlarm Pro before 7.0.302.000 does not validate certain arguments before being passed to hooked SSDT function handlers, which allows local users to cause a denial of service (system crash) or possibly execute arbitrary code via crafted arguments to the (1) NtCreateKey and (2) NtDeleteFile functions.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/465868/100/0/threaded">20070415 ZoneAlarm Multiple insufficient argument validation of hooked SSDT function Vulnerability</ref><ref adv="1" patch="1" source="" url="http://www.matousec.com/info/advisories/ZoneAlarm-Multiple-insufficient-argument-validation-of-hooked-SSDT-functions.php"></ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33664">zonealarm-vsdatant-dos(33664)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2591">2591</ref></refs><vuln_soft><prod name="ZoneAlarm Pro" vendor="Zone Labs"><vers num="6.5.714.000" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-12-31" name="CVE-2007-2084" published="2007-04-18" seq="2007-2084" severity="Medium" type="CVE"><desc><descript source="cve">** DISPUTED **  PHP remote file inclusion vulnerability in MobilePublisherphp 1.1.2 allows remote attackers to execute arbitrary PHP code via a URL in the auth_method parameter to (1) index.php, (2) list.php, (3) postreview.php, (4) reindex.php, (5) sections.php, (6) templates.php, (7) userinfo.php, (8) users.php, and (9) view.php in admin/.  NOTE: this issue has been disputed by a reliable third party, who states that $auth_method is defined before use.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/465724/100/0/threaded">20070414 MobilePublisherphp v1.1.2 Remote File Include Vulnerabilities</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33679">mobilepublisher-authmethod-file-include(33679)</ref><ref source="VIM" url="http://attrition.org/pipermail/vim/2007-April/001523.html">20070414 true until installed: MobilePublisherphp v1.1.2 Remote File Include Vulnerabilities</ref><ref source="OSVDB" url="http://www.osvdb.org/35325">35325</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2583">2583</ref></refs><vuln_soft><prod name="MobilePublisherPHP" vendor="MobilePublisherPHP"><vers num="1.1.2"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-04-18" name="CVE-2007-2085" published="2007-04-18" seq="2007-2085" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in oe2edit.cgi in oe2edit CMS allows remote attackers to inject arbitrary web script or HTML via the q parameter.</descript></desc><impacts><impact source="nvd">An attacker can exploit this issue by enticing an unsuspecting user to follow a malicious URI which indicates a Medium Access Complexity.</impact></impacts><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://www.majorsecurity.de/index_2.php?major_rls=major_rls45"></ref><ref source="BID" url="http://www.securityfocus.com/bid/23512">23512</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1417">ADV-2007-1417</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24919">24919</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/465844/100/0/threaded">

20070415 [MajorSecurity Advisory #45]oe2edit CMS - Cross Site Scripting and Cookie Manipulation Issue</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33690">
oe2editcms-oe2edit-xss(33690)</ref></refs><vuln_soft><prod name="oe2edit CMS" vendor="oe2edit"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-04-18" name="CVE-2007-2086" published="2007-04-18" seq="2007-2086" severity="Medium" type="CVE"><desc><descript source="cve">Multiple PHP remote file inclusion vulnerabilities in CNStats 2.9 allow remote attackers to execute arbitrary PHP code via a URL in the bj parameter to (1) who_r.php or (2) who_s.php in reports/.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MILW0RM" url="http://milw0rm.com/exploits/3741">3741</ref><ref source="BID" url="http://www.securityfocus.com/bid/23501">23501</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24902">24902</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33672">cnstats-whor-file-include(33672)</ref></refs><vuln_soft><prod name="CNStats" vendor="CNStats"><vers num="2.9"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-04-18" name="CVE-2007-2087" published="2007-04-18" seq="2007-2087" severity="Medium" type="CVE"><desc><descript source="cve">Multiple PHP remote file inclusion vulnerabilities in CNStats 2.12, when register_globals is enabled and .htaccess is not recognized, allow remote attackers to execute arbitrary PHP code via a URL in the bn parameter to (1) who_r.php or (2) who_s.php in reports/.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript></desc><impacts><impact source="nvd">Successful exploitation requires that &quot;register_globals&quot; is enabled and support for &quot;.htaccess&quot; files is disabled.</impact></impacts><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24902">24902</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33977">cnstats-bn-file-include(33977)</ref></refs><vuln_soft><prod name="CNStats" vendor="CNStats"><vers num="2.12"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-04-18" name="CVE-2007-2088" published="2007-04-18" seq="2007-2088" severity="High" type="CVE"><desc><descript source="cve">Multiple PHP remote file inclusion vulnerabilities in Sitebar 3.3.5 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the (1) writerFile parametere to index.php and the (2) file parameter to Integrator.php.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/465860/100/0/threaded">20070414 Sitebar 3.3.5 (index.php writerFile)Remote File Include Vulnerabilities</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33688">sitebar-index-integrator-file-include(33688)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2586">2586</ref></refs><vuln_soft><prod name="SiteBar" vendor="SiteBar"><vers num="3.3.5" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-04-18" name="CVE-2007-2089" published="2007-04-18" seq="2007-2089" severity="Medium" type="CVE"><desc><descript source="cve">Multiple PHP remote file inclusion vulnerabilities in the Jx Development Article 1.1 and earlier component for Mambo and Joomla! allow remote attackers to execute arbitrary PHP code via a URL in the absolute_path parameter to com_articles.php in (1) components/ or (2) classes/html/.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3736">3736</ref><ref source="BID" url="http://www.securityfocus.com/bid/23513">23513</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1394">ADV-2007-1394</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33663">newarticle-comarticles-file-include(33663)</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/466059/100/0/threaded">

20070415 Mambo/Joomla Component New Article Component RFI</ref></refs><vuln_soft><prod name="Article Component" vendor="Jx Development"><vers num="1.1" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-04-18" name="CVE-2007-2090" published="2007-04-18" seq="2007-2090" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in index.php in TuMusika Evolution 1.6 allows remote attackers to inject arbitrary web script or HTML via the msg parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/465515/100/0/threaded">20070412 TuMusika Evolution 1.6 Cross Site Scripting Vulnerabilitiy</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1374">ADV-2007-1374</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24874">24874</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33593">tumusika-index-xss(33593)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2585">2585</ref></refs><vuln_soft><prod name="TuMusika Evolution" vendor="TuMusika Evolution"><vers num="1.6"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-08-02" name="CVE-2007-2091" published="2007-04-18" seq="2007-2091" severity="High" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in blocks/tsdisplay4xoops_block2.php in tsdisplay4xoops (TSD4XOOPS, aka the TeamSpeak display module) 0.1 allows remote attackers to execute arbitrary PHP code via a URL in the xoops_url parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3750">3750</ref><ref source="BID" url="http://www.securityfocus.com/bid/23518">23518</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1424">ADV-2007-1424</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33695">xoops-tsdisplay4xoopsblock2-file-include(33695)</ref></refs><vuln_soft><prod name="Tsdisplay4xoops" vendor="Tsdisplay4xoops"><vers num="0.08"/><vers num="0.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-04-18" name="CVE-2007-2092" published="2007-04-18" seq="2007-2092" severity="High" type="CVE"><desc><descript source="cve">Direct static code injection vulnerability in index.php in Limesoft Guestbook (LS Simple Guestbook) allows remote attackers to inject arbitrary PHP code into posts.txt via the name parameter.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1393">ADV-2007-1393</ref></refs><vuln_soft><prod name="Limesoft Guestbook" vendor="Limesoft"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-04-18" name="CVE-2007-2093" published="2007-04-18" seq="2007-2093" severity="High" type="CVE"><desc><descript source="cve">Direct static code injection vulnerability in index.php in Limesoft Guestbook (LS Simple Guestbook) 1.0 allows remote attackers to inject arbitrary PHP code into posts.txt via the message parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/465864/100/0/threaded">20070415 LS simple guestbook - arbitrary code execution</ref><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3735">3735</ref><ref source="BID" url="http://www.securityfocus.com/bid/23503">23503</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1393">ADV-2007-1393</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24904">24904</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33666">lsguestbook-index-code-execution(33666)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2590">2590</ref></refs><vuln_soft><prod name="Limesoft Guestbook" vendor="Limesoft"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-04-18" name="CVE-2007-2094" published="2007-04-18" seq="2007-2094" severity="High" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in index.php in Anthologia 0.5.2 allows remote attackers to execute arbitrary PHP code via a URL in the ads_file parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3751">3751</ref><ref source="BID" url="http://www.securityfocus.com/bid/23524">23524</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1427">
ADV-2007-1427</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24908">
24908</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33705">
anthologia-adsfile-file-include(33705)</ref><ref source="OSVDB" url="http://www.osvdb.org/34083">
34083</ref></refs><vuln_soft><prod name="Anthologia" vendor="Anthologia"><vers num="0.5.2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-04-18" name="CVE-2007-2095" published="2007-04-18" seq="2007-2095" severity="High" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in chat.php in MySpeach 1.9 allows remote attackers to execute arbitrary PHP code via a URL in the my[root] parameter, a different vector than CVE-2007-0498.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/465721/100/0/threaded">20070414 MySpeach v1.9</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2592">2592</ref></refs><vuln_soft><prod name="MySpeach" vendor="MySpeach"><vers num="1.9"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-04-18" name="CVE-2007-2096" published="2007-04-18" seq="2007-2096" severity="High" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in common.php in Hinton Design PHPHD Download System (phphd_downloads) allows remote attackers to execute arbitrary PHP code via a URL in the phphd_real_path parameter. NOTE: this issue may be present in versions from 2006.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/465983/100/0/threaded">20070417 Remot File Include In Script phphd_downloads</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33724">
phphd-common-code-execution(33724)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2588">2588</ref></refs><vuln_soft><prod name="PHPHD Download System" vendor="Hinton Design"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-08-02" name="CVE-2007-2097" published="2007-04-18" seq="2007-2097" severity="High" type="CVE"><desc><descript source="cve">** DISPUTED **  Multiple PHP remote file inclusion vulnerabilities in OpenConcept Back-End CMS 0.4.7 allow remote attackers to execute arbitrary PHP code via a URL in the includes_path parameter to (1) click.php or (2) pollcollector.php in htdocs/; or (3) index.php, (4) articlepages.php, (5) articles.php, (6) articleform.php, (7) articlesections.php, (8) createArticlesPage.php, (9) guestbook.php, (10) helpguide.php, (11) helpguideeditor.php, (12) links.php, (13) upload.php, (14) sitestatistics.php, (15) nav.php, (16) tpl_upload.php, (17) linksections, or (18) pophelp.php in htdocs/site-admin/; different vectors than CVE-2006-5076.  NOTE: this issue is disputed by a third party, who states that $includes_path is defined before use.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/465734/100/0/threaded">20070414 Back-End CMS Database Tables v0.4.7 Remote File Include Vulnerabilities</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33668">backend-multiple-scripts-file-include(33668)</ref><ref source="VIM" url="http://attrition.org/pipermail/vim/2007-April/001528.html">20070415 false: Back-End CMS Database Tables v0.4.7 Remote File Include Vulnerabilities</ref><ref source="OSVDB" url="http://www.osvdb.org/34148">34148</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2573">2573</ref></refs><vuln_soft><prod name="Back-End CMS" vendor="OpenConcept"><vers num="0.4.7"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-04-18" name="CVE-2007-2098" published="2007-04-18" seq="2007-2098" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in showpic.php in Wabbit PHP Gallery 0.9 allow remote attackers to inject arbitrary web script or HTML via the (1) pic and (2) gal parameters.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/465985/100/0/threaded">20070416 Wabbit PHP Gallery v0.9 Cross Site Scripting</ref><ref source="BID" url="http://www.securityfocus.com/bid/23526">
23526</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24943">
24943</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33717">
wabbit-showpic-xss(33717)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2574">2574</ref></refs><vuln_soft><prod name="Wabbit PHP Gallery" vendor="Wabbit"><vers num="0.9"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-04-18" name="CVE-2007-2099" published="2007-04-18" seq="2007-2099" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in htdocs/php.php in OpenConcept Back-End CMS 0.4.7 allows remote attackers to inject arbitrary web script or HTML via the page[] parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/465728/100/0/threaded">20070414 Back-End CMS Database Tables v0.4.7 Cross Site Scripting</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33685">backend-htdocs-xss(33685)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2575">2575</ref></refs><vuln_soft><prod name="Back-End CMS" vendor="OpenConcept"><vers num="0.4.7"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-04-18" name="CVE-2007-2100" published="2007-04-18" seq="2007-2100" severity="High" type="CVE"><desc><descript source="cve">FAC Guestbook 2.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for db/Gdb.mdb.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><access/><design/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/465544/100/0/threaded">20070412 FAC GuestBook v2.0 remote database disclosure vulnerability</ref><ref source="BID" url="http://www.securityfocus.com/bid/23441">23441</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24872">24872</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33600">facguestbook-gdb-gbdb-information-disclosure(33600)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2570">2570</ref></refs><vuln_soft><prod name="FAC Guestbook" vendor="FAC Guestbook"><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-04-18" name="CVE-2007-2101" published="2007-04-18" seq="2007-2101" severity="High" type="CVE"><desc><descript source="cve">FAC Guestbook 3.01 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for db/gbdb.mdb.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><access/><design/></vuln_types><range><network/></range><refs><ref source="BID" url="http://www.securityfocus.com/bid/23441">23441</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24872">24872</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33600">facguestbook-gdb-gbdb-information-disclosure(33600)</ref></refs><vuln_soft><prod name="FAC Guestbook" vendor="FAC Guestbook"><vers num="3.01"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-04-18" name="CVE-2007-2102" published="2007-04-18" seq="2007-2102" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in weblog.php in my little weblog allows remote attackers to inject arbitrary web script or HTML via the id parameter, a different vector than CVE-2006-6087.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/465986/100/0/threaded">20070416 my little weblog Cross Site Scripting</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24942">
24942</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33718">
mylittleweblog-id-xss(33718)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2571">2571</ref></refs><vuln_soft><prod name="My Little Weblog" vendor="my little homepage"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-04-18" name="CVE-2007-2103" published="2007-04-18" seq="2007-2103" severity="High" type="CVE"><desc><descript source="cve">Multiple PHP remote file inclusion vulnerabilities in my little forum 1.7 allow remote attackers to execute arbitrary PHP code via a URL in the lang parameter to (1) admin.php and (2) timedifference.php.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/465987/100/0/threaded">20070416 my little forum 1.7 Remote File Include Vulnerabilitiy</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33719">
mylittleforum-lang-file-include(33719)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2576">2576</ref></refs><vuln_soft><prod name="my little forum" vendor="my little homepage"><vers num="1.7"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-04-18" name="CVE-2007-2104" published="2007-04-18" seq="2007-2104" severity="High" type="CVE"><desc><descript source="cve">Multiple directory traversal vulnerabilities in iXon CMS 0.30 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the theme_url parameter to (1) index.php, (2) page.php, (3) search.php, (4) single.php, and (5) archives.php.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/464675/100/0/threaded">20070404 iXon_CMS 0.30 Remote File Include Vulnerabilities</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33438">ixoncms-themeurl-file-include(33438)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2577">2577</ref></refs><vuln_soft><prod name="iXon CMS" vendor="iXon CMS"><vers num="0.30"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-04-18" name="CVE-2007-2105" published="2007-04-18" seq="2007-2105" severity="High" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in admin/index.php in Monkey CMS 0.0.3 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the admin_skin parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/464704/100/0/threaded">20070404 Monkey CMS v0.0.3 Remote File Include Vulnerabilitiy</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33436">monkeycms-index-file-include(33436)</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/470801/100/100/threaded">20070607 Re: Monkey CMS v0.0.3 Remote File Include Vulnerabilitiy</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2578">2578</ref></refs><vuln_soft><prod name="Monkey CMS" vendor="Monkey CMS"><vers num="0.0.3"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-04-18" name="CVE-2007-2106" published="2007-04-18" seq="2007-2106" severity="High" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in index.php in Kai Content Management System (K-CMS) 1.0 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the current_theme parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/464677/100/0/threaded">20070404 K-CMS v1.0 Remote File Include Vulnerabilities</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33437">kcms-index-file-include(33437)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2579">2579</ref></refs><vuln_soft><prod name="Kai Content Management System" vendor="Kai Content Management System"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-04-18" name="CVE-2007-2107" published="2007-04-18" seq="2007-2107" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in visit.php in the Rha7 Downloads (rha7downloads) 1.0 module for XOOPS allows remote attackers to execute arbitrary SQL commands via the cid parameter, a different vector than CVE-2007-1960.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1266">ADV-2007-1266</ref></refs><vuln_soft><prod name="Rha7 Downloads" vendor="Rha7 Downloads"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-08-02" name="CVE-2007-2108" published="2007-04-18" seq="2007-2108" severity="Medium" type="CVE"><desc><descript source="cve">Unspecified vulnerability in the Core RDBMS component Oracle Database 9.0.1.5, 9.2.0.8, 10.1.0.5, and 10.2.0.2 on Windows allows remote attackers to have an unknown impact, aka DB01.  NOTE: as of 20070424, Oracle has not disputed reliable claims that this issue occurs because the NTLM SSPI AcceptSecurityContext function grants privileges based on the username provided even though all users are authenticated as Guest, which allows remote attackers to gain privileges.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref patch="1" source="" url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpuapr2007.html"></ref><ref source="" url="http://www.integrigy.com/security-resources/analysis/Integrigy_Oracle_CPU_April_2007_Analysis.pdf"></ref><ref source="" url="http://www.ngssoftware.com/papers/database-on-xp.pdf"></ref><ref source="" url="http://www.ngssoftware.com/research/papers/NGSSoftware-OracleCPUAPR2007.pdf"></ref><ref source="" url="http://www.red-database-security.com/advisory/oracle_cpu_apr_2007.html"></ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/809457">VU#809457</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1426">ADV-2007-1426</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017927">1017927</ref><ref source="HP" url="http://www.securityfocus.com/archive/1/archive/1/466329/100/200/threaded">HPSBMA02133</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA07-108A.html">TA07-108A</ref><ref source="BID" url="http://www.securityfocus.com/bid/23532">23532</ref></refs><vuln_soft><prod name="Oracle Database" vendor="Oracle"><vers num="10.1.0.5"/><vers num="10.2.0.2"/><vers num="9.0.1.5"/><vers num="9.2.0.8"/></prod></vuln_soft></entry><entry CVSS_base_score="6.0" CVSS_exploit_subscore="6.8" CVSS_impact_subscore="6.4" CVSS_score="6.0" CVSS_vector="(AV:N/AC:M/Au:S/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-08-02" name="CVE-2007-2109" published="2007-04-18" seq="2007-2109" severity="Medium" type="CVE"><desc><descript source="cve">Multiple unspecified vulnerabilities in Oracle Database 10.2.0.3 have unknown impact and remote authenticated attack vectors related to (1) Rules Manager and Expression Filter components (DB02) and (2) Oracle Streams (DB06).  Note: as of 20070424, Oracle has not disputed reliable claims that DB02 is for a race condition in the RLMGR_TRUNCATE_MAINT trigger in the Rules Manager and Expression Filter components changing the AUTHID of a package from DEFINER to CURRENT_USER after a TRUNCATE call, and DB06 is for SQL injection in the DBMS_APPLY_USER_AGENT.SET_REGISTRATION_HANDLER procedure, which is later passed to the DBMS_APPLY_ADM_INTERNAL.ALTER_APPLY procedure, aka &quot;Oracle Streams&quot;.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input/><race/></vuln_types><range><network/></range><refs><ref patch="1" source="" url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpuapr2007.html"></ref><ref source="" url="http://www.integrigy.com/security-resources/analysis/Integrigy_Oracle_CPU_April_2007_Analysis.pdf"></ref><ref source="" url="http://www.ngssoftware.com/research/papers/NGSSoftware-OracleCPUAPR2007.pdf"></ref><ref source="" url="http://www.red-database-security.com/advisory/oracle_cpu_apr_2007.html"></ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1426">ADV-2007-1426</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017927">1017927</ref><ref source="HP" url="http://www.securityfocus.com/archive/1/archive/1/466329/100/200/threaded">HPSBMA02133</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA07-108A.html">TA07-108A</ref><ref source="BID" url="http://www.securityfocus.com/bid/23532">23532</ref></refs><vuln_soft><prod name="Oracle Database" vendor="Oracle"><vers num="10.2.0.3"/></prod></vuln_soft></entry><entry CVSS_base_score="4.4" CVSS_exploit_subscore="3.4" CVSS_impact_subscore="6.4" CVSS_score="4.4" CVSS_vector="(AV:L/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-08-02" name="CVE-2007-2110" published="2007-04-18" seq="2007-2110" severity="Medium" type="CVE"><desc><descript source="cve">Unspecified vulnerability in the Core RDBMS component for Oracle Database 9.0.1.5 and 10.1.0.4 on Windows systems has unknown impact and attack vectors, aka DB03.  NOTE: as of 20070424, Oracle has not disputed reliable claims that DB03 occurs because RDBMS uses a NULL Discretionary Access Control List (DACL) for the Oracle process and certain shared memory sections, which allows local users to inject threads and execute arbitrary code via the OpenProcess, OpenThread, and SetThreadContext functions (DB03).</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref patch="1" source="" url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpuapr2007.html"></ref><ref source="MLIST" url="http://www.freelists.org/archives/oracle-l/12-2006/msg00004.html">[oracle-l] 20061201 Re: Oracle 9i on Windows 2003 -- Vulnerability Question</ref><ref source="" url="http://www.integrigy.com/security-resources/analysis/Integrigy_Oracle_CPU_April_2007_Analysis.pdf"></ref><ref source="" url="http://www.ngssoftware.com/research/papers/NGSSoftware-OracleCPUAPR2007.pdf"></ref><ref source="" url="http://www.red-database-security.com/advisory/oracle_cpu_apr_2007.html"></ref><ref source="" url="https://www.blackhat.com/presentations/bh-dc-07/Cerrudo/Presentation/bh-dc-07-Cerrudo-ppt.pdf"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1426">ADV-2007-1426</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017927">1017927</ref><ref source="HP" url="http://www.securityfocus.com/archive/1/archive/1/466329/100/200/threaded">HPSBMA02133</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA07-108A.html">TA07-108A</ref><ref source="BID" url="http://www.securityfocus.com/bid/23532">23532</ref></refs><vuln_soft><prod name="Oracle Database" vendor="Oracle"><vers num="10.1.0.4"/><vers num="9.0.1.5"/></prod></vuln_soft></entry><entry CVSS_base_score="6.5" CVSS_exploit_subscore="8.0" CVSS_impact_subscore="6.4" CVSS_score="6.5" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-08-02" name="CVE-2007-2111" published="2007-04-18" seq="2007-2111" severity="Medium" type="CVE"><desc><descript source="cve">SQL injection vulnerability in the SYS.DBMS_AQADM_SYS package in Oracle Database 9.0.1.5, 9.2.0.7, and 10.1.0.5 allows remote authenticated users to inject arbitrary SQL commands via unknown vectors, aka DB04.  NOTE: as of 20070424, Oracle has not disputed reliable claims that DB04 is actually for multiple vulnerabilities.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><range><network/></range><refs><ref patch="1" source="" url="http://www.red-database-security.com/advisory/oracle_sql_injection_dbms_aqadm_sys.html"></ref><ref patch="1" source="" url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpuapr2007.html"></ref><ref source="" url="http://www.integrigy.com/security-resources/analysis/Integrigy_Oracle_CPU_April_2007_Analysis.pdf"></ref><ref source="" url="http://www.ngssoftware.com/research/papers/NGSSoftware-OracleCPUAPR2007.pdf"></ref><ref source="" url="http://www.red-database-security.com/advisory/oracle_cpu_apr_2007.html"></ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1426">ADV-2007-1426</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017927">1017927</ref><ref source="HP" url="http://www.securityfocus.com/archive/1/archive/1/466329/100/200/threaded">HPSBMA02133</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA07-108A.html">TA07-108A</ref><ref source="BID" url="http://www.securityfocus.com/bid/23532">23532</ref></refs><vuln_soft><prod name="Oracle Database" vendor="Oracle"><vers num="10.1.0.5"/><vers num="9.0.1.5"/><vers num="9.2.0.7"/></prod></vuln_soft></entry><entry CVSS_base_score="6.0" CVSS_exploit_subscore="6.8" CVSS_impact_subscore="6.4" CVSS_score="6.0" CVSS_vector="(AV:N/AC:M/Au:S/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-08-02" name="CVE-2007-2112" published="2007-04-18" seq="2007-2112" severity="Medium" type="CVE"><desc><descript source="cve">Unspecified vulnerability in the Authentication component for Oracle Database 10.1.0.5 and 10.2.0.3 has unknown impact and attack vectors, aka DB05.  NOTE: as of 20070424, Oracle has not disputed reliable claims that this issue allows remote authenticated users to bypass the AUTH_ALTER_SESSION security policies via a logon trigger (&quot;AFTER LOGON ON DATABASE&quot; trigger directive), a related issue to CVE-2006-0547.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref patch="1" source="" url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpuapr2007.html"></ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/466151/100/0/threaded">20070418 Advisory: Bypass Oracle Logon Trigger</ref><ref source="" url="http://www.integrigy.com/security-resources/analysis/Integrigy_Oracle_CPU_April_2007_Analysis.pdf"></ref><ref source="" url="http://www.ngssoftware.com/research/papers/NGSSoftware-OracleCPUAPR2007.pdf"></ref><ref source="" url="http://www.red-database-security.com/advisory/bypass_oracle_logon_trigger.html"></ref><ref source="" url="http://www.red-database-security.com/advisory/oracle_cpu_apr_2007.html"></ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1426">ADV-2007-1426</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017927">1017927</ref><ref source="HP" url="http://www.securityfocus.com/archive/1/archive/1/466329/100/200/threaded">HPSBMA02133</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA07-108A.html">TA07-108A</ref><ref source="BID" url="http://www.securityfocus.com/bid/23532">23532</ref></refs><vuln_soft><prod name="Oracle Database" vendor="Oracle"><vers num="10.1.0.5"/><vers num="10.2.0.3"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-08-02" name="CVE-2007-2113" published="2007-04-18" seq="2007-2113" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in the Upgrade/Downgrade component (DBMS_UPGRADE_INTERNAL) for Oracle Database 10.1.0.5 allows remote authenticated users to execute arbitrary SQL commands via unknown vectors, aka DB07.  NOTE: as of 20070424, Oracle has not disputed reliable claims that DB07 is actually for multiple issues.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><range><network/></range><refs><ref patch="1" source="" url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpuapr2007.html"></ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/466153/100/0/threaded">20070418 Advisory: SQL Injection in package SYS.DBMS_UPGRADE_INTERNAL</ref><ref source="" url="http://www.integrigy.com/security-resources/analysis/Integrigy_Oracle_CPU_April_2007_Analysis.pdf"></ref><ref source="" url="http://www.ngssoftware.com/research/papers/NGSSoftware-OracleCPUAPR2007.pdf"></ref><ref source="" url="http://www.red-database-security.com/advisory/oracle_cpu_apr_2007.html"></ref><ref source="" url="http://www.red-database-security.com/advisory/oracle_sql_injection_dbms_upgrade_internal.html"></ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1426">ADV-2007-1426</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017927">1017927</ref><ref source="HP" url="http://www.securityfocus.com/archive/1/archive/1/466329/100/200/threaded">HPSBMA02133</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA07-108A.html">TA07-108A</ref><ref source="BID" url="http://www.securityfocus.com/bid/23532">23532</ref></refs><vuln_soft><prod name="Oracle Database" vendor="Oracle"><vers num="10.1.0.5"/></prod></vuln_soft></entry><entry CVSS_base_score="9.0" CVSS_exploit_subscore="8.0" CVSS_impact_subscore="10.0" CVSS_score="9.0" CVSS_vector="(AV:N/AC:L/Au:S/C:C/I:C/A:C)" CVSS_version="2.0" modified="2008-06-25" name="CVE-2007-2114" published="2007-04-18" seq="2007-2114" severity="High" type="CVE"><desc><descript source="cve">Multiple unspecified vulnerabilities in Oracle Database 10.1.0.5 and 10.2.0.2 have unknown impact and remote authenticated attack vectors, related to (1) Change Data Capture (CDC), aka DB08, and (2) Oracle Instant Client, aka DB11.  NOTE: as of 20070424, oracle has not disputed reliable claims that these issues are buffer overflows using a long CHANGE_TABLE_NAME parameter to the DBMS_CDC_IPUBLISH.CHGTAB_CACHE procedure (DB08) and Oracle Instant Client genezi utility (DB11).</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><range><network/></range><refs><ref patch="1" source="" url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpuapr2007.html"></ref><ref source="" url="http://www.integrigy.com/security-resources/analysis/Integrigy_Oracle_CPU_April_2007_Analysis.pdf"></ref><ref source="" url="http://www.ngssoftware.com/research/papers/NGSSoftware-OracleCPUAPR2007.pdf"></ref><ref source="" url="http://www.red-database-security.com/advisory/oracle_cpu_apr_2007.html"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1426">ADV-2007-1426</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017927">1017927</ref><ref source="HP" url="http://www.securityfocus.com/archive/1/archive/1/466329/100/200/threaded">HPSBMA02133</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA07-108A.html">TA07-108A</ref><ref source="BID" url="http://www.securityfocus.com/bid/23532">23532</ref></refs><vuln_soft><prod name="Oracle Database" vendor="Oracle"><vers num="10.1.0.5"/><vers num="10.2.0.2"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-08-02" name="CVE-2007-2115" published="2007-04-18" seq="2007-2115" severity="Medium" type="CVE"><desc><descript source="cve">Unspecified vulnerability in the Change Data Capture (CDC) component in Oracle Database 9.2.0.7, 10.1.0.5, and 10.2.0.2 has unknown impact and attack vectors, aka DB09.  NOTE: as of 20070424, oracle has not disputed reliable claims that this issue involves multiple SQL injection vulnerabilities in the DBMS_CDC_PUBLISH with remote authenticated vectors involving the &quot;java classes in CDC.jar.&quot;</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref patch="1" source="" url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpuapr2007.html"></ref><ref source="" url="http://www.databasesecurity.com/oracle/OracleOct2006-CPU-Analysis.pdf"></ref><ref source="" url="http://www.integrigy.com/security-resources/analysis/Integrigy_Oracle_CPU_April_2007_Analysis.pdf"></ref><ref source="" url="http://www.ngssoftware.com/research/papers/NGSSoftware-OracleCPUAPR2007.pdf"></ref><ref source="" url="http://www.red-database-security.com/advisory/oracle_cpu_apr_2007.html"></ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1426">ADV-2007-1426</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017927">1017927</ref><ref source="HP" url="http://www.securityfocus.com/archive/1/archive/1/466329/100/200/threaded">HPSBMA02133</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA07-108A.html">TA07-108A</ref><ref source="BID" url="http://www.securityfocus.com/bid/23532">23532</ref></refs><vuln_soft><prod name="Oracle Database" vendor="Oracle"><vers num="10.1.0.5"/><vers num="10.2.0.2"/><vers num="9.2.0.7"/></prod></vuln_soft></entry><entry CVSS_base_score="9.0" CVSS_exploit_subscore="8.0" CVSS_impact_subscore="10.0" CVSS_score="9.0" CVSS_vector="(AV:N/AC:L/Au:S/C:C/I:C/A:C)" CVSS_version="2.0" modified="2008-06-25" name="CVE-2007-2116" published="2007-04-18" seq="2007-2116" severity="High" type="CVE"><desc><descript source="cve">Unspecified vulnerability in the Advanced Replication component in Oracle Database 9.0.1.5, 9.2.0.7, and 10.2.0.1 has unknown impact and attack vectors, aka DB10.  NOTE: as of 20070424, Oracle has not disputed claims that these are buffer overflows in kkzi.o for the SYS.DBMS_SNAP_INTERNAL package using the (1) SNAP_OWNER or (2) SNAP_NAME parameters.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><range><network/></range><refs><ref patch="1" source="" url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpuapr2007.html"></ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/466173/100/0/threaded">20070418 Oracle Database Buffer overflow vulnerabilities in package DBMS_SNAP_INTERNAL</ref><ref source="" url="http://www.appsecinc.com/resources/alerts/oracle/2007-07.shtml"></ref><ref source="" url="http://www.integrigy.com/security-resources/analysis/Integrigy_Oracle_CPU_April_2007_Analysis.pdf"></ref><ref source="" url="http://www.ngssoftware.com/research/papers/NGSSoftware-OracleCPUAPR2007.pdf"></ref><ref source="" url="http://www.red-database-security.com/advisory/oracle_cpu_apr_2007.html"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1426">ADV-2007-1426</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017927">1017927</ref><ref source="HP" url="http://www.securityfocus.com/archive/1/archive/1/466329/100/200/threaded">HPSBMA02133</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA07-108A.html">TA07-108A</ref><ref source="BID" url="http://www.securityfocus.com/bid/23532">23532</ref></refs><vuln_soft><prod name="Oracle Database" vendor="Oracle"><vers num="10.2.0.1"/><vers num="9.0.1.5"/><vers num="9.2.0.7"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="3.1" CVSS_impact_subscore="10.0" CVSS_score="6.8" CVSS_vector="(AV:L/AC:L/Au:S/C:C/I:C/A:C)" CVSS_version="2.0" modified="2008-06-25" name="CVE-2007-2117" published="2007-04-18" seq="2007-2117" severity="Medium" type="CVE"><desc><descript source="cve">Unspecified vulnerability in the Oracle Text component in Oracle Database 9.2.0.5 has unknown impact and attack vectors, aka DB12. NOTE: as of 20070424, Oracle has not disputed reliable claims that this involves a buffer overflow in the ctxsrv server daemon.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><range><local/></range><refs><ref patch="1" source="" url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpuapr2007.html"></ref><ref source="" url="http://www.integrigy.com/security-resources/analysis/Integrigy_Oracle_CPU_April_2007_Analysis.pdf"></ref><ref source="" url="http://www.ngssoftware.com/research/papers/NGSSoftware-OracleCPUAPR2007.pdf"></ref><ref source="" url="http://www.red-database-security.com/advisory/oracle_cpu_apr_2007.html"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1426">ADV-2007-1426</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017927">1017927</ref><ref source="HP" url="http://www.securityfocus.com/archive/1/archive/1/466329/100/200/threaded">HPSBMA02133</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA07-108A.html">TA07-108A</ref><ref source="BID" url="http://www.securityfocus.com/bid/23532">23532</ref></refs><vuln_soft><prod name="Oracle Database" vendor="Oracle"><vers num="9.2.0.5"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-08-02" name="CVE-2007-2118" published="2007-04-18" seq="2007-2118" severity="High" type="CVE"><desc><descript source="cve">Unspecified vulnerability in the Upgrade/Downgrade component of Oracle Database 9.0.1.5 and 9.2.0.7 has unknown impact and attack vectors, aka DB13.  NOTE: as of 20070424, Oracle has not disputed reliable claims that this is a buffer overflow involving the &quot;mig utility.&quot;</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref patch="1" source="" url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpuapr2007.html"></ref><ref source="" url="http://www.integrigy.com/security-resources/analysis/Integrigy_Oracle_CPU_April_2007_Analysis.pdf"></ref><ref source="" url="http://www.ngssoftware.com/research/papers/NGSSoftware-OracleCPUAPR2007.pdf"></ref><ref source="" url="http://www.red-database-security.com/advisory/oracle_cpu_apr_2007.html"></ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1426">ADV-2007-1426</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017927">1017927</ref><ref source="HP" url="http://www.securityfocus.com/archive/1/archive/1/466329/100/200/threaded">HPSBMA02133</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA07-108A.html">TA07-108A</ref><ref source="BID" url="http://www.securityfocus.com/bid/23532">23532</ref></refs><vuln_soft><prod name="Oracle Database" vendor="Oracle"><vers num="9.0.1.5"/><vers num="9.2.0.7"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-04-18" name="CVE-2007-2119" published="2007-04-18" seq="2007-2119" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in boundary_rules.jsp in the Administration Front End for Oracle Enterprise (Ultra) Search, as used in Database Server 9.2.0.8, 10.1.0.5, and 10.2.0.2, and in Application Server 9.0.4.3, 10.1.2.0.2, and 10.1.2.2.0 allows remote attackers to inject arbitrary HTML or web script via the EXPTYPE parameter, aka SES01.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://www.red-database-security.com/advisory/oracle_css_ses.html"></ref><ref patch="1" source="" url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpuapr2007.html"></ref><ref source="" url="http://www.red-database-security.com/advisory/oracle_cpu_apr_2007.html"></ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1426">
ADV-2007-1426</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017927">
1017927</ref><ref source="HP" url="http://www.securityfocus.com/archive/1/archive/1/466329/100/200/threaded">
HPSBMA02133</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/466156/100/0/threaded">

20070418 Advisory: XSS Vulnerability in Oracle Secure Enterprise Search [SES01]</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA07-108A.html">TA07-108A</ref><ref source="BID" url="http://www.securityfocus.com/bid/23532">23532</ref></refs><vuln_soft><prod name="Oracle Database" vendor="Oracle"><vers num="10.1.0.5"/><vers num="10.2.0.2"/><vers num="9.2.0.8"/></prod><prod name="Oracle Application Server" vendor="Oracle"><vers num="10.1.2.0.2"/><vers num="10.1.2.2"/><vers num="9.0.4.3"/></prod></vuln_soft></entry><entry CVSS_base_score="7.8" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.9" CVSS_score="7.8" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_version="2.0" modified="2007-08-02" name="CVE-2007-2120" published="2007-04-18" seq="2007-2120" severity="High" type="CVE"><desc><descript source="cve">The Oracle Discoverer servlet in Oracle Application Server 9.0.4.3, 10.1.2.0.2, and 10.1.2.2.0 allows remote attackers to shut down an Oracle TNS Listener via a TNS STOP commmand in a request that uses the database/TNS alias, aka AS01.</descript></desc><loss_types><avail/></loss_types><range><network/></range><refs><ref source="" url="http://www.red-database-security.com/advisory/oracle_discoverer_servlet.html"></ref><ref patch="1" source="" url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpuapr2007.html"></ref><ref source="" url="http://www.red-database-security.com/advisory/oracle_cpu_apr_2007.html"></ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1426">ADV-2007-1426</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017927">1017927</ref><ref source="HP" url="http://www.securityfocus.com/archive/1/archive/1/466329/100/200/threaded">HPSBMA02133</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/466160/100/0/threaded">20070418 Advisory: Shutdown unprotected Oracle TNS Listener via Oracle Discoverer Servlet [AS01]</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA07-108A.html">TA07-108A</ref><ref source="BID" url="http://www.securityfocus.com/bid/23532">23532</ref></refs><vuln_soft><prod name="Oracle Application Server" vendor="Oracle"><vers num="10.1.2.0.2"/><vers num="10.1.2.2"/><vers num="9.0.4.3"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-04-18" name="CVE-2007-2121" published="2007-04-18" seq="2007-2121" severity="High" type="CVE"><desc><descript source="cve">Unspecified vulnerability in the COREid Access component in Oracle Application Server 7.0.4.4 has unknown impact and attack vectors, aka AS02.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs><ref patch="1" source="" url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpuapr2007.html"></ref><ref source="" url="http://www.red-database-security.com/advisory/oracle_cpu_apr_2007.html"></ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1426">
ADV-2007-1426</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017927">
1017927</ref><ref source="HP" url="http://www.securityfocus.com/archive/1/archive/1/466329/100/200/threaded">
HPSBMA02133</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA07-108A.html">TA07-108A</ref><ref source="BID" url="http://www.securityfocus.com/bid/23532">23532</ref></refs><vuln_soft><prod name="Oracle Application Server" vendor="Oracle"><vers num="7.0.4.4"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-04-18" name="CVE-2007-2122" published="2007-04-18" seq="2007-2122" severity="High" type="CVE"><desc><descript source="cve">Unspecified vulnerability in the Wireless component in Oracle Application Server 9.0.4.3 has unknown impact and attack vectors, aka AS03.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs><ref patch="1" source="" url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpuapr2007.html"></ref><ref source="" url="http://www.red-database-security.com/advisory/oracle_cpu_apr_2007.html"></ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1426">
ADV-2007-1426</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017927">
1017927</ref><ref source="HP" url="http://www.securityfocus.com/archive/1/archive/1/466329/100/200/threaded">
HPSBMA02133</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA07-108A.html">TA07-108A</ref><ref source="BID" url="http://www.securityfocus.com/bid/23532">23532</ref></refs><vuln_soft><prod name="Oracle Application Server" vendor="Oracle"><vers num="9.0.4.3"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-04-18" name="CVE-2007-2123" published="2007-04-18" seq="2007-2123" severity="High" type="CVE"><desc><descript source="cve">Unspecified vulnerability in the Portal component in Oracle Application Server 10.1.3 up to 10.1.3.2.0, 10.1.2 up to 10.1.2.2.0, and 9.0.4.3 has unknown impact and attack vectors, aka AS04.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs><ref patch="1" source="" url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpuapr2007.html"></ref><ref source="" url="http://www.red-database-security.com/advisory/oracle_cpu_apr_2007.html"></ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1426">
ADV-2007-1426</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017927">
1017927</ref><ref source="HP" url="http://www.securityfocus.com/archive/1/archive/1/466329/100/200/threaded">
HPSBMA02133</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA07-108A.html">TA07-108A</ref><ref source="BID" url="http://www.securityfocus.com/bid/23532">23532</ref></refs><vuln_soft><prod name="Oracle Application Server" vendor="Oracle"><vers num="10.1.2.0.0"/><vers num="10.1.2.0.2"/><vers num="10.1.2.2"/><vers num="10.1.3.0"/><vers num="10.1.3.2.0"/><vers num="9.0.4.3"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-04-18" name="CVE-2007-2124" published="2007-04-18" seq="2007-2124" severity="High" type="CVE"><desc><descript source="cve">Unspecified vulnerability in the Portal component in Oracle Application Server 10.1.4.1.0 has unknown impact and remote attack vectors, aka AS05.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs><ref patch="1" source="" url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpuapr2007.html"></ref><ref source="" url="http://www.red-database-security.com/advisory/oracle_cpu_apr_2007.html"></ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1426">
ADV-2007-1426</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017927">
1017927</ref><ref source="HP" url="http://www.securityfocus.com/archive/1/archive/1/466329/100/200/threaded">
HPSBMA02133</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA07-108A.html">TA07-108A</ref><ref source="BID" url="http://www.securityfocus.com/bid/23532">23532</ref></refs><vuln_soft><prod name="Oracle Application Server" vendor="Oracle"><vers num="10.1.4.1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-04-18" name="CVE-2007-2125" published="2007-04-18" seq="2007-2125" severity="High" type="CVE"><desc><descript source="cve">Unspecified vulnerability in Collaborative Workspace in Oracle Collaboration Suite 10.1.2 has unknown impact and attack vectors, aka OCS01.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs><ref patch="1" source="" url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpuapr2007.html"></ref><ref source="" url="http://www.red-database-security.com/advisory/oracle_cpu_apr_2007.html"></ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1426">
ADV-2007-1426</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017927">
1017927</ref><ref source="HP" url="http://www.securityfocus.com/archive/1/archive/1/466329/100/200/threaded">
HPSBMA02133</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA07-108A.html">TA07-108A</ref><ref source="BID" url="http://www.securityfocus.com/bid/23532">23532</ref></refs><vuln_soft><prod name="Collaboration Suite" vendor="Oracle"><vers num="10.1.2"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-04-18" name="CVE-2007-2126" published="2007-04-18" seq="2007-2126" severity="High" type="CVE"><desc><descript source="cve">Unspecified vulnerability in Oracle E-Business Suite 11.5.10CU2 has unknown impact and remote attack vectors in the (1) Common Applications (APPS01) and (2) iProcurement (APPS02).</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs><ref patch="1" source="" url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpuapr2007.html"></ref><ref source="" url="http://www.integrigy.com/security-resources/analysis/Integrigy_Oracle_CPU_April_2007_Analysis.pdf"></ref><ref source="" url="http://www.red-database-security.com/advisory/oracle_cpu_apr_2007.html"></ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1426">
ADV-2007-1426</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017927">
1017927</ref><ref source="HP" url="http://www.securityfocus.com/archive/1/archive/1/466329/100/200/threaded">
HPSBMA02133</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA07-108A.html">TA07-108A</ref><ref source="BID" url="http://www.securityfocus.com/bid/23532">23532</ref></refs><vuln_soft><prod name="E-Business Suite" vendor="Oracle"><vers num="11i 11.5.10 CU2"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2008-06-25" name="CVE-2007-2127" published="2007-04-18" seq="2007-2127" severity="High" type="CVE"><desc><descript source="cve">Multiple unspecified vulnerabilities in Oracle E-Business Suite 12.0.0 have unknown impact and remote attack vectors via (1) Application Object Library (APPS04), iStore (2) APPS05 and (3) APPS06, (4) iSupport (APPS07), (5) Trade Management (APPS09), (6) Applications Manager (APPS10), and (7) Oracle Report Manager (APPS03).</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><other/></vuln_types><range><network/></range><refs><ref patch="1" source="" url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpuapr2007.html"></ref><ref source="" url="http://www.integrigy.com/security-resources/analysis/Integrigy_Oracle_CPU_April_2007_Analysis.pdf"></ref><ref source="" url="http://www.red-database-security.com/advisory/oracle_cpu_apr_2007.html"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1426">ADV-2007-1426</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017927">1017927</ref><ref source="HP" url="http://www.securityfocus.com/archive/1/archive/1/466329/100/200/threaded">HPSBMA02133</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA07-108A.html">TA07-108A</ref><ref source="BID" url="http://www.securityfocus.com/bid/23532">23532</ref></refs><vuln_soft><prod name="E-Business Suite" vendor="Oracle"><vers num="12.0.0"/></prod></vuln_soft></entry><entry CVSS_base_score="9.0" CVSS_exploit_subscore="8.0" CVSS_impact_subscore="10.0" CVSS_score="9.0" CVSS_vector="(AV:N/AC:L/Au:S/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-04-18" name="CVE-2007-2128" published="2007-04-18" seq="2007-2128" severity="High" type="CVE"><desc><descript source="cve">Unspecified vulnerability in the Sales Online component for Oracle E-Business Suite 11.5.10 has unknown impact and remote authenticated attack vectors, aka APPS08.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs><ref patch="1" source="" url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpuapr2007.html"></ref><ref source="" url="http://www.integrigy.com/security-resources/analysis/Integrigy_Oracle_CPU_April_2007_Analysis.pdf"></ref><ref source="" url="http://www.red-database-security.com/advisory/oracle_cpu_apr_2007.html"></ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1426">
ADV-2007-1426</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017927">
1017927</ref><ref source="HP" url="http://www.securityfocus.com/archive/1/archive/1/466329/100/200/threaded">
HPSBMA02133</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA07-108A.html">TA07-108A</ref><ref source="BID" url="http://www.securityfocus.com/bid/23532">23532</ref></refs><vuln_soft><prod name="E-Business Suite" vendor="Oracle"><vers num="11i 11.5.10"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-04-18" name="CVE-2007-2129" published="2007-04-18" seq="2007-2129" severity="High" type="CVE"><desc><descript source="cve">Unspecified vulnerability in the Agent component in Oracle Enterprise Manager 9.2.0.8 has unknown impact and remote attack vectors, aka EM01.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs><ref patch="1" source="" url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpuapr2007.html"></ref><ref source="" url="http://www.red-database-security.com/advisory/oracle_cpu_apr_2007.html"></ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1426">
ADV-2007-1426</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017927">
1017927</ref><ref source="HP" url="http://www.securityfocus.com/archive/1/archive/1/466329/100/200/threaded">
HPSBMA02133</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA07-108A.html">TA07-108A</ref><ref source="BID" url="http://www.securityfocus.com/bid/23532">23532</ref></refs><vuln_soft><prod name="Enterprise Manager" vendor="Oracle"><vers num="9.2.0.8"/></prod></vuln_soft></entry><entry CVSS_base_score="9.0" CVSS_exploit_subscore="8.0" CVSS_impact_subscore="10.0" CVSS_score="9.0" CVSS_vector="(AV:N/AC:L/Au:S/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-04-18" name="CVE-2007-2130" published="2007-04-18" seq="2007-2130" severity="High" type="CVE"><desc><descript source="cve">Unspecified vulnerability in Workflow Cartridge, as used in Oracle Database Server 9.2.0.1, 10.1.0.2, and 10.2.0.1; Application Server 9.0.4.3 and 10.1.2.0.2; Collaboration Suite 10.1.2; and E-Business Suite; has unknown impact and remote authenticated attack vectors, aka OWF01.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs><ref patch="1" source="" url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpuapr2007.html"></ref><ref source="" url="http://www.integrigy.com/security-resources/analysis/Integrigy_Oracle_CPU_April_2007_Analysis.pdf"></ref><ref source="" url="http://www.red-database-security.com/advisory/oracle_cpu_apr_2007.html"></ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1426">
ADV-2007-1426</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017927">
1017927</ref><ref source="HP" url="http://www.securityfocus.com/archive/1/archive/1/466329/100/200/threaded">
HPSBMA02133</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA07-108A.html">TA07-108A</ref><ref source="BID" url="http://www.securityfocus.com/bid/23532">23532</ref></refs><vuln_soft><prod name="Oracle Database Server" vendor="Oracle"><vers num="10.1.0.2"/><vers num="10.2.0.1"/><vers num="9.2.0.1"/></prod><prod name="Oracle Application Server" vendor="Oracle"><vers num="10.1.2.0.2"/><vers num="9.0.4.3"/></prod><prod name="E-Business Suite" vendor="Oracle"><vers num=""/></prod><prod name="Collaboration Suite" vendor="Oracle"><vers num="10.1.2"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-04-18" name="CVE-2007-2131" published="2007-04-18" seq="2007-2131" severity="High" type="CVE"><desc><descript source="cve">Unspecified vulnerability in PeopleTools in Oracle PeopleSoft Enterprise 8.22.14, 8.47.12, and 8.48.08 has unknown impact and attack vectors, aka PSE01.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs><ref patch="1" source="" url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpuapr2007.html"></ref><ref source="" url="http://www.red-database-security.com/advisory/oracle_cpu_apr_2007.html"></ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1426">
ADV-2007-1426</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017927">
1017927</ref><ref source="HP" url="http://www.securityfocus.com/archive/1/archive/1/466329/100/200/threaded">
HPSBMA02133</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA07-108A.html">TA07-108A</ref><ref source="BID" url="http://www.securityfocus.com/bid/23532">23532</ref></refs><vuln_soft><prod name="PeopleSoft Enterprise" vendor="Oracle"><vers num="8.22.14"/><vers num="8.47.12"/><vers num="8.48.08"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-04-18" name="CVE-2007-2132" published="2007-04-18" seq="2007-2132" severity="High" type="CVE"><desc><descript source="cve">Unspecified vulnerability in the PeopleTools component in Oracle PeopleSoft Enterprise 8.47.12 and 8.48.08 has unknown impact and attack vectors, aka PSE02.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs><ref patch="1" source="" url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpuapr2007.html"></ref><ref source="" url="http://www.red-database-security.com/advisory/oracle_cpu_apr_2007.html"></ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1426">
ADV-2007-1426</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017927">
1017927</ref><ref source="HP" url="http://www.securityfocus.com/archive/1/archive/1/466329/100/200/threaded">
HPSBMA02133</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA07-108A.html">TA07-108A</ref><ref source="BID" url="http://www.securityfocus.com/bid/23532">23532</ref></refs><vuln_soft><prod name="PeopleSoft Enterprise" vendor="Oracle"><vers num="8.47.12"/><vers num="8.48.08"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-04-18" name="CVE-2007-2133" published="2007-04-18" seq="2007-2133" severity="High" type="CVE"><desc><descript source="cve">Unspecified vulnerability in the PeopleSoft Enterprise Human Capital Management component in Oracle PeopleSoft Enterprise 8.9 has unknown impact and attack vectors, aka PSEHCM01.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs><ref patch="1" source="" url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpuapr2007.html"></ref><ref source="" url="http://www.red-database-security.com/advisory/oracle_cpu_apr_2007.html"></ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1426">
ADV-2007-1426</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017927">
1017927</ref><ref source="HP" url="http://www.securityfocus.com/archive/1/archive/1/466329/100/200/threaded">
HPSBMA02133</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA07-108A.html">TA07-108A</ref><ref source="BID" url="http://www.securityfocus.com/bid/23532">23532</ref></refs><vuln_soft><prod name="PeopleSoft Enterprise" vendor="Oracle"><vers num="8.9"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-04-19" name="CVE-2007-2134" published="2007-04-18" seq="2007-2134" severity="High" type="CVE"><desc><descript source="cve">Unspecified vulnerability in the HTML Server in Oracle JD Edwards EnterpriseOne SP23_Q1 and 8.96.I1 has unknown impact and local attack vectors, aka JDE01.</descript></desc><sols><sol source="nvd">The vendor has addressed this issue through the release of the following patch information: http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpuapr2007.html</sol></sols><loss_types><avail/><conf/><int/></loss_types><range><local/></range><refs><ref patch="1" source="" url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpuapr2007.html"></ref><ref source="" url="http://www.red-database-security.com/advisory/oracle_cpu_apr_2007.html"></ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1426">
ADV-2007-1426</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017927">
1017927</ref><ref source="HP" url="http://www.securityfocus.com/archive/1/archive/1/466329/100/200/threaded">
HPSBMA02133</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA07-108A.html">TA07-108A</ref><ref source="BID" url="http://www.securityfocus.com/bid/23532">23532</ref></refs><vuln_soft><prod name="JD Edwards EnterpriseOne" vendor="Oracle"><vers num="8.96.11"/><vers num="SP23_Q1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.8" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.9" CVSS_score="7.8" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:N/A:N)" CVSS_version="2.0" modified="2007-04-25" name="CVE-2007-2135" published="2007-04-24" seq="2007-2135" severity="High" type="CVE"><desc><descript source="cve">The ADI_BINARY component in the Oracle E-Business Suite allows remote attackers to download arbitrary documents from the APPS.FND_DOCUMENTS table via the ADI_DISPLAY_REPORT function, when passed a certain parameter.  NOTE: due to lack of details from Oracle, it is not clear whether this issue is related to other CVE identifiers such as CVE-2007-2126, CVE-2007-2127, or CVE-2007-2128.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref patch="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/466215/100/0/threaded">20070418 ZDI-07-017: Oracle E-Business Suite Arbitrary Document Download Vulnerability</ref><ref patch="1" source="" url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpuapr2007.html"></ref><ref patch="1" source="" url="http://www.red-database-security.com/advisory/oracle_cpu_apr_2007.html"></ref><ref patch="1" source="" url="http://www.zerodayinitiative.com/advisories/ZDI-07-017.html"></ref><ref source="SREASON" url="http://securityreason.com/securityalert/2612">2612</ref></refs><vuln_soft><prod name="E-Business Suite" vendor="Oracle"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-04-23" name="CVE-2007-2136" published="2007-04-22" seq="2007-2136" severity="High" type="CVE"><desc><descript source="cve">Stack-based buffer overflow in bgs_sdservice.exe in BMC Patrol PerformAgent allows remote attackers to execute arbitrary code by connecting to TCP port 10128 and sending certain XDR data, which is not properly parsed.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/466222/100/0/threaded">20070418 ZDI-07-019: BMC Patrol PerformAgent bgs_sdservice Memory Corruption Vulnerability</ref><ref adv="1" source="" url="http://www.zerodayinitiative.com/advisories/ZDI-07-019.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/23557">23557</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1457">ADV-2007-1457</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017934">
1017934</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24937">
24937</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33745">
bmcpatrol-bgssdservice-code-execution(33745)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2598">2598</ref></refs><vuln_soft><prod name="PerformAgent" vendor="BMC Software"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-04-23" name="CVE-2007-2137" published="2007-04-22" seq="2007-2137" severity="High" type="CVE"><desc><descript source="cve">Heap-based buffer overflow in kde.dll in IBM Tivoli Monitoring Express 6.1.0 before Fix Pack 2, as used in Tivoli Universal Agent, Windows OS Monitoring agent, and Enterprise Portal Server, allows remote attackers to execute arbitrary code by sending a long string to a certain TCP port.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/466216/100/0/threaded">20070418 ZDI-07-018: IBM Tivoli Monitoring Express Universal Agent Heap Overflow Vunlerability</ref><ref patch="1" source="" url="http://www-1.ibm.com/support/docview.wss?uid=swg24012341"></ref><ref adv="1" source="" url="http://www.zerodayinitiative.com/advisories/ZDI-07-018.html"></ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/23558">23558</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1456">ADV-2007-1456</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017933">
1017933</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24938">
24938</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33746">
tivoli-monitoring-multiple-bo(33746)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2597">2597</ref></refs><vuln_soft><prod name="Tivoli Monitoring Express" vendor="IBM"><vers num="6.1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="6.0" CVSS_exploit_subscore="6.8" CVSS_impact_subscore="6.4" CVSS_score="6.0" CVSS_vector="(AV:N/AC:M/Au:S/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-04-25" name="CVE-2007-2138" published="2007-04-24" seq="2007-2138" severity="Medium" type="CVE"><desc><descript source="cve">Untrusted search path vulnerability in PostgreSQL before 7.3.19, 7.4.x before 7.4.17, 8.0.x before 8.0.13, 8.1.x before 8.1.9, and 8.2.x before 8.2.4 allows remote authenticated users, when permitted to call a SECURITY DEFINER function, to gain the privileges of the function owner, related to &quot;search_path settings.&quot;</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="" url="http://www.postgresql.org/about/news.791"></ref><ref adv="1" patch="1" source="" url="http://www.postgresql.org/support/security.html"></ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/25019">25019</ref><ref source="" url="https://issues.rpath.com/browse/RPL-1292"></ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2007:094">
MDKSA-2007:094</ref><ref source="BID" url="http://www.securityfocus.com/bid/23618">
23618</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1497">
ADV-2007-1497</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25005">
25005</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24989">
24989</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33842">
postgresql-searchpath-privilege-escalation(33842)</ref><ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102894-1">
102894</ref><ref source="TRUSTIX" url="http://www.trustix.org/errata/2007/0015/">
2007-0015</ref><ref source="UBUNTU" url="http://www.ubuntu.com/usn/usn-454-1">
USN-454-1</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1549">
ADV-2007-1549</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017974">
1017974</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25037">
25037</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24999">
24999</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25058">
25058</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2007-0337.html">
RHSA-2007:0337</ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200705-12.xml">
GLSA-200705-12</ref><ref source="REDHAT" url="http://rhn.redhat.com/errata/RHSA-2007-0336.html">
RHSA-2007:0336</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25184">
25184</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25238">
25238</ref><ref source="" url="http://support.avaya.com/elmodocs2/security/ASA-2007-190.htm"></ref><ref source="DEBIAN" url="http://www.debian.org/security/2007/dsa-1309">DSA-1309</ref><ref source="DEBIAN" url="http://www.debian.org/security/2007/dsa-1311">DSA-1311</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:094">MDKSA-2007:094</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25334">25334</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25717">25717</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25725">25725</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25720">25720</ref></refs><vuln_soft><prod name="PostgreSQL" vendor="PostgreSQL"><vers num="7.3.18" prev="1"/><vers num="7.4.16" prev="1"/><vers num="8.0.10" prev="1"/><vers num="8.1.6" prev="1"/><vers num="8.2.1" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-04-26" name="CVE-2007-2139" published="2007-04-25" seq="2007-2139" severity="High" type="CVE"><desc><descript source="cve">Multiple stack-based buffer overflows in the SUN RPC service in CA (formerly Computer Associates) BrightStor ARCserve Media Server, as used in BrightStor ARCserve Backup 9.01 through 11.5 SP2, BrightStor Enterprise Backup 10.5, Server Protection Suite 2, and Business Protection Suite 2, allow remote attackers to execute arbitrary code via malformed RPC strings, a different vulnerability than CVE-2006-5171, CVE-2006-5172, and CVE-2007-1785.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/466790/100/0/threaded">20070424 ZDI-07-022: CA BrightStor ArcServe Media Server Multiple Buffer Overflow Vulnerabilities</ref><ref source="" url="http://www.zerodayinitiative.com/advisories/ZDI-07-022.html"></ref><ref source="" url="http://supportconnectw.ca.com/public/storage/infodocs/babmedser-secnotice.asp"></ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/23635">23635</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/979825">
VU#979825</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1529">
ADV-2007-1529</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24972">
24972</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33854">
brightstor-sun-rpc-bo(33854)</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017952">
1017952</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2628">2628</ref></refs><vuln_soft><prod name="BrightStor ARCServe Backup" vendor="Computer Associates"><vers num="11.1"/><vers num="11.5 SP2"/><vers edition="Windows" num="11"/><vers num="9.01"/></prod><prod name="Business Protection Suite" vendor="Computer Associates"><vers num="r2"/><vers edition="Microsoft SBS Standard" num="r2"/><vers edition="Microsoft SBS Premium" num="r2"/></prod><prod name="Server Protection Suite" vendor="Computer Associates"><vers num="r2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-04-19" name="CVE-2007-2140" published="2007-04-19" seq="2007-2140" severity="High" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in everything.php in Franklin Huang Flip (aka Flip-search-add-on) 2.0 allows remote attackers to execute arbitrary PHP code via a URL in the incpath parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/465738/100/0/threaded">20070414 Flip-search-add-on 2.0</ref><ref source="VIM" url="http://attrition.org/pipermail/vim/2007-May/001576.html">20070503 True: Flip-search-add-on everything.php incpath RFI</ref><ref source="OSVDB" url="http://www.osvdb.org/34147">34147</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33696">flip-search-incpath-file-include(33696)</ref></refs><vuln_soft><prod name="Flip-search-add-on" vendor="Franklin Huang"><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-04-19" name="CVE-2007-2141" published="2007-04-19" seq="2007-2141" severity="High" type="CVE"><desc><descript source="cve">Direct static code injection vulnerability in shoutbox.php in ShoutPro 1.5.2 allows remote attackers to inject arbitrary PHP code into shouts.php via the shout parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/466037/100/0/threaded">20070417 ShoutPro 1.5.2 - arbitrary code execution</ref><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3758">3758</ref><ref source="BID" url="http://www.securityfocus.com/bid/23542">23542</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1432">ADV-2007-1432</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24939">
24939</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33727">
shoutpro-shouts-code-execution(33727)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2593">2593</ref></refs><vuln_soft><prod name="ShoutPro" vendor="ShoutPro"><vers num="1.5.2" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-04-19" name="CVE-2007-2142" published="2007-04-19" seq="2007-2142" severity="High" type="CVE"><desc><descript source="cve">Multiple PHP remote file inclusion vulnerabilities in AjPortal2Php allow remote attackers to execute arbitrary PHP code via a URL in the PagePrefix parameter to (1) begin.inc.php, (2) connection.inc.php, (3) events.inc.php, (4) footer.inc.php, (5) header.inc.php, (6) menuleft.inc.php, or (7) pages.inc.php in includes/.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3752">3752</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1428">ADV-2007-1428</ref><ref source="BID" url="http://www.securityfocus.com/bid/23525">
23525</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33703">
ajportal2php-pageprefix-file-include(33703)</ref></refs><vuln_soft><prod name="AjPortal2Php" vendor="AjPortal2Php"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-04-19" name="CVE-2007-2143" published="2007-04-19" seq="2007-2143" severity="High" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in index.php in the Be2004-2 template for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3759">3759</ref><ref source="BID" url="http://www.securityfocus.com/bid/23549">
23549</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33728">
joomla-be20042-index-file-include(33728)</ref></refs><vuln_soft><prod name="Joomla Template Be2004-2" vendor="BonoEstente"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-10-01" name="CVE-2007-2144" published="2007-04-19" seq="2007-2144" severity="Medium" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in includes/CAltInstaller.php in the JoomlaPack (com_jpack) 1.0.4a2 RE component for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3753">3753</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1429">ADV-2007-1429</ref><ref source="BID" url="http://www.securityfocus.com/bid/23529">23529</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33702">joomlapack-caltinstaller-file-include(33702)</ref></refs><vuln_soft><prod name="JoomlaPack" vendor="JoomlaPack"><vers num="1.0.4a2 RE"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-04-19" name="CVE-2007-2145" published="2007-04-19" seq="2007-2145" severity="High" type="CVE"><desc><descript source="cve">The imagecomments function in classes.php in MiniGal b13 allows remote attackers to inject arbitrary PHP code into a file in the thumbs/ directory via the input parameter.  NOTE: some of these details are obtained from third party information.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3754">3754</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1430">ADV-2007-1430</ref></refs><vuln_soft><prod name="MiniGal" vendor="MiniGal"><vers num="B13"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-04-20" name="CVE-2007-2146" published="2007-04-19" seq="2007-2146" severity="High" type="CVE"><desc><descript source="cve">The imagecomments function in classes.php in MiniGal b13 allow remote attackers to inject arbitrary PHP code into a file in the thumbs/ directory via the (1) name or (2) email parameter.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1430">ADV-2007-1430</ref></refs><vuln_soft><prod name="MiniGal" vendor="MiniGal"><vers num="B13"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-04-20" name="CVE-2007-2147" published="2007-04-19" seq="2007-2147" severity="High" type="CVE"><desc><descript source="cve">admin/options.php in Stephen Craton (aka WiredPHP) Chatness 2.5.3 and earlier does not check for administrative credentials, which allows remote attackers to read and modify the classes/vars.php and classes/varstuff.php configuration files via direct requests.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/465547/100/0/threaded">20070412 Chatness &lt;= 2.5.3 - Arbitrary Code Execution</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1386">ADV-2007-1386</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24873">24873</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2595">2595</ref></refs><vuln_soft><prod name="Chatness" vendor="Stephen Craton"><vers num="2.5.3" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.5" CVSS_exploit_subscore="8.0" CVSS_impact_subscore="6.4" CVSS_score="6.5" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-04-20" name="CVE-2007-2148" published="2007-04-19" seq="2007-2148" severity="Medium" type="CVE"><desc><descript source="cve">Direct static code injection vulnerability in admin/save.php in Stephen Craton (aka WiredPHP) Chatness 2.5.3 and earlier allows remote authenticated administrators to inject PHP code into .html files via the html parameter, as demonstrated by head.html and foot.html, which are included and executed upon a direct request for index.php.  NOTE: a separate vulnerability could be leveraged to make this issue exploitable by remote unauthenticated attackers.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/465547/100/0/threaded">20070412 Chatness &lt;= 2.5.3 - Arbitrary Code Execution</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1386">ADV-2007-1386</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24873">24873</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2595">2595</ref></refs><vuln_soft><prod name="Chatness" vendor="Stephen Craton"><vers num="2.5.3" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-04-20" name="CVE-2007-2149" published="2007-04-19" seq="2007-2149" severity="High" type="CVE"><desc><descript source="cve">Stephen Craton (aka WiredPHP) Chatness 2.5.3 and earlier stores usernames and unencrypted passwords in (1) classes/vars.php and (2) classes/varstuff.php, and recommends 0666 or 0777 permissions for these files, which allows local users to gain privileges by reading the files, and allows remote attackers to obtain credentials via a direct request for admin/options.php.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/465547/100/0/threaded">20070412 Chatness &lt;= 2.5.3 - Arbitrary Code Execution</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1386">ADV-2007-1386</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24873">24873</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2595">2595</ref></refs><vuln_soft><prod name="Chatness" vendor="Stephen Craton"><vers num="2.5.3" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.8" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.9" CVSS_score="7.8" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:C/A:N)" CVSS_version="2.0" modified="2007-04-20" name="CVE-2007-2150" published="2007-04-19" seq="2007-2150" severity="High" type="CVE"><desc><descript source="cve">BlueArc-FTPD in BlueArc Titan 2x00 devices with firmware 4.2.944b allows remote attackers to redirect traffic to other sites (aka FTP bounce) via the PORT command, a variant of CVE-1999-0017.</descript></desc><loss_types><int/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/466025/100/0/threaded">20070417 BlueArc Firmware 4.2.944b FTP bounce</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/23540">23540</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33721">
bluearc-port-traffic-hijacking(33721)</ref></refs><vuln_soft><prod name="Titan" vendor="BlueArc"><vers num="2100"/><vers num="2200"/><vers num="2500"/><vers num="4.2.944b" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0" modified="2007-05-01" name="CVE-2007-2151" published="2007-04-19" seq="2007-2151" severity="Medium" type="CVE"><desc><descript source="cve">The administration server in McAfee e-Business Server before 8.1.1 and 8.5.x before 8.5.2 allows remote attackers to cause a denial of service (service crash) via a large length value in a malformed authentication packet, which triggers a heap over-read.</descript></desc><sols><sol source="nvd">The vendor has addressed this issue in the following product update:
https://knowledge.mcafee.com/SupportSite/dynamickc.do?externalId=612751&amp;command=show&amp;forward=nonthreadedKC</sol></sols><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref patch="1" source="IDEFENSE" url="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=516">20070417 McAfee E-Business Admin Server Invalid Data Length DoS Vulnerability</ref><ref adv="1" source="" url="https://knowledge.mcafee.com/SupportSite/dynamickc.do?externalId=612751&amp;command=show&amp;forward=nonthreadedKC"></ref><ref source="BID" url="http://www.securityfocus.com/bid/23544">23544</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1434">ADV-2007-1434</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017929">1017929</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24893">24893</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33730">
mcafee-ebusiness-utility-dos(33730)</ref></refs><vuln_soft><prod name="e-Business Server" vendor="McAfee"><vers edition="Solaris" num="8.5.1"/><vers edition="Windows" num="8.5.1"/><vers edition="Linux" num="8.1"/><vers edition="HP-UX" num="8.1"/><vers edition="AIX" num="8.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.9" CVSS_exploit_subscore="5.5" CVSS_impact_subscore="10.0" CVSS_score="7.9" CVSS_vector="(AV:A/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-04-20" name="CVE-2007-2152" published="2007-04-19" seq="2007-2152" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in the On-Access Scanner in McAfee VirusScan Enterprise before 8.0i Patch 12 allows user-assisted remote attackers to execute arbitrary code via a long filename containing multi-byte (Unicode) characters.</descript></desc><sols><sol source="nvd">The vendor has addressed this issue with the following product update:
https://knowledge.mcafee.com/SupportSite/dynamickc.do?externalId=612750&amp;command=show&amp;forward=nonthreadedKC</sol></sols><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local_network/><user_init/></range><refs><ref adv="1" patch="1" source="IDEFENSE" url="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=515">20070417 McAfee VirusScan On-Access Scanner Long Unicode File Name Buffer Overflow</ref><ref adv="1" patch="1" source="" url="https://knowledge.mcafee.com/SupportSite/dynamickc.do?externalId=612750&amp;command=show&amp;forward=nonthreadedKC"></ref><ref source="BID" url="http://www.securityfocus.com/bid/23543">23543</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1435">ADV-2007-1435</ref><ref patch="1" source="SECTRACK" url="http://www.securitytracker.com/id?1017928">1017928</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/24914">24914</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/324929">
VU#324929</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33732">
mcafee-onaccess-bo(33732)</ref></refs><vuln_soft><prod name="VirusScan Enterprise" vendor="McAfee"><vers num="8.0i p11" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" discovered="2007-04-05" modified="2007-04-20" name="CVE-2007-2153" published="2007-04-19" seq="2007-2153" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in atmail.php in @Mail 5.0 allows remote attackers to inject arbitrary web script or HTML via the username parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/465378/100/100/threaded">20070411 [MajorSecurity Advisory #43]Calacode ATMail 5.0 - Cross Site Scripting and Cookie Manipulation Issue</ref><ref adv="1" source="" url="http://www.majorsecurity.de/index_2.php?major_rls=major_rls43"></ref><ref source="BID" url="http://www.securityfocus.com/bid/23428">23428</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33591">@mail-atmail-xss(33591)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2594">2594</ref></refs><vuln_soft><prod name="atmail webmail" vendor="atMail"><vers num="5.0" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-04-20" name="CVE-2007-2154" published="2007-04-19" seq="2007-2154" severity="High" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in services/samples/inclusionService.php in Cabron Connector 1.1.0 allows remote attackers to execute arbitrary PHP code via a URL in the CabronServiceFolder parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3756">3756</ref><ref source="BID" url="http://www.securityfocus.com/bid/23531">23531</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1431">ADV-2007-1431</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33716">
cabronconnector-inclusion-file-include(33716)</ref></refs><vuln_soft><prod name="Cabron Connector" vendor="Cabron Connector"><vers num="1.1.0" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.8" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.9" CVSS_score="7.8" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:N/A:N)" CVSS_version="2.0" modified="2007-04-20" name="CVE-2007-2155" published="2007-04-19" seq="2007-2155" severity="High" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in template.php in in phpFaber TopSites 3 allows remote attackers to read arbitrary files via a .. (dot dot) in the modify parameter in a template action to admin/index.php.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/465339/100/100/threaded">20070411 nEw Bug :D</ref><ref source="" url="http://www.phpfaber.com/m/News/phpfaber_topsites_v_3_3-58.html"></ref><ref source="VIM" url="http://www.attrition.org/pipermail/vim/2007-April/001538.html">20070418 [uncertain] (mostly) phpFaber TopSitespath traversal</ref><ref source="BID" url="http://www.securityfocus.com/bid/23419">23419</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33581">phpfaber-index-directory-traversal(33581)</ref></refs><vuln_soft><prod name="TopSites" vendor="phpFaber"><vers num="3" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-04-20" name="CVE-2007-2156" published="2007-04-19" seq="2007-2156" severity="High" type="CVE"><desc><descript source="cve">Multiple PHP remote file inclusion vulnerabilities in Rezervi Generic 0.9 allow remote attackers to execute arbitrary PHP code via a URL in the root parameter to (1) datumVonDatumBis.inc.php, (2) footer.inc.php, (3) header.inc.php, and (4) stylesheets.php in templates/; and (5) wochenuebersicht.inc.php, (6) monatsuebersicht.inc.php, (7) jahresuebersicht.inc.php, and (8) tagesuebersicht.inc.php in belegungsplan/.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3763">3763</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1448">ADV-2007-1448</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24926">
24926</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33737">
Rezervi-root-file-include(33737)</ref><ref source="BID" url="http://www.securityfocus.com/bid/23550">
23550</ref></refs><vuln_soft><prod name="Rezervi Generic" vendor="Rezervi Generic"><vers num="0.9" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.8" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.9" CVSS_score="7.8" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:N/A:N)" CVSS_version="2.0" modified="2007-04-19" name="CVE-2007-2157" published="2007-04-19" seq="2007-2157" severity="High" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in upload/force_download.php in Zomplog 3.8 allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3764">3764</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1449">ADV-2007-1449</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33740">
zomplog-forcedownload-dir-traversal(33740)</ref><ref source="BID" url="http://www.securityfocus.com/bid/23553">
23553</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24899">
24899</ref></refs><vuln_soft><prod name="Zomplog" vendor="Zomplog"><vers num="3.8"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-04-19" name="CVE-2007-2158" published="2007-04-19" seq="2007-2158" severity="High" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in index.php in jGallery 1.3 allows remote attackers to execute arbitrary PHP code via a URL in the G_JGALL[inc_path] parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3760">3760</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1445">ADV-2007-1445</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33738">
jgallery-index-file-include(33738)</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24956">
24956</ref></refs><vuln_soft><prod name="jGallery" vendor="Kooijman-Design"><vers num="1.3"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" modified="2007-04-23" name="CVE-2007-2159" published="2007-04-22" seq="2007-2159" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in the Database Administration (dba) module 4.6.x-*, and before 4.7.x-1.2 in the 4.7.x-1.* series, for Drupal allow remote attackers to inject arbitrary web script or HTML via unspecified vectors relating to (1) direct display of data from the database and (2) other portions of the user interface.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="" url="http://drupal.org/node/135549"></ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1360">ADV-2007-1360</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/24848">24848</ref></refs><vuln_soft><prod name="Database Administration Module" vendor="Drupal"><vers num="4.6"/><vers num="4.7"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-04-23" name="CVE-2007-2160" published="2007-04-22" seq="2007-2160" severity="High" type="CVE"><desc><descript source="cve">Multiple cross-site request forgery (CSRF) vulnerabilities in the Database Administration (dba) module 4.6.x-*, and before 4.7.x-1.2 in the 4.7.x-1.* series, for Drupal allow remote attackers to perform unauthorized actions as an arbitrary user, a related issue to CVE-2006-5476.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="" url="http://drupal.org/node/135549"></ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1360">ADV-2007-1360</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/24848">24848</ref></refs><vuln_soft><prod name="Database Administration Module" vendor="Drupal"><vers num="4.6"/><vers num="4.7"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0" modified="2007-04-23" name="CVE-2007-2161" published="2007-04-22" seq="2007-2161" severity="Medium" type="CVE"><desc><descript source="cve">Microsoft Internet Explorer 7 allows remote attackers to cause a denial of service (browser hang) via JavaScript that matches a regular expression against a long string, as demonstrated using /(.)*/.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/466017/100/0/threaded">20070417 Internet Explorer Crash</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/466043/100/0/threaded">20070417 Re: Internet Explorer Crash</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/466175/100/0/threaded">20070418 Re: Internet Explorer Crash</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33715">ie-unspecified-dos(33715)</ref></refs><vuln_soft><prod name="Internet Explorer" vendor="Microsoft"><vers num="7.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.8" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.9" CVSS_score="7.8" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_version="2.0" modified="2007-04-23" name="CVE-2007-2162" published="2007-04-22" seq="2007-2162" severity="High" type="CVE"><desc><descript source="cve">(1) Mozilla Firefox 2.0.0.3 and (2) GNU IceWeasel 2.0.0.3 allow remote attackers to cause a denial of service (browser crash or system hang) via JavaScript that matches a regular expression against a long string, as demonstrated using /(.)*/.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/466017/100/0/threaded">20070417 Internet Explorer Crash</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/466147/100/0/threaded">20070417 Re: Internet Explorer Crash</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/466220/100/0/threaded">20070418 Re: Internet Explorer Crash</ref></refs><vuln_soft><prod name="IceWeasel" vendor="GNU"><vers num="2.0.0.3"/></prod><prod name="Firefox" vendor="Mozilla"><vers num="2.0.0.3"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0" modified="2007-04-24" name="CVE-2007-2163" published="2007-04-22" seq="2007-2163" severity="Medium" type="CVE"><desc><descript source="cve">Apple Safari allows remote attackers to cause a denial of service (browser crash) via JavaScript that matches a regular expression against a long string, as demonstrated using /(.)*/.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/466017/100/0/threaded">20070417 Internet Explorer Crash</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/466043/100/0/threaded">20070417 Re: Internet Explorer Crash</ref></refs><vuln_soft><prod name="Safari" vendor="Apple"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0" modified="2007-04-24" name="CVE-2007-2164" published="2007-04-22" seq="2007-2164" severity="Medium" type="CVE"><desc><descript source="cve">Konqueror 3.5.5 release 45.4 allows remote attackers to cause a denial of service (browser crash or abort) via JavaScript that matches a regular expression against a long string, as demonstrated using /(.)*/.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/466017/100/0/threaded">20070417 Internet Explorer Crash</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/466147/100/0/threaded">20070417 Re: Internet Explorer Crash</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2600">2600</ref></refs><vuln_soft><prod name="Konqueror" vendor="KDE"><vers num="3.5.5"/></prod></vuln_soft></entry><entry CVSS_base_score="5.1" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="6.4" CVSS_score="5.1" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-05-08" name="CVE-2007-2165" published="2007-04-22" seq="2007-2165" severity="Medium" type="CVE"><desc><descript source="cve">The Auth API in ProFTPD before 20070417, when multiple simultaneous authentication modules are configured, does not require that the module that checks authentication is the same as the module that retrieves authentication data, which might allow remote attackers to bypass authentication, as demonstrated by use of SQLAuthTypes Plaintext in mod_sql, with data retrieved from /etc/passwd.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" source="" url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=419255"></ref><ref patch="1" source="" url="http://bugs.proftpd.org/show_bug.cgi?id=2922"></ref><ref source="BID" url="http://www.securityfocus.com/bid/23546">23546</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1444">ADV-2007-1444</ref><ref adv="1" source="SECTRACK" url="http://securitytracker.com/id?1017931">1017931</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24867">24867</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33733">proftpd-authapi-security-bypass(33733)</ref><ref source="" url="https://bugzilla.redhat.com/show_bug.cgi?id=237533"></ref><ref source="FEDORA" url="https://www.redhat.com/archives/fedora-package-announce/2007-November/msg00065.html">FEDORA-2007-2613</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:130">MDKSA-2007:130</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25724">25724</ref><ref source="SECUNIA" url="http://secunia.com/advisories/27516">27516</ref></refs><vuln_soft><prod name="ProFTPD" vendor="ProFTPD Project"><vers num="1.3.0 rc1" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-04-24" name="CVE-2007-2166" published="2007-04-22" seq="2007-2166" severity="Medium" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in administration/user/lib/group.inc.php in OpenSurveyPilot (osp) 1.2.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the cfgPathToProjectAdmin parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3765">3765</ref><ref source="" url="http://osp.cvs.sourceforge.net/osp/osp12/administration/user/lib/group.inc.php?revision=1.1.1.1&amp;view=markup"></ref><ref source="BID" url="http://www.securityfocus.com/bid/23563">
23563</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1460">
ADV-2007-1460</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24915">
24915</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33749">
osp-groupinc-file-include(33749)</ref></refs><vuln_soft><prod name="OpenSurveyPilot" vendor="OpenSurveyPilot"><vers num="1.2.1" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-04-24" name="CVE-2007-2167" published="2007-04-22" seq="2007-2167" severity="High" type="CVE"><desc><descript source="cve">Static code injection vulnerability in process.php in AimStats 3.2 allows remote attackers to inject PHP code into config.php via the number parameter in an update action.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3762">3762</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1447">ADV-2007-1447</ref><ref source="" url="http://www.x-pose.org/aimstats.php"></ref><ref source="BID" url="http://www.securityfocus.com/bid/23573">
23573</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24955">
24955</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33742">
aimstats-config-command-execution(33742)</ref></refs><vuln_soft><prod name="AimStats" vendor="AimStats"><vers num="3.2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-04-23" name="CVE-2007-2168" published="2007-04-22" seq="2007-2168" severity="High" type="CVE"><desc><descript source="cve">Static code injection vulnerability in process.php in AimStats 3.2 and earlier allows remote attackers to inject PHP code into config.php via the databasehost parameter.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1447">ADV-2007-1447</ref><ref source="" url="http://www.x-pose.org/aimstats.php"></ref><ref source="BID" url="http://www.securityfocus.com/bid/23573">
23573</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24955">
24955</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33742">
aimstats-config-command-execution(33742)</ref></refs><vuln_soft><prod name="AimStats" vendor="AimStats"><vers num="3.2" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-04-23" name="CVE-2007-2169" published="2007-04-22" seq="2007-2169" severity="High" type="CVE"><desc><descript source="cve">Static code injection vulnerability in add.php in Mozzers SubSystem 1.0 allows remote attackers to inject PHP code into subs.php via the (1) Sub-name or (2) Sub-url field.  NOTE: an earlier report indicated that the add action can be reached through a request to index.php.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3761">3761</ref><ref source="BID" url="http://www.securityfocus.com/bid/23548">23548</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1446">ADV-2007-1446</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33739">
mozzers-subsystem-index-code-execution(33739)</ref></refs><vuln_soft><prod name="Mozzers SubSystem" vendor="Mozzers SubSystem"><vers num="1.0" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="9.4" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="9.2" CVSS_score="9.4" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:C/A:C)" CVSS_version="2.0" modified="2007-04-25" name="CVE-2007-2170" published="2007-04-24" seq="2007-2170" severity="High" type="CVE"><desc><descript source="cve">The APPLSYS.FND_DM_NODES package in Oracle E-Business Suite does not check for valid sessions, which allows remote attackers to delete arbitrary nodes.  NOTE: due to lack of details from Oracle, it is not clear whether this issue is related to other CVE identifiers such as CVE-2007-2126, CVE-2007-2127, or CVE-2007-2128.</descript></desc><loss_types><avail/><int/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref patch="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/466214/100/0/threaded">20070418 ZDI-07-016: Oracle E-Business Suite Arbitrary Node Deletion Vulnerability</ref><ref patch="1" source="" url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpuapr2007.html"></ref><ref patch="1" source="" url="http://www.red-database-security.com/advisory/oracle_cpu_apr_2007.html"></ref><ref patch="1" source="" url="http://www.zerodayinitiative.com/advisories/ZDI-07-016.html"></ref><ref source="SREASON" url="http://securityreason.com/securityalert/2611">2611</ref></refs><vuln_soft><prod name="E-Business Suite" vendor="Oracle"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-04-25" name="CVE-2007-2171" published="2007-04-24" seq="2007-2171" severity="High" type="CVE"><desc><descript source="cve">Stack-based buffer overflow in the base64_decode function in GWINTER.exe in Novell GroupWise (GW) WebAccess before 7.0 SP2 allows remote attackers to execute arbitrary code via long base64 content in an HTTP Basic Authentication request.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/466212/100/0/threaded">20070418 ZDI-07-015: Novell Groupwise WebAccess Base64 Decoding Stack Overflow Vulnerability</ref><ref source="" url="http://www.zerodayinitiative.com/advisories/ZDI-07-015.html"></ref><ref patch="1" source="" url="http://download.novell.com/Download?buildid=8RF83go0nZg~"></ref><ref patch="1" source="" url="http://download.novell.com/Download?buildid=O9ucpbS1bK0~"></ref><ref source="BID" url="http://www.securityfocus.com/bid/23556">23556</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1455">ADV-2007-1455</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017932">1017932</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24944">24944</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2610">2610</ref></refs><vuln_soft><prod name="Groupwise" vendor="Novell"><vers num="7.0"/><vers num="7.0 SP1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.7" CVSS_exploit_subscore="3.4" CVSS_impact_subscore="6.9" CVSS_score="4.7" CVSS_vector="(AV:L/AC:M/Au:N/C:N/I:N/A:C)" CVSS_version="2.0" modified="2007-12-31" name="CVE-2007-2172" published="2007-04-22" seq="2007-2172" severity="Medium" type="CVE"><desc><descript source="cve">A typo in Linux kernel 2.6 before 2.6.21-rc6 and 2.4 before 2.4.35 causes RTA_MAX to be used as an array size instead of RTN_MAX, which leads to an &quot;out of bound access&quot; by the (1) dn_fib_props (dn_fib.c, DECNet) and (2) fib_props (fib_semantics.c, IPv4) functions.</descript></desc><loss_types><avail/></loss_types><vuln_types><input bound="1"/></vuln_types><range><local/><user_init/></range><refs><ref source="" url="http://kernel.org/pub/linux/kernel/v2.6/testing/ChangeLog-2.6.21-rc6"></ref><ref source="" url="http://www.mail-archive.com/git-commits-head@vger.kernel.org/msg08269.html"></ref><ref source="" url="http://www.mail-archive.com/git-commits-head@vger.kernel.org/msg08270.html"></ref><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/23447">23447</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2007-0347.html">RHSA-2007:0347</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/25288">25288</ref><ref source="" url="http://support.avaya.com/elmodocs2/security/ASA-2007-287.htm"></ref><ref source="" url="http://www.kernel.org/pub/linux/kernel/v2.4/ChangeLog-2.4.35"></ref><ref source="DEBIAN" url="http://www.debian.org/security/2007/dsa-1356">DSA-1356</ref><ref source="DEBIAN" url="http://www.debian.org/security/2007/dsa-1363">DSA-1363</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:171">MDKSA-2007:171</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:196">MDKSA-2007:196</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:216">MDKSA-2007:216</ref><ref source="REDHAT" url="http://rhn.redhat.com/errata/RHSA-2007-0488.html">RHSA-2007:0488</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2007-1049.html">RHSA-2007:1049</ref><ref source="UBUNTU" url="http://www.ubuntu.com/usn/usn-464-1">USN-464-1</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/2690">ADV-2007-2690</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/25392">25392</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/25838">25838</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/26289">26289</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/26450">26450</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/25068">25068</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/26647">26647</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/26620">26620</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/27913">27913</ref><ref source="DEBIAN" url="http://www.debian.org/security/2008/dsa-1503">DSA-1503</ref><ref source="DEBIAN" url="http://www.debian.org/security/2008/dsa-1504">DSA-1504</ref><ref source="SECUNIA" url="http://secunia.com/advisories/29058">29058</ref></refs><vuln_soft><prod name="Kernel" vendor="Linux"><vers num="2.4.34" prev="1"/><vers num="2.6.20.5" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-04-24" name="CVE-2007-2173" published="2007-04-24" seq="2007-2173" severity="High" type="CVE"><desc><descript source="cve">Eval injection vulnerability in (1) courier-imapd.indirect and (2) courier-pop3d.indirect in Courier-IMAP before 4.0.6-r2, and 4.1.x before 4.1.2-r1, on Gentoo Linux allows remote attackers to execute arbitrary commands via the XMAILDIR variable, related to the LOGINRUN variable.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://bugs.gentoo.org/show_bug.cgi?id=168196"></ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200704-18.xml">GLSA-200704-18</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/24963">24963</ref><ref source="BID" url="http://www.securityfocus.com/bid/23589">
23589</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33805">
gentoo-courier-imap-code-execution(33805)</ref></refs><vuln_soft><prod name="Courier-IMAP" vendor="Double Precision Incorporated"><vers num="4.0.0"/><vers num="4.0.1"/><vers num="4.0.2"/><vers num="4.0.3"/><vers num="4.0.4"/><vers num="4.0.5"/><vers num="4.1.0"/><vers num="4.1.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-04-24" name="CVE-2007-2174" published="2007-04-24" seq="2007-2174" severity="High" type="CVE"><desc><descript source="cve">The IOCTL handling in srescan.sys in the ZoneAlarm Spyware Removal Engine (SRE) in Check Point ZoneAlarm before 5.0.156.0 allows local users to execute arbitrary code via certain IOCTL lrp parameter addresses.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" source="IDEFENSE" url="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=517">20070420 Check Point Zone Labs SRESCAN IOCTL Local Privilege Escalation Vulnerability</ref><ref source="BID" url="http://www.securityfocus.com/bid/23579">23579</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017948">1017948</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/24986">24986</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/466656/100/0/threaded">
20070423 [Reversemode advisory] CheckPoint Zonelabs - ZoneAlarm SRESCAN driver local privilege escalation</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1491">
ADV-2007-1491</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33786">
zonealarm-srescan-privilege-escalation(33786)</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017953">
1017953</ref></refs><vuln_soft><prod name="ZoneAlarm" vendor="Checkpoint"><vers num="5.0.63.0" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="10.0" CVSS_score="7.6" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-05-10" name="CVE-2007-2175" published="2007-04-24" seq="2007-2175" severity="High" type="CVE"><desc><descript source="cve">Apple QuickTime Java extensions (QTJava.dll), as used in Safari and other browsers, and when Java is enabled, allows remote attackers to execute arbitrary code via parameters to the toQTPointer method in quicktime.util.QTHandleRef, which can be used to modify arbitrary memory when creating QTPointerRef objects, as demonstrated during the &quot;PWN 2 0WN&quot; contest at CanSecWest 2007.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><range><network/><user_init/></range><refs><ref source="" url="http://cansecwest.com/post/2007-04-20-14:54:00.First_Mac_Hacked_Cancel_Or_Allow"></ref><ref source="" url="http://www.matasano.com/log/806/hot-off-the-matasano-sms-queue-cansec-macbook-challenge-won/"></ref><ref source="" url="http://www.theregister.co.uk/2007/04/20/pwn-2-own_winner/"></ref><ref source="" url="http://www.matasano.com/log/812/breaking-macbook-vuln-in-quicktime-affects-win32-apple-code/"></ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017950">1017950</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33827">quicktime-unspecified-code-execution(33827)</ref><ref source="" url="http://www.zerodayinitiative.com/advisories/ZDI-07-023.html"></ref><ref source="" url="http://docs.info.apple.com/article.html?artnum=305446"></ref><ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2007/May/msg00001.html">APPLE-SA-2007-05-01</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/467319/100/0/threaded">

20070501 ZDI-07-023: Apple QTJava toQTPointer() Pointer Arithmetic Memory Overwrite Vulnerability</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/420668">
VU#420668</ref><ref source="OSVDB" url="http://www.osvdb.org/34178">34178</ref></refs><vuln_soft><prod name="Safari" vendor="Apple"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-08-02" name="CVE-2007-2176" published="2007-04-24" seq="2007-2176" severity="High" type="CVE"><desc><descript source="cve">Unspecified vulnerability in Mozilla Firefox allows remote attackers to execute arbitrary code via unspecified vectors involving Javascript errors.  NOTE: this might be the same issue as CVE-2007-2175.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><range><network/></range><refs><ref source="" url="http://www.matasano.com/log/806/hot-off-the-matasano-sms-queue-cansec-macbook-challenge-won/"></ref></refs><vuln_soft><prod name="Firefox" vendor="Mozilla"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-04-24" name="CVE-2007-2177" published="2007-04-24" seq="2007-2177" severity="Medium" type="CVE"><desc><descript source="cve">Stack-based buffer overflow in the Microgaming Download Helper ActiveX control (dlhelper.dll) before 7.2.0.19, and the WebHandler Class control, allows remote attackers to execute arbitrary code via unspecified vectors.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/><user_init/></range><refs><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/184473">VU#184473</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/23595">23595</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1507">
ADV-2007-1507</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25017">
25017</ref></refs><vuln_soft><prod name="Download Helper ActiveX Control" vendor="Microgaming"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.8" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.9" CVSS_score="7.8" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_version="2.0" modified="2007-04-25" name="CVE-2007-2178" published="2007-04-24" seq="2007-2178" severity="High" type="CVE"><desc><descript source="cve">Multiple unspecified vulnerabilities in Objective Development Sharity before 3.3 allow remote attackers to cause a denial of service (daemon crash) via unspecified vectors.</descript></desc><loss_types><avail/></loss_types><range><network/></range><refs><ref source="" url="http://www.obdev.at/products/sharity/releasenotes.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/23572">23572</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24925">24925</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33774">
Sharity-unspecified-dos(33774)</ref></refs><vuln_soft><prod name="Sharity" vendor="Objective Development"><vers num="3.2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.8" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.9" CVSS_score="7.8" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_version="2.0" modified="2007-04-25" name="CVE-2007-2179" published="2007-04-24" seq="2007-2179" severity="High" type="CVE"><desc><descript source="cve">Multiple unspecified vulnerabilities in IXceedCompression in XceddZipLib (RaidenFTPD.dll) in RaidenFTPD 2.4 allow remote attackers to cause a denial of service (crash) via unspecified vectors involving the (1) CalculateCrc, (2) Compress, and (3) Uncompress functions, which result in a NULL pointer dereference.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/466319/100/0/threaded">20070419 RaidenFTPd IXceedCompression multiple denial of service vulnerabilities</ref><ref source="BID" url="http://www.securityfocus.com/bid/23570">23570</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33776">
raidenftpd-multiple-dos(33776)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2606">2606</ref></refs><vuln_soft><prod name="RaidenFTPD" vendor="Raiden Professional Servers"><vers num="2.4.2240"/><vers num="2.4.2241"/></prod></vuln_soft></entry><entry CVSS_base_score="7.1" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.9" CVSS_score="7.1" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:C)" CVSS_version="2.0" modified="2007-04-25" name="CVE-2007-2180" published="2007-04-24" seq="2007-2180" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in Nullsoft Winamp 5.3 allows user-assisted remote attackers to cause a denial of service (crash) via a crafted WMV file.</descript></desc><loss_types><avail/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/><user_init/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/466291/100/0/threaded">20070419 Winamp &lt;= (WMV) 5.3 Buffer Overflow DOS Exploit (0-DAY)</ref><ref source="BID" url="http://www.securityfocus.com/bid/23568">23568</ref><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3768">
3768</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33764">
winamp-wmv-bo(33764)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2601">2601</ref></refs><vuln_soft><prod name="WinAmp" vendor="Nullsoft"><vers num="5.3"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-04-25" name="CVE-2007-2181" published="2007-04-24" seq="2007-2181" severity="Medium" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in admin/login.php in Webinsta FM Manager 0.1.4 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the absolute_path parameter, a different product and vector than CVE-2005-0748.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3778">3778</ref><ref source="BID" url="http://www.securityfocus.com/bid/23592">
23592</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1494">
ADV-2007-1494</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24958">
24958</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33793">
webinstafm-login-file-include(33793)</ref></refs><vuln_soft><prod name="FM Manager" vendor="WEBInsta"><vers num="0.1.4" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-04-25" name="CVE-2007-2182" published="2007-04-24" seq="2007-2182" severity="Medium" type="CVE"><desc><descript source="cve">Unrestricted file upload vulnerability in forum_write.php in Maran PHP Forum allows remote attackers to upload and execute arbitrary PHP files via a trailing %00 in a filename in the page parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3775">3775</ref><ref source="BID" url="http://www.securityfocus.com/bid/23614">
23614</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1493">
ADV-2007-1493</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24968">
24968</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33802">
maranforum-pagename-code-execution(33802)</ref></refs><vuln_soft><prod name="PHP Forum" vendor="Maran"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-04-25" name="CVE-2007-2183" published="2007-04-24" seq="2007-2183" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in index.php in PHP-Ring Webring System (aka uPHP_ring_website) 0.9 allows remote attackers to execute arbitrary SQL commands via the ring parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3774">3774</ref><ref source="BID" url="http://www.securityfocus.com/bid/23586">
23586</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33804">
uphp-ring-sql-injection(33804)</ref></refs><vuln_soft><prod name="Webring System" vendor="PHP-Ring"><vers num="0.9"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0" modified="2007-04-25" name="CVE-2007-2184" published="2007-04-24" seq="2007-2184" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in imgsrv.php in jchit counter 1.0.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the acc parameter.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3773">3773</ref><ref source="BID" url="http://www.securityfocus.com/bid/23585">
23585</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33806">
jchitcounter-imgsrv-directory-traversal(33806)</ref></refs><vuln_soft><prod name="counter" vendor="jchit"><vers num="1.0.0"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-08-02" name="CVE-2007-2185" published="2007-04-24" seq="2007-2185" severity="Medium" type="CVE"><desc><descript source="cve">Multiple PHP remote file inclusion vulnerabilities in Supasite 1.23b allow remote attackers to execute arbitrary PHP code via a URL in the supa[db_path] parameter to (1) common_functions.php, (2) admin_auth_cookies.php, (3) admin_mods.php, (4) admin_news.php, (5) admin_topics.php, (6) admin_users.php, (7) admin_utilities.php, (8) site_comment.php, or (9) site_news.php; or the supa[include_path] parameter to (10) admin_settings.php or (11) backend_site.php.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3771">3771</ref><ref source="BID" url="http://www.securityfocus.com/bid/23581">23581</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1492">ADV-2007-1492</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33796">supasite-supa-file-include(33796)</ref></refs><vuln_soft><prod name="Supasite" vendor="Supasite"><vers num="1.23b"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0" modified="2007-04-25" name="CVE-2007-2186" published="2007-04-24" seq="2007-2186" severity="Medium" type="CVE"><desc><descript source="cve">Foxit Reader 2.0 allows remote attackers to cause a denial of service (application crash) via a crafted PDF document.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3770">3770</ref><ref source="BID" url="http://www.securityfocus.com/bid/23576">23576</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33784">foxitreader-pdf-dos(33784)</ref></refs><vuln_soft><prod name="PDF Reader" vendor="Foxit"><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-04-25" name="CVE-2007-2187" published="2007-04-24" seq="2007-2187" severity="High" type="CVE"><desc><descript source="cve">Stack-based buffer overflow in eXtremail 2.1.1 and earlier allows remote attackers to execute arbitrary code via a long DNS response. NOTE: this might be related to CVE-2006-6926.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref source="FULLDISC" url="http://archives.neohapsis.com/archives/fulldisclosure/2007-04/0569.html">20070420 eXtremail-v9</ref><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3769">3769</ref><ref source="" url="http://www.digit-labs.org/files/exploits/extremail-v9.c"></ref><ref source="BID" url="http://www.securityfocus.com/bid/23577">23577</ref></refs><vuln_soft><prod name="eXtremail" vendor="eXtremail"><vers num="2.1"/><vers num="2.1.1"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-04-25" name="CVE-2007-2188" published="2007-04-24" seq="2007-2188" severity="High" type="CVE"><desc><descript source="cve">eXtremail 2.1.1 and earlier does not verify the ID field (aka transaction id) in DNS responses, which makes it easier for remote attackers to conduct DNS spoofing.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref source="FULLDISC" url="http://archives.neohapsis.com/archives/fulldisclosure/2007-04/0569.html">20070420 eXtremail-v9</ref><ref source="BID" url="http://www.securityfocus.com/bid/23577">23577</ref></refs><vuln_soft><prod name="eXtremail" vendor="eXtremail"><vers num="2.1"/><vers num="2.1.1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-04-25" name="CVE-2007-2189" published="2007-04-24" seq="2007-2189" severity="Medium" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in admin/admin_album_otf.php in the MX Smartor Full Album Pack (FAP) 2.0 RC1 module for mxBB allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3766">3766</ref><ref source="BID" url="http://www.securityfocus.com/bid/23561">23561</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33760">mxbb-smartorfap-admin-file-include(33760)</ref></refs><vuln_soft><prod name="Full Album Pack" vendor="MX Smartor"><vers num="2.1 RC1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-04-25" name="CVE-2007-2190" published="2007-04-24" seq="2007-2190" severity="Medium" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in admin/public/webpages.php in Eba News 1.1 allows remote attackers to execute arbitrary PHP code via a URL in the filename parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/466406/100/0/threaded">20070420 Eba News Version : v1.1 &lt;= (webpages.php) Remote File Include // starhack.org</ref><ref adv="1" patch="1" source="" url="http://ebascripts.com/"></ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33783">ebanews-webpages-file-include(33783)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2607">2607</ref></refs><vuln_soft><prod name="Eba News" vendor="Eba News"><vers num="1.1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-04-25" name="CVE-2007-2191" published="2007-04-24" seq="2007-2191" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in freePBX 2.2.x allow remote attackers to inject arbitrary web script or HTML via the (1) From, (2) To, (3) Call-ID, (4) User-Agent, and unspecified other SIP protocol fields, which are stored in /var/log/asterisk/full and displayed by admin/modules/logfiles/asterisk-full-log.php.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2007-April/053882.html">20070419 XSS in freePBX 2.2.x portal&apos;s Asterisk Log tool</ref><ref source="BID" url="http://www.securityfocus.com/bid/23575">23575</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33772">freepbx-sip-xss(33772)</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1535">
ADV-2007-1535</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24935">
24935</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2627">2627</ref></refs><vuln_soft><prod name="freePBX" vendor="freePBX"><vers num="2.2 RC1"/><vers num="2.2.1"/></prod></vuln_soft></entry><entry CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" CVSS_score="9.3" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-04-25" name="CVE-2007-2192" published="2007-04-24" seq="2007-2192" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in Photofiltre Studio 8.1.1 allows user-assisted remote attackers to execute arbitrary code via a crafted .tif file.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3772">3772</ref><ref source="BID" url="http://www.securityfocus.com/bid/23582">23582</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1490">
ADV-2007-1490</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24981">
24981</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33807">
photofiltre-tif-bo(33807)</ref></refs><vuln_soft><prod name="Photofiltre Studio" vendor="Antonio Da Cruz"><vers num="8.1.1"/></prod></vuln_soft></entry><entry CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" CVSS_score="9.3" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-04-25" name="CVE-2007-2193" published="2007-04-24" seq="2007-2193" severity="High" type="CVE"><desc><descript source="cve">Stack-based buffer overflow in the ID_X.apl plugin in ACDSee 9.0 Build 108, Pro 8.1 Build 99, and Photo Editor 4.0 Build 195 allows user-assisted remote attackers to execute arbitrary code via a crafted XPM file with a long section string.  NOTE: some of these details are obtained from third party information.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/><user_init/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3776">3776</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1489">ADV-2007-1489</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24994">24994</ref><ref source="BID" url="http://www.securityfocus.com/bid/23620">
23620</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33812">
acdsee-xpm-bo(33812)</ref><ref source="" url="http://www.acdsee.com/support/knowledgebase/article?id=2800"></ref></refs><vuln_soft><prod name="ACDSee" vendor="ACD Systems"><vers num="9.0 Build 108"/><vers edition="Pro" num="8.1 Build 99"/></prod><prod name="Photo Editor" vendor="ACD Systems"><vers num="4.0 Build 195"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-04-25" name="CVE-2007-2194" published="2007-04-24" seq="2007-2194" severity="High" type="CVE"><desc><descript source="cve">Stack-based buffer overflow in XnView 1.90.3 allows user-assisted remote attackers to execute arbitrary code via a crafted XPM file with a long section string.  NOTE: some of these details are obtained from third party information.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3777">3777</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1488">ADV-2007-1488</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24973">24973</ref><ref source="BID" url="http://www.securityfocus.com/bid/23625">
23625</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33810">
xnview-xpm-bo(33810)</ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200707-06.xml">GLSA-200707-06</ref><ref source="SECUNIA" url="http://secunia.com/advisories/26006">26006</ref></refs><vuln_soft><prod name="XnView" vendor="Gentoo"><vers num="1.90.3"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0" modified="2007-04-25" name="CVE-2007-2195" published="2007-04-24" seq="2007-2195" severity="Medium" type="CVE"><desc><descript source="cve">aMSN (aka Alvaro&apos;s Messenger) 0.96 and earlier allows remote attackers to cause a denial of service (application crash) by sending invalid data to TCP port 31337.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://www.securityfocus.com/data/vulnerabilities/exploits/23583.c"></ref><ref source="BID" url="http://www.securityfocus.com/bid/23583">23583</ref></refs><vuln_soft><prod name="Alvaro&apos;s Messenger" vendor="Alvaro"><vers num="0.96" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-08-02" name="CVE-2007-2196" published="2007-04-24" seq="2007-2196" severity="Medium" type="CVE"><desc><descript source="cve">** DISPUTED **  PHP remote file inclusion vulnerability in jambook.php in the Jambook (com_Jambook) 1.0 beta7 module for Mambo and Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.  NOTE: this issue has been disputed by a reliable third party because the jambook.php protects against direct request.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/465843/100/100/threaded">20070415 Joomla/Mambo Jambook v1.0 beta7 Rfi Vuln.</ref><ref source="" url="http://www.jxdevelopment.com/"></ref><ref source="VIM" url="http://attrition.org/pipermail/vim/2007-April/001535.html">20070417 False: Joomla/Mambo Jambook v1.0 beta7 Rfi Vuln.</ref><ref source="BID" url="http://www.securityfocus.com/bid/23509">23509</ref><ref source="OSVDB" url="http://www.osvdb.org/34151">34151</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2603">2603</ref></refs><vuln_soft><prod name="Jambook" vendor="Mambo"><vers num="1.0 Beta 7"/></prod><prod name="Jambook" vendor="Joomla"><vers num="1.0 Beta 7"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0" modified="2007-06-27" name="CVE-2007-2197" published="2007-04-24" seq="2007-2197" severity="Medium" type="CVE"><desc><descript source="cve">Race condition in the NeatUpload ASP.NET component 1.2.11 through 1.2.16, 1.1.18 through 1.1.23, and trunk.379 through trunk.445 allows remote attackers to obtain other clients&apos; HTTP responses via multiple simultaneous requests, which triggers multiple calls to HttpWorkerRequest.FlushResponse for the same HttpWorkerRequest object and causes a buffer to be reused for a different request.</descript></desc><loss_types><conf/></loss_types><vuln_types><race/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/466404/100/0/threaded">20070420 NeatUpload vulnerability and fix</ref><ref source="BID" url="http://www.securityfocus.com/bid/23578">23578</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/25003">25003</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33785">neatupload-responses-information-disclosure(33785)</ref></refs><vuln_soft><prod name="NeatUpload" vendor="Brettle Development"><vers num="1.1.18"/><vers num="1.1.19"/><vers num="1.1.20"/><vers num="1.1.21"/><vers num="1.1.22"/><vers num="1.1.23"/><vers num="1.2.11"/><vers num="1.2.12"/><vers num="1.2.13"/><vers num="1.2.14"/><vers num="1.2.15"/><vers num="1.2.16"/><vers num="trunk.379"/><vers num="trunk.380"/><vers num="trunk.381"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" modified="2007-04-25" name="CVE-2007-2198" published="2007-04-24" seq="2007-2198" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in LAN Management System (LMS) before 1.6.9 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, probably involving the OD parameter to contrib/formularz_przelewu_wplaty/druk.php.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref patch="1" source="" url="http://www.lms.org.pl/"></ref><ref patch="1" source="" url="http://www.lms.org.pl/download/1.6/lms-1.6.9.tar.gz"></ref><ref source="BID" url="http://www.securityfocus.com/bid/23715">
23715</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25067">
25067</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1580">
ADV-2007-1580</ref></refs><vuln_soft><prod name="LAN Management System" vendor="LAN Management System"><vers num="1.5.6"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-12-31" name="CVE-2007-2199" published="2007-04-24" seq="2007-2199" severity="Medium" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in lib/pcltar.lib.php (aka pcltar.php) in the PclTar module 1.3 and 1.3.1 for Vincent Blavet PhpConcept Library, as used in multiple products including (1) Joomla! 1.5.0 Beta, (2) N/X Web Content Management System (WCMS) 4.5, (3) CJG EXPLORER PRO 3.3, and (4) phpSiteBackup 0.1, allows remote attackers to execute arbitrary PHP code via a URL in the g_pcltar_lib_dir parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3781">3781</ref><ref adv="1" source="" url="http://www.hackers.ir/advisories/joomla.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/23613">23613</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/466687/100/0/threaded">20070423 Remote file inclusion in Joomla 1.5.0 Beta</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1511">ADV-2007-1511</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33837">joomla-pcltar-file-include(33837)</ref><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3915">3915</ref><ref source="VIM" url="http://www.attrition.org/pipermail/vim/2007-May/001618.html">20070514 shared code incolving pcltar.lib.php/g_pcltar_lib_dir RFI</ref><ref source="BID" url="http://www.securityfocus.com/bid/23708">23708</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/25230">25230</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/34273">cjgexplorerpro-pcltarpcltrace-file-include(34273)</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/478503/100/0/threaded">20070904 Re: Multiple vulnerabilities in Joomla 1.5 RC 1</ref><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/4111">4111</ref><ref source="BID" url="http://www.securityfocus.com/bid/24660">24660</ref><ref source="BID" url="http://www.securityfocus.com/bid/25528">25528</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/35092">phpsitebackup-pcltarlib-file-include(35092)</ref></refs><vuln_soft><prod name="CJG EXPLORER PRO" vendor="CJG EXPLORER PRO"><vers num="3.3"/></prod><prod name="N_X WCMS" vendor="NX"><vers num="4.5"/></prod><prod name="Joomla" vendor="Joomla"><vers num="1.5.0 Beta"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-04-25" name="CVE-2007-2200" published="2007-04-24" seq="2007-2200" severity="High" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in navigator/navigator_ok.php in Pagode 0.5.8 allows remote attackers to read and possibly delete arbitrary files via a .. (dot dot) in the asolute parameter.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3783">3783</ref><ref source="BID" url="http://www.securityfocus.com/bid/23617">
23617</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1512">
ADV-2007-1512</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24992">
24992</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33848">
pagode-navigatorok-directory-traversal(33848)</ref></refs><vuln_soft><prod name="Pagode" vendor="Pagode"><vers num="0.5.8"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-04-25" name="CVE-2007-2201" published="2007-04-24" seq="2007-2201" severity="High" type="CVE"><desc><descript source="cve">Multiple PHP remote file inclusion vulnerabilities in Post Revolution 6.6 and 7.0 RC2 allow remote attackers to execute arbitrary PHP code via a URL in the dir parameter to (1) common.php or (2) themes/default/preview_post_completo.php.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/466707/100/0/threaded">20070422 Post Revolution Remote File Inclusion</ref><ref adv="1" source="MILW0RM" url="http://www.milw0rm.com/exploits/3785">3785</ref><ref source="BID" url="http://www.securityfocus.com/bid/23607">23607</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1513">
ADV-2007-1513</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24971">
24971</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33825">
postrevolution-commonpreview-file-include(33825)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2653">2653</ref></refs><vuln_soft><prod name="Post Revolution" vendor="Post Revolution"><vers num="6.6"/><vers num="7.0 RC2"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-04-25" name="CVE-2007-2202" published="2007-04-24" seq="2007-2202" severity="Medium" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in inc_ACVS/SOAP/Transport.php in Accueil et Conseil en Visites et Sejours Web Services (ACVSWS) PHP5 (ACVSWS_PHP5) 1.0 allows remote attackers to execute arbitrary PHP code via a URL in the CheminInclude parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/466695/100/0/threaded">20070423 acvsws_php5_v1.0 &lt;= Multiple Remote File Include Vulnerablitiy</ref><ref source="BID" url="http://www.securityfocus.com/bid/23603">
23603</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1509">
ADV-2007-1509</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24983">
24983</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33840">
acvswebservices-transport-file-include(33840)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2609">2609</ref></refs><vuln_soft><prod name="ACVSWS_PHP5" vendor="ACVSWS"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" modified="2007-04-25" name="CVE-2007-2203" published="2007-04-24" seq="2007-2203" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in Big Blue Guestbook allows remote attackers to inject arbitrary web script or HTML via the message field in the guestbook entry submission form.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/466693/100/0/threaded">20070423 Big Blue Guestbook HTML Injection Vulnerabilities</ref><ref source="BID" url="http://www.securityfocus.com/bid/23591">23591</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1518">
ADV-2007-1518</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24997">
24997</ref></refs><vuln_soft><prod name="Guestbook" vendor="Big Blue"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-04-25" name="CVE-2007-2204" published="2007-04-24" seq="2007-2204" severity="High" type="CVE"><desc><descript source="cve">Multiple PHP remote file inclusion vulnerabilities in GPL PHP Board (GPB) unstable-2001.11.14-1 allow remote attackers to execute arbitrary PHP code via a URL in the root_path parameter to (1) db.mysql.inc.php or (2) gpb.inc.php in include/, or the (3) theme parameter to themes/ubb/login.php.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3786">3786</ref><ref source="BID" url="http://www.securityfocus.com/bid/23622">
23622</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1514">
ADV-2007-1514</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33839">
gpb-multiple-script-file-include(33839)</ref></refs><vuln_soft><prod name="GPL PHP Board" vendor="GPL PHP Board"><vers edition="unstable" num="2001-11-14_1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-04-25" name="CVE-2007-2205" published="2007-04-24" seq="2007-2205" severity="High" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in modules/rtmessageadd.php in LAN Management System (LMS) 1.5.3, and possibly 1.5.4, allows remote attackers to execute arbitrary PHP code via a URL in the _LIB_DIR parameter, a different vector than CVE-2007-1643.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/466664/100/0/threaded">20070422 lms 1.5.3 Remote File Inclusion</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/23611">23611</ref><ref source="VIM" url="http://www.attrition.org/pipermail/vim/2007-April/001560.html">
20070426 true: 2 distinct LMS RFI, one old, one new; and vague ACK</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33819">
lms-rtmessageadd-file-include(33819)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2630">2630</ref></refs><vuln_soft><prod name="LAN Management System" vendor="LAN Management System"><vers num="1.5.3"/><vers num="1.5.4"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" modified="2008-07-30" name="CVE-2007-2206" published="2007-04-24" seq="2007-2206" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in contact/index.php in Ripe Website Manager 0.8.4 and earlier allows remote attackers to inject arbitrary web script or HTML via a leading &quot;&lt;&quot;&lt;&quot; in the ripeformpost parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/466673/100/0/threaded">20070422 Ripe Website Manager (&lt;= 0.8.4) - SQL Injection Vulnerability and Cross-Site Scripting Exploit</ref><ref source="BID" url="http://www.securityfocus.com/bid/23597">23597</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2007-04/0384.html">20070422 Ripe Website Manager (&lt;= 0.8.4) - SQL Injection Vulnerability and Cross-Site Scripting Exploit</ref><ref source="" url="http://john-martinelli.com/work/ripe.txt"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1519">ADV-2007-1519</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24984">24984</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33817">rwm-index-xss(33817)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2602">2602</ref></refs><vuln_soft><prod name="Ripe Website Manager" vendor="Ripe Website Manager"><vers num="0.8.4" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-04-25" name="CVE-2007-2207" published="2007-04-24" seq="2007-2207" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in contact/index.php in Ripe Website Manager 0.8.4 and earlier allows remote attackers to execute arbitrary SQL commands via the ripeformpost parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/466673/100/0/threaded">20070422 Ripe Website Manager (&lt;= 0.8.4) - SQL Injection Vulnerability and Cross-Site Scripting Exploit</ref><ref source="BID" url="http://www.securityfocus.com/bid/23597">23597</ref><ref source="" url="http://john-martinelli.com/work/ripe.txt"></ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1519">
ADV-2007-1519</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24984">
24984</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33818">
rwm-index-sql-injection(33818)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2602">2602</ref></refs><vuln_soft><prod name="Ripe Website Manager" vendor="Ripe Website Manager"><vers num="0.8.4" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-04-25" name="CVE-2007-2208" published="2007-04-24" seq="2007-2208" severity="High" type="CVE"><desc><descript source="cve">Multiple PHP remote file inclusion vulnerabilities in Extreme PHPBB2 3.0 Pre Final allow remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter to (1) functions.php or (2) functions_portal.php in includes/.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/466180/100/0/threaded">20070418 Extreme PHPBB2 Remote File Inclusion</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33743">extremephpbb-phpbbrootpath-file-include(33743)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2608">2608</ref></refs><vuln_soft><prod name="Extreme phpBB" vendor="Extreme phpBB"><vers num="3.0 Pre Final"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-08-02" name="CVE-2007-2209" published="2007-04-24" seq="2007-2209" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in igcore15d.dll 15.1.2.0 and 15.2.0.0 for AccuSoft ImageGear, as used in Corel Paint Shop Pro Photo 11.20 and possibly other products, allows user-assisted remote attackers to execute arbitrary code via a crafted .CLP file.  NOTE: some details were obtained from third party sources.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3779">3779</ref><ref source="BID" url="http://www.securityfocus.com/bid/23604">23604</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1506">ADV-2007-1506</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/25016">25016</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/25050">25050</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33821">paintshopphoto-clp-bo(33821)</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017963">1017963</ref></refs><vuln_soft><prod name="ImageGear" vendor="AccuSoft"><vers num=""/></prod><prod name="Paint Shop Pro Photo" vendor="Corel"><vers num="11.20"/></prod></vuln_soft></entry><entry CVSS_base_score="7.8" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.9" CVSS_score="7.8" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_version="2.0" modified="2007-04-25" name="CVE-2007-2210" published="2007-04-24" seq="2007-2210" severity="High" type="CVE"><desc><descript source="cve">A certain ActiveX control in askPopStp.dll in Netsprint Ask IE Toolbar 1.1 allows remote attackers to cause a denial of service (Internet Explorer crash) via a long AddAllowed property value, related to &quot;improper memory handling,&quot; possibly a buffer overflow.</descript></desc><loss_types><avail/></loss_types><vuln_types><input buffer="1"/><exception/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/466022/100/100/threaded">20070417 Multiple Ask IE Toolbar denial of service vulnerabilities</ref><ref source="BID" url="http://www.securityfocus.com/bid/23535">23535</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2604">2604</ref></refs><vuln_soft><prod name="Ask IE Toolbar" vendor="Netsprint"><vers num="1.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-04-25" name="CVE-2007-2211" published="2007-04-24" seq="2007-2211" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in calendar.php in MyBB (aka MyBulletinBoard) 1.2.5 and earlier allows remote attackers to execute arbitrary SQL commands via the day parameter in a dayview action.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3780">3780</ref><ref source="BID" url="http://www.securityfocus.com/bid/23612">23612</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33814">mybb-calendar-sql-injection(33814)</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1510">
ADV-2007-1510</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24967">
24967</ref></refs><vuln_soft><prod name="MyBulletinBoard" vendor="MyBulletinBoard"><vers num="1.2.5" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-04-25" name="CVE-2007-2212" published="2007-04-24" seq="2007-2212" severity="High" type="CVE"><desc><descript source="cve">Multiple SQL injection vulnerabilities in calendar.php in MyBB (aka MyBulletinBoard) 1.2.5 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) year or (2) month parameter.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33814">mybb-calendar-sql-injection(33814)</ref></refs><vuln_soft><prod name="MyBB" vendor="MyBB"><vers num="1.2.5"/></prod></vuln_soft></entry><entry CVSS_base_score="7.8" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.9" CVSS_score="7.8" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_version="2.0" modified="2007-04-25" name="CVE-2007-2213" published="2007-04-24" seq="2007-2213" severity="High" type="CVE"><desc><descript source="cve">Unspecified vulnerability in the Initialize function in NetscapeFTPHandler in WS_FTP Home and Professional 2007 allows remote attackers to cause a denial of service (NULL dereference and application crash) via unspecified vectors related to &quot;improper arguments.&quot;</descript></desc><loss_types><avail/></loss_types><vuln_types><input buffer="1"/><exception/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/466576/100/0/threaded">20070421 WS_FTP Home 2007 NetscapeFTPHandler denial of service</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/466647/100/0/threaded">20070422 Re: WS_FTP Home 2007 NetscapeFTPHandler denial of service</ref><ref source="BID" url="http://www.securityfocus.com/bid/23584">23584</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33846">
wsftp-netscapeftphandler-dos(33846)</ref></refs><vuln_soft><prod name="WS_FTP" vendor="Ipswitch"><vers edition="Home" num="2007"/><vers edition="Professional" num="2007"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-04-25" name="CVE-2007-2214" published="2007-04-24" seq="2007-2214" severity="High" type="CVE"><desc><descript source="cve">Unrestricted file upload vulnerability in includes/upload_file.php in DmCMS allows remote attackers to upload arbitrary PHP scripts by placing a script&apos;s contents in both the File2 and File3 parameters, and sending a ok.php?do=act Referer.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/466704/100/0/threaded">20070423 DmCMS Shell Uploading</ref><ref source="BID" url="http://www.securityfocus.com/bid/23628">
23628</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1516">
ADV-2007-1516</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2605">2605</ref></refs><vuln_soft><prod name="DmCMS" vendor="DmCMS"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" CVSS_score="9.3" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2008-04-25" name="CVE-2007-2216" published="2007-08-14" seq="2007-2216" severity="High" type="CVE"><desc><descript source="cve">The tblinf32.dll (aka vstlbinf.dll) ActiveX control for Internet Explorer 5.01, 6 SP1, and 7 uses an incorrect IObjectsafety implementation, which allows remote attackers to execute arbitrary code by requesting the HelpString property, involving a crafted DLL file argument to the TypeLibInfoFromFile function, which overwrites the HelpStringDll property to call the DLLGetDocumentation function in another DLL file, aka &quot;ActiveX Object Vulnerability.&quot;</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><other/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/476742/100/0/threaded">20070815 TlbInf32 ActiveX Command Execution</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA07-226A.html">TA07-226A</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/25289">25289</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/2869">ADV-2007-2869</ref><ref source="OSVDB" url="http://www.osvdb.org/36396">36396</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2109">oval:org.mitre.oval:def:2109</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1018562">1018562</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/26419">26419</ref></refs><vuln_soft><prod name="Internet Explorer" vendor="Microsoft"><vers num="5.01"/><vers num="6 SP1"/><vers num="7"/></prod></vuln_soft></entry><entry CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" CVSS_score="9.3" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-12-18" name="CVE-2007-2217" published="2007-10-09" seq="2007-2217" severity="High" type="CVE"><desc><descript source="cve">Kodak Image Viewer in Microsoft Windows 2000 SP4, and in some cases XP SP2 and Server 2003 SP1 and SP2, allows remote attackers to execute arbitrary code via crafted image files that trigger memory corruption, as demonstrated by a certain .tif (TIFF) file.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs><ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms07-055.mspx">MS07-055</ref><ref source="MILW0RM" url="http://milw0rm.com/exploits/4584">4584</ref><ref source="HP" url="http://www.securityfocus.com/archive/1/archive/1/482366/100/0/threaded">HPSBST02280</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA07-282A.html">TA07-282A</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/180345">VU#180345</ref><ref source="BID" url="http://www.securityfocus.com/bid/25909">25909</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/3435">ADV-2007-3435</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1018784">1018784</ref><ref source="SECUNIA" url="http://secunia.com/advisories/27092">27092</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/36799">win-kodak-image-code-execution(36799)</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1481">oval:org.mitre.oval:def:1481</ref></refs><vuln_soft><prod name="Image Viewer" vendor="Kodak"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" CVSS_score="9.3" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-06-13" name="CVE-2007-2218" published="2007-06-12" seq="2007-2218" severity="High" type="CVE"><desc><descript source="cve">Unspecified vulnerability in the Windows Schannel Security Package for Microsoft Windows 2000 SP4, XP SP2, and Server 2003 SP1 and SP2, allows remote servers to execute arbitrary code or cause a denial of service via crafted digital signatures that are processed during an SSL handshake.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><exception/></vuln_types><range><network/><user_init/></range><refs><ref patch="1" source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms07-031.mspx">MS07-031</ref><ref source="HP" url="http://www.securityfocus.com/archive/1/archive/1/471947/100/0/threaded">HPSBST02231</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA07-163A.html">TA07-163A</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/810073">VU#810073</ref><ref source="BID" url="http://www.securityfocus.com/bid/24416">24416</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/2151">ADV-2007-2151</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1895">oval:org.mitre.oval:def:1895</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1018226">1018226</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25620">25620</ref></refs><vuln_soft><prod name="Windows XP" vendor="Microsoft"><vers num="SP2"/></prod><prod name="Windows 2003" vendor="Microsoft"><vers num="SP1"/><vers num="SP2"/></prod><prod name="Windows 2000" vendor="Microsoft"><vers num="SP4"/></prod></vuln_soft></entry><entry CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" CVSS_score="9.3" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-06-14" name="CVE-2007-2219" published="2007-06-12" seq="2007-2219" severity="High" type="CVE"><desc><descript source="cve">Unspecified vulnerability in the Win32 API on Microsoft Windows 2000, XP SP2, and Server 2003 SP1 and SP2 allows remote attackers to execute arbitrary code via certain parameters to an unspecified function.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input/><exception/></vuln_types><range><network/><user_init/></range><refs><ref patch="1" source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms07-035.mspx">MS07-035</ref><ref source="HP" url="http://www.securityfocus.com/archive/1/archive/1/471947/100/0/threaded">HPSBST02231</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA07-163A.html">TA07-163A</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/457281">VU#457281</ref><ref source="BID" url="http://www.securityfocus.com/bid/24370">24370</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/2155">ADV-2007-2155</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1643">oval:org.mitre.oval:def:1643</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1018230">1018230</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25640">25640</ref></refs><vuln_soft><prod name="Windows XP" vendor="Microsoft"><vers num="SP2"/><vers edition="Professional x64" num="Gold"/><vers edition="Professional x64 SP2" num="Gold"/></prod><prod name="Windows 2003" vendor="Microsoft"><vers edition="x64" num=""/><vers edition="x64 SP2" num=""/><vers edition="Itanium" num="SP1"/><vers num="SP1"/><vers num="SP2"/><vers edition="Itanium" num="SP2"/></prod><prod name="Windows 2000" vendor="Microsoft"><vers num="SP4"/></prod></vuln_soft></entry><entry CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" CVSS_score="9.3" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-05-22" name="CVE-2007-2221" published="2007-05-08" seq="2007-2221" severity="High" type="CVE"><desc><descript source="cve">Unspecified vulnerability in the mdsauth.dll COM object in Microsoft Windows Media Server in the Microsoft Internet Explorer 5.01 SP4 on Windows 2000 SP4; 6 SP1 on Windows 2000 SP4; 6 and 7 on Windows XP SP2, or Windows Server 2003 SP1 or SP2; or 7 on Windows Vista allows remote attackers to overwrite arbitrary files via unspecified vectors, aka the &quot;Arbitrary File Rewrite Vulnerability.&quot;</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" patch="1" source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms07-027.mspx">MS07-027</ref><ref source="BID" url="http://www.securityfocus.com/bid/23827">23827</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1712">ADV-2007-1712</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1018019">1018019</ref><ref source="SECUNIA" url="http://secunia.com/advisories/23769">23769</ref><ref source="" url="http://www.fortiguardcenter.com/advisory/FGA-2007-07.html"></ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/500753">VU#500753</ref><ref source="HP" url="http://www.securityfocus.com/archive/1/archive/1/468871/100/200/threaded">HPSBST02214</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA07-128A.html">TA07-128A</ref><ref source="OSVDB" url="http://www.osvdb.org/34404">34404</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1885">oval:org.mitre.oval:def:1885</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33355">ie-msdauth-code-execution(33355)</ref></refs><vuln_soft><prod name="Internet Explorer" vendor="Microsoft"><vers num="5.01 SP4"/><vers num="6 SP1"/><vers num="6.0"/><vers num="7.0"/><vers num="6.0"/><vers num="7.0"/><vers num="7.0"/></prod></vuln_soft></entry><entry CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" CVSS_score="9.3" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-12-27" name="CVE-2007-2222" published="2007-06-12" seq="2007-2222" severity="High" type="CVE"><desc><descript source="cve">Multiple buffer overflows in the (1) ActiveListen (Xlisten.dll) and (2) ActiveVoice (Xvoice.dll) speech controls, as used by Microsoft Internet Explorer 5.01, 6, and 7, allow remote attackers to execute arbitrary code via a crafted ActiveX object that triggers memory corruption, as demonstrated via the ModeName parameter to the FindEngine function in ACTIVEVOICEPROJECTLib.DirectSS.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input bound="1"/><exception/></vuln_types><range><network/><user_init/></range><refs><ref patch="1" source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms07-033.mspx">MS07-033</ref><ref source="" url="http://retrogod.altervista.org/win_speech_2k_sp4.html"></ref><ref source="" url="http://retrogod.altervista.org/win_speech_xp_sp2.html"></ref><ref source="HP" url="http://www.securityfocus.com/archive/1/archive/1/471947/100/0/threaded">HPSBST02231</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA07-163A.html">TA07-163A</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/507433">VU#507433</ref><ref source="BID" url="http://www.securityfocus.com/bid/24426">24426</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/2153">ADV-2007-2153</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2031">oval:org.mitre.oval:def:2031</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1018235">1018235</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/25627">25627</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/34630">ie-speech-code-execution(34630)</ref></refs><vuln_soft><prod name="Internet Explorer" vendor="Microsoft"><vers num="5.01 SP4"/><vers num="6 SP1"/><vers num="6"/><vers num="7.0"/><vers num="6"/><vers num="7.0"/><vers num="7.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="4.9" CVSS_score="5.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:N)" CVSS_version="2.0" modified="2007-12-19" name="CVE-2007-2223" published="2007-08-14" seq="2007-2223" severity="Medium" type="CVE"><desc><descript source="cve">Microsoft XML Core Services (MSXML) 3.0 through 6.0 allows remote attackers to execute arbitrary code via the substringData method on a (1) TextNode or (2) XMLDOM object, which causes an integer overflow that leads to a buffer overflow.</descript></desc><loss_types><conf/><int/></loss_types><vuln_types><other/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" patch="1" source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms07-042.mspx">MS07-042</ref><ref source="IDEFENSE" url="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=576">20070814 Microsoft XML Core Services XMLDOM Memory Corruption Vulnerability</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/476527/100/0/threaded">20070814 ZDI-07-048: Microsoft Internet Explorer substringData() Heap Overflow Vulnerability</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/476747/100/0/threaded">20070816 MS07-042 XMLDOM substringData() PoC</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/361968">VU#361968</ref><ref source="BID" url="http://www.securityfocus.com/bid/25301">25301</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/2866">ADV-2007-2866</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2069">oval:org.mitre.oval:def:2069</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1018559">1018559</ref><ref source="SECUNIA" url="http://secunia.com/advisories/26447">26447</ref></refs><vuln_soft><prod name="XML Core Services" vendor="Microsoft"><vers num="3.0"/><vers num="4.0"/><vers num="6.0"/></prod></vuln_soft></entry><entry CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" CVSS_score="9.3" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-12-19" name="CVE-2007-2224" published="2007-08-14" seq="2007-2224" severity="High" type="CVE"><desc><descript source="cve">Object linking and embedding (OLE) Automation, as used in Microsoft Windows 2000 SP4, XP SP2, Server 2003 SP1 and SP2, Office 2004 for Mac, and Visual Basic 6.0 allows remote attackers to execute arbitrary code via the substringData method on a TextNode object, which causes an integer overflow that leads to a buffer overflow.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><other/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" patch="1" source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms07-043.mspx">MS07-043</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/476527/100/0/threaded">20070814 ZDI-07-048: Microsoft Internet Explorer substringData() Heap Overflow Vulnerability</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA07-226A.html">TA07-226A</ref><ref source="BID" url="http://www.securityfocus.com/bid/25282">25282</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/2867">ADV-2007-2867</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1248">oval:org.mitre.oval:def:1248</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1018560">1018560</ref><ref source="SECUNIA" url="http://secunia.com/advisories/26449">26449</ref></refs><vuln_soft><prod name="Office" vendor="Microsoft"><vers edition="Mac" num="2004"/></prod><prod name="Visual Basic" vendor="Microsoft"><vers num="6.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)" CVSS_version="2.0" modified="2007-06-14" name="CVE-2007-2225" published="2007-06-12" seq="2007-2225" severity="Medium" type="CVE"><desc><descript source="cve">A component in Microsoft Outlook Express 6 and Windows Mail in Windows Vista does not properly handle certain HTTP headers when processing MHTML protocol URLs, which allows remote attackers to obtain sensitive information from other Internet Explorer domains, aka &quot;URL Parsing Cross Domain Information Disclosure Vulnerability.&quot;</descript></desc><loss_types><conf/></loss_types><vuln_types><input/><exception/></vuln_types><range><network/><user_init/></range><refs><ref patch="1" source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms07-034.mspx">MS07-034</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/472002/100/0/threaded">20070622 MS07-034: Executing arbitrary script with mhtml: protocol handler</ref><ref source="" url="http://archive.openmya.devnull.jp/2007.06/msg00060.html"></ref><ref source="" url="http://openmya.hacker.jp/hasegawa/security/ms07-034.txt"></ref><ref source="HP" url="http://www.securityfocus.com/archive/1/archive/1/471947/100/0/threaded">HPSBST02231</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA07-163A.html">TA07-163A</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/682825">VU#682825</ref><ref source="BID" url="http://www.securityfocus.com/bid/24392">24392</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/2154">ADV-2007-2154</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2045">oval:org.mitre.oval:def:2045</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1018231">1018231</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1018232">1018232</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25639">25639</ref></refs><vuln_soft><prod name="Outlook Express" vendor="Microsoft"><vers num="6.0"/></prod><prod name="Windows Mail" vendor="Microsoft"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)" CVSS_version="2.0" modified="2007-06-14" name="CVE-2007-2227" published="2007-06-12" seq="2007-2227" severity="Medium" type="CVE"><desc><descript source="cve">The MHTML protocol handler in Microsoft Outlook Express 6 and Windows Mail in Windows Vista does not properly handle Content-Disposition &quot;notifications,&quot; which allows remote attackers to obtain sensitive information from other Internet Explorer domains, aka &quot;Content Disposition Parsing Cross Domain Information Disclosure Vulnerability.&quot;</descript></desc><loss_types><conf/></loss_types><vuln_types><exception/></vuln_types><range><network/><user_init/></range><refs><ref patch="1" source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms07-034.mspx">MS07-034</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/472002/100/0/threaded">20070622 MS07-034: Executing arbitrary script with mhtml: protocol handler</ref><ref source="" url="http://archive.openmya.devnull.jp/2007.06/msg00060.html"></ref><ref source="" url="http://openmya.hacker.jp/hasegawa/security/ms07-034.txt"></ref><ref source="HP" url="http://www.securityfocus.com/archive/1/archive/1/471947/100/0/threaded">HPSBST02231</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA07-163A.html">TA07-163A</ref><ref source="BID" url="http://www.securityfocus.com/bid/24410">24410</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/2154">ADV-2007-2154</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2085">oval:org.mitre.oval:def:2085</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1018233">1018233</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1018234">1018234</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25639">25639</ref></refs><vuln_soft><prod name="Outlook Express" vendor="Microsoft"><vers num="6.0"/></prod><prod name="Windows Mail" vendor="Microsoft"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.8" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.9" CVSS_score="7.8" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_version="2.0" modified="2007-12-18" name="CVE-2007-2228" published="2007-10-09" seq="2007-2228" severity="High" type="CVE"><desc><descript source="cve">rpcrt4.dll (aka the RPC runtime library) in Microsoft Windows XP SP2, XP Professional x64 Edition, Server 2003 SP1 and SP2, Server 2003 x64 Edition and x64 Edition SP2, and Vista and Vista x64 Edition allows remote attackers to cause a denial of service (RPCSS service stop and system restart) via an RPC request that uses NTLMSSP PACKET authentication with a zero-valued verification trailer signature, which triggers an invalid dereference.  NOTE: this also affects Windows 2000 SP4, although the impact is an information leak.</descript></desc><loss_types><avail/></loss_types><range><network/></range><refs><ref source="MS" url="http://www.microsoft.com/technet/security/Bulletin/MS07-058.mspx">MS07-058</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/482023/100/0/threaded">20071010 ZDI-07-055: Microsoft Windows DCERPC Authentication Denial of Service Vulnerability</ref><ref source="" url="http://www.zerodayinitiative.com/advisories/ZDI-07-055.html"></ref><ref source="HP" url="http://www.securityfocus.com/archive/1/archive/1/482366/100/0/threaded">HPSBST02280</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA07-282A.html">TA07-282A</ref><ref source="BID" url="http://www.securityfocus.com/bid/25974">25974</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/3438">ADV-2007-3438</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1018787">1018787</ref><ref source="SECUNIA" url="http://secunia.com/advisories/27134">27134</ref><ref source="SECUNIA" url="http://secunia.com/advisories/27153">27153</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2310">oval:org.mitre.oval:def:2310</ref></refs><vuln_soft><prod name="windows" vendor="Microsoft"><vers num="2003 Server SP 1"/><vers num="2003 Server SP 2"/><vers num="2003 Server x64"/><vers num="2003 Server x64 SP2"/><vers num="vista"/><vers num="vista x64"/><vers num="xp sp2"/><vers num="2000 sp4"/><vers edition="Professional" num="xp x64"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-12-27" name="CVE-2007-2229" published="2007-06-12" seq="2007-2229" severity="High" type="CVE"><desc><descript source="cve">Microsoft Windows Vista uses insecure default permissions for unspecified &quot;local user information data stores&quot; in the registry and the file system, which allows local users to obtain sensitive information such as administrative passwords, aka &quot;Permissive User Information Store ACLs Information Disclosure Vulnerability.&quot;</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref patch="1" source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms07-032.mspx">MS07-032</ref><ref source="HP" url="http://www.securityfocus.com/archive/1/archive/1/471947/100/0/threaded">HPSBST02231</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA07-163A.html">TA07-163A</ref><ref source="BID" url="http://www.securityfocus.com/bid/24411">24411</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/2152">ADV-2007-2152</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1529">oval:org.mitre.oval:def:1529</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1018225">1018225</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/25623">25623</ref></refs><vuln_soft><prod name="Windows Vista" vendor="Microsoft"><vers edition="x64" num="Gold"/><vers num="Gold"/></prod></vuln_soft></entry><entry CVSS_base_score="6.5" CVSS_exploit_subscore="8.0" CVSS_impact_subscore="6.4" CVSS_score="6.5" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:P)" CVSS_version="2.0" discovered="2007-01-18" modified="2007-08-02" name="CVE-2007-2230" published="2007-04-25" seq="2007-2230" severity="Medium" type="CVE"><desc><descript source="cve">SQL injection vulnerability in CA Clever Path Portal allows remote authenticated users to execute limited SQL commands and retrieve arbitrary database contents via (1) the ofinterest parameter in a light search query, (2) description parameter in the advanced search query, and possibly other vectors.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="FULLDISC" url="http://archives.neohapsis.com/archives/fulldisclosure/2007-04/0648.html">20070424 Security Advisory: CA CleverPath SQL Injection</ref><ref adv="1" source="" url="http://www.hacktics.com/AdvCleverPathApr07.html"></ref><ref source="" url="ftp://ftp.ca.com/pub/portal/4.71/4.71.001_188_070329/readme_4.71.001_188_070329.txt"></ref><ref source="" url="http://supportconnectw.ca.com/public/cp/portal/infodocs/portal-secnot.asp"></ref><ref source="" url="http://www.ca.com/us/securityadvisor/newsinfo/collateral.aspx?cid=136879"></ref><ref source="BID" url="http://www.securityfocus.com/bid/23671">23671</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1544">ADV-2007-1544</ref><ref source="OSVDB" url="http://www.osvdb.org/34128">34128</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25002">25002</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33853">ca-cpp-search-sql-injection(33853)</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017970">1017970</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/466760/100/0/threaded">20070424 Security Advisory: CA CleverPath SQL Injection</ref></refs><vuln_soft><prod name="CleverPath Portal" vendor="CA"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)" CVSS_version="2.0" modified="2007-04-26" name="CVE-2007-2231" published="2007-04-25" seq="2007-2231" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in index/mbox/mbox-storage.c in Dovecot before 1.0.rc29, when using the zlib plugin, allows remote attackers to read arbitrary gzipped (.gz) mailboxes (mbox files) via a .. (dot dot) sequence in the mailbox name.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/466168/100/0/threaded">20070418 rPSA-2007-0074-1 dovecot</ref><ref source="MLIST" url="http://dovecot.org/list/dovecot-cvs/2007-March/008488.html">[dovecot-cvs] 20070330 dovecot/src/lib-storage/index/mbox mbox-storage.c, 1.145.2.14, 1.145.2.15</ref><ref source="MLIST" url="http://dovecot.org/list/dovecot-news/2007-March/000038.html">[dovecot-news] 20070330 Security hole #3: zlib plugin allows opening any gziped mboxes</ref><ref source="" url="http://dovecot.org/doc/NEWS"></ref><ref source="BID" url="http://www.securityfocus.com/bid/23552">23552</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1452">ADV-2007-1452</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2007_8_sr.html">
SUSE-SR:2007:008</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25072">
25072</ref><ref source="DEBIAN" url="http://www.debian.org/security/2007/dsa-1359">DSA-1359</ref><ref source="UBUNTU" url="http://www.ubuntu.com/usn/usn-487-1">USN-487-1</ref></refs><vuln_soft><prod name="Dovecot" vendor="Dovecot"><vers num="1.0.beta1"/><vers num="1.0.beta2"/><vers num="1.0.beta3"/><vers num="1.0.beta4"/><vers num="1.0.beta5"/><vers num="1.0.beta6"/><vers num="1.0.beta7"/><vers num="1.0.beta8"/><vers num="1.0.beta9"/><vers num="1.0.rc1"/><vers num="1.0.rc10"/><vers num="1.0.rc11"/><vers num="1.0.rc12"/><vers num="1.0.rc13"/><vers num="1.0.rc14"/><vers num="1.0.rc15"/><vers num="1.0.rc16"/><vers num="1.0.rc17"/><vers num="1.0.rc18"/><vers num="1.0.rc19"/><vers num="1.0.rc2"/><vers num="1.0.rc20"/><vers num="1.0.rc21"/><vers num="1.0.rc22"/><vers num="1.0.rc23"/><vers num="1.0.rc24"/><vers num="1.0.rc25"/><vers num="1.0.rc26"/><vers num="1.0.rc27"/><vers num="1.0.rc28"/><vers num="1.0.rc3"/><vers num="1.0.rc4"/><vers num="1.0.rc5"/><vers num="1.0.rc6"/><vers num="1.0.rc7"/><vers num="1.0.rc8"/><vers num="1.0.rc9"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-04-26" name="CVE-2007-2232" published="2007-04-25" seq="2007-2232" severity="High" type="CVE"><desc><descript source="cve">The CHECK command in Cosign 2.0.1 and earlier allows remote attackers to bypass authentication requirements via CR (\r) sequences in the cosign cookie parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/465386/100/100/threaded">20070411 Cosign SSO Authentication Bypass</ref><ref adv="1" source="" url="http://www.umich.edu/~umweb/software/cosign/cosign-vuln-2007-001.txt"></ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1359">ADV-2007-1359</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/24845">24845</ref></refs><vuln_soft><prod name="CoSign" vendor="CoSign"><vers num="0.7.0"/><vers num="0.8.0"/><vers num="0.9.0"/><vers num="1.0"/><vers num="1.1"/><vers num="1.5"/><vers num="1.6"/><vers num="1.7"/><vers num="1.8"/><vers num="1.8.5"/><vers num="1.9"/><vers num="2.0.1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.5" CVSS_exploit_subscore="8.0" CVSS_impact_subscore="6.4" CVSS_score="6.5" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-04-26" name="CVE-2007-2233" published="2007-04-25" seq="2007-2233" severity="Medium" type="CVE"><desc><descript source="cve">cosign-bin/cosign.cgi in Cosign 2.0.2 and earlier allows remote authenticated users to perform unauthorized actions as an arbitrary user by using CR (\r) sequences in the service parameter to inject LOGING and REGISTER commands with the desired username.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/465386/100/100/threaded">20070411 Cosign SSO Authentication Bypass</ref><ref adv="1" source="" url="http://www.umich.edu/~umweb/software/cosign/cosign-vuln-2007-002.txt"></ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1359">ADV-2007-1359</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/24845">24845</ref></refs><vuln_soft><prod name="CoSign" vendor="CoSign"><vers num="0.7.0"/><vers num="0.8.0"/><vers num="0.9.0"/><vers num="1.0"/><vers num="1.1"/><vers num="1.5"/><vers num="1.6"/><vers num="1.7"/><vers num="1.8"/><vers num="1.8.5"/><vers num="1.9"/><vers num="2.0.1"/><vers num="2.0.2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-04-26" name="CVE-2007-2234" published="2007-04-25" seq="2007-2234" severity="High" type="CVE"><desc><descript source="cve">include/common.php in PunBB 1.2.14 and earlier does not properly handle a disabled ini_get function when checking the register_globals setting, which allows remote attackers to register global parameters, as demonstrated by an SQL injection attack on the search_id parameter to search.php.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/465400/100/100/threaded">20070411 PunBB &lt;= 1.2.14 Multiple Vulnerabilities (Advisory)</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/465338/100/100/threaded">20070411 PunBB &lt;= 1.2.14 Remote Code Execution (Exploit)</ref><ref source="" url="http://www.acid-root.new.fr/advisories/13070411.txt"></ref><ref source="" url="http://dev.punbb.org/changeset/933"></ref><ref source="SREASON" url="http://securityreason.com/securityalert/2613">2613</ref></refs><vuln_soft><prod name="PunBB" vendor="PunBB"><vers num="1.2.14" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" modified="2007-04-26" name="CVE-2007-2235" published="2007-04-25" seq="2007-2235" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in PunBB 1.2.14 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) Referer HTTP header to misc.php or the (2) category name when deleting a category in admin_categories.php.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/465400/100/100/threaded">20070411 PunBB &lt;= 1.2.14 Multiple Vulnerabilities (Advisory)</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/465338/100/100/threaded">20070411 PunBB &lt;= 1.2.14 Remote Code Execution (Exploit)</ref><ref source="" url="http://www.acid-root.new.fr/advisories/13070411.txt"></ref><ref source="" url="http://dev.punbb.org/changeset/934"></ref><ref source="" url="http://dev.punbb.org/changeset/938"></ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1362">ADV-2007-1362</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/24843">24843</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2613">2613</ref></refs><vuln_soft><prod name="PunBB" vendor="PunBB"><vers num="1.2.14" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-04-26" name="CVE-2007-2236" published="2007-04-25" seq="2007-2236" severity="Medium" type="CVE"><desc><descript source="cve">footer.php in PunBB 1.2.14 and earlier allows remote attackers to include local files in include/user/ via a cross-site scripting (XSS) attack, or via the pun_include tag, as demonstrated by use of admin_options.php to execute PHP code from an uploaded avatar file.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/465400/100/100/threaded">20070411 PunBB &lt;= 1.2.14 Multiple Vulnerabilities (Advisory)</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/465338/100/100/threaded">20070411 PunBB &lt;= 1.2.14 Remote Code Execution (Exploit)</ref><ref adv="1" source="" url="http://www.acid-root.new.fr/advisories/13070411.txt"></ref><ref source="" url="http://dev.punbb.org/changeset/937"></ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1362">ADV-2007-1362</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/24843">24843</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2613">2613</ref></refs><vuln_soft><prod name="PunBB" vendor="PunBB"><vers num="1.2.14" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.1" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.9" CVSS_score="7.1" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:C)" CVSS_version="2.0" modified="2007-06-07" name="CVE-2007-2237" published="2007-06-06" seq="2007-2237" severity="High" type="CVE"><desc><descript source="cve">Microsoft Windows Graphics Device Interface (GDI+, GdiPlus.dll) allows context-dependent attackers to cause a denial of service (crash) via an ICO file with an InfoHeader containing a Height of zero, which triggers a divide-by-zero error.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/><design/><exception/></vuln_types><range><network/></range><refs><ref source="" url="http://www.csis.dk/dk/forside/GdiPlus.pdf"></ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/290961">VU#290961</ref><ref source="BID" url="http://www.securityfocus.com/bid/24346">24346</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/2083">ADV-2007-2083</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/34743">windows-gdi-dos(34743)</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/470746/100/0/threaded">20070607 CSIS Advisory: Microsoft GDI+ Integer division by zero flaw handling .ICO files</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1018202">1018202</ref></refs><vuln_soft><prod name="Windows XP" vendor="Microsoft"><vers num="SP2"/><vers edition="Professional x64" num="SP2" prev="1"/><vers edition="Professional" num="SP2" prev="1"/><vers edition="Tablet PC" num="SP2" prev="1"/><vers edition="Media Center" num="SP2" prev="1"/><vers edition="Home" num="SP2" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" CVSS_score="9.3" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-05-14" name="CVE-2007-2239" published="2007-05-07" seq="2007-2239" severity="High" type="CVE"><desc><descript source="cve">Stack-based buffer overflow in the SaveBMP method in the AXIS Camera Control (aka CamImage) ActiveX control before 2.40.0.0 in AxisCamControl.ocx in AXIS 2100, 2110, 2120, 2130 PTZ, 2420, 2420-IR, 2400, 2400+, 2401, 2401+, 2411, and Panorama PTZ allows remote attackers to cause a denial of service (Internet Explorer crash) or execute arbitrary code via a long argument.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" source="" url="http://www.axis.com/techsup/software/acc/files/acc_security_update_1_00.pdf"></ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/355809">VU#355809</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/25093">25093</ref><ref source="BID" url="http://www.securityfocus.com/bid/23816">
23816</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1663">
ADV-2007-1663</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/34133">
axis-activex-savebmp-bo(34133)</ref></refs><vuln_soft><prod name="AXIS 2110 Network Camera" vendor="Axis Communications"><vers num="2.39" prev="1"/></prod><prod name="AXIS 2130 PTZ Network Camera" vendor="Axis Communications"><vers num="2.39" prev="1"/></prod><prod name="AXIS 2411 Video Server" vendor="Axis Communications"><vers num="2.39" prev="1"/></prod><prod name="AXIS 2420 Network Camera" vendor="Axis Communications"><vers num="2.39" prev="1"/></prod><prod name="AXIS 2401 Video Server" vendor="Axis Communications"><vers num="2.39" prev="1"/></prod><prod name="AXIS 2420-IR Network Camera" vendor="Axis Communications"><vers num="2.39" prev="1"/></prod><prod name="AXIS 2400 Video Server" vendor="Axis Communications"><vers num="2.39" prev="1"/></prod><prod name="AXIS 2400+ Blade Video Server" vendor="Axis Communications"><vers num="2.39" prev="1"/></prod><prod name="AXIS 2120 Network Camera" vendor="Axis Communications"><vers num="2.39" prev="1"/></prod><prod name="AXIS 2400+ Video Server" vendor="Axis Communications"><vers num="2.39" prev="1"/></prod><prod name="AXIS 2100 Network Camera" vendor="Axis Communications"><vers num="2.39" prev="1"/></prod><prod name="AXIS 2401+ Video Server" vendor="Axis Communications"><vers num="2.39" prev="1"/></prod><prod name="AXIS Panorama PTZ Camera" vendor="Axis Communications"><vers num="2.39" prev="1"/></prod><prod name="AXIS 2401+ Blade Video Server" vendor="Axis Communications"><vers num="2.39" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="4.9" CVSS_score="5.8" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:P)" CVSS_version="2.0" modified="2007-08-16" name="CVE-2007-2240" published="2007-08-15" seq="2007-2240" severity="Medium" type="CVE"><desc><descript source="cve">The IBM Lenovo Access Support acpRunner ActiveX control, as distributed in acpcontroller.dll before 1.2.8.0 and possibly acpir.dll before 1.0.0.9 (Automated Solutions 1.0 before fix pack 1), does not properly validate digital signatures of downloaded software, which makes it easier for remote attackers to spoof a download.</descript></desc><loss_types><avail/><int/></loss_types><vuln_types><design/></vuln_types><range><network/><user_init/></range><refs><ref source="" url="http://www-307.ibm.com/pc/support/site.wss/document.do?sitestyle=lenovo&amp;lndocid=MIGR-67649"></ref><ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms07-045.mspx">MS07-045</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/570705">VU#570705</ref><ref source="BID" url="http://www.securityfocus.com/bid/25311">25311</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/2882">ADV-2007-2882</ref><ref source="SECUNIA" url="http://secunia.com/advisories/26482">26482</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/36028">ibm-lenovo-acprunner-code-execution(36028)</ref></refs><vuln_soft><prod name="Access Support" vendor="Lenovo"><vers num=""/></prod><prod name="Automated Solutions" vendor="Lenovo"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.1" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.9" CVSS_score="7.1" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:C)" CVSS_version="2.0" modified="2007-05-04" name="CVE-2007-2241" published="2007-05-02" seq="2007-2241" severity="High" type="CVE"><desc><descript source="cve">Unspecified vulnerability in query.c in ISC BIND 9.4.0, and 9.5.0a1 through 9.5.0a3, when recursion is enabled, allows remote attackers to cause a denial of service (daemon exit) via a sequence of queries processed by the query_addsoa function.</descript></desc><impacts><impact source="nvd">Successful exploitation requires that &quot;recursion&quot; is enabled.</impact></impacts><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref source="" url="http://www.isc.org/index.pl?/sw/bind/bind-security.php"></ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1593">ADV-2007-1593</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017985">1017985</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/25070">25070</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/718460">
VU#718460</ref><ref source="BID" url="http://www.securityfocus.com/bid/23738">
23738</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33988">
bind-queryaddsoa-dos(33988)</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:100">
MDKSA-2007:100</ref></refs><vuln_soft><prod name="BIND" vendor="ISC"><vers num="9.4.0"/><vers num="9.5.0a1"/><vers num="9.5.0a2"/><vers num="9.5.0a3"/></prod></vuln_soft></entry><entry CVSS_base_score="7.8" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.9" CVSS_score="7.8" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_version="2.0" modified="2007-04-26" name="CVE-2007-2242" published="2007-04-25" seq="2007-2242" severity="High" type="CVE"><desc><descript source="cve">The IPv6 protocol allows remote attackers to cause a denial of service via crafted IPv6 type 0 route headers (IPV6_RTHDR_TYPE_0) that create network amplification between two routers.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/><design/></vuln_types><range><network/></range><refs><ref source="" url="http://www.secdev.org/conf/IPv6_RH_security-csw07.pdf"></ref><ref source="OPENBSD" url="http://openbsd.org/errata39.html#022_route6">[3.9] 20070423 012: SECURITY FIX: April 23, 2007</ref><ref source="OPENBSD" url="http://openbsd.org/errata40.html#012_route6">[4.0] 20070423 012: SECURITY FIX: April 23, 2007</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/23615">23615</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/24978">24978</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33851">
openbsd-ipv6-type0-dos(33851)</ref><ref source="FREEBSD" url="http://security.freebsd.org/advisories/FreeBSD-SA-07:03.ipv6.asc">
FreeBSD-SA-07:03.ipv6</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1563">
ADV-2007-1563</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25033">
25033</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25068">
25068</ref><ref source="" url="https://issues.rpath.com/browse/RPL-1310"></ref><ref source="SECUNIA" url="http://secunia.com/advisories/25083">
25083</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2007-0347.html">
RHSA-2007:0347</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25288">
25288</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/471457">20070615 rPSA-2007-0124-1 kernel xen</ref><ref source="" url="http://docs.info.apple.com/article.html?artnum=306375"></ref><ref source="" url="http://docs.info.apple.com/article.html?artnum=305712"></ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:171">MDKSA-2007:171</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:196">MDKSA-2007:196</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:216">MDKSA-2007:216</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2007_51_kernel.html">SUSE-SA:2007:051</ref><ref source="UBUNTU" url="http://www.ubuntu.com/usn/usn-486-1">USN-486-1</ref><ref source="UBUNTU" url="http://www.ubuntu.com/usn/usn-508-1">USN-508-1</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/267289">VU#267289</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/3050">ADV-2007-3050</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/2270">ADV-2007-2270</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017949">1017949</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25691">25691</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25770">25770</ref><ref source="SECUNIA" url="http://secunia.com/advisories/26133">26133</ref><ref source="SECUNIA" url="http://secunia.com/advisories/26651">26651</ref><ref source="SECUNIA" url="http://secunia.com/advisories/26703">26703</ref><ref source="SECUNIA" url="http://secunia.com/advisories/26620">26620</ref><ref source="SECUNIA" url="http://secunia.com/advisories/26664">26664</ref><ref source="SUSE" url="http://lists.opensuse.org/opensuse-security-announce/2008-02/msg00002.html">SUSE-SA:2008:006</ref><ref source="SECUNIA" url="http://secunia.com/advisories/28806">28806</ref></refs><vuln_soft><prod name="IPv6" vendor="IETF"><vers num=""/><vers num=""/><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)" CVSS_version="2.0" modified="2007-04-26" name="CVE-2007-2243" published="2007-04-25" seq="2007-2243" severity="Medium" type="CVE"><desc><descript source="cve">OpenSSH 4.6 and earlier, when ChallengeResponseAuthentication is enabled, allows remote attackers to determine the existence of user accounts by attempting to authenticate via S/KEY, which displays a different response if the user account exists, a similar issue to CVE-2001-1483.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2007-April/053906.html">20070421 OpenSSH - System Account Enumeration if S/Key is used</ref><ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2007-April/053951.html">20070424 OpenSSH - System Account Enumeration if S/Key is used</ref><ref source="BID" url="http://www.securityfocus.com/bid/23601">23601</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33794">openssh-challenge-information-disclosure(33794)</ref><ref source="OSVDB" url="http://www.osvdb.org/34600">
34600</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2631">2631</ref></refs><vuln_soft><prod name="OpenSSH" vendor="OpenBSD"><vers num="1.2"/><vers num="1.2.1"/><vers num="1.2.2"/><vers num="1.2.27"/><vers num="1.2.3"/><vers num="2.1"/><vers num="2.1.1"/><vers num="2.2"/><vers num="2.3"/><vers num="2.5"/><vers num="2.5.1"/><vers num="2.5.2"/><vers num="2.9"/><vers num="2.9.9"/><vers num="2.9.9 p2"/><vers num="2.9 p1"/><vers num="2.9 p2"/><vers num="3.0"/><vers num="3.0 p1"/><vers num="3.0.1"/><vers num="3.0.1 p1"/><vers num="3.0.2"/><vers num="3.0.2 p1"/><vers num="3.1"/><vers num="3.1 p1"/><vers num="3.2"/><vers num="3.2.2"/><vers num="3.2.2 p1"/><vers num="3.2.3 p1"/><vers num="3.3"/><vers num="3.3 p1"/><vers num="3.4"/><vers num="3.4 p1"/><vers num="3.5"/><vers num="3.5 p1"/><vers num="3.6"/><vers num="3.6.1"/><vers num="3.6.1 p1"/><vers num="3.6.1 p2"/><vers num="3.7"/><vers num="3.7.1"/><vers num="3.7.1 p2"/><vers num="3.7.1 p1"/><vers num="3.8"/><vers num="3.8.1"/><vers num="3.8.1 p1"/><vers num="3.9"/><vers num="3.9.1"/><vers num="3.9.1 p1"/><vers num="4.0"/><vers num="4.0 p1"/><vers num="4.1"/><vers num="4.1 p1"/><vers num="4.2"/><vers num="4.2 p1"/><vers num="4.3"/><vers num="4.3 p1"/><vers num="4.4"/><vers num="4.5"/><vers num="4.6"/></prod><prod name="OpenSSH Portable" vendor="OpenBSD"><vers num="4.0.p1"/><vers num="4.1.p1"/><vers num="4.2.p1"/><vers num="4.3.p1"/><vers num="4.3.p2"/><vers num="4.4.p1"/></prod></vuln_soft></entry><entry CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" CVSS_score="9.3" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-12-31" name="CVE-2007-2244" published="2007-04-25" seq="2007-2244" severity="High" type="CVE"><desc><descript source="cve">Multiple buffer overflows in Adobe Photoshop CS2 and CS3, Illustrator CS3, and GoLive 9 allow user-assisted remote attackers to execute arbitrary code via a crafted (1) BMP, (2) DIB, or (3) RLE file.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/><user_init/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3793">3793</ref><ref source="BID" url="http://www.securityfocus.com/bid/23621">23621</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1523">ADV-2007-1523</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/25023">25023</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33838">adobe-multiple-files-bo(33838)</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017962">1017962</ref><ref source="" url="http://www.adobe.com/support/security/bulletins/apsb07-13.html"></ref><ref source="" url="http://www.adobe.com/support/security/bulletins/apsb07-16.html"></ref><ref source="" url="http://www.adobe.com/support/security/bulletins/apsb07-17.html"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/3442">ADV-2007-3442</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/3443">ADV-2007-3443</ref><ref source="OSVDB" url="http://www.osvdb.org/35370">35370</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1018792">1018792</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/26846">26846</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/26864">26864</ref></refs><vuln_soft><prod name="GoLive" vendor="Adobe"><vers num="9"/></prod><prod name="Illustrator" vendor="Adobe"><vers num="CS3"/></prod><prod name="Photoshop" vendor="Adobe"><vers num="CS2"/><vers num="CS3"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-04-26" name="CVE-2007-2245" published="2007-04-25" seq="2007-2245" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin before 2.10.1.0 allow remote attackers to inject arbitrary web script or HTML via (1) the fieldkey parameter to browse_foreigners.php or (2) certain input to the PMA_sanitize function.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://www.phpmyadmin.net/ChangeLog.txt"></ref><ref source="" url="http://www.phpmyadmin.net/home_page/downloads.php?relnotes=0"></ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1508">ADV-2007-1508</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24952">24952</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33898">
phpmyadmin-fieldkey-xss(33898)</ref><ref source="DEBIAN" url="http://www.us.debian.org/security/2007/dsa-1370">DSA-1370</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:199">MDKSA-2007:199</ref><ref source="SECUNIA" url="http://secunia.com/advisories/26733">26733</ref></refs><vuln_soft><prod name="phpMyAdmin" vendor="phpMyAdmin"><vers num="2.10.1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.8" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.9" CVSS_score="7.8" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_version="2.0" modified="2007-08-02" name="CVE-2007-2246" published="2007-04-25" seq="2007-2246" severity="High" type="CVE"><desc><descript source="cve">Unspecified vulnerability in HP-UX B.11.00 and B.11.11, when running sendmail 8.9.3 or 8.11.1; and HP-UX B.11.23 when running sendmail 8.11.1; allows remote attackers to cause a denial of service via unknown attack vectors.  NOTE: due to the lack of details from HP, it is not known whether this issue is a duplicate of another CVE such as CVE-2006-1173 or CVE-2006-4434.</descript></desc><loss_types><avail/></loss_types><range><network/></range><refs><ref source="HP" url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&amp;cc=us&amp;objectID=c00841370">HPSBUX02183</ref><ref source="BID" url="http://www.securityfocus.com/bid/23606">23606</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1504">ADV-2007-1504</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/24990">24990</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017966">1017966</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/349305">VU#349305</ref></refs><vuln_soft><prod name="Sendmail" vendor="Sendmail Consortium"><vers num="8.11.1"/><vers num="8.9.3"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-04-26" name="CVE-2007-2247" published="2007-04-25" seq="2007-2247" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in modules/news/article.php in phpMySpace Gold 8.10 allows remote attackers to execute arbitrary SQL commands via the item_id parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/466706/100/0/threaded">20070422 phpMySpace Gold (v8.10) - Blind SQL/XPath Injection Exploit</ref><ref source="BID" url="http://www.securityfocus.com/bid/23602">23602</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1515">ADV-2007-1515</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33843">
phpmyspace-article-sql-injection(33843)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2616">2616</ref></refs><vuln_soft><prod name="PHPMySpace" vendor="PHPMySpace"><vers edition="Gold" num="8.10"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" modified="2008-02-25" name="CVE-2007-2248" published="2007-04-25" seq="2007-2248" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in admin.php in Phorum before 5.1.22 allow remote attackers to inject arbitrary web script or HTML via the (1) group_id parameter in the groups module or (2) the smiley_id parameter in the smileys modsettings module.</descript></desc><sols><sol source="nvd">This vulnerability is addressed in the following product release:
Phorum, Phorum, 5.1.22</sol></sols><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/466286/100/0/threaded">20070419 [waraxe-2007-SA#049] - Multiple vulnerabilities in Phorum 5.1.20</ref><ref adv="1" patch="1" source="" url="http://www.waraxe.us/advisory-49.html"></ref><ref patch="1" source="" url="http://www.phorum.org/story.php?76"></ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/23616">23616</ref><ref adv="1" patch="1" source="SECTRACK" url="http://www.securitytracker.com/id?1017936">1017936</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/24932">24932</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2617">2617</ref></refs><vuln_soft><prod name="Phorum" vendor="Phorum"><vers num="5.1.21" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.5" CVSS_exploit_subscore="8.0" CVSS_impact_subscore="6.4" CVSS_score="6.5" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-04-26" name="CVE-2007-2249" published="2007-04-25" seq="2007-2249" severity="Medium" type="CVE"><desc><descript source="cve">include/controlcenter/users.php in Phorum before 5.1.22 allows remote authenticated moderators to gain privileges via a modified (1) user_ids POST parameter or (2) userdata array.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/466286/100/0/threaded">20070419 [waraxe-2007-SA#049] - Multiple vulnerabilities in Phorum 5.1.20</ref><ref adv="1" patch="1" source="" url="http://www.waraxe.us/advisory-49.html"></ref><ref source="" url="http://www.phorum.org/story.php?76"></ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/23616">23616</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1479">ADV-2007-1479</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017936">1017936</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/24932">24932</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2617">2617</ref></refs><vuln_soft><prod name="Phorum" vendor="Phorum"><vers num="5.1.20" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0" modified="2007-04-26" name="CVE-2007-2250" published="2007-04-25" seq="2007-2250" severity="Medium" type="CVE"><desc><descript source="cve">admin.php in Phorum before 5.1.22 allows remote attackers to obtain the full path via the module[] parameter.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/466286/100/0/threaded">20070419 [waraxe-2007-SA#049] - Multiple vulnerabilities in Phorum 5.1.20</ref><ref adv="1" patch="1" source="" url="http://www.waraxe.us/advisory-49.html"></ref><ref source="" url="http://www.phorum.org/story.php?76"></ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/23616">23616</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1479">ADV-2007-1479</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017936">1017936</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/24932">24932</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2617">2617</ref></refs><vuln_soft><prod name="Phorum" vendor="Phorum"><vers num="5.1.20" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-04-26" name="CVE-2007-2251" published="2007-04-25" seq="2007-2251" severity="High" type="CVE"><desc><descript source="cve">Unspecified vulnerability in the Roles module in Xaraya 1.1.2 and earlier allows attackers to gain privileges via unspecified vectors, probably related to incorrect permission checking in xartemplates/user-view.xd.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><range><network/></range><refs><ref patch="1" source="" url="http://sourceforge.net/project/shownotes.php?release_id=503035"></ref><ref source="" url="http://www.xaraya.com/index.php/news/772"></ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1522">ADV-2007-1522</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/24959">24959</ref><ref source="BID" url="http://www.securityfocus.com/bid/23631">
23631</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33844">
xaraya-roles-module-security-bypass(33844)</ref></refs><vuln_soft><prod name="Xaraya" vendor="Xaraya"><vers num="1.1.2" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0" modified="2007-04-26" name="CVE-2007-2252" published="2007-04-25" seq="2007-2252" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in iconspopup.php in Exponent CMS 0.96.6 Alpha and earlier allows remote attackers to obtain sensitive information via a .. (dot dot) in the icodir parameter.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://www.bugtraq.ir/articles/advisory/exponent_multiple_vulnerabilities/10"></ref><ref source="BID" url="http://www.securityfocus.com/bid/23574">23574</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24934">24934</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33936">
exponentcms-iconspopup-directory-traversal(33936)</ref></refs><vuln_soft><prod name="Exponent CMS" vendor="Exponent"><vers num="0.96.5 RC1"/><vers num="0.96.6 Alpha"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0" modified="2008-02-25" name="CVE-2007-2253" published="2007-04-25" seq="2007-2253" severity="Medium" type="CVE"><desc><descript source="cve">Exponent CMS 0.96.6 Alpha and earlier allows remote attackers to obtain path information via a direct request for (1) sdk/blanks/formcontrol.php and (2) sdk/blanks/file_modules.php.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="" url="http://www.bugtraq.ir/articles/advisory/exponent_multiple_vulnerabilities/10"></ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33937">exponentcms-multiple-path-disclosure(33937)</ref></refs><vuln_soft><prod name="Exponent CMS" vendor="Exponent"><vers num="0.96.6 Alpha" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-04-26" name="CVE-2007-2254" published="2007-04-25" seq="2007-2254" severity="High" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in admin/setup/level2.php in PHP Classifieds 6.04, and probably earlier versions, allows remote attackers to execute arbitrary PHP code via a URL in the dir parameter.  NOTE: this product was referred to as &quot;Allfaclassfieds&quot; in the original disclosure.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/466648/100/0/threaded">20070422 Allfaclassfieds (level2.php dir) remote file inclusion</ref><ref source="VIM" url="http://www.attrition.org/pipermail/vim/2007-April/001543.html">20070425 [false but true] </ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33798">
allfaclassfieds-level2-file-include(33798)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2618">2618</ref></refs><vuln_soft><prod name="PHP Classifieds" vendor="DeltaScripts"><vers num="6.04"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-04-26" name="CVE-2007-2255" published="2007-04-25" seq="2007-2255" severity="High" type="CVE"><desc><descript source="cve">Multiple PHP remote file inclusion vulnerabilities in Download-Engine 1.4.3 allow remote attackers to execute arbitrary PHP code via a URL in the (1) eng_dir parameter to addmember.php, (2) lang_path parameter to admin/enginelib/class.phpmailer.php, and the (3) spaw_root parameter to admin/includes/spaw/dialogs/colorpicker.php, different vectors than CVE-2006-5291 and CVE-2006-5459.  NOTE: vector 3 might be an issue in SPAW.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/465984/100/100/threaded">20070417 Remot File Include download_engine_V1.4.3</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33723">downloadengine-multiple-file-include(33723)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2619">2619</ref></refs><vuln_soft><prod name="Download-Engine" vendor="Alexscriptengine"><vers num="1.4.3"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" modified="2007-04-26" name="CVE-2007-2256" published="2007-04-25" seq="2007-2256" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in you.php in TJSChat 0.95 allows remote attackers to inject arbitrary web script or HTML via the user parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/466649/100/0/threaded">20070423 TJSChat Version 0.95 Cross Site Scripting</ref><ref source="BID" url="http://www.securityfocus.com/bid/23593">
23593</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1517">
ADV-2007-1517</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24998">
24998</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33845">
tjschat-you-xss(33845)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2620">2620</ref></refs><vuln_soft><prod name="TJSChat" vendor="TJSChat"><vers num="0.95"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-04-26" name="CVE-2007-2257" published="2007-04-25" seq="2007-2257" severity="High" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in subscp.php in Fully Modded phpBB2 allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/466177/100/0/threaded">20070418 FullyModdedphpBB2 Remote File Inclusion</ref><ref source="BID" url="http://www.securityfocus.com/bid/23565">23565</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33751">phpbb2-subscp-file-include(33751)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2621">2621</ref></refs><vuln_soft><prod name="Fully Modded phpBB2" vendor="Fully Modded phpBB"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-04-26" name="CVE-2007-2258" published="2007-04-25" seq="2007-2258" severity="High" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in includes/init.inc.php in PHPMyBibli allows remote attackers to execute arbitrary PHP code via a URL in the base_path parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/466659/100/0/threaded">20070423 PHPMyBibli &lt;= Multiple Remote File Include</ref><ref source="BID" url="http://www.securityfocus.com/bid/23599">
23599</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33808">
phpmybibli-initinc-file-include(33808)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2622">2622</ref></refs><vuln_soft><prod name="PHPmybibli" vendor="PHPmybibli"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-04-26" name="CVE-2007-2259" published="2007-04-25" seq="2007-2259" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in forum.php in EsForum 3.0 allows remote attackers to execute arbitrary SQL commands via the idsalon parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/466663/100/0/threaded">20070422 EsForum &lt;= 3.0 SQL Injection Vulnerability</ref><ref source="BID" url="http://www.securityfocus.com/bid/23605">
23605</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1521">
ADV-2007-1521</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25010">
25010</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33813">
esforum-forum-sql-injection(33813)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2623">2623</ref></refs><vuln_soft><prod name="EsForum" vendor="EsForum"><vers num="3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2008-02-25" name="CVE-2007-2260" published="2007-04-25" seq="2007-2260" severity="High" type="CVE"><desc><descript source="cve">Multiple PHP remote file inclusion vulnerabilities in bibtex mase beta 2.0 allow remote attackers to execute arbitrary PHP code via a URL in the bibtexrootrel parameter to (1) unavailable.php, (2) source.php, (3) log.php, (4) latex.php, (5) indexinfo.php, (6) index.php, (7) importinfo.php, (8) import.php, (9) examplefile.php, (10) clearinfo.php, (11) clear.php, (12) aboutinfo.php, (13) about.php, and other unspecified files.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/466683/100/0/threaded">20070422 bibtex mase Remote File Inclusion</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2624">2624</ref></refs><vuln_soft><prod name="Mase" vendor="Bibtex"><vers num="2.0 Beta"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-04-26" name="CVE-2007-2261" published="2007-04-25" seq="2007-2261" severity="High" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in espaces/communiques/annotations.php in C-Arbre 0.6PR7 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the root_path parameter, a different vector than CVE-2007-1721.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/466682/100/0/threaded">20070422 c-arbre &lt;= Multiple Remote File Include Vulnerablitiy</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33816">
carbre-annotations-file-include(33816)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2625">2625</ref></refs><vuln_soft><prod name="C-Arbre" vendor="Realink"><vers num="0.6 PR7" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-08-02" name="CVE-2007-2262" published="2007-04-25" seq="2007-2262" severity="High" type="CVE"><desc><descript source="cve">Multiple PHP remote file inclusion vulnerabilities in html/php/detail.php in Sinato jmuffin allow remote attackers to execute arbitrary PHP code via a URL in the (1) relPath and (2) folder parameters.  NOTE: this product was originally reported as &quot;File117&quot;.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/466675/100/0/threaded">20070422 File117 Remote File Inclusion</ref><ref source="BID" url="http://www.securityfocus.com/bid/23600">23600</ref><ref source="BID" url="http://www.securityfocus.com/bid/23655">23655</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1520">ADV-2007-1520</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33815">file117-detail-file-include(33815)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2626">2626</ref></refs><vuln_soft><prod name="jmuffin" vendor="Sinato"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" CVSS_score="9.3" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-12-14" name="CVE-2007-2263" published="2007-10-31" seq="2007-2263" severity="High" type="CVE"><desc><descript source="cve">Heap-based buffer overflow in RealNetworks RealPlayer 10.0, 10.1, and possibly 10.5, RealOne Player, and RealPlayer Enterprise allows remote attackers to execute arbitrary code via an SWF (Flash) file with malformed record headers.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/><user_init/></range><refs><ref patch="1" source="" url="http://service.real.com/realplayer/security/10252007_player/en/"></ref><ref source="VIM" url="http://www.attrition.org/pipermail/vim/2007-October/001841.html">20071030 RealPlayer Updates of October 25, 2007</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/26214">26214</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/3628">ADV-2007-3628</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1018866">1018866</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/27361">27361</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/37436">realplayer-swf-bo(37436)</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/483110/100/0/threaded">20071031 ZDI-07-061: RealNetworks RealPlayer SWF Processing Remote Code Execution Vulnerability</ref><ref source="" url="http://www.zerodayinitiative.com/advisories/ZDI-07-061.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/26284">26284</ref></refs><vuln_soft><prod name="RealPlayer" vendor="RealNetworks"><vers edition="unknown" num="10.0"/><vers edition="10.0.0.352" num="10.0"/><vers edition="10.0.0.305" num="10.0"/><vers edition="10.0.0.331" num="10.0"/><vers edition="10.0.9" num="10.0"/><vers edition="10.0.8" num="10.0"/><vers edition="10.0.7" num="10.0"/><vers edition="10.0.6" num="10.0"/><vers edition="10.0.5" num="10.0"/><vers edition="6.0.12.1040" num="10.5"/><vers edition="6.0.12.1578" num="10.5"/><vers edition="6.0.12.1698" num="10.5"/><vers edition="6.0.12.1741" num="10.5"/><vers edition="10.0.0.396" num="10.1"/><vers edition="10.0.0.412" num="10.1"/></prod><prod name="RealPlayer Enterprise" vendor="RealNetworks"><vers edition="unknown" num="unknown"/></prod><prod name="RealOne Player" vendor="RealNetworks"><vers edition="unknown" num="2.0"/><vers edition="unknown" num="unknown"/></prod></vuln_soft></entry><entry CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" CVSS_score="9.3" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-12-14" name="CVE-2007-2264" published="2007-10-31" seq="2007-2264" severity="High" type="CVE"><desc><descript source="cve">Heap-based buffer overflow in RealNetworks RealPlayer 8, 10, 10.1, and possibly 10.5; RealOne Player 1 and 2; and RealPlayer Enterprise allows remote attackers to execute arbitrary code via a RAM (.ra or .ram) file with a large size value in the RA header.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/><user_init/></range><refs><ref patch="1" source="" url="http://service.real.com/realplayer/security/10252007_player/en"></ref><ref source="VIM" url="http://www.attrition.org/pipermail/vim/2007-October/001841.html">20071030 RealPlayer Updates of October 25, 2007</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/26214">26214</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/3628">ADV-2007-3628</ref><ref patch="1" source="SECTRACK" url="http://securitytracker.com/id?1018866">1018866</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/27361">27361</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/37437">realplayer-ram-bo(37437)</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/483113/100/0/threaded">20071031 ZDI-07-063: RealPlayer RA Field Size File Processing Heap Oveflow Vulnerability</ref><ref source="" url="http://www.zerodayinitiative.com/advisories/ZDI-07-063.html"></ref><ref source="" url="http://service.real.com/realplayer/security/10252007_player/en/"></ref></refs><vuln_soft><prod name="RealPlayer" vendor="RealNetworks"><vers edition="unknown" num="10.0"/><vers edition="10.0.0.352" num="10.0"/><vers edition="10.0.0.305" num="10.0"/><vers edition="10.0.0.331" num="10.0"/><vers edition="10.0.9" num="10.0"/><vers edition="10.0.8" num="10.0"/><vers edition="10.0.7" num="10.0"/><vers edition="10.0.6" num="10.0"/><vers edition="10.0.5" num="10.0"/><vers edition="6.0.12.1040" num="10.5"/><vers edition="6.0.12.1578" num="10.5"/><vers edition="6.0.12.1698" num="10.5"/><vers edition="6.0.12.1741" num="10.5"/><vers num="8.0"/><vers edition="10.0.0. 481" num="10.1"/><vers edition="10.0.0.396" num="10.1"/><vers edition="10.0.0.412" num="10.1"/></prod><prod name="RealPlayer Enterprise" vendor="RealNetworks"><vers edition="unknown" num="unknown"/></prod><prod name="RealOne Player" vendor="RealNetworks"><vers edition="unknown" num="2.0"/><vers edition="unknown" num="unknown"/><vers edition="unknown" num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-04-26" name="CVE-2007-2265" published="2007-04-25" seq="2007-2265" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in YA Book 0.98-alpha allows remote attackers to inject arbitrary web script or HTML via the City field in a sign action in index.php.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/466743/100/0/threaded">20070424 YA Book 0.98 Persistent XSS</ref><ref source="BID" url="http://www.securityfocus.com/bid/23626">23626</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33894">
yabook-city-xss(33894)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2629">2629</ref></refs><vuln_soft><prod name="YA Book" vendor="PHPee"><vers num="0.98 alpha"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2008-02-22" name="CVE-2007-2266" published="2007-04-25" seq="2007-2266" severity="High" type="CVE"><desc><descript source="cve">Progress Webspeed Messenger allows remote attackers to read, create, modify, and execute arbitrary files by invoking webutil/_cpyfile.p in the WService parameter to (1) cgiip.exe or (2) wsisa.dll in scripts/, as demonstrated by using the save,editor options to create a new file using the fileName parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/466771/100/0/threaded">20070424 Progress Webspeed exploit for all releases</ref><ref source="BID" url="http://www.securityfocus.com/bid/23634">23634</ref><ref source="" url="http://www.ishare.nl/"></ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24988">24988</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/472574/100/0/threaded">20070629 Re: Re: Progress Webspeed exploit for all releases</ref></refs><vuln_soft><prod name="WebSpeed Messenger" vendor="Progress Software Corp"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.0" CVSS_impact_subscore="6.9" CVSS_score="6.8" CVSS_vector="(AV:N/AC:L/Au:S/C:N/I:N/A:C)" CVSS_version="2.0" modified="2007-04-26" name="CVE-2007-2267" published="2007-04-25" seq="2007-2267" severity="Medium" type="CVE"><desc><descript source="cve">Unspecified vulnerability in Sun Cluster 3.1 and Solaris Cluster 3.2 before 20070424 allows remote authenticated users, operating from a different cluster node, to cause a denial of service (data corruption or send_mondo panic) via unspecified vectors, as demonstrated by EMC Symcli backup software 6.2.1.</descript></desc><loss_types><avail/></loss_types><range><network/></range><refs><ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102874-1">102874</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1530">
ADV-2007-1530</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33858">
cluster-sibling-node-dos(33858)</ref><ref source="BID" url="http://www.securityfocus.com/bid/23638">
23638</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017953">
1017953</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24985">
24985</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1018642">1018642</ref></refs><vuln_soft><prod name="Sun Cluster" vendor="Sun"><vers edition="Solaris 8" num="3.1"/><vers edition="Solaris 9" num="3.1"/><vers edition="Solaris 10" num="3.1"/><vers edition="Solaris 9" num="3.2"/><vers edition="Solaris 10" num="3.2"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0" modified="2007-05-16" name="CVE-2007-2268" published="2007-04-25" seq="2007-2268" severity="Medium" type="CVE"><desc><descript source="cve">Multiple directory traversal vulnerabilities in SWsoft Plesk for Windows 7.6.1, 8.1.0, and 8.1.1 allow remote attackers to read arbitrary files via a .. (dot dot) in the locale_id parameter to (1) login.php3 or (2) login_up.php3.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://forum.swsoft.com/showthread.php?s=&amp;postid=172761#post172761"></ref><ref patch="1" source="" url="http://kb.swsoft.com/en/1798"></ref><ref source="OSVDB" url="http://www.osvdb.org/34081">34081</ref><ref source="OSVDB" url="http://www.osvdb.org/34082">34082</ref><ref source="BID" url="http://www.securityfocus.com/bid/23639">23639</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/25036">25036</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1588">ADV-2007-1588</ref></refs><vuln_soft><prod name="Plesk" vendor="SWsoft"><vers edition="Windows" num="7.6.1"/><vers edition="Windows" num="8.1.0"/><vers edition="Windows" num="8.1.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" modified="2007-04-26" name="CVE-2007-2269" published="2007-04-25" seq="2007-2269" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in top.php3 in SWsoft Plesk for Windows 8.1 and 8.1.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the locale_id parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://forum.swsoft.com/showthread.php?s=&amp;postid=172761#post172761"></ref><ref source="SECUNIA" url="http://secunia.com/advisories/25036">
25036</ref></refs><vuln_soft><prod name="Plesk" vendor="SWsoft"><vers edition="Windows" num="8.1.0"/><vers edition="Windows" num="8.1.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.8" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.9" CVSS_score="7.8" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_version="2.0" modified="2007-04-26" name="CVE-2007-2270" published="2007-04-25" seq="2007-2270" severity="High" type="CVE"><desc><descript source="cve">The Linksys SPA941 VoIP Phone allows remote attackers to cause a denial of service (device reboot) via a 0377 (0xff) character in the From header, and possibly certain other locations, in a SIP INVITE request.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3791">3791</ref><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3792">3792</ref><ref source="BID" url="http://www.securityfocus.com/bid/23619">23619</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1532">
ADV-2007-1532</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33856">
linksys-spa941-sip-dos(33856)</ref><ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2007-April/053959.html">

20070424 Linksys SPA941 remote DOS with \377 character</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017957">
1017957</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25031">
25031</ref></refs><vuln_soft><prod name="SPA941" vendor="Linksys"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="9.4" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="9.2" CVSS_score="9.4" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:N)" CVSS_version="2.0" modified="2007-04-26" name="CVE-2007-2271" published="2007-04-25" seq="2007-2271" severity="High" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in Rajneel Lal TotaRam USP FOSS Distribution 1.01 allows remote attackers to read arbitrary files via a .. (dot dot) in the dnld parameter.</descript></desc><loss_types><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3794">3794</ref><ref source="BID" url="http://www.securityfocus.com/bid/23632">23632</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1527">
ADV-2007-1527</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24957">
24957</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33893">
uspfoss-download-file-include(33893)</ref></refs><vuln_soft><prod name="USP Foss Distribution" vendor="Rajneel Lal TotaRam"><vers num="1.01"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-04-27" name="CVE-2007-2272" published="2007-04-25" seq="2007-2272" severity="High" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in docs/front-end-demo/cart2.php in Advanced Webhost Billing System (AWBS) 2.4.0 allows remote attackers to execute arbitrary PHP code via a URL in the workdir parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3795">3795</ref><ref source="BID" url="http://www.securityfocus.com/bid/23633">23633</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33860">
awbs-cart2-file-include(33860)</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25046">
25046</ref></refs><vuln_soft><prod name="Advanced Webhost Billing System" vendor="Advanced Webhost Billing System"><vers num="2.4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-04-27" name="CVE-2007-2273" published="2007-04-25" seq="2007-2273" severity="High" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in include/loading.php in Alessandro Lulli wavewoo 0.1.1 allows remote attackers to execute arbitrary PHP code via a URL in the path_include parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3796">3796</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/25015">25015</ref><ref source="BID" url="http://www.securityfocus.com/bid/23636">
23636</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1528">
ADV-2007-1528</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33865">
wavewoo-loading-file-include(33865)</ref></refs><vuln_soft><prod name="wavewoo" vendor="Alessandro Lulli"><vers num="0.1.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.8" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.9" CVSS_score="7.8" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_version="2.0" modified="2007-04-27" name="CVE-2007-2274" published="2007-04-25" seq="2007-2274" severity="High" type="CVE"><desc><descript source="cve">The BitTorrent implementation in Opera 9.2 allows remote attackers to cause a denial of service (CPU consumption and application crash) via a malformed torrent file.  NOTE: the original disclosure refers to this to as a memory leak, but it is not certain.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3784">3784</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/34079">opera-bittorrent-dos(34079)</ref></refs><vuln_soft><prod name="Opera" vendor="Opera Software"><vers num="9.2"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-04-27" name="CVE-2007-2275" published="2007-04-25" seq="2007-2275" severity="Medium" type="CVE"><desc><descript source="cve">Unspecified vulnerability in HP StorageWorks Command View Advanced Edition for XP before 5.6.0-01, XP Replication Monitor before 5.6.0-01, and XP Tiered Storage Manager before 5.5.0-02 allows local users to access other accounts via unspecified vectors during registration or addition of new users.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><range><local/></range><refs><ref adv="1" source="HP" url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00911797">HPSBST02200</ref><ref source="BID" url="http://www.securityfocus.com/bid/23630">23630</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1533">
ADV-2007-1533</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25029">
25029</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017959">
1017959</ref></refs><vuln_soft><prod name="HP StorageWorks XP Tiered Storage Manager" vendor="HP"><vers num="1.1_00"/><vers num="5.0_00"/><vers num="5.5_01"/></prod><prod name="StorageWorks XP Replication Monitor" vendor="HP"><vers num="1.1_00"/><vers num="5.0_00"/><vers num="5.5_02"/></prod><prod name="StorageWorks Command View XP" vendor="HP"><vers num="5.0.00"/><vers num="5.1.05"/><vers num="5.5"/><vers num="5.5.02"/></prod></vuln_soft></entry><entry CVSS_base_score="7.8" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.9" CVSS_score="7.8" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_version="2.0" modified="2007-08-02" name="CVE-2007-2276" published="2007-04-25" seq="2007-2276" severity="High" type="CVE"><desc><descript source="cve">** DISPUTED **  3Com TippingPoint IPS allows remote attackers to cause a denial of service (device hang) via a flood of packets on TCP port 80 with sequentially increasing source ports, related to a &quot;badly written loop.&quot;  NOTE: the vendor disputes this issue, stating that the product has &quot;performed as expected with no DoS emerging.&quot;</descript></desc><loss_types><avail/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/466784/100/0/threaded">20070424 3Com&apos;s TippingPoint Denial of Service</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/466795/100/0/threaded">20070424 Re: 3Com&apos;s TippingPoint Denial of Service</ref><ref source="BID" url="http://www.securityfocus.com/bid/23644">23644</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/466891/100/0/threaded">20070425 Re: 3Com&apos;s TippingPoint Denial of Service</ref></refs><vuln_soft><prod name="TippingPoint IPS" vendor="3Com"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-04-27" name="CVE-2007-2277" published="2007-04-25" seq="2007-2277" severity="High" type="CVE"><desc><descript source="cve">Session fixation vulnerability in Plogger allows remote attackers to hijack web sessions by setting the PHPSESSID parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/466772/100/0/threaded">20070424 [MajorSecurity Advisory #46]Plogger - Session fixation Issue</ref><ref source="" url="http://www.majorsecurity.de/index_2.php?major_rls=major_rls46"></ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33863">
plogger-phpsessid-weak-security(33863)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2614">2614</ref></refs><vuln_soft><prod name="Plogger" vendor="Plogger"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-04-27" name="CVE-2007-2278" published="2007-04-25" seq="2007-2278" severity="High" type="CVE"><desc><descript source="cve">Multiple PHP remote file inclusion vulnerabilities in DCP-Portal 6.1.1 allow remote attackers to execute arbitrary PHP code via a URL in (1) the path parameter to library/adodb/adodb.inc.php, (2) the abs_path_editor parameter to library/editor/editor.php, or (3) the cfgfile_to_load parameter to admin/phpMyAdmin/libraries/common.lib.php.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/466783/100/0/threaded">20070424 dcp-portal v611 &gt;&gt; RFi</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33876">
dcpportal-adodb-editor-file-include(33876)</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33878">
dcpportal-common-file-include(33878)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2615">2615</ref></refs><vuln_soft><prod name="DCP-Portal" vendor="DCP-Portal"><vers num="6.1.1"/></prod></vuln_soft></entry><entry CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" CVSS_score="9.3" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-12-28" name="CVE-2007-2279" published="2007-06-04" seq="2007-2279" severity="High" type="CVE"><desc><descript source="cve">The Scheduler Service (VxSchedService.exe) in Symantec Storage Foundation for Windows 5.0 allows remote attackers to bypass authentication and execute arbitrary code via certain requests to the service socket that create (1) PreScript or (2) PostScript registry values under Veritas\VxSvc\CurrentVersion\Schedules specifying future command execution.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><access/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" patch="1" source="" url="http://www.symantec.com/avcenter/security/Content/2007.06.01.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/24194">24194</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/470562/100/0/threaded">20070605 TPTI-07-08: Symantec Veritas Storage Foundation Scheduler Service Authentication Bypass Vulnerability</ref><ref source="" url="http://seer.entsupport.symantec.com/docs/288627.htm"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/2035">ADV-2007-2035</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1018188">1018188</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/25537">25537</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/34680">symantec-scheduler-security-bypass(34680)</ref></refs><vuln_soft><prod name="Veritas Storage Foundation" vendor="Symantec"><vers edition="Windows" num="5.0"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-04-27" name="CVE-2007-2282" published="2007-04-26" seq="2007-2282" severity="High" type="CVE"><desc><descript source="cve">Cisco Network Services (CNS) NetFlow Collection Engine (NFC) before 6.0 has an nfcuser account with the default password nfcuser, which allows remote attackers to modify the product configuration and, when installed on Linux, obtain login access to the host operating system.</descript></desc><sols><sol source="nvd">The vendor has addressed this issue through the update 6.0.0 of the NetFlow Collection Engine. </sol></sols><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="CISCO" url="http://www.cisco.com/en/US/products/products_security_advisory09186a008082c520.shtml">20070425 Default Passwords in NetFlow Collection Engine</ref><ref source="BID" url="http://www.securityfocus.com/bid/23647">23647</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1545">ADV-2007-1545</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1017960">1017960</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33861">cisco-nfc-default-password(33861)</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/127545">VU#127545</ref><ref source="OSVDB" url="http://www.osvdb.org/35524">35524</ref></refs><vuln_soft><prod name="Netflow Collection Engine" vendor="Cisco"><vers num="1.0"/><vers num="2.0"/><vers num="3.0"/><vers num="3.5"/><vers num="3.6"/><vers num="4.0"/><vers num="5.0"/><vers num="5.0.3"/></prod></vuln_soft></entry><entry CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" CVSS_score="9.3" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-06-27" name="CVE-2007-2283" published="2007-04-26" seq="2007-2283" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in Fresh View 7.15 allows user-assisted remote attackers to execute arbitrary code via a crafted .PSP file.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/><user_init/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3798">3798</ref><ref source="BID" url="http://www.securityfocus.com/bid/23660">23660</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1543">ADV-2007-1543</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25054">25054</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33866">freshview-psp-bo(33866)</ref></refs><vuln_soft><prod name="FreshView" vendor="FreshDevices"><vers num="7.15"/></prod></vuln_soft></entry><entry CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" CVSS_score="9.3" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-04-27" name="CVE-2007-2284" published="2007-04-26" seq="2007-2284" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in ABC-View Manager 1.42 allows user-assisted remote attackers to execute arbitrary code via a crafted .PSP file.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/><user_init/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3797">3797</ref><ref source="BID" url="http://www.securityfocus.com/bid/23653">23653</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1542">ADV-2007-1542</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25055">
25055</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33862">
abcviewmanager-psp-bo(33862)</ref></refs><vuln_soft><prod name="ABC-View Manager" vendor="ABC-View"><vers num="1.42"/></prod></vuln_soft></entry><entry CVSS_base_score="7.8" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.9" CVSS_score="7.8" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:N/A:N)" CVSS_version="2.0" modified="2007-04-27" name="CVE-2007-2285" published="2007-04-26" seq="2007-2285" severity="High" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in examples/layout/feed-proxy.php in Jack Slocum Ext 1.0 alpha1 (Ext JS) allows remote attackers to read arbitrary files via a .. (dot dot) in the feed parameter.  NOTE: analysis by third party researchers indicates that this issue might be platform dependent.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3800">3800</ref><ref source="VIM" url="http://attrition.org/pipermail/vim/2007-April/001545.html">20070426 False: ext 1.0 alpha1 (feed-proxy.php) Remote File Disclosure</ref><ref source="VIM" url="http://attrition.org/pipermail/vim/2007-April/001546.html">20070426 Re: False: ext 1.0 alpha1 (feed-proxy.php) Remote File Disclosure</ref><ref source="VIM" url="http://attrition.org/pipermail/vim/2007-April/001549.html">20070426 re: False: ext 1.0 alpha1 (feed-proxy.php) Remote File Disclosure</ref><ref source="BID" url="http://www.securityfocus.com/bid/23643">23643</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33864">
ext-feedproxy-directory-traversal(33864)</ref></refs><vuln_soft><prod name="Ext JS" vendor="Jack Slocum"><vers num="1.0 alpha1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-04-27" name="CVE-2007-2286" published="2007-04-26" seq="2007-2286" severity="High" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in config.php in Built2Go PHP Link Portal 1.79 allows remote attackers to execute arbitrary PHP code via a URL in the full_path_to_db parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/466865/100/0/thread">20070425 Built2Go_PHP_Link_Portal_v1.79 &gt;&gt; RFI</ref><ref source="BID" url="http://www.securityfocus.com/bid/23651">23651</ref></refs><vuln_soft><prod name="PHP Link Portal" vendor="Built2Go"><vers num="1.79"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-04-27" name="CVE-2007-2287" published="2007-04-26" seq="2007-2287" severity="High" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in accept.php in comus 2.0 Final allows remote attackers to execute arbitrary PHP code via a URL in the DOCUMENT_ROOT parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/466870/100/0/threaded">20070425 comus 2.0 Final &gt;&gt; RFI</ref><ref source="BID" url="http://www.securityfocus.com/bid/23661">23661</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33870">
comus-accept-file-include(33870)</ref><ref source="OSVDB" url="http://www.osvdb.org/34168">
34168</ref></refs><vuln_soft><prod name="Comus" vendor="Comus"><vers num="2.0 Final" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-04-27" name="CVE-2007-2288" published="2007-04-26" seq="2007-2288" severity="High" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in info.php in Doruk100.net doruk100net allows remote attackers to execute arbitrary PHP code via a URL in the file parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/466842/100/0/threaded">20070425 :doruk100net &gt;&gt; RFI</ref><ref source="BID" url="http://www.securityfocus.com/bid/23675">
23675</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33923">
doruk100net-info-file-include(33923)</ref></refs><vuln_soft><prod name="Doruk100net" vendor="Doruk100.net"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-04-27" name="CVE-2007-2289" published="2007-04-26" seq="2007-2289" severity="High" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in admin/includes/spaw/dialogs/insert_link.php in download engine (Download-Engine) 1.4.1 allows remote authenticated users to execute arbitrary PHP code via a URL in the spaw_root parameter, a different vector than CVE-2007-2255.  NOTE: this may be an issue in SPAW.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/466890/100/0/threaded">20070425 download engine V1.4.1 &gt;&gt; RFI (local)</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33918">
downloadengine-insertlink-file-include(33918)</ref></refs><vuln_soft><prod name="Download-Engine" vendor="Alexscriptengine"><vers num="1.4.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-04-27" name="CVE-2007-2290" published="2007-04-26" seq="2007-2290" severity="High" type="CVE"><desc><descript source="cve">Multiple PHP remote file inclusion vulnerabilities in B2 Weblog and News Publishing Tool 0.6.1 allow remote attackers to execute arbitrary PHP code via a URL in the b2inc parameter to (1) b2archives.php, (2) b2categories.php, or (3) b2mail.php.  NOTE: this may overlap CVE-2002-1466.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/466860/100/0/threaded">20070425 B2 Weblog and News Publishing Tool v0.6.1 &gt;&gt; RFI</ref><ref source="BID" url="http://www.securityfocus.com/bid/23659">23659</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33884">
b2-b2inc-file-include(33884)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2632">2632</ref></refs><vuln_soft><prod name="b2" vendor="CafeLog"><vers num="0.6.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-08-02" name="CVE-2007-2291" published="2007-04-26" seq="2007-2291" severity="High" type="CVE"><desc><descript source="cve">CRLF injection vulnerability in the Digest Authentication support for Microsoft Internet Explorer 7.0.5730.11 allows remote attackers to conduct HTTP response splitting attacks via a LF (%0a) in the username attribute.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/466906/100/0/threaded">20070425 IE 7 and Firefox Browsers Digest Authentication Request Splitting</ref><ref adv="1" source="" url="http://www.wisec.it/vulns.php?id=11"></ref><ref source="BID" url="http://www.securityfocus.com/bid/23668">23668</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017969">1017969</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2654">2654</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33978">ie-lf-response-splitting(33978)</ref></refs><vuln_soft><prod name="Internet Explorer" vendor="Microsoft"><vers num="7.0.5730.11"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" modified="2008-01-17" name="CVE-2007-2292" published="2007-04-26" seq="2007-2292" severity="Medium" type="CVE"><desc><descript source="cve">CRLF injection vulnerability in the Digest Authentication support for Mozilla Firefox before 2.0.0.8 and SeaMonkey before 1.1.5 allows remote attackers to conduct HTTP request splitting attacks via LF (%0a) bytes in the username attribute.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/466906/100/0/threaded">20070425 IE 7 and Firefox Browsers Digest Authentication Request Splitting</ref><ref source="" url="http://www.wisec.it/vulns.php?id=11"></ref><ref source="BID" url="http://www.securityfocus.com/bid/23668">23668</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017968">1017968</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/482925/100/0/threaded">20071029 FLEA-2007-0062-1 firefox</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/482876/100/200/threaded">20071026 rPSA-2007-0225-1 firefox</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/482932/100/200/threaded">20071029 rPSA-2007-0225-2 firefox thunderbird</ref><ref source="" url="https://bugzilla.mozilla.org/show_bug.cgi?id=378787"></ref><ref source="" url="http://www.mozilla.org/security/announce/2007/mfsa2007-31.html"></ref><ref source="" url="https://issues.rpath.com/browse/RPL-1858"></ref><ref source="" url="http://support.novell.com/techcenter/psdb/60eb95b75c76f9fbfcc9a89f99cd8f79.html"></ref><ref source="DEBIAN" url="http://www.debian.org/security/2007/dsa-1396">DSA-1396</ref><ref source="DEBIAN" url="http://www.debian.org/security/2007/dsa-1401">DSA-1401</ref><ref source="DEBIAN" url="http://www.debian.org/security/2007/dsa-1392">DSA-1392</ref><ref source="FEDORA" url="https://www.redhat.com/archives/fedora-package-announce/2007-October/msg00285.html">FEDORA-2007-2601</ref><ref source="FEDORA" url="https://www.redhat.com/archives/fedora-package-announce/2007-October/msg00355.html">FEDORA-2007-2664</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200711-14.xml">GLSA-200711-14</ref><ref source="MANDRIVA" url="http://www.mandriva.com/en/security/advisories?name=MDKSA-2007:202">MDKSA-2007:202</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2007-0979.html">RHSA-2007:0979</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2007-0980.html">RHSA-2007:0980</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2007-0981.html">RHSA-2007:0981</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2007_57_mozilla.html">SUSE-SA:2007:057</ref><ref source="UBUNTU" url="http://www.ubuntulinux.org/support/documentation/usn/usn-535-1">USN-535-1</ref><ref source="UBUNTU" url="http://www.ubuntu.com/usn/usn-536-1">USN-536-1</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/3544">ADV-2007-3544</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/27276">27276</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/27325">27325</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/27327">27327</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/27335">27335</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/27356">27356</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/27383">27383</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/27425">27425</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/27403">27403</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/27480">27480</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/27387">27387</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/27298">27298</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/27311">27311</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/27315">27315</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/27336">27336</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/27665">27665</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/27414">27414</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2654">2654</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33981">firefox-lf-response-splitting(33981)</ref><ref source="FEDORA" url="https://www.redhat.com/archives/fedora-package-announce/2007-November/msg00498.html">FEDORA-2007-3431</ref><ref source="SECUNIA" url="http://secunia.com/advisories/27680">27680</ref><ref source="HP" url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00771742">HPSBUX02153</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/3587">ADV-2007-3587</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/0083">ADV-2008-0083</ref><ref source="SECUNIA" url="http://secunia.com/advisories/27360">27360</ref><ref source="SECUNIA" url="http://secunia.com/advisories/28398">28398</ref><ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-66-201516-1">201516</ref></refs><vuln_soft><prod name="Internet Explorer" vendor="Microsoft"><vers num="7.0.5730.11"/></prod><prod name="SeaMonkey" vendor="Mozilla"><vers num="1.1.5" prev="1"/></prod><prod name="Firefox" vendor="Mozilla"><vers num="2.0.0.8" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="10.0" CVSS_score="7.6" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-07-10" name="CVE-2007-2293" published="2007-04-26" seq="2007-2293" severity="High" type="CVE"><desc><descript source="cve">Multiple stack-based buffer overflows in the process_sdp function in chan_sip.c of the SIP channel T.38 SDP parser in Asterisk before 1.4.3 allow remote attackers to execute arbitrary code via a long (1) T38FaxRateManagement or (2) T38FaxUdpEC SDP parameter in an SIP message, as demonstrated using SIP INVITE.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33895">asterisk-processsdp-bo(33895)</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/472804/100/0/threaded">20070704 Multiple Remote unauthenticated stack overflows in Asterisk chan_sip.c</ref><ref source="OSVDB" url="http://www.osvdb.org/35368">35368</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1018337">1018337</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2645">2645</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/466883/100/0/threaded">20070425 ASA-2007-010: Two stack buffer overflows in SIP channel&apos;s T.38 SDP parsing code</ref><ref source="" url="http://www.asterisk.org/files/ASA-2007-010.pdf"></ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/23648">23648</ref><ref patch="1" source="SECTRACK" url="http://www.securitytracker.com/id?1017951">1017951</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/24977">24977</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1534">ADV-2007-1534</ref></refs><vuln_soft><prod name="Asterisk" vendor="Asterisk"><vers num="1.4 Beta"/><vers num="1.4.1"/><vers num="1.4.2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.8" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.9" CVSS_score="7.8" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_version="2.0" modified="2007-04-27" name="CVE-2007-2294" published="2007-04-26" seq="2007-2294" severity="High" type="CVE"><desc><descript source="cve">The Manager Interface in Asterisk before 1.2.18 and 1.4.x before 1.4.3 allows remote attackers to cause a denial of service (crash) by using MD5 authentication to authenticate a user that does not have a password defined in manager.conf, resulting in a NULL pointer dereference.</descript></desc><impacts><impact source="nvd">Successful exploitation requires that the Management Interface is enabled and a user without a password is configured in the manager.conf file.</impact></impacts><loss_types><avail/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/466911/100/0/threaded">20070425 ASA-2007-012: Remote Crash Vulnerability in Manager Interface</ref><ref source="" url="http://www.asterisk.org/files/ASA-2007-012.pdf"></ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017955">1017955</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/24977">24977</ref><ref source="BID" url="http://www.securityfocus.com/bid/23649">
23649</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1534">
ADV-2007-1534</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33886">
asterisk-interface-dos(33886)</ref><ref source="DEBIAN" url="http://www.debian.org/security/2007/dsa-1358">DSA-1358</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2007_34_asterisk.html">SUSE-SA:2007:034</ref><ref source="OSVDB" url="http://www.osvdb.org/35369">35369</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25582">25582</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2646">2646</ref></refs><vuln_soft><prod name="Asterisk" vendor="Asterisk"><vers num="1.2.0 Beta1"/><vers num="1.2.0 Beta2"/><vers num="1.2.10"/><vers num="1.2.11"/><vers num="1.2.12"/><vers num="1.2.13"/><vers num="1.2.14"/><vers num="1.2.15"/><vers num="1.2.16"/><vers num="1.2.17"/><vers num="1.2.5"/><vers num="1.2.6"/><vers num="1.2.7"/><vers num="1.2.8"/><vers num="1.2.9"/><vers num="1.4 Beta"/><vers num="1.4.1"/><vers num="1.4.2"/></prod></vuln_soft></entry><entry CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" CVSS_score="9.3" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-12-31" name="CVE-2007-2295" published="2007-04-26" seq="2007-2295" severity="High" type="CVE"><desc><descript source="cve">Heap-based buffer overflow in the JVTCompEncodeFrame function in Apple Quicktime 7.1.5 and other versions before 7.2 allows remote attackers to execute arbitrary code via a crafted H.264 MOV file.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" source="" url="http://security-protocols.com/sp-x45-advisory.php"></ref><ref source="BID" url="http://www.securityfocus.com/bid/23650">23650</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017965">1017965</ref><ref source="" url="http://docs.info.apple.com/article.html?artnum=305947"></ref><ref source="APPLE" url="http://lists.apple.com/archives/Security-announce/2007/Jul/msg00001.html">APPLE-SA-2007-07-11</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA07-193A.html">TA07-193A</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/2510">ADV-2007-2510</ref><ref source="OSVDB" url="http://www.osvdb.org/35577">35577</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1018373">1018373</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/26034">26034</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/35356">quicktime-h264-code-execution(35356)</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/34070">quicktime-jvtcompencodeframe-bo(34070)</ref></refs><vuln_soft><prod name="Quicktime" vendor="Apple"><vers num="7.1"/><vers num="7.1.1"/><vers num="7.1.2"/><vers num="7.1.3"/><vers num="7.1.4"/><vers num="7.1.5"/></prod></vuln_soft></entry><entry CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" CVSS_score="9.3" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-12-31" name="CVE-2007-2296" published="2007-04-26" seq="2007-2296" severity="High" type="CVE"><desc><descript source="cve">Integer overflow in the FlipFileTypeAtom_BtoN function in Apple Quicktime 7.1.5, and other versions before 7.2, allows remote attackers to execute arbitrary code via a crafted M4V (MP4) file.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" source="" url="http://security-protocols.com/sp-x46-advisory.php"></ref><ref source="BID" url="http://www.securityfocus.com/bid/23652">23652</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017967">1017967</ref><ref source="" url="http://docs.info.apple.com/article.html?artnum=305947"></ref><ref source="APPLE" url="http://lists.apple.com/archives/Security-announce/2007/Jul/msg00001.html">APPLE-SA-2007-07-11</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA07-193A.html">TA07-193A</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/2510">ADV-2007-2510</ref><ref source="OSVDB" url="http://www.osvdb.org/35578">35578</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1018373">1018373</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/26034">26034</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/34069">quicktime-flipfiletypeatombton-overflow(34069)</ref></refs><vuln_soft><prod name="Quicktime" vendor="Apple"><vers num="7.1"/><vers num="7.1.1"/><vers num="7.1.2"/><vers num="7.1.3"/><vers num="7.1.4"/><vers num="7.1.5"/></prod></vuln_soft></entry><entry CVSS_base_score="7.8" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.9" CVSS_score="7.8" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_version="2.0" modified="2007-04-27" name="CVE-2007-2297" published="2007-04-26" seq="2007-2297" severity="High" type="CVE"><desc><descript source="cve">The SIP channel driver (chan_sip) in Asterisk before 1.2.18 and 1.4.x before 1.4.3 does not properly parse SIP UDP packets that do not contain a valid response code, which allows remote attackers to cause a denial of service (crash).</descript></desc><loss_types><avail/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/466882/100/0/threaded">20070425 ASA-2007-011: Multiple problems in SIP channel parser handling response codes</ref><ref source="" url="http://bugs.digium.com/view.php?id=9313"></ref><ref source="" url="http://www.asterisk.org/files/ASA-2007-011.pdf"></ref><ref patch="1" source="SECTRACK" url="http://www.securitytracker.com/id?1017954">1017954</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33892">
asterisk-sip-response-dos(33892)</ref><ref source="DEBIAN" url="http://www.debian.org/security/2007/dsa-1358">DSA-1358</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2007_34_asterisk.html">SUSE-SA:2007:034</ref><ref source="BID" url="http://www.securityfocus.com/bid/24359">24359</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25582">25582</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2644">2644</ref></refs><vuln_soft><prod name="Asterisk" vendor="Asterisk"><vers num="1.2.0 Beta1"/><vers num="1.2.0 Beta2"/><vers num="1.2.10"/><vers num="1.2.11"/><vers num="1.2.12"/><vers num="1.2.13"/><vers num="1.2.14"/><vers num="1.2.15"/><vers num="1.2.16"/><vers num="1.2.17"/><vers num="1.4 Beta"/><vers num="1.4.1"/><vers num="1.4.2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-04-27" name="CVE-2007-2298" published="2007-04-26" seq="2007-2298" severity="High" type="CVE"><desc><descript source="cve">Multiple PHP remote file inclusion vulnerabilities in Garennes 0.6.1 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the repertoire_config parameter to index.php in (1) cpe/, (2) direction/, or (3) professeurs/.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3732">3732</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/23479">23479</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1389">ADV-2007-1389</ref></refs><vuln_soft><prod name="Garennes" vendor="GForge"><vers num="0.6.1" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-04-27" name="CVE-2007-2299" published="2007-04-26" seq="2007-2299" severity="High" type="CVE"><desc><descript source="cve">Multiple SQL injection vulnerabilities in Frogss CMS 0.7 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) dzial parameter to (a) katalog.php, or the (2) t parameter to (b) forum.php or (c) forum/viewtopic.php, different vectors than CVE-2006-4536.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3731">3731</ref><ref source="BID" url="http://www.securityfocus.com/bid/23476">23476</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1388">ADV-2007-1388</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33640">frogsscms-katalog-sql-injection(33640)</ref></refs><vuln_soft><prod name="Frogss CMS" vendor="Frogss"><vers num="0.7" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" modified="2007-04-27" name="CVE-2007-2300" published="2007-04-26" seq="2007-2300" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Endy Kristanto Surat kabar / News Management Online (aka phpwebnews) 0.2 and earlier allow remote attackers to inject arbitrary web script or HTML via the m_txt parameter to (1) iklan.php, (2) index.php, or (3) bukutamu.php.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/465545/100/0/threaded">20070412 phpwebnews v.1 Multiple Cross Site Scripting Vulnerabilites</ref><ref source="BID" url="http://www.securityfocus.com/bid/23448">23448</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33641">phpwebnews-mtxt-xss(33641)</ref><ref source="OSVDB" url="http://www.osvdb.org/35365">35365</ref><ref source="OSVDB" url="http://www.osvdb.org/35366">35366</ref><ref source="OSVDB" url="http://www.osvdb.org/35367">35367</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2643">2643</ref></refs><vuln_soft><prod name="phpwebnews" vendor="Surat kabar"><vers num="0.1"/><vers num="0.2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-04-27" name="CVE-2007-2301" published="2007-04-26" seq="2007-2301" severity="High" type="CVE"><desc><descript source="cve">Multiple PHP remote file inclusion vulnerabilities in audioCMS arash 0.1.4 allow remote attackers to execute arbitrary PHP code via a URL in the arashlib_dir parameter to (1) edit.inc.php and (2) list_features.inc.php in arash_lib/include, and (3) arash_gadmin.class.php and (4) arash_sadmin.class.php in arash_lib/class/.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3744">3744</ref><ref source="BID" url="http://www.securityfocus.com/bid/23496">23496</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1396">ADV-2007-1396</ref></refs><vuln_soft><prod name="AudioCMS" vendor="Arash"><vers num="0.1.4"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-04-27" name="CVE-2007-2302" published="2007-04-26" seq="2007-2302" severity="High" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in autoindex.php in Expow 0.8 allows remote attackers to execute arbitrary PHP code via a URL in the cfg_file parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3722">3722</ref><ref source="BID" url="http://www.securityfocus.com/bid/23464">23464</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33619">expow-autoindex-file-include(33619)</ref></refs><vuln_soft><prod name="Expow" vendor="Expow"><vers num="0.8"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-04-27" name="CVE-2007-2303" published="2007-04-26" seq="2007-2303" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in includes/footer.php in News Manager Deluxe (NMDeluxe) 1.0.1 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the template parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MILW0RM" url="http://milw0rm.com/exploits/3742">3742</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1395">ADV-2007-1395</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24896">24896</ref></refs><vuln_soft><prod name="News Manager Deluxe" vendor="News Manager Deluxe"><vers num="1.0.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-04-27" name="CVE-2007-2304" published="2007-04-26" seq="2007-2304" severity="High" type="CVE"><desc><descript source="cve">Multiple directory traversal vulnerabilities in Quick and Dirty Blog (QDBlog) 0.4, and possibly earlier, allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the theme parameter to categories.php and other unspecified files.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3729">3729</ref><ref source="BID" url="http://www.securityfocus.com/bid/23485">23485</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1387">ADV-2007-1387</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33634">qdblog-categories-file-include(33634)</ref></refs><vuln_soft><prod name="QDBlog" vendor="QDBlog"><vers num="0.4" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-04-27" name="CVE-2007-2305" published="2007-04-26" seq="2007-2305" severity="High" type="CVE"><desc><descript source="cve">Multiple SQL injection vulnerabilities in authenticate.php in Quick and Dirty Blog (QDBlog) 0.4, and possibly earlier, allow remote attackers to execute arbitrary SQL commands via the (1) username and (2) password parameters.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3729">3729</ref><ref source="BID" url="http://www.securityfocus.com/bid/23485">23485</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1387">ADV-2007-1387</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33631">qdblog-login-sql-injection(33631)</ref></refs><vuln_soft><prod name="QDBlog" vendor="QDBlog"><vers num="0.4" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" modified="2007-04-27" name="CVE-2007-2306" published="2007-04-26" seq="2007-2306" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in the Virtual War (VWar) 1.5.0 R15 and earlier module for PHP-Nuke, when register_globals is enabled, allow remote attackers to inject arbitrary web script or HTML via the (1) memberlist parameter to extra/login.php and the (2) title parameter to extra/today.php.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/465612/100/0/threaded">20070413 [waraxe-2007-SA#048] - Multiple vulnerabilities in Virtual War 1.5 module for PhpNuke</ref><ref source="" url="http://www.waraxe.us/advisory-48.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/23478">23478</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33647">vwar-login-today-xss(33647)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2642">2642</ref></refs><vuln_soft><prod name="Virtual War" vendor="VWar"><vers num="1.5.0 R15" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-04-27" name="CVE-2007-2307" published="2007-04-26" seq="2007-2307" severity="High" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in engine/engine.inc.php in WebKalk2 1.9.0 allows remote attackers to execute arbitrary PHP code via a URL in the absolute_path parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3717">3717</ref><ref source="BID" url="http://www.securityfocus.com/bid/23451">23451</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1385">ADV-2007-1385</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33598">webkalk2-engine-file-include(33598)</ref></refs><vuln_soft><prod name="WebKalk2" vendor="WebKalk2"><vers num="1.9.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" modified="2007-04-27" name="CVE-2007-2308" published="2007-04-26" seq="2007-2308" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in cas.php in FloweRS 2.0 allows remote attackers to inject arbitrary web script or HTML via the rok parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/465730/100/0/threaded">20070414 FloweRS v2.0 Cross Site Scripting</ref><ref source="BID" url="http://www.securityfocus.com/bid/23488">23488</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1402">ADV-2007-1402</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2639">2639</ref></refs><vuln_soft><prod name="FloweRS" vendor="FloweRS"><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" modified="2007-04-27" name="CVE-2007-2309" published="2007-04-26" seq="2007-2309" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in cas.php in FloweRS 2.0 allows remote attackers to inject arbitrary web script or HTML via the den parameter.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1402">ADV-2007-1402</ref></refs><vuln_soft><prod name="FloweRS" vendor="FloweRS"><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" modified="2007-04-27" name="CVE-2007-2310" published="2007-04-26" seq="2007-2310" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in plugins/spaw/img_popup.php in BloofoxCMS 0.2.2 allows remote attackers to inject arbitrary web script or HTML via the img_url parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/465719/100/0/threaded">20070414 bloofoxCMS 0.2.2 Cross Site Scripting</ref><ref source="BID" url="http://www.securityfocus.com/bid/23487">23487</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2640">2640</ref></refs><vuln_soft><prod name="BloofoxCMS" vendor="BloofoxCMS"><vers num="0.2.2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-04-27" name="CVE-2007-2311" published="2007-04-26" seq="2007-2311" severity="High" type="CVE"><desc><descript source="cve">** DISPUTED **  PHP remote file inclusion vulnerability in install/index.php in BlooFoxCMS 0.2.2 allows remote attackers to execute arbitrary PHP code via a URL in the content_php parameter.  NOTE: this issue has been disputed by a reliable third party, stating that content_php is initialized before use.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/465739/100/0/threaded">20070414 bloofoxCMS 0.2.2 Remote File Include Vulnerabilitiy</ref><ref source="VIM" url="http://www.attrition.org/pipermail/vim/2007-April/001526.html">20070415 false: bloofoxCMS 0.2.2 Remote File Include Vulnerabilitiy</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/466016/100/200/threaded">
20070417 Re: bloofoxCMS 0.2.2 Remote File Include Vulnerabilitiy</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2641">2641</ref></refs><vuln_soft><prod name="BloofoxCMS" vendor="BloofoxCMS"><vers num="0.2.2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-04-27" name="CVE-2007-2312" published="2007-04-26" seq="2007-2312" severity="High" type="CVE"><desc><descript source="cve">Multiple SQL injection vulnerabilities in the Virtual War (VWar) 1.5.0 R15 module for PHP-Nuke allow remote attackers to execute arbitrary SQL commands via the n parameter to extra/online.php and other unspecified scripts in extra/.  NOTE: this might be same vulnerability as CVE-2006-4142; however, there is an intervening vendor fix announcement.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/465612/100/0/threaded">20070413 [waraxe-2007-SA#048] - Multiple vulnerabilities in Virtual War 1.5 module for PhpNuke</ref><ref source="" url="http://www.waraxe.us/advisory-48.html"></ref><ref source="VIM" url="http://www.attrition.org/pipermail/vim/2007-April/001519.html">20070413 DUP?: [waraxe-2007-SA#048] - Multiple vulnerabilities in Virtual War 1.5 module for PhpNuke</ref><ref source="BID" url="http://www.securityfocus.com/bid/23478">23478</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33649">vwar-online-sql-injection(33649)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2642">2642</ref></refs><vuln_soft><prod name="Virtual War" vendor="VWar"><vers num="1.5.0 R15"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-04-27" name="CVE-2007-2313" published="2007-04-26" seq="2007-2313" severity="High" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in getinfo1.php in the Shotcast 1.0 RC2 module for mxBB allows remote attackers to execute arbitrary PHP code via a URL in the mx_root_path parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3716">3716</ref><ref source="BID" url="http://www.securityfocus.com/bid/23444">23444</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1384">ADV-2007-1384</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33599">mxbb-shotcast-getinfo1-file-include(33599)</ref></refs><vuln_soft><prod name="MX Shotcast" vendor="mxBB"><vers num="1.0 RC2"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-04-27" name="CVE-2007-2314" published="2007-04-26" seq="2007-2314" severity="Medium" type="CVE"><desc><descript source="cve">Multiple SQL injection vulnerabilities in Crea-Book 1.0, and possibly earlier, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) pseudo or (2) passe parameter to (a) configurer.php, (b) connect.php, (c) delete.php, (d) delete2.php, (e) index.php, (f) infos.php, (g) membres.php, (h) modif-infos.php, (i) modif-message.php, (j) modif.php, (k) uninstall.php, or (l) uninstall_table.php in admin/, different vectors than CVE-2007-2000.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24862">24862</ref><ref source="OSVDB" url="http://www.osvdb.org/34818">34818</ref><ref source="OSVDB" url="http://www.osvdb.org/34819">34819</ref><ref source="OSVDB" url="http://www.osvdb.org/34820">34820</ref><ref source="OSVDB" url="http://www.osvdb.org/34821">34821</ref><ref source="OSVDB" url="http://www.osvdb.org/34822">34822</ref><ref source="OSVDB" url="http://www.osvdb.org/34823">34823</ref><ref source="OSVDB" url="http://www.osvdb.org/34824">34824</ref><ref source="OSVDB" url="http://www.osvdb.org/34825">34825</ref><ref source="OSVDB" url="http://www.osvdb.org/34826">34826</ref><ref source="OSVDB" url="http://www.osvdb.org/34827">34827</ref><ref source="OSVDB" url="http://www.osvdb.org/34828">34828</ref><ref source="OSVDB" url="http://www.osvdb.org/34829">34829</ref></refs><vuln_soft><prod name="Crea-Book" vendor="Crea-Book"><vers num="1.0" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.8" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.9" CVSS_score="7.8" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_version="2.0" modified="2007-04-27" name="CVE-2007-2315" published="2007-04-26" seq="2007-2315" severity="High" type="CVE"><desc><descript source="cve">MiniShare 1.5.4, and possibly earlier, allows remote attackers to cause a denial of service (application crash) via a flood of requests for new connections.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref patch="1" source="" url="http://sourceforge.net/forum/forum.php?forum_id=685448"></ref><ref patch="1" source="" url="http://sourceforge.net/project/shownotes.php?group_id=109595&amp;release_id=500854"></ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/24898">24898</ref></refs><vuln_soft><prod name="Minimal HTTP Server" vendor="MiniShare"><vers num="1.5.4" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-04-27" name="CVE-2007-2316" published="2007-04-26" seq="2007-2316" severity="High" type="CVE"><desc><descript source="cve">Unspecified vulnerability in the admin script in Open Business Management (OBM) before 2.0.0 allows remote attackers to have an unknown impact by calling the script &quot;in txt mode from a browser.&quot;</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs><ref source="" url="http://obm.aliasource.org/changelogs/changelog-2.0.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/23472">23472</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1376">ADV-2007-1376</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/24775">24775</ref></refs><vuln_soft><prod name="Open Business Management" vendor="Open Business Management"><vers num="1.2.4"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-04-27" name="CVE-2007-2317" published="2007-04-26" seq="2007-2317" severity="High" type="CVE"><desc><descript source="cve">Multiple PHP remote file inclusion vulnerabilities in MiniBB Forum 1.5a and earlier, as used by TOSMO/Mambo 4.0.12 and probably other products, allow remote attackers to execute arbitrary PHP code via a URL in the absolute_path parameter to bb_plugins.php in (1) components/minibb/ or (2) components/com_minibb, or (3) configuration.php.  NOTE: the com_minibb.php vector is already covered by CVE-2006-3690.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3707">3707</ref><ref source="VIM" url="http://www.attrition.org/pipermail/vim/2007-April/001518.html">20070413 Dup: TOSMO/Mambo 1.4.13a (absolute_path) Remote File Inclusion Vulns</ref><ref source="BID" url="http://www.securityfocus.com/bid/23416">23416</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1354">ADV-2007-1354</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33578">tosmomambo-absolutepath-file-include(33578)</ref></refs><vuln_soft><prod name="MiniBB" vendor="MiniBB"><vers num="1.5a" prev="1"/></prod><prod name="TOSMO Mambo" vendor="TOSMO Mambo"><vers num="4.0.12" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" CVSS_score="9.3" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-05-08" name="CVE-2007-2318" published="2007-04-26" seq="2007-2318" severity="High" type="CVE"><desc><descript source="cve">Multiple format string vulnerabilities in FileZilla before 2.2.32 allow remote attackers to execute arbitrary code via format string specifiers in (1) FTP server responses or (2) data sent by an FTP server.  NOTE: some of these details are obtained from third party information.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref patch="1" source="" url="http://sourceforge.net/project/shownotes.php?release_id=501534&amp;group_id=21558"></ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/23506">23506</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/24894">24894</ref></refs><vuln_soft><prod name="FileZilla" vendor="FileZilla"><vers num="2.2.31" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-10-01" name="CVE-2007-2319" published="2007-04-26" seq="2007-2319" severity="Medium" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in the AutoStand 1.1 and earlier module for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter to mod_as_category.php in (1) modules/mod_as_category/ or (2) modules/.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3734">3734</ref><ref source="BID" url="http://www.securityfocus.com/bid/23490">23490</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1392">ADV-2007-1392</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33660">autostand-modascategory-file-include(33660)</ref></refs><vuln_soft><prod name="Autostand Category" vendor="Autostand Category"><vers num="1.1" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-04-27" name="CVE-2007-2320" published="2007-04-26" seq="2007-2320" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in kontakt.php in Papoo 3.02 and earlier allows remote attackers to execute arbitrary SQL commands via the menuid parameter, a different vector than CVE-2005-4478.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3739">3739</ref><ref source="BID" url="http://www.securityfocus.com/bid/23500">23500</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25071">
25071</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33682">
papoo-kontakt-sql-injection(33682)</ref></refs><vuln_soft><prod name="Papoo" vendor="Papoo"><vers num="3.02" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-04-27" name="CVE-2007-2321" published="2007-04-26" seq="2007-2321" severity="High" type="CVE"><desc><descript source="cve">Unspecified vulnerability in the search functionality in SilverStripe 2.0.0 has unknown impact and attack vectors.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs><ref source="" url="http://www.silverstripe.com/silverstripe-2-0-1-released/"></ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/24936">24936</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1537">
ADV-2007-1537</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33883">
silverstripe-search-unspecified(33883)</ref></refs><vuln_soft><prod name="SilverStripe" vendor="SilverStripe"><vers num="2.0.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.8" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.9" CVSS_score="7.8" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_version="2.0" modified="2008-04-22" name="CVE-2007-2322" published="2007-04-26" seq="2007-2322" severity="High" type="CVE"><desc><descript source="cve">NMMediaServer.exe in Nero MediaHome 2.5.5.0 and CE 1.3.0.4 allows remote attackers to cause a denial of service (NULL dereference and application crash) via a crafted packet that contains two CRLF sequences.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24724">24724</ref><ref source="BID" url="http://www.securityfocus.com/bid/23640">23640</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33974">nero-crlf-dos(33974)</ref></refs><vuln_soft><prod name="MediaHome" vendor="Nero"><vers num="2.5.5.0"/></prod><prod name="MediaHome CE" vendor="Nero"><vers num="1.3.0.4"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-04-27" name="CVE-2007-2323" published="2007-04-26" seq="2007-2323" severity="High" type="CVE"><desc><descript source="cve">Multiple buffer overflows in the WinDVDX ActiveX control in InterVideo Home Theater 2.1.13.0 and 2.5.13.58 allow remote attackers to execute arbitrary code via a long string argument to the (1) GetDiscType or (2) AddFileList method.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24710">24710</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33868">
intervideo-windvdx-bo(33868)</ref></refs><vuln_soft><prod name="Home Theater" vendor="InterVideo"><vers num="2.1.13.0"/><vers num="2.5.13.58"/></prod></vuln_soft></entry><entry CVSS_base_score="7.8" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.9" CVSS_score="7.8" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:N/A:N)" CVSS_version="2.0" modified="2007-04-27" name="CVE-2007-2324" published="2007-04-26" seq="2007-2324" severity="High" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in file.php in JulmaCMS 1.4 allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3799">3799</ref><ref source="BID" url="http://www.securityfocus.com/bid/23642">23642</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25053">
25053</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33859">
julmacms-file-directory-traversal(33859)</ref></refs><vuln_soft><prod name="JulmaCMS" vendor="Julmajanne"><vers num="1.4"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-04-27" name="CVE-2007-2325" published="2007-04-26" seq="2007-2325" severity="High" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in include.php in MyNewsGroups :) allows remote attackers to execute arbitrary PHP code via a URL in the myng_root parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/466836/100/0/threaded">20070424 MyNewsGroups &gt;&gt; RFI in include.php</ref><ref source="BID" url="http://www.securityfocus.com/bid/23646">
23646</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33867">
mynewsgroups-include-file-include(33867)</ref></refs><vuln_soft><prod name="MyNewsGroup" vendor="MyNewsGroup"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-04-27" name="CVE-2007-2326" published="2007-04-26" seq="2007-2326" severity="High" type="CVE"><desc><descript source="cve">Multiple PHP remote file inclusion vulnerabilities in HYIP Manager Pro allow remote attackers to execute arbitrary PHP code via a URL in the plugin_file parameter to (1) Smarty.class.php and (2) Smarty_Compiler.class.php in inc/libs/; (3) core.display_debug_console.php, (4) core.load_plugins.php, (5) core.load_resource_plugin.php, (6) core.process_cached_inserts.php, (7) core.process_compiled_include.php, and (8) core.read_cache_file.php in inc/libs/core/; and other unspecified files.  NOTE: (1) and (2) might be incorrectly reported vectors in Smarty.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/466837/100/0/threaded">20070425 HYIP Manager Pro Script &gt;&gt; Remote file Include</ref><ref source="BID" url="http://www.securityfocus.com/bid/23663">
23663</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33882">
hyipmanager-pluginfile-file-include(33882)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2634">2634</ref></refs><vuln_soft><prod name="HYIP Manager Pro" vendor="GoldCoders"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-04-27" name="CVE-2007-2327" published="2007-04-26" seq="2007-2327" severity="High" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in _editor.php in HTMLeditbox 2.2 allows remote attackers to execute arbitrary PHP code via a URL in the settings[app_dir] parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/466841/100/0/threaded">20070425 HTMLeditbox &amp; 2.2 &gt;&gt; RFI</ref><ref source="BID" url="http://www.securityfocus.com/bid/23664">
23664</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33875">
htmleditbox-editor-file-include(33875)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2635">2635</ref></refs><vuln_soft><prod name="htmlEditbox" vendor="Labs4"><vers num="2.2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-04-27" name="CVE-2007-2328" published="2007-04-26" seq="2007-2328" severity="High" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in addvip.php in phpMYTGP 1.4b allows remote attackers to execute arbitrary PHP code via a URL in the msetstr[PROGSDIR] parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/466845/100/0/threaded">20070425 phpMYTGP v v1.4b &gt;&gt; RFI</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33880">
phpmytgp-addvip-file-include(33880)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2636">2636</ref></refs><vuln_soft><prod name="phpMYTGP" vendor="phpMYTGP"><vers num="1.4b"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-04-27" name="CVE-2007-2329" published="2007-04-26" seq="2007-2329" severity="High" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in searchbot.php in Searchactivity allows remote attackers to execute arbitrary PHP code via a URL in the path parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/466846/100/0/threaded">20070425 Searchactivity &gt;&gt; RFI</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33881">
searchactivity-searchbot-file-include(33881)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2637">2637</ref></refs><vuln_soft><prod name="Searchactivity" vendor="Searchactivity"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-04-27" name="CVE-2007-2330" published="2007-04-26" seq="2007-2330" severity="High" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in includes_handler.php in DynaTracker 151 allows remote attackers to execute arbitrary PHP code via a URL in the base_path parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/466843/100/0/threaded">20070425 DynaTracker &amp;v151&gt;&gt; RFI</ref><ref source="BID" url="http://www.securityfocus.com/bid/23667">
23667</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33873">
dynatracker-basepath-file-include(33873)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2638">2638</ref></refs><vuln_soft><prod name="DynaTracker" vendor="DynaTracker"><vers num="151"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-04-27" name="CVE-2007-2331" published="2007-04-26" seq="2007-2331" severity="High" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in cart.php in Shop-Script 2.0 allows remote attackers to execute arbitrary PHP code via a URL in the lang_list parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/466851/100/0/threaded">20070425 Shop-Script v 2.0 &gt;&gt; RFI</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33877">
shopscript-cart-file-include(33877)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2633">2633</ref></refs><vuln_soft><prod name="Shop-Script" vendor="Shop-Script"><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="9.0" CVSS_exploit_subscore="8.0" CVSS_impact_subscore="10.0" CVSS_score="9.0" CVSS_vector="(AV:N/AC:L/Au:S/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-04-27" name="CVE-2007-2332" published="2007-04-27" seq="2007-2332" severity="High" type="CVE"><desc><descript source="cve">Nortel VPN Router (aka Contivity) 1000, 2000, 4000, and 5000 before 6_05.140 uses a fixed DES key to encrypt passwords, which allows remote authenticated users to obtain a password via a brute force attack on a hash from the LDAP store.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://www130.nortelnetworks.com/go/main.jsp?cscat=BLTNDETAIL&amp;DocumentOID=567877&amp;RenditionID=&amp;poid=null"></ref><ref source="BID" url="http://www.securityfocus.com/bid/23562">23562</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1464">ADV-2007-1464</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24962">24962</ref></refs><vuln_soft><prod name="VPN Router" vendor="Nortel"><vers num="1010"/><vers num="1050"/><vers num="1100"/><vers num="1700"/><vers num="1740"/><vers num="1750"/><vers num="2700"/><vers num="5000"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-04-30" name="CVE-2007-2333" published="2007-04-27" seq="2007-2333" severity="High" type="CVE"><desc><descript source="cve">Nortel VPN Router (aka Contivity) 1000, 2000, 4000, and 5000 before 5_05.149, 5_05.3xx before 5_05.304, and 6.x before 6_05.140 includes the FIPSecryptedtest1219 and FIPSunecryptedtest1219 default accounts in the LDAP template, which might allow remote attackers to access the private network.</descript></desc><sols><sol source="nvd">The vendor has addressed this issue through a product update that can be found at: http://www130.nortelnetworks.com/go/main.jsp?cscat=BLTNDETAIL&amp;DocumentOID=567877&amp;RenditionID=&amp;poid=null </sol></sols><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref patch="1" source="" url="http://www130.nortelnetworks.com/go/main.jsp?cscat=BLTNDETAIL&amp;DocumentOID=567877&amp;RenditionID=&amp;poid=null"></ref><ref source="BID" url="http://www.securityfocus.com/bid/23562">23562</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1464">ADV-2007-1464</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017943">1017943</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/24962">24962</ref></refs><vuln_soft><prod name="Contivity" vendor="Nortel"><vers num="1000 VPN Switch"/><vers num="2000 VPN Switch"/><vers num="4000 VPN Switch"/></prod><prod name="VPN Router" vendor="Nortel"><vers num="5000"/></prod><prod name="VPN Router Portfolio" vendor="Nortel"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-04-30" name="CVE-2007-2334" published="2007-04-27" seq="2007-2334" severity="High" type="CVE"><desc><descript source="cve">Nortel VPN Router (aka Contivity) 1000, 2000, 4000, and 5000 before 5_05.149, 5_05.3xx before 5_05.304, and 6.x before 6_05.140 has two template HTML files lacking certain verification tags, which allows remote attackers to access the administration interface and change the device configuration via certain requests.</descript></desc><sols><sol source="nvd">The vendor has addressed this issue with the following product update: http://www130.nortelnetworks.com/go/main.jsp?cscat=BLTNDETAIL&amp;DocumentOID=567877&amp;RenditionID=&amp;poid=null  </sol></sols><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="" url="http://www130.nortelnetworks.com/go/main.jsp?cscat=BLTNDETAIL&amp;DocumentOID=567877&amp;RenditionID=&amp;poid=null"></ref><ref source="BID" url="http://www.securityfocus.com/bid/23562">23562</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1464">ADV-2007-1464</ref><ref patch="1" source="SECTRACK" url="http://www.securitytracker.com/id?1017943">1017943</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/24962">24962</ref></refs><vuln_soft><prod name="Contivity" vendor="Nortel"><vers num="1000 VPN Switch"/><vers num="2000 VPN Switch"/><vers num="4000 VPN Switch"/></prod><prod name="VPN Router" vendor="Nortel"><vers num="5000"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" modified="2007-04-30" name="CVE-2007-2335" published="2007-04-27" seq="2007-2335" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in the RSS feed reader functionality in Lunascape 4.1.3 build2 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref source="" url="http://jvn.jp/jp/JVN%2336628264/index.html"></ref><ref source="" url="http://lunapedia.lunascape.jp/index.php?title=Lunascape_4#2007.2F04.2F25_ver_4.2.0"></ref><ref source="BID" url="http://www.securityfocus.com/bid/23665">23665</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1538">ADV-2007-1538</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/25000">25000</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/34074">lunascape-rssfeed-xss(34074)</ref></refs><vuln_soft><prod name="Lunascape" vendor="Lunascape"><vers num="4.1"/><vers num="4.1.1"/><vers num="4.1.2"/><vers num="4.1.3"/></prod></vuln_soft></entry><entry CVSS_base_score="7.8" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.9" CVSS_score="7.8" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_version="2.0" modified="2007-04-30" name="CVE-2007-2336" published="2007-04-27" seq="2007-2336" severity="High" type="CVE"><desc><descript source="cve">Unspecified vulnerability in InterVations NaviCOPA Web Server 2.01 20070323 allows remote attackers to cause a denial of service (daemon crash) via crafted HTTP requests, as demonstrated by long requests containing &apos;\A&apos; characters, probably a different issue than CVE-2006-5112 and CVE-2007-1733.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/25049">25049</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33903">
navicopa-httpget-dos(33903)</ref></refs><vuln_soft><prod name="NaviCOPA Web Server" vendor="InterVations"><vers num="2.01 2007-03-23"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" modified="2007-04-30" name="CVE-2007-2337" published="2007-04-27" seq="2007-2337" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Exponent CMS 0.96.6 Alpha and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) url parameter to (a) magpie_debug.php and (b) magpie_simple.php in external/magpierss/scripts/, the (2) rss_url parameter to (c) magpie_slashbox.php in external/magpierss/scripts/, and the (3) body parameter to the (d) weblogmodule (aka Weblog Comments) module.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref source="" url="http://www.bugtraq.ir/articles/advisory/exponent_multiple_vulnerabilities/10"></ref><ref source="BID" url="http://www.securityfocus.com/bid/23574">23574</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/34077">exponentcms-multiple-scripts-xss(34077)</ref></refs><vuln_soft><prod name="Exponent CMS" vendor="Exponent"><vers num="0.96.5 RC1"/><vers num="0.96.6 Alpha"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-04-30" name="CVE-2007-2338" published="2007-04-27" seq="2007-2338" severity="High" type="CVE"><desc><descript source="cve">Cross-site request forgery (CSRF) vulnerability in include/admin/banlist.php in Phorum before 5.1.22 allows remote attackers to perform unauthorized banlist deletions as an administrator via the delete parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/466286/100/0/threaded">20070419 [waraxe-2007-SA#049] - Multiple vulnerabilities in Phorum 5.1.20</ref><ref adv="1" source="" url="http://www.waraxe.us/advisory-49.html"></ref><ref source="" url="http://www.phorum.org/story.php?76"></ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/23616">23616</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1479">ADV-2007-1479</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1017936">1017936</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/24932">24932</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2617">2617</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/34078">phorum-banlist-csrf(34078)</ref></refs><vuln_soft><prod name="Phorum" vendor="Phorum"><vers num="5.1.20" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-04-30" name="CVE-2007-2339" published="2007-04-27" seq="2007-2339" severity="High" type="CVE"><desc><descript source="cve">Multiple SQL injection vulnerabilities in Phorum before 5.1.22 allow remote attackers to execute arbitrary SQL commands via (1) a modified recipients parameter name in (a) pm.php; (2) the curr parameter to the (b) badwords (aka censorlist) or (c) banlist module in admin.php; or (3) the &quot;Edit groups / Add group&quot; field in the (d) groups module in admin.php.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/466286/100/0/threaded">20070419 [waraxe-2007-SA#049] - Multiple vulnerabilities in Phorum 5.1.20</ref><ref adv="1" source="" url="http://www.waraxe.us/advisory-49.html"></ref><ref source="" url="http://www.phorum.org/story.php?76"></ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/23616">23616</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1479">ADV-2007-1479</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1017936">1017936</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/24932">24932</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2617">2617</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/34081">phorum-multiple-scripts-sql-injection(34081)</ref></refs><vuln_soft><prod name="Phorum" vendor="Phorum"><vers num="5.1.20" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-08-02" name="CVE-2007-2340" published="2007-04-27" seq="2007-2340" severity="High" type="CVE"><desc><descript source="cve">Multiple PHP remote file inclusion vulnerabilities in inc/include_all.inc.php in phporacleview allow remote attackers to execute arbitrary PHP code via a URL in the (1) page_dir or (2) inc_dir parameters.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3803">3803</ref><ref source="BID" url="http://www.securityfocus.com/bid/23672">23672</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33904">phporacleview-includeallinc-file-include(33904)</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1555">ADV-2007-1555</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/25035">25035</ref></refs><vuln_soft><prod name="phpOracleView" vendor="phpOracleView"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-04-30" name="CVE-2007-2341" published="2007-04-27" seq="2007-2341" severity="High" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in suite/index.php in phpBandManager 0.8 allows remote attackers to execute arbitrary PHP code via a URL in the pg parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3802">3802</ref><ref source="BID" url="http://www.securityfocus.com/bid/23673">23673</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1556">
ADV-2007-1556</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33906">
phpbandmanager-index-file-include(33906)</ref></refs><vuln_soft><prod name="phpBandManager" vendor="phpBandManager"><vers num="0.8"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-04-30" name="CVE-2007-2342" published="2007-04-27" seq="2007-2342" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in error.asp in CreaScripts CreaDirectory 1.2 allows remote attackers to execute arbitrary SQL commands via the id parameter, a different vector than CVE-2006-6083.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3767">3767</ref><ref source="BID" url="http://www.securityfocus.com/bid/23564">23564</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1476">
ADV-2007-1476</ref></refs><vuln_soft><prod name="CreaDirectory" vendor="CreaScripts"><vers num="1.2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-04-30" name="CVE-2007-2343" published="2007-04-27" seq="2007-2343" severity="High" type="CVE"><desc><descript source="cve">Stack-based buffer overflow in the TFTPD component in Enterasys NetSight Console 2.1 and NetSight Inventory Manager 2.1, and possibly earlier, allows remote attackers to execute arbitrary code via crafted request packets that contain long file names.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="IDEFENSE" url="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=506">20070404 Enterasys Networks Multiple NetSight Products Multiple Vulnerabilities</ref><ref patch="1" source="" url="http://www.enterasys.com/pub/NetSight/Patches/SP1/NetSight_SP1.pdf"></ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1271">ADV-2007-1271</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017876">1017876</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24764">24764</ref></refs><vuln_soft><prod name="NetSight Console" vendor="Enterasys"><vers num="2.1" prev="1"/></prod><prod name="NetSight Inventory Manager" vendor="Enterasys"><vers num="2.1" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.8" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.9" CVSS_score="7.8" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_version="2.0" modified="2007-05-22" name="CVE-2007-2344" published="2007-04-27" seq="2007-2344" severity="High" type="CVE"><desc><descript source="cve">The BOOTPD component in Enterasys NetSight Console 2.1 and NetSight Inventory Manager 2.1, and possibly earlier, on Windows allows remote attackers to cause a denial of service (daemon crash) via a UDP packet that contains an invalid &quot;packet type&quot; field.</descript></desc><sols><sol source="nvd">The vendor has addressed this issue with the following product updates:

Apply Security Patch 1 :
http://www.enterasys.com/products/management/downloads/security_and_patches/

Or upgrade to Enterasys NetSight Console 2.3.1 build 6 and NetSight Inventory Manager 2.2.2 build 4 :
http://www.enterasys.com/services/support/downloads/ </sol></sols><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref source="IDEFENSE" url="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=506">20070404 Enterasys Networks Multiple NetSight Products Multiple Vulnerabilities</ref><ref adv="1" source="" url="http://www.enterasys.com/pub/NetSight/Patches/SP1/NetSight_SP1.pdf"></ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1271">ADV-2007-1271</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017876">1017876</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/24764">24764</ref></refs><vuln_soft><prod name="NetSight Console" vendor="Enterasys"><vers num="2.1"/></prod><prod name="NetSight Inventory Manager" vendor="Enterasys"><vers num="2.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-04-30" name="CVE-2007-2345" published="2007-04-27" seq="2007-2345" severity="High" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in include/include_stream.inc.php in CodeWand phpBrowse allows remote attackers to execute arbitrary PHP code via a URL in the include_path parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3668">3668</ref><ref source="BID" url="http://www.securityfocus.com/bid/23329">23329</ref></refs><vuln_soft><prod name="phpBrowse" vendor="CodeWand"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-04-30" name="CVE-2007-2346" published="2007-04-27" seq="2007-2346" severity="High" type="CVE"><desc><descript source="cve">Multiple PHP remote file inclusion vulnerabilities in PHP-Generics 1.0 beta allow remote attackers to execute arbitrary PHP code via a URL in the _APP_RELATIVE_PATH parameter to (1) include.php, (2) dbcommon/include.php, and (3) exception/include.php.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3669">3669</ref><ref source="BID" url="http://www.securityfocus.com/bid/23328">23328</ref></refs><vuln_soft><prod name="PHP-Generics" vendor="PHP-Generics"><vers num="1.0 beta"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-04-30" name="CVE-2007-2347" published="2007-04-27" seq="2007-2347" severity="High" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in main/forum/komentar.php in OneClick CMS (aka Sisplet CMS) 05.10 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the site_path parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3667">3667</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33455">Sispletcms-komentar-file-include(33455)</ref><ref source="BID" url="http://www.securityfocus.com/bid/23334">23334</ref></refs><vuln_soft><prod name="Sisplet CMS" vendor="Sisplet CMS"><vers num="05.10" prev="1"/></prod><prod name="OneClick CMS" vendor="OneClick CMS"><vers num="05.10" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-04-30" name="CVE-2007-2348" published="2007-04-27" seq="2007-2348" severity="Medium" type="CVE"><desc><descript source="cve">mirror --script in lftp before 3.5.9 does not properly quote shell metacharacters, which might allow remote user-assisted attackers to execute shell commands via a malicious script.  NOTE: it is not clear whether this issue crosses security boundaries, since the script already supports commands such as &quot;get&quot; which could overwrite executable files.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><design/></vuln_types><range><network/><user_init/></range><refs><ref source="" url="http://bugs.gentoo.org/show_bug.cgi?id=173524"></ref><ref source="" url="http://lftp.yar.ru/news.html"></ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1590">
ADV-2007-1590</ref><ref source="" url="https://issues.rpath.com/browse/RPL-1229"></ref><ref source="BID" url="http://www.securityfocus.com/bid/23736">
23736</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25107">
25107</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25132">
25132</ref></refs><vuln_soft><prod name="lftp" vendor="Alexander V. Lukyanov"><vers num="3.5.8" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="4.9" CVSS_score="5.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:N)" CVSS_version="2.0" modified="2007-05-01" name="CVE-2007-2349" published="2007-04-30" seq="2007-2349" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in Invision Power Board (IP.Board) 2.1.x and 2.2.x allows remote attackers to inject arbitrary web script or HTML by uploading crafted images or PDF files.</descript></desc><sols><sol source="nvd">The vendor has addressed this issue with the following product update:
http://forums.invisionpower.com/index.php?showtopic=234377</sol></sols><loss_types><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref patch="1" source="" url="http://forums.invisionpower.com/index.php?showtopic=234377"></ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1558">ADV-2007-1558</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/25021">25021</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33942">ipb-classupload-xss(33942)</ref></refs><vuln_soft><prod name="Invision Power Board" vendor="Invision Power Services"><vers num="2.1"/><vers num="2.2"/></prod></vuln_soft></entry><entry CVSS_base_score="6.5" CVSS_exploit_subscore="8.0" CVSS_impact_subscore="6.4" CVSS_score="6.5" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-05-01" name="CVE-2007-2350" published="2007-04-30" seq="2007-2350" severity="Medium" type="CVE"><desc><descript source="cve">admin/config.php in the music-on-hold module in freePBX 2.2.x allows remote authenticated administrators to execute arbitrary commands via shell metacharacters in the del parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2007-April/053915.html">20070421 freePBX 2.2.x&apos;s Music-on-hold Remote Code Execution Injection</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1535">ADV-2007-1535</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24935">24935</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2652">2652</ref></refs><vuln_soft><prod name="freePBX" vendor="freePBX"><vers num="2.2.1" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-05-01" name="CVE-2007-2351" published="2007-04-30" seq="2007-2351" severity="High" type="CVE"><desc><descript source="cve">Unspecified vulnerability in the HP Power Manager Remote Agent (RA) 4.0Build10 and earlier in HP-UX B.11.11 and B.11.23 allows local users to execute arbitrary code via unspecified vectors.</descript></desc><sols><sol source="nvd">The vendor has addressed this issue with the following product update:
http://h18004.www1.hp.com/products/servers/proliantstorage/power-protection/software/power-manager/pm3-dl.html</sol></sols><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><range><local/></range><refs><ref adv="1" patch="1" source="HP" url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&amp;cc=us&amp;objectID=c00819543">HPSBMA02197</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/23703">23703</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1574">ADV-2007-1574</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/25066">25066</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017977">
1017977</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33965">hpux-hppower-privilege-escalation(33965)</ref></refs><vuln_soft><prod name="Power Manager Remote Agent" vendor="HP"><vers num="4.0Build10" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-05-01" name="CVE-2007-2352" published="2007-04-30" seq="2007-2352" severity="High" type="CVE"><desc><descript source="cve">Multiple format string vulnerabilities in AFFLIB 2.2.6 allow remote attackers to execute arbitrary code via certain command line parameters, which are used in (1) warn and (2) err calls, possibly involving (a) lib/s3.cpp, (b) tools/afconvert.cpp, (c) tools/afcopy.cpp, (d) tools/afinfo.cpp, (e) aimage/imager.cpp, and (f) tools/afxml.cpp.  NOTE: this identifier is intended to address the vectors that were not fixed in CVE-2007-2054, but the unfixed vectors were not explicitly listed.</descript></desc><sols><sol source="nvd">The vendor has addressed this issue with the following product update: http://www.afflib.org/downloads/
</sol></sols><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/467040/100/0/threaded">20070427 AFFLIB(TM): Multiple Format String Injections</ref><ref patch="1" source="" url="http://www.vsecurity.com/bulletins/advisories/2007/afflib-fmtstr.txt"></ref><ref source="SREASON" url="http://securityreason.com/securityalert/2657">2657</ref></refs><vuln_soft><prod name="AFFLIB" vendor="AFFLIB"><vers num="2.2.6" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0" modified="2008-02-11" name="CVE-2007-2353" published="2007-04-30" seq="2007-2353" severity="Medium" type="CVE"><desc><descript source="cve">Apache Axis 1.0 allows remote attackers to obtain sensitive information by requesting a non-existent WSDL file, which reveals the installation path in the resulting exception message.</descript></desc><loss_types><conf/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref source="VIM" url="http://attrition.org/pipermail/vim/2007-April/001562.html">20070427 Apache AXIS Non-Existent Java Web Service Path Disclosure?</ref><ref source="BID" url="http://www.securityfocus.com/bid/23687">23687</ref><ref source="OSVDB" url="http://www.osvdb.org/34154">34154</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/34167">apache-axis-wsdl-path-disclosure(34167)</ref></refs><vuln_soft><prod name="Axis" vendor="Apache Software Foundation"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.8" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.9" CVSS_score="7.8" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:N/A:N)" CVSS_version="2.0" modified="2007-05-01" name="CVE-2007-2354" published="2007-04-30" seq="2007-2354" severity="High" type="CVE"><desc><descript source="cve">Progress Webspeed Messenger allows remote attackers to obtain sensitive information via a WService parameter containing &quot;wsbroker1/webutil/about.r&quot;, which reveals the operating system and product information.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/><exception/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/467184/100/0/threaded">20070429 Flaw in about.r OS and Progress version disclosure</ref><ref source="" url="http://www.ishare.nl/"></ref></refs><vuln_soft><prod name="WebSpeed Messenger" vendor="Progress Software Corp"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-05-01" name="CVE-2007-2355" published="2007-04-30" seq="2007-2355" severity="High" type="CVE"><desc><descript source="cve">The get_url function in DODS_Dispatch.pm for the CGI_server in OPeNDAP 3 allows remote attackers to execute arbitrary commands via shell metacharacters in a URL.</descript></desc><sols><sol source="nvd">The vendor has addressed this issue with the following solution: http://www.opendap.org/server3-patch-04.27.2007.txt</sol></sols><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://www.opendap.org/server3-patch-04.27.2007.txt"></ref><ref source="" url="http://www.opendap.org/"></ref><ref patch="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/857153">VU#857153</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/23719">23719</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1591">
ADV-2007-1591</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017983">
1017983</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25060">
25060</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33997">
opendap-geturl-command-execution(33997)</ref></refs><vuln_soft><prod name="Server3" vendor="OPeNDAP"><vers num="3.2.10"/><vers num="3.7.4"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-10-05" name="CVE-2007-2356" published="2007-04-30" seq="2007-2356" severity="Medium" type="CVE"><desc><descript source="cve">Stack-based buffer overflow in the set_color_table function in sunras.c in the SUNRAS plugin in Gimp 2.2.14 allows user-assisted remote attackers to execute arbitrary code via a crafted RAS file.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/><user_init/></range><refs><ref source="MILW0RM" url="http://milw0rm.com/exploits/3801">3801</ref><ref source="BID" url="http://www.securityfocus.com/bid/23680">23680</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/25012">25012</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33911">gimp-sunras-plugin-bo(33911)</ref><ref source="" url="https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=238422"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1560">ADV-2007-1560</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/467231/100/0/threaded">20070430 FLEA-2007-0015-1: gimp</ref><ref source="" url="https://issues.rpath.com/browse/RPL-1318"></ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200705-08.xml">GLSA-200705-08</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/25111">25111</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/25167">25167</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2007-0343.html">RHSA-2007:0343</ref><ref source="SUSE" url="http://lists.suse.com/archive/suse-security-announce/2007-May/0005.html">SUSE-SR:2007:011</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/25239">25239</ref><ref source="DEBIAN" url="http://www.debian.org/security/2007/dsa-1301">DSA-1301</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:108">MDKSA-2007:108</ref><ref source="UBUNTU" url="http://www.ubuntu.com/usn/usn-467-1">USN-467-1</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1018092">1018092</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25346">25346</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25359">25359</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25466">25466</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25573">25573</ref><ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-103170-1">103170</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/4241">ADV-2007-4241</ref><ref source="SECUNIA" url="http://secunia.com/advisories/28114">28114</ref><ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-66-201320-1">201320</ref></refs><vuln_soft><prod name="GIMP" vendor="The GIMP Team"><vers num="2.2.14"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-05-01" name="CVE-2007-2357" published="2007-04-30" seq="2007-2357" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in mods/Core/result.php in SineCms 2.3.4 allows remote attackers to inject arbitrary web script or HTML via the stringa parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/466965/100/0/threaded">20070426 SineCMS</ref><ref source="BID" url="http://www.securityfocus.com/bid/23682">23682</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1559">
ADV-2007-1559</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25014">
25014</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33919">
sinecms-result-xss(33919)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2649">2649</ref></refs><vuln_soft><prod name="SineCMS" vendor="SineCMS"><vers num="2.3.4"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-05-01" name="CVE-2007-2358" published="2007-04-30" seq="2007-2358" severity="High" type="CVE"><desc><descript source="cve">** DISPUTED **  Multiple PHP remote file inclusion vulnerabilities in b2evolution allow remote attackers to execute arbitrary PHP code via a URL in the (1) inc_path parameter to (a) a_noskin.php, (b) a_stub.php, (c) admin.php, (d) contact.php, (e) default.php, (f) index.php, and (g) multiblogs.php in blogs/; the (2) view_path and (3) control_path parameters to blogs/admin.php; and the (4) skins_path parameter to (h) blogs/contact.php and (i) blogs/multiblogs.php.  NOTE: this issue is disputed by CVE, since the inc_path, view_path, control_path, and skins_path variables are all initialized in conf/_advanced.php before they are used.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/466886/100/0/threaded">20070425 Remote File Inclusion</ref><ref source="VIM" url="http://attrition.org/pipermail/vim/2007-April/001566.html">20070427 What the *#$(! -- b2evolution RFI [False]</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33907">b2evolution-multiple-scripts-file-include(33907)</ref><ref source="OSVDB" url="http://www.osvdb.org/34152">
34152</ref></refs><vuln_soft><prod name="b2evolution" vendor="b2evolution"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-05-01" name="CVE-2007-2359" published="2007-04-30" seq="2007-2359" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in Ghost Service Manager, as used in Symantec Norton Ghost, Norton Save &amp; Recovery, LiveState Recovery, and BackupExec System Recovery before 20070426, allows local users to gain privileges via a long string.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" source="IDEFENSE" url="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=519">20070426 Symantec Norton Ghost 10 Service Manager Buffer Overflow Vulnerability</ref><ref adv="1" source="" url="http://www.symantec.com/avcenter/security/Content/2007.04.26.html"></ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017971">
1017971</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33931">
symantec-backup-unspecified-bo(33931)</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1552">ADV-2007-1552</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25013">25013</ref></refs><vuln_soft><prod name="Ghost" vendor="Symantec"><vers edition="Norton System Works" num="10.0"/><vers num="10.01"/><vers edition="Dell" num="10.0"/><vers num="10.0"/></prod><prod name="BackupExec System Recovery" vendor="Symantec"><vers num="6.5"/><vers num="6.52"/><vers num="6.52A"/><vers num="6.53"/></prod><prod name="Norton Save &amp; Recovery" vendor="Symantec"><vers num="11.0"/><vers num="11.01"/><vers num="11.01B"/><vers edition="Norton System Works 2007" num="1.01B"/><vers edition="Sony Euro" num="1.01"/></prod><prod name="LiveState Recovery" vendor="Symantec"><vers num="6.0"/><vers num="6.01"/><vers num="6.02"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="3.1" CVSS_impact_subscore="10.0" CVSS_score="6.8" CVSS_vector="(AV:L/AC:L/Au:S/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-05-01" name="CVE-2007-2360" published="2007-04-30" seq="2007-2360" severity="Medium" type="CVE"><desc><descript source="cve">Symantec Norton Ghost, Norton Save &amp; Recovery, LiveState Recovery, and BackupExec System Recovery before 20070426, when remote backups of restore point images are configured, encrypt network share credentials with a key formed by a hash of the username, which allows local users to obtain the credentials by calculating the key.</descript></desc><impacts><impact source="nvd">&quot;In order for this exploit to have an impact, administrators would either have to configure client machines to save restore points images to a private share, or the vulnerable machine would have to be shared by several users who each saved their restore points images to private shares.&quot;</impact></impacts><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><access/><design/></vuln_types><range><local/></range><refs><ref source="IDEFENSE" url="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=520">20070426 Symantec Norton Ghost 10 Recovery Points Insecure Password Storage Vulnerability</ref><ref source="" url="http://www.symantec.com/avcenter/security/Content/2007.04.26.html"></ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017971">
1017971</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1552">ADV-2007-1552</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25013">25013</ref></refs><vuln_soft><prod name="Ghost" vendor="Symantec"><vers edition="Norton System Works" num="10.0"/><vers num="10.01"/><vers edition="Dell" num="10.0"/></prod><prod name="BackupExec System Recovery" vendor="Symantec"><vers num="6.5"/><vers num="6.52"/><vers num="6.52A"/><vers num="6.53"/></prod><prod name="Norton Save &amp; Recovery" vendor="Symantec"><vers num="11.0"/><vers num="11.01"/><vers num="11.01B"/><vers edition="Norton System Works 2007" num="1.01B"/><vers edition="Sony Euro" num="1.01"/></prod><prod name="LiveState Recovery" vendor="Symantec"><vers num="6.0"/><vers num="6.01"/><vers num="6.02"/></prod></vuln_soft></entry><entry CVSS_base_score="4.9" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.9" CVSS_score="4.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:N/A:N)" CVSS_version="2.0" modified="2007-05-01" name="CVE-2007-2361" published="2007-04-30" seq="2007-2361" severity="Medium" type="CVE"><desc><descript source="cve">Symantec Norton Ghost, Norton Save &amp; Recovery, LiveState Recovery, and BackupExec System Recovery before 20070426, when remote backups of restore points images are configured, uses weak permissions (world readable) for a configuration file with network share credentials, which allows local users to obtain the credentials by reading the file.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" source="IDEFENSE" url="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=520">20070426 Symantec Norton Ghost 10 Recovery Points Insecure Password Storage Vulnerability</ref><ref adv="1" patch="1" source="" url="http://www.symantec.com/avcenter/security/Content/2007.04.26.html"></ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017971">
1017971</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33929">
symantec-backup-information-disclosure(33929)</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1552">ADV-2007-1552</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25013">25013</ref></refs><vuln_soft><prod name="Ghost" vendor="Symantec"><vers edition="Norton System Works" num="10.0"/><vers edition="Dell" num="10.0"/><vers num="10.0"/><vers num="10.01"/></prod><prod name="BackupExec System Recovery" vendor="Symantec"><vers num="6.5"/><vers num="6.52"/><vers num="6.52A"/><vers num="6.53"/></prod><prod name="Norton Save &amp; Recovery" vendor="Symantec"><vers num="11.0"/><vers num="11.01"/><vers num="11.01B"/><vers edition="Sony Euro" num="1.01"/><vers edition="Norton System Works 2007" num="1.01B"/></prod><prod name="LiveState Recovery" vendor="Symantec"><vers num="6.0"/><vers num="6.01"/><vers num="6.02"/></prod></vuln_soft></entry><entry CVSS_base_score="9.0" CVSS_exploit_subscore="8.0" CVSS_impact_subscore="10.0" CVSS_score="9.0" CVSS_vector="(AV:N/AC:L/Au:S/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-05-01" name="CVE-2007-2362" published="2007-04-30" seq="2007-2362" severity="High" type="CVE"><desc><descript source="cve">Multiple buffer overflows in MyDNS 1.1.0 allow remote attackers to (1) cause a denial of service (daemon crash) and possibly execute arbitrary code via a certain update, which triggers a heap-based buffer overflow in update.c; and (2) cause a denial of service (daemon crash) via unspecified vectors that trigger an off-by-one stack-based buffer overflow in update.c.</descript></desc><impacts><impact source="nvd">Successful exploitation requires update privileges and that &quot;allow-update&quot; is set to &quot;yes&quot; in mydns.conf.</impact></impacts><loss_types><avail/><conf/><int/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2007-April/054024.html">20070427 mydns-1.1.0 remote heap overflow</ref><ref source="" url="http://www.digit-labs.org/files/exploits/mydns-rr-smash.c"></ref><ref source="" url="http://www.digit-labs.org/files/patches/mydns-update.c.diff"></ref><ref source="BID" url="http://www.securityfocus.com/bid/23694">23694</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1561">ADV-2007-1561</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/25007">25007</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33933">mydns-update-bo(33933)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2658">2658</ref><ref source="DEBIAN" url="http://www.debian.org/security/2007/dsa-1434">DSA-1434</ref><ref source="SECUNIA" url="http://secunia.com/advisories/28086">28086</ref></refs><vuln_soft><prod name="MyDNS" vendor="Don Moore"><vers num="1.1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="8.5" CVSS_exploit_subscore="6.8" CVSS_impact_subscore="10.0" CVSS_score="8.5" CVSS_vector="(AV:N/AC:M/Au:S/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-05-09" name="CVE-2007-2363" published="2007-04-30" seq="2007-2363" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in IrfanView 4.00 and earlier allows user-assisted remote attackers to execute arbitrary code via a crafted .IFF file.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/><user_init/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3811">3811</ref><ref source="BID" url="http://www.securityfocus.com/bid/23692">23692</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33946">irfanview-iff-bo(33946)</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1575">ADV-2007-1575</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/25052">25052</ref></refs><vuln_soft><prod name="IrfanView" vendor="IrfanView"><vers num="4.00" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-05-09" name="CVE-2007-2364" published="2007-04-30" seq="2007-2364" severity="High" type="CVE"><desc><descript source="cve">Multiple PHP remote file inclusion vulnerabilities in burnCMS 0.2 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the root parameter to (1) mysql.class.php or (2) postgres.class.php in lib/db/; or (3) authuser.php, (4) misc.php, or (5) connect.php in lib/.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3809">3809</ref><ref source="BID" url="http://www.securityfocus.com/bid/23691">23691</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1557">ADV-2007-1557</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33938">burncms-multiple-script-file-include(33938)</ref></refs><vuln_soft><prod name="BurnCMS" vendor="Burnstone"><vers num="0.2" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" CVSS_score="9.3" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-12-31" name="CVE-2007-2365" published="2007-04-30" seq="2007-2365" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in Adobe Photoshop CS2 and CS3, Photoshop Elements 5.0, Illustrator CS3, and GoLive 9 allows user-assisted remote attackers to execute arbitrary code via a crafted .PNG file.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/><user_init/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3812">3812</ref><ref source="BID" url="http://www.securityfocus.com/bid/23698">23698</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1577">ADV-2007-1577</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/25044">25044</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33956">adobe-pngfile-bo(33956)</ref><ref source="" url="http://www.adobe.com/support/security/bulletins/apsb07-13.html"></ref><ref source="" url="http://www.adobe.com/support/security/bulletins/apsb07-16.html"></ref><ref source="" url="http://www.adobe.com/support/security/bulletins/apsb07-17.html"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/3442">ADV-2007-3442</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/3443">ADV-2007-3443</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1018792">1018792</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/26846">26846</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/26864">26864</ref></refs><vuln_soft><prod name="GoLive" vendor="Adobe"><vers num="9"/></prod><prod name="Photoshop Elements" vendor="Adobe"><vers num="5.0"/></prod><prod name="Illustrator" vendor="Adobe"><vers num="CS3"/></prod><prod name="Photoshop" vendor="Adobe"><vers num="CS2"/><vers num="CS3"/></prod></vuln_soft></entry><entry CVSS_base_score="7.4" CVSS_exploit_subscore="4.4" CVSS_impact_subscore="10.0" CVSS_score="7.4" CVSS_vector="(AV:A/AC:M/Au:S/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-05-09" name="CVE-2007-2366" published="2007-04-30" seq="2007-2366" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in Corel Paint Shop Pro 11.20 allows user-assisted remote attackers to execute arbitrary code via a crafted .PNG file.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local_network/><user_init/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3812">3812</ref><ref source="BID" url="http://www.securityfocus.com/bid/23698">23698</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1576">ADV-2007-1576</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/25034">25034</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33956">adobe-pngfile-bo(33956)</ref></refs><vuln_soft><prod name="Paint Shop Pro Photo" vendor="Corel"><vers num="11.20"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-05-09" name="CVE-2007-2367" published="2007-04-30" seq="2007-2367" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in wserve_console.exe in Wserve HTTP Server (whttp) 4.6 allows remote attackers to cause a denial of service (forced application exit) via a long directory name in the URI.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/464819/100/0/threaded">20070405 Wserve HTTP Server 4.6 Version (Long Directory Name) Buffer Overflow - Denial Of Service</ref><ref source="BID" url="http://www.securityfocus.com/bid/23341">23341</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2647">2647</ref></refs><vuln_soft><prod name="Wserve HTTP Server" vendor="Wserve HTTP Server"><vers num="4.6"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0" modified="2007-05-09" name="CVE-2007-2368" published="2007-04-30" seq="2007-2368" severity="Medium" type="CVE"><desc><descript source="cve">picture.php in WebSPELL 4.01.02 and earlier allows remote attackers to read arbitrary files via the file parameter.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3673">3673</ref></refs><vuln_soft><prod name="webSPELL" vendor="webSPELL"><vers num="4.01.02" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0" modified="2007-05-09" name="CVE-2007-2369" published="2007-04-30" seq="2007-2369" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in picture.php in WebSPELL 4.01.02 and earlier, when PHP before 4.3.0 is used, allows remote attackers to read arbitrary files via a .. (dot dot) in the id parameter.</descript></desc><impacts><impact source="nvd">Successful exploitation requires that PHP before 4.3.0 is used.</impact></impacts><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3673">3673</ref></refs><vuln_soft><prod name="webSPELL" vendor="webSPELL"><vers num="4.01.02" prev="1"/></prod><prod name="PHP" vendor="PHP"><vers num="4.2.3" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-05-09" name="CVE-2007-2370" published="2007-04-30" seq="2007-2370" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in index.php in the John Mordo Jobs 2.4 and earlier module for XOOPS allows remote attackers to execute arbitrary SQL commands via the cid parameter in a jobsview action. NOTE: the module name was originally reported as Job Listings.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3672">3672</ref><ref source="VIM" url="http://www.attrition.org/pipermail/vim/2007-April/001494.html">20070405 true: XOOPS Module Jobs &lt;= 2.4 (cid) SQL Injection Exploit</ref></refs><vuln_soft><prod name="John Mordo Jobs Module" vendor="Xoops"><vers num="2.4" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-05-08" name="CVE-2007-2371" published="2007-04-30" seq="2007-2371" severity="High" type="CVE"><desc><descript source="cve">admin/index.php in Gregory Kokanosky phpMyNewsletter 0.8 beta5 and earlier provides access to configuration modification before login, which allows remote attackers to cause a denial of service (loss of configuration data), and possibly perform direct static code injection, via a saveGlobalconfig action.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><access/><input/></vuln_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3671">3671</ref><ref source="BID" url="http://www.securityfocus.com/bid/23342">23342</ref></refs><vuln_soft><prod name="phpMyNewsLetter" vendor="Gregory Kokanosky"><vers num="0.8 Beta 5" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-05-08" name="CVE-2007-2372" published="2007-04-30" seq="2007-2372" severity="High" type="CVE"><desc><descript source="cve">admin/send_mod.php in Gregory Kokanosky phpMyNewsletter 0.8 beta5 and earlier prints a Location header but does not exit when administrative credentials are missing, which allows remote attackers to compose an e-mail message via a post with the subject, message, format, and list_id fields; and send the message via a direct request for the MsgId value under admin/.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><access/><input/></vuln_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3671">3671</ref><ref source="BID" url="http://www.securityfocus.com/bid/23342">23342</ref></refs><vuln_soft><prod name="phpMyNewsLetter" vendor="Gregory Kokanosky"><vers num="0.8 Beta 5" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-05-08" name="CVE-2007-2373" published="2007-04-30" seq="2007-2373" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in viewcat.php in the WF-Links (wflinks) 1.03 and earlier module for XOOPS allows remote attackers to execute arbitrary SQL commands via the cid parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3670">3670</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/488316/100/0/threaded">20080218 XOOPS Module wflinks SQL Injection(cid)</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/488375/100/0/threaded">20080220 Re: XOOPS Module wflinks SQL Injection(cid)</ref><ref source="" url="http://packetstormsecurity.org/0704-exploits/xoopswflinks-sql.txt"></ref><ref source="BID" url="http://www.securityfocus.com/bid/23340">23340</ref></refs><vuln_soft><prod name="WF-Links" vendor="WF-Links"><vers num="1.03" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" CVSS_score="9.3" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-06-27" name="CVE-2007-2374" published="2007-04-30" seq="2007-2374" severity="High" type="CVE"><desc><descript source="cve">Unspecified vulnerability in Microsoft Windows 2000, XP, and Server 2003 allows user-assisted remote attackers to execute arbitrary code via unspecified vectors.  NOTE: this information is based upon a vague pre-advisory with no actionable information. However, the advisory is from a reliable source.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><range><network/><user_init/></range><refs><ref source="" url="http://research.eeye.com/html/advisories/upcoming/20070327.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/23332">23332</ref></refs><vuln_soft><prod name="S3400 Message Application Server" vendor="Avaya"><vers num=""/></prod><prod name="DefinityOne Media Servers" vendor="Avaya"><vers num=""/></prod><prod name="Windows XP" vendor="Microsoft"><vers edition="Professional" num="SP1"/><vers edition="Media Center" num="SP1"/><vers edition="Home" num="SP1"/><vers edition="Gold" num="SP1"/><vers edition="Embedded" num="SP1"/><vers edition="64-bit 2003" num="SP1"/><vers edition="Tablet PC" num="SP1"/><vers edition="Tablet PC" num="SP2"/><vers edition="Professional" num="SP2"/><vers edition="Media Center" num="SP2"/><vers edition="Home" num="SP2"/></prod><prod name="Media Server" vendor="Avaya"><vers num=""/></prod><prod name="Windows Server 2003" vendor="Microsoft"><vers num="Datacenter"/><vers num="Enterprise"/><vers edition="Itanium" num="Enterprise"/><vers edition="Itanium SP1" num="Enterprise"/><vers edition="Itanium SP1 Beta 1" num="Enterprise"/><vers edition="SP1" num="Enterprise"/><vers edition="64-bit" num="Enterprise"/><vers edition="SP1 Beta 1" num="Enterprise"/><vers num="Itanium"/><vers edition="SP1" num="Standard"/><vers edition="64-bit" num="Standard"/><vers edition="SP1 Beta 1" num="Standard"/><vers num="Standard"/><vers edition="SP1 Beta 1" num="Web"/><vers edition="SP1" num="Web"/><vers num="Web"/></prod><prod name="S8100 Media Servers" vendor="Avaya"><vers num=""/></prod><prod name="Windows 2000" vendor="Microsoft"><vers num="Advanced Server"/><vers num="Advanced Server SP1"/><vers num="Advanced Server SP2"/><vers num="Advanced Server SP3"/><vers num="Advanced Server SP4"/><vers num="Datacenter Server"/><vers num="Datacenter Server SP1"/><vers num="Datacenter Server SP2"/><vers num="Datacenter Server SP3"/><vers num="Datacenter Server SP4"/><vers num="Professional"/><vers num="Professional SP1"/><vers num="Professional SP2"/><vers num="Professional SP3"/><vers num="Professional SP4"/><vers num="Server"/><vers num="Server SP1"/><vers num="Server SP2"/><vers num="Server SP3"/><vers num="Server SP4"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-05-08" name="CVE-2007-2375" published="2007-04-30" seq="2007-2375" severity="High" type="CVE"><desc><descript source="cve">The agent remote upgrade interface in Symantec Enterprise Security Manager (ESM) before 20070405 does not verify the authenticity of upgrades, which allows remote attackers to execute arbitrary code via software that implements the agent upgrade protocol.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" source="" url="http://www.symantec.com/avcenter/security/Content/2007.04.05d.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/23287">23287</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/24767">24767</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1017881">
1017881</ref></refs><vuln_soft><prod name="Enterprise Security Manager" vendor="Symantec"><vers num="5.5.3"/><vers num="6.0"/><vers num="6.5"/><vers num="6.5.1"/><vers num="6.5.2"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0" modified="2007-05-08" name="CVE-2007-2376" published="2007-04-30" seq="2007-2376" severity="Medium" type="CVE"><desc><descript source="cve">The Dojo framework exchanges data using JavaScript Object Notation (JSON) without an associated protection scheme, which allows remote attackers to obtain the data via a web page that retrieves the data through a URL in the SRC attribute of a SCRIPT element and captures the data using other JavaScript code, aka &quot;JavaScript Hijacking.&quot;</descript></desc><loss_types><conf/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref source="" url="http://www.fortifysoftware.com/servlet/downloads/public/JavaScript_Hijacking.pdf"></ref></refs><vuln_soft><prod name="Dojo Toolkit" vendor="Dojo Toolkit"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0" modified="2007-05-08" name="CVE-2007-2377" published="2007-04-30" seq="2007-2377" severity="Medium" type="CVE"><desc><descript source="cve">The Getahead Direct Web Remoting (DWR) framework 1.1.4 exchanges data using JavaScript Object Notation (JSON) without an associated protection scheme, which allows remote attackers to obtain the data via a web page that retrieves the data through a URL in the SRC attribute of a SCRIPT element and captures the data using other JavaScript code, aka &quot;JavaScript Hijacking.&quot;</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://www.fortifysoftware.com/servlet/downloads/public/JavaScript_Hijacking.pdf"></ref></refs><vuln_soft><prod name="Direct Web Remoting" vendor="Getahead"><vers num="1.1.4"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0" modified="2007-05-08" name="CVE-2007-2378" published="2007-04-30" seq="2007-2378" severity="Medium" type="CVE"><desc><descript source="cve">The Google Web Toolkit (GWT) framework exchanges data using JavaScript Object Notation (JSON) without an associated protection scheme, which allows remote attackers to obtain the data via a web page that retrieves the data through a URL in the SRC attribute of a SCRIPT element and captures the data using other JavaScript code, aka &quot;JavaScript Hijacking.&quot;</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://www.fortifysoftware.com/servlet/downloads/public/JavaScript_Hijacking.pdf"></ref></refs><vuln_soft><prod name="Google Web Toolkit" vendor="Google"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0" modified="2007-05-08" name="CVE-2007-2379" published="2007-04-30" seq="2007-2379" severity="Medium" type="CVE"><desc><descript source="cve">The jQuery framework exchanges data using JavaScript Object Notation (JSON) without an associated protection scheme, which allows remote attackers to obtain the data via a web page that retrieves the data through a URL in the SRC attribute of a SCRIPT element and captures the data using other JavaScript code, aka &quot;JavaScript Hijacking.&quot;</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://www.fortifysoftware.com/servlet/downloads/public/JavaScript_Hijacking.pdf"></ref></refs><vuln_soft><prod name="jQuery" vendor="jQuery"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0" modified="2007-05-08" name="CVE-2007-2380" published="2007-04-30" seq="2007-2380" severity="Medium" type="CVE"><desc><descript source="cve">The Microsoft Atlas framework exchanges data using JavaScript Object Notation (JSON) without an associated protection scheme, which allows remote attackers to obtain the data via a web page that retrieves the data through a URL in the SRC attribute of a SCRIPT element and captures the data using other JavaScript code, aka &quot;JavaScript Hijacking.&quot;</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://www.fortifysoftware.com/servlet/downloads/public/JavaScript_Hijacking.pdf"></ref></refs><vuln_soft><prod name="Atlas framework" vendor="Microsoft"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0" modified="2007-05-08" name="CVE-2007-2381" published="2007-04-30" seq="2007-2381" severity="Medium" type="CVE"><desc><descript source="cve">The MochiKit framework exchanges data using JavaScript Object Notation (JSON) without an associated protection scheme, which allows remote attackers to obtain the data via a web page that retrieves the data through a URL in the SRC attribute of a SCRIPT element and captures the data using other JavaScript code, aka &quot;JavaScript Hijacking.&quot;</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://www.fortifysoftware.com/servlet/downloads/public/JavaScript_Hijacking.pdf"></ref></refs><vuln_soft><prod name="MochiKit Framework" vendor="Mochikit"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0" modified="2007-05-08" name="CVE-2007-2382" published="2007-04-30" seq="2007-2382" severity="Medium" type="CVE"><desc><descript source="cve">The Moo.fx framework exchanges data using JavaScript Object Notation (JSON) without an associated protection scheme, which allows remote attackers to obtain the data via a web page that retrieves the data through a URL in the SRC attribute of a SCRIPT element and captures the data using other JavaScript code, aka &quot;JavaScript Hijacking.&quot;</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://www.fortifysoftware.com/servlet/downloads/public/JavaScript_Hijacking.pdf"></ref></refs><vuln_soft><prod name="Moo.fx" vendor="Mad4Milk"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0" modified="2007-12-31" name="CVE-2007-2383" published="2007-04-30" seq="2007-2383" severity="Medium" type="CVE"><desc><descript source="cve">The Prototype (prototypejs) framework before 1.5.1 RC3 exchanges data using JavaScript Object Notation (JSON) without an associated protection scheme, which allows remote attackers to obtain the data via a web page that retrieves the data through a URL in the SRC attribute of a SCRIPT element and captures the data using other JavaScript code, aka &quot;JavaScript Hijacking.&quot;</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://www.fortifysoftware.com/servlet/downloads/public/JavaScript_Hijacking.pdf"></ref><ref source="" url="http://dev.rubyonrails.org/ticket/7910"></ref><ref source="" url="http://prototypejs.org/2007/4/24/release-candidate-3"></ref></refs><vuln_soft><prod name="Prototype framework" vendor="PrototypeJS"><vers num="1.5.1_RC3"/></prod></vuln_soft></entry><entry CVSS_base_score="7.8" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.9" CVSS_score="7.8" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:N/A:N)" CVSS_version="2.0" modified="2007-05-08" name="CVE-2007-2384" published="2007-04-30" seq="2007-2384" severity="High" type="CVE"><desc><descript source="cve">The Script.aculo.us framework exchanges data using JavaScript Object Notation (JSON) without an associated protection scheme, which allows remote attackers to obtain the data via a web page that retrieves the data through a URL in the SRC attribute of a SCRIPT element and captures the data using other JavaScript code, aka &quot;JavaScript Hijacking.&quot;</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://www.fortifysoftware.com/servlet/downloads/public/JavaScript_Hijacking.pdf"></ref></refs><vuln_soft><prod name="Script.aculo.us" vendor="Script.aculo.us"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0" modified="2007-05-08" name="CVE-2007-2385" published="2007-04-30" seq="2007-2385" severity="Medium" type="CVE"><desc><descript source="cve">The Yahoo! UI framework exchanges data using JavaScript Object Notation (JSON) without an associated protection scheme, which allows remote attackers to obtain the data via a web page that retrieves the data through a URL in the SRC attribute of a SCRIPT element and captures the data using other JavaScript code, aka &quot;JavaScript Hijacking.&quot;</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://www.fortifysoftware.com/servlet/downloads/public/JavaScript_Hijacking.pdf"></ref></refs><vuln_soft><prod name="Yahoo UI framework" vendor="Yahoo"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="9.4" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="9.2" CVSS_score="9.4" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:N/A:C)" CVSS_version="2.0" modified="2007-05-29" name="CVE-2007-2386" published="2007-05-24" seq="2007-2386" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in mDNSResponder in Apple Mac OS X 10.4 up to 10.4.9 allows remote attackers to cause a denial of service (application termination) or execute arbitrary code via a crafted UPnP Internet Gateway Device (IGD) packet.</descript></desc><loss_types><avail/><conf/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2007/May/msg00004.html">APPLE-SA-2007-05-24</ref><ref source="" url="http://docs.info.apple.com/article.html?artnum=305530"></ref><ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2007/Jun/msg00001.html">APPLE-SA-2007-06-20</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/221876">VU#221876</ref><ref source="BID" url="http://www.securityfocus.com/bid/24144">24144</ref><ref source="BID" url="http://www.securityfocus.com/bid/24159">24159</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1939">ADV-2007-1939</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/2269">ADV-2007-2269</ref><ref source="OSVDB" url="http://www.osvdb.org/35142">35142</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1018123">1018123</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25402">25402</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25745">25745</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/34493">macos-mdnsresponder-upnp-bo(34493)</ref></refs><vuln_soft><prod name="Mac OS X" vendor="Apple"><vers num="10.4"/><vers num="10.4.1"/><vers num="10.4.2"/><vers num="10.4.3"/><vers num="10.4.4"/><vers num="10.4.5"/><vers num="10.4.6"/><vers num="10.4.7"/><vers num="10.4.8"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-06-05" name="CVE-2007-2387" published="2007-06-04" seq="2007-2387" severity="High" type="CVE"><desc><descript source="cve">Apple Xserve Lights-Out Management before Firmware Update 1.0 on Intel hardware does not require a password for remote access to IPMI, which allows remote attackers to gain administrative access via unspecified requests with ipmitool.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref patch="1" source="" url="http://docs.info.apple.com/article.html?artnum=305571"></ref><ref source="" url="http://www.apple.com/support/downloads/xservelightsoutmanagementfirmwareupdate10.html"></ref><ref patch="1" source="APPLE" url="http://lists.apple.com/archives/security-announce/2007/May/msg00006.html">APPLE-SA-2007-05-31</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/24257">24257</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/2014">ADV-2007-2014</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/25499">25499</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1018181">1018181</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/34651">xserve-ipmi-privilege-escalation(34651)</ref></refs><vuln_soft><prod name="Xserve Lights-Out Management" vendor="Apple"><vers num="Firmware 0"/></prod></vuln_soft></entry><entry CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" CVSS_score="9.3" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-12-29" name="CVE-2007-2388" published="2007-05-29" seq="2007-2388" severity="High" type="CVE"><desc><descript source="cve">Apple QuickTime for Java 7.1.6 on Mac OS X and Windows does not properly restrict QTObject subclassing, which allows remote attackers to execute arbitrary code via a web page containing a user-defined class that accesses unsafe functions that can be leveraged to write to arbitrary memory locations.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><design/></vuln_types><range><network/><user_init/></range><refs><ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2007/May/msg00005.html">APPLE-SA-2007-05-29</ref><ref adv="1" source="" url="http://secunia.com/secunia_research/2007-52/advisory/"></ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/995836">VU#995836</ref><ref source="BID" url="http://www.securityfocus.com/bid/24221">24221</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1974">ADV-2007-1974</ref><ref source="OSVDB" url="http://www.osvdb.org/35576">35576</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1018136">1018136</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/25130">25130</ref></refs><vuln_soft><prod name="Quicktime" vendor="Apple"><vers edition="Java" num="7.1.6"/></prod></vuln_soft></entry><entry CVSS_base_score="7.1" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.9" CVSS_score="7.1" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:N/A:N)" CVSS_version="2.0" modified="2007-06-13" name="CVE-2007-2389" published="2007-05-29" seq="2007-2389" severity="High" type="CVE"><desc><descript source="cve">Apple QuickTime for Java 7.1.6 on Mac OS X and Windows does not clear potentially sensitive memory before use, which allows remote attackers to read memory from a web browser via unknown vectors related to Java applets.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/><user_init/></range><refs><ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2007/May/msg00005.html">APPLE-SA-2007-05-29</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/434748">VU#434748</ref><ref source="BID" url="http://www.securityfocus.com/bid/24222">24222</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1974">ADV-2007-1974</ref><ref source="OSVDB" url="http://www.osvdb.org/35575">35575</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1018136">1018136</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25130">25130</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/34571">quicktime-applet-information-disclosure(34571)</ref></refs><vuln_soft><prod name="Quicktime" vendor="Apple"><vers edition="Java" num="7.1.6"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-05-29" name="CVE-2007-2390" published="2007-05-24" seq="2007-2390" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in iChat in Apple Mac OS X 10.3.9 and 10.4.9 allows remote attackers to cause a denial of service (application termination) and possibly execute arbitrary code via a crafted UPnP Internet Gateway Device (IGD) packet.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2007/May/msg00004.html">APPLE-SA-2007-05-24</ref><ref source="" url="http://docs.info.apple.com/article.html?artnum=305530"></ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/116100">VU#116100</ref><ref source="BID" url="http://www.securityfocus.com/bid/24144">24144</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1939">ADV-2007-1939</ref><ref source="OSVDB" url="http://www.osvdb.org/35141">35141</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1018119">1018119</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25402">25402</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/34502">macos-ichat-bo(34502)</ref></refs><vuln_soft><prod name="Mac OS X" vendor="Apple"><vers num="10.3.9"/><vers num="10.4.9"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" modified="2007-12-27" name="CVE-2007-2391" published="2007-06-14" seq="2007-2391" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in Apple Safari Beta 3.0.1 for Windows allows remote attackers to inject arbitrary web script or HTML via a web page that includes a windows.setTimeout function that is activated after the user has moved from the current page.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref patch="1" source="APPLE" url="http://lists.apple.com/archives/security-announce/2007/Jun/msg00000.html">APPLE-SA-2007-06-14</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/471255/100/0/threaded">20070613 Apple Safari: cookie stealing</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/471266/100/0/threaded">20070613 Re: [Full-disclosure] Apple Safari: cookie stealing</ref><ref source="BID" url="http://www.securityfocus.com/bid/24457">24457</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/2192">ADV-2007-2192</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1018238">1018238</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/34847">safari-settimeout-security-bypass(34847)</ref></refs><vuln_soft><prod name="Safari" vendor="Apple"><vers edition="Windows" num="3.0.1 Beta"/></prod></vuln_soft></entry><entry CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" CVSS_score="9.3" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-07-18" name="CVE-2007-2392" published="2007-07-15" seq="2007-2392" severity="High" type="CVE"><desc><descript source="cve">Apple Quicktime before 7.2 on Mac OS X 10.3.9 and 10.4.9 allows user-assisted remote attackers to execute arbitrary code via a crafted movie file that triggers memory corruption.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref patch="1" source="" url="http://docs.info.apple.com/article.html?artnum=305947"></ref><ref patch="1" source="APPLE" url="http://lists.apple.com/archives/Security-announce/2007/Jul/msg00001.html">APPLE-SA-2007-07-11</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/582681">VU#582681</ref><ref source="BID" url="http://www.securityfocus.com/bid/24873">24873</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/2510">ADV-2007-2510</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/26034">26034</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/35353">quicktime-moviefile-code-execution(35353)</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA07-193A.html">TA07-193A</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1018373">1018373</ref></refs><vuln_soft><prod name="Quicktime" vendor="Apple"><vers num="7.0"/><vers num="7.0.1"/><vers num="7.0.2"/><vers num="7.0.3"/><vers num="7.0.4"/><vers num="7.0.8"/><vers num="7.1"/><vers num="7.1.1"/><vers num="7.1.2"/><vers num="7.1.3"/><vers num="7.1.4"/><vers num="7.1.5"/></prod></vuln_soft></entry><entry CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" CVSS_score="9.3" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-07-18" name="CVE-2007-2393" published="2007-07-15" seq="2007-2393" severity="High" type="CVE"><desc><descript source="cve">The design of QuickTime for Java in Apple Quicktime before 7.2 allows remote attackers to bypass certain security controls and write to process memory via Java applets, possibly leading to arbitrary code execution.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><design/></vuln_types><range><network/><user_init/></range><refs><ref patch="1" source="" url="http://docs.info.apple.com/article.html?artnum=305947"></ref><ref patch="1" source="APPLE" url="http://lists.apple.com/archives/Security-announce/2007/Jul/msg00001.html">APPLE-SA-2007-07-11</ref><ref source="BID" url="http://www.securityfocus.com/bid/24873">24873</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/2510">ADV-2007-2510</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/26034">26034</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/35359">quicktime-java-applet-code-execution(35359)</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA07-193A.html">TA07-193A</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1018373">1018373</ref></refs><vuln_soft><prod name="Quicktime" vendor="Apple"><vers num="7.0"/><vers num="7.0.1"/><vers num="7.0.2"/><vers num="7.0.3"/><vers num="7.0.4"/><vers num="7.0.8"/><vers num="7.1"/><vers num="7.1.1"/><vers num="7.1.2"/><vers num="7.1.3"/><vers num="7.1.4"/><vers num="7.1.5"/></prod></vuln_soft></entry><entry CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" CVSS_score="9.3" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-07-18" name="CVE-2007-2394" published="2007-07-15" seq="2007-2394" severity="High" type="CVE"><desc><descript source="cve">Integer overflow in Apple Quicktime before 7.2 on Mac OS X 10.3.9 and 10.4.9 allows user-assisted remote attackers to execute arbitrary code via crafted (1) title and (2) author fields in an SMIL file, related to improper calculations for memory allocation.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/><user_init/></range><refs><ref patch="1" source="IDEFENSE" url="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=556">20070711 Apple QuickTime SMIL File Processing Integer Overflow Vulnerability</ref><ref patch="1" source="" url="http://docs.info.apple.com/article.html?artnum=305947"></ref><ref patch="1" source="APPLE" url="http://lists.apple.com/archives/Security-announce/2007/Jul/msg00001.html">APPLE-SA-2007-07-11</ref><ref source="BID" url="http://www.securityfocus.com/bid/24873">24873</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/2510">ADV-2007-2510</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/26034">26034</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/35357">quicktime-smil-overflow(35357)</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/473882/100/100/threaded">20070717 Re: iDefense Security Advisory 07.11.07: Apple QuickTime SMIL File Processing Integer Overflow Vulnerability</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA07-193A.html">TA07-193A</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1018373">1018373</ref></refs><vuln_soft><prod name="Quicktime" vendor="Apple"><vers num="7.0"/><vers num="7.0.1"/><vers num="7.0.2"/><vers num="7.0.3"/><vers num="7.0.4"/><vers num="7.0.8"/><vers num="7.1"/><vers num="7.1.1"/><vers num="7.1.2"/><vers num="7.1.3"/><vers num="7.1.4"/><vers num="7.1.5"/></prod></vuln_soft></entry><entry CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" CVSS_score="9.3" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2008-02-22" name="CVE-2007-2395" published="2007-11-07" seq="2007-2395" severity="High" type="CVE"><desc><descript source="cve">Unspecified vulnerability in Apple QuickTime before 7.3 allows remote attackers to execute arbitrary code via a crafted image description atom in a movie file, related to &quot;memory corruption.&quot;</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><range><network/><user_init/></range><refs><ref patch="1" source="" url="http://docs.info.apple.com/article.html?artnum=306896"></ref><ref adv="1" source="APPLE" url="http://lists.apple.com/archives/Security-announce/2007/Nov/msg00000.html">APPLE-SA-2007-11-05</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/3723">ADV-2007-3723</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1018894">1018894</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/27523">27523</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA07-310A.html">TA07-310A</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/797875">VU#797875</ref><ref source="BID" url="http://www.securityfocus.com/bid/26340">26340</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/38266">apple-quicktime-movie-code-execution(38266)</ref></refs><vuln_soft><prod name="Quicktime" vendor="Apple"><vers num="7.2" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" CVSS_score="9.3" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-07-18" name="CVE-2007-2396" published="2007-07-15" seq="2007-2396" severity="High" type="CVE"><desc><descript source="cve">The JDirect support in QuickTime for Java in Apple Quicktime before 7.2 exposes certain dangerous interfaces, which allows remote attackers to execute arbitrary code via crafted Java applets.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input/><design/></vuln_types><range><network/><user_init/></range><refs><ref patch="1" source="" url="http://docs.info.apple.com/article.html?artnum=305947"></ref><ref patch="1" source="APPLE" url="http://lists.apple.com/archives/Security-announce/2007/Jul/msg00001.html">APPLE-SA-2007-07-11</ref><ref source="BID" url="http://www.securityfocus.com/bid/24873">24873</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/2510">ADV-2007-2510</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/26034">26034</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/35360">quicktime-jdirect-code-execution(35360)</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA07-193A.html">TA07-193A</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1018373">1018373</ref></refs><vuln_soft><prod name="Quicktime" vendor="Apple"><vers num="7.0"/><vers num="7.0.1"/><vers num="7.0.2"/><vers num="7.0.3"/><vers num="7.0.4"/><vers num="7.0.8"/><vers num="7.1"/><vers num="7.1.1"/><vers num="7.1.2"/><vers num="7.1.3"/><vers num="7.1.4"/><vers num="7.1.5"/></prod></vuln_soft></entry><entry CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" CVSS_score="9.3" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-07-18" name="CVE-2007-2397" published="2007-07-15" seq="2007-2397" severity="High" type="CVE"><desc><descript source="cve">QuickTime for Java in Apple Quicktime before 7.2 does not properly check permissions, which allows remote attackers to disable security controls and execute arbitrary code via crafted Java applets.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><access/></vuln_types><range><network/><user_init/></range><refs><ref patch="1" source="" url="http://docs.info.apple.com/article.html?artnum=305947"></ref><ref patch="1" source="APPLE" url="http://lists.apple.com/archives/Security-announce/2007/Jul/msg00001.html">APPLE-SA-2007-07-11</ref><ref source="BID" url="http://www.securityfocus.com/bid/24873">24873</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/2510">ADV-2007-2510</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/26034">26034</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/35358">quicktime-applet-code-execution(35358)</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA07-193A.html">TA07-193A</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1018373">1018373</ref></refs><vuln_soft><prod name="Quicktime" vendor="Apple"><vers num="7.0"/><vers num="7.0.1"/><vers num="7.0.2"/><vers num="7.0.3"/><vers num="7.0.4"/><vers num="7.0.8"/><vers num="7.1"/><vers num="7.1.1"/><vers num="7.1.2"/><vers num="7.1.3"/><vers num="7.1.4"/><vers num="7.1.5"/></prod></vuln_soft></entry><entry CVSS_base_score="7.1" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.9" CVSS_score="7.1" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:C/A:N)" CVSS_version="2.0" modified="2007-06-21" name="CVE-2007-2398" published="2007-06-21" seq="2007-2398" severity="High" type="CVE"><desc><descript source="cve">Apple Safari 3.0.1 beta (522.12.12) on Windows allows remote attackers to modify the window title and address bar while filling the main window with arbitrary content by setting the location bar and using setTimeout() to create an event that modifies the window content, which could facilitate phishing attacks.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref source="FULLDISC" url="http://archives.neohapsis.com/archives/fulldisclosure/2007-06/0311.html">20070614 Re: Apple Safari: urlbar/window title spoofing</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/471452/100/0/threaded">20070614 Re: [Full-disclosure] Apple Safari: urlbar/window title spoofing</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/471454/100/0/threaded">20070615 Re: [Full-disclosure] Apple Safari: urlbar/window title spoofing</ref><ref source="APPLE" url="http://lists.apple.com/archives/Security-announce/2007/Jun/msg00004.html">APPLE-SA-2007-06-22</ref><ref source="BID" url="http://www.securityfocus.com/bid/24484">24484</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/2316">ADV-2007-2316</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1018282">1018282</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/35050">safari-addressbar-spoofing(35050)</ref><ref source="" url="http://support.apple.com/kb/HT1467"></ref><ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2008/Apr/msg00001.html">APPLE-SA-2008-04-16</ref></refs><vuln_soft><prod name="Safari" vendor="Apple"><vers edition="Windows" num="3.0.1 Beta"/></prod></vuln_soft></entry><entry CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" CVSS_score="9.3" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-12-26" name="CVE-2007-2399" published="2007-06-25" seq="2007-2399" severity="High" type="CVE"><desc><descript source="cve">WebKit in Apple Mac OS X 10.3.9, 10.4.9 and later, and iPhone before 1.0.1 performs an &quot;invalid type conversion&quot;, which allows remote attackers to execute arbitrary code via unspecified frame sets that trigger memory corruption.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref source="" url="http://docs.info.apple.com/article.html?artnum=305759"></ref><ref source="APPLE" url="http://lists.apple.com/archives/Security-announce/2007/Jun/msg00003.html">APPLE-SA-2007-06-22</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/389868">VU#389868</ref><ref source="BID" url="http://www.securityfocus.com/bid/24597">24597</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/2296">ADV-2007-2296</ref><ref patch="1" source="SECTRACK" url="http://www.securitytracker.com/id?1018281">1018281</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/25786">25786</ref><ref source="" url="http://docs.info.apple.com/article.html?artnum=306173"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/2316">ADV-2007-2316</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/2731">ADV-2007-2731</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/26287">26287</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/35019">macos-framesets-code-execution(35019)</ref></refs><vuln_soft><prod name="Mac OS X Server" vendor="Apple"><vers num="10.3.9"/><vers num="10.4.9"/></prod><prod name="Mac OS X" vendor="Apple"><vers num="10.3.9"/><vers num="10.4.9"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" modified="2007-12-26" name="CVE-2007-2400" published="2007-06-25" seq="2007-2400" severity="Medium" type="CVE"><desc><descript source="cve">Race condition in Apple Safari 3 Beta before 3.0.2 on Mac OS X, Windows XP, Windows Vista, and iPhone before 1.0.1, allows remote attackers to bypass the JavaScript security model and modify pages outside of the security domain and conduct cross-site scripting (XSS) attacks via vectors related to page updating and HTTP redirects.</descript></desc><loss_types><int/></loss_types><vuln_types><race/></vuln_types><range><network/><user_init/></range><refs><ref patch="1" source="APPLE" url="http://lists.apple.com/archives/Security-announce/2007/Jun/msg00004.html">APPLE-SA-2007-06-22</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/24599">24599</ref><ref patch="1" source="SECTRACK" url="http://www.securitytracker.com/id?1018282">1018282</ref><ref source="" url="http://docs.info.apple.com/article.html?artnum=306173"></ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/289988">VU#289988</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/2316">ADV-2007-2316</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/2731">ADV-2007-2731</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/26287">26287</ref></refs><vuln_soft><prod name="Safari" vendor="Apple"><vers edition="Windows" num="3 Beta"/><vers edition="Windows" num="3.0.1 Beta"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" modified="2007-12-26" name="CVE-2007-2401" published="2007-06-25" seq="2007-2401" severity="Medium" type="CVE"><desc><descript source="cve">CRLF injection vulnerability in WebCore in Apple Mac OS X 10.3.9, 10.4.9 and later, and iPhone before 1.0.1, allows remote attackers to inject arbitrary HTTP headers via LF characters in an XMLHttpRequest request, which are not filtered when serializing headers via the setRequestHeader function.  NOTE: this issue can be leveraged for cross-site scripting (XSS) attacks.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="" url="http://www.westpoint.ltd.uk/advisories/wp-07-0002.txt"></ref><ref source="" url="http://docs.info.apple.com/article.html?artnum=305759"></ref><ref patch="1" source="APPLE" url="http://lists.apple.com/archives/Security-announce/2007/Jun/msg00003.html">APPLE-SA-2007-06-22</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/845708">VU#845708</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/24598">24598</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/2296">ADV-2007-2296</ref><ref patch="1" source="SECTRACK" url="http://www.securitytracker.com/id?1018281">1018281</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/25786">25786</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/472198/100/0/threaded">20070625 Safari XMLHttpRequest HTTP header injection</ref><ref source="" url="http://docs.info.apple.com/article.html?artnum=306173"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/2316">ADV-2007-2316</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/2731">ADV-2007-2731</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/26287">26287</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/35017">macos-xmlhttprequest-header-injection(35017)</ref></refs><vuln_soft><prod name="Mac OS X Server" vendor="Apple"><vers num="10.3.9"/><vers num="10.4.9"/></prod><prod name="Mac OS X" vendor="Apple"><vers num="10.3.9"/><vers num="10.4.9"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)" CVSS_version="2.0" modified="2008-04-22" name="CVE-2007-2402" published="2007-07-15" seq="2007-2402" severity="Medium" type="CVE"><desc><descript source="cve">QuickTime for Java in Apple Quicktime before 7.2 does not perform sufficient &quot;access control,&quot; which allows remote attackers to obtain sensitive information (screen content) via crafted Java applets.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/><user_init/></range><refs><ref patch="1" source="" url="http://docs.info.apple.com/article.html?artnum=305947"></ref><ref patch="1" source="APPLE" url="http://lists.apple.com/archives/Security-announce/2007/Jul/msg00001.html">APPLE-SA-2007-07-11</ref><ref source="BID" url="http://www.securityfocus.com/bid/24873">24873</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/2510">ADV-2007-2510</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/26034">26034</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/35361">quicktime-java-information-disclosure(35361)</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA07-193A.html">TA07-193A</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1018373">1018373</ref></refs><vuln_soft><prod name="Quicktime" vendor="Apple"><vers num="7.0"/><vers num="7.0.1"/><vers num="7.0.2"/><vers num="7.0.3"/><vers num="7.0.4"/><vers num="7.0.8"/><vers num="7.1"/><vers num="7.1.1"/><vers num="7.1.2"/><vers num="7.1.3"/><vers num="7.1.4"/><vers num="7.1.5"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-08-03" name="CVE-2007-2403" published="2007-08-03" seq="2007-2403" severity="Medium" type="CVE"><desc><descript source="cve">CFNetwork on Apple Mac OS X 10.3.9 and 10.4.10 does not properly validate ftp: URIs, which allows remote attackers to trigger the transmission of arbitrary FTP commands to arbitrary FTP servers.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/35721">macos-ftp-command-execution(35721)</ref><ref source="" url="http://docs.info.apple.com/article.html?artnum=306172"></ref><ref source="APPLE" url="http://lists.apple.com/archives/security-announce//2007/Jul/msg00004.html">APPLE-SA-2007-07-31</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/25159">25159</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/2732">ADV-2007-2732</ref><ref patch="1" source="SECTRACK" url="http://securitytracker.com/id?1018491">1018491</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/26235">26235</ref></refs><vuln_soft><prod name="CFNetwork" vendor="Apple"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" modified="2007-08-03" name="CVE-2007-2404" published="2007-08-03" seq="2007-2404" severity="Medium" type="CVE"><desc><descript source="cve">CRLF injection vulnerability in CFNetwork on Apple Mac OS X 10.3.9 and 10.4.10 before 20070731 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via CRLF sequences in an unspecified context.  NOTE: this can be leveraged for cross-site scripting (XSS) attacks.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref patch="1" source="" url="http://docs.info.apple.com/article.html?artnum=306172"></ref><ref source="APPLE" url="http://lists.apple.com/archives/security-announce//2007/Jul/msg00004.html">APPLE-SA-2007-07-31</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/25159">25159</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/2732">ADV-2007-2732</ref><ref patch="1" source="SECTRACK" url="http://securitytracker.com/id?1018491">1018491</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/26235">26235</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/35723">macos-cfnetwork-response-splitting(35723)</ref></refs><vuln_soft><prod name="Mac OS X Server" vendor="Apple"><vers num="10.3"/><vers num="10.3.1"/><vers num="10.3.2"/><vers num="10.3.3"/><vers num="10.3.4"/><vers num="10.3.5"/><vers num="10.3.6"/><vers num="10.3.7"/><vers num="10.3.8"/><vers num="10.3.9"/><vers num="10.4"/><vers num="10.4.1"/><vers num="10.4.10"/><vers num="10.4.2"/><vers num="10.4.3"/><vers num="10.4.4"/><vers num="10.4.5"/><vers num="10.4.6"/><vers num="10.4.7"/><vers num="10.4.8"/><vers num="10.4.9"/></prod><prod name="Mac OS X" vendor="Apple"><vers num="10.3"/><vers num="10.3.1"/><vers num="10.3.2"/><vers num="10.3.3"/><vers num="10.3.4"/><vers num="10.3.5"/><vers num="10.3.6"/><vers num="10.3.7"/><vers num="10.3.8"/><vers num="10.3.9"/><vers num="10.4"/><vers num="10.4.1"/><vers num="10.4.10"/><vers num="10.4.2"/><vers num="10.4.3"/><vers num="10.4.4"/><vers num="10.4.5"/><vers num="10.4.6"/><vers num="10.4.7"/><vers num="10.4.8"/><vers num="10.4.9"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-08-03" name="CVE-2007-2405" published="2007-08-03" seq="2007-2405" severity="Medium" type="CVE"><desc><descript source="cve">Integer underflow in Preview in PDFKit on Apple Mac OS X 10.4.10 allows remote attackers to execute arbitrary code via a crafted PDF file.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref source="" url="http://docs.info.apple.com/article.html?artnum=306172"></ref><ref source="APPLE" url="http://lists.apple.com/archives/security-announce//2007/Jul/msg00004.html">APPLE-SA-2007-07-31</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/25159">25159</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/2732">ADV-2007-2732</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/26235">26235</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/35734">macos-pdfkit-code-execution(35734)</ref></refs><vuln_soft><prod name="PDFKit" vendor="Apple"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-08-03" name="CVE-2007-2406" published="2007-08-03" seq="2007-2406" severity="Medium" type="CVE"><desc><descript source="cve">Quartz Composer on Apple Mac OS X 10.4.10 does not initialize a certain object pointer, which might allow user-assisted remote attackers to execute arbitrary code via a crafted Quartz Composer file.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref source="" url="http://docs.info.apple.com/article.html?artnum=306172"></ref><ref source="APPLE" url="http://lists.apple.com/archives/security-announce//2007/Jul/msg00004.html">APPLE-SA-2007-07-31</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/25159">25159</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/2732">ADV-2007-2732</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/26235">26235</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/35737">macos-quartzcomposer-code-execution(35737)</ref></refs><vuln_soft><prod name="Quartz Composer" vendor="Apple"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="4.0" CVSS_exploit_subscore="8.0" CVSS_impact_subscore="2.9" CVSS_score="4.0" CVSS_vector="(AV:N/AC:L/Au:S/C:N/I:N/A:P)" CVSS_version="2.0" modified="2007-08-03" name="CVE-2007-2407" published="2007-08-03" seq="2007-2407" severity="Medium" type="CVE"><desc><descript source="cve">The Samba server on Apple Mac OS X 10.3.9 and 10.4.10, when Windows file sharing is enabled, does not enforce disk quotas after dropping privileges, which allows remote authenticated users to use disk space in excess of quota.</descript></desc><loss_types><avail/></loss_types><vuln_types><design/><exception/></vuln_types><range><network/></range><refs><ref source="" url="http://docs.info.apple.com/article.html?artnum=306172"></ref><ref source="APPLE" url="http://lists.apple.com/archives/security-announce//2007/Jul/msg00004.html">APPLE-SA-2007-07-31</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/25159">25159</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/2732">ADV-2007-2732</ref><ref source="SECUNIA" url="http://secunia.com/advisories/26235">26235</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/35738">samba-filesystem-security-bypass(35738)</ref></refs><vuln_soft><prod name="Samba Server" vendor="Samba"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" CVSS_score="9.3" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-08-06" name="CVE-2007-2408" published="2007-08-03" seq="2007-2408" severity="High" type="CVE"><desc><descript source="cve">WebKit in Apple Safari 3 Beta before Update 3.0.3 does not properly recognize an unchecked &quot;Enable Java&quot; setting, which allows remote attackers to execute Java applets via a crafted web page.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><design/></vuln_types><range><network/><user_init/></range><refs><ref source="" url="http://isc.sans.org/diary.html?storyid=3214"></ref><ref patch="1" source="" url="http://docs.info.apple.com/article.html?artnum=306174"></ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/25157">25157</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/2730">ADV-2007-2730</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/35714">safari-applet-security-bypass(35714)</ref></refs><vuln_soft><prod name="Safari" vendor="Apple"><vers edition="Windows" num="3.0.1 Beta"/><vers num="3.0.1 Beta"/><vers edition="Windows" num="3.0.2 Beta"/><vers num="3.0.2 Beta"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)" CVSS_version="2.0" modified="2007-08-03" name="CVE-2007-2409" published="2007-08-03" seq="2007-2409" severity="Medium" type="CVE"><desc><descript source="cve">Cross-domain vulnerability in WebCore on Apple Mac OS X 10.3.9 and 10.4.10 allows remote attackers to obtain sensitive information via a popup window, which is able to read the current URL of the parent window.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/><user_init/></range><refs><ref source="" url="http://docs.info.apple.com/article.html?artnum=306172"></ref><ref source="APPLE" url="http://lists.apple.com/archives/security-announce//2007/Jul/msg00004.html">APPLE-SA-2007-07-31</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/25159">25159</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/2732">ADV-2007-2732</ref><ref patch="1" source="SECTRACK" url="http://securitytracker.com/id?1018494">1018494</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/26235">26235</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/35740">macos-webcore-information-disclosure(35740)</ref></refs><vuln_soft><prod name="WebCore" vendor="Apple"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" modified="2007-08-03" name="CVE-2007-2410" published="2007-08-03" seq="2007-2410" severity="Medium" type="CVE"><desc><descript source="cve">WebCore on Apple Mac OS X 10.3.9 and 10.4.10 retains properties of certain global objects when a new URL is visited in the same window, which allows remote attackers to conduct cross-site scripting (XSS) attacks.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref source="" url="http://docs.info.apple.com/article.html?artnum=306172"></ref><ref source="APPLE" url="http://lists.apple.com/archives/security-announce//2007/Jul/msg00004.html">APPLE-SA-2007-07-31</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/25159">25159</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/2732">ADV-2007-2732</ref><ref patch="1" source="SECTRACK" url="http://securitytracker.com/id?1018494">1018494</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/26235">26235</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/35743">safari-global-objects-security-bypass(35743)</ref></refs><vuln_soft><prod name="WebCore" vendor="Apple"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-05-08" name="CVE-2007-2411" published="2007-05-01" seq="2007-2411" severity="High" type="CVE"><desc><descript source="cve">** DISPUTED **  PHP remote file inclusion vulnerability in index.php in Sphider 1.2.x allows remote attackers to execute arbitrary PHP code via a URL in the include_dir parameter.  NOTE: a third party disputes this vulnerability, stating that &quot;the application is not vulnerable to this issue.&quot;</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/467102/100/0/threaded">20070428 Sphider Version 1.2.x (include_dir) file include</ref><ref source="BID" url="http://www.securityfocus.com/bid/23699">23699</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/467220/100/0/threaded">20070430 Re: Sphider Version 1.2.x (include_dir) file include</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33963">sphider-index-file-include(33963)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2648">2648</ref></refs><vuln_soft><prod name="Sphider" vendor="Sphider"><vers num="1.2.7" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.8" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.9" CVSS_score="7.8" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:N/A:N)" CVSS_version="2.0" modified="2007-05-08" name="CVE-2007-2412" published="2007-05-01" seq="2007-2412" severity="High" type="CVE"><desc><descript source="cve">** DISPUTED **  Directory traversal vulnerability in modules/file.php in Seir Anphin allows remote attackers to obtain sensitive information via a .. (dot dot) in the a[filepath] parameter.  NOTE: a third party has disputed this issue because the a array is populated by a database query before use.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/467103/100/0/threaded">20070428 Seir Anphin (file.php a[filepath]) Remote File Disclosure Vulnerability</ref><ref source="VIM" url="http://www.attrition.org/pipermail/vim/2007-April/001567.html">20070429 false: Seir Anphin (file.php a[filepath]) Remote File Disclosure Vulnerability</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33962">seiranphin-file-directory-traversal(33962)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/2651">2651</ref></refs><vuln_soft><prod name="Seir Anphin" vendor="Seir Anphin"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="0.0" CVSS_exploit_subscore="0.0" CVSS_impact_subscore="0.0" CVSS_score="0.0" CVSS_version="2.0" modified="2008-02-26" name="CVE-2007-2413" published="2007-05-01" reject="1" seq="2007-2413" severity="Low" type="CVE"><desc><descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2007-2459.  Reason: This candidate is a duplicate of CVE-2007-2459.  Notes: All CVE users should reference CVE-2007-2459 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs/></entry><entry CVSS_base_score="7.8" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.9" CVSS_score="7.8" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_version="2.0" modified="2007-05-04" name="CVE-2007-2414" published="2007-05-01" seq="2007-2414" severity="High" type="CVE"><desc><descript source="cve">MyServer before 0.8.8 allows remote attackers to cause a denial of service via unspecified vectors.</descript></desc><loss_types><avail/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref source="" url="http://sourceforge.net/project/shownotes.php?release_id=504709&amp;group_id=63119"></ref><ref source="" url="http://www.myserverproject.net/forum/viewtopic.php?t=1659&amp;sid=ab6d273497a064cd3ed7a83d1c44a70a"></ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/25026">25026</ref><ref source="BID" url="http://www.securityfocus.com/bid/23716">23716</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33971">myserver-data-dos(33971)</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1589">ADV-2007-1589</ref></refs><vuln_soft><prod name="myServer" vendor="myServer"><vers num="0.8.7" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0" modified="2007-08-02" name="CVE-2007-2415" published="2007-05-01" seq="2007-2415" severity="Medium" type="CVE"><desc><descript source="cve">Pi3Web Web Server 2.0.3 PL1 allows remote attackers to cause a denial of service (application exit) via a long URI.  NOTE: this issue was originally reported as a crash, but the vendor states that the impact is a &quot;clean&quot; exit in which &quot;the server I/O loop finishes and the process exits normally.&quot;</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://sourceforge.net/forum/forum.php?thread_id=1725156&amp;forum_id=131392"></ref><ref source="BID" url="http://www.securityfocus.com/bid/23713">23713</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/25009">25009</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1579">ADV-2007-1579</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33967">pi3web-http-dos(33967)</ref></refs><vuln_soft><prod name="Pi3Web Web Server" vendor="Pi3Web"><vers num="2.0.3 PL1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-05-04" name="CVE-2007-2416" published="2007-05-01" seq="2007-2416" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in home.php in E-Annu allows remote attackers to execute arbitrary SQL commands via the a
