Benchmark-Perl-Formance-Cargo
view release on metacpan or search on metacpan
share/SpamAssassin/easy_ham_2/01345.c40d5798193a4a060ec9f3d2321e37e4 view on Meta::CPAN
remote system being overwritten, including stack frame data.
An attacker may be able to take advantage of this vulnerability to execute
malicious code on a vulnerable SSLv3 client machine.
Oracle reports that CorporateTime Outlook Connector is only vulnerable
under Microsoft Windows 98, NT, 2K, and XP.
** This vulnerability was originally part of BID 5353, Multiple OpenSSL
Buffer Overflow Vulnerabilities. It has now been reissued as a separate
vulnerability.
5. phpBB2 Gender Mod Remote SQL Injection Vulnerability
BugTraq ID: 5342
Remote: Yes
Date Published: Jul 29 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5342
Summary:
phpBB2 is an open-source web forum application that is written in PHP and
backended by a number of database products. It will run on most Unix and
Linux variants, as well as Microsoft Windows operating systems.
Gender Mod is a modification for phpBB2 which allows the association of a
gender with a given user profile. A SQL injection vulnerability has been
reported in this mod.
A malicious user may modify the specified value for 'gender' when updating
their profile. It is possible to include additional SQL statements in this
string, and subvert the SQL statement used to update the user profile.
It has been reported possible to gain administrative access to the phpBB2
site through exploitation of this issue. Other attacks may be possible,
including the ability to view sensitive database information or to modify
additional information stored in the database.
6. ShoutBox Form Field HTML Injection Vulnerability
BugTraq ID: 5354
Remote: Yes
Date Published: Jul 29 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5354
Summary:
shoutBOX is web-based user feedback software. It is written in PHP and
runs on Unix and Linux variants as well as Microsoft Windows operating
systems.
ShoutBox does not sufficiently sanitize HTML tags from input supplied via
form fields. In particular, the user website URL field of the feedback
form is not sanitized of HTML tags.
Attackers may exploit this lack of input validation to inject arbitrary
HTML and script code into pages that are generated by the script. This
may result in execution of attacker-supplied code in the web client of a
user who visits such a page. HTML and script code will be executed in the
security context of the site hosting the software.
This condition may be exploited to hijack web content or potentially steal
cookie-based authentication credentials.
7. Sympoll File Disclosure Vulnerability
BugTraq ID: 5360
Remote: Yes
Date Published: Jul 30 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5360
Summary:
Sympoll is web-based voting booth software. It is implemented in PHP and
will run on most Unix and Linux variants as well as Microsoft Windows
operating systems.
Sympoll is prone to an issue which may allow remote attackers to disclose
the contents of arbitrary webserver readable files. This vulnerability is
only present on hosts which are running the vulnerable version of the
software and have the PHP 'register_globals' directive enabled. The
source of this vulnerability is reported to be insufficient integrity
checking of variables.
The vendor has stated that this issue is only believed to affect Sympoll
version 1.2.
Exploitation of this issue on Microsoft Windows operating systems may
potentially expose arbitrary system files since webservers typically run
in the SYSTEM context.
8. OpenSSL ASN.1 Parsing Error Denial Of Service Vulnerability
BugTraq ID: 5366
Remote: Yes
Date Published: Jul 30 2002 12:00AM
Relevant URL:
http://www.securityfocus.com/bid/5366
Summary:
OpenSSL is an open source implementation of the SSL protocol. It is used
by a number of other projects, including but not restricted to Apache,
Sendmail, Bind, etc.. It is commonly found on Linux and Unix based
systems.
A remotely exploitable denial of service condition has been reported in
the OpenSSL ASN.1 library.
This vulnerability is due to parsing errors and affects SSL, TLS, S/MIME,
PKCS#7 and certificate creation routines. In particular, malformed
certificate encodings could cause a denial of service to server and client
implementations which depend on OpenSSL.
Oracle reports that CorporateTime Outlook Connector is only vulnerable
under Microsoft Windows 98, NT, 2K, and XP.
** This vulnerability was originally part of BID 5353, Multiple OpenSSL
Buffer Overflow Vulnerabilities. It has now been reissued as a separate
vulnerability.
9. William Deich Super SysLog Format String Vulnerability
BugTraq ID: 5367
Remote: No
Date Published: Jul 31 2002 12:00AM
Relevant URL:
( run in 1.265 second using v1.01-cache-2.11-cpan-5fbc6bb55f2 )