|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
on-line диагностика
|
|
принадлежность к ua-ix
|
|
|
|
|
|
|
|
|
|
|
|
| |
|
|
|
|
|
Новости IT Безопастность
|
|
Panda Software : Новый червь крадет информацию из баз данных MS SQL Server и MySQL
|
|
12-07-2006 22:39
Новый червь распространяется по электронной почте и через пиринговые программы, и способен выполнять множество действий, нацеленных на снижения уровня безопасности системы и собтвенную маскировку.
|
|
|
|
|
|
CVE-2006-3403
|
|
11-07-2006 23:00
The smdb daemon (smbd/service.c) in Samba 3.0.1 through 3.0.22 allows remote attackers to cause a denial of service (memory consumption) via a large number of share connection requests.
|
|
|
|
|
|
CVE-2006-3452
|
|
11-07-2006 23:00
Adobe Reader and Acrobat 6.0.4 and earlier, on Mac OSX, has insecure file and directory permissions, which allows local users to gain privileges by overwriting program files.
|
|
|
|
|
|
CVE-2006-3530
|
|
11-07-2006 23:00
PHP remote file inclusion vulnerability in com_pccookbook/pccookbook.php in the PccookBook Component for Mambo and Joomla 0.3 and possibly up to 1.3.1, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via the mosConfig_absolute_path parameter.
|
|
|
|
|
|
CVE-2006-3531
|
|
11-07-2006 23:00
includes/editor/insert_image.php in Pivot 1.30 RC2 and earlier creates the authentication credentials from parameters, which allows remote attackers to obtain privileges and upload arbitrary files via modified (1) pass and (2) session parameters, and (3) pass and (4) userlevel indices of the (a) Pivot_Vars[] or (b) Users[] array parameters.
|
|
|
|
|
|
CVE-2006-3532
|
|
11-07-2006 23:00
PHP file inclusion vulnerability in includes/edit_new.php in Pivot 1.30 RC2 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a FTP URL or full file path in the Paths[extensions_path] parameter.
|
|
|
|
|
|
CVE-2006-3533
|
|
11-07-2006 23:00
Multiple cross-site scripting (XSS) vulnerabilities in Pivot 1.30 RC2 and earlier, when register_globals is enabled, allow remote attackers to inject arbitrary web script or HTML via the (1) fg, (2) line1, (3) line2, (4) bg, (5) c1, (6) c2, (7) c3, and (8) c4 parameters in (a) includes/blogroll.php; (9) name and (10) js_name parameters in (b) includes/editor/edit_menu.php; and, even if register_globals is not enabled, the (11) h and (12) w parameters in (c) includes/photo.php.
|
|
|
|
|
|
CVE-2006-3534
|
|
11-07-2006 23:00
Directory traversal vulnerability in Nullsoft SHOUTcast DSP before 1.9.6 filters directory traversal sequences before decoding, which allows remote attackers to read arbitrary files via encoded dot dot (%2E%2E) sequences in an HTTP GET request for a file path containing"/content".
|
|
|
|
|
|
CVE-2006-3535
|
|
11-07-2006 23:00
Directory traversal vulnerability in Nullsoft SHOUTcast DSP before 1.9.7 allows remote attackers to read arbitrary files via unspecifed vectors, which are a"slight variation"of CVE-2006-????.
|
|
|
|
|
|
CVE-2006-3536
|
|
11-07-2006 23:00
Direct static code injection vulnerability in code/class_db_text.php in EJ3 TOPo 2.2.178 and earlier allows remote attackers to execute arbitrary PHP code via parameters such as (1) descripcion and (2) pais, which are stored directly in a PHP script. NOTE: the provenance of this information is unknown; the details are obtained solely from third party reports.
|
|
|
|
|
|
|
|
|
| Новости |
 |
|
ООО "Терабит"
Украина, Киев, 03040
ул. Васильковская, 22
офис 502 (5-й этаж)
тел: +38044 259 01 01
e-mail: info@terabit.net.ua
|
|
 |
|
|