|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
on-line диагностика
|
|
принадлежность к ua-ix
|
|
|
|
|
|
|
|
|
|
|
|
| |
|
|
|
|
|
Новости IT Безопастность
|
|
SQL-инъекция в IMGallery
|
|
30-06-2006 02:53
Удаленный пользователь может выполнить произвольные SQL команды на системе.
|
|
|
|
|
|
SQL-инъекция в Open-Realty
|
|
30-06-2006 02:53
Удаленный пользователь может выполнить произвольные SQL команды на системе.
|
|
|
|
|
|
Повышение привилегий в Hosting Controller
|
|
30-06-2006 02:51
Удаленный пользователь может повысить свои привилегии в приложении.
|
|
|
|
|
|
Межсайтовый скриптинг и SQL-инъекция в VUBB
|
|
30-06-2006 02:50
Удаленный пользователь может произвести XSS нападение и выполнить произвольные SQL команды на системе.
|
|
|
|
|
|
CVE-2006-2198
|
|
29-06-2006 23:00
OpenOffice.org 1.1.x up to 1.1.5 and 2.0.x before 2.0.3 allows user-complicit attackers to conduct unauthorized activities via an OpenOffice document with a malicious BASIC macro, which is executed without prompting the user.
|
|
|
|
|
|
CVE-2006-2199
|
|
29-06-2006 23:00
Unspecified vulnerability in Java Applets in OpenOffice.org 1.1.x up to 1.1.5 and 2.0.x before 2.0.3 allows user-complicit attackers to escape the Java sandbox and conduct unauthorized activities via certain applets in OpenOffice documents.
|
|
|
|
|
|
CVE-2006-2934
|
|
29-06-2006 23:00
SCTP conntrack (ip_conntrack_proto_sctp.c) in netfilter for Linux kernel before 2.6.17.3 allows remote attackers to cause a denial of service (crash) via a packet without any chunks, which causes a variable to contain an invalid value that is later used to dereference a pointer.
|
|
|
|
|
|
CVE-2006-3117
|
|
29-06-2006 23:00
Heap-based buffer overflows in OpenOffice.org 1.1.x up to 1.1.5 and 2.0.x before 2.0.3 allows user-complicit attackers to execute arbitrary code via a crafted OpenOffice XML document that is not properly handled by (1) Calc, (2) Draw, (3) Impress, (4) Math, or (5) Writer.
|
|
|
|
|
|
CVE-2006-3118
|
|
29-06-2006 23:00
spread uses a temporary file with a static filename based on the port number, which allows local users to cause a denial of service by creating the file during a race condition between unlink and bind function calls. NOTE: spread deletes this temporary file before use, which could cause conflicts with other programs that use the same filename, but this is not a distinct issue.
|
|
|
|
|
|
CVE-2006-3330
|
|
29-06-2006 23:00
Cross-site scripting (XSS) vulnerability in AddAsset1.php in PHP/MySQL Classifieds (PHP Classifieds) allows remote attackers to execute arbitrary SQL commands via the (1) ProductName ("Title"field), (2) url, and (3) Description parameters, possibly related to issues in add1.php.
|
|
|
|
|
|
|
|
|
| Новости |
 |
|
ООО "Терабит"
Украина, Киев, 03040
ул. Васильковская, 22
офис 502 (5-й этаж)
тел: +38044 259 01 01
e-mail: info@terabit.net.ua
|
|
 |
|
|