stargeek
PHP news website logo.
home    PHP scripts    articles    seo tools    links    search    contact    shop    realtors


Php Vulnerability N. 2







Php Vulnerability N. 2

Php Vulnerability N. 2 09/16/2004 01:29 PM

Stefano Di Paola (Sep 15 2004)




This is a GrokNews Entry: (what is grok?)





Similar Items

Php Vulnerability N. 2

Grok Headline matches for Php Vulnerability N. 2

NISCC Vulnerability Advisory 236929:
Vulnerability Issues in TCP


NISCC Vulnerability Advisory 236929:
Vulnerability Issues in TCP
04/20/2004 02:16 PM
David Ahmad (Apr 20 2004)

Open source outfit releases
vulnerability for IE vulnerability


Open source outfit releases
vulnerability for IE vulnerability
12/19/2003 01:10 PM
The Register Dec 19 2003 11:57AM ET

Re: NISCC Vulnerability Advisory 236929:
Vulnerability Issues in TCP


Re: NISCC Vulnerability Advisory 236929:
Vulnerability Issues in TCP
05/11/2004 06:04 PM
Florian Weimer (May 11 2004)

Re: [USN-52-1] vim vulnerability


Re: [USN-52-1] vim vulnerability 12/25/2004 05:09 PM
Liu Die Yu (Dec 23 2004)

Vulnerability in 2.6 and 2.61


Vulnerability in 2.6 and 2.61 03/13/2003 10:15 AM
If you upgraded to 2.6 or 2.61, you need to upgrade immediately to 2.62. There is a security vulnerability in...

Vulnerability in man < 1.5l


Vulnerability in man < 1.5l 03/13/2003 10:22 AM
Jack Lloyd (Mar 11 2003)

802.11 Has DoS Vulnerability


802.11 Has DoS Vulnerability 05/13/2004 08:11 PM
Internet News May 13 2004 11:39PM GMT

Vulnerability with XP SP2


Vulnerability with XP SP2 08/18/2004 06:29 AM
Just to bare in mind, Microsoft are dealing with this and are holding off SP2s release on Automatic Update because of it. There's a bug in the implementation of a new security feature; it'd be hard to criticize Microsoft too hard for this problem.

"With Service Pack 2, Microsoft introduces a new security feature which warns users before executing files that originate from an untrusted location (zone) such as the Internet. There are two flaws in the implementation of this feature: a cmd issue and the caching of ZoneIDs in Windows Explorer. The Windows command shell cmd ignores zone information and starts executables without warnings. Virus authors could use this to spread viruses despite the new security features of SP2.

Windows Explorer does not update zone information properly when files are overwritten. So it can be tricked to execute files from the internet without warning."

Heise do concede that it would take a fair amount of user interaction for a virus writer to use this vulnerability. However, as they point out, the powers of social engineering and playing on less IT adept people do mean that it's not that in-conceivable it could happen. With Service Pack 2, Microsoft had clearly been hoping for less vulnerabilities, and will no doubt be disappointed with this news.

View: More info @ Heise.de

Read full story...

PHP Vulnerability N. 1


PHP Vulnerability N. 1 09/15/2004 03:20 PM
Stefano Di Paola (Sep 15 2004)

IE6 + XP SP2 Vulnerability


IE6 + XP SP2 Vulnerability 09/17/2004 12:37 AM
cns (Sep 15 2004)

[USN-52-1] vim vulnerability


[USN-52-1] vim vulnerability 12/24/2004 12:36 PM
Martin Pitt (Dec 23 2004)

PHP CGI Vulnerability


PHP CGI Vulnerability 02/20/2003 10:46 AM
PHP CGI Vulnerability I don't know how many folks are actually doing php as a CGI but if so ... [17-Feb-2003] The PHP Group today announced the details of a serious CGI vulnerability in PHP version 4.3.0. A security update, PHP 4.3.1, fixes the issue. Everyone running affected version of PHP (as CGI) are encouraged to upgrade immediately. The new 4.3.1 release does not include any other changes, so upgrading from 4.3.0 is safe and painless. [_Go_] I have to commend the php team for NOT including any other changes thereby making it much more likely that affected systems get patched. Good going!

KDE Vulnerability


KDE Vulnerability 08/12/2004 06:18 AM

Direct and Related Links for 'KDE Vulnerability'

“Two vulnerabilities have been discovered in KDE, which can be exploited by malicious, local users to perform certain actions on a vulnerable system with escalated privileges. 1) Certain directories and files are created insecurely when a user runs a KDE application outside the KDE environment or as another user. This can be exploited via symlink attacks to overwrite or truncate arbitrary files or prevent KDE applications from accessing certain directories. This vulnerability affects KDE 3.2.3…

[USN-108-1] GDK vulnerability


[USN-108-1] GDK vulnerability 04/06/2005 05:45 PM
Posted by Martin Pitt, Apr 05 2005

XSS vulnerability in XOOPS 2.0.5.1


XSS vulnerability in XOOPS 2.0.5.1 12/22/2003 05:21 PM
Chintan Trivedi (Dec 21 2003)

[USN-142-1] sudo vulnerability


[USN-142-1] sudo vulnerability 06/22/2005 02:10 AM
Posted by Martin Pitt, Tuesday, 21 June

New Cisco vulnerability


New Cisco vulnerability 04/11/2004 06:24 PM
Australian IT Apr 11 2004 11:17PM GMT

Moodle XSS Vulnerability


Moodle XSS Vulnerability 07/13/2004 12:06 PM
Thomas Waldegger (Jul 13 2004)

GMail Vulnerability


GMail Vulnerability 07/15/2004 03:37 PM
"A vulnerability was reported in Google's GMail beta e-mail service. A remote user may be able to determine information about another user attempting to register an account on the system"

[USN-71-1] PostgreSQL vulnerability


[USN-71-1] PostgreSQL vulnerability 02/01/2005 09:28 PM
Martin Pitt (Feb 01 2005)

Re: Moodle XSS Vulnerability


Re: Moodle XSS Vulnerability 07/17/2004 01:07 PM
Martin Dougiamas (Jul 17 2004)

XSS vulnerability in Sqwebmail 4.0.4


XSS vulnerability in Sqwebmail 4.0.4 06/21/2004 08:13 PM
Luca Legato (Jun 21 2004)

[USN-104-1] unshar vulnerability


[USN-104-1] unshar vulnerability 04/05/2005 01:36 AM
Martin Pitt

[USN-107-1] racoon vulnerability


[USN-107-1] racoon vulnerability 04/05/2005 05:38 PM
Martin Pitt

IMWheel Vulnerability


IMWheel Vulnerability 08/27/2004 09:14 PM

Direct and Related Links for 'IMWheel Vulnerability'

“I)ruid has reported a vulnerability in IMWheel, which can be exploited by malicious, local users to perform certain actions on a vulnerable system with escalated privileges or cause a DoS (Denial of Service)….

IE Vulnerability Flagged


IE Vulnerability Flagged 04/09/2004 03:55 PM
Other Web browsers could also be affected because of a flaw in Internet Explorer's ITS protocol handler, CERT warns.

[USN-97-1] libxpm vulnerability


[USN-97-1] libxpm vulnerability 03/17/2005 03:53 AM
Martin Pitt (Mar 16 2005)

Nasty new IE vulnerability


Nasty new IE vulnerability 12/09/2003 02:34 PM

Most people reading are probably aware of the common trick whereby spammers and other assorted ne'er-do-wells publish URLs with usernames that look like hostnames to fool people in to trusting a malicious site - for example, http://www.microsoft.com&session%123123123@simon.incutio.com . This trick is frequently used by spammers to steal people's PayPal accounts, by tricking them in to "resetting" their password at a site owned by the spammer but disguised as PayPal.com.

Today's new Internet Explorer vulnerability makes the problem a hundred times worse. By including an 0x01 character after the @ symbol in the fake URL, IE can be tricked in to not displaying the rest of the URL at all. Don't expect a patch for a while either; the guy who discovered the bug released it to BugTraq on the same day he notified the vendor.


[USN-49-1] debmake vulnerability


[USN-49-1] debmake vulnerability 12/24/2004 12:36 PM
Martin Pitt (Dec 23 2004)

TCP Vulnerability Published


TCP Vulnerability Published 04/20/2004 03:23 PM

Vulnerability Issues in TCP


Vulnerability Issues in TCP 04/20/2004 01:57 PM

The vulnerability of Macs


The vulnerability of Macs 12/11/2003 10:49 AM
Discussing what it calls a "significant hole," ABCnews asserts that a security issue affecting both Jaguar and Panther versions of OS X announced last month means that the "Mac OS is just as vulnerable as Microsoft Windows." While no operating system can claim to be perfectly secure, OS X and Unix variants in general are more secure than Windows by design, because Unix was created for a networked, multiple user environment, and Windows was created to operate on...

New Spoofing Vulnerability in IE


New Spoofing Vulnerability in IE 12/17/2004 06:27 PM

LDU (land down under) xss vulnerability


LDU (land down under) xss vulnerability 05/29/2004 03:25 PM
tim de gier (May 29 2004)

[USN-75-1] cpio vulnerability


[USN-75-1] cpio vulnerability 02/05/2005 09:38 PM
Martin Pitt (Feb 04 2005)

OS X security vulnerability


OS X security vulnerability 12/16/2003 06:33 PM
A new Mac OS X security vulnerability has been discovered. Apparantly this vulnerability can allow execution of arbitrary code with "root" priviledges. The issue is considered a "Less Critical" vulnerability, and affects Mac OS X 10.3.1 and possibly other versions of the operating system.

WebArtFactory CMS Vulnerability


WebArtFactory CMS Vulnerability 12/17/2003 02:31 PM
Noticias (Dec 16 2003)

[USN-74-1] Postfix vulnerability


[USN-74-1] Postfix vulnerability 02/05/2005 09:38 PM
Martin Pitt (Feb 04 2005)

[USN-73-1] Python vulnerability


[USN-73-1] Python vulnerability 02/05/2005 09:38 PM
Martin Pitt (Feb 03 2005)
Grok Description matches for Php Vulnerability N. 2
GrokA matches for Php Vulnerability N. 2

Php Vulnerability N. 2

The following phrases have been identified by the grok system as matching this entry:

















Also check out:


Grok

Ipod Porn on the
Rise

Brief Abstract of
Wikipedia's
Mesothelioma Cancer
page

Get first aid
instructions in your
cell phone

IE is crap
JSPWiki gains
podcasting support

MDKSA-2004:097 -
Updated cups
packages fix DoS
vulnerability

[OpenPKG-SA-2004.041
] OpenPKG Security
Advisory
(spamassassin)

DOT dismisses
privacy complaint
against Northwest

National
Semiconductor
Unveils 'Trusted'
Chip for PCs

Isabel Gill,
Victorian Stargazer

New World Disorder
When Does Heckling
Cross the Line?

You know, for kids!
Vodafone Sweden 3G
Customers Get
Premier League
Action

Train Information on
3G Phones

Access Made Easier
to 3G Data Services

Nortel warns of
lower quarterly
revenue

JP Morgan cancels
$5bn IBM outsourcing
deal

PC Cubed: Amanda
Wade

PC Cubed: Paul
O'Connell

KTF Demonstrates
Portable Internet
Technology

Privacy complaint
against Northwest
dismissed

Microsoft pursuers
get $386m in fees

1&1 Internet
Upgrades Shared
Hosting Packages

'Father' of European
internet retires

Inflow Wins 'Best
Practices in
Enterprise
Management' Award at
Computerworld Show

Network Vendors Aim
High

US FCC: High Speed
Internet and
television

Lawmakers Call for
Cybersecurity
Enhancements

Microsoft flip-flops
on blogs as
bandwidth crisis
looms

Lawson Warning May
Portend Sector Slump

Linux creator nets
iEconomist/i honour

Government plans key
role for IT in
health services

Blackberry shrinks
phone keyboard

Jeeves defects to
Google Search Engine

New and Noteworthy:
How to protect
yourself from
Windows viruses: get
a Mac; Firefox
gaining on Internet
Explo

Yahoo to Acquire
Musicmatch, Will
Expand Music
Portfolio

Scavenger hunts
elevated to a new
level

VoIP providers
jockey for position

Microsoft Korea held
a show case of its
new models of mice
and keyboards at a
hotel in Seoul, on
Tuesday

Celestica shares
hammered

Ingram: When the
chips fall

ATI to launch RX480
AMD K8 chipset by
the end of this
month

Can Microsoft Sue
Open Office Users?

Via K8T900 Pro has
two PCI Express
slots

Comment : When will
Microsoft wake up to
the IE problem?

Nikon Adds 802.11g
Operators May Get
Burned on Flat Rate
3G

Call of Duty: United
Offensive comes to
Mac

Nikon intros D2X
SLR, three new
Coolpix cameras

DxO intros Optics
Pro 2.0, Raw Engine

Airbus Denies
Backing Microsoft in
EU Case (Reuters)

Net Virus Turf War
Resumes After
Rival's Arrest
(Reuters)

Bargain Hunting
The Journal Will
Work Weekends

what is grok?