“CRITICAL: Moderately critical IMPACT: Security Bypass WHERE:
From remote Paul Craig has reported a vulnerability in Mailworks,
which can be exploited by malicious people to bypass the user
authentication. The problem is that the application doesn’t
verify if a user is logged on. It merely checks if a cookie with the
appropriate “uId” and “auth” parameters is
set. Successful exploitation allows a malicious person to log on as
any user. SOLUTION: The vendor has reportedly…
“Description: Fernando Quintero has reported a vulnerability
in LinPHA, which can be exploited by malicious people to conduct SQL
injection attacks….The vulnerability has been reported in
version 0.9.4. Other versions may also be affected. Solution: A fix is
available in the CVS repository.”…