stargeek
PHP news website logo.
home    PHP scripts    articles    seo tools    links    search    contact    shop    realtors


[waraxe-2004-SA#017 - User-level authentication bypass in phpnuke 6.x-7.2]







[waraxe-2004-SA#017 - User-level
authentication bypass in phpnuke
6.x-7.2]

[waraxe-2004-SA#017 - User-level
authentication bypass in phpnuke
6.x-7.2]
04/12/2004 04:55 PM

Janek Vind (Apr 12 2004)




This is a GrokNews Entry: (what is grok?)





Similar Items

[waraxe-2004-SA#017 - User-level authentication bypass in phpnuke 6.x-7.2]

Grok Headline matches for [waraxe-2004-SA#017 - User-level authentication bypass in phpnuke 6.x-7.2]

[waraxe-2004-SA#018 - Admin-level
authentication bypass in phpnuke
6.x-7.2]


[waraxe-2004-SA#018 - Admin-level
authentication bypass in phpnuke
6.x-7.2]
04/12/2004 04:55 PM
Janek Vind (Apr 12 2004)

[waraxe-2004-SA#027 - Once again -
critical vulnerabilities in PhpNuke 6.x
- 7.2]


[waraxe-2004-SA#027 - Once again -
critical vulnerabilities in PhpNuke 6.x
- 7.2]
05/05/2004 05:09 PM
Janek Vind (May 05 2004)

[waraxe-2004-SA#030 - Multiple
vulnerabilities in PhpNuke 6.x - 7.3]


[waraxe-2004-SA#030 - Multiple
vulnerabilities in PhpNuke 6.x - 7.3]
05/17/2004 05:58 PM
Janek Vind (May 17 2004)

[waraxe-2004-SA#029 - Possible remote
file inclusion in PhpNuke 6.x - 7.3]


[waraxe-2004-SA#029 - Possible remote
file inclusion in PhpNuke 6.x - 7.3]
05/17/2004 05:58 PM
Janek Vind (May 17 2004)

[waraxe-2004-SA#032 - Multiple security
flaws in PhpNuke 6.x - 7.3]


[waraxe-2004-SA#032 - Multiple security
flaws in PhpNuke 6.x - 7.3]
06/13/2004 07:52 PM
Janek Vind (Jun 11 2004)

[waraxe-2004-SA#028 - Multiple
vulnerabilities in NukeJokes module for
PhpNuke]


[waraxe-2004-SA#028 - Multiple
vulnerabilities in NukeJokes module for
PhpNuke]
05/08/2004 04:15 PM
Janek Vind (May 08 2004)

[waraxe-2004-SA#016 - Cross-Site
Scripting aka XSS in phpnuke 6.x-7.2
part 3]


[waraxe-2004-SA#016 - Cross-Site
Scripting aka XSS in phpnuke 6.x-7.2
part 3]
04/13/2004 12:43 AM
Janek Vind (Apr 12 2004)

[waraxe-2004-SA#035 - Multiple security
holes in PhpNuke - part 2]


[waraxe-2004-SA#035 - Multiple security
holes in PhpNuke - part 2]
07/16/2004 08:39 PM
Janek Vind (Jul 16 2004)

[waraxe-2004-SA#036 - Multiple security
holes in PhpNuke - part 3]


[waraxe-2004-SA#036 - Multiple security
holes in PhpNuke - part 3]
07/19/2004 04:35 PM
Janek Vind (Jul 18 2004)

[waraxe-2004-SA#026 - Multiple
vulnerabilities in Coppermine Photo
Gallery for PhpNuke]


[waraxe-2004-SA#026 - Multiple
vulnerabilities in Coppermine Photo
Gallery for PhpNuke]
05/03/2004 01:59 PM
Janek Vind (May 02 2004)

[waraxe-2004-SA#025 - Multiple
vulnerabilities in Protector System
1.15b1 for PhpNuke]


[waraxe-2004-SA#025 - Multiple
vulnerabilities in Protector System
1.15b1 for PhpNuke]
04/23/2004 07:01 PM
Janek Vind (Apr 23 2004)

LinPHA User Authentication Bypass
Vulnerability


LinPHA User Authentication Bypass
Vulnerability
08/01/2004 11:45 AM

Direct and Related Links for 'LinPHA User Authentication Bypass Vulnerability'

“Description: Fernando Quintero has reported a vulnerability in LinPHA, which can be exploited by malicious people to conduct SQL injection attacks….The vulnerability has been reported in version 0.9.4. Other versions may also be affected. Solution: A fix is available in the CVS repository.”…

Mailworks User Authentication Bypass
Vulnerability


Mailworks User Authentication Bypass
Vulnerability
09/07/2004 01:32 AM

Direct and Related Links for 'Mailworks User Authentication Bypass Vulnerability'

“CRITICAL: Moderately critical IMPACT: Security Bypass WHERE: From remote Paul Craig has reported a vulnerability in Mailworks, which can be exploited by malicious people to bypass the user authentication. The problem is that the application doesn’t verify if a user is logged on. It merely checks if a cookie with the appropriate “uId” and “auth” parameters is set. Successful exploitation allows a malicious person to log on as any user. SOLUTION: The vendor has reportedly…

[waraxe-2005-SA#041] - Critical Sql
Injection in PhpNuke 6.x-7.6 Top module


[waraxe-2005-SA#041] - Critical Sql
Injection in PhpNuke 6.x-7.6 Top module
04/06/2005 05:45 PM
Posted by Janek Vind, Apr 06 2005

Jaws 0.4: authentication bypass


Jaws 0.4: authentication bypass 07/30/2004 03:19 AM
Rubén Molina (Jul 29 2004)

Linpha 0.9.4: authentication bypass


Linpha 0.9.4: authentication bypass 07/29/2004 03:31 PM
Rubén Molina (Jul 29 2004)

MySQL Authentication Bypass


MySQL Authentication Bypass 07/05/2004 02:38 PM
NGSSoftware Insight Security Research (Jul 05 2004)

MailWorks Professional - Authentication
bypass


MailWorks Professional - Authentication
bypass
09/02/2004 07:18 PM
headpimp_at_pimp-industries.com (Sep 02 2004)

Cisco IOS IKE Xauth Authentication
Bypass Vulnerabilities


Cisco IOS IKE Xauth Authentication
Bypass Vulnerabilities
04/07/2005 03:25 AM
frSIRT Apr 7 2005 8:12AM GMT

Cisco IOS IKE XAUTH ISAKMP IPSec SA
Establish Authentication Bypass


Cisco IOS IKE XAUTH ISAKMP IPSec SA
Establish Authentication Bypass
04/17/2005 10:34 AM
Addict3d.org Apr 17 2005 12:19PM GMT

Re: OSX - trojan apps can bypass
authentication controls and gain root
privilages


Re: OSX - trojan apps can bypass
authentication controls and gain root
privilages
04/06/2005 05:45 PM
Posted by KF (lists), Apr 06 2005

Vulns: Motorola WR850G Wireless Router
Remote Authentication Bypass
Vulnerability


Vulns: Motorola WR850G Wireless Router
Remote Authentication Bypass
Vulnerability
09/26/2004 05:11 PM
SecurityFocus Sep 26 2004 8:09PM GMT

[Full-Disclosure] iDEFENSE Security
Advisory 05.27.04: 3Com OfficeConnect
Remote 812 ADSL Router Authentication
Bypass Vulnerability


[Full-Disclosure] iDEFENSE Security
Advisory 05.27.04: 3Com OfficeConnect
Remote 812 ADSL Router Authentication
Bypass Vulnerability
05/30/2004 01:49 AM
idlabs-advisories_at_idefense.com (May 27 2004)

Re: [Full-Disclosure] iDEFENSE Security
Advisory 05.27.04: 3Com OfficeConnect
Remote 812 ADSL Router Authentication
Bypass Vulnerability


Re: [Full-Disclosure] iDEFENSE Security
Advisory 05.27.04: 3Com OfficeConnect
Remote 812 ADSL Router Authentication
Bypass Vulnerability
05/28/2004 12:24 PM
Seth Alan Woolley (May 27 2004)

[waraxe-2004-SA#019 - Critical sql
injection bug in Phorum 3.4.7]


[waraxe-2004-SA#019 - Critical sql
injection bug in Phorum 3.4.7]
04/19/2004 03:02 PM
Janek Vind (Apr 18 2004)

Hardening Linux authentication and user
identity


Hardening Linux authentication and user
identity
09/23/2004 10:56 AM

[waraxe-2004-SA#031 - Multiple
vulnerabilities in e107 version 0.615]


[waraxe-2004-SA#031 - Multiple
vulnerabilities in e107 version 0.615]
05/29/2004 09:18 PM
Janek Vind (May 29 2004)

NewsForge: Hardening Linux
Authentication and User Identity


NewsForge: Hardening Linux
Authentication and User Identity
09/24/2004 01:43 PM

[waraxe-2004-SA#021 - Multiple
vulnerabilities in phprofession 2.5
module for PostNuke]


[waraxe-2004-SA#021 - Multiple
vulnerabilities in phprofession 2.5
module for PostNuke]
04/21/2004 07:53 PM
Janek Vind (Apr 21 2004)

[waraxe-2004-SA#022 - Multiple
vulnerabilities in PostNuke 0.726
Phoenix - part 2]


[waraxe-2004-SA#022 - Multiple
vulnerabilities in PostNuke 0.726
Phoenix - part 2]
04/21/2004 07:53 PM
Janek Vind (Apr 21 2004)

[waraxe-2004-SA#024 - XSS and full path
disclosure in Network Query Tool 1.6]


[waraxe-2004-SA#024 - XSS and full path
disclosure in Network Query Tool 1.6]
04/23/2004 08:28 PM
Janek Vind (Apr 23 2004)

LULA - Lightweight User-Level ACL


LULA - Lightweight User-Level ACL 05/15/2004 09:45 PM
Coming Soon....

Intrusion response dips down to end-user
level


Intrusion response dips down to end-user
level
05/14/2004 04:30 PM
A company's ability to respond in real time to network attacks is becoming crucial as traditional firewall and antivirus defenses are increasingly being breached by new worms and viruses.

Linux Programming: User-Level Memory
Management


Linux Programming: User-Level Memory
Management
05/17/2004 04:19 PM
An excerpt from Linux Programming by Example: The Fundamentals explaining memory management and the Linux/Unix address space.

Re: [Squid 2004-Nuke-001] Inadequate
Security Checking in PHPNuke v7.3 and
earlier


Re: [Squid 2004-Nuke-001] Inadequate
Security Checking in PHPNuke v7.3 and
earlier
06/05/2004 01:15 PM
Remy Wetzels (Jun 05 2004)

[Squid 2004-Nuke-001] Inadequate
Security Checking in PHPNuke v7.3 and
earlier


[Squid 2004-Nuke-001] Inadequate
Security Checking in PHPNuke v7.3 and
earlier
06/01/2004 03:27 PM
Squid (Jun 01 2004)

Cisco Security Advisory: Cisco Personal
Assistant User Password Bypass
Vulnerability


Cisco Security Advisory: Cisco Personal
Assistant User Password Bypass
Vulnerability
01/08/2004 08:28 PM
Cisco Systems Product Security Incident Response Team (Jan 08 2004)

[waraxe-2004-SA#034 - XSS and path full
path disclosure in PhpBB 2.0.8]


[waraxe-2004-SA#034 - XSS and path full
path disclosure in PhpBB 2.0.8]
07/16/2004 12:02 PM
Janek Vind (Jul 16 2004)

CNN.com - Clinton 'recovering normally'
after bypass - Sep 6, 2004


CNN.com - Clinton 'recovering normally'
after bypass - Sep 6, 2004
09/07/2004 08:51 AM
Hmmm, this is interesting: .. successfully completed .. went well

cnn.com/2004/ALLPOLITICS/09/06/clinton.bypass/index.html
track this site | 3 links


Grok Description matches for [waraxe-2004-SA#017 - User-level authentication bypass in phpnuke 6.x-7.2]
GrokA matches for [waraxe-2004-SA#017 - User-level authentication bypass in phpnuke 6.x-7.2]

[waraxe-2004-SA#017 - User-level authentication bypass in phpnuke 6.x-7.2]

The following phrases have been identified by the grok system as matching this entry:

















Also check out:


Grok

Ipod Porn on the
Rise

Brief Abstract of
Wikipedia's
Mesothelioma Cancer
page

Get first aid
instructions in your
cell phone

IE is crap
JSPWiki gains
podcasting support

eMule <= 0.42d
Remote Exploit

BID 7482, bug in
OpenSSH (Still in
FreeBSD-STABLE)

Adobe Acrobat Reader
PDF file DoS
vulnerability

[waraxe-2004-SA#018
- Admin-level
authentication
bypass in phpnuke
6.x-7.2]

Why Microsoft Will
Win Any War

Jedi-Con 2004 :
Small Coverage

Tips on Defensive
Coding

Update: Microsoft,
InterTrust settle
patent case for
$440M

Microsoft to cut
some Longhorn
features

Three states ask to
join Oracle
antitrust suit

Intergraph, AMD
reach Clipper patent
accord

CRM software on a
smaller scale

IBM acquiring Daksh
CEOs urged to take
control of
cybersecurity

Mother of all
gravity games 0.8

ShiftyGames Hangman
0.9.2

X-Chat 2.0.8
Spakes 0.7.2
Dialogos 0.5
wbmtranslator 0.2.0
Mr. Voice 1.10.4
TUTOS 1.1.20040412
Midi Grasshopper 3.8
Break Your Record
for 100 Math Tables
1.3

CocoModX 0.3.3
Hollow Ground 1.1
ListSaver 2.0
Super Blingo 3.0.1
Ban on Weight-Loss
Herb Ephedra Takes
Effect (Reuters)

Tiger Woods Arrives
for Military
Training (AP)

Barr Tries to Revive
Clinton-Flynt Suit
(AP)

Bush to Answer
Questions in Prime
Time (AP)

Microsoft Settles
InterTrust Patent
Suit (AP)

Replacing Complex
Hardware With Mobile
Phones

Can You Go To Prison
For Copying A Chat
Transcript?

Not you. Sorry. Ok,
you can come in.

Jon Stewart
interview

PowerMac G5
Cooling/Sensor
Issues?

Mullah Omar
interview

Buffy meets Bilbo et
al.

Double Crossing the
Rubicon

The real slim shady
gum, check.
household cleaning
product, check.

Microsoft shuffles
execs to combat
security flaws

Study: Bright
picture for digital
TV sales

mnoGoSearch v3.2.16
Becky! Internet Mail
v2.09.01

HMonitor v4.1.4.1
SoundEdit Pro v1.3
System Inspector
v1.1

what is grok?