|
Colapse all |
Post message
TA04-033A: Multiple Vulnerabilities in Microsoft Internet Explorer 2004-02-03 CERT Advisory (cert-advisory cert org) Re: sqwebmail web login 2004-02-03 scott jefferd cantire com This is actually very similar to another problem that some on BugTraq may be interested in. There is at least one major "Unix-based" OS (AIX) that in it's default configuration will provide a unique reply for a correctly guessed password when direct remote login is disabled for the userid in quest [ more ] [ reply ] Re: MS to stop allowing passwords in URLs 2004-02-03 Vinny Abello (vinny tellurian com) Interestingly, I've already found that this patch doesn't fix this problem when using IE as an object in VB6. You can still programmatically call an instance of IE as a browser object and use that format to login to a web site. At 05:54 PM 1/28/2004, McAllister, Andrew wrote: >I just read that Mi [ more ] [ reply ] RE: virus handling 2004-02-03 Shaun Bertrand (sbertrand cbihome com) Mmmmm, Well to be quite honest I've had a lot of luck mitigating with an ISP to solve any DoS issues. Now that's not to say the results have always been successful, but if you know the means of communication and WHO to contact within the ISP you may have some luck. I've blocked ICMP floods, DDoS, D [ more ] [ reply ] Cisco Security Advisory: Cisco 6000/6500/7600 Crafted Layer 2 Frame Vulnerability 2004-02-03 Cisco Systems Product Security Incident Response Team (psirt cisco com) -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Cisco Security Advisory: Cisco 6000/6500/7600 Crafted Layer 2 Frame Vulnerability Revision 1.0 - FINAL For Public Release 2004 February 03 1600 UTC (GMT) - ------------------------------------------------------------------------ ---- Contents Su [ more ] [ reply ] Re: BUG IN APACHE HTTPD SERVER (current version 2.0.47) 2004-02-03 Vietnamese Security Group (security security com vn) In-Reply-To: <20040131211851.30391.qmail (at) www.securityfocus (dot) com [email concealed]> Note : of course it affected also in the current version 2.0.48 ( tested) Vietnamese Security Group www.security.com.vn >Received: (qmail 2149 invoked from network); 3 Feb 2004 02:12:35 -0000 >Received: from outgoing3.securi [ more ] [ reply ] [SECURITY] [DSA 432-1] New crawl packages fix potential local games exploit 2004-02-03 joey infodrom org (Martin Schulze) X-Cart vulnerability 2004-02-03 Philip (securityfocus magicwebsolutions co uk) X-Cart (ttp://www.x-cart.com)is a well distributed PHP e-commerce solution. We have discovered some security related bugs in X-Cart Version 3.4.3. It is possible that other versions are vulnerable too. Any visitor can view any file on the web server. This URL my be used as proof of concept: [ more ] [ reply ] Arbitrary File Disclosure Vulnerability in phpMyAdmin 2.5.5-pl1 and prior 2004-02-03 Cedric Cochin (cco netvigilance com) -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Arbitrary File Disclosure Vulnerability in phpMyAdmin 2.5.5-pl1 and prior ######################################################################## ######## Summary : phpMyAdmin is a tool written in PHP intended to handle the administration of MySQL [ more ] [ reply ] [waraxe-2004-SA#001] - Script injection in GBook for Php-Nuke ver. 1.0 2004-02-02 Janek Vind (come2waraxe yahoo com) ZH2004-03SA (security advisory): Photopost PHP Pro 4.6 Sql Injection Vulnerability 2004-02-02 ZetaLabs (zetalabs zone-h org) PHP Code Injection Vulnerabilities in phpGedView 2.65.1 and prior 2004-01-29 Cedric Cochin (cco netvigilance com) -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 PHP Code Injection Vulnerabilities in phpGedView 2.65.1 and prior ######################################################################## ######## Summary : phpGedView is an open source system for online viewing Gedcom information (family tree [ more ] [ reply ] Re: Fw: phpBB privmsg.php XSS vulnerability patch. 2004-01-29 Micheal Cottingham (micheal michealcottingham com) I'm going to regret replying to this as many people seem to abuse autoresponders and I end up with 50+ emails saying so-and-so is out of the office ... If you think you have found a security hole with phpBB, contact the security email address ... I assure you they won't bite your head off for n [ more ] [ reply ] Re: GOOROO CROSSING: File Spoofing Internet Explorer 6 2004-01-30 Dustin Furrer (dfurrer gorea com) Seens how this really has'nt much to do with IE itself and is more of an Explorer.exe bug\feature I'd say this was posted already and about a year ago. We are already aware of this and of the fact that it affects just about every aspect of the Operating System. Why the repost in a modified form? [ more ] [ reply ] |
|
Privacy Statement |
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
Multiple Vulnerabilities in Microsoft Internet Explorer
Original issue date: February 02, 2004
Last revised: --
Source: US-CERT
Systems Affected
Microsoft Windows systems running
* Internet Explorer 5.01
* Internet Explorer 5.
[ more ] [ reply ]