Date Reported:      09/03/2002
Brief Description:  Microsoft Internet Explorer URL encoded forward-
                    slash "Same Origin Policy" bypass
Risk Factor:        Medium
Attack Type:        Network Based
Platforms:          Konqueror 3.0.3, Microsoft Internet Explorer 6.0,
                    Windows ME, Windows 98, Windows NT 4.0, Windows
                    2000 Any version
Vulnerability:      ie-sameoriginpolicy-bypass
X-Force URL:        http://www.iss.net/security_center/static/10039.php



 ____________________________________________________________
\
/   Scott Fosseen - Systems Engineer - Arrowhead AEA 5
\   www.aea5.k12.ia.us/aeaphone.nsf/Web/FosseenScott
/____________________________________________________________
----- Original Message -----
From: "X-Force" <[EMAIL PROTECTED]>
To: <[EMAIL PROTECTED]>
Sent: Monday, September 09, 2002 1:16 PM
Subject: ISS Security Alert Summary AS02-36


>
> TO UNSUBSCRIBE: email "unsubscribe alert" in the body of your message to
> [EMAIL PROTECTED]  Contact [EMAIL PROTECTED] for help with any problems!
> --------------------------------------------------------------------------
-
>
> -----BEGIN PGP SIGNED MESSAGE-----
>
> Internet Security Systems Security Alert Summary AS02-36
> September 9, 2002
>
> X-Force Vulnerability and Threat Database:
> http://www.iss.net/security_center
>
> To receive these Alert Summaries, as well as other Alerts and
> Advisories, subscribe to the Internet Security Systems Alert
> mailing list at:
> http://www.iss.net/security_center/maillists
>
> This summary is available at the following address:
> http://www.iss.net/security_center/alerts/AS02-36.php
>
> _____
> Contents:
> * 46 Reported Vulnerabilities
> * Risk Factor Key
> _____
>
>
> Date Reported:      08/26/2002
> Brief Description:  Microsoft Word INCLUDETEXT field in shared
>                     documents can be used to read other files
> Risk Factor:        Low
> Attack Type:        Host Based / Network Based
> Platforms:          Microsoft Word 97, Microsoft Word 2000, Microsoft
>                     Word 2002, Windows Any version
> Vulnerability:      word-includetext-read-files
> X-Force URL:        http://www.iss.net/security_center/static/10008.php
>
> Date Reported:      08/28/2002
> Brief Description:  Python os._execvpe function temporary file symlink
>                     attack
> Risk Factor:        High
> Attack Type:        Host Based
> Platforms:          Python 1.5.2 through 2.2.1, Debian Linux 2.2,
>                     Debian Linux 3.0
> Vulnerability:      python-execvpe-tmpfile-symlink
> X-Force URL:        http://www.iss.net/security_center/static/10009.php
>
> Date Reported:      08/28/2002
> Brief Description:  Samba enum_csc_policy memory structure buffer
>                     overflow
> Risk Factor:        High
> Attack Type:        Host Based
> Platforms:          FreeBSD Ports Collection prior to 2002-08-28, Samba
>                     prior to 2.2.5, Unix Any version
> Vulnerability:      samba-memory-structure-bo
> X-Force URL:        http://www.iss.net/security_center/static/10010.php
>
> Date Reported:      08/28/2002
> Brief Description:  ZMailer IPv6 address HELO command buffer overflow
> Risk Factor:        High
> Attack Type:        Network Based
> Platforms:          Unix Any version, ZMailer prior to 2.99.51_1,
>                     FreeBSD Ports Collection prior to 2002-08-28
> Vulnerability:      zmailer-ipv6-helo-bo
> X-Force URL:        http://www.iss.net/security_center/static/10013.php
>
> Date Reported:      08/28/2002
> Brief Description:  AIDE aid.conf file could allow a remote attacker to
>                     bypass detection
> Risk Factor:        Medium
> Attack Type:        Host Based
> Platforms:          FreeBSD Ports Collection prior to 2002-08-28, AIDE
>                     prior to 0.7_1, Unix Any version
> Vulnerability:      aide-conf-bypass-detection
> X-Force URL:        http://www.iss.net/security_center/static/10015.php
>
> Date Reported:      08/28/2002
> Brief Description:  Webmin Printer Administration shell command
>                     execution
> Risk Factor:        High
> Attack Type:        Network Based
> Platforms:          Unix Any version, Webmin prior to 0.990, FreeBSD
>                     Ports Collection prior to 2002-08-28, Linux Any
>                     version
> Vulnerability:      webmin-printer-shell-commands
> X-Force URL:        http://www.iss.net/security_center/static/10052.php
>
> Date Reported:      08/29/2002
> Brief Description:  RPM Package Manager (RPM) improper verification of
>                     signed RPM packages
> Risk Factor:        Medium
> Attack Type:        Network Based
> Platforms:          Linux Any version, Unix Any version, RPM 4.0.4
> Vulnerability:      rpm-improper-sig-verification
> X-Force URL:        http://www.iss.net/security_center/static/10011.php
>
> Date Reported:      08/31/2002
> Brief Description:  HP Tru64 UNIX /usr/sbin/ping denial of service
> Risk Factor:        Low
> Attack Type:        Host Based / Network Based
> Platforms:          Tru64 UNIX 5.1a, Tru64 UNIX 4.0f, Tru64 UNIX 4.0g,
>                     Tru64 UNIX 5.0a
> Vulnerability:      tru64-ping-dos
> X-Force URL:        http://www.iss.net/security_center/static/10014.php
>
> Date Reported:      08/31/2002
> Brief Description:  HP Tru64 UNIX multiple binaries have buffer
>                     overflows
> Risk Factor:        High
> Attack Type:        Host Based / Network Based
> Platforms:          Tru64 UNIX 5.0a, Tru64 UNIX 4.0f, Tru64 UNIX 4.0g,
>                     Tru64 UNIX 5.1a
> Vulnerability:      tru64-multiple-binaries-bo
> X-Force URL:        http://www.iss.net/security_center/static/10016.php
>
> Date Reported:      09/02/2002
> Brief Description:  Microsoft Outlook Express S/MIME spoofed CA
>                     certificate man-in-the-middle attack
> Risk Factor:        Medium
> Attack Type:        Network Based
> Platforms:          Microsoft Outlook Express 5.0, Windows Any version
> Vulnerability:      outlook-smime-mitm
> X-Force URL:        http://www.iss.net/security_center/static/10033.php
>
> Date Reported:      09/03/2002
> Brief Description:  Microsoft SQL Server sp_MSSetServerProperties and
>                     sp_MSsetalertinfo stored procedures allow "public"
>                     role access
> Risk Factor:        Low
> Attack Type:        Host Based / Network Based
> Platforms:          Windows 2000 Any version, Windows NT Any version,
>                     Microsoft SQL Server 2000
> Vulnerability:      mssql-sp-public-access
> X-Force URL:        http://www.iss.net/security_center/static/10012.php
>
> Date Reported:      09/03/2002
> Brief Description:  Cisco VPN 3000 concentrators could allow a remote
>                     attacker to bypass authentication
> Risk Factor:        Medium
> Attack Type:        Network Based
> Platforms:          Cisco VPN 3000 Concentrators prior to 3.0.3(B),
>                     Cisco VPN 3000 Concentrators 2.x.x, Cisco VPN 3000
>                     Concentrators 3.6(Rel), Cisco VPN 3000
>                     Concentrators 3.5(Rel) to 3.5.4, Cisco VPN 3000
>                     Concentrators prior to 3.1.2
> Vulnerability:      cisco-vpn-bypass-authentication
> X-Force URL:        http://www.iss.net/security_center/static/10017.php
>
> Date Reported:      09/03/2002
> Brief Description:  Cisco VPN 3000 series concentrators HTML parser
>                     denial of service
> Risk Factor:        Low
> Attack Type:        Network Based
> Platforms:          Cisco VPN 3000 Concentrators 2.x.x, Cisco VPN 3000
>                     Concentrators prior to 3.0.3(B)
> Vulnerability:      cisco-vpn-html-parser-dos
> X-Force URL:        http://www.iss.net/security_center/static/10018.php
>
> Date Reported:      09/03/2002
> Brief Description:  Cisco VPN 3000 series concentrators administrative
>                     Web page contains plaintext user passwords
> Risk Factor:        Low
> Attack Type:        Network Based
> Platforms:          Cisco VPN 3000 Concentrators prior to 3.5.1, Cisco
>                     VPN 3000 Concentrators 3.0.x, Cisco VPN 3000
>                     Concentrators 2.x.x, Cisco VPN 3000 Concentrators
>                     prior to 3.1.4
> Vulnerability:      cisco-vpn-user-passwords
> X-Force URL:        http://www.iss.net/security_center/static/10019.php
>
> Date Reported:      09/03/2002
> Brief Description:  Cisco VPN 3000 series concentrators disclose
>                     sensitive information in application layer banners
> Risk Factor:        Low
> Attack Type:        Network Based
> Platforms:          Cisco VPN 3000 Concentrators 2.x.x, Cisco VPN 3000
>                     Concentrators 3.0.x, Cisco VPN 3000 Concentrators
>                     3.1.x, Cisco VPN 3000 Concentrators prior to 3.5.4
> Vulnerability:      cisco-vpn-banner-information
> X-Force URL:        http://www.iss.net/security_center/static/10020.php
>
> Date Reported:      09/03/2002
> Brief Description:  Cisco VPN 3000 series concentrators Windows PPTP
>                     client denial of service
> Risk Factor:        Low
> Attack Type:        Network Based
> Platforms:          Cisco VPN 3000 Concentrators prior to 2.5.2(F)
> Vulnerability:      cisco-vpn-pptp-dos
> X-Force URL:        http://www.iss.net/security_center/static/10021.php
>
> Date Reported:      09/03/2002
> Brief Description:  Cisco VPN 3000 series concentrators Certificate
>                     Management HTML page contains plaintext passwords
> Risk Factor:        Low
> Attack Type:        Network Based
> Platforms:          Cisco VPN 3000 Concentrators 3.1.x, Cisco VPN 3000
>                     Concentrators 3.0.x, Cisco VPN 3000 Concentrators
>                     prior to 3.5.2, Cisco VPN 3000 Concentrators 2.x.x
> Vulnerability:      cisco-vpn-certificate-passwords
> X-Force URL:        http://www.iss.net/security_center/static/10022.php
>
> Date Reported:      09/03/2002
> Brief Description:  Cisco VPN 3000 series concentrators with the XML
>                     filter enabled could allow unauthorized access
> Risk Factor:        Medium
> Attack Type:        Network Based
> Platforms:          Cisco VPN 3000 Concentrators 2.x.x, Cisco VPN 3000
>                     Concentrators prior to 3.5.3, Cisco VPN 3000
>                     Concentrators 3.0.x, Cisco VPN 3000 Concentrators
>                     3.1.x
> Vulnerability:      cisco-vpn-xml-filter
> X-Force URL:        http://www.iss.net/security_center/static/10023.php
>
> Date Reported:      09/03/2002
> Brief Description:  Cisco VPN 3000 series concentrators could allow
>                     unauthorized access to Web pages
> Risk Factor:        Low
> Attack Type:        Network Based
> Platforms:          Cisco VPN 3000 Concentrators 3.1.x, Cisco VPN 3000
>                     Concentrators 3.0.x, Cisco VPN 3000 Concentrators
>                     prior to 3.5.3, Cisco VPN 3000 Concentrators 2.x.x
> Vulnerability:      cisco-vpn-web-access
> X-Force URL:        http://www.iss.net/security_center/static/10024.php
>
> Date Reported:      09/03/2002
> Brief Description:  Cisco VPN 3000 series concentrators HTML interface
>                     denial of service
> Risk Factor:        Low
> Attack Type:        Network Based
> Platforms:          Cisco VPN 3000 Concentrators 2.x.x, Cisco VPN 3000
>                     Concentrators prior to 3.5.3, Cisco VPN 3000
>                     Concentrators 3.0.x, Cisco VPN 3000 Concentrators
>                     3.1.x
> Vulnerability:      cisco-vpn-html-interface-dos
> X-Force URL:        http://www.iss.net/security_center/static/10025.php
>
> Date Reported:      09/03/2002
> Brief Description:  Cisco VPN 3000 series concentrators long VPN
>                     username denial of service
> Risk Factor:        Low
> Attack Type:        Network Based
> Platforms:          Cisco VPN 3000 Concentrators 3.0.x, Cisco VPN 3000
>                     Concentrators 3.1.x, Cisco VPN 3000 Concentrators
>                     3.6(Rel), Cisco VPN 3000 Concentrators 2.x.x, Cisco
>                     VPN 3000 Concentrators prior to 3.5.5
> Vulnerability:      cisco-vpn-username-dos
> X-Force URL:        http://www.iss.net/security_center/static/10026.php
>
> Date Reported:      09/03/2002
> Brief Description:  Cisco VPN 3000 series concentrators LAN-to-LAN
>                     connection denial of service
> Risk Factor:        Low
> Attack Type:        Network Based
> Platforms:          Cisco VPN 3000 Concentrators 2.x.x, Cisco VPN 3000
>                     Concentrators prior to 3.5.4, Cisco VPN 3000
>                     Concentrators 3.0.x, Cisco VPN 3000 Concentrators
>                     3.1.x
> Vulnerability:      cisco-vpn-lan-connection-dos
> X-Force URL:        http://www.iss.net/security_center/static/10027.php
>
> Date Reported:      09/03/2002
> Brief Description:  Cisco VPN 3000 series concentrators malformed
>                     ISAKMP packet denial of service
> Risk Factor:        Low
> Attack Type:        Network Based
> Platforms:          Cisco VPN 3000 Concentrators 3.1.x, Cisco VPN 3000
>                     Concentrators 3.0.x, Cisco VPN 3000 Concentrators
>                     2.x.x, Cisco VPN 3000 Concentrators prior to 3.5.5,
>                     Cisco VPN 3000 Concentrators 3.6(Rel)
> Vulnerability:      cisco-vpn-isakmp-dos
> X-Force URL:        http://www.iss.net/security_center/static/10028.php
>
> Date Reported:      09/03/2002
> Brief Description:  Aestiva HTML/OS CGI scripts cross-site scripting
> Risk Factor:        Medium
> Attack Type:        Network Based
> Platforms:          Aestiva HTML/OS Any version, Linux Any version,
>                     Windows Any version, Unix Any version
> Vulnerability:      aestiva-htmlos-cgi-xss
> X-Force URL:        http://www.iss.net/security_center/static/10029.php
>
> Date Reported:      09/03/2002
> Brief Description:  Check Point FireWall-1/VPN-1
>                     SecuRemote/SecureClient IKE Aggressive Mode
>                     username enumeration
> Risk Factor:        Low
> Attack Type:        Network Based
> Platforms:          Check Point VPN-1/Firewall-1 4.1, Check Point VPN-
>                     1/Firewall-1 4.0
> Vulnerability:      fw1-ike-username-enumeration
> X-Force URL:        http://www.iss.net/security_center/static/10034.php
>
> Date Reported:      09/03/2002
> Brief Description:  Microsoft Internet Explorer URL encoded forward-
>                     slash "Same Origin Policy" bypass
> Risk Factor:        Medium
> Attack Type:        Network Based
> Platforms:          Konqueror 3.0.3, Microsoft Internet Explorer 6.0,
>                     Windows ME, Windows 98, Windows NT 4.0, Windows
>                     2000 Any version
> Vulnerability:      ie-sameoriginpolicy-bypass
> X-Force URL:        http://www.iss.net/security_center/static/10039.php
>
> Date Reported:      09/03/2002
> Brief Description:  Cacti graphs.php vertical label command execution
> Risk Factor:        Medium
> Attack Type:        Network Based
> Platforms:          Linux Any version, Cacti 0.6.8 and earlier
> Vulnerability:      cacti-graph-label-commands
> X-Force URL:        http://www.iss.net/security_center/static/10048.php
>
> Date Reported:      09/03/2002
> Brief Description:  Cacti config.php is world-readable
> Risk Factor:        Medium
> Attack Type:        Host Based / Network Based
> Platforms:          Cacti 0.6.8 and earlier, Linux Any version
> Vulnerability:      cacti-config-world-readable
> X-Force URL:        http://www.iss.net/security_center/static/10049.php
>
> Date Reported:      09/03/2002
> Brief Description:  Cacti console mode command execution
> Risk Factor:        Medium
> Attack Type:        Network Based
> Platforms:          Linux Any version, Cacti 0.6.8 and earlier
> Vulnerability:      cacti-console-mode-commands
> X-Force URL:        http://www.iss.net/security_center/static/10050.php
>
> Date Reported:      09/04/2002
> Brief Description:  Polycom ViewStation uses a blank password by default
> Risk Factor:        High
> Attack Type:        Host Based
> Platforms:          Polycom Viewstation 128 7.2 and earlier, Polycom
>                     Viewstation 512 7.2 and earlier, Polycom
>                     Viewstation DCP 7.2 and earlier, Polycom
>                     Viewstation FX/VS 4000 4.1.5 and earlier, Polycom
>                     Viewstation H.323 7.2 and earlier, Polycom
>                     Viewstation MP 7.2 and earlier, Polycom Viewstation
>                     V.35 7.2 and earlier
> Vulnerability:      viewstation-default-blank-password
> X-Force URL:        http://www.iss.net/security_center/static/9347.php
>
> Date Reported:      09/04/2002
> Brief Description:  Polycom ViewStation Unicode encoded directory
>                     traversal could be used to retrieve administrator
>                     password
> Risk Factor:        High
> Attack Type:        Network Based
> Platforms:          Polycom Viewstation MP 7.2 and earlier, Polycom
>                     Viewstation H.323 7.2 and earlier, Polycom
>                     Viewstation V.35 7.2 and earlier, Polycom
>                     Viewstation FX/VS 4000 4.1.5 and earlier, Polycom
>                     Viewstation DCP 7.2 and earlier, Polycom
>                     Viewstation 512 7.2 and earlier, Polycom
>                     Viewstation 128 7.2 and earlier
> Vulnerability:      viewstation-unicode-retrieve-password
> X-Force URL:        http://www.iss.net/security_center/static/9348.php
>
> Date Reported:      09/04/2002
> Brief Description:  Polycom ViewStation Telnet server unlimited login
>                     attempts denial of service
> Risk Factor:        Low
> Attack Type:        Network Based
> Platforms:          Polycom Viewstation 128 7.2 and earlier, Polycom
>                     Viewstation 512 7.2 and earlier, Polycom
>                     Viewstation DCP 7.2 and earlier, Polycom
>                     Viewstation FX/VS 4000 4.1.5 and earlier, Polycom
>                     Viewstation V.35 7.2 and earlier, Polycom
>                     Viewstation H.323 7.2 and earlier, Polycom
>                     Viewstation MP 7.2 and earlier
> Vulnerability:      viewstation-telnet-login-dos
> X-Force URL:        http://www.iss.net/security_center/static/9349.php
>
> Date Reported:      09/04/2002
> Brief Description:  Polycom ViewStation fragmented ICMP packet denial
>                     of service
> Risk Factor:        Low
> Attack Type:        Network Based
> Platforms:          Polycom Viewstation V.35 7.2 and earlier, Polycom
>                     Viewstation MP 7.2 and earlier, Polycom Viewstation
>                     FX/VS 4000 4.1.5 and earlier, Polycom Viewstation
>                     H.323 7.2 and earlier, Polycom Viewstation 512 7.2
>                     and earlier, Polycom Viewstation 128 7.2 and
>                     earlier, Polycom Viewstation DCP 7.2 and earlier
> Vulnerability:      viewstation-icmp-dos
> X-Force URL:        http://www.iss.net/security_center/static/9350.php
>
> Date Reported:      09/04/2002
> Brief Description:  Microsoft Visual FoxPro could allow an attacker to
>                     execute an application
> Risk Factor:        Medium
> Attack Type:        Network Based
> Platforms:          Microsoft Visual FoxPro 6.0, Windows 2000 Any
>                     version, Windows XP, Windows 95, Windows 98,
>                     Windows ME, Windows NT 4.0
> Vulnerability:      ms-foxpro-app-execution
> X-Force URL:        http://www.iss.net/security_center/static/10035.php
>
> Date Reported:      09/04/2002
> Brief Description:  AFD multiple suid binary buffer overflows
> Risk Factor:        High
> Attack Type:        Host Based
> Platforms:          Linux Any version, AFD 1.2.14
> Vulnerability:      afd-multiple-binaries-bo
> X-Force URL:        http://www.iss.net/security_center/static/10036.php
>
> Date Reported:      09/04/2002
> Brief Description:  Finjan SurfinGate URL "dot" URL filtering bypass
> Risk Factor:        Medium
> Attack Type:        Host Based
> Platforms:          Finjan SurfinGate 6.0x, Windows NT 4.0, Windows
>                     2000 Any version
> Vulnerability:      finjan-surfingate-dot-bypass
> X-Force URL:        http://www.iss.net/security_center/static/10037.php
>
> Date Reported:      09/04/2002
> Brief Description:  Finjan SurfinGate IP address bypass URL filtering
> Risk Factor:        Medium
> Attack Type:        Host Based
> Platforms:          Windows NT 4.0, Windows 2000 Any version, Finjan
>                     SurfinGate 6.0x
> Vulnerability:      finjan-surfingate-ip-bypass
> X-Force URL:        http://www.iss.net/security_center/static/10038.php
>
> Date Reported:      09/05/2002
> Brief Description:  Cisco VPN Client TCP packet denial of service
>                     attack
> Risk Factor:        Low
> Attack Type:        Network Based
> Platforms:          MacOS X 10.1.x, Cisco VPN Client prior to 3.0.5,
>                     Cisco VPN Client 2.x.x, Windows Any version, Red
>                     Hat Linux 6.2, Solaris 2.6, Solaris 9, Solaris 7,
>                     Solaris 8
> Vulnerability:      cisco-vpn-tcp-dos
> X-Force URL:        http://www.iss.net/security_center/static/10042.php
>
> Date Reported:      09/05/2002
> Brief Description:  PGP overly long file name buffer overflow
> Risk Factor:        High
> Attack Type:        Network Based
> Platforms:          Windows XP, Windows 2000 Any version, PGP Corporate
>                     Desktop 7.1.1
> Vulnerability:      pgp-long-filename-bo
> X-Force URL:        http://www.iss.net/security_center/static/10043.php
>
> Date Reported:      09/05/2002
> Brief Description:  Cisco VPN Client Windows utility program could
>                     decipher the group password
> Risk Factor:        Medium
> Attack Type:        Host Based
> Platforms:          Cisco VPN Client 3.0.x, Cisco VPN Client 3.1.x,
>                     Cisco VPN Client prior to 3.5.1C, Cisco VPN Client
>                     2.x.x, Windows Any version
> Vulnerability:      cisco-vpn-obtain-password
> X-Force URL:        http://www.iss.net/security_center/static/10044.php
>
> Date Reported:      09/05/2002
> Brief Description:  Cisco VPN Client improper verification of
>                     certificate DN fields could allow a man-in-the-
>                     middle attack
> Risk Factor:        Medium
> Attack Type:        Network Based
> Platforms:          Windows Any version, Solaris 8, Solaris 9, Solaris
>                     7, Solaris 2.6, Red Hat Linux 6.2, Cisco VPN Client
>                     2.x.x, Cisco VPN Client 3.0.x, Cisco VPN Client
>                     prior to 3.5.1C, Cisco VPN Client 3.1.x, MacOS X
>                     10.1.x
> Vulnerability:      cisco-vpn-certificate-mitm
> X-Force URL:        http://www.iss.net/security_center/static/10045.php
>
> Date Reported:      09/05/2002
> Brief Description:  Cisco VPN Client insecure random number generator
> Risk Factor:        Medium
> Attack Type:        Network Based
> Platforms:          MacOS X 10.1.x, Cisco VPN Client prior to 3.5.2B,
>                     Cisco VPN Client 3.1.x, Cisco VPN Client 3.0.x,
>                     Cisco VPN Client 2.x.x, Red Hat Linux 6.2, Solaris
>                     2.6, Solaris 8, Solaris 7, Solaris 9, Windows Any
>                     version
> Vulnerability:      cisco-vpn-random-numbers
> X-Force URL:        http://www.iss.net/security_center/static/10046.php
>
> Date Reported:      09/05/2002
> Brief Description:  Cisco VPN Client TCP filter could leak sensitive
>                     information
> Risk Factor:        Low
> Attack Type:        Network Based
> Platforms:          Windows Any version, Solaris 9, Solaris 7, Solaris
>                     8, Solaris 2.6, Red Hat Linux 6.2, Cisco VPN Client
>                     2.x.x, Cisco VPN Client 3.0.x, Cisco VPN Client
>                     3.1.x, Cisco VPN Client 3.6(Rel), Cisco VPN Client
>                     prior to 3.5.4, MacOS X 10.1.x
> Vulnerability:      cisco-vpn-tcp-filter
> X-Force URL:        http://www.iss.net/security_center/static/10047.php
>
> Date Reported:      09/05/2002
> Brief Description:  Web Server 4 Everyone hexadecimal URL encoded
>                     directory traversal
> Risk Factor:        Medium
> Attack Type:        Network Based
> Platforms:          Web Server 4 Everyone 1.22, Windows Any version
> Vulnerability:      webserver-4everyone-directory-traversal
> X-Force URL:        http://www.iss.net/security_center/static/10051.php
>
> Date Reported:      09/05/2002
> Brief Description:  AMaViS securetar TAR file denial of service
> Risk Factor:        Low
> Attack Type:        Network Based
> Platforms:          Unix Any version, Linux Any version, AMaViS 0.2.1-
>                     r2 and earlier
> Vulnerability:      amavis-securetar-tar-dos
> X-Force URL:        http://www.iss.net/security_center/static/10056.php
>
> Date Reported:      09/06/2002
> Brief Description:  ZMerge administration database could allow
>                     unauthorized script access
> Risk Factor:        Medium
> Attack Type:        Network Based
> Platforms:          Windows Any version, ZMerge 4.x, ZMerge 5.x
> Vulnerability:      zmerge-admindb-script-access
> X-Force URL:        http://www.iss.net/security_center/static/10057.php
>
> _____
>
> Risk Factor Key:
>
>      High     Any vulnerability that provides an attacker with immediate
>               access into a machine, gains superuser access, or bypasses
>               a firewall. Example: A vulnerable Sendmail 8.6.5 version
>               that allows an intruder to execute commands on mail server.
>      Medium   Any vulnerability that provides information that has a high
>               potential of giving system access to an intruder. Example:
>               A misconfigured TFTP or vulnerable NIS server that allows
>               an intruder to get the password file that could contain an
>               account with a guessable password.
>      Low      Any vulnerability that provides information that could
>               potentially lead to a compromise. Example: A finger that
>               allows an intruder to find out who is online and potential
>               accounts to attempt to crack passwords via brute force
>               methods.
>
> ______
>
> About Internet Security Systems (ISS)
> Founded in 1994, Internet Security Systems (ISS) (Nasdaq: ISSX) is a
> pioneer and world leader in software and services that protect critical
> online resources from an ever-changing spectrum of threats and misuse.
> Internet Security Systems is headquartered in Atlanta, GA, with
> additional operations throughout the Americas, Asia, Australia, Europe
> and the Middle East.
>
> Copyright (c) 2002 Internet Security Systems, Inc. All rights reserved
> worldwide.
>
> Permission is hereby granted for the electronic redistribution of this
> document. It is not to be edited or altered in any way without the
> express written consent of the Internet Security Systems X-Force. If you
> wish to reprint the whole or any part of this document in any other
> medium excluding electronic media, please email [EMAIL PROTECTED] for
> permission.
>
> Disclaimer: The information within this paper may change without notice.
Internet
> Security Systems provides this information on an AS IS basis with NO
warranties,
> implied or otherwise. Any use of this information is at the user's risk.
In no event
> shall Internet Security Systems be held liable for any damages whatsoever
arising
> out of or in connection with the use or dissemination of this information.
>
> X-Force PGP Key available on MIT's PGP key server and PGP.com's key
server,
> as well as at http://www.iss.net/security_center/sensitive.php
>
> Please send suggestions, updates, and comments to: X-Force
> [EMAIL PROTECTED] of Internet Security Systems, Inc.
>
> -----BEGIN PGP SIGNATURE-----
> Version: 2.6.2
>
> iQCVAwUBPXzlFzRfJiV99eG9AQEv2wP/akqOLyyhN6WL6yjydaRIfh4xD1PeWJ0e
> P96V7Okc0pPxMhpm88eBPMNd4D3Wt/ntVljuwRzdm9qlcTj+u19c6WfX/w8g3JlT
> bs9V9J1bxk17KX27RXU4xAEWA42VakTYYBsN5cp51s/UVIQTLhd8l9ObbCrUwXFt
> hDzwn06ihJI=
> =35j5
> -----END PGP SIGNATURE-----
>
> ---
> [This E-mail scanned for viruses by Declude Virus]
>
>

Attachment: smime.p7s
Description: application/pkcs7-signature

Reply via email to