CVE-2010-2010
published 2010-05-21CVE-2010-2010: Multiple cross-site scripting (XSS) vulnerabilities in the Chaos Tool Suite (aka CTools) module 6.x before 6.x-1.4 for Drupal allow remote attackers to inject…
PriorityP415medium4.3CVSS 2.0
AVNACMAuNCNIPAN
EPSS
1.03%
60.0th percentile
Multiple cross-site scripting (XSS) vulnerabilities in the Chaos Tool Suite (aka CTools) module 6.x before 6.x-1.4 for Drupal allow remote attackers to inject arbitrary web script or HTML via a node title.
Affected
16 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| chaos_tool_suite_project | ctools | — | — |
| chaos_tool_suite_project | ctools | — | — |
| chaos_tool_suite_project | ctools | — | — |
| chaos_tool_suite_project | ctools | — | — |
| chaos_tool_suite_project | ctools | — | — |
| msrc | microsoft_office_2016_for_mac | — | — |
| msrc | microsoft_office_for_mac_2011 | — | — |
| msrc | windows_7_for_32-bit_systems_service_pack_1 | — | — |
| msrc | windows_7_for_x64-based_systems_service_pack_1 | — | — |
| msrc | windows_server_2008_for_32-bit_systems_service_pack_2 | — | — |
| msrc | windows_server_2008_for_itanium-based_systems_service_pack_2 | — | — |
| msrc | windows_server_2008_for_x64-based_systems_service_pack_2 | — | — |
| msrc | windows_server_2008_r2_for_itanium-based_systems_service_pack_1 | — | — |
| msrc | windows_server_2008_r2_for_x64-based_systems_service_pack_1 | — | — |
| msrc | windows_vista_service_pack_2 | — | — |
| msrc | windows_vista_x64_edition_service_pack_2 | — | — |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
vendor_cisco10.0CRITICAL
vendor_redhat9.3CRITICAL
vendor_msrc6.7MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-mvgf-43cx-7vh6: Multiple cross-site scripting (XSS) vulnerabilities in the Chaos Tool Suite (aka CTools) module 6
ghsa_unreviewed·2022-05-17
CVE-2010-2010 [MEDIUM] CWE-79 GHSA-mvgf-43cx-7vh6: Multiple cross-site scripting (XSS) vulnerabilities in the Chaos Tool Suite (aka CTools) module 6
Multiple cross-site scripting (XSS) vulnerabilities in the Chaos Tool Suite (aka CTools) module 6.x before 6.x-1.4 for Drupal allow remote attackers to inject arbitrary web script or HTML via a node title.
Palo Alto
PAN-SA-2024-0008 Informational Bulletin: Impact of OSS CVEs in PAN-OS
vendor_paloalto·2024-09-04·CVSS 6.0
CVE-2022-22965 [MEDIUM] PAN-SA-2024-0008 Informational Bulletin: Impact of OSS CVEs in PAN-OS
PAN-SA-2024-0008 Informational Bulletin: Impact of OSS CVEs in PAN-OS
The Palo Alto Networks Product Security Assurance team has evaluated the following open source software (OSS) CVEs as they relate to PAN-OS software. While PAN-OS software may include the
CVEs: CVE-2010-1622, CVE-2015-7552, CVE-2018-16840, CVE-2019-7639, CVE-2020-17049, CVE-2020-7774, CVE-2021-0131, CVE-2021-0132, CVE-2021-0133, CVE-2021-0134, CVE-2021-4044, CVE-2021-4160, CVE-2021-41773, CVE-2022-1343, CVE-2022-21449, CVE-2022-2274, CVE-2022-22963, CVE-2022-22965, CVE-2022-24697, CVE-2022-32207, CVE-2022-3358, CVE-2022-3996, CVE-2022-40664, CVE-2022-44792, CVE-2022-44793, CVE-2023-1255, CVE-2023-22809, CVE-2023-23919, CVE-2023-3341, CVE-2023-4236, CVE-2023-4863, CVE-2023-51767
Affected products: PAN-OS
Red Hat
kernel: DoS (crash) due slab corruption in inotify_init1 (incomplete fix for CVE-2010-4250)
vendor_redhat·2011-04-05·CVSS 4.9
CVE-2011-1479 [MEDIUM] kernel: DoS (crash) due slab corruption in inotify_init1 (incomplete fix for CVE-2010-4250)
kernel: DoS (crash) due slab corruption in inotify_init1 (incomplete fix for CVE-2010-4250)
Double free vulnerability in the inotify subsystem in the Linux kernel before 2.6.39 allows local users to cause a denial of service (system crash) via vectors involving failed attempts to create files. NOTE: this vulnerability exists because of an incorrect fix for CVE-2010-4250.
Statement: This issue did not affect the versions of Linux kernel as shipped with Red Hat
Enterprise Linux 4 and 5. This has been addressed in Red Hat Enterprise Linux 6 and Red Hat Enterprise MRG via https://rhn.redhat.com/errata/RHSA-2011-0498.html and https://rhn.redhat.com/errata/RHSA-2011-1253.html.
Package: kernel (Red Hat Enterprise Linux 6) - Affected
Package: kernel (Red Hat Enterprise Linux Extended Update Su
Red Hat
festival: insecure library loading vulnerability
vendor_redhat·2010-09-29·CVSS 6.9
CVE-2010-3996 [MEDIUM] festival: insecure library loading vulnerability
festival: insecure library loading vulnerability
festival_server in Centre for Speech Technology Research (CSTR) Festival, probably 2.0.95-beta and earlier, places a zero-length directory name in the LD_LIBRARY_PATH, which allows local users to gain privileges via a Trojan horse shared library in the current working directory.
Statement: Not vulnerable. This issue did not affect the versions of festival as shipped with Red Hat Enterprise Linux 3, 4, or 5.
Red Hat
Bind: DoS (assertion failure) via a DNS query with bad signatures
vendor_redhat·2010-09-28·CVSS 4.3
CVE-2010-3762 [MEDIUM] Bind: DoS (assertion failure) via a DNS query with bad signatures
Bind: DoS (assertion failure) via a DNS query with bad signatures
ISC BIND before 9.7.2-P2, when DNSSEC validation is enabled, does not properly handle certain bad signatures if multiple trust anchors exist for a single zone, which allows remote attackers to cause a denial of service (daemon crash) via a DNS query.
Package: bind (Red Hat Enterprise Linux 4) - Not affected
Package: bind97 (Red Hat Enterprise Linux 5) - Not affected
Package: bind (Red Hat Enterprise Linux 6) - Not affected
Red Hat
flash-plugin: multiple security flaws (APSB10-14)
vendor_redhat·2010-06-10·CVSS 9.3
CVE-2010-2163 [CRITICAL] flash-plugin: multiple security flaws (APSB10-14)
flash-plugin: multiple security flaws (APSB10-14)
Multiple unspecified vulnerabilities in Adobe Flash Player before 9.0.277.0 and 10.x before 10.1.53.64, and Adobe AIR before 2.0.2.12610, might allow attackers to execute arbitrary code via unknown vectors.
Red Hat
WebKit: use-after-free vulnerability in handling of HTML elements with custom vertical positioning
vendor_redhat·2010-06-07·CVSS 9.3
CVE-2010-1405 [CRITICAL] CWE-416 WebKit: use-after-free vulnerability in handling of HTML elements with custom vertical positioning
WebKit: use-after-free vulnerability in handling of HTML elements with custom vertical positioning
Use-after-free vulnerability in WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac OS X 10.4, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via an HTML element that has custom vertical positioning.
Package: qt (Red Hat Enterprise Linux 6) - Will not fix
Package: webkitgtk (Red Hat Enterprise Linux 6) - Will not fix
Cisco
Cisco IOS Software Session Initiation Protocol Denial of Service Vulnerabilities
vendor_cisco·2010-03-24·CVSS 10.0
CVE-2010-0579 [CRITICAL] CWE-399 Cisco IOS Software Session Initiation Protocol Denial of Service Vulnerabilities
Cisco IOS Software Session Initiation Protocol Denial of Service Vulnerabilities
Multiple vulnerabilities exist in the Session Initiation Protocol (SIP)
implementation in Cisco IOS® Software that could
allow an unauthenticated, remote attacker to cause a reload of an affected
device when SIP operation is enabled. Remote code execution may also be
possible.
Cisco has released software updates that address these vulnerabilities. For devices that must run SIP there are no workarounds;
however, mitigations are available to limit exposure of the
vulnerabilities.
This advisory is posted at
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20100324-sip.
Note: The March 24, 2010, Cisco IOS Software Security Advisory bundled
publication includes seven Securit
Red Hat
libESMTP: Multiple certificate validation flaws
vendor_redhat·2010-03-03·CVSS 5.9
CVE-2010-1192 [MEDIUM] libESMTP: Multiple certificate validation flaws
libESMTP: Multiple certificate validation flaws
libESMTP, probably 1.0.4 and earlier, does not properly handle a '\0' character in a domain name in the subject's Common Name (CN) field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408.
Package: libesmtp (Red Hat Enterprise Linux 6) - Affected
Suricata
ET WEB_SPECIFIC_APPS Grayscale Blog SQL Injection Attempt -- userdetail.php id UNION SELECT
suricata·2010-07-30·CVSS 7.5
CVE-2007-1434 [HIGH] ET WEB_SPECIFIC_APPS Grayscale Blog SQL Injection Attempt -- userdetail.php id UNION SELECT
ET WEB_SPECIFIC_APPS Grayscale Blog SQL Injection Attempt -- userdetail.php id UNION SELECT
Rule: alert http $EXTERNAL_NET any -> $HTTP_SERVERS any (msg:"ET WEB_SPECIFIC_APPS Grayscale Blog SQL Injection Attempt -- userdetail.php id UNION SELECT"; flow:established,to_server; http.uri; content:"/userdetail.php?"; nocase; content:"id="; nocase; content:"UNION"; nocase; content:"SELECT"; nocase; distance:0; reference:cve,CVE-2007-1434; reference:url,www.securityfocus.com/bid/22911; classtype:web-application-attack; sid:2004350; rev:9; metadata:affected_product Web_Server_Applications, attack_target Web_Server, created_at 2010_07_30, deployment Datacenter, confidence Medium, signature_severity Major, tag SQL_Injection, updated_at 2020_09_11, mitre_tactic_id TA0001, mitre_tactic_name Initial_A
Suricata
ET WEB_SPECIFIC_APPS Coppermine Photo Gallery SQL Injection Attempt -- albmgr.php cat INSERT
suricata·2010-07-30·CVSS 6.5
CVE-2007-0122 [MEDIUM] ET WEB_SPECIFIC_APPS Coppermine Photo Gallery SQL Injection Attempt -- albmgr.php cat INSERT
ET WEB_SPECIFIC_APPS Coppermine Photo Gallery SQL Injection Attempt -- albmgr.php cat INSERT
Rule: alert http $EXTERNAL_NET any -> $HTTP_SERVERS any (msg:"ET WEB_SPECIFIC_APPS Coppermine Photo Gallery SQL Injection Attempt -- albmgr.php cat INSERT"; flow:established,to_server; http.uri; content:"/albmgr.php?"; nocase; content:"cat="; nocase; content:"INSERT"; nocase; content:"INTO"; nocase; distance:0; reference:cve,CVE-2007-0122; reference:url,www.securityfocus.com/bid/21894; classtype:web-application-attack; sid:2005843; rev:9; metadata:affected_product Web_Server_Applications, attack_target Web_Server, created_at 2010_07_30, deployment Datacenter, confidence Medium, signature_severity Major, tag SQL_Injection, updated_at 2020_09_10, mitre_tactic_id TA0001, mitre_tactic_name Initial_Acc
Suricata
ET WEB_SPECIFIC_APPS Rialto SQL Injection Attempt -- searchoption.asp cost2 UPDATE
suricata·2010-07-30·CVSS 7.5
CVE-2006-6927 [HIGH] ET WEB_SPECIFIC_APPS Rialto SQL Injection Attempt -- searchoption.asp cost2 UPDATE
ET WEB_SPECIFIC_APPS Rialto SQL Injection Attempt -- searchoption.asp cost2 UPDATE
Rule: alert http $EXTERNAL_NET any -> $HTTP_SERVERS any (msg:"ET WEB_SPECIFIC_APPS Rialto SQL Injection Attempt -- searchoption.asp cost2 UPDATE"; flow:established,to_server; http.uri; content:"/searchoption.asp?"; nocase; content:"cost2="; nocase; content:"UPDATE"; nocase; pcre:"/UPDATE.+SET/i"; reference:cve,CVE-2006-6927; reference:url,www.securityfocus.com/bid/21191; classtype:web-application-attack; sid:2005753; rev:8; metadata:affected_product Web_Server_Applications, attack_target Web_Server, created_at 2010_07_30, deployment Datacenter, confidence Medium, signature_severity Major, tag SQL_Injection, updated_at 2020_09_09, mitre_tactic_id TA0001, mitre_tactic_name Initial_Access, mitre_technique_id T
Suricata
ET WEB_SPECIFIC_APPS HIOX Star Rating System Script (HSRS) SQL Injection Attempt -- addrating.php url DELETE
suricata·2010-07-30·CVSS 7.5
CVE-2006-6155 [HIGH] ET WEB_SPECIFIC_APPS HIOX Star Rating System Script (HSRS) SQL Injection Attempt -- addrating.php url DELETE
ET WEB_SPECIFIC_APPS HIOX Star Rating System Script (HSRS) SQL Injection Attempt -- addrating.php url DELETE
Rule: alert http $EXTERNAL_NET any -> $HTTP_SERVERS any (msg:"ET WEB_SPECIFIC_APPS HIOX Star Rating System Script (HSRS) SQL Injection Attempt -- addrating.php url DELETE"; flow:established,to_server; http.uri; content:"/addrating.php?"; nocase; content:"url="; nocase; content:"DELETE"; nocase; content:"FROM"; nocase; distance:0; reference:cve,CVE-2006-6155; reference:url,www.frsirt.com/english/advisories/2006/4689; classtype:web-application-attack; sid:2007413; rev:9; metadata:affected_product Web_Server_Applications, attack_target Web_Server, created_at 2010_07_30, deployment Datacenter, confidence Medium, signature_severity Major, tag SQL_Injection, updated_at 2020_09_11, mitre_
Suricata
ET WEB_SPECIFIC_APPS webSPELL SQL Injection Attempt -- printview.php topic SELECT
suricata·2010-07-30·CVSS 7.5
CVE-2007-1163 [HIGH] ET WEB_SPECIFIC_APPS webSPELL SQL Injection Attempt -- printview.php topic SELECT
ET WEB_SPECIFIC_APPS webSPELL SQL Injection Attempt -- printview.php topic SELECT
Rule: alert http $EXTERNAL_NET any -> $HTTP_SERVERS any (msg:"ET WEB_SPECIFIC_APPS webSPELL SQL Injection Attempt -- printview.php topic SELECT"; flow:established,to_server; http.uri; content:"/printview.php?"; nocase; content:"topic="; nocase; content:"SELECT"; nocase; content:"FROM"; nocase; distance:0; reference:cve,CVE-2007-1163; reference:url,www.milw0rm.com/exploits/3351; classtype:web-application-attack; sid:2004748; rev:8; metadata:affected_product Web_Server_Applications, attack_target Web_Server, created_at 2010_07_30, deployment Datacenter, confidence Medium, signature_severity Major, tag SQL_Injection, updated_at 2020_09_10, mitre_tactic_id TA0001, mitre_tactic_name Initial_Access, mitre_techniqu
Suricata
ET WEB_SPECIFIC_APPS ClickTech Click Gallery SQL Injection Attempt -- gallery.asp orderby ASCII
suricata·2010-07-30·CVSS 7.5
CVE-2006-6187 [HIGH] ET WEB_SPECIFIC_APPS ClickTech Click Gallery SQL Injection Attempt -- gallery.asp orderby ASCII
ET WEB_SPECIFIC_APPS ClickTech Click Gallery SQL Injection Attempt -- gallery.asp orderby ASCII
Rule: alert http $EXTERNAL_NET any -> $HTTP_SERVERS any (msg:"ET WEB_SPECIFIC_APPS ClickTech Click Gallery SQL Injection Attempt -- gallery.asp orderby ASCII"; flow:established,to_server; http.uri; content:"/gallery.asp?"; nocase; content:"orderby="; nocase; content:"ASCII("; nocase; content:"SELECT"; nocase; distance:0; reference:cve,CVE-2006-6187; reference:url,www.securityfocus.com/archive/1/archive/1/452733/100/0/threaded; classtype:web-application-attack; sid:2007257; rev:8; metadata:affected_product Web_Server_Applications, attack_target Web_Server, created_at 2010_07_30, deployment Datacenter, confidence Medium, signature_severity Major, tag SQL_Injection, updated_at 2020_09_10, mitre_ta
Suricata
ET WEB_SPECIFIC_APPS Savas Guestbook SQL Injection Attempt -- add2.php name DELETE
suricata·2010-07-30·CVSS 6.8
CVE-2007-1304 [MEDIUM] ET WEB_SPECIFIC_APPS Savas Guestbook SQL Injection Attempt -- add2.php name DELETE
ET WEB_SPECIFIC_APPS Savas Guestbook SQL Injection Attempt -- add2.php name DELETE
Rule: alert http $EXTERNAL_NET any -> $HTTP_SERVERS any (msg:"ET WEB_SPECIFIC_APPS Savas Guestbook SQL Injection Attempt -- add2.php name DELETE"; flow:established,to_server; http.uri; content:"/add2.php?"; nocase; content:"name="; nocase; content:"DELETE"; nocase; pcre:"/DELETE.+FROM/i"; reference:cve,CVE-2007-1304; reference:url,www.securityfocus.com/bid/22820; classtype:web-application-attack; sid:2004496; rev:8; metadata:affected_product Web_Server_Applications, attack_target Web_Server, created_at 2010_07_30, deployment Datacenter, confidence Medium, signature_severity Major, tag SQL_Injection, updated_at 2020_09_09, mitre_tactic_id TA0001, mitre_tactic_name Initial_Access, mitre_technique_id T1190, mi
Suricata
ET WEB_SPECIFIC_APPS MidiCart ASP Shopping Cart and ASP Plus Shopping Cart SQL Injection Attempt -- item_list.asp maingroup SELECT
suricata·2010-07-30·CVSS 7.5
CVE-2006-6209 [HIGH] ET WEB_SPECIFIC_APPS MidiCart ASP Shopping Cart and ASP Plus Shopping Cart SQL Injection Attempt -- item_list.asp maingroup SELECT
ET WEB_SPECIFIC_APPS MidiCart ASP Shopping Cart and ASP Plus Shopping Cart SQL Injection Attempt -- item_list.asp maingroup SELECT
Rule: alert http $EXTERNAL_NET any -> $HTTP_SERVERS any (msg:"ET WEB_SPECIFIC_APPS MidiCart ASP Shopping Cart and ASP Plus Shopping Cart SQL Injection Attempt -- item_list.asp maingroup SELECT"; flow:established,to_server; http.uri; content:"/item_list.asp?"; nocase; content:"maingroup="; nocase; content:"SELECT"; nocase; pcre:"/SELECT.+FROM/i"; reference:cve,CVE-2006-6209; reference:url,www.securityfocus.com/bid/21273; classtype:web-application-attack; sid:2007012; rev:8; metadata:affected_product Web_Server_Applications, attack_target Web_Server, created_at 2010_07_30, deployment Datacenter, confidence Medium, signature_severity Major, tag SQL_Injection, upd
Suricata
ET WEB_SPECIFIC_APPS bitweaver SQL Injection Attempt -- edition.php tk UPDATE
suricata·2010-07-30·CVSS 7.5
CVE-2006-6923 [HIGH] ET WEB_SPECIFIC_APPS bitweaver SQL Injection Attempt -- edition.php tk UPDATE
ET WEB_SPECIFIC_APPS bitweaver SQL Injection Attempt -- edition.php tk UPDATE
Rule: alert http $EXTERNAL_NET any -> $HTTP_SERVERS any (msg:"ET WEB_SPECIFIC_APPS bitweaver SQL Injection Attempt -- edition.php tk UPDATE"; flow:established,to_server; http.uri; content:"/newsletters/edition.php?"; nocase; content:"tk="; nocase; content:"UPDATE"; nocase; pcre:"/UPDATE.+SET/i"; reference:cve,CVE-2006-6923; reference:url,www.securityfocus.com/bid/20996; classtype:web-application-attack; sid:2005771; rev:8; metadata:affected_product Web_Server_Applications, attack_target Web_Server, created_at 2010_07_30, deployment Datacenter, confidence Medium, signature_severity Major, tag SQL_Injection, updated_at 2020_09_09, mitre_tactic_id TA0001, mitre_tactic_name Initial_Access, mitre_technique_id T1190,
Suricata
ET WEB_SPECIFIC_APPS Rialto SQL Injection Attempt -- searchmain.asp area INSERT
suricata·2010-07-30·CVSS 7.5
CVE-2006-6927 [HIGH] ET WEB_SPECIFIC_APPS Rialto SQL Injection Attempt -- searchmain.asp area INSERT
ET WEB_SPECIFIC_APPS Rialto SQL Injection Attempt -- searchmain.asp area INSERT
Rule: alert http $EXTERNAL_NET any -> $HTTP_SERVERS any (msg:"ET WEB_SPECIFIC_APPS Rialto SQL Injection Attempt -- searchmain.asp area INSERT"; flow:established,to_server; http.uri; content:"/searchmain.asp?"; nocase; content:"area="; nocase; content:"INSERT"; nocase; pcre:"/INSERT.+INTO/i"; reference:cve,CVE-2006-6927; reference:url,www.securityfocus.com/bid/21191; classtype:web-application-attack; sid:2005725; rev:8; metadata:affected_product Web_Server_Applications, attack_target Web_Server, created_at 2010_07_30, deployment Datacenter, confidence Medium, signature_severity Major, tag SQL_Injection, updated_at 2020_09_09, mitre_tactic_id TA0001, mitre_tactic_name Initial_Access, mitre_technique_id T1190, mi
Suricata
ET WEB_SPECIFIC_APPS Future Internet SQL Injection Attempt -- index.cfm newsId ASCII
suricata·2010-07-30·CVSS 7.5
CVE-2006-6776 [HIGH] ET WEB_SPECIFIC_APPS Future Internet SQL Injection Attempt -- index.cfm newsId ASCII
ET WEB_SPECIFIC_APPS Future Internet SQL Injection Attempt -- index.cfm newsId ASCII
Rule: alert http $EXTERNAL_NET any -> $HTTP_SERVERS any (msg:"ET WEB_SPECIFIC_APPS Future Internet SQL Injection Attempt -- index.cfm newsId ASCII"; flow:established,to_server; http.uri; content:"/index.cfm?"; nocase; content:"newsId="; nocase; content:"ASCII("; nocase; content:"SELECT"; nocase; distance:0; reference:cve,CVE-2006-6776; reference:url,www.securityfocus.com/bid/21727; classtype:web-application-attack; sid:2006193; rev:9; metadata:affected_product Web_Server_Applications, attack_target Web_Server, created_at 2010_07_30, deployment Datacenter, confidence Medium, signature_severity Major, tag SQL_Injection, updated_at 2020_09_11, mitre_tactic_id TA0001, mitre_tactic_name Initial_Access, mitre_t
Suricata
ET WEB_SPECIFIC_APPS ClickTech Click Gallery SQL Injection Attempt -- view_gallery.asp gallery_id SELECT
suricata·2010-07-30·CVSS 7.5
CVE-2006-6187 [HIGH] ET WEB_SPECIFIC_APPS ClickTech Click Gallery SQL Injection Attempt -- view_gallery.asp gallery_id SELECT
ET WEB_SPECIFIC_APPS ClickTech Click Gallery SQL Injection Attempt -- view_gallery.asp gallery_id SELECT
Rule: alert http $EXTERNAL_NET any -> $HTTP_SERVERS any (msg:"ET WEB_SPECIFIC_APPS ClickTech Click Gallery SQL Injection Attempt -- view_gallery.asp gallery_id SELECT"; flow:established,to_server; http.uri; content:"/view_gallery.asp?"; nocase; content:"gallery_id="; nocase; content:"SELECT"; nocase; content:"FROM"; nocase; distance:0; reference:cve,CVE-2006-6187; reference:url,www.securityfocus.com/archive/1/archive/1/452733/100/0/threaded; classtype:web-application-attack; sid:2007235; rev:9; metadata:affected_product Web_Server_Applications, attack_target Web_Server, created_at 2010_07_30, deployment Datacenter, confidence Medium, signature_severity Major, tag SQL_Injection, updated
Exploit-DB
POP Peeper 3.4 - DATE Buffer Overflow (Metasploit)
exploitdb·2010-11-11
CVE-2009-1029 POP Peeper 3.4 - DATE Buffer Overflow (Metasploit)
POP Peeper 3.4 - DATE Buffer Overflow (Metasploit)
---
##
# $Id: poppeeper_date.rb 10998 2010-11-11 22:43:22Z jduck $
##
##
# This file is part of the Metasploit Framework and may be subject to
# redistribution and commercial restrictions. Please see the Metasploit
# Framework web site for more information on licensing and terms of use.
# http://metasploit.com/framework/
##
class Metasploit3 'POP Peeper v3.4 DATE Buffer Overflow',
'Description' => %q{
This module exploits a stack buffer overflow in POP Peeper v3.4.
When a specially crafted DATE string is sent to a client,
an attacker may be able to execute arbitrary code. This
module is based off of krakowlabs code.
},
'Author' => [ 'MC' ],
'License' => MSF_LICENSE,
'Version' => '$Revision: 10998 $',
'References' =>
[
[ 'CVE', '2009-10
Exploit-DB
Joomla! Component PicSell 1.0 - Local File Disclosure
exploitdb·2010-08-30
CVE-2010-3203 Joomla! Component PicSell 1.0 - Local File Disclosure
Joomla! Component PicSell 1.0 - Local File Disclosure
---
# Author: Craw
# Email: [email protected]
# Software Link: http://vm.xmlswf.com/index.php?option=com_content&view=article&id=104&Itemid=131
# Category: web applications
[+] ExploiT :
http://server/index.php?option=com_picsell&controller=prevsell&task=dwnfree&dflink=[File Disclosure]
[+] Example :
http://server/index.php?option=com_picsell&controller=prevsell&task=dwnfree&dflink=../../../configuration.php
Greetz @ LUXEMBOURG
Exploit-DB
AutoDealer 1.0/2.0 - MSSQL Injection
exploitdb·2010-04-30
CVE-2007-0053 AutoDealer 1.0/2.0 - MSSQL Injection
AutoDealer 1.0/2.0 - MSSQL Injection
---
# vendor :http://www.aspsiteware.com/Auto.asp
# Date: 30 apr,2010
# Dork:Copyright © 2010 ASP SiteWare. All rights reserved.
#####################Sid3^effects aKa HaRi##################################
#Greetz to all Andhra Hackers and ICW Memebers[Indian Cyber Warriors]
#Thanks:*L0rd ÇrusAdêr*,d4rk-blu™®,R45C4L idi0th4ck3r,CR4C|< 008,M4n0j,MaYuR
#ShouTZ:kedar,dec0d3r,41.w4r10r
#Catch us at www.andhrahackers.com or www.teamicw.in
############################################################################
Description :
AutoDealer is an application ideal for the small or independent new or used car dealer who needs a way
to display and update their inventory online. Backend by Access database, AutoDealer can store
thousands of vehicles in catego
Exploit-DB
Adobe (Multiple Products) - XML External Entity / XML Injection
exploitdb·2010-02-22·CVSS 6.5
CVE-2009-3960 [MEDIUM] Adobe (Multiple Products) - XML External Entity / XML Injection
Adobe (Multiple Products) - XML External Entity / XML Injection
---
( , ) (,
. `.' ) ('. ',
). , ('. ( ) (
(_,) .`), ) _ _,
/ _____/ / _ \ ____ ____ _____
\____ \==/ /_\ \ _/ ___\/ _ \ / \
/ \/ | \\ \__( ) Y Y \
/______ /\___|__ / \___ >____/|__|_| /
\/ \/.-. \/ \/:wq
(x.0)
'=.|w|.='
_='`"``=.
presents..
Multiple Adobe Products
XML External Entity And XML Injection Vulnerabilities
CVE: CVE-2009-3960
Adobe PSIRT: APSB10-05 - http://www.adobe.com/support/security/bulletins/apsb10-05.html
Link: http://www.security-assessment.com/files/advisories/2010-02-22_Multiple_Adobe_Products-XML_External_Entity_and_XML_Injection.pdf
+-----------+
|Description|
+-----------+
Security-Assessment.com discovered that multiple Adobe
products with different Data Services versions are
vulnerable to XML E
Nuclei
Joomla! Component com_jvideodirect - Directory Traversal
nuclei·CVSS 5.0
CVE-2010-0942 [MEDIUM] Joomla! Component com_jvideodirect - Directory Traversal
Joomla! Component com_jvideodirect - Directory Traversal
Directory traversal vulnerability in the jVideoDirect (com_jvideodirect) component for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php.
Template:
id: CVE-2010-0942
info:
name: Joomla! Component com_jvideodirect - Directory Traversal
author: daffainfo
severity: medium
description: Directory traversal vulnerability in the jVideoDirect (com_jvideodirect) component for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php.
impact: |
An attacker can exploit this vulnerability to read arbitrary files on the server.
remediation: Apply all relevant security patches and product upgrades.
reference:
- https://ww
Bugzilla
CVE-2010-3666 php-typo3-phar-stream-wrapper2: php-typo3-phar-stream-wrapper: contains insecure randomness in the uniqid function [epel-7]
bugzilla·2019-11-12·CVSS 5.3
CVE-2010-3666 [MEDIUM] CVE-2010-3666 php-typo3-phar-stream-wrapper2: php-typo3-phar-stream-wrapper: contains insecure randomness in the uniqid function [epel-7]
CVE-2010-3666 php-typo3-phar-stream-wrapper2: php-typo3-phar-stream-wrapper: contains insecure randomness in the uniqid function [epel-7]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-7.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit messag
Bugzilla
CVE-2010-5312 sagemath: jquery-ui: XSS vulnerability in jQuery.ui.dialog title option [fedora-all]
bugzilla·2014-11-21·CVSS 6.1
CVE-2010-5312 [MEDIUM] CVE-2010-5312 sagemath: jquery-ui: XSS vulnerability in jQuery.ui.dialog title option [fedora-all]
CVE-2010-5312 sagemath: jquery-ui: XSS vulnerability in jQuery.ui.dialog title option [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple s
Bugzilla
CVE-2010-4471 OpenJDK Java2D font-related system property leak (6985453)
bugzilla·2011-02-08·CVSS 5.0
CVE-2010-4471 [MEDIUM] CVE-2010-4471 OpenJDK Java2D font-related system property leak (6985453)
CVE-2010-4471 OpenJDK Java2D font-related system property leak (6985453)
A vulnerability was discovered in the 2D subcomponent. Exceptions thrown when processing broken CFF fonts could leak system property values.
This issue (CVE-2010-4471) is not exploitable when using OpenJDK on Red Hat
Enterprise Linux 5 and 6; however, the fix was added as a defense in depth.
Discussion:
This issue has been addressed in following products:
Supplementary for Red Hat Enterprise Linux 5
Supplementary for Red Hat Enterprise Linux 6
Extras for RHEL 4
Via RHSA-2011:0282 https://rhn.redhat.com/errata/RHSA-2011-0282.html
---
This issue has been addressed in following products:
Red Hat Enterprise Linux 5
Red Hat Enterprise Linux 6
Via RHSA-2011:0281 https://rhn.redhat.com/errata/RHSA-2011-0281.html
-
Bugzilla
CVE-2010-4072 kernel: ipc/shm.c: reading uninitialized stack memory
bugzilla·2010-11-01·CVSS 1.9
CVE-2010-4072 [LOW] CVE-2010-4072 kernel: ipc/shm.c: reading uninitialized stack memory
CVE-2010-4072 kernel: ipc/shm.c: reading uninitialized stack memory
Description of problem:
The old shm interface allows unprivileged users to read uninitialized stack memory, because shmid_ds structure declared on the stack is not altered or zeroed before being copied back to the user.
Reference:
http://www.openwall.com/lists/oss-security/2010/10/07/1
http://lkml.org/lkml/2010/10/6/454
Acknowledgements:
Red Hat would like to thank Vasiliy Kulikov of Openwall and Kees Cook for reporting this issue.
Discussion:
Statement:
This issue is not planned to be fixed in Red Hat Enterprise Linux 3, due to this product being in Extended Life Cycle Phase of its maintenance life-cycle, where only qualified security errata of critical impact are addressed.
For further information about the Errat
Bugzilla
CVE-2010-3492 python accept() implementation in async core is broken
bugzilla·2010-09-28·CVSS 5.0
CVE-2010-3492 [MEDIUM] CVE-2010-3492 python accept() implementation in async core is broken
CVE-2010-3492 python accept() implementation in async core is broken
From the upstream bug: http://bugs.python.org/issue6706
An old bad design choice in asyncore is how it forces the user to override
handle_accept() and then call self.accept() to obtain a socket pair.
def handle_accept(self):
conn, addr = self.accept()
The documentation itself shows the code above as an example of how an
asyncore-based server should handle an incoming connection. What the doc
doesn't say is that the user calling self.accept() is exposed to different
risks:
- self.accept() can return None instead of a socket pair in which case
TypeError is raised (see pyftpdlib bug:
http://code.google.com/p/pyftpdlib/issues/detail?id=91)
- ECONNABORTED can be raised. This is reproducible on Linux by hammering
the serv
Bugzilla
CVE-2010-3303 mantis: several XSS flaws fixed in 1.2.3
bugzilla·2010-09-15·CVSS 2.1
CVE-2010-3303 [LOW] CVE-2010-3303 mantis: several XSS flaws fixed in 1.2.3
CVE-2010-3303 mantis: several XSS flaws fixed in 1.2.3
Upstream MantisBT has released [1] version 1.2.3 which corrects a number of XSS flaws. Two already have CVE names: CVE-2010-3070 and CVE-2010-2574. There are an additional four issues currently without CVE names.
From the changelog [1]:
- 0012312: [security] NuSOAP WSDL XSS (cross-site scripting vulnerability) in Mantis 1.2.2 (CVE-2010-3070)
- 0012230: [security] XSS vulnerability when deleting maliciously named categories (CVE-2010-2574)
- 0012231: [security] XSS vulnerability when uninstalling maliciously named plugins
- 0012232: [security] Multiple XSS issues with custom field enumeration values
- 0012234: [security] XSS issues when using custom field String values
- 0012238: [security] XSS in print_all_bug_page_word.php when pri
Bugzilla
CVE-2010-3170 firefox/nss: doesn't handle IP-based wildcards in X509 certificates safely
bugzilla·2010-09-03·CVSS 5.9
CVE-2010-3170 [MEDIUM] CVE-2010-3170 firefox/nss: doesn't handle IP-based wildcards in X509 certificates safely
CVE-2010-3170 firefox/nss: doesn't handle IP-based wildcards in X509 certificates safely
Richard Moore and Simon Ward reported flaws in the way browsers such
as Firefox handled wildcard characters in the Common Name field of
a certificate. If an attacker is able to get a carefully-crafted certificate,
signed by a Certificate Authority trusted by Firefox, the attacker could
use the certificate during the man-in-the-middle attack and potentially
confuse Firefox into accepting it by mistake. Different vulnerability than
CVE-2009-2408.
References:
[1] http://www.westpoint.ltd.uk/advisories/wp-10-0001.txt
[2] http://bugs.gentoo.org/show_bug.cgi?id=335731
Discussion:
This will be fixed in NSS 3.12.8
---
Mozilla has assigned CVE-2010-3170 identifier to this issue.
Mozilla upstream bug:
[3]
Bugzilla
CVE-2010-2071 kernel: btrfs: prevent users from setting ACLs on files they do not own
bugzilla·2010-06-14·CVSS 4.6
CVE-2010-2071 [MEDIUM] CVE-2010-2071 kernel: btrfs: prevent users from setting ACLs on files they do not own
CVE-2010-2071 kernel: btrfs: prevent users from setting ACLs on files they do not own
Description of problem:
http://lkml.org/lkml/2010/5/17/544
On btrfs, do the following
# su user1
# cd btrfs-part/
# touch aaa
# getfacl aaa
# file: aaa
# owner: user1
# group: user1
user::rw-
group::rw-
other::r--
# su user2
# cd btrfs-part/
# setfacl -m u::rwx aaa
# getfacl aaa
# file: aaa
# owner: user1
# group: user1
user::rwx <- successed to setfacl
group::rw-
other::r--
but we should prohibit it that user2 changing user1's acl.
In fact, on ext3 and other fs, a message occurs:
setfacl: aaa: Operation not permitted
Upstream commit:
http://git.kernel.org/linus/2f26afba
Discussion:
Meanwhile, we should also include http://git.kernel.org/linus/731e3d1b.
---
Statement:
Not vulnerable. This issue di
Bugzilla
CVE-2010-1403 WebKit: uninitialized memory access vulnerability in handling of 'use' elements in SVG documents (ZDI-CAN-702)
bugzilla·2010-05-26·CVSS 9.3
CVE-2010-1403 [CRITICAL] CVE-2010-1403 WebKit: uninitialized memory access vulnerability in handling of 'use' elements in SVG documents (ZDI-CAN-702)
CVE-2010-1403 WebKit: uninitialized memory access vulnerability in handling of 'use' elements in SVG documents (ZDI-CAN-702)
An uninitialized memory access issue exists in WebKit's handling of 'use' elements in SVG documents. Visiting a maliciously crafted website may lead to an unexpected application termination or arbitrary code execution. This issue is addressed through improved handling of 'use' elements in SVG documents.
References:
Bugzilla: https://bugs.webkit.org/show_bug.cgi?id=35708
Trac: http://trac.webkit.org/changeset/53446
Acknowledgements:
Red Hat would like to thank Drew Yao of Apple Product Security for responsibly reporting this issue. Upstream acknowledges wushi of team509, working with TippingPoint's Zero Day Initiative, as the original reporter.
Discussion:
Publ
Bugzilla
CVE-2010-1431 cacti: SQL injection vulnerability (BONSAI-2010-0104)
bugzilla·2010-04-23·CVSS 7.5
CVE-2010-1431 [HIGH] CVE-2010-1431 cacti: SQL injection vulnerability (BONSAI-2010-0104)
CVE-2010-1431 cacti: SQL injection vulnerability (BONSAI-2010-0104)
An SQL injection vulnerability was reported in cacti [1]. Input passed via the 'export_item_id' parameter to the templates_export.php script is not properly sanitized prior to being used in an SQL query. Upstream has provided a patch to correct this issue [2].
[1] http://seclists.org/fulldisclosure/2010/Apr/272
[2] http://www.cacti.net/downloads/patches/0.8.7e/sql_injection_template_export.patch
Discussion:
Created cacti tracking bugs for this issue
Affects: fedora-all [bug 585402]
---
bug 585207 has addressed this in Fedora and EPEL.
---
This has been assigned CVE-2010-1431.
---
Direct link to BONSAI-2010-0104 advisory:
http://www.bonsai-sec.com/en/research/vulnerabilities/cacti-sql-injection-0104.php
---
Th
Bugzilla
CVE-2010-0436 kdm privilege escalation flaw
bugzilla·2010-03-04·CVSS 6.9
CVE-2010-0436 [MEDIUM] CVE-2010-0436 kdm privilege escalation flaw
CVE-2010-0436 kdm privilege escalation flaw
Sebastian Krahmer from the SUSE security team discovered a privilege escalation flaw in the KDE Display Manager (kdm).
kdm uses a user owned directory to store a command socket. If the local user can prevent this directory from being removed, they can create a race condition with ksm that could result in setting an arbitrary file on the filesystem to have word writable permissions.
A local user with access to a console running kdm could use this flaw to gain superuser access.
Discussion:
Created attachment 397924
Current proposed patch from upstream
I'm not 100% sure this will be the final patch. I'll be sure to upload a new patch as soon as I hear more from upstream.
---
Created attachment 400244
latest patch provided by upstream
This i
Bugzilla
CVE-2009-4538 kernel: e1000e frame fragment issue
bugzilla·2009-12-29·CVSS 10.0
CVE-2009-4538 [CRITICAL] CVE-2009-4538 kernel: e1000e frame fragment issue
CVE-2009-4538 kernel: e1000e frame fragment issue
Description of problem:
Similar to the second issue that Fab mentioned in his presentation at 26c3, this affects the e1000e driver. See https://bugzilla.redhat.com/show_bug.cgi?id=550907#c0 issue #2 for the description, and this https://bugzilla.redhat.com/show_bug.cgi?id=550907#c4. This bug is filed to make sure we fix this too.
http://www.securityfocus.com/bid/37523
Discussion:
A quick heads up to all the release owners on this bug, the patch I posted upstream for bz 550915 (specifically the e1000 bits) will apply pretty cleanly to e1000e here.
---
This issue has been addressed in following products:
Red Hat Enterprise Linux 5
Via RHSA-2010:0019 https://rhn.redhat.com/errata/RHSA-2010-0019.html
---
This issue has been addressed
Trendmicro
Asruex Backdoor Infects Files Via Old Vulnerabilities
blogs_trendmicro·2019-08-22·CVSS 7.3
[HIGH] Asruex Backdoor Infects Files Via Old Vulnerabilities
Ciberamenazas
## Asruex Backdoor Infects Files Via Old Vulnerabilities
Asruex has been known for its backdoor capabilities. However, when we encountered Asruex in a PDF file, we found that a variant of the malware can also act as an infector particularly through the use of old vulnerabilities.
By: Ian Mercado, Mhica Romero Aug 22, 2019 Read time: ( words)
Save to Folio
Since it first emerged in 2015, Asruex has been known for its backdoor capabilities and connection to the spyware DarkHotel. However, when we encountered Asruex in a PDF file, we found that a variant of the malware can also act as an infector particularly through the use of old vulnerabilities CVE-2012-0158 and CVE-2010-2883 , which inject code in Word and PDF files respectively. The use of old, patched vulnerabilities
http://drupal.org/node/803944http://secunia.com/advisories/39884http://www.securityfocus.com/bid/40285https://exchange.xforce.ibmcloud.com/vulnerabilities/58721http://drupal.org/node/803944http://secunia.com/advisories/39884http://www.securityfocus.com/bid/40285https://exchange.xforce.ibmcloud.com/vulnerabilities/58721
2010-05-21
Published