installation software vulnerabilities
vulnerabilities.aspcode.net
Searching installation software vulnerabilities
The installation of Sun Source (sunsrc) tapes a
installation
|
Source
|
Sun
|
The installation of Sun Source (sunsrc) tapes allows local users to gain root privileges via setuid root programs (1) makeinstall or (2) winstall.
The installation of 1ArcServe Backup and Inocul
exchverifylog
|
installation
|
passwords
|
usernames
|
plaintext
|
1ArcServe
|
contains
|
Inoculan
|
Exchange
|
modules
|
create
|
client
|
Backup
|
which
|
file
|
log
|
The installation of 1ArcServe Backup and Inoculan AV client modules for Exchange create a log file, exchverify.log, which contains usernames and passwords in plaintext.
Vulnerability in restore0.9 installation script
Vulnerability
|
installation
|
privileges
|
restore09
|
allows
|
script
|
users
|
local
|
root
|
gain
|
NeXT
|
10a
|
Vulnerability in restore0.9 installation script in NeXT 1.0a and 1.0 allows local users to gain root privileges.
An installation of Red Hat uses DES password en
installation
|
encryption
|
password
|
uses
|
Red
|
Hat
|
DES
|
An installation of Red Hat uses DES password encryption with crypt() for the initial password, instead of md5.
The installation of Tumbleweed Messaging Manage
installation
|
Management
|
Tumbleweed
|
Messaging
|
System
|
The installation of Tumbleweed Messaging Management System (MMS) 4.6 and earlier (formerly Worldtalk Worldsecure) creates a default account "sa" with no password.
Buffer overflow in admintool in Solaris 2.6, 7,
installation
|
privileges
|
admintool
|
overflow
|
Solaris
|
Buffer
|
allows
|
media
|
local
|
users
|
path
|
long
|
gain
|
root
|
via
|
Buffer overflow in admintool in Solaris 2.6, 7, and 8 allows local users to gain root privileges via a long media installation path.
The installation of Tarantella Enterprise 3 all
installation
|
"spinning"
|
Enterprise
|
Tarantella
|
arbitrary
|
temporary
|
overwrite
|
symlink
|
attack
|
allows
|
local
|
files
|
users
|
file
|
via
|
The installation of Tarantella Enterprise 3 allows local users to overwrite arbitrary files via a symlink attack on the "spinning" temporary file.
Unknown vulnerability in Mac OS X 10.3.4, relat
vulnerability
|
Unknown
|
Mac
|
Unknown vulnerability in Mac OS X 10.3.4, related to "package installation scripts," a different vulnerability than CVE-2004-0517.
The install scripts in SugarCRM Sugar Sales 2.0
administrative
|
installation
|
attackers
|
cleartext
|
changing
|
password
|
SugarCRM
|
database
|
settings
|
default
|
scripts
|
install
|
removed
|
earlier
|
service
|
allows
|
denial
|
obtain
|
cause
|
Sugar
|
after
|
Sales
|
MySQL
|
which
|
201c
|
form
|
not
|
The install scripts in SugarCRM Sugar Sales 2.0.1c and earlier are not removed after installation, which allows attackers to obtain the MySQL administrative password in cleartext from an installation form, or to cause a denial of service by changing database settings to the default.
The installation confirmation dialog in Firefox
confirmation
|
installation
|
Firefox
|
before
|
dialog
|
The installation confirmation dialog in Firefox before 1.0.1, Thunderbird before 1.0.1, and Mozilla before 1.7.6 allows remote attackers to use InstallTrigger to spoof the hostname of the host performing the installation via a long "user:pass" sequence in the URL, which appears before the real hostname.
Directory traversal vulnerability in 04WebServe
vulnerability
|
04WebServer
|
Directory
|
traversal
|
Directory traversal vulnerability in 04WebServer 1.81 allows remote attackers to read files outside of the web root but within the installation folder.
The default installation of Horde 3.0.4 contain
installation
|
default
|
Horde
|
The default installation of Horde 3.0.4 contains an administrative account with a blank password, which allows remote attackers to gain access.
post.php in XMB 1.9.2 allows remote attackers t
postphp
|
XMB
|
post.php in XMB 1.9.2 allows remote attackers to obtain the installation path via an invalid fid parameter in a newthread action.
** DISPUTED ** dotProject 2.0.1 and earlier lea
dotProject
|
DISPUTED
|
** DISPUTED ** dotProject 2.0.1 and earlier leaves (1) phpinfo.php and (2) check.php accessible under the /docs/ directory after installation, which allows remote attackers to obtain sensitive configuration information. NOTE: the vendor disputes this issue, saying that it could only occur if the administrator ignores the installation instructions as well as warnings generated by check.php.
NOCC Webmail 1.0 allows remote attackers to obt
html/headerphp
|
installation
|
attackers
|
Webmail
|
request
|
direct
|
remote
|
allows
|
obtain
|
path
|
NOCC
|
via
|
NOCC Webmail 1.0 allows remote attackers to obtain the installation path via a direct request to html/header.php.
sysinfo.cgi in sysinfo 1.21 allows remote attac
sysinfocgi
|
sysinfo
|
sysinfo.cgi in sysinfo 1.21 allows remote attackers to obtain the installation path via the debugger action.
Unspecified vulnerability in the installation p
vulnerability
|
installation
|
Unspecified
|
privileges
|
attackers
|
Directory
|
created
|
process
|
written
|
remote
|
allows
|
causes
|
Server
|
System
|
which
|
users
|
wrong
|
local
|
gain
|
user
|
Java
|
file
|
data
|
Sun
|
Unspecified vulnerability in the installation process in Sun Java System Directory Server 5.2 causes wrong user data to be written to a file created by the installation, which allows remote attackers or local users to gain privileges.
index.php in SoftBB 0.1, and possibly earlier,
installation
|
parameter
|
attackers
|
indexphp
|
possibly
|
invalid
|
earlier
|
page[]
|
allows
|
remote
|
obtain
|
SoftBB
|
path
|
null
|
via
|
index.php in SoftBB 0.1, and possibly earlier, allows remote attackers to obtain the installation path via a null or invalid page[] parameter.
index.php in mAlbum 0.3 and earlier allows remo
installation
|
attackers
|
parameter
|
indexphp
|
earlier
|
invalid
|
obtain
|
mAlbum
|
allows
|
remote
|
path
|
gal
|
via
|
index.php in mAlbum 0.3 and earlier allows remote attackers to obtain the installation path via an invalid gal parameter.
Mozilla Firefox 2.0.0.4 and earlier allows remo
Firefox
|
Mozilla
|
Mozilla Firefox 2.0.0.4 and earlier allows remote attackers to read files in the local Firefox installation directory via a resource:// URI.
Software vulnerabilities results 1 to 20 of 231
Page:
1
2
3
4
5
...
12
►