vary software vulnerabilities
vulnerabilities.aspcode.net
Searching vary software vulnerabilities
Quake II server before R1Q2, as used in multipl
reconnecting
|
disconnect
|
attackers
|
structure
|
prevents
|
server's
|
products
|
notified
|
multiple
|
exiting
|
session
|
changes
|
command
|
corrupt
|
without
|
server
|
allows
|
before
|
remote
|
client
|
which
|
Quake
|
being
|
state
|
valid
|
used
|
R1Q2
|
data
|
then
|
mod
|
Quake II server before R1Q2, as used in multiple products, allows remote attackers to corrupt the server's client state data structure by exiting a session without a valid disconnect command, then reconnecting, which prevents a mod from being notified of changes in the client state. NOTE: the impact of this issue will vary depending on which mod is being used.
Trend Micro ServerProtect 5.58, and possibly In
ServerProtect
|
Micro
|
Trend
|
Trend Micro ServerProtect 5.58, and possibly InterScan Messaging Security Suite and InterScan Web Security Suite, have a default configuration setting of "Do not scan compressed files when Extracted file count exceeds 500 files," which may be too low in certain circumstances, which allows remote attackers to bypass anti-virus checks by sending compressed archives containing many small files. NOTE: since this is related to a configuration setting that has an operational impact that might vary depending on the environment, and the product is claimed to report a message when the compressed file exceeds specified limits, perhaps this should not be included in CVE.
The CAPTCHA functionality in php-Nuke 6.0 throu
challenge/response
|
functionality
|
php-Nuke
|
through
|
CAPTCHA
|
based
|
Agent
|
pairs
|
fixed
|
uses
|
User
|
only
|
vary
|
once
|
per
|
day
|
The CAPTCHA functionality in php-Nuke 6.0 through 7.9 uses fixed challenge/response pairs that only vary once per day based on the User Agent (HTTP_USER_AGENT), which allows remote attackers to bypass CAPTCHA controls by fixing the User Agent, performing a valid challenge/response, then replaying that pair in the random_num and gfx_check parameters.
Ultimate PHP Board (UPB) 1.9.6 and earlier allo
Ultimate
|
Board
|
PHP
|
Ultimate PHP Board (UPB) 1.9.6 and earlier allows remote attackers to gain access via modified user_env, pass_env, power_env, and id_env parameters in a cookie, which comprise a persistent logon that does not vary across sessions.
Software vulnerabilities results 1 to 5 of 5
Page:
1