Packet Storm new exploits for September, 2000.
d6a5a00fc7eba2e587d4ba194f32a06fThe CSM proxy server's siteblocker feature can be bypassed by setting up your web browser to use an external proxy.
0a7ad2c061a8fb7df08d92978e52e4f9Delphis Consulting Plc Security Team Advisory DST2K0035 - CyberOffice Shopping Cart v2 under Windows NT allows remote users to gain access to the main database by default.
0598cfba81570725c565076d84c93d54Ezbounce version (0.85.2 and probably others) remote overflow exploit for RedHat 6.0.
2782b93ed5b29bce6d752df87c0f3297Netscape Navigator is vulnerable to trivial, remote buffer overflow attack when viewing prepared html.
17e325f95cdbca4a1931a1d7ca8489bbThe Siemens HiNet LP 5100 IP-phone is vulnerable to a buffer overflow when the GET request method is used with a large request size. Vulnerability can lead to a partial or complete crash of phone services.
5058db51ef389d9daeb965195e6703bcDelphis Consulting Plc Security Team Advisory DST2K0042 - The following vulnerability in Web+ Application Server under Linux has been discovered. Severity: High. If the default example scripts are installed it is possible to execute/read any file which Web+ user (default is 'nobody') has access to using the Web+Ping example.
b91b26b4ff2de318a49b001c95acdcb7Delphis Consulting Plc Security Team Advisory DST2K0037 - It is possible to bypass the quotas imposed by QuotaAdvisor by utilizing data streams alternative to the default.
6139ef84ad6cd2adca0d9b2251ae1b28DST2K0032: Multiple Issues with Talentsoft WebPlus Application Server. Delphis Consulting Internet Security Team (DCIST) discovered low to medium severity vulnerabilities in Webplus under Windows NT.
90834434a0526c8f0381367efe6e9b9dINND/NNRP remote root overflow. Overflow occurs in the From: field. Affects INND/NNRP versions prior to 1.6.X. Author Unknown.
58a7da31969ed2ec7966ac2b353c6243Remote root overflow for linux rpc.statd SM_UNMON_ALL vulnerability. Author Unknown.
199996adc4198d935536377be0884413GDM Remote Exploit based on the original bug found by Chris Evans. Vulnerable version : gdm-2.0beta2-23 ( gnome and single version ). Not Vulnerable : 1.0.0.35. Vulnerable Platforms : RedHat 6.0-6.2.
6777692e74bd59054de06020eca0a929FlagShip (from Red Hat Application CD) is a Database Development System for xBase based applications on nearly all Unix brands. Problem: /usr/bin/FSserial is world-writeable! We can replace it with an trojan and trick root to execute it. OS affected: Red Hat 6.0.
9dbab3a13fc9e2daa36bb639377573a1Q-POP 2.53 Remote Overflow.
0222942a6e5d4605ff1d691486cb0fbbSco 5.0.4 local overflow using xload.
42ad86ee0fce11262db472eb19131fd5Remote root exploit for wu-ftpd on SCO unix. Based on: ADMwuftpd.c from duke.
71ccbbc38cdeae5baa54a127527a2cceLinux wu-ftpd - 2.6.0(1) (tested on RH6.2 wu from rpm).
9d061022e9c73fd147f2ff351a180997Msql local overflow. Author Unknown.
136e9df161229757309e52ac7516d1ddSolaris 7 Xsun(suid) local overflow - Solaris 2.7/(2.6?) x86 sploit no sparc code.
86bd74bf45b0f314cfbfec8c7e27cb4cScounix httpd Remote Exploit.
fdcecbb8d514a282fbf75df0452872a1QPOP 3.0beta AUTH remote root stack overflow (linux x86 version)
fd61b6224c6b0456578d397c4ee83181Local exploit for cxterm 5.1-p1. Tested on: RedHat 5.2/6.0, Slackware 3.6.
decdc24a3350940eac9605e9cc64f283IMAPrev1 12.2xx exploit (lsub bug). Slackware 4.0 remote overflow.
c8698088a10ed8c23dfaad3ec71b4247WinShellCode. win32 portbinding shellcode.
4122658ca195af797f13c7c988a1a80fDenial of service for NetcPlus BrowseGate 2.80 for Windows NT and 2000 when you sned more than 8000 characters in a GET / http-request, causing the system to crash.
a2100c2a0c80d3fcea1fabfd6045a871