PHP 4
PHP 5
WordPress MultiUser 1.0
ActiveKB 1.5
Joomla! <= 1.0.13
ActiveKB NX 2.5.4
Nucleus 3.01
Stride v1.0 Content Management System
Merchant
Courses
MyFTPUploader
Site-Up <= 2.64
Google Search Appliance
PRO-search 0.17.1
Urchin Web Analytics 5.7.03
Mozilla Firefox <= 2.0
Drupal <= 5.2
TikiWiki 1.9.8
English
Advisory Content :
Dear bugtraq (at) securityfocus (dot) com [email concealed],
Vulnerabilities reported by different Russian speaking authors to
http://securityvulns.ru
1. Elekt(Antichat.ru) reports protection bypass vulnerability in PHP 4
and 5.
disable_functions feature can be bypassed by using functions alias. A
list of aliases is given in http://php.net/aliases/. For example,
ini_alter() may be used instead of ini_set() and vice versa.
SecurityVulns issue: http://securityvulns.com/news/PHP/alias-pb.html
Original message (in Russian): http://securityvulns.ru/Sdocument67.html
2. MustLive reports Crossite-Cripting vulnerability in WordPress
MultiUser 1.0
XSS is possible via Username form field.
Additional information (in Ukranian): http://websecurity.com.ua/1269/
Original message (in Russian): http://securityvulns.ru/Rdocument875.html
Additional information (in Ukranian): http://websecurity.com.ua/1224/
Original message (in Russian): http://securityvulns.ru/Sdocument68.html
10. MustLive reports multiple vulnerabilities in Urchin Web Analytics
5.7.03.
In addition to re-discovered XSS vulnerability, there is also
authentication bypass (access without username/password).
Additional information (in Ukranian): http://websecurity.com.ua/1283/
Original message: (in Russian): http://securityvulns.ru/Sdocument90.html
11. MustLive reports crossite scripting vulnerability in Mozilla Firefox
<= 2.0 with gopher: protocol URL if UTF-7 if page content is displayed
as
UTF-7. Examples:
Also, multiple vulnerabilities were reported in English by
:: iNs @ uNkn0wn.eu :: http://securityvulns.com/source26994.html
and
r0t: http://securityvulns.com/source12948.html
--
http://securityvulns.com/
/_/ { , . } |+--oQQo->{ ^ }<-----+ | ZARAZA U 3APA3A
} You know my name - look up my number (The Beatles)
+-------------o66o--+ /
|/
Feedback :
If you have additional information or notice any errors regarding this security advisory, please use contact form or email us at info()securityreason()com.