<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0">
<!-- $Id: WebpageGenerator.java 140 2008-09-12 10:39:59Z hc $ -->
<channel>
<title>Advisories</title>
<link>http://ctf.hcesperer.org/gameserver/</link>
<description>CTF advisories</description>
<language>en</language>
<item>
  <title>foo (rl)</title>
  <description>New advisory by : hc&lt;br /&gt;Affected service(s): foo&lt;br /&gt;Severity [lmh] : rl&lt;br /&gt;&lt;br /&gt;===== Problem =====&lt;br /&gt;viel stress hier&lt;br /&gt;&lt;br /&gt;===== Impact =====&lt;br /&gt;foo&lt;br /&gt;&lt;br /&gt;===== Fix =====&lt;br /&gt;bla&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;</description>
  <link>http://130.83.160.197/score/adv/a_1.html</link>
  <guid>http://130.83.160.197/score/adv/a_1.html</guid>
</item><item>
  <title>zweites (foo)</title>
  <description>New advisory by : hc&lt;br /&gt;Affected service(s): zweites&lt;br /&gt;Severity [lmh] : foo&lt;br /&gt;&lt;br /&gt;===== Problem =====&lt;br /&gt;bar&lt;br /&gt;&lt;br /&gt;===== Impact =====&lt;br /&gt;&lt;br /&gt;===== Fix =====&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;</description>
  <link>http://130.83.160.197/score/adv/a_2.html</link>
  <guid>http://130.83.160.197/score/adv/a_2.html</guid>
</item><item>
  <title>noch ein advi (sory, high)</title>
  <description>New advisory by : hc&lt;br /&gt;Affected service(s): noch ein advi&lt;br /&gt;Severity [lmh] : sory, high&lt;br /&gt;&lt;br /&gt;===== Problem =====&lt;br /&gt;hallo welt&lt;br /&gt;foo&lt;br /&gt;&lt;br /&gt;===== Impact =====&lt;br /&gt;bar&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;===== Fix =====&lt;br /&gt;a.b.c.d&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;</description>
  <link>http://130.83.160.197/score/adv/a_3.html</link>
  <guid>http://130.83.160.197/score/adv/a_3.html</guid>
</item><item>
  <title> (low)</title>
  <description>New advisory by : ailurotest&lt;br /&gt;Affected service(s): &lt;br /&gt;Severity [lmh] : low&lt;br /&gt;&lt;br /&gt;===== Problem =====&lt;br /&gt;Test problem&lt;br /&gt;&lt;br /&gt;===== Impact =====&lt;br /&gt;Kills internets&lt;br /&gt;&lt;br /&gt;===== Fix =====&lt;br /&gt;Pending.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;</description>
  <link>http://130.83.160.197/score/adv/a_4.html</link>
  <guid>http://130.83.160.197/score/adv/a_4.html</guid>
</item><item>
  <title>testing123 (low)</title>
  <description>New advisory by : ailurotest&lt;br /&gt;Affected service(s): testing123&lt;br /&gt;Severity [lmh] : low&lt;br /&gt;&lt;br /&gt;===== Problem =====&lt;br /&gt;test&lt;br /&gt;&lt;br /&gt;===== Impact =====&lt;br /&gt;test&lt;br /&gt;&lt;br /&gt;===== Fix =====&lt;br /&gt;test&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;</description>
  <link>http://130.83.160.197/score/adv/a_5.html</link>
  <guid>http://130.83.160.197/score/adv/a_5.html</guid>
</item><item>
  <title>cgibass (high)</title>
  <description>New advisory by : slashd&lt;br /&gt;Affected service(s): cgibass&lt;br /&gt;Severity [lmh] : high&lt;br /&gt;&lt;br /&gt;===== Problem =====&lt;br /&gt;The confenicial information lise in free access&lt;br /&gt;===== Impact =====&lt;br /&gt;http://10.23.1.3/cgi/index.bas?inc=download.bas&amp;amp;amp;gimme=91cc2eb9&lt;br /&gt;&lt;br /&gt;s&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;</description>
  <link>http://130.83.160.197/score/adv/a_6.html</link>
  <guid>http://130.83.160.197/score/adv/a_6.html</guid>
</item><item>
  <title>ultrashare (high)</title>
  <description>New advisory by : churchy&lt;br /&gt;Affected service(s): ultrashare&lt;br /&gt;Severity [lmh] : high&lt;br /&gt;&lt;br /&gt;Hello ladies and gentlemen from all over the world,&lt;br /&gt;&lt;br /&gt;===== Problem =====&lt;br /&gt;The ultrashare service allows user to share (upload and download) files. The service is implemented in...</description>
  <link>http://130.83.160.197/score/adv/a_7.html</link>
  <guid>http://130.83.160.197/score/adv/a_7.html</guid>
</item><item>
  <title>cgibas (medium)</title>
  <description>New advisory by : slashd&lt;br /&gt;Affected service(s): cgibas&lt;br /&gt;Severity [lmh] : medium&lt;br /&gt;&lt;br /&gt;===== Problem =====&lt;br /&gt;Directory cgi/ readible &lt;br /&gt;===== Impact =====&lt;br /&gt;&lt;br /&gt;===== Fix =====&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;</description>
  <link>http://130.83.160.197/score/adv/a_8.html</link>
  <guid>http://130.83.160.197/score/adv/a_8.html</guid>
</item><item>
  <title>VDspi (high)</title>
  <description>New advisory by : fid&lt;br /&gt;Affected service(s): VDspi&lt;br /&gt;Severity [lmh] : high&lt;br /&gt;&lt;br /&gt;===== Problem =====&lt;br /&gt;Flags a saved as comment in a record and can read out without authentification by everyone&lt;br /&gt;&lt;br /&gt;===== Impact =====&lt;br /&gt;&lt;br /&gt;===== Fix =====&lt;br /&gt;&lt;br /&gt;restrict the access with username a...</description>
  <link>http://130.83.160.197/score/adv/a_9.html</link>
  <guid>http://130.83.160.197/score/adv/a_9.html</guid>
</item><item>
  <title>cgibas (medium)</title>
  <description>New advisory by : slashd&lt;br /&gt;Affected service(s): cgibas&lt;br /&gt;Severity [lmh] : medium&lt;br /&gt;&lt;br /&gt;===== Problem =====&lt;br /&gt;XSS attack&lt;br /&gt;===== Impact =====&lt;br /&gt;http://10.23.1.3/cgi/search.bas?inc=search.bas&amp;amp;amp;term=%27%3E%3Cscript%3Ealert(%27xxs%27)%3C/script%3E&lt;br /&gt;&lt;br /&gt;===== Fix =====&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;</description>
  <link>http://130.83.160.197/score/adv/a_10.html</link>
  <guid>http://130.83.160.197/score/adv/a_10.html</guid>
</item><item>
  <title>cgibas (medium)</title>
  <description>New advisory by : slashd&lt;br /&gt;Affected service(s): cgibas&lt;br /&gt;Severity [lmh] : medium&lt;br /&gt;&lt;br /&gt;===== Problem =====&lt;br /&gt;XSS bug&lt;br /&gt;===== Impact =====&lt;br /&gt;http://10.23.1.3/cgi/index.bas?inc=search.bas&amp;amp;amp;term=%3Cscript%3Ealert(%27xss%27)%3C%2Fscript%3E&lt;br /&gt;===== Fix =====&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;</description>
  <link>http://130.83.160.197/score/adv/a_11.html</link>
  <guid>http://130.83.160.197/score/adv/a_11.html</guid>
</item><item>
  <title>ICANHASGOFERDEE (high)</title>
  <description>New advisory by : ailurotest&lt;br /&gt;Affected service(s): ICANHASGOFERDEE&lt;br /&gt;Severity [lmh] : high&lt;br /&gt;&lt;br /&gt;===== Problem =====&lt;br /&gt;The service runs a daemon written in lolcode&lt;br /&gt;without performing proper input sanitizing.&lt;br /&gt;FLAGSTORE command allows to execute commands in the server...</description>
  <link>http://130.83.160.197/score/adv/a_12.html</link>
  <guid>http://130.83.160.197/score/adv/a_12.html</guid>
</item><item>
  <title>lighttpd/web2.0 (low)</title>
  <description>New advisory by : lwi&lt;br /&gt;Affected service(s): lighttpd/web2.0&lt;br /&gt;Severity [lmh] : low&lt;br /&gt;&lt;br /&gt;===== Problem =====&lt;br /&gt;Directory traversal vuln&lt;br /&gt;http://10.65.1.3/cgi/index.bas?inc=download.bas&amp;amp;amp;gimme=../../../../var/www/foo&lt;br /&gt;&lt;br /&gt;===== Impact =====&lt;br /&gt;We can read every file reada...</description>
  <link>http://130.83.160.197/score/adv/a_13.html</link>
  <guid>http://130.83.160.197/score/adv/a_13.html</guid>
</item><item>
  <title>cgibas (high)</title>
  <description>New advisory by : slashd&lt;br /&gt;Affected service(s): cgibas&lt;br /&gt;Severity [lmh] : high&lt;br /&gt;&lt;br /&gt;===== Problem =====&lt;br /&gt;Read file on filesystem&lt;br /&gt;===== Impact =====&lt;br /&gt;Create the post &lt;br /&gt;http://10.23.1.3/cgi/index.bas?inc=upload.bas&lt;br /&gt;input in &amp;amp;quot;Caption&amp;amp;quot; &amp;amp;quot;../../../../../../e...</description>
  <link>http://130.83.160.197/score/adv/a_14.html</link>
  <guid>http://130.83.160.197/score/adv/a_14.html</guid>
</item><item>
  <title>vdspi (low)</title>
  <description>New advisory by : thorben&lt;br /&gt;Affected service(s): vdspi&lt;br /&gt;Severity [lmh] : low&lt;br /&gt;&lt;br /&gt;===== Problem =====&lt;br /&gt;vdspi has loginshell&lt;br /&gt;===== Impact =====&lt;br /&gt;daemons should not have login shells&lt;br /&gt;===== Fix =====&lt;br /&gt;edit /etc/passwd and change loginshell of vdspi from /bin/sh to /bin...</description>
  <link>http://130.83.160.197/score/adv/a_15.html</link>
  <guid>http://130.83.160.197/score/adv/a_15.html</guid>
</item><item>
  <title>goffer (low)</title>
  <description>New advisory by : thorben&lt;br /&gt;Affected service(s): goffer&lt;br /&gt;Severity [lmh] : low&lt;br /&gt;&lt;br /&gt;===== Problem =====&lt;br /&gt;goffer has loginshell&lt;br /&gt;===== Impact =====&lt;br /&gt;daemons should not have login shells&lt;br /&gt;===== Fix =====&lt;br /&gt;edit /etc/passwd and change loginshell of goffer from /bin/sh to /...</description>
  <link>http://130.83.160.197/score/adv/a_16.html</link>
  <guid>http://130.83.160.197/score/adv/a_16.html</guid>
</item><item>
  <title>cgibas (high)</title>
  <description>New advisory by : Samsa&lt;br /&gt;Affected service(s): cgibas&lt;br /&gt;Severity [lmh] : high&lt;br /&gt;&lt;br /&gt;===== Problem =====&lt;br /&gt;The 'inc' variable is not sanatized in index.bas before being used to include a file. This allows an attacker to include any arbritrary file on the system leadin...</description>
  <link>http://130.83.160.197/score/adv/a_17.html</link>
  <guid>http://130.83.160.197/score/adv/a_17.html</guid>
</item><item>
  <title>CGIBASS (high)</title>
  <description>New advisory by : anonymous coward&lt;br /&gt;Affected service(s): CGIBASS&lt;br /&gt;Severity [lmh] : high&lt;br /&gt;&lt;br /&gt;===== Problem =====&lt;br /&gt;Directory /var/www/cgi is readable&lt;br /&gt;&lt;br /&gt;===== Impact =====&lt;br /&gt;&lt;br /&gt;===== Fix =====&lt;br /&gt;.htaccess in /var/www/cgi mit &amp;amp;quot;Options -Indexes&amp;amp;quot;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;</description>
  <link>http://130.83.160.197/score/adv/a_18.html</link>
  <guid>http://130.83.160.197/score/adv/a_18.html</guid>
</item><item>
  <title>vdspi (medium)</title>
  <description>New advisory by : cjay&lt;br /&gt;Affected service(s): vdspi&lt;br /&gt;Severity [lmh] : medium&lt;br /&gt;&lt;br /&gt;===== Problem =====&lt;br /&gt;vdspi is started as root via daemon tools&lt;br /&gt;===== Impact =====&lt;br /&gt;unnecessary risk&lt;br /&gt;===== Fix =====&lt;br /&gt;change the last line of /etc/vdspi/run to:&lt;br /&gt;cd /usr/vdspi &amp;amp;amp;&amp;amp;amp;...</description>
  <link>http://130.83.160.197/score/adv/a_19.html</link>
  <guid>http://130.83.160.197/score/adv/a_19.html</guid>
</item><item>
  <title>cgibas (medium)</title>
  <description>New advisory by : lamer&lt;br /&gt;Affected service(s): cgibas&lt;br /&gt;Severity [lmh] : medium&lt;br /&gt;&lt;br /&gt;===== Problem =====&lt;br /&gt;download.bas lists all files in /var/data/cgibas&lt;br /&gt;===== Impact =====&lt;br /&gt;can download all files under /var/data/cgibas&lt;br /&gt;===== Fix =====&lt;br /&gt;remove line 121, open dir...&lt;br /&gt;...</description>
  <link>http://130.83.160.197/score/adv/a_20.html</link>
  <guid>http://130.83.160.197/score/adv/a_20.html</guid>
</item><item>
  <title>cgibas (high)</title>
  <description>New advisory by : Samsa&lt;br /&gt;Affected service(s): cgibas&lt;br /&gt;Severity [lmh] : high&lt;br /&gt;&lt;br /&gt;===== Problem =====&lt;br /&gt;The 'inc' variable is not sanatized in index.bas before being used to include a file. This allows an attacker to include any arbritrary file on the system leadin...</description>
  <link>http://130.83.160.197/score/adv/a_21.html</link>
  <guid>http://130.83.160.197/score/adv/a_21.html</guid>
</item><item>
  <title>/etc/passwd (low)</title>
  <description>New advisory by : thorben&lt;br /&gt;Affected service(s): /etc/passwd&lt;br /&gt;Severity [lmh] : low&lt;br /&gt;&lt;br /&gt;===== Problem =====&lt;br /&gt;loginshells for non-physical users (i.e. services/daemons) in /etc/passwd set to /bin/sh&lt;br /&gt;===== Impact =====&lt;br /&gt;potentially vulnerable services/daemons could a...</description>
  <link>http://130.83.160.197/score/adv/a_22.html</link>
  <guid>http://130.83.160.197/score/adv/a_22.html</guid>
</item><item>
  <title>CGIBAS (high)</title>
  <description>New advisory by : manager&lt;br /&gt;Affected service(s): CGIBAS&lt;br /&gt;Severity [lmh] : high&lt;br /&gt;&lt;br /&gt;===== Problem =====&lt;br /&gt;Download.bas lists files that contain the flags&lt;br /&gt;&lt;br /&gt;===== Impact =====&lt;br /&gt;highly critical&lt;br /&gt;&lt;br /&gt;===== Fix =====&lt;br /&gt;fix upload.bas to not write the caption into dir-listing&lt;br /&gt;1...</description>
  <link>http://130.83.160.197/score/adv/a_23.html</link>
  <guid>http://130.83.160.197/score/adv/a_23.html</guid>
</item><item>
  <title>system (medium)</title>
  <description>New advisory by : fid&lt;br /&gt;Affected service(s): system&lt;br /&gt;Severity [lmh] : medium&lt;br /&gt;&lt;br /&gt;===== Problem =====&lt;br /&gt;weak passwords from users goopher and vdspi found pretty fast with john&lt;br /&gt;===== Impact =====&lt;br /&gt;other users can log in remotely&lt;br /&gt;===== Fix =====&lt;br /&gt;change passwords&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;</description>
  <link>http://130.83.160.197/score/adv/a_24.html</link>
  <guid>http://130.83.160.197/score/adv/a_24.html</guid>
</item><item>
  <title>cgibas (medium)</title>
  <description>New advisory by : Samsa&lt;br /&gt;Affected service(s): cgibas&lt;br /&gt;Severity [lmh] : medium&lt;br /&gt;&lt;br /&gt;===== Problem =====&lt;br /&gt;We can access the source code of the files stored on /cgi/ using the port 81 as the configuration allows it.&lt;br /&gt;&lt;br /&gt;For instance :&lt;br /&gt;&lt;br /&gt;http://192.168.2.33:81/cgi/index....</description>
  <link>http://130.83.160.197/score/adv/a_25.html</link>
  <guid>http://130.83.160.197/score/adv/a_25.html</guid>
</item><item>
  <title>ICANHASGOFERDEE (medium)</title>
  <description>New advisory by : ailurotest&lt;br /&gt;Affected service(s): ICANHASGOFERDEE&lt;br /&gt;Severity [lmh] : medium&lt;br /&gt;&lt;br /&gt;===== Problem =====&lt;br /&gt;The service runs a daemon written in lolcode&lt;br /&gt;without performing proper input sanitizing.&lt;br /&gt;FLAGSTORE command allows to execute commands in the serv...</description>
  <link>http://130.83.160.197/score/adv/a_26.html</link>
  <guid>http://130.83.160.197/score/adv/a_26.html</guid>
</item><item>
  <title>cgibas (high)</title>
  <description>New advisory by : lamer&lt;br /&gt;Affected service(s): cgibas&lt;br /&gt;Severity [lmh] : high&lt;br /&gt;&lt;br /&gt;===== Problem =====&lt;br /&gt;upload.bas allows write to any file with directory traversal (..)&lt;br /&gt;===== Impact =====&lt;br /&gt;write to any file&lt;br /&gt;===== Fix =====&lt;br /&gt;500 let idx=index$(caption,&amp;amp;quot;..&amp;amp;quot;)...</description>
  <link>http://130.83.160.197/score/adv/a_27.html</link>
  <guid>http://130.83.160.197/score/adv/a_27.html</guid>
</item><item>
  <title>vdspi (high)</title>
  <description>New advisory by : Ge0rG&lt;br /&gt;Affected service(s): vdspi&lt;br /&gt;Severity [lmh] : high&lt;br /&gt;&lt;br /&gt;===== Problem =====&lt;br /&gt;In ui-debug_menu.adb, there is a root shell accessible via menu 9 -&amp;amp;gt; 5,&lt;br /&gt;&amp;amp;quot;maintainance shell&amp;amp;quot; menu.  it allows full access to the system.&lt;br /&gt;&lt;br /&gt;===== Impac...</description>
  <link>http://130.83.160.197/score/adv/a_28.html</link>
  <guid>http://130.83.160.197/score/adv/a_28.html</guid>
</item><item>
  <title>vdspi (high)</title>
  <description>New advisory by : Ge0rG&lt;br /&gt;Affected service(s): vdspi&lt;br /&gt;Severity [lmh] : high&lt;br /&gt;&lt;br /&gt;===== Problem =====&lt;br /&gt;By sending an ASCII BEL character, a root shell is spawned.&lt;br /&gt;&lt;br /&gt;===== Impact =====&lt;br /&gt;A complete system compromise is possible, including reading flags.&lt;br /&gt;&lt;br /&gt;===== Fix ====...</description>
  <link>http://130.83.160.197/score/adv/a_29.html</link>
  <guid>http://130.83.160.197/score/adv/a_29.html</guid>
</item><item>
  <title>vdspi (low)</title>
  <description>New advisory by : lamer&lt;br /&gt;Affected service(s): vdspi&lt;br /&gt;Severity [lmh] : low&lt;br /&gt;&lt;br /&gt;===== Problem =====&lt;br /&gt;VDSPI does not release db file lock when error occurs&lt;br /&gt;===== Impact =====&lt;br /&gt;DoS&lt;br /&gt;===== Fix =====&lt;br /&gt;don't know enough ADA to fix, and there are too many places to fix&lt;br /&gt;&lt;br /&gt;</description>
  <link>http://130.83.160.197/score/adv/a_30.html</link>
  <guid>http://130.83.160.197/score/adv/a_30.html</guid>
</item><item>
  <title>vdspi (high)</title>
  <description>New advisory by : het&lt;br /&gt;Affected service(s): vdspi&lt;br /&gt;Severity [lmh] : high&lt;br /&gt;&lt;br /&gt;===== Problem =====&lt;br /&gt;string length is not checked&lt;br /&gt;&lt;br /&gt;for example :   &lt;br /&gt;     first, last, comment : String (1..1024);&lt;br /&gt;then&lt;br /&gt;     Ada.Text_IO.Get_Line (last, nl);&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;===== Impact =====&lt;br /&gt;pussibl...</description>
  <link>http://130.83.160.197/score/adv/a_31.html</link>
  <guid>http://130.83.160.197/score/adv/a_31.html</guid>
</item><item>
  <title>vdspi (low)</title>
  <description>New advisory by : lamer&lt;br /&gt;Affected service(s): vdspi&lt;br /&gt;Severity [lmh] : low&lt;br /&gt;&lt;br /&gt;===== Problem =====&lt;br /&gt;vdspi does search for name only checks __lengths__, not contents&lt;br /&gt;===== Impact =====&lt;br /&gt;search all db records&lt;br /&gt;===== Fix =====&lt;br /&gt;don't know enough ADA to fix&lt;br /&gt;&lt;br /&gt;</description>
  <link>http://130.83.160.197/score/adv/a_32.html</link>
  <guid>http://130.83.160.197/score/adv/a_32.html</guid>
</item><item>
  <title>gopherdee (high)</title>
  <description>New advisory by : lamer&lt;br /&gt;Affected service(s): gopherdee&lt;br /&gt;Severity [lmh] : high&lt;br /&gt;&lt;br /&gt;===== Problem =====&lt;br /&gt;Directory traversal&lt;br /&gt;===== Impact =====&lt;br /&gt;Can read /etc/passwd&lt;br /&gt;===== Fix =====&lt;br /&gt;No clue, LOL&lt;br /&gt;&lt;br /&gt;</description>
  <link>http://130.83.160.197/score/adv/a_33.html</link>
  <guid>http://130.83.160.197/score/adv/a_33.html</guid>
</item><item>
  <title>cgibass (high)</title>
  <description>New advisory by : slashd&lt;br /&gt;Affected service(s): cgibass&lt;br /&gt;Severity [lmh] : high&lt;br /&gt;&lt;br /&gt;===== Problem =====&lt;br /&gt;The confidencial information lise in free access&lt;br /&gt;=====  Impact =====&lt;br /&gt;http://10.23.1.3/cgi/index.bas?inc=download.bas&amp;amp;amp;gimme=91cc2eb9&lt;br /&gt;===== Fix =====&lt;br /&gt;add .ht...</description>
  <link>http://130.83.160.197/score/adv/a_34.html</link>
  <guid>http://130.83.160.197/score/adv/a_34.html</guid>
</item><item>
  <title>LeetWWW (low)</title>
  <description>New advisory by : Ge0rG&lt;br /&gt;Affected service(s): LeetWWW&lt;br /&gt;Severity [lmh] : low&lt;br /&gt;&lt;br /&gt;===== Problem =====&lt;br /&gt;&lt;br /&gt;The RFC does not specify on what port the service has to be run.&lt;br /&gt;&lt;br /&gt;===== Impact =====&lt;br /&gt;&lt;br /&gt;Different implementations have a chance of 1:65535 to actually match ports...</description>
  <link>http://130.83.160.197/score/adv/a_35.html</link>
  <guid>http://130.83.160.197/score/adv/a_35.html</guid>
</item><item>
  <title>vdspi (high)</title>
  <description>New advisory by : thaidn&lt;br /&gt;Affected service(s): vdspi&lt;br /&gt;Severity [lmh] : high&lt;br /&gt;&lt;br /&gt;===== Problem =====&lt;br /&gt;By entering 5 in DEBUG menu, a root shell is spawned.&lt;br /&gt;&lt;br /&gt;===== Impact =====&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;do anything to the host&lt;br /&gt;&lt;br /&gt;===== Fix =====&lt;br /&gt;The shell access can be disabled by removing...</description>
  <link>http://130.83.160.197/score/adv/a_36.html</link>
  <guid>http://130.83.160.197/score/adv/a_36.html</guid>
</item><item>
  <title>vdspi (low)</title>
  <description>New advisory by : Ge0rG&lt;br /&gt;Affected service(s): vdspi&lt;br /&gt;Severity [lmh] : low&lt;br /&gt;&lt;br /&gt;===== Problem =====&lt;br /&gt;&lt;br /&gt;Certain IDs can crash the service, causing a DoS.&lt;br /&gt;&lt;br /&gt;The following calculation in persondb.adb causes the Log() function to&lt;br /&gt;terminate the application:&lt;br /&gt;&lt;br /&gt;&amp;amp;quot;n : ID...</description>
  <link>http://130.83.160.197/score/adv/a_37.html</link>
  <guid>http://130.83.160.197/score/adv/a_37.html</guid>
</item><item>
  <title>cgbas (medium)</title>
  <description>New advisory by : slashd&lt;br /&gt;Affected service(s): cgbas&lt;br /&gt;Severity [lmh] : medium&lt;br /&gt;&lt;br /&gt;===== Problem =====&lt;br /&gt;We can access the source code of the files stored on /cgi/ on port 81 as the configuration allows it.&lt;br /&gt;&lt;br /&gt;===== Impact =====&lt;br /&gt;Source code disclosure of the cgi dir...</description>
  <link>http://130.83.160.197/score/adv/a_38.html</link>
  <guid>http://130.83.160.197/score/adv/a_38.html</guid>
</item><item>
  <title>unknown/several (high)</title>
  <description>New advisory by : anonymous coward&lt;br /&gt;Affected service(s): unknown/several&lt;br /&gt;Severity [lmh] : high&lt;br /&gt;&lt;br /&gt;===== Problem =====&lt;br /&gt;A botnet is running with bots connecting per the IRC protocol to 10.5.1.99 on port 24051. This botnet is probably operated by h4ck!nb3rg. The...</description>
  <link>http://130.83.160.197/score/adv/a_39.html</link>
  <guid>http://130.83.160.197/score/adv/a_39.html</guid>
</item><item>
  <title>cgibas (medium)</title>
  <description>New advisory by : Silicium&lt;br /&gt;Affected service(s): cgibas&lt;br /&gt;Severity [lmh] : medium&lt;br /&gt;&lt;br /&gt;===== Problem =====&lt;br /&gt;The upload.bas allows to xss javascript.&lt;br /&gt;&lt;br /&gt;===== Impact =====&lt;br /&gt;Run Scrips on Client Systems, Steal Cookies...&lt;br /&gt;&lt;br /&gt;===== Fix =====&lt;br /&gt;&lt;br /&gt;Filter some html taggins with ...</description>
  <link>http://130.83.160.197/score/adv/a_40.html</link>
  <guid>http://130.83.160.197/score/adv/a_40.html</guid>
</item><item>
  <title>cgibas (medium)</title>
  <description>New advisory by : watz&lt;br /&gt;Affected service(s): cgibas&lt;br /&gt;Severity [lmh] : medium&lt;br /&gt;&lt;br /&gt;===== Problem =====&lt;br /&gt;&lt;br /&gt;Lighttpd allows read of .htaccess or .htpasswd files&lt;br /&gt;&lt;br /&gt;===== Impact =====&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;===== Fix =====&lt;br /&gt;&lt;br /&gt;Add something like url.access-deny = ( &amp;amp;quot;.htaccess&amp;amp;quot;, &amp;amp;quo...</description>
  <link>http://130.83.160.197/score/adv/a_41.html</link>
  <guid>http://130.83.160.197/score/adv/a_41.html</guid>
</item><item>
  <title>ultrashare (medium)</title>
  <description>New advisory by : churchy&lt;br /&gt;Affected service(s): ultrashare&lt;br /&gt;Severity [lmh] : medium&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Hello again fellow hackers and those who (like we) desperately try to get some services running,&lt;br /&gt;&lt;br /&gt;===== Problem =====&lt;br /&gt;The application ultrashare allows users to up and down...</description>
  <link>http://130.83.160.197/score/adv/a_42.html</link>
  <guid>http://130.83.160.197/score/adv/a_42.html</guid>
</item><item>
  <title>cgibas (medium/high)</title>
  <description>New advisory by : Samsa&lt;br /&gt;Affected service(s): cgibas&lt;br /&gt;Severity [lmh] : medium/high&lt;br /&gt;&lt;br /&gt;===== Problem =====&lt;br /&gt;Search functionality can be abused to retrieve confidential data.&lt;br /&gt;The search functionality uses wild cards and its content structure is know to be hexadec...</description>
  <link>http://130.83.160.197/score/adv/a_43.html</link>
  <guid>http://130.83.160.197/score/adv/a_43.html</guid>
</item><item>
  <title>vdspi (medium)</title>
  <description>New advisory by : lamer&lt;br /&gt;Affected service(s): vdspi&lt;br /&gt;Severity [lmh] : medium&lt;br /&gt;&lt;br /&gt;===== Problem =====&lt;br /&gt;Exploit to get flag.&lt;br /&gt;1\n&lt;br /&gt;2\n&lt;br /&gt;\n&lt;br /&gt;\n&lt;br /&gt;===== Impact =====&lt;br /&gt;Get all flags&lt;br /&gt;===== Fix =====&lt;br /&gt;Don't know how.&lt;br /&gt;&lt;br /&gt;</description>
  <link>http://130.83.160.197/score/adv/a_44.html</link>
  <guid>http://130.83.160.197/score/adv/a_44.html</guid>
</item><item>
  <title>cgibas (low)</title>
  <description>New advisory by : Ge0rG&lt;br /&gt;Affected service(s): cgibas&lt;br /&gt;Severity [lmh] : low&lt;br /&gt;&lt;br /&gt;===== Problem =====&lt;br /&gt;&lt;br /&gt;The directory traversal mentioned in #14 and #27 allows writing to the FS.&lt;br /&gt;&lt;br /&gt;===== Impact =====&lt;br /&gt;&lt;br /&gt;Writing to any file accessible by the daemon&lt;br /&gt;&lt;br /&gt;===== Fix =====&lt;br /&gt;&lt;br /&gt;Th...</description>
  <link>http://130.83.160.197/score/adv/a_45.html</link>
  <guid>http://130.83.160.197/score/adv/a_45.html</guid>
</item><item>
  <title>ultrashare (medium)</title>
  <description>New advisory by : js&lt;br /&gt;Affected service(s): ultrashare&lt;br /&gt;Severity [lmh] : medium&lt;br /&gt;&lt;br /&gt;===== Problem =====&lt;br /&gt;In line 210 of db.rb, there is an unescaped use of the variable user.&lt;br /&gt;&lt;br /&gt;===== Impact =====&lt;br /&gt;Arbitrary SQL queries can be executed.&lt;br /&gt;&lt;br /&gt;===== Fix =====&lt;br /&gt;Change owner...</description>
  <link>http://130.83.160.197/score/adv/a_46.html</link>
  <guid>http://130.83.160.197/score/adv/a_46.html</guid>
</item><item>
  <title>vdspi (high)</title>
  <description>New advisory by : Ge0rG&lt;br /&gt;Affected service(s): vdspi&lt;br /&gt;Severity [lmh] : high&lt;br /&gt;&lt;br /&gt;===== Problem =====&lt;br /&gt;&lt;br /&gt;ID search via menu 1 -&amp;amp;gt; 3 is matching for substrings.&lt;br /&gt;&lt;br /&gt;===== Impact =====&lt;br /&gt;&lt;br /&gt;It is possible to easily enumerate from 0 to 9 to extract all entries in the&lt;br /&gt;databa...</description>
  <link>http://130.83.160.197/score/adv/a_47.html</link>
  <guid>http://130.83.160.197/score/adv/a_47.html</guid>
</item><item>
  <title>vdspi (low)</title>
  <description>New advisory by : Ge0rG&lt;br /&gt;Affected service(s): vdspi&lt;br /&gt;Severity [lmh] : low&lt;br /&gt;&lt;br /&gt;===== Problem =====&lt;br /&gt;&lt;br /&gt;Certain IDs can crash the service, causing a DoS.&lt;br /&gt;&lt;br /&gt;This is a Follow-Up for #37, providing a fix.&lt;br /&gt;&lt;br /&gt;===== Impact =====&lt;br /&gt;&lt;br /&gt;unpatched:&lt;br /&gt;&lt;br /&gt;The current session is terminate...</description>
  <link>http://130.83.160.197/score/adv/a_48.html</link>
  <guid>http://130.83.160.197/score/adv/a_48.html</guid>
</item><item>
  <title>vdspi (medium)</title>
  <description>New advisory by : thaidn&lt;br /&gt;Affected service(s): vdspi&lt;br /&gt;Severity [lmh] : medium&lt;br /&gt;&lt;br /&gt;===== Problem =====&lt;br /&gt;Exploit to get flag.&lt;br /&gt;1\n&lt;br /&gt;2\n&lt;br /&gt;\n&lt;br /&gt;\n&lt;br /&gt;&lt;br /&gt;===== Impact =====&lt;br /&gt;Get all flags&lt;br /&gt;&lt;br /&gt;===== Fix =====&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;</description>
  <link>http://130.83.160.197/score/adv/a_49.html</link>
  <guid>http://130.83.160.197/score/adv/a_49.html</guid>
</item><item>
  <title>vdspi (medium)</title>
  <description>New advisory by : thaidn&lt;br /&gt;Affected service(s): vdspi&lt;br /&gt;Severity [lmh] : medium&lt;br /&gt;&lt;br /&gt;===== Problem =====&lt;br /&gt;Exploit to get flag.&lt;br /&gt;1\n&lt;br /&gt;2\n&lt;br /&gt;\n&lt;br /&gt;\n&lt;br /&gt;&lt;br /&gt;===== Impact =====&lt;br /&gt;Get all flags&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;===== Fix =====&lt;br /&gt;file persondb.adb, line 106, change to this::&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;if first'Length &amp;amp;gt;0 an...</description>
  <link>http://130.83.160.197/score/adv/a_50.html</link>
  <guid>http://130.83.160.197/score/adv/a_50.html</guid>
</item><item>
  <title>10.131.1.2 (high)</title>
  <description>New advisory by : js&lt;br /&gt;Affected service(s): 10.131.1.2&lt;br /&gt;Severity [lmh] : high&lt;br /&gt;&lt;br /&gt;===== Problem =====&lt;br /&gt;There is a backdoor shell in /usr/vdspi/ui.adb.&lt;br /&gt;&lt;br /&gt;===== Impact =====&lt;br /&gt;Executing of arbitrary code.&lt;br /&gt;&lt;br /&gt;===== Fix =====&lt;br /&gt;Comment out line 52 and 53.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;</description>
  <link>http://130.83.160.197/score/adv/a_51.html</link>
  <guid>http://130.83.160.197/score/adv/a_51.html</guid>
</item><item>
  <title>vdspi (high)</title>
  <description>New advisory by : js&lt;br /&gt;Affected service(s): vdspi&lt;br /&gt;Severity [lmh] : high&lt;br /&gt;&lt;br /&gt;===== Problem =====&lt;br /&gt;There is a backdoor shell in /usr/vdspi/ui.adb.&lt;br /&gt;&lt;br /&gt;===== Impact =====&lt;br /&gt;Executing of arbitrary code.&lt;br /&gt;&lt;br /&gt;===== Fix =====&lt;br /&gt;Comment out line 52 and 53.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;</description>
  <link>http://130.83.160.197/score/adv/a_52.html</link>
  <guid>http://130.83.160.197/score/adv/a_52.html</guid>
</item><item>
  <title>goffer (high)</title>
  <description>New advisory by : anonymous coward&lt;br /&gt;Affected service(s): goffer&lt;br /&gt;Severity [lmh] : high&lt;br /&gt;&lt;br /&gt;===== Problem =====&lt;br /&gt;The &amp;amp;quot;TIKLE&amp;amp;quot; command executes a command. The command is assembled by concatinating the strings &amp;amp;quot;echo&amp;amp;quot; and &amp;amp;quot;id&amp;amp;quot;, as well a...</description>
  <link>http://130.83.160.197/score/adv/a_53.html</link>
  <guid>http://130.83.160.197/score/adv/a_53.html</guid>
</item><item>
  <title>VDspi (medium)</title>
  <description>New advisory by : adc&lt;br /&gt;Affected service(s): VDspi&lt;br /&gt;Severity [lmh] : medium&lt;br /&gt;&lt;br /&gt;===== Problem =====&lt;br /&gt;IDs are not sufficiently random&lt;br /&gt;===== Impact =====&lt;br /&gt;you can predict ids and steal information (flags)&lt;br /&gt;===== Fix =====&lt;br /&gt;use larger numbers and make them random&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;</description>
  <link>http://130.83.160.197/score/adv/a_54.html</link>
  <guid>http://130.83.160.197/score/adv/a_54.html</guid>
</item><item>
  <title>ultrashare (low)</title>
  <description>New advisory by : watz&lt;br /&gt;Affected service(s): ultrashare&lt;br /&gt;Severity [lmh] : low&lt;br /&gt;&lt;br /&gt;===== Problem =====&lt;br /&gt;&lt;br /&gt;The variable &amp;amp;quot;cgibin&amp;amp;quot; in config.rb shows to the wrong path &lt;br /&gt;&lt;br /&gt;===== Impact =====&lt;br /&gt;&lt;br /&gt;Links in the Menu of ultrashare are wrong ...&lt;br /&gt;&lt;br /&gt;===== Fix =====&lt;br /&gt;&lt;br /&gt;Cha...</description>
  <link>http://130.83.160.197/score/adv/a_55.html</link>
  <guid>http://130.83.160.197/score/adv/a_55.html</guid>
</item><item>
  <title>cgibas (medium)</title>
  <description>New advisory by : Samsa&lt;br /&gt;Affected service(s): cgibas&lt;br /&gt;Severity [lmh] : medium&lt;br /&gt;&lt;br /&gt;===== Problem =====&lt;br /&gt;Shoutbox doesn't filter html characters making it vulnerable to a xss attack.&lt;br /&gt;&lt;br /&gt;===== Impact =====&lt;br /&gt;Request may be forged : For instance, storing altered data.&lt;br /&gt;&lt;br /&gt;...</description>
  <link>http://130.83.160.197/score/adv/a_56.html</link>
  <guid>http://130.83.160.197/score/adv/a_56.html</guid>
</item><item>
  <title>vdspi (high)</title>
  <description>New advisory by : Ge0rG&lt;br /&gt;Affected service(s): vdspi&lt;br /&gt;Severity [lmh] : high&lt;br /&gt;&lt;br /&gt;===== Problem =====&lt;br /&gt;&lt;br /&gt;VDspi allows to search for empty names, dumping the whole database.&lt;br /&gt;&lt;br /&gt;Reproduce:&lt;br /&gt;&lt;br /&gt;1 -&amp;amp;gt; 2 -&amp;amp;gt; &amp;amp;lt;enter&amp;amp;gt; -&amp;amp;gt; &amp;amp;lt;enter&amp;amp;gt;&lt;br /&gt;&lt;br /&gt;===== Impact =====&lt;br /&gt;&lt;br /&gt;Reading o...</description>
  <link>http://130.83.160.197/score/adv/a_57.html</link>
  <guid>http://130.83.160.197/score/adv/a_57.html</guid>
</item><item>
  <title>ultrashare (low)</title>
  <description>New advisory by : churchy&lt;br /&gt;Affected service(s): ultrashare&lt;br /&gt;Severity [lmh] : low&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;okaaayyy, here is our second try:&lt;br /&gt;&lt;br /&gt;===== Problem =====&lt;br /&gt;every user in the ultrashare application can change its password withou the need of entering the old password first - an...</description>
  <link>http://130.83.160.197/score/adv/a_58.html</link>
  <guid>http://130.83.160.197/score/adv/a_58.html</guid>
</item><item>
  <title>vdspi (low)</title>
  <description>New advisory by : scyclops&lt;br /&gt;Affected service(s): vdspi&lt;br /&gt;Severity [lmh] : low&lt;br /&gt;&lt;br /&gt;===== Problem =====&lt;br /&gt;VDPI does not release db file lock when error occurs&lt;br /&gt;===== Impact =====&lt;br /&gt;DoS&lt;br /&gt;===== Fix =====&lt;br /&gt;surround code in Search_By_Pred and File procedures after the Lock_F...</description>
  <link>http://130.83.160.197/score/adv/a_59.html</link>
  <guid>http://130.83.160.197/score/adv/a_59.html</guid>
</item><item>
  <title>ultrashare (medium)</title>
  <description>New advisory by : churchy&lt;br /&gt;Affected service(s): ultrashare&lt;br /&gt;Severity [lmh] : medium&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Ok, here is the next one:&lt;br /&gt;&lt;br /&gt;===== Problem =====&lt;br /&gt;when a user uploads a file, a unique id is assigned to it. only the user who uploaded the file should be able to delete it. b...</description>
  <link>http://130.83.160.197/score/adv/a_60.html</link>
  <guid>http://130.83.160.197/score/adv/a_60.html</guid>
</item><item>
  <title>cgibas (medium)</title>
  <description>New advisory by : Samsa&lt;br /&gt;Affected service(s): cgibas&lt;br /&gt;Severity [lmh] : medium&lt;br /&gt;&lt;br /&gt;===== Problem =====&lt;br /&gt;Shoutbox doesn't filter html characters making it vulnerable to a xss attack. This kind of attack can be usefull to steal cookie or POST data information. &lt;br /&gt;&lt;br /&gt;==...</description>
  <link>http://130.83.160.197/score/adv/a_61.html</link>
  <guid>http://130.83.160.197/score/adv/a_61.html</guid>
</item><item>
  <title>CGIBAS (medium)</title>
  <description>New advisory by : c1de0x&lt;br /&gt;Affected service(s): CGIBAS&lt;br /&gt;Severity [lmh] : medium&lt;br /&gt;&lt;br /&gt;===== Problem =====&lt;br /&gt;&lt;br /&gt;CGIBAS site is vulnerable to XSS. Adding a caption like:&lt;br /&gt;&lt;br /&gt;&amp;amp;lt;SCRIPT SRC=http://ha.ckers.org/xss.js&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&lt;br /&gt;&lt;br /&gt;Will result in a javascript popup on ...</description>
  <link>http://130.83.160.197/score/adv/a_62.html</link>
  <guid>http://130.83.160.197/score/adv/a_62.html</guid>
</item><item>
  <title>cgibas (low)</title>
  <description>New advisory by : lwi&lt;br /&gt;Affected service(s): cgibas&lt;br /&gt;Severity [lmh] : low&lt;br /&gt;&lt;br /&gt;===== Problem =====&lt;br /&gt;XSS bug&lt;br /&gt;&lt;br /&gt;http://10.72.1.3/cgi/index.bas?inc=download.bas&amp;amp;amp;gimme=%3Cu%3E70%3C/u%3E for example&lt;br /&gt;&lt;br /&gt;===== Impact =====&lt;br /&gt;&lt;br /&gt;Steal cookies, rape people etc.&lt;br /&gt;&lt;br /&gt;===== Fix ===...</description>
  <link>http://130.83.160.197/score/adv/a_63.html</link>
  <guid>http://130.83.160.197/score/adv/a_63.html</guid>
</item><item>
  <title>ultrashare (low)</title>
  <description>New advisory by : churchy&lt;br /&gt;Affected service(s): ultrashare&lt;br /&gt;Severity [lmh] : low&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Ok, this vuln is sooo severe that it's the end of the app as we know it :)&lt;br /&gt;&lt;br /&gt;===== Problem =====&lt;br /&gt;There is a principal design error throughout the whole application. The applica...</description>
  <link>http://130.83.160.197/score/adv/a_64.html</link>
  <guid>http://130.83.160.197/score/adv/a_64.html</guid>
</item><item>
  <title>cgibas (low)</title>
  <description>New advisory by : bluemood&lt;br /&gt;Affected service(s): cgibas&lt;br /&gt;Severity [lmh] : low&lt;br /&gt;&lt;br /&gt;===== Problem =====&lt;br /&gt;Replaced to #45 for #14 and #27&lt;br /&gt;===== Impact =====&lt;br /&gt;Uploading illegal chars in upload.bas and get invalid file in download.bas&lt;br /&gt;===== Fix =====&lt;br /&gt;in upload.bas&lt;br /&gt;100...</description>
  <link>http://130.83.160.197/score/adv/a_65.html</link>
  <guid>http://130.83.160.197/score/adv/a_65.html</guid>
</item><item>
  <title>vdspi (low)</title>
  <description>New advisory by : Samsa&lt;br /&gt;Affected service(s): vdspi&lt;br /&gt;Severity [lmh] : low&lt;br /&gt;&lt;br /&gt;===== Problem =====&lt;br /&gt;&lt;br /&gt;ID search via menu 1 -&amp;amp;gt; 3 does not supports letters,&lt;br /&gt;throws an unhandled exception&lt;br /&gt;&lt;br /&gt;===== Impact =====&lt;br /&gt;&lt;br /&gt;The service crashes&lt;br /&gt;&lt;br /&gt;===== Fix =====&lt;br /&gt;&lt;br /&gt;--- vdspi.old/ui-...</description>
  <link>http://130.83.160.197/score/adv/a_66.html</link>
  <guid>http://130.83.160.197/score/adv/a_66.html</guid>
</item><item>
  <title>CGIBAS (high)</title>
  <description>New advisory by : manager&lt;br /&gt;Affected service(s): CGIBAS&lt;br /&gt;Severity [lmh] : high&lt;br /&gt;&lt;br /&gt;===== Problem =====&lt;br /&gt;Uploading .bas file to the repository and executing them via inclusion in index.bas allows execution of arbitrary basic code.&lt;br /&gt;The command &amp;amp;quot;foo&amp;amp;quot; of th...</description>
  <link>http://130.83.160.197/score/adv/a_67.html</link>
  <guid>http://130.83.160.197/score/adv/a_67.html</guid>
</item><item>
  <title>CGIBAS (low)</title>
  <description>New advisory by : diskin&lt;br /&gt;Affected service(s): CGIBAS&lt;br /&gt;Severity [lmh] : low&lt;br /&gt;&lt;br /&gt;===== Problem =====&lt;br /&gt;there is no sanitizing of the data written into the shoutbox. and of the data displayed by the shoutbox later. together these allow injection of code to the page...</description>
  <link>http://130.83.160.197/score/adv/a_68.html</link>
  <guid>http://130.83.160.197/score/adv/a_68.html</guid>
</item><item>
  <title>VDSI (high)</title>
  <description>New advisory by : John_K&lt;br /&gt;Affected service(s): VDSI&lt;br /&gt;Severity [lmh] : high&lt;br /&gt;&lt;br /&gt;===== Problem =====&lt;br /&gt;VIDs are assigned sequentially instead of randomly&lt;br /&gt;===== Impact =====&lt;br /&gt;Keys are easily obtainable by executing a ID Search starting at 1 until no results are retur...</description>
  <link>http://130.83.160.197/score/adv/a_69.html</link>
  <guid>http://130.83.160.197/score/adv/a_69.html</guid>
</item><item>
  <title>VDS (high)</title>
  <description>New advisory by : het&lt;br /&gt;Affected service(s): VDS&lt;br /&gt;Severity [lmh] : high&lt;br /&gt;&lt;br /&gt;===== Problem =====&lt;br /&gt;Service is seen as 	&amp;amp;quot;Connection error&amp;amp;quot; while there is traffic on the concerned port&lt;br /&gt;===== Impact =====&lt;br /&gt;Impossible to get credit for obtained flags for this ...</description>
  <link>http://130.83.160.197/score/adv/a_70.html</link>
  <guid>http://130.83.160.197/score/adv/a_70.html</guid>
</item><item>
  <title>ultrashare (high)</title>
  <description>New advisory by : lamer&lt;br /&gt;Affected service(s): ultrashare&lt;br /&gt;Severity [lmh] : high&lt;br /&gt;&lt;br /&gt;===== Problem =====&lt;br /&gt;Hidden command &amp;amp;quot;show&amp;amp;quot;.&lt;br /&gt;===== Impact =====&lt;br /&gt;Together with the reported SQL injection, one can list all the files.&lt;br /&gt;===== Fix =====&lt;br /&gt;Disable the show co...</description>
  <link>http://130.83.160.197/score/adv/a_71.html</link>
  <guid>http://130.83.160.197/score/adv/a_71.html</guid>
</item><item>
  <title>ultrashare (low)</title>
  <description>New advisory by : churchy&lt;br /&gt;Affected service(s): ultrashare&lt;br /&gt;Severity [lmh] : low&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Here we go:&lt;br /&gt;&lt;br /&gt;===== Problem =====&lt;br /&gt;The application ultrashare is vulnerable to xss attacks. When registering a new user the parameter &amp;amp;quot;username&amp;amp;quot; is susceptible. You ca...</description>
  <link>http://130.83.160.197/score/adv/a_72.html</link>
  <guid>http://130.83.160.197/score/adv/a_72.html</guid>
</item><item>
  <title>cgibas (high)</title>
  <description>New advisory by : adc&lt;br /&gt;Affected service(s): cgibas&lt;br /&gt;Severity [lmh] : high&lt;br /&gt;&lt;br /&gt;===== Problem =====&lt;br /&gt;Index.bas is doing a gosub on unfiltered user input resulting in remote code execution&lt;br /&gt;&lt;br /&gt;===== Impact =====&lt;br /&gt;Remote code execution (and command execution if you use ...</description>
  <link>http://130.83.160.197/score/adv/a_73.html</link>
  <guid>http://130.83.160.197/score/adv/a_73.html</guid>
</item><item>
  <title>goferdee (low)</title>
  <description>New advisory by : manager&lt;br /&gt;Affected service(s): goferdee&lt;br /&gt;Severity [lmh] : low&lt;br /&gt;&lt;br /&gt;===== Problem =====&lt;br /&gt;flags are readable to system users. If a team gained shell access to the system the flag are readable from the shell.&lt;br /&gt;&lt;br /&gt;===== Impact =====&lt;br /&gt;retrieval of all ser...</description>
  <link>http://130.83.160.197/score/adv/a_74.html</link>
  <guid>http://130.83.160.197/score/adv/a_74.html</guid>
</item><item>
  <title>CGIBAS (low)</title>
  <description>New advisory by : manager&lt;br /&gt;Affected service(s): CGIBAS&lt;br /&gt;Severity [lmh] : low&lt;br /&gt;&lt;br /&gt;===== Problem =====&lt;br /&gt;flags are readable to system users. If a team gained shell access to the system the flag are readable from the shell.&lt;br /&gt;&lt;br /&gt;===== Impact =====&lt;br /&gt;retrieval of all servi...</description>
  <link>http://130.83.160.197/score/adv/a_75.html</link>
  <guid>http://130.83.160.197/score/adv/a_75.html</guid>
</item><item>
  <title>VDspi (low)</title>
  <description>New advisory by : manager&lt;br /&gt;Affected service(s): VDspi&lt;br /&gt;Severity [lmh] : low&lt;br /&gt;&lt;br /&gt;===== Problem =====&lt;br /&gt;flags are readable to system users. If a team gained shell access to the system the flag are readable from the shell.&lt;br /&gt;&lt;br /&gt;===== Impact =====&lt;br /&gt;retrieval of all servic...</description>
  <link>http://130.83.160.197/score/adv/a_76.html</link>
  <guid>http://130.83.160.197/score/adv/a_76.html</guid>
</item><item>
  <title>ultrashare (low)</title>
  <description>New advisory by : manager&lt;br /&gt;Affected service(s): ultrashare&lt;br /&gt;Severity [lmh] : low&lt;br /&gt;&lt;br /&gt;===== Problem =====&lt;br /&gt;flags are readable to system users. If a team gained shell access to the system the flag are readable from the shell.&lt;br /&gt;&lt;br /&gt;===== Impact =====&lt;br /&gt;retrieval of all s...</description>
  <link>http://130.83.160.197/score/adv/a_77.html</link>
  <guid>http://130.83.160.197/score/adv/a_77.html</guid>
</item><item>
  <title>Ultrashare (high)</title>
  <description>New advisory by : thaidn&lt;br /&gt;Affected service(s): Ultrashare&lt;br /&gt;Severity [lmh] : high&lt;br /&gt;&lt;br /&gt;===== Problem =====&lt;br /&gt;curUser in main.rb can be leveraged to impersonate other users, including admins&lt;br /&gt;&lt;br /&gt;===== Impact =====&lt;br /&gt;steal other user's accounT and fileS&lt;br /&gt;&lt;br /&gt;===== Fix =====&lt;br /&gt;r...</description>
  <link>http://130.83.160.197/score/adv/a_78.html</link>
  <guid>http://130.83.160.197/score/adv/a_78.html</guid>
</item><item>
  <title>cgibas (medium)</title>
  <description>New advisory by : bluemood&lt;br /&gt;Affected service(s): cgibas&lt;br /&gt;Severity [lmh] : medium&lt;br /&gt;&lt;br /&gt;===== Problem =====&lt;br /&gt;Listing flags&lt;br /&gt;===== Impact =====&lt;br /&gt;Data capturing&lt;br /&gt;===== Fix =====&lt;br /&gt;in download.bas&lt;br /&gt;change those line to:&lt;br /&gt;121 rem open &amp;amp;quot;dir&amp;amp;quot; for input as #2&lt;br /&gt;130 rem r...</description>
  <link>http://130.83.160.197/score/adv/a_79.html</link>
  <guid>http://130.83.160.197/score/adv/a_79.html</guid>
</item><item>
  <title>goffer (medium)</title>
  <description>New advisory by : anonymous coward&lt;br /&gt;Affected service(s): goffer&lt;br /&gt;Severity [lmh] : medium&lt;br /&gt;&lt;br /&gt;===== Problem =====&lt;br /&gt;When entering the command &amp;amp;quot;dir&amp;amp;quot;, a new file &amp;amp;quot;listing&amp;amp;quot; with the contents of the directory (containing the flags) is created. This...</description>
  <link>http://130.83.160.197/score/adv/a_80.html</link>
  <guid>http://130.83.160.197/score/adv/a_80.html</guid>
</item><item>
  <title>VDspi (low)</title>
  <description>New advisory by : struppi&lt;br /&gt;Affected service(s): VDspi&lt;br /&gt;Severity [lmh] : low&lt;br /&gt;&lt;br /&gt;===== Problem =====&lt;br /&gt;&lt;br /&gt;Search by ID &amp;amp;quot;n&amp;amp;quot; lists all records whose ID contains substring &amp;amp;quot;n&amp;amp;quot;&lt;br /&gt;&lt;br /&gt;===== Impact =====&lt;br /&gt;&lt;br /&gt;sequentially searching for IDs 1, 2, 3, ..., 9 will ...</description>
  <link>http://130.83.160.197/score/adv/a_81.html</link>
  <guid>http://130.83.160.197/score/adv/a_81.html</guid>
</item><item>
  <title>ultrashare (medium)</title>
  <description>New advisory by : thaidn&lt;br /&gt;Affected service(s): ultrashare&lt;br /&gt;Severity [lmh] : medium&lt;br /&gt;&lt;br /&gt;===== Problem =====&lt;br /&gt;delete function in main.rb failed to check whether curUser is admin which allows any authorized user can delete account of any other users, including admi...</description>
  <link>http://130.83.160.197/score/adv/a_82.html</link>
  <guid>http://130.83.160.197/score/adv/a_82.html</guid>
</item><item>
  <title>UltraShare (medium)</title>
  <description>New advisory by : thaidn&lt;br /&gt;Affected service(s): UltraShare&lt;br /&gt;Severity [lmh] : medium&lt;br /&gt;&lt;br /&gt;===== Problem =====&lt;br /&gt;deleteFile function in main.rb failed to check whether curUser is the owner of the file to be deleted which allows any authorized user to delete files bel...</description>
  <link>http://130.83.160.197/score/adv/a_83.html</link>
  <guid>http://130.83.160.197/score/adv/a_83.html</guid>
</item><item>
  <title>UltraShare (medium)</title>
  <description>New advisory by : thaidn&lt;br /&gt;Affected service(s): UltraShare&lt;br /&gt;Severity [lmh] : medium&lt;br /&gt;&lt;br /&gt;===== Problem =====&lt;br /&gt;&lt;br /&gt;delete function in main.rb failed to check whether curUser is admin which allows any authorized user can delete account of any other users (but not admin...</description>
  <link>http://130.83.160.197/score/adv/a_84.html</link>
  <guid>http://130.83.160.197/score/adv/a_84.html</guid>
</item><item>
  <title>ultrashare (low)</title>
  <description>New advisory by : churchy&lt;br /&gt;Affected service(s): ultrashare&lt;br /&gt;Severity [lmh] : low&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Keep it up teams, 2.5 more hours to go :)&lt;br /&gt;&lt;br /&gt;===== Problem =====&lt;br /&gt;In the file &amp;amp;quot;test.rb&amp;amp;quot; there is a vulnerability in the routine of the creation of random files:&lt;br /&gt;filenam...</description>
  <link>http://130.83.160.197/score/adv/a_85.html</link>
  <guid>http://130.83.160.197/score/adv/a_85.html</guid>
</item><item>
  <title>Cashflags (low)</title>
  <description>New advisory by : adc&lt;br /&gt;Affected service(s): Cashflags&lt;br /&gt;Severity [lmh] : low&lt;br /&gt;&lt;br /&gt;===== Problem =====&lt;br /&gt;It is possible to intercept cashflag flags &lt;br /&gt;with command execution on a vulnerable server,&lt;br /&gt;just listen up on the port. Theres no form&lt;br /&gt;of authenticationc&lt;br /&gt;===== Im...</description>
  <link>http://130.83.160.197/score/adv/a_86.html</link>
  <guid>http://130.83.160.197/score/adv/a_86.html</guid>
</item><item>
  <title>UltraShare (medium)</title>
  <description>New advisory by : thaidn&lt;br /&gt;Affected service(s): UltraShare&lt;br /&gt;Severity [lmh] : medium&lt;br /&gt;&lt;br /&gt;===== Problem =====&lt;br /&gt;This is not a duplicated adv. My previous adv (#60) is wrong but this one is correct. Please double check. The main different is deleteFile calls @db.dele...</description>
  <link>http://130.83.160.197/score/adv/a_87.html</link>
  <guid>http://130.83.160.197/score/adv/a_87.html</guid>
</item><item>
  <title>Goferdee (high)</title>
  <description>New advisory by : anonymous coward&lt;br /&gt;Affected service(s): Goferdee&lt;br /&gt;Severity [lmh] : high&lt;br /&gt;&lt;br /&gt;===== Problem =====&lt;br /&gt;The 'dir' command, in conjuction with the purpose of the service itself, makes it possible to access flags without knowing their FLAGSTORE id. By is...</description>
  <link>http://130.83.160.197/score/adv/a_88.html</link>
  <guid>http://130.83.160.197/score/adv/a_88.html</guid>
</item><item>
  <title>CGIBAS (high)</title>
  <description>New advisory by : John_K&lt;br /&gt;Affected service(s): CGIBAS&lt;br /&gt;Severity [lmh] : high&lt;br /&gt;&lt;br /&gt;===== Problem =====&lt;br /&gt;Use CGIBASE upload.bas to overwrite a script file at an absolute path that is writable by www-data&lt;br /&gt;===== Impact =====&lt;br /&gt;Any file writable by www-data can be overw...</description>
  <link>http://130.83.160.197/score/adv/a_89.html</link>
  <guid>http://130.83.160.197/score/adv/a_89.html</guid>
</item><item>
  <title>ultrashare (medium)</title>
  <description>New advisory by : Samsa&lt;br /&gt;Affected service(s): ultrashare&lt;br /&gt;Severity [lmh] : medium&lt;br /&gt;&lt;br /&gt;===== Problem =====&lt;br /&gt;&lt;br /&gt;The application maintain the same session id in both zones,&lt;br /&gt;the public and the private one. Consecuently is it possible&lt;br /&gt;to steal the cookie ID using anoth...</description>
  <link>http://130.83.160.197/score/adv/a_90.html</link>
  <guid>http://130.83.160.197/score/adv/a_90.html</guid>
</item><item>
  <title>Goferdee (low)</title>
  <description>New advisory by : anonymous coward&lt;br /&gt;Affected service(s): Goferdee&lt;br /&gt;Severity [lmh] : low&lt;br /&gt;&lt;br /&gt;===== Problem =====&lt;br /&gt;FLAGSTORE command can be used to overwrite ./ls script, which is used to implement 'dir' command&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;===== Impact =====&lt;br /&gt;&lt;br /&gt;===== Fix =====&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;</description>
  <link>http://130.83.160.197/score/adv/a_91.html</link>
  <guid>http://130.83.160.197/score/adv/a_91.html</guid>
</item><item>
  <title>Goferdee (medium)</title>
  <description>New advisory by : anonymous coward&lt;br /&gt;Affected service(s): Goferdee&lt;br /&gt;Severity [lmh] : medium&lt;br /&gt;&lt;br /&gt;===== Problem =====&lt;br /&gt;FLAGSTORE command can be used to overwrite ./ls script, which is used to implement 'dir' command&lt;br /&gt;===== Impact =====&lt;br /&gt;Exploit: FLAGSTORE reversed_cm...</description>
  <link>http://130.83.160.197/score/adv/a_92.html</link>
  <guid>http://130.83.160.197/score/adv/a_92.html</guid>
</item><item>
  <title>CGIBAS (low)</title>
  <description>New advisory by : adc&lt;br /&gt;Affected service(s): CGIBAS&lt;br /&gt;Severity [lmh] : low&lt;br /&gt;&lt;br /&gt;===== Problem =====&lt;br /&gt;There exists a shoutbox dos , you can insert newlines&lt;br /&gt;and mess up the service&lt;br /&gt;===== Impact =====&lt;br /&gt;you dont get any points because functionality is lost&lt;br /&gt;===== Fix ===...</description>
  <link>http://130.83.160.197/score/adv/a_93.html</link>
  <guid>http://130.83.160.197/score/adv/a_93.html</guid>
</item><item>
  <title>ultrashare (medium)</title>
  <description>New advisory by : anonymous coward&lt;br /&gt;Affected service(s): ultrashare&lt;br /&gt;Severity [lmh] : medium&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;</description>
  <link>http://130.83.160.197/score/adv/a_94.html</link>
  <guid>http://130.83.160.197/score/adv/a_94.html</guid>
</item><item>
  <title>ultrashare (low)</title>
  <description>New advisory by : churchy&lt;br /&gt;Affected service(s): ultrashare&lt;br /&gt;Severity [lmh] : low&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;How is the atmosphrere there in berlin? are many people watchin the local teams or the operators?&lt;br /&gt;&lt;br /&gt;===== Problem =====&lt;br /&gt;The script &amp;amp;quot;test.rb&amp;amp;quot; is not validating and eca...</description>
  <link>http://130.83.160.197/score/adv/a_95.html</link>
  <guid>http://130.83.160.197/score/adv/a_95.html</guid>
</item><item>
  <title>CONTEST (HIGH)</title>
  <description>New advisory by : adc&lt;br /&gt;Affected service(s): CONTEST&lt;br /&gt;Severity [lmh] : HIGH&lt;br /&gt;&lt;br /&gt;===== Problem =====&lt;br /&gt;Sitting next to too many CCCers can lead to &lt;br /&gt;fuses blowing :(. This happened just hours earlier&lt;br /&gt;to Janet Reno. &lt;br /&gt;===== Impact =====&lt;br /&gt;Sudden Death&lt;br /&gt;===== Fix =====&lt;br /&gt;Un...</description>
  <link>http://130.83.160.197/score/adv/a_96.html</link>
  <guid>http://130.83.160.197/score/adv/a_96.html</guid>
</item><item>
  <title>VDspi (low)</title>
  <description>New advisory by : struppi&lt;br /&gt;Affected service(s): VDspi&lt;br /&gt;Severity [lmh] : low&lt;br /&gt;&lt;br /&gt;===== Problem =====&lt;br /&gt;&lt;br /&gt;Search by ID &amp;amp;quot;n&amp;amp;quot; lists all records whose ID contains substring &amp;amp;quot;n&amp;amp;quot;&lt;br /&gt;&lt;br /&gt;===== Impact =====&lt;br /&gt;&lt;br /&gt;sequentially searching for IDs 1, 2, 3, ..., 9 will ...</description>
  <link>http://130.83.160.197/score/adv/a_97.html</link>
  <guid>http://130.83.160.197/score/adv/a_97.html</guid>
</item><item>
  <title>cgibase (low)</title>
  <description>New advisory by : BfrOv3rfl0w&lt;br /&gt;Affected service(s): cgibase&lt;br /&gt;Severity [lmh] : low&lt;br /&gt;&lt;br /&gt;===== Problem =====&lt;br /&gt;There is still a possible way to perform a dos on the shoutbox. &lt;br /&gt;You just have to use other strings or chars than newline.&lt;br /&gt;similar to #93&lt;br /&gt;===== Impact ====...</description>
  <link>http://130.83.160.197/score/adv/a_98.html</link>
  <guid>http://130.83.160.197/score/adv/a_98.html</guid>
</item><item>
  <title>Goferdee (high)</title>
  <description>New advisory by : EQ&lt;br /&gt;Affected service(s): Goferdee&lt;br /&gt;Severity [lmh] : high&lt;br /&gt;&lt;br /&gt;===== Problem =====&lt;br /&gt;the flagstore part allows to modify the original execution.&lt;br /&gt;&lt;br /&gt;===== Impact =====&lt;br /&gt;remote code execution&lt;br /&gt;&lt;br /&gt;===== Fix =====&lt;br /&gt;&lt;br /&gt;new and better regexps.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;</description>
  <link>http://130.83.160.197/score/adv/a_99.html</link>
  <guid>http://130.83.160.197/score/adv/a_99.html</guid>
</item><item>
  <title>CGIBAS (low)</title>
  <description>New advisory by : manager&lt;br /&gt;Affected service(s): CGIBAS&lt;br /&gt;Severity [lmh] : low&lt;br /&gt;&lt;br /&gt;===== Problem =====&lt;br /&gt;shoutbox not working.&lt;br /&gt;===== Impact =====&lt;br /&gt;no communication via shouting.&lt;br /&gt;===== Fix =====&lt;br /&gt;we fixed several conditions of the if-commands for action and shout.&lt;br /&gt;Sho...</description>
  <link>http://130.83.160.197/score/adv/a_100.html</link>
  <guid>http://130.83.160.197/score/adv/a_100.html</guid>
</item><item>
  <title>General (low)</title>
  <description>New advisory by : adc&lt;br /&gt;Affected service(s): General&lt;br /&gt;Severity [lmh] : low&lt;br /&gt;&lt;br /&gt;===== Problem ===== &lt;br /&gt;if wolfgang's password is same for all the server and if someone can crack the password,&lt;br /&gt;he can log in any system. goffer is too.&lt;br /&gt;&lt;br /&gt; ===== Impact ===== &lt;br /&gt;we can get...</description>
  <link>http://130.83.160.197/score/adv/a_101.html</link>
  <guid>http://130.83.160.197/score/adv/a_101.html</guid>
</item><item>
  <title>ultrashare (low)</title>
  <description>New advisory by : Samsa&lt;br /&gt;Affected service(s): ultrashare&lt;br /&gt;Severity [lmh] : low&lt;br /&gt;&lt;br /&gt;===== Problem =====&lt;br /&gt;&lt;br /&gt;The application is vulnerable a 'Fixed Session' attack. This attack &lt;br /&gt;consists in setting the user session before the server. After that,  &lt;br /&gt;when the user logi...</description>
  <link>http://130.83.160.197/score/adv/a_102.html</link>
  <guid>http://130.83.160.197/score/adv/a_102.html</guid>
</item><item>
  <title>Cashflags (low)</title>
  <description>New advisory by : slashd&lt;br /&gt;Affected service(s): Cashflags&lt;br /&gt;Severity [lmh] : low&lt;br /&gt;&lt;br /&gt;===== Problem =====&lt;br /&gt;It is possible to join to netcat and to send TRASH&lt;br /&gt;===== Impact =====&lt;br /&gt;nC 10.64.1.3 12345 TRASH SPAM&lt;br /&gt;===== Fix =====&lt;br /&gt;nc -lp 12345 | grep FLAG &lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;</description>
  <link>http://130.83.160.197/score/adv/a_103.html</link>
  <guid>http://130.83.160.197/score/adv/a_103.html</guid>
</item><item>
  <title>gopherdee (high)</title>
  <description>New advisory by : lamer&lt;br /&gt;Affected service(s): gopherdee&lt;br /&gt;Severity [lmh] : high&lt;br /&gt;&lt;br /&gt;Problem &lt;br /&gt;--------&lt;br /&gt;FLAGSTORE command can be used to overwrite multiple script inside /service/ICANHASGOFERDEE, includung shell scripts such as goferdee.sh, ls and run due to the w...</description>
  <link>http://130.83.160.197/score/adv/a_104.html</link>
  <guid>http://130.83.160.197/score/adv/a_104.html</guid>
</item><item>
  <title>Goferdee (high)</title>
  <description>New advisory by : thaidn&lt;br /&gt;Affected service(s): Goferdee&lt;br /&gt;Severity [lmh] : high&lt;br /&gt;&lt;br /&gt;===== Problem =====&lt;br /&gt;&amp;amp;quot;dir&amp;amp;quot; command save a list of files inside /service/ICANHASGOFERDEE to the 'listing' file. By keep issuing dir command and monitor the content of the...</description>
  <link>http://130.83.160.197/score/adv/a_105.html</link>
  <guid>http://130.83.160.197/score/adv/a_105.html</guid>
</item><item>
  <title>advisory system (low)</title>
  <description>New advisory by : anonymous coward&lt;br /&gt;Affected service(s): advisory system&lt;br /&gt;Severity [lmh] : low&lt;br /&gt;&lt;br /&gt;===== Problem =====&lt;br /&gt;The advisory submission system does not properly verify credentials.&lt;br /&gt;	===== Impact =====&lt;br /&gt;You can submit an advisory as another team and make t...</description>
  <link>http://130.83.160.197/score/adv/a_106.html</link>
  <guid>http://130.83.160.197/score/adv/a_106.html</guid>
</item><item>
  <title>cashflag (low)</title>
  <description>New advisory by : slashd&lt;br /&gt;Affected service(s): cashflag&lt;br /&gt;Severity [lmh] : low&lt;br /&gt;&lt;br /&gt;===== Problem =====&lt;br /&gt;Spam in cashflag service&lt;br /&gt;===== Impact =====&lt;br /&gt;When other teams execute&lt;br /&gt;&lt;br /&gt;nc -l -p 12345&lt;br /&gt;&lt;br /&gt;he is avalebel to free connect&lt;br /&gt;we do&lt;br /&gt;&lt;br /&gt;nc team_ip 12345&lt;br /&gt;Send spam, War and...</description>
  <link>http://130.83.160.197/score/adv/a_107.html</link>
  <guid>http://130.83.160.197/score/adv/a_107.html</guid>
</item><item>
  <title>Goferdee (high)</title>
  <description>New advisory by : EQ&lt;br /&gt;Affected service(s): Goferdee&lt;br /&gt;Severity [lmh] : high&lt;br /&gt;&lt;br /&gt;===== Problem =====&lt;br /&gt;the flagstore part allows to modify the original execution.&lt;br /&gt;&lt;br /&gt;===== Impact =====&lt;br /&gt;remote code execution&lt;br /&gt;&lt;br /&gt;===== Fix =====&lt;br /&gt;new regexp: allow only [a-zA-z0-9]* not .* ...</description>
  <link>http://130.83.160.197/score/adv/a_108.html</link>
  <guid>http://130.83.160.197/score/adv/a_108.html</guid>
</item><item>
  <title>CGIBAS (high)</title>
  <description>New advisory by : c1de0x&lt;br /&gt;Affected service(s): CGIBAS&lt;br /&gt;Severity [lmh] : high&lt;br /&gt;&lt;br /&gt;===== Problem =====&lt;br /&gt;The existing fix for the directory traversal in download.bas doesn't fix absolute access.&lt;br /&gt;&lt;br /&gt;===== Impact =====&lt;br /&gt;Read any system files.&lt;br /&gt;&lt;br /&gt;===== Fix =====&lt;br /&gt;&lt;br /&gt;Prepend ....</description>
  <link>http://130.83.160.197/score/adv/a_109.html</link>
  <guid>http://130.83.160.197/score/adv/a_109.html</guid>
</item><item>
  <title>ULTRASHARE (high)</title>
  <description>New advisory by : John_K&lt;br /&gt;Affected service(s): ULTRASHARE&lt;br /&gt;Severity [lmh] : high&lt;br /&gt;&lt;br /&gt;===== Problem =====&lt;br /&gt;UltraShare templates are writable by www-data user. Ruby code can be appended to the templates to access private data, and execute arbitrary code as www-dat...</description>
  <link>http://130.83.160.197/score/adv/a_110.html</link>
  <guid>http://130.83.160.197/score/adv/a_110.html</guid>
</item><item>
  <title>tcpserver (medium)</title>
  <description>New advisory by : Samsa&lt;br /&gt;Affected service(s): tcpserver&lt;br /&gt;Severity [lmh] : medium&lt;br /&gt;&lt;br /&gt;===== Problem =====&lt;br /&gt;&lt;br /&gt;Boundary condition problem in remoteinfo.c can make a remote service to crash &lt;br /&gt;with big buffers, this is done with stralloc_append(out,&amp;amp;amp;ch)&lt;br /&gt;&lt;br /&gt;To exploit...</description>
  <link>http://130.83.160.197/score/adv/a_111.html</link>
  <guid>http://130.83.160.197/score/adv/a_111.html</guid>
</item><item>
  <title>ICANHASGOFERDEE (high)</title>
  <description>New advisory by : thorben&lt;br /&gt;Affected service(s): ICANHASGOFERDEE&lt;br /&gt;Severity [lmh] : high&lt;br /&gt;&lt;br /&gt;===== Problem =====&lt;br /&gt;goferdee lists contents of arbitrary files in datadir, if the reverse of their names is known&lt;br /&gt;&lt;br /&gt;===== Impact =====&lt;br /&gt;as flags are stored in files in the ...</description>
  <link>http://130.83.160.197/score/adv/a_112.html</link>
  <guid>http://130.83.160.197/score/adv/a_112.html</guid>
</item><item>
  <title>CGIBAS (high)</title>
  <description>New advisory by : c1de0x&lt;br /&gt;Affected service(s): CGIBAS&lt;br /&gt;Severity [lmh] : high&lt;br /&gt;&lt;br /&gt;===== Problem =====&lt;br /&gt;upload.bas allows to store into absolute paths.&lt;br /&gt;===== Impact =====&lt;br /&gt;Overwrite/create files wherever www-data can write.&lt;br /&gt;===== Fix =====&lt;br /&gt;Prepend ./ to all pathnam...</description>
  <link>http://130.83.160.197/score/adv/a_113.html</link>
  <guid>http://130.83.160.197/score/adv/a_113.html</guid>
</item><item>
  <title>teamimage (low)</title>
  <description>New advisory by : hc&lt;br /&gt;Affected service(s): teamimage&lt;br /&gt;Severity [lmh] : low&lt;br /&gt;&lt;br /&gt;We were the first to post a teamimage&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;</description>
  <link>http://130.83.160.197/score/adv/a_114.html</link>
  <guid>http://130.83.160.197/score/adv/a_114.html</guid>
</item><item>
  <title>ultrashare (medium)</title>
  <description>New advisory by : adc&lt;br /&gt;Affected service(s): ultrashare&lt;br /&gt;Severity [lmh] : medium&lt;br /&gt;&lt;br /&gt;===== Problem =====&lt;br /&gt;There exists a CSRF vulnerability in ultrashare .&lt;br /&gt;===== Impact =====&lt;br /&gt;Users logged in may be coerced by a third-party website&lt;br /&gt;into performing actions with the...</description>
  <link>http://130.83.160.197/score/adv/a_115.html</link>
  <guid>http://130.83.160.197/score/adv/a_115.html</guid>
</item><item>
  <title>ultrashare (medium)</title>
  <description>New advisory by : manager&lt;br /&gt;Affected service(s): ultrashare&lt;br /&gt;Severity [lmh] : medium&lt;br /&gt;&lt;br /&gt;===== Problem =====&lt;br /&gt;&lt;br /&gt;ultrashare discloses _all_ flags as comments in the html-sourcecode&lt;br /&gt;&lt;br /&gt;===== Impact =====&lt;br /&gt;all flags can be access by simply browsing the site&lt;br /&gt;&lt;br /&gt;===== Fix =...</description>
  <link>http://130.83.160.197/score/adv/a_116.html</link>
  <guid>http://130.83.160.197/score/adv/a_116.html</guid>
</item><item>
  <title>Team SquareRoots (high)</title>
  <description>New advisory by : John_K&lt;br /&gt;Affected service(s): Team SquareRoots&lt;br /&gt;Severity [lmh] : high&lt;br /&gt;&lt;br /&gt;===== Problem =====&lt;br /&gt;You got pwnt.&lt;br /&gt;===== Impact =====&lt;br /&gt;All your points are belong to us.&lt;br /&gt;===== Fix =====&lt;br /&gt;Cry, then fix your software.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;</description>
  <link>http://130.83.160.197/score/adv/a_117.html</link>
  <guid>http://130.83.160.197/score/adv/a_117.html</guid>
</item><item>
  <title>all? (low)</title>
  <description>New advisory by : churchy&lt;br /&gt;Affected service(s): all?&lt;br /&gt;Severity [lmh] : low&lt;br /&gt;&lt;br /&gt;===== Problem =====&lt;br /&gt;the user &amp;amp;quot;www-data&amp;amp;quot; has write-access to the directory &amp;amp;quot;/var/www/styles&amp;amp;quot;. if an attacker can write files to the system, some shells like a ruby...</description>
  <link>http://130.83.160.197/score/adv/a_118.html</link>
  <guid>http://130.83.160.197/score/adv/a_118.html</guid>
</item><item>
  <title>vdspi (medium)</title>
  <description>New advisory by : Samsa&lt;br /&gt;Affected service(s): vdspi&lt;br /&gt;Severity [lmh] : medium&lt;br /&gt;&lt;br /&gt;===== Problem =====&lt;br /&gt;&lt;br /&gt;A full database dump can be done by bruteforcing the menus.&lt;br /&gt;&lt;br /&gt;===== Impact =====&lt;br /&gt;&lt;br /&gt;The full database can be dumped. The range of IDs to use should&lt;br /&gt;be specified t...</description>
  <link>http://130.83.160.197/score/adv/a_119.html</link>
  <guid>http://130.83.160.197/score/adv/a_119.html</guid>
</item><item>
  <title>goffer (low)</title>
  <description>New advisory by : anonymous coward&lt;br /&gt;Affected service(s): goffer&lt;br /&gt;Severity [lmh] : low&lt;br /&gt;&lt;br /&gt;===== Problem =====&lt;br /&gt;Goffer uses a shell script &amp;amp;quot;ls&amp;amp;quot; in place of the normal /bin/ls. Normally, this shell script only executes /bin/ls, but an attacker might get ...</description>
  <link>http://130.83.160.197/score/adv/a_120.html</link>
  <guid>http://130.83.160.197/score/adv/a_120.html</guid>
</item><item>
  <title>CGIBAS (high)</title>
  <description>New advisory by : John_K&lt;br /&gt;Affected service(s): CGIBAS&lt;br /&gt;Severity [lmh] : high&lt;br /&gt;&lt;br /&gt;===== Problem =====&lt;br /&gt;cgibas.pl has a back door in function internal_foo&lt;br /&gt;===== Impact =====&lt;br /&gt;Execute system commands as www-data from basic scripts.&lt;br /&gt;===== Fix =====&lt;br /&gt;remove internal_fo...</description>
  <link>http://130.83.160.197/score/adv/a_121.html</link>
  <guid>http://130.83.160.197/score/adv/a_121.html</guid>
</item><item>
  <title>vdspi (medium)</title>
  <description>New advisory by : c1de0x&lt;br /&gt;Affected service(s): vdspi&lt;br /&gt;Severity [lmh] : medium&lt;br /&gt;&lt;br /&gt;===== Problem =====&lt;br /&gt;see adv #119&lt;br /&gt;&lt;br /&gt;===== Impact =====&lt;br /&gt;see adv #119&lt;br /&gt;&lt;br /&gt;===== Fix =====&lt;br /&gt;change or remove the mod 1024 in person.ids:&lt;br /&gt;type ID_Type is mod 1024&lt;br /&gt;using some value like 6553...</description>
  <link>http://130.83.160.197/score/adv/a_122.html</link>
  <guid>http://130.83.160.197/score/adv/a_122.html</guid>
</item></channel>
</rss>

