Re: Microsoft Baseline Security Analyzer exploit (Exposed vulnerabilities' list)

From: 3APA3A (3APA3A@SECURITY.NNOV.RU)
Date: 04/25/02


Date: Thu, 25 Apr 2002 12:51:44 +0400
From: 3APA3A <3APA3A@SECURITY.NNOV.RU>
To: "Menashe Eliezer" <menashe@finjan.com>

Dear Menashe Eliezer,

Sorry for asking, but it's unclear from advisory: is it possible to
access reports with either:

1. ActiveX element marked safe for scripting
2. Javascript or VBscript from "Internet" security zone

Examples you give for scripting will only run in local host content, so
this problem seems to be local only (default permissions for sensitive
files) with minimal impact, because analysis of security policy,
registry and file permissions can (mostly) be done by local user with
unprivileged account. In this case risk is low.

--Thursday, April 25, 2002, 5:06:32 AM, you wrote to bugtraq@securityfocus.com:

ME> Microsoft Baseline Security Analyzer exploit (Exposed vulnerabilities' list)
ME> Finjan Software Security Advisory
ME> URL: http://www.finjan.com/mcrc/alert_show.cfm?attack_release_id=71
ME> April 24, 2002
ME> Risk: Medium
ME> -------------

-- 
~/ZARAZA
Человек это тайна... я занимаюсь этой тайной чтобы быть человеком. (Достоевский)



Relevant Pages

  • NetScreen Advisory 58412: XSS Bug in NetScreen-SA SSL VPN
    ... vulnerability affects customers using all versions of the IVE Platform ... There exists a cross-site scripting bug in 'row' parameter of the ... NetScreen has security patches available to address this vulnerability. ... This advisory as well as any future updates will be made available ...
    (Bugtraq)
  • Re: XP Home - Service Pack 2
    ... > router (linksys) that I've been using as a firewall, so I do have security. ... The Security Center doesn't say that your computer is at risk, ... -- torgeir, Microsoft MVP Scripting and WMI, Porsgrunn Norway Administration scripting examples and an ONLINE version of the 1328 page Scripting Guide: ...
    (microsoft.public.windowsupdate)
  • Re: Microsoft Baseline Security Analyzer exploit (Exposed vulnerabilities list)
    ... Javascript or VBscript from "Internet" security zone ... Examples you give for scripting will only run in local host content, ... In this case risk is low. ... ME> Finjan Software Security Advisory ...
    (Bugtraq)
  • [NEWS] Wonderware SuiteLink Denial of Service Vulnerability
    ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... Get your security news from a reliable source. ... Vendor Information, Solutions and Workarounds ... Core sends the advisory draft to Wonderware support team. ...
    (Securiteam)
  • [Full-disclosure] CORE-2009-0820 - Dnsmasq Heap Overflow and Null-pointer Derefe
    ... Core Security Technologies - CoreLabs Advisory ... Dnsmasq Heap Overflow and Null-pointer Dereference on TFTP Server ... Herederos de Don Pablo" of Core Security Technologies. ...
    (Full-Disclosure)