Release Date: 2008-10-17
Critical:
Moderately critical
Impact: System access
Where: From remote
Solution Status: Unpatched
Software: Mantis 1.x
Description:
EgiX has discovered a vulnerability in Mantis, which can be exploited by malicious users to compromise a vulnerable system.
Input passed to the "sort" parameter in manage_proj_page.php is not properly sanitised before being used in a "create_function()" call. This can be exploited to execute arbitrary PHP code.
Successful exploitation requires valid user credentials.
The vulnerability is confirmed in version 1.1.2 and reported in version 1.1.3. Other versions may also be affected.
Solution:
Restrict access to manage_proj_page.php (e.g. with ".htaccess").
Provided and/or discovered by:
EgiX
Original Advisory:
http://milw0rm.com/exploits/6768
Hummingbird Xweb ActiveX Control "PlainTextPassword" Property Buffer Overflow
Release Date: 2008-10-17
Critical:
Highly critical
Impact: DoS
System access
Where: From remote
Solution Status: Unpatched
Software: Exceed 10.x
Exceed 2006 11.x
Exceed 2007
Exceed 9.x
Exceed PowerSuite 10.x
Hummingbird Xweb ActiveX Control
Description:
Thomas Pollet has reported a vulnerability in Hummingbird Xweb ActiveX Control, which potentially can be exploited by malicious people to compromise a user's system.
The vulnerability is caused due to a boundary error within the Hummingbird.XWebHostCtrl.1 ActiveX control (hclxweb.dll) when handling the "PlainTextPassword" property. This can be exploited to cause a stack-based buffer overflow by assigning an overly long string to the affected property.
Successful exploitation may allow execution of arbitrary code.
The vulnerability is reported in versions prior to 13.0.
Solution:
Set the kill-bit for the affected ActiveX control.
Provided and/or discovered by:
Thomas Pollet
Original Advisory:
http://milw0rm.com/exploits/6761

Chowhound
Comic Vine
GameFAQs
GameSpot
Giant Bomb
TechRepublic