Release Date: 2008-10-28
Critical:
Highly critical
Impact: DoS
System access
Where: From remote
Solution Status: Unpatched
Software: Blaze Media Pro 8.x
Description:
A vulnerability has been reported in Blaze Media Pro, which can be exploited by malicious people to potentially compromise a user's system.
For more information:
SA31936
The vulnerability is reported in Blaze Media Pro 8.02 Special Edition (8.2.0.9, trial version). Other versions may also be affected.
Solution:
Set the kill-bit for the affected ActiveX control.
Provided and/or discovered by:
Originally reported by bruiser, Nine Situations Group. Reported in Blaze Media Pro SE by ipsdix.
Other References:
SA31936:
http://secunia.com/advisories/31936/
Eaton MGE Network Shutdown Module Arbitrary Command Execution Vulnerability
Release Date: 2008-10-28
Critical:
Moderately critical
Impact: System access
Where: From local network
Solution Status: Vendor Patch
Software: Eaton MGE Network Shutdown Module 3.x
Description:
n.runs AG has reported a vulnerability in Eaton MGE Network Shutdown Module, which can be exploited by malicious people to compromise a vulnerable system.
The vulnerability is caused due to the application allowing unrestricted access to the "pane_actionbutton.php" and "exec_action.php" scripts. This can be exploited to add and execute custom actions containing arbitrary commands.
Successful exploitation may allow execution of arbitrary code.
The vulnerability is reported in versions prior to 3.20.
Solution:
Update to version 3.20.
http://download.mgeops.com/explore/eng/network/net_sol.htm
Provided and/or discovered by:
Jan Rossmann and Jan Wagner, n.runs AG
Original Advisory:
Eaton MGE Office Protection Systems:
http://download.mgeops.com/install/win32/nsm/release_note_nsm_320.txt
n.runs AG:
http://packetstormsecurity.org/0810-advisories/n.runs-SA-2008.009.txt

Chowhound
Comic Vine
GameFAQs
GameSpot
Giant Bomb
TechRepublic