Thursday, September 2, 2010
TCMS: Local File Inclusion
Users of TCMS please be advised of a Local File Inclusion vulnerability that has been identified.
To view this vulnerability, possible remedies, and others please check out the Security Advisories at Critical Watch (http://criticalwatch.com/support/security-advisories.aspx)
HTB22573: [HTB22573] Local File Inclusion in TCMS
Product: TCMS
Vulnerability Type: Local File Inclusion
Vulnerability Details:
Null-byte (%00) injection and catalog bypass (../) attacks are possible and can lead to arbitrary local file inclusion and execution. An attacker needs to have a possibility to modify or create local files to exploit this vulnerability, or have a malicious file already existing in the system.
Read more at www.criticalwatch.com
TCMS: File Content Disclosure
Users of TCMS please be advised of a File Content Disclosure vulnerability that has been identified.
To view this vulnerability, possible remedies, and others please check out the Security Advisories at Critical Watch (http://criticalwatch.com/support/security-advisories.aspx)
HTB22579: [HTB22579] File Content Disclosure in TCMS
Vulnerability Type: File Content Disclosure
Product: TCMS
Vulnerability Details:
An attacker can disclose arbitrary local file content.
Read more at www.criticalwatch.com
BugTracker.net 3.4.3: SQL Injection
Users of BugTracker.NET 3.4.3 please be advised of a SQL Injection vulnerability that has been identified.
To view this vulnerability, possible remedies, and others please check out the Security Advisories at Critical Watch (http://criticalwatch.com/support/security-advisories.aspx)
BugTracker.NET-SA-08/26/2010: BugTracker.net 3.4.3 SQL Injection
Name BugTracker.NET
SQL Injection
_______________________________
The application allows the use of Custom Fields, searching
of these custom fields is possible on the search page.
The value used for searching the custom field is not
properly cleaned before being used in the SQL query.
Please note this vulnerability is in the code lot for a long time
if using BugTracker.NET publicly you could be vulnerable.
Read more at www.criticalwatch.com
