Dark Reading Registration Ad - Top Left
DATE: June 18, 2008
LIVE EVENT: Broadband Wireless World
More Information
Home > Most Popular News Analysis
Most Popular News Analysis

Dark Reading News Analysis: Researchers Infiltrate and 'Pollute' Storm Botnet - 4/23/2008 3:45:00 PM
European botnet experts devise a method that disrupts stubborn peer-to-peer botnets like Storm
Dark Reading News Analysis: Hacker's Choice: Top Six Database Attacks - 5/8/2008 6:20:00 PM
It doesn't take a database expert to break into one
Dark Reading News Analysis: Companies May Be Held Liable for Deals With Terrorists, ID Thieves - 4/23/2008 5:25:00 PM
New and little-known regulations could mean fines, or even jail time, for companies that do business with bad guys
Dark Reading News Analysis: New Tests Show Rootkits Still Evade AV - 5/13/2008 4:52:00 PM
AV-Test.org tests rootkit detection and removal on XP, Vista
Dark Reading News Analysis: New Massive Botnet Twice the Size of Storm - 4/7/2008 8:00:00 AM
400,000-strong 'Kraken' botnet has infiltrated 50 Fortune 500 companies -- and now usurps Storm as world's biggest botnet
Dark Reading Reports: DR's 10 Most Popular Stories Ever (Second Edition) - 5/2/2008 1:55:00 PM
A look at the top stories from our first two years, including coolest hacks, biggest botnets, and a thumb drive exploit that readers just can't put down
Dark Reading News Analysis: AV Still Weak on Rootkit Detection, Fixing Infections - 3/12/2008 5:20:00 PM
New AV-Test.org results reveal some nagging problems with antivirus products
Dark Reading News Analysis: Tech Insight: DIY Penetration Testing - 4/25/2008 3:05:00 PM
When to conduct your own penetration test or to farm it out to a third party
Dark Reading News Analysis: The Five Coolest Hacks of 2007 - 12/31/2007 2:51:00 PM
Nothing was sacred – not cars, not truckers, not even the stock exchange
Dark Reading News Analysis: IBM: The Security Business 'Has No Future' - 4/10/2008 4:30:00 PM
IBM executive tells RSA attendees that the security business is dead – and sustainable business is the future
Dark Reading News Analysis: 'Long-Term' Phishing Attack Underway - 4/28/2008 5:15:00 PM
New phishing exploit doesn't bother asking for passwords, and its stealthy malware hides out on victim's machine
Dark Reading News Analysis: Supermarket ATM/Card Reader Rigged With Illicit Scanner - 5/1/2008 5:55:00 PM
Shoppers' credit card, debit card information stolen and used in identity theft scheme in California
Dark Reading News Analysis: 'Dailydave': Full Disclosure - 10/4/2007 5:10:00 PM
Immunity's David Aitel chats up the NSA, lobstering, and hackers with rabbits
Dark Reading News Analysis: Hackers in the House - 5/5/2008 5:15:00 PM
New social network for hackers lets white hats share and job-hunt
Dark Reading News Analysis: CA Exec: Security Pros Need to Be Unburied From the Org Chart - 4/14/2008 6:00:00 PM
To succeed, IT security must raise its profile in the business, says former CIO
Dark Reading News Analysis: Who Killed My Hard Drive? - 5/6/2008 5:45:00 PM
University study examines the causes and costs of hard drive failure
Dark Reading News Analysis: Securing the Internet's DNS - 4/24/2008 5:30:00 PM
Internet's .arpa, .org, and .uk domains soon to adopt DNSSEC
Dark Reading News Analysis: Ex-Feds Start Up ID Theft Protection Service - 5/7/2008 6:00:00 PM
iSekurity promises to find out who stole your identity – or pay you $11,000
Dark Reading News Analysis: Tech Insight: Finding & Prioritizing Web Application Vulnerabilities - 5/9/2008 5:15:00 PM
Web app flaws are rapidly becoming the most serious threat to your data. Do you know how to identify them – and which ones to fix first?
Dark Reading News Analysis: Market's Message to Security Pros: Adapt or Die - 4/23/2008 9:30:00 AM
Shifts in economy, business are forcing re-prioritization in the IT security department, studies say
Dark Reading News Analysis: 'Provider-in-the-Middle Attacks' Put Major Websites, Users at Risk - 4/21/2008 9:58:00 AM
Researchers discover that ad servers from over 70 ISPs, such as Earthlink and Comcast, put trademarked sites – and users who visit them – at risk of cross-site scripting, other attacks
Dark Reading News Analysis: When Bots Don't Care - Or Don't Know Enough to - 4/30/2008 3:40:00 PM
Misguided apathy among consumers could be contributing to botnet proliferation
Dark Reading News Analysis: RSA: Hashing Out Encryption - 4/14/2008 5:50:00 PM
Vendors at RSA 2008 rolled out tools that make encryption easier to use and manage
Dark Reading News Analysis: Wireless Vulnerabilities Present Enterprise-Wide Threats, Expert Says - 4/28/2008 5:40:00 PM
Wireless is the greatest threat to corporate networks since the emergence of the Internet, AirPatrol CEO says
Dark Reading News Analysis: Large Businesses Wrestle With Web 2.0 - 4/30/2008 6:15:00 PM
New capabilities turn security policies and practices on end, panelists say
NATO Members Form Cyber Defense Center
Third Wave of Web Attacks Not the Last
Laptop Thieves Outfoxed by Savvy Apple User
MORE KEYHOLE
ENTERPRISE VULNERABILITIES
Vulnerability: DeluxeBB DeluxeBB
Published: 2008-05-14
Severity: HIGH
Description: sql injection
vulnerability in forums.php
in deluxebb 1.2 and earlier
allows remote attackers to
execute arbitrary sql
commands via the sort
parameter.

Vulnerability: scorpnews scorpnews
Published: 2008-05-14
Severity: HIGH
Description: php remote
file inclusion vulnerability
in example.php in thomas
gossmann scorpnews 2.0
allows remote attackers to
execute arbitrary php code
via a url in the site
parameter.

Vulnerability: ITCMS ITCMS
Published: 2008-05-14
Severity: HIGH
Description: static code
injection vulnerability in
box/minichat/boxpop.php in
it!cms (aka itcms) 1.9
allows remote attackers to
inject arbitrary php code
into
box/minichat/data/shouts.php
via the shout parameter.

Vulnerability: PostNuke Software Foundation pnEncyclopedia
Published: 2008-05-14
Severity: MEDIUM
Description: sql injection
vulnerability in the
pnencyclopedia module 0.2.0
and earlier for postnuke
allows remote attackers to
execute arbitrary sql
commands via the id
parameter in a display_term
action to index.php.

Vulnerability: romedchim_international_srl online_rent_property_script
Published: 2008-05-14
Severity: HIGH
Description: sql injection
vulnerability in index.php
in online rent (aka online
rental property script) 4.5
and earlier allows remote
attackers to execute
arbitrary sql commands via
the pid parameter.

POWERFUL INFORMATION
AT YOUR FINGERTIPS
(SPONSORED LINKS)
Application scanning  |  Application Security  |  Attacks / Exploits / Threats  |  Authentication  |  Botnets  |  Browser security  |  Computer crime  |  Consultants  |  DOS  |  Encryption  |  Hashing algorithms  |  Host Protection  |  Identity management  |  Industry Trends   |  Key management  |  Law enforcement  |  Legal & Regulatory Topics  |  Legislation  |  Malware  |  Market Research  |  Messaging Security  |  Microsoft  |  Penetration testing  |  Penetration testing  |  Perimeter Security  |  Phishing  |  Policy management  |  RSA  |  Security Administration / Management  |  Security Industry  |  Security Services  |  Social engineering  |  Spam  |  Spyware  |  SQL injection  |  Storage Security  |  Stored data losses  |  Symantec  |  Trojans  |  User privacy  |  Viruses  |  Vulnerabilities  |  Vulnerability assessment  |  Vulnerability management  |  Vulnerability Management  |  Web application firewall  |  Web services security  |  Wireless security  |  WLANs  |  Worms
Dark Reader Weekly Newsletter
Dark Reading Daily Newsletter
MORE INFO
Copyright © 2008 United Business Media LLC - All rights reserved.
RSS FEED  |   ARCHIVE  |   FREE NEWSLETTER  |   ORDER REPRINTS  |   ADVERTISE WITH US  |   TECHWEB  |   CONTACT US  |   USER PREFERENCES  |   HELP
Companies
3Com (15), Aventail (7), CA (16), Check Point (29), Cisco (140), Enterasys (5), F-Secure (8), F5 (5), HP (16), IBM (122), Intel (6), ISS (35), Juniper (36), Alcatel-Lucent (2), McAfee (162), Microsoft (1129), NetIQ (2), Nokia (3), Nortel (6), Oracle (41), Qualys (2), RSA (62), Secure Computing (18), Sun (9), Symantec (277), Trend Micro (26), VeriSign (33)

Application and Perimeter Security
802.11x (46), Anomaly detection (74), Anti-spam (136), Application quality assurance (27), Application scanning (139), Auditing (27), AVDL (1), Buffer overflows (101), CERT (7), Consultants (205), Cross-site scripting (159), CVE (7), Database encryption (53), Digital vaults (8), DOS (188), EAP/LEAP (1), Email gateways (191), Encryption (125), Filtering (50), Firewalls (293), FIRST (1), HIPAA (101), Host-based IDS (45), Host/server configuration (16), Host/server encryption (9), IDS (14), IDS (164), IM (69), IPS (264), ISO 17799 (8), Key management (63), Least-privilege user (46), License management (30), Malware (1237), NAC (274), Network IDS (34), NIST (16), OWASP (10), OWASP (14), Patch management (288), PCI (185), Penetration testing (191), Phishing (616), PKI (44), Rootkits (104), SAML (2), Software metering (3), Source-code auditing (73), SOX (85), SSL (172), Systems integrators (8), VPNs (247), Vulnerability assessment (688), Web App Security Consortium (8), Web App Security Consortium (17), Web application firewall (84), Web services security (528), WLANs (343), Worms (268), WPA (15), XML (27)

Desktop Security
Anti-spam (136), Antivirus (339), Application Security (1006), Attacks / Exploits / Threats (2412), Authentication (833), Browser security (674), Digital certificates (58), Digital signatures (44), Disk encryption (54), DRM (51), Encryption (570), File/folder encryption (35), Identity management (320), IM (69), Malware (1237), Messaging Security (484), PGP (5), Phishing (616), Rootkits (104), S/MIME (2), Security Administration / Management (1573), Social engineering (323), Spam (649), Spyware (250), Tokens (67), Trojans (333), User privacy (1374), Viruses (355), VOIP security (113), Vulnerabilities (2746), Vulnerability Management (398), Worms (268)

Discovery and management
Anomaly detection (74), Application scanning (139), AVDL (1), Black Hat (108), COBIT (8), Consultants (205), Content filtering (162), CVE (7), End-user monitoring (239), Filtering (50), FISMA (19), HIPAA (101), Host intrusion prevention (105), Host-based IDS (45), IDS (164), IDS (14), IPS (264), ISACA (1), ISO 17799 (8), Log aggregation (51), Network IDS (34), OWASP (10), OWASP (14), PCI (185), Penetration testing (191), Penetration testing (177), SAML (2), SIM/SEM (194), Source-code auditing (73), SOX (85), Vulnerability assessment (688), Vulnerability management (772), Web App Security Consortium (8)

Host security
802.11x (46), Application quality assurance (27), Authentication (833), Backup security (64), Biometrics (152), Buffer overflows (101), Digital certificates (58), Disk encryption (54), Encryption (570), End-user monitoring (239), HIPAA (101), Host anti-spam (77), Host anti-spyware (100), Host antivirus (109), Host intrusion prevention (105), Host Protection (467), Host-based IDS (45), Host/server configuration (16), Host/server encryption (9), Host/server patching (10), IDS (14), IEEE (4), ISO 17799 (8), Least-privilege user (46), License management (30), NAC (274), P2P management (28), Patch management (288), PGP (14), Port control (12), Single sign-on (66), Smart cards (76), Software metering (3), SOX (85), Systems integrators (8), TCG (18), Tokens (67), User privacy (1374), Vulnerability Management (398), WPA (15)

Security services
Agency application (2), Application quality assurance (27), Application scanning (139), AVDL (1), COBIT (8), Consultants (205), FISMA (19), HIPAA (101), ISO 17799 (8), Managed services (293), PCI (185), Penetration testing (177), PKI (44), Policy management (440), SIM/SEM (194), Source-code auditing (73), SOX (85), Systems integrators (8)

Storage Security
AES (11), Backup security (64), COBIT (8), Database encryption (53), DES (3), Digital vaults (8), Disk encryption (54), Encryption (125), File/folder encryption (35), FIPS-140-2 (1), FISMA (19), Hashing algorithms (15), HIPAA (101), Host/server encryption (9), Identity management (101), ISO 17799 (8), Key management (63), Law enforcement (928), Legislation (289), Offsite backup (26), PCI (185), PKI (44), SOX (85), Stored data losses (308), Systems integrators (8), Triple DES (3), User privacy (1374)

Wireless Security
802.11x (46), AES (11), Auditing (27), COBIT (8), Credential service provider (8), DES (3), Digital certificates (58), Digital signatures (44), DOS (188), EAP/LEAP (1), FISMA (19), Hashing algorithms (15), HIPAA (101), Host/server encryption (9), IEEE (4), IETF (10), ISO 17799 (8), Key management (63), NAC (274), Network IDS (34), PCI (185), Penetration testing (177), PKI (44), Port control (12), Tokens (67), Triple DES (3), VPNs (247), Vulnerability assessment (688), WLANs (343), WPA (15)