Microsoft has released a patch that eliminates a security vulnerability in web applications associated with Microsoft® Site Server 3.0, Commerce Edition. These applications are provided as samples and generated by wizards, but do notfollow security best practices. If deployed on a web site, they could allow inappropriate access to a database on the site. Two sample web sites provided as part of Site Server 3.0, Commerce Edition do not follow security best practices;the code generated by one of the wizards is affected by the same problem. The code requests an identification number as one of the inputs, but does not validate it before using it ina database query. As a result, a malicious user could, instead of entering an appropriate input, provide SQL commands. If this were done, the SQL commands would be executed as part of the query, and could be used to create, modify, delete or read data in the database. The vulnerability only affects sites that have either deployed the code at issue here, or have used the code as a model for developingcustom code. Customers who have deployed the code should apply the patch to ensure that security best practices are followed.
The VirtuaRAID is advanced RAID array application for software RAID solutions.
With VirtuaRAID you can consolidate up to 5 files in one virtual disk,...
If a specially-malformed TDS packet is sent to a SQL server, it can cause the SQL service to crash. This vulnerability would not allow any inappropria...
This is a buffer overrun vulnerability. A malicious user could exploit this vulnerability in either of two ways. In the simplest case, he or she could...
This is a buffer overrun vulnerability. A malicious user could exploit this vulnerability in either of two ways. In the simplest case, he or she could...
Microsoft Security Bulletin MS00-012 announces the availability of a patch that eliminates a vulnerability in Microsoft Systems Management Server (SMS...
Microsoft has released a patch and a tool that eliminate a security vulnerability in Microsoft® Windows® 2000. The vulnerability could make it easier ...
The HyperTerminal application is a utility that installs, by default, on all versions of Windows 98, 98SE, Windows ME, Windows NT, and Windows 2000. T...
The Microsoft IPX/SPX protocol implementation (NWLink) includes an NMPI (Name Management Protocol on IPX) listener that will reply to any requesting n...
Microsoft Windows 95 provides a password protection feature referred to as (share level access) for the File and Print Sharing service. However, due t...
The HyperTerminal application is a utility that installs, by default, on all versions of Windows 98, 98SE, Windows ME, Windows NT, and Windows 2000. T...