Version 2

Vulnerability Report Status

This page is intended as a cross reference to vulnerability reports on othe sites

Created by: Lester Caine, Last modification: 10 Dec 2008 (07:48 UTC) by Lester Caine
In order to address the number of outstanding vulnerability reports visible on the network, it is intended that this page will list identified reports, provide links to them, and identify their current status. In a large number of cases, the reports are simply clones of one another and in many cases there is insufficient information to verify them, but often it is impossible to get the report updated to reflect the current status.
Bitweaver has the interesting problem of being able to install a sub-set of available facilities, and select tools and formats to be used, so while some reports may well be valid on one site, other sites may not have the same packages enabled. Sites configured only to allow tikiwiki syntax will not be affected by html vulnerabilities for instance. The first stopping place for assessing security is Security and any recommendations for improving a sites security should be documented there.
Why we need quite so many duplicate copies of these reports seems somewhat of a last of time, and where reports from 2006 are STILL marked as 'under review', perhaps these sites need to cull material that they do not want to manage? I suspect that we need to identify two or three original report sites and simply track them. CVE and it's copy at NVD seem to be the most comprehensive listing.

DateSiteLink to ReportStatusNotes
Undated 2006CVECVE-2006-3103 Version 1.3 - superseded by Version 2
Undated 2007CVECVE-2007-6374 Multiple Cross-site Scripting Vulnerabilities
Undated 2007CVECVE-2007-6375 SQL Injection Vulnerabilities
Undated 2007CVECVE-2007-6412 Code Injection into content
7th Dec 2007HSC-ResearchWas 28129Fixed R2.1Bitweaver Cross-Site Scripting
9th Dec 2007XForce39129Duplicatesee HSC 7th Dec 2007
9th Dec 2007XForce39130Duplicatesee HSC 7th Dec 2007
9th Dec 2007XForce38943Fixed R2.1
10th Dec 2007Secunia28024DuplicateQuoted original advisory no longer available - see HSC 7th Dec 2007
10th Dec 2007securityfocus26801Duplicatesee HSC 7th Dec 2007
9th Dec 2007osvdb26801Duplicatesee HSC 7th Dec 2007
11th Dec 2007securityreason3428Duplicate see HSC 7th Dec 2007
11th Dec 2007Vupen2007/4168Duplicatesee HSC 7th Dec 2007
30th Dec 2007AmnPardaz4814 Not sure file upload problem is valid?
25th Sept 2008Secunia32014Fixed R2.1Multiple Cross-site Scripting Vulnerabilities
25th Sept 2008XForce45409Fixed R2.1
28th Sept 2008securityfocus31395 Nothing identified to test
Undated 2008CVECVE-2008-4337Fixed R2.1Multiple Cross-site Scripting Vulnerabilities


Outstanding search results
CVE Listing 18 entries back to 2005 - mainly XSS
Secunia Listing 7 entries sub set of CVE
XForce (IBM ISS) Listing 19 entries - not spotted the extra one over CVE
Page History
Date/CommentUserIPVersion
17 May 2009 (01:51 UTC)
spiderr71.77.29.2316
Current • Source
Lester Caine81.138.11.1365
View • Compare • Difference • Source
Lester Caine81.138.11.1364
View • Compare • Difference • Source
laetzer141.20.150.433
View • Compare • Difference • Source
Lester Caine81.138.11.1362
View • Compare • Difference • Source