Provided and/or discovered by: 1-3) Antonio "s4tan" Parata and Francesco "ascii" Ongaro
4) SEC Consult Vulnerability Lab via a Mantis bug report.
Changelog: 2008-05-19: Added CVE reference.
2008-05-21: Updated advisory with additional information provided by Antonio "s4tan" Parata and Francesco "ascii" Ongaro. Increased "Criticality", changed "Solution" section, "Solution status", and updated credits.
2008-06-17: Added vulnerability #4 to "Description". Updated "Solution" and credits section. Added links to "Original Advisory" section.
2008-07-28: Added CVE reference.
Customers of the Secunia Vulnerability Intelligence solutions will automatically receive updates when new information regarding this advisory is released.
If you have new information regarding this Secunia advisory or a product in our database, please send it to us using either our web form or email us at vuln@secunia.com.
Ideas, suggestions, and other feedback are most welcome.