Computer Security
[EN] securityvulns.ru
no-pyccku



Web applications security vulnerabilities (PHP, ASP, CGI, Perl, etc)
updated since 08.08.2005
Published:14.08.2005
Source:
SecurityVulns ID:5078
Type:remote
Level:5/10
Description:PHP inclusions, SQL injections, directory traversals, crossite scripting, information leaks, etc.
Affected:OPENBB : OpenBB 1.0
 OPENBB : OpenBB 1.1
 INVISION : Invision Power Board 2.0
 XMB : XMB 1.9
 AWSTATS : AWStats 6.3
 PHPOPENCHAT : PhpOpenChat 3.0
 WORDPRESS : WordPress 1.5
 MYBB : MyBB 1.0
 SIMPLEPHPBLOG : SimplePHPBlog 0.4
 BLOGTORRENT : BlogTorrent 0.92
 E107 : e107 0.6171
 INVISION : Invision Power Board 1.0
 SYSCP : SysCP 1.2
 GRAVITYBOARDX : Gravity Board X 1.1
 CFBB : CFBB 1.1
 MYFAQ : MYFAQ 1.0
 TDIARY : tDiary 2.1
 PHPINCLUDES : phpIncludes News System 1.0
 FUNKBOARD : FunkBoard 0.66
 PHPLITE : Calendar Express 2.0
 XMBFORUM : XMB Forum 1.9
 XOOPS : XOOPS 2.2
 CHIPMUNK : Chipmunk Forum 1.3
 PHLYMAIL : PHlyMail 3.02
 CPANEL : cPanel 10.4
 OMNIPILOT : Lasso 8.0
 VEGADNS : VegaDNS 0.9
 EQDKP : EQdkp 1.2
 CALOGIC : CaLogic 1.22
 GALLERY : Gallery 1.5
 FUDFORUM : Fud Forum 2.6
 CLAROLINE : Claroline 1.6
 PHPDESIGNER : PHP Designer 2005 3.0
 BLOODSHED : Bloodshed Dev-Pascal 1.9
 DEVPHP : Dev-PHP 2.0
 PHPTB : Topic Boards 2.0
 EZ : ezUpload 2.2
Original documentdocumentSECURITEAM, [UNIX] Blog Torrent Remote User and Password Disclosure (14.08.2005)
 documentSECURITEAM, [EXPL] SimplePHPBlog Password Disclosure (Exploit) (14.08.2005)
 documentSECURITEAM, [EXPL] ezUpload path Parameter Command Execution (Exploit) (14.08.2005)
 documentalmaster_(at)_hotmail.com, SQL in PHPTB Topic Boards 2.0 (14.08.2005)
 documentSECUNIA, [SA16420] Dev-PHP NULL Character File Display Weakness (13.08.2005)
 documentSECUNIA, [SA16422] Bloodshed Dev-Pascal NULL Character File Display Weakness (13.08.2005)
 documentSECUNIA, [SA16398] PHP Designer 2005 NULL Character File Display Weakness (13.08.2005)
 documentlaurent gaffié, Xoops 2.2.1 Full Path Disclosure (12.08.2005)
 documentphuket, [Full-disclosure] My Bulletin Board RC 4 Vulnerabilities (12.08.2005)
 documentAlexander Heidenreich, [Full-disclosure] Fudforum: incompletely check of user rights in tree view gaining access to all messages (12.08.2005)
 documentSECUNIA, [SA16377] MidiCart ASP Shopping Cart SQL Injection Vulnerability (11.08.2005)
 documentSECUNIA, [SA16389] Gallery PostNuke Integration Security Issue (11.08.2005)
 documentgb.network_(at)_gmail.com, Full path disclosure in CaLogic 1.22 and possible in older versions. (10.08.2005)
 documentSECUNIA, [SA16285] EQdkp session.php Session Handling Vulnerability (10.08.2005)
 documentSECUNIA, [SA16370] VegaDNS "message" Cross-Site Scripting Vulnerability (10.08.2005)
 documentSECUNIA, [SA16364] Lasso Professional Auth Tag Security Bypass Vulnerability (10.08.2005)
 documentSECUNIA, [SA16362] cPanel Password Change Privilege Escalation Security Issue (10.08.2005)
 documentSECUNIA, [SA16375] XMB Forum Server Set Variable Overwrite and SQL Injection (10.08.2005)
 documentSECUNIA, [SA16388] PHlyMail Unspecified Login Bypass Vulnerability (10.08.2005)
 documentSECUNIA, [SA16365] Chipmunk Forum "fontcolor" Cross-Site Scripting Vulnerability (09.08.2005)
 documentSECUNIA, [SA16357] e107 HTML / TXT Attachment Script Insertion Vulnerability (09.08.2005)
 documentSECUNIA, [SA16348] Invision Power Board HTML / TXT Attachment Script Insertion (09.08.2005)
 documentSECUNIA, [SA16339] XOOPS PHPMailer and XML-RPC Vulnerabilities (09.08.2005)
 documentheintz_(at)_hotmail.com, Sql injection and global variables poisoning in XMB Forum 1.9.1 (09.08.2005)
 documentIDEFENSE, [Full-disclosure] iDEFENSE Security Advisory 08.09.05: AWStats ShowInfoURL Remote Command Execution Vulnerability (09.08.2005)
 documentretrogod_(at)_aliceposta.it, FunkBoard V0.66CF (possibly prior versions) cross site scripting, possible database username/password disclosure & board takeover,possible remote code execution (09.08.2005)
 documentSECUNIA, [SA16353] PHPLite Calendar Express Two Vulnerabilities (09.08.2005)
 documentSECUNIA, [SA16371] FunkBoard Multiple Cross-Site Scripting Vulnerabilities (09.08.2005)
 documentSECUNIA, [SA16351] phpIncludes News System SQL Injection Vulnerability (09.08.2005)
 documentSECUNIA, [SA16329] tDiary Cross-Site Request Forgery Vulnerability (09.08.2005)
 documentsvt_(at)_svt.nukleon.us, [SVadvisory#13] - SQL injection in MYFAQ 1.0 (09.08.2005)
 documentstormhacker_(at)_hotmail.com, XSS in forums CFBB v1.1.0 (09.08.2005)
 documentedward11_(at)_postmaster.co.uk, E107 + IPB XSS Exploit (09.08.2005)
 documentabducter_minds_(at)_yahoo.com, SQL IN Open Bulletin Board (09.08.2005)
 documentretrogod_(at)_aliceposta.it, Gravity Board X v1.1 multiple vulnerabilities (09.08.2005)
 documentChristopher Kunz, [Full-disclosure] Advisory 13/2005: Remote code execution in SysCP (08.08.2005)
Files:EzUpload 2.2 Remote Command Execution
Discuss:Read or add your comments to this news (0 comments)

About | Terms of use | Privacy Policy
© SecurityVulns, 3APA3A, Vladimir Dubrovin
Nizhny Novgorod

 
 



Rating@Mail.ru
test server