|
| Daily web applications security vulnerabilities summary (PHP, ASP, JSP, CGI, Perl) | | Published: |  | 25.05.2006 | | Source: |  | BUGTRAQ | | SecurityVulns ID: |  | 6178 | | Type: |  | remote | | Level: |  | 5/10 | | Description: |  | PHP inclusions, SQL injections, directory traversals, crossite scripting, information leaks, etc. |
| Affected: |  | MAMBOSERVER : Mambo Server 4.6 | | |  | PHPNUKE : PHP-Nuke 7.9 | | |  | OPENCMS : OpenCms 6.0 | | |  | DSCHAT : DSChat 1.0 | | |  | IPLOGGER : IpLogger 1.7 | | |  | QB : QB 14 | | |  | SKYESHOUTBOX : SkyeShoutbox 1.2 | | |  | PHPMYDIRECTORY : phpMyDirectory 10.4 | | |  | ALSTRASOFT : Article Manager Pro 1.6 | | |  | DGBOOK : DGbook 1.0 | | |  | ALSTRASOFT : Web Host Directory 1.2 | | |  | PUBLICIST : Publicist 0.95 | | |  | DRUPAL : Drupal 4.7 | | |  | FRONTRANGE : iHEAT 8.3 |
| Original document |  | SECUNIA, [SA20165] FrontRange iHEAT Host System Access Vulnerability (25.05.2006) |
| |  | jaime.blasco_(at)_eazel.es, OpenCms version 6.0.x Xml Content Demo search engine Cross site scripting (25.05.2006) |
| |  | a_linuxer_(at)_yahoo.com, Diesel Joke Site SQL INJECTION (25.05.2006) |
| |  | Breeeeh_(at)_hotmail.com, YLZH(right.php)Cross Site Scripting (25.05.2006) |
| |  | rgod_(at)_autistici.org, Mambo <= 4.6. RC1 xss (25.05.2006) |
| |  | luny_(at)_youfucktard.com, Publicist v0.95 - XSS And Full Path Errors (25.05.2006) |
| |  | luny_(at)_youfucktard.com, AlstraSoft Web Host Directory v1.2 (25.05.2006) |
| |  | luny_(at)_youfucktard.com, Alstrasoft Article Manager Pro v1.6 (25.05.2006) |
| |  | luny_(at)_youfucktard.com, AlstraSoft E-Friends - XSS (25.05.2006) |
| |  | ajannhwt_(at)_hotmail.com, phpMyDirectory <= 10.4.4 Multiple Remote File Include(new!) (25.05.2006) |
| |  | zerogue_(at)_gmail.com, SkyeShoutbox <= v.1.2.0 XSS (25.05.2006) |
| |  | zerogue_(at)_gmail.com, Russcom Ping Remote code execution (25.05.2006) |
| |  | zerogue_(at)_gmail.com, Russcom PHPImages lack of validation (25.05.2006) |
| |  | zerogue_(at)_gmail.com, QBv14 XSS (25.05.2006) |
| |  | zerogue_(at)_gmail.com, IpLogger <= 1.7 XSS (25.05.2006) |
| |  | zerogue_(at)_gmail.com, DSChat <= 1.0 XSS (25.05.2006) |
| |  | zerogue_(at)_gmail.com, Chatty improper input sanitizing (25.05.2006) |
| |  | Private Private, PHP - Nuke Recherches Module 7.x Version Cross Site Scripting {!} (25.05.2006) |
| |  | SpiderZ, View Topic Flood phpBB, MercuryBoard, Vbulletin, Ipb (25.05.2006) |
| |  | SpiderZ, View Topic Flood phpBB, MercuryBoard, Vbulletin, Ipb (25.05.2006) |
|
|
|
|
|