Computer Security
[EN] securityvulns.ru
no-pyccku



Web applications security vulnerabilities (PHP, ASP, CGI, Perl, etc)
updated since 07.11.2005
Published:11.11.2005
Source:
SecurityVulns ID:5429
Type:remote
Level:5/10
Description:PHP inclusions, SQL injections, directory traversals, crossite scripting, information leaks, etc.
Affected:PHPBB : phpBB 2.0
 ADVANCEDGUESTBOO : Advanced Guestbook 2.3
 VBULLETIN : vBulletin 3.0
 INVISION : Invision Power Board 2.0
 PHORUM : Phorum 5.0
 XMB : XMB 1.9
 PHPKIT : PHPKIT 1.6
 ADVANCEDGUESTBOO : Advanced Guestbook 2.2
 TWIKI : TWiki 20030201
 B2EVOLUTION : b2evolution 0.9
 PHPADSNEW : phpAdsNew 2.0
 PHPSYSINFO : phpSysInfo 2.3
 MOODLE : Moodle 1.5
 CUREPHP : CuteNews 1.4
 IBPROARCADE : ibProArcade 2.0
 INVISION : Invision Power Board 2.1
 OSTE : OSTE 1.0
 PHPLIST : phpList 2.10
 MAGPIERSS : MagpieRSS 0.71
 TONIO : Tonio Gallery 2.4
 TOENDA : toendaCMS 0.6
 TIKIWIKI : tikiwiki 1.9
 ANTVILLE : Antville 1.1
 YABB : YaBB 2.0
 MOODLE : Moodle 1.6
 CAMPSITE : Campsite 2.3
 OCOMON : OcoMon 1.21
 DEVEDITOR : Dev-Editor 3.0
Original documentdocumentSECUNIA, [SA17537] Dev-Editor Virtual Root Directory Restriction Bypass (11.11.2005)
 documentSECUNIA, [SA17470] OcoMon Unspecified SQL Injection Vulnerabilities (11.11.2005)
 documentMaksymilian Arciemowicz, [Full-disclosure] phpBB 2.0.18 SQL Query problem (11.11.2005)
 documentSECUNIA, [SA17441] phpSysInfo "register_globals" Emulation Layer Overwrite Vulnerability (11.11.2005)
 documentSECUNIA, [SA17528] Campsite MySQL Password Exposure Mail Transfer Security Issue (11.11.2005)
 documentSECURITEAM, [UNIX] Community Link Pro Command Execution (login.cgi) (11.11.2005)
 documentIDEFENSE, [Full-disclosure] iDEFENSE Security Advisory 11.10.05: Tikiwiki tiki-user_preferences Command Injection Vulnerability (11.11.2005)
 documentIDEFENSE, [Full-disclosure] iDEFENSE Security Advisory 11.10.05: Tikiwiki tiki-editpage Arbitrary File Exposure Vulnerability (11.11.2005)
 documentretrogod_(at)_aliceposta.it, Moodle <=1.6dev blind SQL Injection (11.11.2005)
 documentToni Koivunen, [FS-05-01] Multiple vulnerabilities in phpAdsNew (11.11.2005)
 documentspyburn mexico rlz, RANKBOX <= XSS vulnerability (11.11.2005)
 documentYABB, [SA17411] YaBB Attachment Script Insertion Vulnerability (10.11.2005)
 documentPreben Nylokken, ASPKnowledgebase vulnerable to XSS injection. (10.11.2005)
 documentPreben Nylokken, ASPKnowledgebase vulnerable to SQL-inject (10.11.2005)
 documentMoritz Naumann, Antville 1.1 Cross Site Scripting (10.11.2005)
 documentMoritz Naumann, Multiple security issues in TikiWiki 1.9.x (10.11.2005)
 documentSECUNIA, [SA17471] toendaCMS Disclosure of Sensitive Information (08.11.2005)
 documentSECUNIA, [SA17453] Tonio Gallery "galid" SQL Injection Vulnerability (08.11.2005)
 documentSECUNIA, [SA17440] b2evolution XML-RPC PHP Code Execution Vulnerabilities (08.11.2005)
 documentSECUNIA, [SA17458] XMB "username" Cross-Site Scripting Vulnerability (08.11.2005)
 documentSECURITEAM, [UNIX] MagpieRSS Remote Command Execution (08.11.2005)
 documentChristopher Kunz, [Full-disclosure] Advisory 21/2005: Multiple vulnerabilities in PHPKIT (08.11.2005)
 documentspyburn mexico rlz, [Full-disclosure] RANKBOX <= XSS vulnerability (08.11.2005)
 documenttk_(at)_trapkit.de, [TKADV2005-11-001] Multiple vulnerabilities in PHPlist (08.11.2005)
 documentbhs_team_(at)_yahoo.com, Advanced Guestbook 2.2 ( SQL Injection Exploit ) (08.11.2005)
 documentGeekZ_(at)_WorldDefacers.net, TWiki 20030201 VIEW string remote command execution (08.11.2005)
 documentJerome ATHIAS, Invision Power Board 2.1 : Multiple XSS Vulnerabilities (08.11.2005)
 documentGeekZ_(at)_WorldDefacers.net, upload phpshell in PHPFM (08.11.2005)
 documentpoizon_(at)_securityinfo.ru, Path disclosure in CuteNews <= 1.4.0 (08.11.2005)
 documentkhc_(at)_bsdmail.org, OSTE v1.0 Remote Command Exucetion (08.11.2005)
 documentDaniel Fabian, [Full-disclosure] SEC Consult SA-20051107-0 :: toendaCMS multiple vulnerabilites (07.11.2005)
 documentsikikmail_(at)_gmail.com, Zoomblog HTML Injection Vulnerability (07.11.2005)
 documentJanek Vind, [waraxe-2005-SA#043] - Sql injection in Phorum 5.0.20 and earlier (07.11.2005)
 documentbenjilenoob_(at)_hotmail.com, Failles dans Invision Power Board 2.1 [xss] (07.11.2005)
 documents2b_(at)_hotmail.com, Xss - Html injection in XMB (07.11.2005)
 documentAnti Matter, Invision Power Board Privilege Esaclation (2.0.1 + more) (07.11.2005)
 documentsikikmail_(at)_gmail.com, Zoomblog <IMG> BBCode Tag JavaScript Injection Vulnerability (07.11.2005)
 documentbhfh01_(at)_gmail.com, Sql injection in ibProArcade (07.11.2005)
 documentАгиевич Игорь aka Shanker, Баг в vBulletin 3.x (07.11.2005)
Files:Moodle <= 1.6dev get record() SQL injection / remote commands execution
Discuss:Read or add your comments to this news (0 comments)


Show Threads
Messages
 
Login:* (Register)
Password:*
(private) To:
(reply) Subject:*
Text:

Main Forum (Eng)

General security questions not appropriate for another forums.
3proxy Forum (Eng)

All 3proxy question must be posted to this forum.
Bugs, Vulnerabilities, PoCs and Exploits (Eng)

All vulnerability related questions, vulnerability digging and exploit creation.
Windows programming and administration (Eng)

Administering Windows and application development.
Unix programming and administation (Eng)

Administering Unix and application development.
Test forum

Please post all test messages here. All test messages from different forums will be deteted.
Main Forum (Rus)
3proxy Forum (Rus)
Bugs, Vulnerabilities, PoCs and Exploits (Rus)
Windows programming and administration (Rus)
Unix programming and administation (Rus)
About | Terms of use | Privacy Policy
© SecurityVulns, 3APA3A, Vladimir Dubrovin
Nizhny Novgorod

 
 



Rating@Mail.ru