|
| Daily web applications security vulnerabilities summary (PHP, ASP, JSP, CGI, Perl) | | Published: |  | 10.08.2007 | | Source: |  | | | SecurityVulns ID: |  | 8026 | | Type: |  | remote | | Level: |  | 5/10 | | Description: |  | PHP inclusions, SQL injections, directory traversals, crossite scripting, information leaks, etc. |
| Affected: |  | COPPERMINE : Coppermine Photo Gallery 1.3 | | |  | PHPMYADMIN : phpMyAdmin 2.10 | | |  | STORESPRITE : Storesprite 7 | | |  | MAPOSSCRIPTS : File Uploader 1.1 | | |  | MAPOSSCRIPTS : Web News 1.1 | | |  | MAPOSSCRIPTS : Bilder Uploader 1.3 | | |  | MAPOSSCRIPTS : Mapos Bilder Galerie Version 1.0 | | |  | MAPOSSCRIPTS : Gästebuch 1.5 | | |  | IDEVSPOT : PhpHostBot 1.06 | | |  | SHOUTBOX : Shoutbox 1.0 |
| Original document |  | okan alp, CA.View/view-law.asp/view-info.asp sql injection (10.08.2007) |
| |  | okan alp, Education_info/edu_view.asp sql injection (10.08.2007) |
| |  | rizgar_(at)_linuxmail.org, Shoutbox 1.0 Remote Command Execution Vulnerability (10.08.2007) |
| |  | master-of-desastor_(at)_hotmail.com, Coppermine Photo Gallery (yabbse.inc.php) Remote File Inclusion Vulnerability (10.08.2007) |
| |  | Advisory_(at)_Aria-Security.net, [Aria-Security.net] SAS Hotel Management System SQL Injection (10.08.2007) |
| |  | erdc_(at)_echo.or.id, [ECHO_ADV_83$2007] PhpHostBot <= 1.06 (svr_rootscript) Remote File Inclusion Vulnerability (10.08.2007) |
| |  | rizgar_(at)_linuxmail.org, Web News 1.1 Remote Command Execution Vulnerability (10.08.2007) |
| |  | rizgar_(at)_linuxmail.org, Bilder Uploader 1.3 Remote Command Execution Vulnerability (10.08.2007) |
| |  | rizgar_(at)_linuxmail.org, Mapos Bilder Galerie Version 1.0 Remote Command Execution Vulnerability (10.08.2007) |
| |  | rizgar_(at)_linuxmail.org, Gstebuch Version 1.5 Remote Command Execution Vulnerability (10.08.2007) |
| |  | rizgar_(at)_linuxmail.org, File Uploader Version 1.1 Remote Command Execution Vulnerability (10.08.2007) |
| |  | rizgar_(at)_linuxmail.org, FinDix Remote File Inclusion Vulnerability (10.08.2007) |
| |  | r0t, phpMyAdmin multiple XSS vuln. (10.08.2007) |
| |  | r0t, Storesprite XSS vuln. (10.08.2007) |
|
|
|
|
|