Computer Security
[EN] securityvulns.ru
no-pyccku



Daily web applications security vulnerabilities summary (PHP, ASP, JSP, CGI, Perl)
Published:21.08.2007
Source:
SecurityVulns ID:8071
Type:remote
Level:5/10
Description:PHP inclusions, SQL injections, directory traversals, crossite scripting, information leaks, etc.
Affected:MCLINKSCOUNTER : mcLinksCounter 1.2
 MYREFERER : My_REFERER 1.08
 BUTTERFLY : Butterfly online vistors counter 1.08
 GURURHABER : Gurur Portal 2.0
 JOOMLA : SimpleFAQ 2.11
CVE:CVE-2007-4486 (Multiple PHP remote file inclusion vulnerabilities in index.php in Linkliste 1.2 allow remote attackers to execute arbitrary PHP code via a URL in the (1) styl[top], (2) url_eintrag, or (3) styl[themen] parameter.)
 CVE-2007-4484 (PHP remote file inclusion vulnerability in login.php in My_REFERER 1.08 allows remote attackers to execute arbitrary PHP code via a URL in the value parameter.)
 CVE-2007-4479 (Cross-site scripting (XSS) vulnerability in search.html in Search Engine Builder allows remote attackers to inject arbitrary web script or HTML via the searWords parameter.)
 CVE-2006-4863 (** DISPUTED ** Multiple PHP remote file inclusion vulnerabilities in Marc Cagninacci mcLinksCounter 1.1 allow remote attackers to execute arbitrary PHP code via a URL in the langfile parameter in (1) login.php, (2) stats.php, (3) detail.php, or (4) erase.php. NOTE: CVE and a third party dispute this vulnerability, because the langfile parameter is set to english.php in each file.)
Original documentdocumentI. D., [Full-disclosure] OSNews (21.08.2007)
 documentHackers Center Security Group, Invision Power Board D22-Shoutbox HTML Injections (21.08.2007)
 documentk1tk4t_(at)_newhack.org, Mambo Component SimpleFAQ V2.11 - Remote SQL Injection (21.08.2007)
 documentthe.dumenci_(at)_gmail.com, Gurur Haber v2.0 (21.08.2007)
 documentIvan Niiiil, My_REFERER v.1.08 Remote File Include (21.08.2007)
 documentIvan Niiiil, Butterfly online vistors counter 1.08 RFI (21.08.2007)
 documentIvan Niiiil, mcLinksCounter 1.2 Remote File Include by iNs (21.08.2007)
 documentMustLive, Vulnerability in Search Engine Builder (21.08.2007)
Discuss:Read or add your comments to this news (0 comments)


Show Threads
Messages
 
Login:* (Register)
Password:*
(private) To:
(reply) Subject:*
Text:

Main Forum (Eng)

General security questions not appropriate for another forums.
3proxy Forum (Eng)

All 3proxy question must be posted to this forum.
Bugs, Vulnerabilities, PoCs and Exploits (Eng)

All vulnerability related questions, vulnerability digging and exploit creation.
Windows programming and administration (Eng)

Administering Windows and application development.
Unix programming and administation (Eng)

Administering Unix and application development.
Test forum

Please post all test messages here. All test messages from different forums will be deteted.
Main Forum (Rus)
3proxy Forum (Rus)
Bugs, Vulnerabilities, PoCs and Exploits (Rus)
Windows programming and administration (Rus)
Unix programming and administation (Rus)
About | Terms of use | Privacy Policy
© SecurityVulns, 3APA3A, Vladimir Dubrovin
 



Рейтинг@Mail.ru