Computer Security
[EN] securityvulns.ru
no-pyccku



Daily web applications security vulnerabilities summary (PHP, ASP, JSP, CGI, Perl)
Published:20.10.2007
Source:
SecurityVulns ID:8277
Type:remote
Level:5/10
Description:PHP inclusions, SQL injections, directory traversals, crossite scripting, information leaks, etc.
Affected:ZOPH : zoph 0.3
 RELOADCMS : ReloadCMS 1.2
 SITEBAR : SiteBar 3.3
 ZOPH : zoph 0.6
 ZOPH : zoph 0.7
 ALCATEL : Omnivista 4760
 ARESKI : Areski 2.0
 FREEPBX : FreePBX 2.3
 TRIBOX : Tribox 2.3
 SIMPLEMACHINES : Simple Machines Forum 1.3
CVE:CVE-2007-5695 (command.php in SiteBar 3.3.8 allows remote attackers to redirect users to arbitrary web sites via the forward parameter in a Log In action.)
 CVE-2007-5694 (Absolute path traversal vulnerability in the translation module (translator.php) in SiteBar 3.3.8 allows remote authenticated users to read arbitrary files via an absolute path in the dir parameter, a different vulnerability than CVE-2007-5491.)
 CVE-2007-5693 (Eval injection vulnerability in the translation module (translator.php) in SiteBar 3.3.8 allows remote authenticated users to execute arbitrary PHP code via the edit parameter in an upd cmd action, a different vulnerability than CVE-2007-5492.)
 CVE-2007-5692 (Multiple cross-site scripting (XSS) vulnerabilities in SiteBar 3.3.8 allow remote attackers to inject arbitrary web script or HTML via (1) the lang parameter to integrator.php; (2) the token parameter in a New Password action, (3) the nid_acl parameter in a Folder Properties action, or (4) the uid parameter in a Modify User action to command.php; or (5) the target parameter to index.php, different vectors than CVE-2006-3320.)
 CVE-2007-5492 (Static code injection vulnerability in the translation module (translator.php) in SiteBar 3.3.8 allows remote authenticated users to execute arbitrary PHP code via the value parameter.)
 CVE-2007-5491 (Directory traversal vulnerability in the translation module (translator.php) in SiteBar 3.3.8 allows remote authenticated users to chmod arbitrary files to 0777 via ".." sequences in the lang parameter.)
 CVE-2007-3905 (SQL injection vulnerability in Zoph before 0.7.0.1 might allow remote attackers to execute arbitrary SQL commands via the _order parameter to (1) photos.php and (2) edit_photos.php.)
 CVE-2006-3320 (Cross-site scripting (XSS) vulnerability in command.php in SiteBar 3.3.8 and earlier allows remote attackers to inject arbitrary web script or HTML via the command parameter.)
Original documentdocumentsekuru_(at)_email.ua, ReloadCMS Vulnerable (20.10.2007)
 documentth3.r00k.spammenot_(at)_gmail.com, Simple Machines Forum multiple sql injection flaws with exploit code. (20.10.2007)
 documentAdvisory_(at)_Aria-Security.net, [Aria-Security.Net] SearchSimon Lite Cross-Site Scripting Vuln. (20.10.2007)
 documentRadu State, [Full-disclosure] XSS and SQL injection via SIP (part 2) and toll fraud bonus (20.10.2007)
 documentlabs_(at)_s21sec.com, S21SEC-038-en: Alcatel Omnivista 4760 Cross-Site Scripting (20.10.2007)
 documentAdvisory_(at)_Aria-Security.net, A-Cart SQL Injection And Cross-Site Scripting (20.10.2007)
 documentTim Brown, Serious holes affecting SiteBar 3.3.8 (20.10.2007)
 documentDEBIAN, [SECURITY] [DSA 1389-1] New zoph packages fix SQL injection (20.10.2007)
Files:SMF 1.1.3 Extremely fast Blind SQL Injection Exploit
Discuss:Read or add your comments to this news (0 comments)


Show Threads
Messages
 
Login:* (Register)
Password:*
(private) To:
(reply) Subject:*
Text:

Main Forum (Eng)

General security questions not appropriate for another forums.
3proxy Forum (Eng)

All 3proxy question must be posted to this forum.
Bugs, Vulnerabilities, PoCs and Exploits (Eng)

All vulnerability related questions, vulnerability digging and exploit creation.
Windows programming and administration (Eng)

Administering Windows and application development.
Unix programming and administation (Eng)

Administering Unix and application development.
Test forum

Please post all test messages here. All test messages from different forums will be deteted.
Main Forum (Rus)
3proxy Forum (Rus)
Bugs, Vulnerabilities, PoCs and Exploits (Rus)
Windows programming and administration (Rus)
Unix programming and administation (Rus)
About | Terms of use | Privacy Policy
© SecurityVulns, 3APA3A, Vladimir Dubrovin
 



Рейтинг@Mail.ru