Computer Security
[EN] securityvulns.ru
no-pyccku



Daily web applications security vulnerabilities summary (PHP, ASP, JSP, CGI, Perl)
Published:11.05.2008
Source:
SecurityVulns ID:8982
Type:remote
Level:5/10
Description:PHP inclusions, SQL injections, directory traversals, crossite scripting, information leaks, etc. pMachinePro: HTTP Response Splitting
Affected:SAZCART : SazCart 1.5
 CPANEL : cPanel 11.18
 CPANEL : WHM 11.15
 PHPFUSION : PHP-Fusion 6.01
CVE:CVE-2008-2071 (Multiple cross-site request forgery (CSRF) vulnerabilities in the WHM interface 11.15.0 for cPanel 11.18 before 11.18.4 and 11.22 before 11.22.3 allow remote attackers to perform unauthorized actions as cPanel administrators via requests to cpanel/whm/webmail and other unspecified vectors.)
 CVE-2008-2070 (The WHM interface 11.15.0 for cPanel 11.18 before 11.18.4 and 11.22 before 11.22.3 allows remote attackers to bypass XSS protection and inject arbitrary script or HTML via repeated, improperly-ordered "<" and ">" characters in the (1) issue parameter to scripts2/knowlegebase, (2) user parameter to scripts2/changeip, (3) search parameter to scripts2/listaccts, and other unspecified vectors.)
Original documentdocumentCharles "real" F., PHP-Fusion <= 6.01.15 Multiple Vulnerabilities (11.05.2008)
 documentBreeeeh_(at)_hotmail.com, OtherLogic[vocourse.php]SQL Injection Exploit (11.05.2008)
 documentJose Luis Góngora Fernández, SazCart <= 1.5.1 (prodid) Remote SQL Injection Exploit (11.05.2008)
 documentMatteo Carli, XSS and CSRF vulnerability on Cpanel 11 (11.05.2008)
Files:SazCart <= v1.5.1 (details&prodid) Remote SQL Injection Exploit
Discuss:Read or add your comments to this news (0 comments)


Show Threads
Messages
 
Login:* (Register)
Password:*
(private) To:
(reply) Subject:*
Text:

Main Forum (Eng)

General security questions not appropriate for another forums.
3proxy Forum (Eng)

All 3proxy question must be posted to this forum.
Bugs, Vulnerabilities, PoCs and Exploits (Eng)

All vulnerability related questions, vulnerability digging and exploit creation.
Windows programming and administration (Eng)

Administering Windows and application development.
Unix programming and administation (Eng)

Administering Unix and application development.
Test forum

Please post all test messages here. All test messages from different forums will be deteted.
Main Forum (Rus)
3proxy Forum (Rus)
Bugs, Vulnerabilities, PoCs and Exploits (Rus)
Windows programming and administration (Rus)
Unix programming and administation (Rus)
About | Terms of use | Privacy Policy
© SecurityVulns, 3APA3A, Vladimir Dubrovin
 



Рейтинг@Mail.ru