Computer Security
[EN] securityvulns.ru no-pyccku


Daily web applications security vulnerabilities summary (PHP, ASP, JSP, CGI, Perl)
Published:21.08.2007
Source:
SecurityVulns ID:8071
Type:remote
Threat Level:
5/10
Description:PHP inclusions, SQL injections, directory traversals, crossite scripting, information leaks, etc.
Affected:MCLINKSCOUNTER : mcLinksCounter 1.2
 MYREFERER : My_REFERER 1.08
 BUTTERFLY : Butterfly online vistors counter 1.08
 GURURHABER : Gurur Portal 2.0
 JOOMLA : SimpleFAQ 2.11
CVE:CVE-2007-4486 (Multiple PHP remote file inclusion vulnerabilities in index.php in Linkliste 1.2 allow remote attackers to execute arbitrary PHP code via a URL in the (1) styl[top], (2) url_eintrag, or (3) styl[themen] parameter.)
 CVE-2007-4484 (PHP remote file inclusion vulnerability in login.php in My_REFERER 1.08 allows remote attackers to execute arbitrary PHP code via a URL in the value parameter.)
 CVE-2007-4479 (Cross-site scripting (XSS) vulnerability in search.html in Search Engine Builder allows remote attackers to inject arbitrary web script or HTML via the searWords parameter.)
 CVE-2006-4863 (** DISPUTED ** Multiple PHP remote file inclusion vulnerabilities in Marc Cagninacci mcLinksCounter 1.1 allow remote attackers to execute arbitrary PHP code via a URL in the langfile parameter in (1) login.php, (2) stats.php, (3) detail.php, or (4) erase.php. NOTE: CVE and a third party dispute this vulnerability, because the langfile parameter is set to english.php in each file.)
Original documentdocumentI. D., [Full-disclosure] OSNews (21.08.2007)
 documentHackers Center Security Group, Invision Power Board D22-Shoutbox HTML Injections (21.08.2007)
 documentk1tk4t_(at)_newhack.org, Mambo Component SimpleFAQ V2.11 - Remote SQL Injection (21.08.2007)
 documentthe.dumenci_(at)_gmail.com, Gurur Haber v2.0 (21.08.2007)
 documentIvan Niiiil, My_REFERER v.1.08 Remote File Include (21.08.2007)
 documentIvan Niiiil, Butterfly online vistors counter 1.08 RFI (21.08.2007)
 documentIvan Niiiil, mcLinksCounter 1.2 Remote File Include by iNs (21.08.2007)
 documentMustLive, Vulnerability in Search Engine Builder (21.08.2007)

About | Terms of use | Privacy Policy
© SecurityVulns, 3APA3A, Vladimir Dubrovin
Nizhny Novgorod