Computer Security
[EN] no-pyccku

Daily web applications security vulnerabilities summary (PHP, ASP, JSP, CGI, Perl)
updated since 07.11.2007
SecurityVulns ID:8322
Threat Level:
Description:PHP inclusions, SQL injections, directory traversals, crossite scripting, information leaks, etc. WordPress Peter’s Custom Anti-Spam Image: CAPTCHA protection bypass.
Affected:IDMOS : IDMOS 1.0
 CYPBX : Cyp/bx 1.0
 SFSHOUTBOX : SF-Shoutbox 1.4
 PLONE : Plone 2.5
CVE:CVE-2007-5741 (Plone 2.5 through 2.5.4 and 3.0 through 3.0.2 allows remote attackers to execute arbitrary Python code via network data containing pickled objects for the (1) statusmessages or (2) linkintegrity module, which the module unpickles and executes.)
Original documentdocumentmj_(at), [CVE-2007-5741] Plone: statusmessages and linkintegrity unsafe network data hotfix (07.11.2007)
 documentAdvisory_(at), MyWebFTP Password Disclosure (07.11.2007)
 documentSkyOut, [Full-disclosure] SF-Shoutbox 1.2.1 <= 1.4 HTML/JS Injection Vulnerability (07.11.2007)
 documentGuns_(at), PhpNuke (add-on) MS TopSites Edit Exploit And Html Injection (07.11.2007)
 documentChris, Cypress BX script backdoored? (07.11.2007)
 documentGuns_(at), IDMOS v1.0 Alpha Multiple RFI Vulnerability (07.11.2007)
 documenth3llcode_(at), SMF .htaccess bypass (07.11.2007)
Files:Exploits PhpNuke (add-on) MS TopSites Edit And Html Injection

About | Terms of use | Privacy Policy
© SecurityVulns, 3APA3A, Vladimir Dubrovin
Nizhny Novgorod