Computer Security
Daily web applications security vulnerabilities summary (PHP, ASP, JSP, CGI, Perl)
updated since 18.02.2008
SecurityVulns ID:8701
Description:PHP inclusions, SQL injections, directory traversals, crossite scripting, information leaks, etc. Power Phlogger: multiple XSS.
Affected:POWERPHLOGGER : Power Phlogger 2.2
 RUNCMS : RunCMS 1.6
 LIGHTBLOG : lightblog 9.6
 CRAFTYSYNTAX : Crafty Syntax 2.4
 SIMPLECMS : Simple CMS 1.0
Original documentdocumenthackturkiye.hackturkiye_(at), joomla SQL Injection(com_ricette) (18.02.2008)
 documenthackturkiye.hackturkiye_(at), joomla SQL Injection (cat)(com_downloads) (18.02.2008)
 documentJose Luis Góngora Fernández, Simple CMS <= 1.0.3 (indexen.php area) Remote SQL Injection Exploit (18.02.2008)
 documentnbbn_(at), RunCMS 1.6.1 Multiple XSS and XSRF Vulnerabilties (18.02.2008)
 documentOzgur Ozdemircili, Crafty Syntax Xss Vulnerability (18.02.2008)
 documentmuuratsalo experimental hack lab, lightblog 9.6 local file inclusion vulnerability (18.02.2008)
 documenthackturkiye.hackturkiye_(at), joomla SQL Injection(com_profile) (18.02.2008)
 documenthackturkiye.hackturkiye_(at), WordPress forumaction (PAGE_id)(user)SQL Injection (18.02.2008)
 documenthackturkiye.hackturkiye_(at), Wordpress Plugin (wp-content/recipe) SQL Injection (18.02.2008)
 documenthackturkiye.hackturkiye_(at), joomla SQL Injection(com_detail) (18.02.2008)
 documenthackturkiye.hackturkiye_(at), joomla SQL Injection(com_filebase) (18.02.2008)
 documenthackturkiye.hackturkiye_(at), joomla SQL Injection(com_galeria) (18.02.2008)
 documenthackturkiye.hackturkiye_(at), WordPress SQL Injection(wp-content-simple-forum) (18.02.2008)
 documenthackturkiye.hackturkiye_(at), Wordpress Plugin (wp-people) SQL Injection (18.02.2008)
 documenthackturkiye.hackturkiye_(at), joomla SQL Injection(com_jooget) (18.02.2008)
 documenthackturkiye.hackturkiye_(at), WordPress album PHOTO SQL Injection (18.02.2008)
 documentMustLive, New vulnerabilities in Power Phlogger (18.02.2008)
Files:Simple CMS <= 1.0.3 (?area=) Remote SQL Injection Exploit

