 |
|
|
|
| Daily web applications security vulnerabilities summary (PHP, ASP, JSP, CGI, Perl) | | Published: |  | 07.09.2008 | | Source: |  | | | SecurityVulns ID: |  | 9265 | | Type: |  | remote | | Level: |  | 5/10 | | Description: |  | PHP inclusions, SQL injections, directory traversals, crossite scripting, information leaks, etc.
myPHPNuke: SQL injection. |
| Affected: |  | MYPHPNUKE : myPHPNuke 1.8 | | |  | DJANGO : django 0.95 | | |  | ZENCART : Zen Cart | | |  | ASPWEBALBUM : aspWebAlbum 3.2 | | CVE: |  | CVE-2008-3664 (Multiple cross-site scripting (XSS) vulnerabilities in XRMS allow remote attackers to inject arbitrary web script or HTML via (1) the real name field, related to the user list; (2) the target parameter to login.php, (3) the title parameter to activities/some.php, (4) the company_name parameter to companies/some.php, (5) the last_name parameter to contacts/some.php, (6) the campaign_title parameter to campaigns/some.php, (7) the opportunity_title parameter to opportunities/some.php, (8) the case_title parameter to cases/some.php, (9) the file_id parameter to files/some.php, or (10) the starting parameter to reports/custom/mileage.php, a related issue to CVE-2008-1129.) |
|
|
|
|
|
|
|
|