Computer Security
[EN] no-pyccku

Web applications security vulnerabilities summary (PHP, ASP, JSP, CGI, Perl)
SecurityVulns ID:12176
Threat Level:
Description:PHP inclusions, SQL injections, directory traversals, crossite scripting, information leaks, etc.
Affected:CUBECART : CubeCart 3.0
 GLPI : GLPI 0.80
 EFRONTLEARNING : eFront Community++ 3.6
 DOLIBARR : Dolibarr CMS 3.2
 ONXSHOP : OnxShop CMS 1.5
 KLOXO : Kloxo LxCenter Server CP 6.1
 APACHE : MyFaces 2.0
 APACHE : MyFaces 2.1
CVE:CVE-2012-1037 (PHP remote file inclusion vulnerability in front/popup.php in GLPI 0.78 through 0.80.61 allows remote authenticated users to execute arbitrary PHP code via a URL in the sub_type parameter.)
 CVE-2011-4367 (Multiple directory traversal vulnerabilities in MyFaces JavaServer Faces (JSF) in Apache MyFaces Core 2.0.x before 2.0.12 and 2.1.x before 2.1.6 allow remote attackers to read arbitrary files via a .. (dot dot) in the (1) ln parameter to faces/javax.faces.resource/web.xml or (2) the PATH_INFO to faces/javax.faces.resource/.)
Original documentdocumentAPACHE, [SECURITY] CVE-2011-4367 Apache MyFaces information disclosure vulnerability (12.02.2012)
 documentAPACHE, [SECURITY] CVE-2011-4367 Apache MyFaces information disclosure vulnerability (12.02.2012)
 documentVulnerability Lab, eFront Community++ v3.6.10 - Multiple Web Vulnerabilities (12.02.2012)
 documentVulnerability Lab, Dolibarr CMS v3.2.0 Alpha - File Include Vulnerabilities (12.02.2012)
 documentVulnerability Lab, OnxShop CMS v1.5.0 - Multiple Web Vulnerabilities (12.02.2012)
 documentVulnerability Lab, Dolibarr CMS v3.2.0 Alpha - SQL Injection Vulnerabilities (12.02.2012)
 documentVulnerability Lab, Kloxo LxCenter Server CP v6.1.10 - Multiple Web Vulnerabilities (12.02.2012)
 documentYGN Ethical Hacker Group, CubeCart 3.0.20 (3.0.x) and lower | Open URL Redirection Vulnerability (12.02.2012)
 documentMANDRIVA, [ MDVSA-2012:016 ] glpi (12.02.2012)

CVS client buffer overflow
SecurityVulns ID:12177
Threat Level:
Description:Heap buffer overflow on server response parsing.
CVE:CVE-2012-0804 (Heap-based buffer overflow in the proxy_connect function in src/client.c in CVS 1.11 and 1.12 allows remote HTTP proxy servers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted HTTP response.)
Original documentdocumentDEBIAN, [SECURITY] [DSA 2407-1] cvs security update (12.02.2012)

About | Terms of use | Privacy Policy
© SecurityVulns, 3APA3A, Vladimir Dubrovin
Nizhny Novgorod