Computer Security
[EN] securityvulns.ru
no-pyccku



PHP, ASP, CGI web applications security vulnerabilities
updated since 09.03.2005
Published:13.03.2005
Source:
SecurityVulns ID:4559
Type:remote
Level:5/10
Description:PHP inclusions, SQL injections, directory traversals, crossite scripting, etc.
Affected:PHPBB : phpBB 2.0
 XOOPS : xoops 2.0
 PAFILEDB : paFileDB 3.1
 MCNEWS : mcNews 1.3
 PHPBB : UBBThreads 6.2
 PHORUM : Phorum 5.0
 PHPMYFAQ : phpMyFAQ 1.4
 HOSTINGCONTROLLE : Hosting Controller 6.1
 STADTAUS : Form Mail Script 2.3
 WFSECTIONS : wfsections 1.07
 PHPFUSION : PHP-Fusion 5.01
 PHPWEBLOG : phpWebLog 0.5
 PROJECTBB : ProjectBB 0.4
 OUTSTART : PE
 EXPERIENCE2 : eXPerience2
 SOCIALMPN : SocialMPN 1.2
 BERLIOS : iPhoto 0.2
 WEBINSTA : WEBInsta 1.3
 PHOTOPOST : Photopost 5.0
 HOLACMS : Hola CMS 1.4
 ACTIVECAMPAIGN : KnowledgeBase
 SPINWORKS : Spinworks Application Server 3.0
Original documentdocumentSECUNIA, [SA14579] Spinworks Application Server Web Server Denial of Service (14.03.2005)
 documentFrancisco Alisson, KnowledgeBase (14.03.2005)
 documentfarhad koosha, aeNovo Database Content Disclosure Vulnerability (14.03.2005)
 documentsp3x_(at)_securityreason.com, [SECURITYREASON.COM] Mass Full Path Disclosure in paFileDB (14.03.2005)
 documentVirginity Security, Virginity Security Advisory 2005-001 : Hola CMS - File destruction and System access (13.03.2005)
 documentmozako, [badroot.org] The Includer remote commands execution exploit (13.03.2005)
 documentIgor Franchuk, PhotoPost PHP 5.0 RC3, and later, multiple vulnerabilities (13.03.2005)
 documentsp3x_(at)_securityreason.com, [SECURITYREASON.COM] SQL injection and XSS in paFileDB (13.03.2005)
 documentMaksymilian Arciemowicz, [SECURITYREASON.COM][phpBB 2.0.13 SQL error in session cXIb8O3.8] (13.03.2005)
 documentkreon, UBB.threads 6 SQL Injection (13.03.2005)
 documentSECUNIA, [SA14554] Phorum Unspecified Cross-Site Scripting Vulnerability (11.03.2005)
 documentkreon, Wfsection 1.07 vulnerabilities (11.03.2005)
 documentSECUNIA, [SA14550] WEBInsta Mailing list manager "absolute_path" Arbitrary File Inclusion (10.03.2005)
 documentSECUNIA, [SA14401] iPhoto CopperExport Plugin "xp_publish.php" SQL Injection (09.03.2005)
 documentSECUNIA, [SA14516] phpMyFaq "username" SQL Injection Vulnerability (09.03.2005)
 documentahmad muammar, Remote Testing SocialMPN Remote File Inclusion by y3dips (09.03.2005)
 documentFrancisco Alisson, Multiples Vulnerabilities (09.03.2005)
 documentAltrus Wollesen, PE Multiple Remote Access Validation Vulnerabilities (Participate Systems Inc. / Outstart Inc.) (09.03.2005)
 documentbenjilenoob_(at)_hotmail.com, failles dans ProjectBB v0.4.5.1 (09.03.2005)
 documentsp3x_(at)_securityreason.com, Multiple vulnerabilities in paFileDB (09.03.2005)
 documentpokleyzz, [SCAN Associates Security Advisory] xoops 2.0.9.2 and below weak file extension validation (09.03.2005)
 documentFilip Groszynski, phpWebLog <= 0.5.3 arbitrary file inclusion (VXSfx) (09.03.2005)
 documentFilip Groszynski, PHP mcNews <= 1.3 arbitrary file inclusion (VXSfx) (09.03.2005)
 documentFireSt0rm, PHP-FUSION 5.* XSS VULNERABILITY (09.03.2005)
 documentSome one, phpBB 2.0.13 - user level exploit (09.03.2005)
 documentmozako, PHP Form Mail Script <= 2.3 arbitrary file inclusion exploit exploit (09.03.2005)
 documentsmall mouse, Hosting Controller Multiple Unauthenticated information disclose (09.03.2005)
Discuss:Read or add your comments to this news (0 comments)

About | Terms of use | Privacy Policy
© SecurityVulns, 3APA3A, Vladimir Dubrovin
 



Рейтинг@Mail.ru