 |
|
|
|
| Daily web applications security vulnerabilities summary (PHP, ASP, JSP, CGI, Perl) | | Published: |  | 16.02.2008 | | Source: |  | | | SecurityVulns ID: |  | 8698 | | Description: |  | PHP inclusions, SQL injections, directory traversals, crossite scripting, information leaks, etc. |
| Affected: |  | SIMPLEFORUM : Simple Forum 1.11 | | |  | BANPRODMS : banpro-dms 1.0 |
| Original document |  | muuratsalo experimental hack lab, banpro-dms 1.0 local file inclusion vulnerability (16.02.2008) |
| |  | hackturkiye.hackturkiye_(at)_gmail.com, joomla SQL Injection(com_sg) (16.02.2008) |
| |  | hackturkiye.hackturkiye_(at)_gmail.com, joomla SQL Injection(com_emcompose) (16.02.2008) |
| |  | hackturkiye.hackturkiye_(at)_gmail.com, joomla SQL Injection(com_filebase) (16.02.2008) |
| |  | hackturkiye.hackturkiye_(at)_gmail.com, joomla SQL Injection(com_lexikon) (16.02.2008) |
| |  | hackturkiye.hackturkiye_(at)_gmail.com, joomla SQL Injection( com_scheduling) (16.02.2008) |
| |  | hackturkiye.hackturkiye_(at)_gmail.com, joomla SQL Injection(com_salesrep) (16.02.2008) |
| |  | hackturkiye.hackturkiye_(at)_gmail.com, Simple Forum Version 1.7-1.9(pagename) (16.02.2008) |
| |  | hackturkiye.hackturkiye_(at)_gmail.com, SellOwnHouse login SQL Injection (16.02.2008) |
| |  | hackturkiye.hackturkiye_(at)_gmail.com, all version Wordpress FORUM S@L injection (16.02.2008) |
| |  | hackturkiye.hackturkiye_(at)_gmail.com, joomla faq SQL Injection (16.02.2008) |
| |  | hackturkiye.hackturkiye_(at)_gmail.com, joomla com_activities sql injection (16.02.2008) |
| |  | hackturkiye.hackturkiye_(at)_gmail.com, Ecommerce Websites from b1st.com SQL Injection (16.02.2008) |
| |  | hackturkiye.hackturkiye_(at)_gmail.com, joomla "com_smslist" sql injecton (16.02.2008) |
| |  | hackturkiye.hackturkiye_(at)_gmail.com, engineering Neoteric UK LTD S@L İNJECTİON (16.02.2008) |
| |  | hadihadi_zedehal_2006_(at)_yahoo.com, artmedic_weblog Cross Site Scriptting Vulnerbility (16.02.2008) |
| |  | hackturkiye.hackturkiye_(at)_gmail.com, Simple Forum Version 1.10-1.11 SQL Injection (16.02.2008) |
| OpenDAL DoS | | Published: |  | 16.02.2008 | | Source: |  | | | SecurityVulns ID: |  | 8700 | | Type: |  | remote | | Level: |  | 5/10 |
| CVE: |  | CVE-2008-0658 (slapd/back-bdb/modrdn.c in the BDB backend for slapd in OpenLDAP 2.3.39 allows remote authenticated users to cause a denial of service (daemon crash) via a modrdn operation with a NOOP (LDAP_X_NO_OPERATION) control, a related issue to CVE-2007-6698.) | | |  | CVE-2007-6698 (The BDB backend for slapd in OpenLDAP before 2.3.36, allows remote authenticated users to cause a denial of service (crash) via a potentially-successful modify operation with the NOOP control set to critical, possibly due to a double free vulnerability.) |
| Original document |  | RPATH, rPSA-2008-0059-1 openldap openldap-clients openldap-servers (16.02.2008) |
| UniversalFtp Server multiple security vulnerabilities | | Published: |  | 16.02.2008 | | Source: |  | BUGTRAQ | | SecurityVulns ID: |  | 8694 | | Type: |  | remote | | Level: |  | 5/10 | | Description: |  | Buffer overflows and DoS conditions. |
| Affected: |  | UNIVERSALFTP : UniversalFtp Server 1.0 |
| Original document |  | securfrog_(at)_gmail.com, UniversalFtp Server 1.0.44 Multiple Remote Denial of service (16.02.2008) |
| SOPHOS Email Security Appliance crossite scripting | | Published: |  | 16.02.2008 | | Source: |  | BUGTRAQ | | SecurityVulns ID: |  | 8695 | | Type: |  | remote | | Level: |  | 4/10 | | Description: |  | Administration interface crossite scripting. |
| Affected: |  | SOPHOS : Sophos ES1000 |
| Original document |  | infocus, [INFIGO-2008-02-13]: SOPHOS Email Security Appliance Cross Site Scripting Vulnerability (16.02.2008) |
Mplayer / Xine multiple security vulnerabilities updated since 05.02.2008 | | Published: |  | 16.02.2008 | | Source: |  | BUGTRAQ | | SecurityVulns ID: |  | 8631 | | Type: |  | remote | | Level: |  | 5/10 | | Description: |  | Buffer overflow on FLAC data parsing, uninitilized pointer dereference on MOV parsing. |
| Affected: |  | MPLAYER : MPlayer 1.0 | | |  | XINE : xine 1.1 | | |  | XINE : xinelib 1.1 | | CVE: |  | CVE-2008-0486 (Array index vulnerability in libmpdemux/demux_audio.c in MPlayer 1.0rc2 and SVN before r25917, and possibly earlier versions, as used in Xine-lib 1.1.10, might allow remote attackers to execute arbitrary code via a crafted FLAC tag, which triggers a buffer overflow.) | | |  | CVE-2008-0485 (Array index error in libmpdemux/demux_mov.c in MPlayer 1.0 rc2 and earlier might allow remote attackers to execute arbitrary code via a QuickTime MOV file with a crafted stsc atom tag.) | | |  | CVE-2008-0238 (Multiple heap-based buffer overflows in the rmff_dump_cont function in input/libreal/rmff.c in xine-lib 1.1.9 allow remote attackers to execute arbitrary code via the SDP (1) Title, (2) Author, or (3) Copyright attribute, related to the rmff_dump_header function, different vectors than CVE-2008-0225. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.) | | |  | CVE-2008-0225 (Heap-based buffer overflow in the rmff_dump_cont function in input/libreal/rmff.c in xine-lib 1.1.9 and earlier allows remote attackers to execute arbitrary code via the SDP Abstract attribute, related to the rmff_dump_header function and related to disregarding the max field. NOTE: some of these details are obtained from third party information.) |
| |
|
| |