 |
|
|
|
| Daily web applications security vulnerabilities summary (PHP, ASP, JSP, CGI, Perl) | | Published: |  | 18.04.2006 | | Source: |  | | | SecurityVulns ID: |  | 6018 | | Type: |  | remote | | Level: |  | 5/10 | | Description: |  | PHP inclusions, SQL injections, directory traversals, crossite scripting, information leaks, etc. |
| Original document |  | GroundZero Security, [Full-disclosure] RechnungsZentrale V2 - SQL injection and Remote PHP inclusion vulnerabilities (18.04.2006) |
| |  | d4igoro_(at)_gmail.com, Linpha 1.1.0 - XSS Vulnerabilities (18.04.2006) |
| |  | SECUNIA, [SA19645] MODx Cross-Site Scripting and Directory Traversal (18.04.2006) |
| |  | SECUNIA, [SA19716] Avaya CMS / IR "/proc" Denial of Service (18.04.2006) |
| |  | Aliaksandr Hartsuyeu, [eVuln] Wire Plastik wpBlog SQL Injection Vulnerability (18.04.2006) |
| |  | Steve, Neon Responder (Dos,Exploit) (18.04.2006) |
| |  | qex_(at)_bsdmail.org, AnimeGenesis <= XSS (18.04.2006) |
| |  | Hessam Salehi, Tiny PHP forum - vulns (18.04.2006) |
| |  | Aliaksandr Hartsuyeu, [eVuln] CzarNews XSS and Multiple SQL Injection Vulnerabilities (18.04.2006) |
| |  | qex_(at)_bsdmail.org, Neuron Blog <= 1.1 XSS (18.04.2006) |
| |  | qex_(at)_bsdmail.org, ShoutBOOK <= 1.1 XSS (18.04.2006) |
| |  | r0t, BluePay Manager v2.0 Script Insertion Vulnerability (18.04.2006) |
| |  | r0t, ModernBill multiple SQL inj. vuln. (18.04.2006) |
| |  | r0t, Leadhound multiple vuln. (18.04.2006) |
| |  | r0t, xFlow v5.x multiple vuln. (18.04.2006) |
| |  | r0t, Article Publisher Pro SQL inj. (18.04.2006) |
| Neon Responder LANsurveyor add-on DoS | | Published: |  | 18.04.2006 | | Source: |  | BUGTRAQ | | SecurityVulns ID: |  | 6019 | | Type: |  | remote | | Level: |  | 5/10 | | Description: |  | Service crash on malformed TCP/4347 packet. |
Multiple Firefox / Netscape / SeaMonkey vulnerabilities updated since 14.04.2006 | | Published: |  | 18.04.2006 | | Source: |  | SECUNIA | | SecurityVulns ID: |  | 6011 | | Type: |  | client | | Level: |  | 8/10 | | Description: |  | Crossite scripting, memory corruptions, buffer overflows, array overflows, integer overflows. Can be exploited to silently install malware code. |
Symantec Live Update for Macintosh privilege escalation updated since 18.04.2006 | | Published: |  | 19.04.2006 | | Source: |  | SECUNIA | | SecurityVulns ID: |  | 6021 | | Type: |  | local | | Level: |  | 5/10 | | Description: |  | suid applications executes external application by relative path. |
Privilege escalation in IBM AIX rm_mlcache_file with file overwrite updated since 18.04.2006 | | Published: |  | 24.04.2006 | | Source: |  | SECUNIA | | SecurityVulns ID: |  | 6022 | | Type: |  | local | | Level: |  | 5/10 | | Description: |  | Race conditions on temporary file creation. |
Xine media player format string vulnerability updated since 18.04.2006 | | Published: |  | 02.05.2006 | | Source: |  | FULL-DISCLOSURE | | SecurityVulns ID: |  | 6020 | | Type: |  | client | | Level: |  | 6/10 | | Description: |  | Format string bug on diagnostic message printing, including playlist files parsing. |
|
|
|
|
|
|
|
|