 |
|
|
|
| Daily web applications security vulnerabilities summary (PHP, ASP, JSP, CGI, Perl) | | Published: |  | 18.11.2006 | | Source: |  | | | SecurityVulns ID: |  | 6839 | | Type: |  | remote | | Level: |  | 5/10 | | Description: |  | PHP inclusions, SQL injections, directory traversals, crossite scripting, information leaks, etc. |
| Affected: |  | WORDPRESS : WordPress 2.0 | | |  | MGAPPLANIX : mg.applanix 1.3 | | |  | DOSEPA : DoSePa 1.0 | | |  | UPLOADTOOL : HTTP Upload Tool For PHP 1.0 | | |  | MINIOPENCMS : Mini Open CMS 1.0 | | |  | POWIE : Powie's PHP Forum 1.29 | | |  | POWIE : Powie's PHP MatchMaker 4.05 | | |  | MXBB : mxBB calsnails module 1.06 | | |  | ECCUBE : EC-CUBE 1.0 |
| Original document |  | SECUNIA, [SA22925] EC-CUBE Unspecified Cross-Site Scripting Vulnerability (18.11.2006) |
| |  | bd0rk_(at)_hackermail.com, mxBB calsnails module 1.06 Remote File Inclusion Vulnerability (18.11.2006) |
| |  | SHiKaA-_(at)_hotmail.com, Powie's PHP MatchMaker <= v4.05 (matchdetail) Remote SQL Injection Exploit (18.11.2006) |
| |  | SHiKaA-_(at)_hotmail.com, Powie's PHP Forum <= v1.29a (editpoll) Remote SQL Injection Exploit (18.11.2006) |
| |  | Craig Heffner, HTTP Upload Tool (download.php) Information Disclosure Vulnerability (18.11.2006) |
| |  | Craig Heffner, DoSePa 1.0.4 (textview.php) Information Disclosure Vulnerability (18.11.2006) |
| |  | v1per-haCker, mg.applanix (RFI) (18.11.2006) |
| |  | laurent gaffié, Dating Site [ login bypass & xss] (18.11.2006) |
| |  | laurent gaffié, Infinitytechs Restaurants CM (18.11.2006) |
| |  | laurent gaffié, 20/20 datashed [ multiples injection sql ] (18.11.2006) |
| |  | laurent gaffié, Aspmforum [ multiples injection sql (get&post)] (18.11.2006) |
| |  | laurent gaffié, 20/20 real estate [ multiples injection sql ] (18.11.2006) |
| |  | laurent gaffié, 20/20 auto gallery [ multiples injection sql ] (18.11.2006) |
| |  | Advisory_(at)_Aria-Security.net, [Aria-Security] CPanel Network Tools Cross Site Scripting [Advisory] (18.11.2006) |
| |  | GENTOO, [ GLSA 200611-10 ] WordPress: Multiple vulnerabilities (18.11.2006) |
| |  | laurent gaffié, Active News Manager [ injection sql (post&get)] (18.11.2006) |
| HP-UX WBEM DoS | | Published: |  | 18.11.2006 | | Source: |  | BUGTRAQ | | SecurityVulns ID: |  | 6840 | | Type: |  | remote | | Level: |  | 5/10 |
| |
|
| |