 |
|
|
|
| Daily web applications security vulnerabilities summary (PHP, ASP, JSP, CGI, Perl) | | Published: |  | 18.11.2006 | | Source: |  | | | SecurityVulns ID: |  | 6839 | | Type: |  | remote | | Level: |  | 5/10 | | Description: |  | PHP inclusions, SQL injections, directory traversals, crossite scripting, information leaks, etc. |
| Original document |  | SECUNIA, [SA22925] EC-CUBE Unspecified Cross-Site Scripting Vulnerability (18.11.2006) |
| |  | bd0rk_(at)_hackermail.com, mxBB calsnails module 1.06 Remote File Inclusion Vulnerability (18.11.2006) |
| |  | SHiKaA-_(at)_hotmail.com, Powie's PHP MatchMaker <= v4.05 (matchdetail) Remote SQL Injection Exploit (18.11.2006) |
| |  | SHiKaA-_(at)_hotmail.com, Powie's PHP Forum <= v1.29a (editpoll) Remote SQL Injection Exploit (18.11.2006) |
| |  | Craig Heffner, HTTP Upload Tool (download.php) Information Disclosure Vulnerability (18.11.2006) |
| |  | Craig Heffner, DoSePa 1.0.4 (textview.php) Information Disclosure Vulnerability (18.11.2006) |
| |  | v1per-haCker, mg.applanix (RFI) (18.11.2006) |
| |  | laurent gaffié, Dating Site [ login bypass & xss] (18.11.2006) |
| |  | laurent gaffié, Infinitytechs Restaurants CM (18.11.2006) |
| |  | laurent gaffié, 20/20 datashed [ multiples injection sql ] (18.11.2006) |
| |  | laurent gaffié, Aspmforum [ multiples injection sql (get&post)] (18.11.2006) |
| |  | laurent gaffié, 20/20 real estate [ multiples injection sql ] (18.11.2006) |
| |  | laurent gaffié, 20/20 auto gallery [ multiples injection sql ] (18.11.2006) |
| |  | Advisory_(at)_Aria-Security.net, [Aria-Security] CPanel Network Tools Cross Site Scripting [Advisory] (18.11.2006) |
| |  | GENTOO, [ GLSA 200611-10 ] WordPress: Multiple vulnerabilities (18.11.2006) |
| |  | laurent gaffié, Active News Manager [ injection sql (post&get)] (18.11.2006) |
| HP-UX WBEM DoS | | Published: |  | 18.11.2006 | | Source: |  | BUGTRAQ | | SecurityVulns ID: |  | 6840 | | Type: |  | remote | | Level: |  | 5/10 |
| TFTPD32 TFTP server buffer overflow | | Published: |  | 18.11.2006 | | Source: |  | BUGTRAQ | | SecurityVulns ID: |  | 6841 | | Type: |  | remote | | Level: |  | 5/10 | | Description: |  | Buffer overflow on oversized filename. |
| Sun Java sandbox protection bypass | | Published: |  | 18.11.2006 | | Source: |  | SECUNIA | | SecurityVulns ID: |  | 6843 | | Type: |  | library | | Level: |  | 5/10 | | Description: |  | Swing library functions may access data from different applets. |
| NetGear WG111 driver buffer overflow | | Published: |  | 18.11.2006 | | Source: |  | METASPLOIT | | SecurityVulns ID: |  | 6844 | | Type: |  | remote | | Level: |  | 7/10 | | Description: |  | Buffer overflow on beakon frame parsing. |
libpng DoS updated since 16.11.2006 | | Published: |  | 18.11.2006 | | Source: |  | SECUNIA | | SecurityVulns ID: |  | 6836 | | Type: |  | library | | Level: |  | 6/10 | | Description: |  | Out-of-bounds reading in png_set_sPLT(). |
| Computer Associates CA Internet Security / CA Personal Firewall privilege escalation | | Published: |  | 18.11.2006 | | Source: |  | BUGTRAQ | | SecurityVulns ID: |  | 6842 | | Type: |  | local | | Level: |  | 5/10 | | Description: |  | Insufficient TDI and NDIS hooked function paramters validation. |
|
|
|
|
|
|
|
|