 |
|
|
|
| Daily web applications security vulnerabilities summary (PHP, ASP, JSP, CGI, Perl) | | Published: |  | 23.09.2006 | | Source: |  | | | SecurityVulns ID: |  | 6646 | | Type: |  | remote | | Level: |  | 5/10 | | Description: |  | PHP inclusions, SQL injections, directory traversals, crossite scripting, information leaks, etc. |
| Affected: |  | REDBLOG : RedBloG 0.5 | | |  | ESKOLAR : Eskolar CMS 0.9 | | |  | CAKEPHP : CakePHP 1.1 | | |  | EVISION : e-Vision CMS 2.0 | | |  | SQUIZ : MySource Matrix 3.8 | | |  | PLESK : PLESK 7.5 | | |  | SWSOFT : Plesk 7.6 |
| Original document |  | SECUNIA, [SA21992] BandSite CMS Cross-Site Scripting Vulnerabilities (23.09.2006) |
| |  | SECUNIA, [SA22063] NixieAffiliate Multiple Vulnerabilities (23.09.2006) |
| |  | SECUNIA, [SA22040] CakePHP "file" Parameter Disclosure of Sensitive Information (23.09.2006) |
| |  | SECUNIA, [SA22000] Feedsplitter Script Insertion and Local File Inclusion (23.09.2006) |
| |  | guanyu_vn_(at)_yahoo.com, [PLESK 7.5 Reload] & [PLESK 7.6 for MS Windows] path passing and disclosure vulnerability (23.09.2006) |
| |  | Patrick Webster, Squiz MySource Matrix Unauthorised Proxy and Cross Site Scripting (23.09.2006) |
| |  | Patrick Webster, Google Mini Search Applicance Path Disclosure (23.09.2006) |
| |  | CvIr.System_(at)_gmail.com, jevoncms (.inc) Path Disclosure (23.09.2006) |
| |  | sn4k3.23_(at)_gmail.com, Woltlab Burning Board 2.3.X SQL Injection Vulnerability (23.09.2006) |
| |  | HACKERS PAL, Eskolar CMS Remote Sql Injection (23.09.2006) |
| |  | HACKERS PAL, E-Vision CMS Multible Remote injections (23.09.2006) |
| |  | KeyCoder KeyCoder, RedBloG 0.x Multiple Remote File Include (23.09.2006) |
| |
|
| |