 |
|
|
|
| Cygwin setup packages spoofing | | Published: |  | 26.07.2008 | | Source: |  | BUGTRAQ | | SecurityVulns ID: |  | 9173 | | Type: |  | client | | Level: |  | 4/10 | | Description: |  | Package source authentity is not checked during installation procedure. |
| Apple Safari memory corruption | | Published: |  | 26.07.2008 | | Source: |  | BUGTRAQ | | SecurityVulns ID: |  | 9175 | | Type: |  | client | | Level: |  | 5/10 | | Description: |  | memory corruption on stylesheets parsing. |
| CVE: |  | CVE-2008-2317 (WebCore in Apple Safari does not properly perform garbage collection of JavaScript document elements, which allows remote attackers to execute arbitrary code or cause a denial of service (heap corruption and application crash) via a reference to the ownerNode property of a copied CSSStyleSheet object of a STYLE element, as originally demonstrated on Apple iPhone before 2.0 and iPod touch before 2.0, a different vulnerability than CVE-2008-1590.) |
Daily web applications security vulnerabilities summary (PHP, ASP, JSP, CGI, Perl) updated since 26.07.2008 | | Published: |  | 29.07.2008 | | Source: |  | | | SecurityVulns ID: |  | 9174 | | Type: |  | remote | | Level: |  | 5/10 | | Description: |  | PHP inclusions, SQL injections, directory traversals, crossite scripting, information leaks, etc.
FireStats WordPress plugin: crossite scripting, automation protection bypass, DoS, information leak, unauthorized access. |
| Original document |  | Ghost hacker, PhpJobScheduler 3.1 Remote File Inclusion Vulnerability (29.07.2008) |
| |  | Fabian Fingerle, Cross Site Scripting (XSS) in Owl <=0.95, CVE-2008-3100 (29.07.2008) |
| |  | JeiAr, ViArt <= 3.5 SQL Injection (29.07.2008) |
| |  | supportrup_(at)_gmail.com, Multiple Cross-Site Scripting Vulnerabilities in Web Wiz Rich Text Editor version 4.02 (29.07.2008) |
| |  | JeiAr, JamRoom <= 3.3.8 Authentication Bypass (29.07.2008) |
| |  | Digital Security Research Group [DSecRG], [DSECRG-08-033] Local File Include Vulnerability in Pixelpost 1.7.1 (29.07.2008) |
| |  | MustLive, Vulnerabilities in FireStats (29.07.2008) |
| |  | MustLive, Multiple vulnerabilities in FireStats (29.07.2008) |
| |  | HACKERS PAL, ezContents CMS Renote File inclusion (26.07.2008) |
| |  | azzcoder_(at)_hotmail.com, XRMS 1.99.2 (RFI/XSS/IG) Multiple Remote Vulnerabilities (26.07.2008) |
| |  | MustLive, Vulnerabilities in PostNuke Phoenix (26.07.2008) |
|
|
|
|
|
|
|
|