 |
|
|
|
| Daily web applications security vulnerabilities summary (PHP, ASP, JSP, CGI, Perl) | | Published: |  | 29.01.2006 | | Source: |  | | | SecurityVulns ID: |  | 5709 | | Type: |  | remote | | Level: |  | 5/10 | | Description: |  | PHP inclusions, SQL injections, directory traversals, crossite scripting, information leaks, etc. |
| Mozilla CSS crossite scripting | | Published: |  | 29.01.2006 | | Source: |  | FULL-DISCLOSURE | | SecurityVulns ID: |  | 5710 | | Type: |  | client | | Level: |  | 5/10 | | Description: |  | -moz-binding: CSS allows to bind XBL with element and XBL may contains scripts. It may lead to crossite sripting within e.g. webmail. |
Multiple PHP vulnerabilities updated since 31.10.2005 | | Published: |  | 29.01.2006 | | Source: |  | FULL-DISCLOSURE | | SecurityVulns ID: |  | 5398 | | Type: |  | library | | Level: |  | 6/10 | | Description: |  | phpinfo() crossite scripting, parse_str() register_globals activisation possibility, $GLOBALS variable modification witrh HTTP POST form 'fileupload' field. It's also possible to modify any variable with GLOBALS[variable]. |
|
|
|
|
|
|
|
|