 |
|
|
|
| Web applications security vulnerabilities (PHP, ASP, CGI, Perl, etc) | | Published: |  | 29.11.2005 | | Source: |  | | | SecurityVulns ID: |  | 5487 | | Type: |  | remote | | Level: |  | 5/10 | | Description: |  | PHP inclusions, SQL injections, directory traversals, crossite scripting, information leaks, mb_send_mail() message headers modification, etc. |
| Affected: |  | JTR : Jax Calendar 1.34 | | |  | GUPPY : Guppy 4.5 | | |  | SOFTBIZSCRIPTS : SoftBiz FAQ 1.1 | | |  | SOFTBIZSCRIPTS : Softbiz B2B trading Marketplace 1.1 | | |  | SOCKETKB : SocketKB 1.1 | | |  | SENSATIONDESIGNS : KBase Express 1.0 | | |  | GREYWYVERN : Orca Knowledgebase 2.1 | | |  | GREYWYVERN : Orca Blog 1.3 | | |  | GREYWYVERN : Orca Ringmaker 2.3 | | |  | RETRAN : phpWTF 0.2 | | |  | ILYAV : FAQ System 1.1 | | |  | ILYAV : Survey System 1.1 | | |  | CODEWALKERS : ltwCalendar 4. | | |  | PHPLITE : Calendar Express 2 | | |  | 88SCRIPTS : Event Calendar 2.0 | | |  | AG0NY : O-Kiraku Nikki 1.3 | | |  | WEBMIN : Webmin 1.24 | | |  | AMPACHE : ampache 3.3 | | |  | RANDSHOP : randshop 1.1 |
| Original document |  | SECUNIA, [SA17779] Ampache Snoopy "_httpsrequest()" Command Injection Vulnerability (29.11.2005) |
| |  | advisory_(at)_dyadsecurity.com, [Full-disclosure] Webmin miniserv.pl format string vulnerability (29.11.2005) |
| |  | :) :), Randshop all versiyon Sql İnjection (29.11.2005) |
| |  | retrogod_(at)_aliceposta.it, Guppy <= 4.5.9 Remote code execution (29.11.2005) |
| |  | r0t, SoftBiz FAQ Script Multiple SQL vuln. (29.11.2005) |
| |  | r0t, Softbiz B2B trading Marketplace Script SQL inj (29.11.2005) |
| |  | r0t, SocketKB 1.1.x Vuln. (29.11.2005) |
| |  | r0t, KBase Express SQL inj. vuln. (29.11.2005) |
| |  | r0t, Orca Knowledgebase SQL vuln. (29.11.2005) |
| |  | r0t, Orca Blog SQL inj. vuln. (29.11.2005) |
| |  | r0t, Orca Ringmaker SQL inj. vuln. (29.11.2005) |
| |  | r0t, phpWTF Full Path Disclosure vuln. (29.11.2005) |
| |  | r0t, FAQ System 1.1 SQL inj. vuln. (29.11.2005) |
| |  | r0t, Survey System 1.1 SQL inj. vuln. (29.11.2005) |
| |  | r0t, Codewalkers ltwCalendar 4.x SQL inj. vuln (29.11.2005) |
| |  | r0t, Jax Calendar 1.34 vuln. (29.11.2005) |
| |  | r0t, Calendar Express 2 SQL inj. vuln. (29.11.2005) |
| |  | r0t, 88Script's Event Calendar v2.0 SQL inj. vuln. (29.11.2005) |
| |  | r0t, O-Kiraku Nikki v1.3 SQL inj. vuln. (29.11.2005) |
Cisco IOS HTTP server crossite scripting updated since 29.11.2005 | | Published: |  | 02.12.2005 | | Source: |  | BUGTRAQ | | SecurityVulns ID: |  | 5490 | | Type: |  | remote | | Level: |  | 4/10 | | Description: |  | There is no characters filtering on memory buffers displaying. |
| |
|
| |