Section: .. / 0605-advisories /
| /// File Name: |
AZPhotoAlbum.txt |
Description:
|
AZ Photo Album Script Pro is vulnerable to XSS
| | Author: | luny | | File Size: | 857 | | Last Modified: | May 26 19:09:07 2006 |
| MD5 Checksum: | 1afea1dd147a5fdcb8fdb07793ae41c5 |
|
| /// File Name: |
VSR-2006-05-23.txt |
Description:
|
On April 18th, 2006 VSR has identified a stack overflow in the PDF Tools AG PDF Form Filling and Flattening tool. Although this is a traditional command line utility there may be a risk to those users of the application who use it within web application or a network service, particularly when relying on user supplied input to generate the PDF form field name or value pairs.
| | Homepage: | http://www.vsecurity.com/ | | File Size: | 4424 | | Last Modified: | May 26 18:43:54 2006 |
| MD5 Checksum: | b6ed72429d95e4de71ab22b8e31caed7 |
|
| /// File Name: |
PostgreSQL-8.1.4.txt |
Description:
|
An attacker able to submit crafted strings to an application that will embed those strings in SQL commands can use invalidly-encoded multibyte characters to bypass standard string-escaping methods, resulting in possible injection of hostile SQL commands into the database. The attacks covered here work in any multibyte encoding. Affected versions: PostgreSQL 8.1.0-8.1.3, 8.0.0-8.0.7, 7.4.0-7.4.12, 7.3.0-7.3.14
| | Homepage: | http://www.postgresql.org/ | | File Size: | 3613 | | Last Modified: | May 26 18:38:13 2006 |
| MD5 Checksum: | 47bf71400d49c724eafa4d2916a4855d |
|
| /// File Name: |
Mambo-4.6.txt |
Description:
|
Mambo versions less than or equal to 4.6 suffer from XSS.
| | Author: | rgod | | File Size: | 1466 | | Last Modified: | May 26 18:16:22 2006 |
| MD5 Checksum: | 198a3d477c018b7a97f437372f20b376 |
|
| /// File Name: |
Publicistv0.95.txt |
Description:
|
Publicist v0.95 suffers from full path disclosure, XSS, and SQL injection vulnerabilities.
| | Author: | luny | | File Size: | 2157 | | Last Modified: | May 26 18:15:39 2006 |
| MD5 Checksum: | d4b63e99177e88a7fec0a3ac0d580f67 |
|
| /// File Name: |
USN-286-1.txt |
Description:
|
Ubuntu Security Notice 286-1: Several format string vulnerabilities have been discovered in dia. By tricking a user into opening a specially crafted dia file, or a file with a specially crafted name, this could be exploited to execute arbitrary code with the user's privileges.
| | Homepage: | http://security.ubuntu.com/ | | File Size: | 5692 | | Last Modified: | May 26 18:13:57 2006 |
| MD5 Checksum: | d5f1a212478ffe6cb7ef72769722ba82 |
|
| /// File Name: |
USN-285-1.txt |
Description:
|
Ubuntu Security Notice 285-1: AWStats did not properly sanitize the 'migrate' CGI parameter. If the update of the stats via web front-end is allowed, a remote attacker could execute arbitrary commands on the server with the privileges of the AWStats server.
| | Homepage: | http://security.ubuntu.com/ | | File Size: | 2269 | | Last Modified: | May 26 18:13:50 2006 |
| MD5 Checksum: | 16816c83453e806800d575421942bfa8 |
|
| /// File Name: |
HackernetworkMail.txt |
Description:
|
Hackernetwork Mail suffers from XSS in the search parameter.
| | Author: | ajannhwt | | File Size: | 962 | | Last Modified: | May 26 18:13:44 2006 |
| MD5 Checksum: | b4f626249f8b4e3f0691cec28a533e8f |
|
| /// File Name: |
WebHostDirectoryv1.2.txt |
Description:
|
AlstraSoft Web Host Directory v1.2 suffers from XSS.
| | Author: | luny | | File Size: | 1361 | | Last Modified: | May 26 18:13:02 2006 |
| MD5 Checksum: | eb34f99114fcc4563636fe4d6f7d034e |
|
| /// File Name: |
DGbook-1.0.txt |
Description:
|
DGbook v1.0 suffers from XSS.
| | Author: | luny | | File Size: | 799 | | Last Modified: | May 26 18:12:24 2006 |
| MD5 Checksum: | 61bebf0ae5a86fa614e789f5aaff6177 |
|
| /// File Name: |
ArticleManager-1.6.txt |
Description:
|
Alstrasoft Article Manager Pro v1.6 suffers from XSS and full path disclosure vulnerabilities.
| | Author: | luny | | File Size: | 1853 | | Last Modified: | May 26 18:11:33 2006 |
| MD5 Checksum: | 6b8362340d998e742df2f165ce6121e7 |
|
| /// File Name: |
AlstraSoftE-Friends.txt |
Description:
|
Alstrasoft E-friends suffers from XSS in index.php.
| | Author: | luny | | File Size: | 441 | | Last Modified: | May 26 18:10:51 2006 |
| MD5 Checksum: | 8fabe870ca72379110a29888f08b445e |
|
| /// File Name: |
SkyeShoutbox-1.2.0.txt |
Description:
|
SkyeShoutbox versions less than or equal to v.1.2.0 suffer from many XSS vulnerabilities.
| | Author: | zerogue | | File Size: | 233 | | Last Modified: | May 26 18:09:25 2006 |
| MD5 Checksum: | 24033b300bdb67130b4058c5623958d1 |
|
| /// File Name: |
RusscomPing.txt |
Description:
|
Russcom's Ping script allows attackers to execute arbitrary code.
| | Author: | zerogue | | File Size: | 294 | | Last Modified: | May 26 18:08:31 2006 |
| MD5 Checksum: | 4e756f2146c8815a59fb4fe2dfb01f74 |
|
| /// File Name: |
RusscomPHPImages.txt |
Description:
|
Russcom PHPImages doesn't validate if the uploaded file is an image, it just checks for the extension, thus allowing an attacker to upload php scripts with a .gif extension for example.
| | Author: | zerogue | | File Size: | 393 | | Last Modified: | May 26 18:07:43 2006 |
| MD5 Checksum: | beab3cc3ea5f47f0c4e8f3ebbfa87b7d |
|
| /// File Name: |
QBv14.txt |
Description:
|
QBv14 suffers from many XSS vulnerabilities.
| | Author: | zerogue | | File Size: | 169 | | Last Modified: | May 26 18:06:55 2006 |
| MD5 Checksum: | 5b52bd7753c62a7545fb5a83932162fe |
|
| /// File Name: |
IpLogger-1.7.txt |
Description:
|
IpLogger versions less than or equal to 1.7 suffer from XSS
| | Author: | zerogue | | File Size: | 365 | | Last Modified: | May 26 18:04:31 2006 |
| MD5 Checksum: | 4d37f1b5ed4939fbfec1ca55a57bf531 |
|
| /// File Name: |
DSChat-1.0.txt |
Description:
|
DSChat versions less than or equal to 1.0 suffer from XSS
| | Author: | zerogue | | File Size: | 260 | | Last Modified: | May 26 18:03:45 2006 |
| MD5 Checksum: | 201c6b299808786ca376c5815f2f6c22 |
|
| /// File Name: |
OpenCms-6.0.xss.txt |
Description:
|
OpenCms version 6.0.x Xml Content Demo search engine suffers from a XSS vulnerability.
| | Homepage: | http://www.eazel.es | | File Size: | 772 | | Last Modified: | May 26 18:02:58 2006 |
| MD5 Checksum: | 7969ee06e1dcb86248508b1451670346 |
|
| /// File Name: |
sa20164.txt |
Description:
|
Secunia Security Advisory - Hendrik Weimer has discovered a security issue in AWStats, which can be exploited by malicious people to bypass certain security restrictions.
| | Homepage: | http://secunia.com/advisories/20164/ | | File Size: | 2359 | | Last Modified: | May 26 17:57:34 2006 |
| MD5 Checksum: | 07a1a5ea442042fa2ec929649d3d81f4 |
|
| /// File Name: |
sa20218.txt |
Description:
|
Secunia Security Advisory - VietMafia has reported a vulnerability in eSyndiCat Directory Software, which can be exploited by malicious people to disclose sensitive information.
| | Homepage: | http://secunia.com/advisories/20218/ | | File Size: | 2027 | | Last Modified: | May 26 17:57:34 2006 |
| MD5 Checksum: | 50f668a531654e4d186e63041076d550 |
|
| /// File Name: |
sa20271.txt |
Description:
|
Secunia Security Advisory - rgod has discovered a vulnerability in WordPress, which can be exploited by malicious users to compromise a vulnerable system.
| | Homepage: | http://secunia.com/advisories/20271/ | | File Size: | 2080 | | Last Modified: | May 26 17:57:34 2006 |
| MD5 Checksum: | 1d64393a165843b2b2e67518e172ec48 |
|
| /// File Name: |
sa20272.txt |
Description:
|
Secunia Security Advisory - Marcelo Almeida has discovered some vulnerabilities in CosmicShoppingCart, which can be exploited by malicious people to conduct cross-site scripting and SQL injection attacks.
| | Homepage: | http://secunia.com/advisories/20272/ | | File Size: | 2209 | | Last Modified: | May 26 17:57:34 2006 |
| MD5 Checksum: | c69a54f981b7efb3b134ecc726404303 |
|
| /// File Name: |
sa20273.txt |
Description:
|
Secunia Security Advisory - Aesthetico has reported a vulnerability in SocketMail, which can be exploited by malicious people to compromise a vulnerable system.
| | Homepage: | http://secunia.com/advisories/20273/ | | File Size: | 2035 | | Last Modified: | May 26 17:57:34 2006 |
| MD5 Checksum: | 7f075c5865bf5c776a0e8680236c4ec0 |
|
| /// File Name: |
sa20280.txt |
Description:
|
Secunia Security Advisory - mx has reported a vulnerability in phpFoX, which can be exploited by malicious people to bypass certain security restrictions.
| | Homepage: | http://secunia.com/advisories/20280/ | | File Size: | 1754 | | Last Modified: | May 26 17:57:34 2006 |
| MD5 Checksum: | 431f7e5f2e9c43b3cbc2036a24eb99d4 |
|
|
|
|
|