Section: .. / 0606-advisories /
| /// File Name: |
aWebNews-1.0.txt |
Description:
|
aWebNews version 1.0 suffers from a remote file disclosure vulnerability.
| | Author: | Federico Fazzi | | File Size: | 1005 | | Last Modified: | Jun 11 05:21:53 2006 |
| MD5 Checksum: | e4c68aa4ee408969656fbf20f69baa20 |
|
| /// File Name: |
XtremeDownloadsv.1.0.txt |
Description:
|
Xtreme Downloads v.1.0 suffers from multiple file inclusion vulnerabilities.
| | Author: | black-cod3 | | File Size: | 836 | | Last Modified: | Jun 11 05:18:12 2006 |
| MD5 Checksum: | cbeae17188a9aeec9788422977ef360e |
|
| /// File Name: |
KAPDA-47.txt |
Description:
|
[KAPDA::#47] - myNewsletter 1.1.2 SQL_Injection
| | Homepage: | http://www.KAPDA.ir | | File Size: | 1800 | | Last Modified: | Jun 11 05:17:14 2006 |
| MD5 Checksum: | 9081b758fc5c004f6a1c61c3c7f26cb7 |
|
| /// File Name: |
ewsEngine-1.5.0.txt |
Description:
|
NewsEngine 1.5.0 or prior suffers from a remote SQL injection vulnerability in newscomments.php.
| | Author: | ajann | | File Size: | 374 | | Last Modified: | Jun 11 05:12:38 2006 |
| MD5 Checksum: | 62629145abc8020f806826102f32395e |
|
| /// File Name: |
KmitaFAQv1.0.txt |
Description:
|
Kmita FAQ v1.0 suffers from XSS and SQL injection.
| | Author: | luny | | File Size: | 347 | | Last Modified: | Jun 11 05:09:38 2006 |
| MD5 Checksum: | 83956cd801a1af4423240c4cb45241dd |
|
| /// File Name: |
20060611-XSS |
Description:
|
List of XSS vulnerabilities received between 06/02/06 and 06/11/06. Affected software includes: LabWiki 1.0, LarkinWEB Database Development, Web Site Design Marketing and Advertising System, ASPScriptz Guest Book 2.0 , ParticleSoft Whois v1.0.3, ParticleSoft Wiki v1.0.2, GANTTy v1.0.3, MyBB 1.1.2 New XSS, PBLGuestbook v1.31, ViArt Shop v2.5.5 Free (and possibly Light, Standard, and Enterprise), E-Dating System, vSCAL and vREAL v1.0, Easy Ad-Manager, Ez Ringtone Manager, tikiwiki 1.9.x, Skoom i.List 1.5, OkMall v1.0, QuickLinks v1.1, OKArticles v1.0, iFoto v0.20-06/06/06, phazizGuestbook v2.0, Ticket Booking Script, MobeSpace v2.0, TinyMuw v1.0, Contensis CMS, Daum Search, DaNaWa Search, DreamWiz Search.
| | Author: | PSS Staff | | Homepage: | http://packetstormsecurity.org/ | | File Size: | 19761 | | Last Modified: | Jun 11 05:08:38 2006 |
| MD5 Checksum: | ec1b4e4ae4b34eb4c0fc09e140cf27ac |
|
| /// File Name: |
CyBoards-1.25.txt |
Description:
|
CyBoards PHP Lite v1.25 suffer from a remote file inclusion vulnerability in common.php.
| | Homepage: | http://wWw.SaVSaK.CoM | | File Size: | 614 | | Last Modified: | Jun 11 05:07:18 2006 |
| MD5 Checksum: | 4a317289486c1cae1d92967c4a9bdb0c |
|
| /// File Name: |
rumble-1.02.txt |
Description:
|
Rumble versions less than or equal to 1.02 suffer from remote file inclusion vulnerabilities.
| | Author: | Milli-Harekat | | File Size: | 615 | | Last Modified: | Jun 11 05:04:23 2006 |
| MD5 Checksum: | ecf9bb1ed09fc3489084980f16ce1419 |
|
| /// File Name: |
Bookmark4U-2.0.0.txt |
Description:
|
Bookmark4U versions less than or equal to 2.0.0 suffer from remote file inclusion vulnerabilities.
| | Author: | SnIpEr_SA | | File Size: | 1356 | | Last Modified: | Jun 11 05:03:20 2006 |
| MD5 Checksum: | 6961cfd8199ab6f66b608b79f7f38c25 |
|
| /// File Name: |
shoutcastservers.txt |
Description:
|
Shoutcast servers may be susceptible to XSS in the DJ columns.
| | Author: | Mantas Jadzevi | | File Size: | 451 | | Last Modified: | Jun 11 04:41:15 2006 |
| MD5 Checksum: | 5444804061c6b33ec05401cec07dd9e8 |
|
| /// File Name: |
PHP-Nuke-7.9.txt |
Description:
|
PHP-Nuke versions less than or equal to 7.9 suffer from XSS in the Search parameter.
| | Author: | try_og | | File Size: | 293 | | Last Modified: | Jun 11 04:40:12 2006 |
| MD5 Checksum: | ba5bb290a0d317150bf00ef5fb95c058 |
|
| /// File Name: |
NPDS-5.10.txt |
Description:
|
NPDS versions less than or equal to 5.10 suffer from local file inclusion, XSS, and full path disclosure.
| | Author: | gmdarkfig | | File Size: | 1322 | | Last Modified: | Jun 11 04:38:51 2006 |
| MD5 Checksum: | fc63d1a6fbc9bb3235c0b0fcfc9e6800 |
|
| /// File Name: |
gallery2.4.0.txt |
Description:
|
gallery 2.4.0 suffers from a remote file disclosure vulnerability.
| | Author: | Federico Fazzi | | File Size: | 2499 | | Last Modified: | Jun 11 04:37:57 2006 |
| MD5 Checksum: | e99e75a74f788e64dd3823ea021b07ab |
|
| /// File Name: |
USN-296-1.txt |
Description:
|
Ubuntu Security Notice 296-1: firefox vulnerabilities
| | Homepage: | http://security.ubuntu.com/ | | File Size: | 9729 | | Last Modified: | Jun 11 04:26:14 2006 |
| MD5 Checksum: | cbb1b7a7220061d387fd5fa931cc9dd3 |
|
| /// File Name: |
USN-295-1.txt |
Description:
|
Ubuntu Security Notice 295-1: xine-lib vulnerability
| | Homepage: | http://security.ubuntu.com/ | | File Size: | 6012 | | Last Modified: | Jun 11 04:26:08 2006 |
| MD5 Checksum: | 466d42e90ba77eaa045799b7f603c82e |
|
| /// File Name: |
USN-294-1.txt |
Description:
|
Ubuntu Security Notice 294-1: A Denial of Service vulnerability has been found in the function for encoding email addresses. Addresses containing a '=' before the '@' character caused the Courier to hang in an endless loop, rendering the service unusable.
| | Homepage: | http://security.ubuntu.com/ | | File Size: | 29476 | | Last Modified: | Jun 11 04:25:59 2006 |
| MD5 Checksum: | 208ce8ed1bbf3a1e04696e9611d6536f |
|
| /// File Name: |
USN-288-3.txt |
Description:
|
Ubuntu Security Notice 288-3: dovecot, exim4, postfix vulnerabilities
| | Homepage: | http://security.ubuntu.com/ | | File Size: | 27980 | | Last Modified: | Jun 11 04:25:52 2006 |
| MD5 Checksum: | 0f7527b671f2d03a7433bdbc30d99b3c |
|
| /// File Name: |
USN-292-1.txt |
Description:
|
Ubuntu Security Notice 292-1: binutils vulnerability
| | Homepage: | http://security.ubuntu.com/ | | File Size: | 10468 | | Last Modified: | Jun 11 04:25:47 2006 |
| MD5 Checksum: | 17e64f42f3114d99d8febdb8ee1dab74 |
|
| /// File Name: |
USN-293-1.txt |
Description:
|
Ubuntu Security Notice 293-1: gdm vulnerability
| | Homepage: | http://security.ubuntu.com/ | | File Size: | 3501 | | Last Modified: | Jun 11 04:25:37 2006 |
| MD5 Checksum: | 17ca8fcff3f03e696dd5d598b67f1781 |
|
| /// File Name: |
USN-288-2.txt |
Description:
|
Ubuntu Security Notice 288-2: postgresql-8.1 vulnerabilities
| | Homepage: | http://security.ubuntu.com/ | | File Size: | 10920 | | Last Modified: | Jun 11 04:25:33 2006 |
| MD5 Checksum: | 450ff04965b265327ef89206dca3e66a |
|
| /// File Name: |
USN-290-1.txt |
Description:
|
Ubuntu Security Notice 290-1: awstats vulnerability
| | Homepage: | http://security.ubuntu.com/ | | File Size: | 4128 | | Last Modified: | Jun 11 04:25:24 2006 |
| MD5 Checksum: | 2b1b85a1c67b30ce5882fafad03254e2 |
|
| /// File Name: |
USN-289-1.txt |
Description:
|
Ubuntu Security Notice 289-1: Vixie Cron allows local users to execute programs as root.
| | Homepage: | http://security.ubuntu.com/ | | File Size: | 9376 | | Last Modified: | Jun 11 04:25:16 2006 |
| MD5 Checksum: | 0475eb395c346079cd576951d66c2631 |
|
| /// File Name: |
glsa-200606-06.txt |
Description:
|
Gentoo Linux Security Advisory GLSA 200606-06 - Hendrik Weimer has found that if updating the statistics via the web frontend is enabled, it is possible to inject arbitrary code via a pipe character in the migrate parameter. Additionally, r0t has discovered that AWStats fails to properly sanitize user-supplied input in awstats.pl. Versions less than 6.5-r1 are affected.
| | Homepage: | http://security.gentoo.org | | File Size: | 3142 | | Last Modified: | Jun 11 04:24:10 2006 |
| MD5 Checksum: | 205e539642523e01bb222fa57a5db1f9 |
|
| /// File Name: |
glsa-200606-05.txt |
Description:
|
Gentoo Linux Security Advisory GLSA 200606-05 - Pound fails to handle HTTP requests with conflicting Content-Length and Transfer-Encoding headers correctly. Versions less than 2.0.5 are affected.
| | Homepage: | http://security.gentoo.org | | File Size: | 2683 | | Last Modified: | Jun 11 04:24:03 2006 |
| MD5 Checksum: | 09eb8d13a1bbb9a20486643f75befc3e |
|
| /// File Name: |
glsa-200606-04.txt |
Description:
|
Gentoo Linux Security Advisory GLSA 200606-04 - Some integer overflows exist when adding elements to the smartlists. Non-printable characters received from the network are not properly sanitised before being logged. There are additional unspecified bugs in the directory server and in the internal circuits. Versions less than 0.1.1.20 are affected.
| | Homepage: | http://security.gentoo.org | | File Size: | 2838 | | Last Modified: | Jun 11 04:23:57 2006 |
| MD5 Checksum: | 894806c78f157fa8fe4724e5d95f2ebc |
|
|
|
|
|