<?xml version="1.0" encoding="ISO-8859-1" ?>
<rss version="2.0">
	<channel>
	<title>Packet Storm Security Last 100</title>
	<link>http://packetstormsecurity.org/</link>
	<description>100 Most Recent Packet Storm File Additions</description>
	<language>en-us</language>

<item>
	<title>browser_insecurity_iceberg_2008.pdf</title>
	<link>http://packetstormsecurity.org/papers/general/browser_insecurity_iceberg_2008.pdf</link>
	<description>Understanding the Web browser threat: Examination of vulnerable online Web browser populations and the  insecurity iceberg . </description>
</item>
<item>
	<title>SSRT080039.txt</title>
	<link>http://packetstormsecurity.org/0807-advisories/SSRT080039.txt</link>
	<description>HP Security Bulletin - A potential security vulnerability has been identified with HP System Management Homepage (SMH) for Linux and Windows. This vulnerability could by exploited remotely to allow cross site scripting (XSS). </description>
</item>
<item>
	<title>25C3-CFP.txt</title>
	<link>http://packetstormsecurity.org/papers/call_for/25C3-CFP.txt</link>
	<description>The Call For Papers for the 25th Chaos Communication Congress (25C3) has been announced. </description>
</item>
<item>
	<title>SCANIT-2008-003.txt</title>
	<link>http://packetstormsecurity.org/0807-advisories/SCANIT-2008-003.txt</link>
	<description>Wordtrans versions 1.1pre15 and below suffer from a remote command execution vulnerability. </description>
</item>
<item>
	<title>SCANIT-2008-002.txt</title>
	<link>http://packetstormsecurity.org/0807-advisories/SCANIT-2008-002.txt</link>
	<description>Wordtrans versions 1.1pre15 and below suffer from a remote command execution vulnerability. </description>
</item>
<item>
	<title>SCANIT-2008-001.txt</title>
	<link>http://packetstormsecurity.org/0807-advisories/SCANIT-2008-001.txt</link>
	<description>QNX RTOS phgrafx version 6.3.2 and 6.3.0 suffer from a privilege escalation vulnerability. </description>
</item>
<item>
	<title>usurdat.zip</title>
	<link>http://packetstormsecurity.org/0807-exploits/usurdat.zip</link>
	<description>Proof of concept denial of service exploit for SOLDNER - Secret Wars versions 33724 and below which suffer from an endless loop vulnerability. </description>
</item>
<item>
	<title>usurdat.txt</title>
	<link>http://packetstormsecurity.org/0807-advisories/usurdat.txt</link>
	<description>SOLDNER - Secret Wars versions 33724 and below suffer from an endless loop vulnerability. </description>
</item>
<item>
	<title>glsa-200807-02.txt</title>
	<link>http://packetstormsecurity.org/0807-advisories/glsa-200807-02.txt</link>
	<description>Gentoo Linux Security Advisory GLSA 200807-02 - Nico Golde reported an off-by-one error within the read_client() function in the webhttpd.c file, leading to a stack-based buffer overflow. Stefan Cornelius (Secunia Research) reported a boundary error within the same function, also leading to a stack-based buffer overflow. Both vulnerabilities require that the HTTP Control interface is enabled. Versions less than 3.2.10.1 are affected. </description>
</item>
<item>
	<title>glsa-200807-01.txt</title>
	<link>http://packetstormsecurity.org/0807-advisories/glsa-200807-01.txt</link>
	<description>Gentoo Linux Security Advisory GLSA 200807-01 - Multiple integer overflows may allow for Denial of Service. Versions less than 2.4.4-r13 are affected. </description>
</item>
<item>
	<title>blogparticle-traverse.txt</title>
	<link>http://packetstormsecurity.org/0807-exploits/blogparticle-traverse.txt</link>
	<description>Blog Particle version 8.0 suffers from directory traversal and database credential disclosure vulnerabilities. </description>
</item>
<item>
	<title>hbr-rfi.txt</title>
	<link>http://packetstormsecurity.org/0807-exploits/hbr-rfi.txt</link>
	<description>HIOX Banner Rotator (HBR) version 1.3 suffers from a remote file inclusion vulnerability. </description>
</item>
<item>
	<title>0806-exploits.tgz</title>
	<link>http://packetstormsecurity.org/0806-exploits/0806-exploits.tgz</link>
	<description>Packet Storm new exploits for June, 2008. </description>
</item>
<item>
	<title>mambongal-sql.txt</title>
	<link>http://packetstormsecurity.org/0807-exploits/mambongal-sql.txt</link>
	<description>The Mambo n-gallery component suffers from multiple SQL injection vulnerabilities. </description>
</item>
<item>
	<title>psys070-sql.txt</title>
	<link>http://packetstormsecurity.org/0807-exploits/psys070-sql.txt</link>
	<description>pSys version 0.7.0 suffers from a remote SQL injection vulnerability in chatbox.php. </description>
</item>
<item>
	<title>pivot-disclosure.txt</title>
	<link>http://packetstormsecurity.org/0807-exploits/pivot-disclosure.txt</link>
	<description>Pivot version 1.40.5 Dreamwind load_template() credential disclosure exploit. </description>
</item>
<item>
	<title>USN-617-2.txt</title>
	<link>http://packetstormsecurity.org/0807-advisories/USN-617-2.txt</link>
	<description>Ubuntu Security Notice 617-2 - USN-617-1 fixed vulnerabilities in Samba. The upstream patch introduced a regression where under certain circumstances accessing large files might cause the client to report an invalid packet length error. This update fixes the problem. Samba developers discovered that nmbd could be made to overrun a buffer during the processing of GETDC logon server requests. When samba is configured as a Primary or Backup Domain Controller, a remote attacker could send malicious logon requests and possibly cause a denial of service. Alin Rad Pop of Secunia Research discovered that Samba did not properly perform bounds checking when parsing SMB replies. A remote attacker could send crafted SMB packets and execute arbitrary code. </description>
</item>
<item>
	<title>rcm-sql.txt</title>
	<link>http://packetstormsecurity.org/0807-exploits/rcm-sql.txt</link>
	<description>RCM Revision Web Development suffers from a remote SQL injection vulnerability in products.php. </description>
</item>
<item>
	<title>barenuked-admin.txt</title>
	<link>http://packetstormsecurity.org/0807-exploits/barenuked-admin.txt</link>
	<description>BareNuked CMS version 1.1.0 arbitrary add administrator exploit. </description>
</item>
<item>
	<title>faname10-xss.txt</title>
	<link>http://packetstormsecurity.org/0807-exploits/faname10-xss.txt</link>
	<description>Fa Name version 1.0 suffers from multiple cross site scripting vulnerabilities. </description>
</item>
<item>
	<title>faname10-sql.txt</title>
	<link>http://packetstormsecurity.org/0807-exploits/faname10-sql.txt</link>
	<description>Fa Name version 1.0 suffers from a remote SQL injection vulnerability. </description>
</item>
<item>
	<title>rssagg-sql.txt</title>
	<link>http://packetstormsecurity.org/0807-exploits/rssagg-sql.txt</link>
	<description>RSS-aggregator version 1.0 suffers from direct administrative access and SQL injection vulnerabilities. </description>
</item>
<item>
	<title>lul-busybox.c</title>
	<link>http://packetstormsecurity.org/0807-exploits/lul-busybox.c</link>
	<description>BusyBox local format string exploit. </description>
</item>
<item>
	<title>openbsdanim-local.txt</title>
	<link>http://packetstormsecurity.org/0807-exploits/openbsdanim-local.txt</link>
	<description>Local root animated,.. yes animated, exploit for OpenBSD 4.0 that takes advantage of an old vga vulnerability. </description>
</item>
<item>
	<title>ashop-sql.txt</title>
	<link>http://packetstormsecurity.org/0807-exploits/ashop-sql.txt</link>
	<description>AShop Deluxe version 4.x remote SQL injection exploit that takes advantage of catalogue.php. </description>
</item>
<item>
	<title>mybloggie-sql.txt</title>
	<link>http://packetstormsecurity.org/0807-exploits/mybloggie-sql.txt</link>
	<description>myBloggie version 2.1.6 suffers from multiple remote SQL injection vulnerability. </description>
</item>
<item>
	<title>catviz-sql.txt</title>
	<link>http://packetstormsecurity.org/0807-exploits/catviz-sql.txt</link>
	<description>Catviz version 0.4.0 beta1 suffers from a SQL injection vulnerability. </description>
</item>
<item>
	<title>surgemail-dos.txt</title>
	<link>http://packetstormsecurity.org/0806-exploits/surgemail-dos.txt</link>
	<description>Surgemail version 39e-1 post authentication IMAP remote buffer overflow denial of service exploit. </description>
</item>
<item>
	<title>eshop100-sql.txt</title>
	<link>http://packetstormsecurity.org/0806-exploits/eshop100-sql.txt</link>
	<description>eSHOP100 suffers from a remote SQL injection vulnerability. </description>
</item>
<item>
	<title>dirlist-traverse.txt</title>
	<link>http://packetstormsecurity.org/0806-exploits/dirlist-traverse.txt</link>
	<description>dirLIST suffers from an arbitrary file download vulnerability. </description>
</item>
<item>
	<title>singapore-database.txt</title>
	<link>http://packetstormsecurity.org/0806-exploits/singapore-database.txt</link>
	<description>Singapore version 0.10.1 suffers from directory traversal and database credential exposure vulnerabilities. </description>
</item>
<item>
	<title>pktanon-1.2.0-dev.tar.gz</title>
	<link>http://packetstormsecurity.org/UNIX/scanners/pktanon-1.2.0-dev.tar.gz</link>
	<description>PKtAnon performs network trace anonymization. It is highly configurable and uses anonymization profiles. Anonymization profiles allow for mapping of arbitrary anonymization primitives to protocol attributes, thus providing high flexibility and easy usability. A huge number of anonymization primitives and network protocols are supported and ready to use for online and offline anonymization. </description>
</item>
<item>
	<title>acmlmboard-sql.txt</title>
	<link>http://packetstormsecurity.org/0806-exploits/acmlmboard-sql.txt</link>
	<description>AcmlmBoard version 1.A2 suffers from a remote SQL injection vulnerability. </description>
</item>
<item>
	<title>haloloop2.zip</title>
	<link>http://packetstormsecurity.org/0806-exploits/haloloop2.zip</link>
	<description>Proof of concept exploit for Halo: Combat Evolved versions 1.07 and below which suffer from an endless loop vulnerability. </description>
</item>
<item>
	<title>haloloop2.txt</title>
	<link>http://packetstormsecurity.org/0806-advisories/haloloop2.txt</link>
	<description>Halo: Combat Evolved versions 1.07 and below suffer from an endless loop vulnerability. </description>
</item>
<item>
	<title>stalker39x.zip</title>
	<link>http://packetstormsecurity.org/0806-exploits/stalker39x.zip</link>
	<description>Proof of concept exploit for S.T.A.L.K.E.R.: Shadow of Chernobyl versions 1.0006 and below which suffer from multiple buffer overflow vulnerabilities. </description>
</item>
<item>
	<title>stalker39x.txt</title>
	<link>http://packetstormsecurity.org/0806-advisories/stalker39x.txt</link>
	<description>S.T.A.L.K.E.R.: Shadow of Chernobyl versions 1.0006 and below suffer from multiple buffer overflow vulnerabilities. </description>
</item>
<item>
	<title>seportal-sql.txt</title>
	<link>http://packetstormsecurity.org/0806-exploits/seportal-sql.txt</link>
	<description>SePortal version 2.4 suffers from a remote SQL injection vulnerability in poll.php. </description>
</item>
<item>
	<title>phpfusionclass-sql.txt</title>
	<link>http://packetstormsecurity.org/0806-exploits/phpfusionclass-sql.txt</link>
	<description>The PHP-Fusion classifieds module suffers from a remote SQL injection vulnerability. </description>
</item>
<item>
	<title>sebraccms-sql.txt</title>
	<link>http://packetstormsecurity.org/0806-exploits/sebraccms-sql.txt</link>
	<description>SebracCMS versions 0.4 and below suffer from multiple SQL injection vulnerabilities. </description>
</item>
<item>
	<title>joomlawebtv-sql.txt</title>
	<link>http://packetstormsecurity.org/0806-exploits/joomlawebtv-sql.txt</link>
	<description>Joomla Xe webtv component blind SQL injection exploit. </description>
</item>
<item>
	<title>joomlabea-sql.txt</title>
	<link>http://packetstormsecurity.org/0806-exploits/joomlabea-sql.txt</link>
	<description>The Joomla beamospetition component suffers from a remote SQL injection vulnerability. </description>
</item>
<item>
	<title>obm-sql.txt</title>
	<link>http://packetstormsecurity.org/0806-exploits/obm-sql.txt</link>
	<description>Online Booking Manager version 2.2 suffers from a remote SQL injection vulnerability. </description>
</item>
<item>
	<title>joomlajabode-sql.txt</title>
	<link>http://packetstormsecurity.org/0806-exploits/joomlajabode-sql.txt</link>
	<description>The Joomla jabode component suffers from a remote SQL injection vulnerability. </description>
</item>
<item>
	<title>SSRT080063-2.txt</title>
	<link>http://packetstormsecurity.org/0806-advisories/SSRT080063-2.txt</link>
	<description>HP Security Bulletin - A potential security vulnerability has been identified with HP-UX running Apache with PHP. This vulnerability could be exploited remotely to execute arbitrary code. </description>
</item>
<item>
	<title>SSRT080075.txt</title>
	<link>http://packetstormsecurity.org/0806-advisories/SSRT080075.txt</link>
	<description>HP Security Bulletin - A potential security vulnerabilities has been identified with HP-UX running HP CIFS Server (Samba). The vulnerabilities could be exploited remotely to execute arbitrary code. </description>
</item>
<item>
	<title>otmanager-cookie.txt</title>
	<link>http://packetstormsecurity.org/0806-exploits/otmanager-cookie.txt</link>
	<description>OTManager CMS version 2.4 suffers from an insecure cookie handling vulnerability. </description>
</item>
<item>
	<title>aplus-cookie.txt</title>
	<link>http://packetstormsecurity.org/0806-exploits/aplus-cookie.txt</link>
	<description>A+ PHP scripts News Management System suffers from an insecure cookie handling vulnerability. </description>
</item>
<item>
	<title>poweraward-lfi.txt</title>
	<link>http://packetstormsecurity.org/0806-exploits/poweraward-lfi.txt</link>
	<description>PowerAward version 1.1.0 RC1 suffers from local file inclusion and cross site scripting vulnerabilities. </description>
</item>
<item>
	<title>bacom2008-cfp.txt</title>
	<link>http://packetstormsecurity.org/papers/call_for/bacom2008-cfp.txt</link>
	<description>Call for the papers for the first annual BA-Con applied technical security conference has been announced. It will be held in Buenos Aires on September 30th and October 1st, 2008. </description>
</item>
<item>
	<title>WebUI-dos.rar</title>
	<link>http://packetstormsecurity.org/0806-exploits/WebUI-dos.rar</link>
	<description>uTorrent / BitTorrent WebUI HTTP 1.7.7/6.0.1 denial of service exploit. </description>
</item>
<item>
	<title>unhide20080519.tgz</title>
	<link>http://packetstormsecurity.org/UNIX/audit/unhide20080519.tgz</link>
	<description>Unhide is a forensic tool to find hidden processes and TCP/UDP ports that are hidden via rootkits, LKMs, or other techniques.</description>
</item>
<item>
	<title>w1l3d4-sqlxss.txt</title>
	<link>http://packetstormsecurity.org/0806-exploits/w1l3d4-sqlxss.txt</link>
	<description>W1L3D4 Philboard version 1.2 suffers from blind SQL injection and cross site scripting vulnerabilities. </description>
</item>
<item>
	<title>otmanager-lfixss.txt</title>
	<link>http://packetstormsecurity.org/0806-exploits/otmanager-lfixss.txt</link>
	<description>OTManager CMS version 24a suffers from local file inclusion and cross site scripting vulnerabilities. </description>
</item>
<item>
	<title>orca-rfi.txt</title>
	<link>http://packetstormsecurity.org/0806-exploits/orca-rfi.txt</link>
	<description>Orca version 2.0 suffers from a remote file inclusion vulnerability in params.php. </description>
</item>
<item>
	<title>cheatswebsite-sql.txt</title>
	<link>http://packetstormsecurity.org/0806-exploits/cheatswebsite-sql.txt</link>
	<description>Cheats Complete Website version 1.1.1 suffers from a SQL injection vulnerability. </description>
</item>
<item>
	<title>drinkswebsite-sql.txt</title>
	<link>http://packetstormsecurity.org/0806-exploits/drinkswebsite-sql.txt</link>
	<description>Drinks Complete Website version 2.1.0 suffers from a SQL injection vulnerability. </description>
</item>
<item>
	<title>jokeswebsite-sql.txt</title>
	<link>http://packetstormsecurity.org/0806-exploits/jokeswebsite-sql.txt</link>
	<description>Jokes Complete Website version 2.1.3 suffers from a SQL injection vulnerability. </description>
</item>
<item>
	<title>riddle-sql.txt</title>
	<link>http://packetstormsecurity.org/0806-exploits/riddle-sql.txt</link>
	<description>Riddle Complete Website version 1.2.1 suffers from a SQL injection vulnerability. </description>
</item>
<item>
	<title>seagull-upload.txt</title>
	<link>http://packetstormsecurity.org/0806-exploits/seagull-upload.txt</link>
	<description>Seagull PHP Framework version 0.6.4 and below arbitrary file upload exploit. </description>
</item>
<item>
	<title>phpblaster-lfi.txt</title>
	<link>http://packetstormsecurity.org/0806-exploits/phpblaster-lfi.txt</link>
	<description>phpBlaster CMS version 1.0 RC1 suffers from multiple local file inclusion vulnerabilities. </description>
</item>
<item>
	<title>MDVSA-2008-124.txt</title>
	<link>http://packetstormsecurity.org/0806-advisories/MDVSA-2008-124.txt</link>
	<description>Mandriva Linux Security Advisory - A vulnerability in the Speex library was found where it did not properly validate input values read from the Speex files headers. An attacker could create a malicious Speex file that would crash an application or potentially allow the execution of arbitrary code with the privileges of the application calling the Speex library. Xine-lib is similarly affected by this issue. As well, the previous version of xine as provided in Mandriva Linux 2008.1 would crash when playing matroska files, and a regression was introduced that prevented Amarok from playing m4a files. </description>
</item>
<item>
	<title>USN-621-1.txt</title>
	<link>http://packetstormsecurity.org/0806-advisories/USN-621-1.txt</link>
	<description>Ubuntu Security Notice 621-1 - Drew Yao discovered several vulnerabilities in Ruby which lead to integer overflows. If a user or automated system were tricked into running a malicious script, an attacker could cause a denial of service or execute arbitrary code with the privileges of the user invoking the program. Drew Yao discovered that Ruby did not sanitize its input when using ALLOCA. If a user or automated system were tricked into running a malicious script, an attacker could cause a denial of service via memory corruption. </description>
</item>
<item>
	<title>dsa-1599-1.txt</title>
	<link>http://packetstormsecurity.org/0806-advisories/dsa-1599-1.txt</link>
	<description>Debian Security Advisory 1599-1 - Havoc Pennington discovered that DBus, a simple interprocess messaging system, performs insufficient validation of security policies, which might allow local privilege escalation. </description>
</item>
<item>
	<title>wellyblog-xss.txt</title>
	<link>http://packetstormsecurity.org/0806-exploits/wellyblog-xss.txt</link>
	<description>WellyBlog Open Source Blog Portal suffers from a cross site scripting vulnerability. </description>
</item>
<item>
	<title>prelude-manager-0.9.13.tar.gz</title>
	<link>http://packetstormsecurity.org/UNIX/IDS/prelude-manager-0.9.13.tar.gz</link>
	<description>Prelude Manager is the main program of the Prelude Hybrid IDS suite. It is able to register local or remote sensors, let the operator configure them remotely, receive alerts, and store alerts in a database or any format supported by reporting plugins, thus providing centralized logging and analysis.</description>
</item>
<item>
	<title>strongswan-4.2.4.tar.gz</title>
	<link>http://packetstormsecurity.org/crypt/misc/strongswan-4.2.4.tar.gz</link>
	<description>strongSwan is a complete IPsec and IKEv1 implementation for Linux 2.4 and 2.6 kernels. It interoperates with most other IPsec-based VPN products. It is a descendant of the discontinued FreeS/WAN project. The focus of the strongSwan project is on strong authentication mechanisms using X.509 public key certificates and optional secure storage of private keys on smartcards through a standardized PKCS#11 interface. A unique feature is the use of X.509 attribute certificates to implement advanced access control schemes based on group memberships.</description>
</item>
<item>
	<title>Reverse.Engineering.AntiCracking.Techniques.pdf</title>
	<link>http://packetstormsecurity.org/papers/general/Reverse.Engineering.AntiCracking.Techniques.pdf</link>
	<description>This paper was written to give a better understanding of the various approaches taken in reverse engineering. It also provides insight into proper software design to protect sensitive data, etc. </description>
</item>
<item>
	<title>joomlayanc-sql.txt</title>
	<link>http://packetstormsecurity.org/0806-exploits/joomlayanc-sql.txt</link>
	<description>The Joomla YaNC component suffers from a SQL injection vulnerability. </description>
</item>
<item>
	<title>joomlanetinvoice-sql.txt</title>
	<link>http://packetstormsecurity.org/0806-exploits/joomlanetinvoice-sql.txt</link>
	<description>The Joomla netinvoice component version 1.2.0 SP1 suffers from a SQL injection vulnerability. </description>
</item>
<item>
	<title>phpmotion-upload.txt</title>
	<link>http://packetstormsecurity.org/0806-exploits/phpmotion-upload.txt</link>
	<description>PHPmotion versions 2.0 and below remote shell upload exploit that makes use of update_profile.php. </description>
</item>
<item>
	<title>firefox3.tar.gz</title>
	<link>http://packetstormsecurity.org/0806-exploits/firefox3.tar.gz</link>
	<description>This is a specially crafted JPEG that causes a denial of service resulting in a crash in Firefox 3. </description>
</item>
<item>
	<title>kroax-sql.txt</title>
	<link>http://packetstormsecurity.org/0806-exploits/kroax-sql.txt</link>
	<description>The PHP-Fusion module Kroax versions 4.42 and below suffer form a SQL injection vulnerability. </description>
</item>
<item>
	<title>polypager-sqlxss.txt</title>
	<link>http://packetstormsecurity.org/0806-exploits/polypager-sqlxss.txt</link>
	<description>PolyPager versions 1.0rc2 and below suffer from SQL injection and cross site scripting vulnerabilities. </description>
</item>
<item>
	<title>kellerwebadmin-lfi.txt</title>
	<link>http://packetstormsecurity.org/0806-exploits/kellerwebadmin-lfi.txt</link>
	<description>Keller Web Admin CMS version 0.94 Pro suffers form a local file inclusion vulnerability. </description>
</item>
<item>
	<title>galmetapost-lfi.txt</title>
	<link>http://packetstormsecurity.org/0806-exploits/galmetapost-lfi.txt</link>
	<description>Galmeta Post CMS version 0.2 suffers from multiple local file inclusion vulnerabilities. </description>
</item>
<item>
	<title>evolution-dos.txt</title>
	<link>http://packetstormsecurity.org/0806-advisories/evolution-dos.txt</link>
	<description>Evolution version 2.22.2 suffers from a denial of service vulnerability. </description>
</item>
<item>
	<title>pidgin-dos.txt</title>
	<link>http://packetstormsecurity.org/0806-advisories/pidgin-dos.txt</link>
	<description>The Pidgin instant message program version 2.4.1 suffers from a denial of service vulnerability. </description>
</item>
<item>
	<title>rhythmbox-dos.txt</title>
	<link>http://packetstormsecurity.org/0806-advisories/rhythmbox-dos.txt</link>
	<description>Rhythmbox MP3 player version 0.11.5 suffers from a denial of service vulnerability. </description>
</item>
<item>
	<title>theratcms-sqlxss.txt</title>
	<link>http://packetstormsecurity.org/0806-exploits/theratcms-sqlxss.txt</link>
	<description>The Rat CMS version Pre-Alpha 2 suffers from SQL injection and cross site scripting vulnerabilities. </description>
</item>
<item>
	<title>commtouch-xss.txt</title>
	<link>http://packetstormsecurity.org/0806-exploits/commtouch-xss.txt</link>
	<description>The Commtouch Anti-Spam Enterprise Gateway solution suffers from a reflected cross site scripting vulnerability. </description>
</item>
<item>
	<title>USN-620-1.txt</title>
	<link>http://packetstormsecurity.org/0806-advisories/USN-620-1.txt</link>
	<description>Ubuntu Security Notice 620-1 - It was discovered that OpenSSL was vulnerable to a double-free when using TLS server extensions. A remote attacker could send a crafted packet and cause a denial of service via application crash in applications linked against OpenSSL. Ubuntu 8.04 LTS does not compile TLS server extensions by default. It was discovered that OpenSSL could dereference a NULL pointer. If a user or automated system were tricked into connecting to a malicious server with particular cipher suites, a remote attacker could cause a denial of service via application crash. </description>
</item>
<item>
	<title>linkara-xss.txt</title>
	<link>http://packetstormsecurity.org/0806-exploits/linkara-xss.txt</link>
	<description>Linkara.com appears to suffer from a cross site scripting vulnerability. </description>
</item>
<item>
	<title>MDVSA-2008-123.txt</title>
	<link>http://packetstormsecurity.org/0806-advisories/MDVSA-2008-123.txt</link>
	<description>Mandriva Linux Security Advisory - Stefan Cornelius discovered two buffer overflows in Imlib's image loaders for PNM and XPM images, which could possibly result in the execution of arbitrary code. </description>
</item>
<item>
	<title>gtalk-inject.txt</title>
	<link>http://packetstormsecurity.org/0806-exploits/gtalk-inject.txt</link>
	<description>It appears that Gtalk version 1.0.0.105 suffers from cross site scripting vulnerabilities. </description>
</item>
<item>
	<title>cisco-sa-20080625-cucm.txt</title>
	<link>http://packetstormsecurity.org/0806-advisories/cisco-sa-20080625-cucm.txt</link>
	<description>Cisco Security Advisory - Cisco Unified Communications Manager (CUCM), formerly Cisco CallManager, contains a denial of service (DoS) vulnerability in the Computer Telephony Integration (CTI) Manager service that may cause an interruption in voice services and an authentication bypass vulnerability in the Real-Time Information Server (RIS) Data Collector that may expose information that is useful for reconnaissance. </description>
</item>
<item>
	<title>munky-lfi.txt</title>
	<link>http://packetstormsecurity.org/0806-exploits/munky-lfi.txt</link>
	<description>mUnky version 0.0.1 suffers from a local file inclusion vulnerability in index.php. </description>
</item>
<item>
	<title>myphpcms-sql.txt</title>
	<link>http://packetstormsecurity.org/0806-exploits/myphpcms-sql.txt</link>
	<description>MyPHP CMS version 0.3.1 suffers from a remote SQL injection vulnerability in page.php. </description>
</item>
<item>
	<title>pagemanagercms-upload.txt</title>
	<link>http://packetstormsecurity.org/0806-exploits/pagemanagercms-upload.txt</link>
	<description>Page Manager CMS version 2006-02-04 suffers from a remote arbitrary file vulnerability. </description>
</item>
<item>
	<title>webdevindo-sql.txt</title>
	<link>http://packetstormsecurity.org/0806-exploits/webdevindo-sql.txt</link>
	<description>Webdevindo-CMS version 0.1 suffers from a remote SQL injection vulnerability in index.php. </description>
</item>
<item>
	<title>mcguestbook-rfi.txt</title>
	<link>http://packetstormsecurity.org/0806-exploits/mcguestbook-rfi.txt</link>
	<description>mcGuestbook version 1.2 suffers from a remote file inclusion vulnerability. </description>
</item>
<item>
	<title>idebox-rfi.txt</title>
	<link>http://packetstormsecurity.org/0806-exploits/idebox-rfi.txt</link>
	<description>IdeBox suffers from a remote file inclusion vulnerability. </description>
</item>
<item>
	<title>glsa-200806-11.txt</title>
	<link>http://packetstormsecurity.org/0806-advisories/glsa-200806-11.txt</link>
	<description>Gentoo Linux Security Advisory GLSA 200806-11 - Because of sharing the same codebase, IBM JDK and JRE are affected by the vulnerabilities mentioned in GLSA 200804-20. Versions less than 1.5.0.7 are affected. </description>
</item>
<item>
	<title>evacms-rfi.txt</title>
	<link>http://packetstormsecurity.org/0806-exploits/evacms-rfi.txt</link>
	<description>EVA CMS version 2.3.1 suffers from a remote file inclusion vulnerability. </description>
</item>
<item>
	<title>bluemoon-advisory-2008-07.txt</title>
	<link>http://packetstormsecurity.org/0806-advisories/bluemoon-advisory-2008-07.txt</link>
	<description>A format string vulnerability exists in 5th street and derived clients. </description>
</item>
<item>
	<title>tokokita-sql.txt</title>
	<link>http://packetstormsecurity.org/0806-exploits/tokokita-sql.txt</link>
	<description>Exploit for TOKOKITA which suffers from multiple SQL injection vulnerabilities in barang.php. </description>
</item>
<item>
	<title>mosxml-lfi.txt</title>
	<link>http://packetstormsecurity.org/0806-exploits/mosxml-lfi.txt</link>
	<description>MosXML Alpha version 1.x suffers from a remote file inclusion vulnerability. </description>
</item>
<item>
	<title>jonascms-lfi.txt</title>
	<link>http://packetstormsecurity.org/0806-exploits/jonascms-lfi.txt</link>
	<description>Jonas CMS version 1.2 suffers from multiple local file inclusion vulnerabilities. </description>
</item>
<item>
	<title>mamboarticles-sql.txt</title>
	<link>http://packetstormsecurity.org/0806-exploits/mamboarticles-sql.txt</link>
	<description>Mambo Articles component blind SQL injection exploit. </description>
</item>
<item>
	<title>jokesfunny-sql.txt</title>
	<link>http://packetstormsecurity.org/0806-exploits/jokesfunny-sql.txt</link>
	<description>Jokes and Funny Pics scripts suffers from a remote SQL injection vulnerability. </description>
</item></channel>
</rss>
