 |
|
|
|
Очередные ошибки PHP, ASP, CGI дополнено с 19 апреля 2005 г. | | Опубликовано: |  | 23 апреля 2005 г. | | Источник: |  | | | SecurityVulns ID: |  | 4708 | | Тип: |  | удаленная | | Опасность: |  | 5/10 | | Описание: |  | Инъекции PHP, инъекции SQL, обратный путь в каталогах, межсайтовый скриптинг и т.д. |
| Оригинальный текст |  | SECUNIA, [SA15054] WebAPP E-Cart Module Shell Command Injection Vulnerability (23.04.2005) |
| |  | ShineShadow, Multiple vulnerabilities in Argosoft Mail Server 1.8.7.6 (23.04.2005) |
| |  | dcrab_(at)_hackerscenter.com, Multiple Sql injection and XSS in Asp Nuke 0.80 (Working exploits included) (23.04.2005) |
| |  | deluxe_(at)_security-project.org, [SePro Bugtraq] WBB - WoltLab Burning Board <= 2.3.1 - XSS Vulnerability (22.04.05) (23.04.2005) |
| |  | SECUNIA, [SA15038] netMailshar Professional Two Vulnerabilities (22.04.2005) |
| |  | piker piker, Vulnerability kali's tagboard (22.04.2005) |
| |  | SECURITEAM, [NT] OneWorldStore Cross Site Scripting and SQL Injection Vulnerabilities (21.04.2005) |
| |  | SECURITEAM, [UNIX] Jaws Cross Site Scripting (GlossaryModel.php) (21.04.2005) |
| |  | SSC Advisory Notice, Secure Science Corporation Application Software Advisory 055 (21.04.2005) |
| |  | c0d3r_(at)_ihsteam.com, Ecommerce-Carts SQL injection vulnerability ( IHSTeam ) (21.04.2005) |
| |  | jaguar, Annuaire Netref v4.2 [ fwrite php ] vulnerability (21.04.2005) |
| |  | JeiAr, Multiple Security Issues Found In AZBB (21.04.2005) |
| |  | JeiAr, Multiple eGroupware Vulnerabilities (21.04.2005) |
| |  | Zinho, [HSC Security Group] Ocean12 Calendar manager 1.01 SQL injection (20.04.2005) |
| |  | SECUNIA, [SA15027] PHP Labs proFile "dir" and "file" Cross-Site Scripting (20.04.2005) |
| |  | SECUNIA, [SA15009] CityPost Automated Link Exchange "msg" Cross-Site Scripting (20.04.2005) |
| |  | SECUNIA, [SA15010] CityPost Simple PHP Upload "message" Cross-Site Scripting (20.04.2005) |
| |  | SECUNIA, [SA15011] CityPost Image Editor Cross-Site Scripting Vulnerabilities (20.04.2005) |
| |  | CorryL, [Full-disclosure] Shoutbox SCRIPT <= 3.0.2 Administrative MD5 Username and Password Retrieval (20.04.2005) |
| |  | dcrab_(at)_hackerscenter.com, DUportal Pro 3.4 has MANY Sql injection and Sql Errors. (20.04.2005) |
| |  | DEBIAN, [SECURITY] [DSA 712-1] New geneweb packages fix insecure file operations (20.04.2005) |
| |  | DEBIAN, [SECURITY] [DSA 711-1] New info2www packages fix cross-site scripting vulnerability (20.04.2005) |
| |  | Hillel Himovich, UBB Thread printthread.php SQL Injection (20.04.2005) |
| |  | deluxe_(at)_security-project.org, phpBB - Knowledge Base MOD - SQL-Injection and Full Path Disclosure (19.04.2005) |
| |  | GHC team, Vulnerability in Coppermine Photo Gallery 1.3.* (19.04.2005) |
|
|
|
|
|
|
|
|