New User, Welcome!     Login

Next Page >>

Code Injection

eFront <= 3.6.10 (build 11944) Multiple Security Vulnerabilities

   Host: localhost
   Cookie: cookie_login[login]=admin;cookie_login[active]=1;cookie_login[user_type]=administrator;cookie_login[password]=1;cookie_password=1
   Connection: keep-alive
   
  +--------------------+
  | PHP Code Injection |
  +--------------------+
  
  The vulnerable code is located in /www/student.php
  
  123.       if (isset($_GET['course']) || isset($_GET['from_course'])) {

SA00001-2010

for small and medium sized enterprises looking for an inexpensive way to
effectively manage and develop their human resources."
Product link: http://www.orangehrm.com/

2. Vulnerability Information
Class: Cross site scripting, SQL injection, PHP code injection, Cross-site
request forgery
Impact: Session hijacking, unauthorized data access, privilege escalation,
user-assisted arbitrary command execution
Rating: Less critical
Remotely Exploitable: Yes

[MORNINGSTAR-2009-02] Multiple security issues in Cute News and UTF-8 Cute News

8.12.3 Non-Vulnerable packages

UTF-8b


8.13 PHP Code Injection for categories module
------------------------------------------------------------------------------------------------------------------------
Severity:     Medium
Requires:     Administrator level account

8.13.1 Proof of concept exploit

CORE-2009-0108: Multiple vulnerabilities in Sun Calendar Express Web Server

9. *References*

[1] http://www.sun.com/software/products/calendar_srvr/
[2] HTML Code Injection and Cross-Site Scripting
http://www.technicalinfo.net/papers/CSS.html.
[3] The Cross-Site Scripting FAQ (XSS)
http://www.cgisecurity.com/articles/xss-faq.shtml
[4] How to prevent Cross-Site Scripting Security Issues
http://support.microsoft.com/default.aspx?scid=KB;en-us;q252985

ViArt Shopping Cart v3.5 Multiple Remote Vulnerabilities

then save the shopping cart for the tables to be revealed by 
browsing to: http://www.victim.com/cart_save.php
===============================================================

===============================================================
!risk 3 - Arbitrary Code Injection
High
Attackers can use this vulnerability to execute arbitrary code
on a legitimate user.
===============================================================


[Onapsis Security Advisory 2010-003] SAP WebDynpro Runtime XSS/CSS Injection

- - Affected Components:
        
        . SAP NetWeaver 2004 < SP21
        . SAP NetWeaver 2004s < SP13

- - Vulnerability Class: HTML Code Injection

- - Remotely Exploitable: Yes

- - Locally Exploitable: Yes


MULTIPLE CODE INJECTION VULNERABILITIES --TUENTI--SPAIN-->

####################
Language: English
####################

------------------------------------------------------------
MULTIPLE CODE INJECTION VULNERABILITIES --TUENTI--SPAIN-->
------------------------------------------------------------

SYSTEM INFORMATION:

-->WEB: http://www.tuenti.com/

JibberBook GuestBook 2.3 Multiple Vulnerabilities

                </message>

###########################################################################
###########################################################################

=== [ HTML Code Injection ] ===

        [»] add new message
        
                <img src="">


[INFIGO-2008-02-13]: SOPHOS Email Security Appliance Cross Site Scripting Vulnerability

Title: SOPHOS Email Security Appliance Cross Site Scripting Vulnerability
Advisory ID: INFIGO-2008-02-13
Date: 2008-02-13
Advisory URL: http://www.infigo.hr/en/in_focus/advisories/INFIGO-2008-02-13
Impact: Malicious JavaScript Code Injection
Risk Level: Medium
Vulnerability Type: Remote




[OPENADS-SA-2008-001] Openads 2.4.2 vulnerability fixed

Versions not affected: >= 2.4.3
========================================================================


========================================================================
Vulnerability:  Remote PHP code injection and execution
========================================================================

Description
-----------
A remote PHP code injection and execution vulnerability has recently

CORE-2009-0109 - Multiple XSS in Sun Communications Express

10. *References*

[1]
http://www.sun.com/software/products/calendar_srvr/comms_express/index.xml
[2] HTML Code Injection and Cross-Site Scripting
http://www.technicalinfo.net/papers/CSS.html.
[3] The Cross-Site Scripting FAQ (XSS)
http://www.cgisecurity.com/articles/xss-faq.shtml
[4] How to prevent Cross-Site Scripting Security Issues
http://support.microsoft.com/default.aspx?scid=KB;en-us;q252985

Tiki Wiki CMS Groupware <= 8.2 (snarf_ajax.php) Remote PHP Code Injection

-------------------------------------------------------------------------
Tiki Wiki CMS Groupware <= 8.2 (snarf_ajax.php) Remote PHP Code Injection
-------------------------------------------------------------------------

author...........: Egidio Romano aka EgiX
mail.............: n0b0d13s[at]gmail[dot]com
software link....: http://info.tiki.org/


[-] Vulnerability explanation:

Multiple vulnerabilities in SonicWall

--------------------------------------------------

Title:
======

SonicWall web admin interface mltiple code injection vulnerabilities


Date:
=====
2011-09-29

Dolphin <= 7.0.7 (member_menu_queries.php) Remote PHP Code Injection

--------------------------------------------------------------------
Dolphin <= 7.0.7 (member_menu_queries.php) Remote PHP Code Injection
--------------------------------------------------------------------

author...............: EgiX
mail.................: n0b0d13s[at]gmail[dot]com
software link........: http://www.boonex.com/dolphin
affected versions....: from 7.0.0 to 7.0.7
   

[PT-2011-02] PHP code Injection in Kayako Support Suite

-----------------------------------------------------------------
(PT-2011-02) Positive Technologies Security Advisory 
PHP code Injection in Kayako Support Suite
-----------------------------------------------------------------

---[ Vulnerable software ]

Kayako Support Suite 
Version: 3.70.02-stable and earlier


Yoono Firefox Extension - Privileged Code Injection

                  '=.|w|.='
                  _='`"``=.

        presents..

Yoono Firefox Extension Code Injection Vulnerability
Versions affected: < 6.1.1


+-----------+
|Description|

[SECURITY] [DSA 1802-1] New squirrelmail packages fix several vulnerabilities

    Cross site scripting was possible through a number of pages which
    allowed an attacker to steal sensitive session data.

CVE-2009-1579

    Code injection was possible when SquirrelMail was configured to
    use the map_yp_alias function to authenticate users. This is not
    the default.

CVE-2009-1580


Oracle Portal XSS fixed by CPU July 2008

Class: Input Validation Error
Risk: Low
Remote: Yes

Oracle has just released CPU July 2008 critical patch that fixes a flaw 
which allows code injection by malicious web users into the web pages 
viewed by other users.

The security issue was found on POPUP_NAME parameter OF 
PORTAL.WWPOB_HOME_PAGE web page of Oracle Portal.


Re: CVE-2009-1151: phpMyAdmin Remote Code Execution Proof of Concept

Poc for Static code injection vulnerability in setup.php in phpMyAdmin.
http://www.milw0rm.com/exploits/8921

Best Regards
-Rajesh Kumar



[BONSAI] SQL Injection in Achievo

manner [0].


4. *Vulnerability Description*

SQL injection is a code injection technique that exploits a security
vulnerability occurring in the database layer of an application. The
vulnerability is present when user input is either incorrectly filtered for
string literal escape characters embedded in SQL statements or user input
is not strongly typed and thereby unexpectedly executed.


[ MDVSA-2009:115 ] phpMyAdmin

 Multiple cross-site scripting (XSS) vulnerabilities in the export page
 (display_export.lib.php) in phpMyAdmin 2.11.x before 2.11.9.5 and 3.x
 before 3.1.3.1 allow remote attackers to inject arbitrary web script
 or HTML via the pma_db_filename_template cookie (CVE-2009-1150).
 
 Static code injection vulnerability in setup.php in phpMyAdmin 2.11.x
 before 2.11.9.5 and 3.x before 3.1.3.1 allows remote attackers to
 inject arbitrary PHP code into a configuration file via the save action
 (CVE-2009-1151).
 
 This update provides phpMyAdmin 2.11.9.5, which is not vulnerable to

ZDI-11-037: Symantec IM Manager Administrative Interface IMAdminSchedTask.asp Eval Code Injection Remote Code Execution Vulnerability

ZDI-11-037: Symantec IM Manager Administrative Interface IMAdminSchedTask.asp Eval Code Injection Remote Code Execution Vulnerability

http://www.zerodayinitiative.com/advisories/ZDI-11-037

January 31, 2011

-- CVE ID:
CVE-2010-3719

-- CVSS:

CanSecWest 2010 CALL FOR PAPERS (deadline Nov 30, conf. Mar22-26) and PacSec (Nov 4/5) Selections

Keynote Presentation November 4: Mitsugu Okatani, National Information Security Center / Ministry of Defense / Japan Air Self-Defense Force
Keynote Presentation November 5: Hideaki Kobayashi, Information Technology Promotion Agency
Virtualisation security and the Intel privilege model - Tavis Ormandy & Julien Tinnes, Google
Silicon Chips: No More Secrets - Karsten Nohl
Filter Resistant Code Injection on ARM - Yves Younan, University of Leuven
iPhone SMS Fuzzing and Exploitation - Charlie Miller, Independent Security Evaluators
The Microsoft View of the 2008 Threat Landscape - Tony Lee, Microsoft
Cloud Defense in the Post-BotWar Era - Ikuo Takahashi
The Android Security Story: Challenges and Solutions for Secure Open Systems - Rich Cannings & Alex Stamos, Google, iSec Partners
Stealthy Rootkit : How malware fools live memory forensics - Tsukasa Ooi, Livegrid

Re: Airkiosk/formlib application is XSS vuln

rely on cookies for session management.  The AirKiosk system does not
use cookies at all, and we discourage their use generally.

STATUS:

formlib.pl has been patched where applicable and possible code injection
is no longer possible.  



Raymond Pete

Advisory SE-2007-01: TikiWiki Remote PHP Code Evaluation Vulnerability

    * Map Server (like Google Maps)
    * Link Directory (like DMOZ)
    * Translation and i18n (like Babel Fish)"
    
   TikiWiki 1.9.8.1 fixes a broken white-list check (CVE-2007-5423) 
   that is supposed to protect against arbitrary PHP code injection
   in a call to create_function(). When we analysed the bugfix we
   discovered that while the reported bug in the white-list check 
   is now repaired, it is still possible to execute arbitrary PHP
   code by only using the strings allowed in the white-list.
   

Bitweaver <= 2.6 /boards/boards_rss.php / saveFeed() remote code execution exploit

    "by bitweaver" Version  powered +boards
    "You are running bitweaver in TEST mode"|"bitweaver * White Screen of Death"
     
    Versions tested: 2.6.0, 2.0.2
     
    Vulnerability type: folder creation, file creation, file overwrite, PHP code injection.
     
    Explaination:
    look at /boards/boards_rss.php, line 102:
    ...
    echo $rss->saveFeed( $rss_version_name, $cacheFile );

vBulletin 3.7.1 PL1 and lower, vBulletin 3.6.10 PL1: XSS in modcp index

admin/moderator is already logged in;
if the admin/moderator is not, they  will be required to log in.
However, if an admin
logs into the MCP, he is also logged into the ACP, allowing the same
exploit as last time
(remote PHP code injection via the hooks system).

If you Base64-encode your attack vector using
the data: URI scheme, the XSS survives the login request and activates after
the admin/moderator is logged in. A simple example of the above:


Month of PHP Security - Summary - 11st May - 21th

Articles
--------

MOPS Submission 07: Our Dynamic PHP – Obvious and not so obvious PHP
code injection and evaluation
http://php-security.org/2010/05/20/mops-submission-07-our-dynamic-php/

MOPS Submission 06: Variable Initialization in PHP
http://php-security.org/2010/05/17/mops-submission-06-variable-initialization-in-php/


[ MDVSA-2011:124 ] phpmyadmin

 vulnerability. (CVE-2011-2505).
 
 setup/lib/ConfigGenerator.class.php in phpMyAdmin 3.x before 3.3.10.2
 and 3.4.x before 3.4.3.1 does not properly restrict the presence of
 comment closing delimiters, which allows remote attackers to conduct
 static code injection attacks by leveraging the ability to modify
 the SESSION superglobal array (CVE-2011-2506).
 
 libraries/server_synchronize.lib.php in the Synchronize implementation
 in phpMyAdmin 3.x before 3.3.10.2 and 3.4.x before 3.4.3.1 does not
 properly quote regular expressions, which allows remote authenticated

[SECURITY] [DSA 2286-1] phpmyadmin security update

  Possible session manipulation in Swekey authentication.

CVE-2011-2506

  Possible code injection in setup script, in case session
  variables are compromised.

CVE-2011-2507

  Regular expression quoting issue in Synchronize code.

Next Page>>

Copyright © 1995-2012 LinuxRocket.net. All rights reserved.

Nearly all of LinuxRocket's features are free. Be kind and donate to the cause!