New User, Welcome!     Login

Next Page >>

injections

Cisco Security Advisory: Multiple Vulnerabilities in Cisco TelePresence Endpoint Devices

each component of the solution is addressed independently in its own
advisory. This advisory addresses Cisco TelePresence endpoint devices
and details the following vulnerabilities:

  * Unauthenticated Common Gateway Interface (CGI) Access
  * CGI Command Injection
  * TFTP Information Disclosure
  * Malicious IP Address Injection
  * XML-Remote Procedure Call (RPC) Command Injection
  * Cisco Discovery Protocol Remote Code Execution


Nginx, Varnish, Cherokee, thttpd, mini-httpd, WEBrick, Orion, AOLserver, Yaws and Boa log escape sequence injection

Nginx, Varnish, Cherokee, thttpd, mini-httpd, WEBrick, Orion, AOLserver,
Yaws and Boa log escape sequence injection

 Name              Nginx, Varnish, Cherokee, thttpd, mini-httpd,
                   WEBrick, Orion, AOLserver, Yaws and Boa log escape
                   sequence injection
 Systems Affected  nginx 0.7.64
                   Varnish 2.0.6
                   Cherokee 0.99.30
                   mini_httpd 1.19

[waraxe-2009-SA#074] - Multiple Vulnerabilities in TorrentTrader Classic 1.09

List of found vulnerabilities
===============================================================================

1. Sql Injection vulnerability in "account-inbox.php"
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Reasons:
  1. unsanitized user submitted parameter "origmsg" is used in sql query
Preconditions:

Aspect9: Internet Explorer 8.0 Beta 2 Anti-XSS Filter Vulnerabilities

The Anti-XSS filter has been found to have some security holes in the
current implementation. Microsoft decided to filter "Type 1 XSS" which is
free  text send to the server being reflected to the user and therefore
injecting HTML code into the website's page. They chose not to handle
certain situations such as injection into a JavaScript tag space, which
would be extremely difficult to filter. The software giant also chose not
to filter injection into HTTP headers, which will drive hackers to focus on
discovering CRLF vulnerabilities.

A quote of Microsoft's Anti-XSS filter design philosophy:

Pligg <= 9.9.0 Multiple Vulnerabilities

Description:
Pligg is a popular open source, full featured, content management
system written in php. There are a number of vulnerabilities
within Pligg that allow for remote file enumeration, file inclusion,
cross site scripting, and sql injection. When combined these issues
allow for remote code execution on the affected installation
via arbitrary php code placed within template files once admin
credentials are gained via SQL Injection.



Multiple Adobe Products - XML External Entity And XML Injection Vulnerabilities

                  _='`"``=.

                presents..

Multiple Adobe Products
XML External Entity And XML Injection Vulnerabilities

CVE: CVE-2009-3960
Adobe PSIRT: APSB10-05 - http://www.adobe.com/support/security/bulletins/apsb10-05.html
Link: http://www.security-assessment.com/files/advisories/2010-02-22_Multiple_Adobe_Products-XML_External_Entity_and_XML_Injection.pdf


Pandora FMS Authentication Bypass and Multiple Input Validation Vulnerabilities

Vulnerabilities

CVE IDs in this security advisory:

1) Authentication bypass - CVE-2010-4279
2) OS Command Injection - CVE-2010-4278
3) SQL Injection - CVE-2010-4280
4) Blind SQL Injection - CVE-2010-4280
5) Path Traversal - CVE-2010-4281 - CVE-2010-4282 - CVE-2010-4283



[waraxe-2008-SA#062] - Multiple Sql Injections in MyBB 1.2.10

[waraxe-2008-SA#062] - Multiple Sql Injections in MyBB 1.2.10
===============================================================================

Author: Janek Vind "waraxe"
Date: 16. January 2008
Location: Estonia, Tartu
Web: http://www.waraxe.us/advisory-62.html



Xigla Multiple Products - Multiple Vulnerabilities

####################
2. Vulnerabilities:
####################
    2.1. Absolute Live Support XE (ASP version 5.1) (admin)
                2.1.1. SQL Injection in "search.asp" by "orderby" parameter.
                        POC: 
                                http://[URL]/xlaabsolutels/search.asp?orderby=[SQL INJECTION]
                        
                2.1.2. XSS in "search.asp" (all fields are vulnerable).
                        POC:

Cacti 0.8.7a Multiple Vulnerabilities

multiple data acquisition methods, and user management features out of
the box".
 
II. DESCRIPTION
 
Multiple vulnerabilities exist in Cacti software (XSS, SQL Injection,
Path Disclosure, HTTP Response Splitting).
 
III. ANALYSIS
 
Summary:

[InterN0T] AdPeeps 8.5d1 - XSS and HTML Injection Vulnerabilities

AdPeeps Ad Rotator - XSS and HTML Injection Vulnerabilities

Version Affected: 8.5d1 (3-18-09) (newest)

Info: Ad Peeps is a banner rotator and text ad rotator - all in one that allows you to track, sell and manage   banner ads, rich-media/flash ads  and  text ads on your website. Built using PHP/MYSQL, Ad Peeps provides you and your advertisers with highly detailed real-time statistics and is capable of delivering millions of impressions per day on a typical shared web server. -  Plus, you can try it right now on your website with our 7 day trial.

Ad Peeps is so versatile that it can even show your text ads Yahoo! Style or Google AdWords Style. Unlike many other banner ad rotator programs, Ad Peeps was skillfully designed to use minimal server resources while maintaining speed and unparalleled performance. Built on a highly scalable and versatile database architecture, Ad Peeps works without fuss even on high traffic web sites and won't crash your high powered website..

Opinion: AdPeeps, along with many others should really hire people to audit their code.


PHP Security Framework: Vuln and Security Bypass

 Released on:   2007/12/16
   Changelog:   2007/12/16

     Summary:   [HT] Remote File Inclusion
                [MT] SQL Injection
                [MT] SQL Injection Protection Bypass
                [__] Conclusion

      Legend:   L - Low risk         M - Medium risk
                H - High risk        T - Tested

Pooya Site Builder (PSB) SQL Injection Vulnerabilities

########################## www.BugReport.ir #######################################
#
#               AmnPardaz Security Research Team
#
# Title: Pooya Site Builder (PSB) SQL Injection Vulnerabilities
# Vendor: www.paridel.com
# Vulnerable Version: 6.0 (Assembly Version)
# Exploit: Available
# Impact: High
# Fix: N/A

Cisco Security Advisory: Multiple Vulnerabilities in Cisco Security Agent

Summary
=======

The Management Center for Cisco Security Agents is affected by a
directory traversal vulnerability and a SQL injection vulnerability.
Successful exploitation of the directory traversal vulnerability may
allow an authenticated attacker to view and download arbitrary files
from the server hosting the Management Center. Successful
exploitation of the SQL injection vulnerability may allow an
authenticated attacker to execute SQL statements that can cause

[RT-SA-2009-003] IceWarp WebMail Server: SQL Injection in Groupware Component

Advisory: IceWarp WebMail Server: SQL Injection in Groupware Component

During a penetration test RedTeam Pentesting discovered multiple
SQL-Injections in the IceWarp WebMail Server. Attackers that are in
control of a user account for the web-based email and groupware
components are able to execute arbitrary SQL SELECT statements and
therefore read any data from the DBMS that are accessible by the Icewarp
eMail Server.



Invision Power Board <= 3.0.4 Local PHP File Inclusion and SQL Injection

- Severity: Moderately High
=============================================

I. VULNERABILITY
-------------------------
Invision Power Board <= 3.0.4 Local PHP File Inclusion and SQL Injection
Invision Power Board <= 2.3.6 SQL Injection

II. BACKGROUND
-------------------------
Invision Power Board (IPB) is a professional forum system that has  

Multiple Vulnerabilities in OpenClassifieds 1.7.0.3

 good example of this.   Its impossible to account for all the ways a variable can be mangled once it
 enters a program and if you Sanitize input when it first enters the program there will be cases where it
 will become dangerous again.   This isn't only a problem for SQLi,  its also a problem for XSS.  I am
 inserting JS into the database, which isn't a vulnerablity,  but printing it, is persistant XSS. 

 The blind sql injection is a bit strange.  I can't use white space or commas,  which is a pain.  I had to
 rewrite my general purpose Blind SQLi Class to accommodate.   A binary search is used to greatly
 speed up the blind sqli attack.   
 (which I also used in my php-nuke exploit: http://www.exploit-db.com/exploits/12510/)

 Special thanks to Reiners for this sqli filter evasion cheat sheet: 

Plaintext injection in STARTTLS (multiple implementations)

SASL (Simple Authentication and Security Layer) username and password.

This is not as big a problem as it may appear to be.  The reason
is that many SMTP client applications don't verify server TLS
certificates.  These SMTP clients are always vulnerable to command
injection and other attacks. Their TLS sessions are only encrypted
but not protected.

A similar plaintext injection flaw may exist in the way SMTP clients
handle SMTP-over-TLS server responses, but its impact is less
interesting than the server-side flaw.

[OPENX-SA-2009-002] OpenX 2.4.11, 2.6.5, 2.8.0 fix multiple vulnerabilities

Description
-----------
A security review was recently being conducted on Openx 2.6.4 by Sandro
Gauci. As part of the review he reported the following vulnerabilities:

  - SQL injection in adview.php and other delivery scripts because of
   missing or improper validation of the "OAID" cookie;
  - SQL injection in tjs.php because of missing or improper validation
   of the "referer" GET parameter;
  - XSS vulnerability in sso-accounts.php because of missing or improper
   validation of the "email" GET parameter (2.4.x not affected)

Opera Stored Cross Site Scripting Vulnerability

Opera browser is vulnerable to stored Cross Site
Scripting.  A malicious attacker is able to inject
arbitrary browser content through the
websites visited with the Opera browser. The code
injection is rendered into the Opera History Search
page which displays URL and a short
description of the visited pages.

== Bug Analysis ==


Theeta CMS (Cross Site Scripting,SQL Injection) Multiple Vulnerabilities

#                                             +-+-+-+-+          #
#                                             |C|r|e|w|          #
#                                             +-+-+-+-+          #
##################################################################
##################################################################
# [#] Theeta CMS (Cross Site Scripting,SQL Injection) Multiple Vulnerabilities  #
# [#] Discovered By c0dy                                         #
# [#] http://r00tDefaced.net                                     #
# [#] Greetz: sHoKeD-bYte, syst0x1c & r00tDefaced Members        #
##################################################################
#

Eshopbuilde CMS SQL Injection Vulnerability

================= IUT-CERT =================

Title: Eshopbuilde CMS SQL Injection Vulnerability

Vendor: www.eshopbuilder.ir

Dork: Design by Satcom Co
Type: Input.Validation.Vulnerability (SQL Injection)

Fix: N/A

BLIND SQL INJECTION exploit (GET var 'AlbumID')--RTWebalbum 1.0.462-->

#!/usr/bin/perl
#-----------------------------------------------------------------
#BLIND SQL INJECTION (GET var 'AlbumID')--RTWebalbum 1.0.462-->
#-----------------------------------------------------------------
#
#CMS INFORMATION:
#
#-->WEB: http://rtwebalbum.x12.pl/
#-->DOWNLOAD: http://sourceforge.net/projects/rtwebalbum/
#-->DEMO: http://rtwebalbum.x12.pl/

CLAN TIGER CMS--(module custompage.php) BLIND SQL INJECTION-->

#!/usr/bin/perl
#
#-------------------------------------------------
# (module custompage.php) BLIND SQL INJECTION                        
#-------------------------------------------------
#
# CMS INFORMATION:                              
#
#-->WEB: http://www.clantiger.com
#-->DOWNLOAD: http://www.clantiger.com/download-clan-cms

iScripts SocialWare 2.2.x Multiple Remote Vulnerability

II. DESCRIPTION

This  CMS  is  affected by multiple remote security flaws,
such as SQL Injection, Arbitrary File upload, etc.
These security flaws DO NOT require authentication. Other
files may be vulnerable.


III. ANALYSIS

Month of PHP Security - Summary - 1st May - 10th May

PHP Security on Twitter, too. Just follow @mops_2010

Vulnerabilities in PHP Applications
-----------------------------------

MOPS-2010-020: Xinha WYSIWYG Plugin Configuration Injection
Vulnerability - http://bit.ly/bLHmuS
MOPS-2010-019: Serendipity WYSIWYG Editor Plugin Configuration Injection
Vulnerability - http://bit.ly/cdxZHX
MOPS-2010-018: EFront ask_chat chatrooms_ID SQL Injection Vulnerability
- http://bit.ly/crEATq

[waraxe-2010-SA#078] - Multiple Vulnerabilities in CruxCMS 3.0.0

Php script "manager/passwordreset.php" is directly accessible via web
without any authorization. Source code snippet:

-----------------[ source code start ]---------------------------------
include ("../includes/injectionprevention.php");

$ID = numericquery($_POST["ID"]) ;

if (isset($ID)) {


SQL-Ledger =?utf-8?Q?=E2=80=93_severa?= =?utf-8?Q?l?= vulnerabilities

Product: SQL-Ledger – an open source double entry accounting/ERP system
Website: http://www.sql-ledger.org
Vulnerabilities:
  - no Cross-Site-Request-Forgery (XSRF) protection
  - persistent cross site scripting
  - SQL injections
  - local file include
  - secure cookie flag not set
Class: remote
Status: unpatched
Severity: moderate

SunShop <= 4.1.4 SQL Injection

# GulfTech Security Research              August 18, 2008
##########################################################
# Vendor : Turnkey Web Tools, Inc
# URL : http://www.turnkeywebtools.com
# Version : SunShop <= 4.1.4
# Risk : SQL Injection
##########################################################


Description:
SunShop shopping cart is a full featured ecommerce solution written

Update+Errata: Re: A paper by Amit Klein (Trusteer): "OpenBSD DNS Cache Poisoning and Multiple O/S Predictable IP ID Vulnerability"

> another field, this time the IP fragmentation ID, part of the
> OpenBSD kernel network stack. The analysis carries out quite
> similarly to show that OpenBSD's IP ID is predictable as well,
> which gives way to O/S fingerprinting, idle-scanning, host alias
> detection, traffic analysis, and in some cases, even to TCP blind
> data injection.
>
> But it gets more interesting. Several other BSD operating systems
> copied the OpenBSD code for their own IP ID PRNG, so they're
> vulnerable too. This is particularly so with Apple's Mac OS X,
> Mac OS X Server and Darwin, but also with NetBSD, FreeBSD and

Next Page>>

Copyright © 1995-2012 LinuxRocket.net. All rights reserved.

Nearly all of LinuxRocket's features are free. Be kind and donate to the cause!