phpMyAdmin Unspecified UTF-7 Cross-Site Scripting Vulnerability More about

Posted on Wednesday, November 01, 2006 @ 11:31:26 CST in Security
by Raven

SECUNIA ADVISORY ID: SA22599

VERIFY ADVISORY: http://secunia.com/advisories/22599/

CRITICAL: Less critical

IMPACT: Cross Site Scripting

WHERE: >From remote

SOFTWARE: phpMyAdmin 2.x - http://secunia.com/product/1720/

DESCRIPTION: A vulnerability has been reported in phpMyAdmin, which can be exploited by malicious people to conduct cross-site scripting attacks. Input containing UTF-7 encoded characters passed to unspecified parameters is not properly sanitised before being returned to the user. This can be exploited to execute arbitrary HTML and script code in a user's browser session in context of an affected site. The vulnerability is reported in versions 2.6.4 through 2.9.0.2.

SOLUTION: Update to version 2.9.0.3.

PROVIDED AND/OR DISCOVERED BY: The vendor credits Stefan Esser.

ORIGINAL ADVISORY: http://www.phpmyadmin.net/home_page/security.php?issue=PMASA-2006-6
 

 

PHP-Nuke *forwhat* SQL Injection Vulnerability More about

Posted on Wednesday, November 01, 2006 @ 09:01:40 CST in Security
by Raven

SECUNIA ADVISORY ID: SA22617

VERIFY ADVISORY: http://secunia.com/advisories/22617/

CRITICAL: Moderately critical

IMPACT: Manipulation of data

WHERE: >From remote

SOFTWARE: PHP-Nuke 7.x - http://secunia.com/product/2385/

DESCRIPTION: Paisterist has discovered a vulnerability in PHP-Nuke, which can be exploited by malicious people to conduct SQL injection attacks. Input passed to the "forwhat" parameter in modules/journal/search.php is not properly sanitised, before being used in a SQL query. This can be exploited to manipulate SQL queries by injecting arbitrary SQL code. The vulnerability is confirmed in version 7.9. Other versions may also be affected.

SOLUTION: Edit the source code to ensure that input is properly verified.

PROVIDED AND/OR DISCOVERED BY: Paisterist

ORIGINAL ADVISORY: http://www.neosecurityteam.net/index.php?action=advisories&id=29
 

 

PHPEasyData Pro *cat* SQL Injection Vulnerability More about

Posted on Wednesday, November 01, 2006 @ 01:10:28 CST in Security
by Raven

SECUNIA ADVISORY ID: SA22616

VERIFY ADVISORY: http://secunia.com/advisories/22616/

CRITICAL: Moderately critical

IMPACT: Manipulation of data

WHERE: >From remote

SOFTWARE: PHPEasyData Pro 2.x - http://secunia.com/product/12454/

DESCRIPTION: ajann has reported a vulnerability in PHPEasyData Pro, which can be exploited by malicious people to conduct SQL injection attacks. Input passed to the "cat" parameter in index.php is not properly sanitised before being used in SQL queries. This can be exploited to manipulate SQL queries by injecting arbitrary SQL code. The vulnerability is reported in version 2.2.2. Other versions may also be affected.

SOLUTION: Edit the source code to ensure that input is properly sanitised.

PROVIDED AND/OR DISCOVERED BY: ajann

ORIGINAL ADVISORY: http://milw0rm.com/exploits/2675
 

 

Internet Explorer 7 Window Injection Vulnerability More about

Posted on Wednesday, November 01, 2006 @ 01:08:25 CST in Security
by Raven

SECUNIA ADVISORY ID: SA22628

VERIFY ADVISORY: http://secunia.com/advisories/22628/

CRITICAL: Moderately critical

IMPACT: Spoofing

WHERE: >From remote

SOFTWARE: Microsoft Internet Explorer 7.x - http://secunia.com/product/12366/

DESCRIPTION: A vulnerability has been discovered in Internet Explorer 7, which can be exploited by malicious people to spoof the content of websites. The problem is that a website can inject content into another site's window if the target name of the window is known. This can e.g. be exploited by a malicious website to spoof the content of a pop-up window opened on a trusted website.

This is related to: SA13251. Secunia has constructed a test, which can be used to check if your browser is affected by this issue: http://secunia.com/multiple_browsers_window_injection_vulnerability_test/ . The vulnerability has been confirmed on a fully patched system with Internet Explorer 7.0 and Microsoft Windows XP SP2.

SOLUTION: Do not browse untrusted sites while browsing trusted sites.

PROVIDED AND/OR DISCOVERED BY: Originally discovered by: Secunia Research

Reported in Internet Explorer 7 by: Per Gravgaard

OTHER REFERENCES: SA13251: http://secunia.com/advisories/13251/
 

 

Microsoft Windows Internet Connection Sharing Denial of Service More about

Posted on Wednesday, November 01, 2006 @ 01:05:21 CST in Security
by Raven

SECUNIA ADVISORY ID: SA22592

VERIFY ADVISORY: http://secunia.com/advisories/22592/

CRITICAL: Less critical

IMPACT: DoS

WHERE: >From local network

OPERATING SYSTEM:
Microsoft Windows XP Home Edition - http://secunia.com/product/16/
Microsoft Windows XP Professional - http://secunia.com/product/22/

DESCRIPTION: h07 has discovered a vulnerability in Microsoft Windows, which can be exploited by malicious people to cause a DoS (Denial of Service). The vulnerability is caused due to a NULL pointer dereference error in Windows NAT Helper Components (ipnathlp.dll). This can be exploited to crash the service via a specially crafted DNS query. Successful exploitation requires that Internet Connection Sharing is enabled and the query is received from a client on the shared network interface. The vulnerability is confirmed in a fully patched Windows XP SP2 system. Other versions may also be affected.

SOLUTION: Use another way of sharing the Internet connection.

PROVIDED AND/OR DISCOVERED BY: h07

ORIGINAL ADVISORY: http://milw0rm.com/exploits/2672
 

 

Coppermine Photo Gallery *aid* SQL Injection Vulnerability More about

Posted on Wednesday, November 01, 2006 @ 01:03:08 CST in Security
by Raven

Coppermine Photo Gallery *aid* SQL Injection Vulnerability SECUNIA ADVISORY ID: SA22625

VERIFY ADVISORY: http://secunia.com/advisories/22625/

CRITICAL: Less critical

IMPACT: Manipulation of data

WHERE: >From remote

SOFTWARE: Coppermine Photo Gallery 1.x - http://secunia.com/product/1427/

DESCRIPTION: w4ck1ng has reported a vulnerability in Coppermine Photo Gallery, which can be exploited by malicious users to conduct SQL injection attacks. Input passed to the "aid" parameter in picmgr.php is not properly sanitised before being used in a SQL query. This can be exploited to manipulate SQL queries by injecting arbitrary SQL code. The vulnerability is reported in version 1.4.9. Other versions may also be affected.

SOLUTION: Update to version 1.4.10.

PROVIDED AND/OR DISCOVERED BY: w4ck1ng

ORIGINAL ADVISORY: http://coppermine-gallery.net/forum/index.php?topic=37895.0
 



Page 264 of 659 (3950 total stories) [ << | < | 259 | 260 | 261 | 262 | 263 | 264 | 265 | 266 | 267 | 268 | 269 | > | >> ]  

News ©

Site Info

Last SeenLast Seen
  • Raven
  • rhineus
Server TrafficServer Traffic
  • Total: 567,822,251
  • Today: 46,737
Server InfoServer Info
  • Jun 26, 2026
  • 11:38 am CDT