Ravens PHP Scripts: Security



Search on This Topic:   
[ Go to Home | Select a New Topic ]
 

 

More Nuke Security Advisories More about

Posted on Tuesday, June 15, 2004 @ 07:28:12 CDT in Security
by Raven

Janek Vind (waraxe) has found more security issues in phpnuke. We are reviewing his findings now and will report back soon. See this link for the gory details.
 

 

Oracle SQL Injections - Puts Things In Perspective More about Read More...

Posted on Monday, June 14, 2004 @ 09:32:15 CDT in Security
by Raven

All Oracle Corp. Applications and most E-Business Suite customers are at high risk from multiple, critical SQL injection vulnerabilities. The vulnerabilities were uncovered by Stephen Kost from the security firm Integrigy Corp. Read Article  Read More...
 

 

New Nuke Security Advisories More about

Posted on Tuesday, June 08, 2004 @ 07:49:20 CDT in Security
by Raven

We are aware that some new exploits/advisories have been issued concerning phpnuke and we are looking into those reports right now. If we find that they are legitimate, we will determine a solution and will make it/them available ASAP.
 

 

Sec-Fix Patch 7.3 More about

Posted on Tuesday, June 08, 2004 @ 00:20:23 CDT in Security
by chatserv


Note: 
Update: Forum files removed from patch and security fix applied to the Reviews module.
 

 

Your Account module security holes More about

Posted on Thursday, May 27, 2004 @ 15:22:26 CDT in Security
by Raven

BobMarion writes:  
This was uncovered by NSN Sentinelâ„¢ when applied to the test sites.

In Your Account's index.php file you will find 4 placements of:
getusrinfo($user);
if (($userinfo[username] != $cookie[1]) AND ($userinfo[user_password] != $cookie[2])) {

These should be:
cookiedecode($user);
getusrinfo($user);
if ((is_user($user)) AND ($userinfo['username'] == $cookie[1]) AND ($userinfo['user_password'] == $cookie[2])) {


Note: 
Admin note: Code updated 5/28/04, our thanks to Dogman.
 

 

Unsolicited Security Advisories More about

Posted on Monday, May 24, 2004 @ 22:08:37 CDT in Security
by sixonetonoffun

I've started a topic in the Security Forum regarding reports of Unsolicited Security Advisories. Please read this as an actual advisory and feel free to contribute to the discussion.

sixonetonoffun
 



Page 97 of 102 (608 total stories) [ << | < | 92 | 93 | 94 | 95 | 96 | 97 | 98 | 99 | 100 | 101 | 102 | > | >> ]  

News ©

Site Info

Last SeenLast Seen
  • vashd1
  • neralex
Server TrafficServer Traffic
  • Total: 519,454,346
  • Today: 50,947
Server InfoServer Info
  • May 25, 2025
  • 08:32 am CDT