Packet Storm new exploits for September, 2006.
0206dc67a401156ae56b31893ce3eef2the 0004_init_urls.php file included with syntaxCMS allows for remote file inclusion.
e29cc1ffa0374856a15cfe5995b33cc2GW Script 250 versions 2.1.4 and prior suffer from a remote file inclusion vulnerability if register_globals = on.
580310b39fecb2b4ca21d7059334193cphpstak suffers from a remote file inclusion vulnerability.
5afc5509c94a68ced344cc314e6b2af3Kietu suffers from a local file inclusion vulnerability.
edf2819882a8558a90631ffde20280c8ZoomStats suffers from a remote file inclusion vulnerability.
1f5e1660ad95e12efacee2ca91ab18d2WebNews suffers from a remote file inclusion vulnerability.
f0807be021c2cd9280205d1bb27156dbFlushCMS suffers from a remote file inclusion vulnerability.
998963100faf07513287a3079667af0aPie Cart Pro suffers from a remote file inclusion vulnerability in the Home_Path variable.
9e3051fd771e0ef43afbd9c71bb5a18fMambo's script mambo_hotornot versions 1.2.2 and below allow malicious users to upload and execute arbitrary php files.
e58899358879bd5e30609fa855298512PhotoPost PHP 4.6 - 4.5 remote file inclusion vulnerability.
e1a0b50a98aeee603539a512201627cbPNphpBB suffers from a remote file inclusion flaw in functions_admin.php.
fe0a2af56b9045af3c80b5dfc22e6789Techno Dreams Articles and Papers Package versions 2.0 and prior suffer from a SQL injection vulnerability.
af37e6eb060152a803a638e90321f1eaECardPro v2.0 suffers from a SQL injection vulnerability
11635ca295e6dfcabfd6ec83cb92042fPHPQuiz versions less than or equal 1.2 remote SQL injection exploit.
fccfbd2b1d73ee814d44a73cfe00647aPlume CMS 1.1.10 suffers from a remote file inclusion vulnerability.
0b539703dc19e237897be5f017bcd4c1HitWeb v3.0 suffers from several remote file inclusion vulnerabilities.
068202c7c241c8e7e08c9e4b9f6b2508Site@School 2.4.02 and below suffers from multiple remote command execution vulnerabilities.
cc6518c3af1fef29c314e1a959ac5591xweblog versions 2.1 and below suffer from a remote SQL injection vulnerability in kategori.asp.
662ac1b37e68d8718feb2bc82c720ad3Charon Cart v3 suffers from a SQL injection vulnerability in Review.asp.
4ac05cfc744d1e027e1ed13515201d2bQ-Shop v3.5 suffers from a SQL injection flaw in browse.asp. POC included.
ab508b27614c6f2eb72ec9974001259cEShoppingPro v1.0 is vulnerable to SQL injection in search_run.asp. POC provided.
c85d1d1628e2d0d8c68fdf191406a143Haberx version 1.1 suffers from a SQL injection vulnerability.
d6afdf9cac86b039f35195ac45dd5977PHP DocWriter versions 0.3 and below remote file inclusion exploit.
f9a6067d722c86d78f625ff8df6518b2ReviewPost version 2.5 suffers from a remote file inclusion flaw in RP_PATH.
fb26c73da5da6a3ccdbd7330298d8331