Packet Storm new exploits for October, 2006.
65c5b9a87c44a999d9f30e03ff73357e[ECHO_ADV_53$2006] QnECMS 2.5.6 and prior suffers from a remote file inclusion vulnerability. POC included.
7bb824ac64c3f8a19a5cd7d2f77128ddPHPEasyData Pro 2.2.1 suffers from a SQL injection vulnerability in index.php.
86a25a3b5aefd59ee9a0b8bc83a2ae72PHPEasyData Pro 1.4.1 suffers from a SQL injection vulnerability in index.php.
e13278379bc514af54a379123d0d3e56Simple Website Software v0.99 suffers from a remote file inclusion vulnerability in common.php.
b83c9ea6e8ce9db3d5dd4c2c14d91fa3easy notes manager (eNM) version 0.0.1 is affected by multiple SQL injection issues. POC included that demonstrates how to bypass authentication.
4c602907941ded3261092a9e6f0dea6afreenews suffers from a remote file inclusion vulnerability in aff_news.php.
d8dc0e07497d88c4592cffbfea769e4dRemote exploit for Exporia versions 0.3.0 and prior remote file inclusion vulnerability.
246973950a592676923fc4a992fa0c0cCentiPaid 1.4.3 suffers from a remote file inclusion vulnerability in centipaid_class.php.
5b84c392a064a6af9aad58133dac5b03Ban v0.1 suffers from a remote file inclusion vulnerability in bannieres.php.
b275e2597c9c598264d817f53415c3f7Thepeak File Upload v1.3 suffers from a vulnerability that allows anyone to download arbitrary files.
2b37dfff1ae29534e19e368cd6903f36Hosting Controller 6.1 Hotfix less than or equal to 3.2 suffers from multiple vulnerabilities which can allow an unauthenticated user to delete sites and perform SQL injection attacks.
550389fe90820188ecc8262a1b61c698phpAdsNew 2.0.8 suffers from a file inclusion vulnerability in adlayer.php.
f281c4a164e02d3f643549e2366b440aNucleus Core v3.23 suffers from a remote file inclusion vulnerability in media.php.
52047ce9f27cd35356fb629852777187PunBB 1.2.13 suffers from multiple vulnerabilities including SQL injection and local file inclusion.
cbf2c36a8a9b138e100f8910791ca4b8GestArt vbeta 1 and prior suffer from a remote file inclusion vulnerability in /gestArt/aide.php.
88df7d9896ceb21d0abf1b424291c221The Joomla extended_registration mod suffers from a remote file inclusion vulnerability.
7d7731045cf55284af46a7f7cc323c12TorrentFlux 2.1 doesn't properly sanitize user input passed via the "dir" GET variable thus allowing anyone to get a list of files anywhere on the system.
d69dbdf46cda5007d346cbdb94b1e73dUNISOR CMS suffers from a SQL injection vulnerability that can be used to gain administrative privileges.
aaf61e087988f7fb207d71a9dfcf2bffIf magic_quotes_gpc is off opendocman 1.2rc3 suffers from an authentication bypass vulnerability.
ad7914cf51bff4deabe41709de9e163fAmember suffers from a remote file inclusion vulnerability in /admin/setup.php.
c0a93dcc4809ea7efa19c971fd4976f4Coppermine 1.4.9 suffers from a SQL injection vulnerability. POC included that grabs the admin hash.
0576b80395ec0c30ff6eec9d1933f3d8phpLedAds 2.0 suffers from multiple remote file inclusion vulnerabilities.
926df7aa321ce03c90fa6afb4ee426c3PLS-Bannieres 1.21 suffers from a remote file inclusion vulnerability in bannieres.php.
50cefaeeae022fd7ac82aa6a5d15c2daMiniBILL v2006-10-10 suffers from a remote file inclusion vulnerability in config[page_dir].
f75082953dd72f4ec9b0f82e8ceb78d5