Packet Storm new exploits for November, 2006.
318c11bdc5554956d9625b8c0bc123e6b2evolution versions 1.8.2 through 1.9 beta suffer from a remote file inclusion flaw.
a34bc12a155987f8eb60e232bd38a0d0b2evolution versions 1.8.2 through 1.9 beta suffer from cross site scripting flaws.
3b10337a893bdc3fd9ad635d44ebc408Evince Document Viewer buffer overflow exploit that makes use of the same vulnerability that exists in gv.
0f13fb1eca55172dab4e76fc14fa42abA remotely exploitable stack overflow vulnerability has been found in ProFTPD server. The vulnerability allows a remote authenticated attacker to gain root privileges. Versions below 1.3.0a are affected. Exploit included.
b1752a0ea3478f34b3424fdb19d3671cA vulnerability has been identified in 3CTftpSvc TFTP Server, which could be exploited by attackers to execute arbitrary commands or cause a denial of service.
9f9bc09763e5252031a4ede19325b112Click Contact suffers from a SQL injection vulnerability.
eba02be83e4e59ef50f9120123d4a84bClick Blog suffers from a SQL injection vulnerability.
65aef323119951a37731a65e6646a086The Mambo jambook component suffers from a HTML injection vulnerability via the Entry field.
d1c34827d58039dab0fbc025ba86035bA vulnerability has been identified in TFTP server AT-TFTP server version 1.9, which could be exploited by remote or local attackers to execute arbitrary commands or cause a denial of service.
d0728414231a3bf51ea3f7c04c6fb760Wisi Portal suffers from SQL injection vulnerabilities in multiple asp files.
f1bd4768bdc3a66808ff9a83a6435c6eSiap CMS suffers from a SQL injection vulnerability in login.asp.
84c0a099548ada8c956abe2b863c0427PHP-Nuke Mermaid module version 1.2 remote file inclusion exploit that makes use of formdisp.php.
7bcc1b4093a59a3640bb2084e33eb419Cahier de texte version 2.0 remote SQL code execution exploit.
e632d2f7de9d0f95dd55072a3044e520WebHost Manager version 3.1.0 suffers from cross site scripting vulnerabilities.
f488dc8bb332a3106ca4c5cf918501c1CPanel 11 Beta suffers from cross site scripting vulnerabilities.
963ecc22aa00fef722d906bacf269b95MidiCart ASP Shopping Cart suffers from a SQL injection vulnerability.
ac643051042e61ead978d0bf2a68da0eASP ListPics version 5.0 suffers from a SQL injection vulnerability.
0c35e39fb8f64c8e12e708c839d35782iNews News Manager suffers from a cross site scripting vulnerability.
a90c459f169c149c4a68bc4eecd2bda9iDMS Pro Image Gallery suffers from SQL injection and cross site scripting vulnerabilities.
696ba01f32ecab6b4f9d2ce395db5bb4Ultimate Survey Pro suffers from SQL injection vulnerabilities.
8775ab751e0b1e3224d1647227f2518d[N]eo [S]ecurity [T]eam [NST] - Advisory 30 - 2006-11-24: PHP-Nuke versions 7.9 and below suffer from a SQL injection vulnerability in the sid variable of the news module.
24a019bab3794e026aa656d258745069Active PHP Bookmarks version 1.1.02 suffers from a remote file inclusion flaw in apb.php.
eb87b9d0d671d5af9f66d0a45bb6be78Woltlab Burning Board Lite version 1.0.2 Zend_Hash_Del_Key_Or_Index / blind SQL injection exploit.
51876241b351f7781a3c0d53a94cc130mmgallery suffers from a cross site scripting flaw.
7cad755b7c618f7b93abf004c4666a2b