Packet Storm new exploits for February, 2007.
4293d73fbe0d189cd0fbb512857db6c8Netragard, L.L.C Advisory - McAfee Virex contains an exploitable feature that enables users to define what files should be excluded for scanning. This feature relies on a configuration file with insecure privileges and is located in /Library/Application Support. Any user on the system can modify or delete the configuration file thus affecting what Virex will scan. Versions 7.7 and below are affected.
7a113c2b8adb0d5f52d1d955c4363497Kiwi CatTools TFTP versions up to 3.2.8 suffer from information disclosure and remote code execution flaws.
fe9946d867abc56849eec4c61a5de1c2Nullsoft ShoutcastServer version 1.9.7/Win32 suffers from a cross site scripting flaw.
5b123c23812dd6500955a30ff0287cb1Wordpress version 2.1.1 suffers from multiple script injection vulnerabilities.
d1d3b2ca1222938073e4984f72460183SEC Consult Security Advisory 20070226-0 - The 3rd party module Pagesetter for PostNuke is susceptible to a local file inclusion vulnerability. Versions 6.2.0 and 6.3.0 beta 5 are affected.
80f3f17ffa2c97e576a6821c1866f9a8It appears that the un.org web site suffers from SQL injection vulnerabilities.
d60cbb057b860d20afc9500b8465f689SQLiteManager version 1.2.0 suffers from local file inclusion and multiple cross site scripting vulnerabilities.
f9ec290e820ad8915d572d66d43821bcCoppermine Photo Gallery version 1.3.x blind SQL injection exploit.
a455d05a88b89a11ba6a2296c29cffb3Photostand version 1.2.0 suffers from multiple cross site scripting vulnerabilities.
1df5510dadc3259613ea6b3ecc866c89ActiveCalendar version 1.2.0 suffers from cross site scripting and local file inclusion vulnerabilities.
f8122376858f457b150dbad19ec59183Pickle suffers from a local file download vulnerability.
823adf2f666230ceadf399608d885dd3Simple One-File Gallery suffers from local file inclusion and cross site scripting vulnerabilities.
3822c65a6a3ada8839f41826ed25912fsitex suffers from upload and cross site scripting vulnerabilities.
9706228a123398dec332f03115bb2779xtcommerce suffers from a local file inclusion vulnerability.
54491a12c6ec084136ae5078654e94f0shopkitplus suffers from a local file inclusion vulnerability.
cf64e7219e80bfb09d781f7e051bb96aZPanel suffers from a remote file inclusion vulnerability.
b3a614a627f1cc00641e4edfc20ae2efExploit that demonstrates the vulnerability in ReadDirectoryChangesW() for Microsoft Windows 2000/XP/2003/Vista.
f7f6bf6fe0ea633cd5976b0a644ad70cWebSpell versions greater than 4.0 suffer from authentication bypass and arbitrary code execution flaws.
a6d5965c0980c6edd14deac5f17706f0SaphpLesson version 3.0 suffers from a remote SQL injection vulnerability.
1d4c7171f12dd2a696976c27a73fdec1Pheap CMS suffers from a local file inclusion vulnerability that allows for the editing of the file.
723592a21d57dd6e7ba731cd3e1611bdLoveCMS version 1.4 suffers from remote file inclusion, local file inclusion, upload, and cross site scripting vulnerabilities.
794c87a701ed83cbf848253d244509b3Plantilla PHP suffers from local file inclusion and arbitrary file upload vulnerabilities.
73f4ea1c9dc8e4b78621b2278d20ac45It appears that JBrowser may allow arbitrary access to admin/config files.
76269815469d0ef8356da349250ddaceOracle 10g KUPW$WORKER.MAIN Grant/Revoke dba permission exploit.
1a6267279e19948c6072527708174f73