Packet Storm new exploits for November, 2007.
74817b159ff17cf5f7c20384ecdd2dcfbcoos versions 1.0.10 and below suffer from a SQL injection vulnerability in ratefile.php.
d53d7c40431175ff10d61e6db7e21b51A cross site scripting vulnerability has been discovered in Apache versions 2.2.x and 2.0.x using a malformed HTTP request with 413 error pages.
b092742d65bdd0de195982310809ac70The F5 FirePass 4100 SSL VPN is susceptible to cross site scripting vulnerabilities in my.logon.php3.
d2712a2796254f18fd7453d88ff3e8baThe F5 FirePass 4100 SSL VPN is susceptible to cross site scripting vulnerabilities in my.activation.php3.
a5c5e3277bf1f9ac5dd422520c6fb014Ossigeno Suite CMS versions 2.2 and below suffer from remote file inclusion vulnerabilities.
051f6e3d7c633886ea156c35f2856754APC PDU products appear to be susceptible to a login bypass vulnerability.
4bc09aa79a448444bcbdde8d01b65592Apple Quicktime versions 7.2 and 7.3 RTSP response Content-Type header stack buffer overflow exploit for Mac-OSX and Microsoft Windows.
d4baf9f14cde879e614f5c6db71a820eFTP Admin version 0.1.0 suffers from bypass, local file inclusion, and cross site scripting vulnerabilities.
1e741f922fd81e1ff0a42de723906a5fSeditio CMS versions 1.21 and below remote SQL injection exploit.
468a077a42d53b68260892de589cbfceLearnLoop version 2.0beta7 suffers from a remote file disclosure vulnerability in file_download.php.
5e6cd1e53b99aaa460c0f6ceca7a3dceKML Share version 1.1 suffers from a remote file disclosure vulnerability in region.php.
2b1ec2490af8164970e908bd9e80aad0WebED version 0.0.9 suffers from a remote file disclosure vulnerability in index.php.
9269a457a149191bd915d544cc6e3c8dWeb-MeetMe version 3.0.3 suffers from a remote file disclosure vulnerability in play.php.
d4655f22240f4a2600afd9d831200b17Windows Media Player AIFF divide by zero exception denial of service proof of concept exploit.
418492572208c1f1fa8aac6f3178c854bcoos versions 1.0.10 and below suffer from cross site scripting and SQL injection vulnerabilities.
051227c1abe093f587291db4854390ecCharrays CMS version 0.9.3 suffers from multiple remote file inclusion vulnerabilities.
03378f132fba2d0c8642c5e906af52c1EHCP versions 0.22.8 and below suffer from multiple remote file inclusion vulnerabilities.
96d23787130e22bae7ab1aae6b53c59aPHP-CON version 1.3 suffers from a remote file inclusion vulnerability in include.php.
1b2245850cdd8bc0ce2db14a132a198ep.mapper version 3.2.0 suffers from a remote file inclusion vulnerability.
95cff3614ec14efae28f68ea8533d20aLiferay Enterprise Portal version 4.3.1 suffers from cross site scripting vulnerabilities.
4f6ca29e3e2d33f578a48d27a40e59f1PHPkit version 1.6.1 suffers from a remote file inclusion vulnerability.
33d8aa2719f9b4b7d6a7c63fb2459101Apple QuickTime RTSP response Content-type remote stack rewrite exploit for Internet Explorer 6/7.
e6f416f2debf73019e613a9b48030d21BitDefender Online Scanner 8 ActiveX heap overflow exploit that makes use of OScan8.ocx and OScan81.ocx.
dad0a96eb5485519621d9f97946244b3wpQuiz version 2.7 suffers from multiple remote SQL injection vulnerabilities.
e8def58121202d2e6e3daf32b2bde72b