Packet Storm new exploits for May, 2008.
8bf014a7a2a523bb3f6779ab85a9dc91Social Site Generator suffers from a remote file inclusion vulnerability.
b20df112e9c0efe10956375bea48cce9The Joomla component Prayercenter versions 1.4.9 and below suffer from a remote SQL injection vulnerability.
e244ed6f86603e165391b21c009fc473PassWiki versions 0.9.16 RC3 and below suffer from a local file inclusion vulnerability.
baeb923b8ab1ba8a3e6b1249e3c2c70cEasyWay CMS remote SQL injection exploit that takes advantage of index.php.
53c5121201a176ece30a16e8b1bd9368PHP Visit Counter versions 0.4 and below suffer from a SQL injection vulnerability.
ed3a1ef4bcb84035bc70bc127b7d355fAzureSites CMS suffers from insecure cookie handling and SQL injection vulnerabilities.
3513c24689e3199ef778f5b611d771fdBP Blog version 6.0 suffers from a remote blind SQL injection vulnerability in template_permalink.asp.
2e1b090d5a3112d606a84882feb3f514Social Site Generator suffers from a remote SQL injection vulnerability.
2c7c928c2b002837e0316f5bfee65d7eCMSimple version 3.1 local file inclusion and arbitrary file upload exploit.
bff5f52c65330c8e6a004b30fef457f1PsychoStats versions 2.3.3 and below suffer from remote SQL injection vulnerabilities.
1784f9f1b7d8ab7c4300bc7af532a4aaNow SMS/MMS Gateway version 5.5 remote buffer overflow exploit that binds a shell to port 4444.
49f4abb982903edd29a7f3ca736e3bc5Remote SQL injection exploit for the Mambo mambads component version 1.0 RC1 Beta and 1.0 RC1.
7e0907265c933df3d0299268dbe846e6HiveMaker Professional versions 1.0.2 and below suffer from a remote SQL injection vulnerability.
3559711ae15bdf164869ffb27f37c04dApple Mail versions 3.1 and 3.2 suffer from a denial of service vulnerability when reading a specially crafted e-mail.
ce912545b903fa38b3114b0702de84f7Dot Net Nuke versions 4.8.3 and below suffer from a cross site scripting vulnerability.
904a25b30b16bbaf6000063abbc27ac0PHP Booking Calendar version 10d arbitrary file upload exploit.
d402515882cf622d34091b2b8760dbd2CMS from Scratch versions 1.1.3 and below suffer from a directory traversal vulnerability in image.php.
1e43ee740d022518e2dd23dad1963f5fPHP Booking Calendar version 10d remote SQL injection exploit that retrieves the administrator login and password hash.
b6350f88a0485a428470e288c73a9ddeASUS DPC proxy versions 2.0.0.16 and 2.0.0.19 remote buffer overflow exploit that binds a shell to port 4444.
699076b2a1cd858005940e45fc27c360XEROX DocuShare versions 6 and below suffer from a cross site scripting vulnerability.
6b3c1615f69e72ad510afb7522a87c74CMS from Scratch versions 1.1.3 and below remote shell upload exploit.
55015dace42e2f4b4858f77a22e978cadvbbs version 8.2 is vulnerable to remote SQL injection attacks via login.asp.
224a4abb9cd8b3dc7868a8dea19980b8FlashBlog beta version 0.31 suffers from a remote file upload vulnerability.
98c5e3c83967e35214d666b472bcac32PicoFlat CMS version 0.5.9 suffers from a local file inclusion vulnerability in index.php. This uses the same variable that had a remote file inclusion vulnerability back in October of 2007.
92188ef0a3d4e5e0aee53acb9dbd05e7