Packet Storm new exploits for July, 2008.
88d7fb354b82c39ac5382a30173f22d5PHPX version 3.5.16 suffers from a cookie poisoning and login bypass vulnerability.
9274ec1502f7a3ae16086a8bd2a2856dSymphony versions 1.7.01 and below remote code execution exploit.
ab4d37da277c788f9a43fde4fe745d6bCoppermine Photo Gallery versions 1.4.18 and below local file inclusion and remote code execution exploit.
bbdf830ba1ed2c11699b73d0c8cb3121LetterIt 2 suffers from a local file inclusion vulnerability.
73cc2b51a7f6eae8f3442eceee94b54fThe PozScripts Classified Ads Script suffers from a remote SQL injection vulnerability in product_desc.php.
bd9b9bf2fec0d032acec4e682b9e5a85csphonebook version 1.02 suffers from a cross site scripting vulnerability.
e62631a4fb5b369616d9954eda4870faF-PROT Antivirus version 6.2.1.4252 suffers from an infinite loop denial of service vulnerability when handling a malformed archive. Such an archive is included.
ccf02c136598d7886c30a98078a7ba43NCTsoft ActiveX related remote buffer overflow exploit that takes advantage of AudFile.dll.
8ee8f9330dd6abfe717fd0230ca78998The PozScripts Classified Ads Script suffers from a remote SQL injection vulnerability in browsecats.php.
6c859a1f6d06c0d0e8c25326fb61bf41TubeGuru Video Sharing Script suffers from a remote SQL injection vulnerability in ugroups.php.
d8a20f6abf6a9d93d1cac1a1b5f7c64aeNdonesia version 8.4 remote SQL injection exploit that takes advantage of the calendar module.
8bff5e54cb510b4b387b287c56efe645Pligg versions 9.9 and below remote code execution exploit.
48f192b98b7e0813651772beee33a5bbPligg versions 9.9 and below suffer from cross site scripting, arbitrary file access, and SQL injection vulnerabilities.
32bbd3741f287522ca607c70fb37baeeAffinium Campaign version 7.2.1.0.55 suffers from a denial of service vulnerability in its Listener.
1c8609882e0498db76d246324b9bd7f2Affinium Campaign version 7.2.1.0.55 suffers from a directory traversal vulnerability in its Listener.
f040894ebb6ca88833e11c0ceaf0b9bfAffinium Campaign version 7.2.1.0.55 suffers from a directory traversal vulnerability.
ca8bd33d4a7da59a4f997badf8bfc625Affinium Campaign version 7.2.1.0.55 suffers from a javascript insertion vulnerability.
aa73e008ea27448fe48f62df82d14ae0Affinium Campaign version 7.2.1.0.55 suffers from multiple cross site scripting vulnerabilities.
a40af2b210279d4f88bbd6a9f78d411dScrewTurn Wiki versions 2.0.29 and 2.0.30 suffer from a cross site scripting vulnerability.
efef90d34b2439d0972f18bf9cab7b71Atmail PHP version 5.41 suffers from a file download vulnerability that allows a remote attacker to gain access to database passwords and more.
8d096f5271b884f9d032f7989bfbb7eaArticle Friendly Pro and Article Friendly Standard suffer from a SQL injection vulnerability in categorydetail.php.
bae1a29a678865b7c8200c072c31c913ZeeReviews suffers from a remote SQL injection vulnerability in comments.php.
2c764888f278479d2df38d1d60d42afcAtMail leaves world readable files available post install, allowing for the htpasswd file and more to be extracted.
4fdfda34b46c5b29ffe67fcb8aa22e22DEV WMS suffers from local file inclusion, cross site scripting, and SQL injection vulnerabilities.
21cc74aefeacf04b081d6a1024ca7bcb