Packet Storm new exploits for January, 2009.
a679372cf3d841f02c6c482748023eb7E-PHP Scripts B2B Trading Marketplace suffers from a cross site scripting vulnerability.
deec79aea026a9bc2386f1fc2d078a65E-PHP Scripts EShop suffers from a remote SQL injection vulnerability in search_results.php.
8f2e7a15126edfd60dcc55704c1ade10eVision CMS version 2.0 remote command execution exploit that uses local file inclusion and a file upload vulnerability in conjunction with each other.
0f2142fee41f615b11c8f2dce00d31cceVision CMS versions 2.0 and below suffer from a remote SQL injection vulnerability.
8c7d53b57111535b4c8bd4dd3ec6089bSpider Player version 2.3.9.5 off-by-one crash exploit that creates a malicious .asx file.
c3e7e35f2fc931e6655d15f853e22ebcOrca version 2.0.2 suffers from a remote cross site scripting vulnerability.
1e711502a37e8e725b7fc355c8426a2dSkaLinks version 1.5 suffers from a remote SQL injection vulnerability that allows for authentication bypass.
ee529237a1d0640c3d37d78b11a1c33bBPAutoSales version 1.0.1 suffers from remote SQL injection and cross site scripting vulnerabilities.
67f21253d4f84229ebf1ec079e2bf486ReVou Micro Blogging suffers from remote SQL injection and cross site scripting vulnerabilities.
42b3ef7131af09543901cced672b33f3Updated version of the Google Chrome chromehtml: code execution vulnerability that demonstrates disabling of the sandbox. Version 1.0.154.46 is affected.
4770d42cc22cb22e1421be952380ac92Enomaly ECP/Enomalism versions prior to 2.1.1 use temporary files in an insecure manner, allowing for symlink and command injection attacks.
a737bdd340609b1aa09bfc6f0bef51e6Bugs Online version 2.14 suffers from a remote SQL injection vulnerability.
b8f713a4214348dddc7c893c6be9b6caSalesCart suffers from a remote SQL injection vulnerability that allows for authentication bypass.
5fccc3fc50f341d82ab28da84f93cc98The Synactis ALL_IN_THE_BOX Active-X control version 3 can be used to overwrite any file on the target system.
9afe6894b1963fa333698dca82c26d27Remote SEH overwrite exploit for the Amaya Web Editor version 11.
79e19afd11fb10ec7dcf2e031de3c092PerlSoft Gastebuch version 1.7b bruteforcer and remote code execution exploit.
47c2b8013be89664265730b5badd0153Cross site request forgery exploit for the Zoom VoIP Phone Adapter ATA1+1.
52b6a55f494de461e310428068e50b37The D-Link VoIP Phone Adapter suffers from cross site request forgery and cross site scripting vulnerabilities.
f0b88a1f7c24b11bce6007dd3272ed2fThe Profense Web Application Firewall version 2.6.2 suffers from cross site request forgery and cross site scripting vulnerabilities.
18464aecf6a95f5e72d0989484c8d7b4The ManageEngine Firewall Analyzer version 5 suffers from cross site request forgery and cross site scripting vulnerabilities.
4471b559ed2d4f8c8c9d2800f1bccfc4Pligg version 9.9.5 cross site request forgery protection bypass and captcha bypass exploits.
6f4b97b7c8101a98dc278ee22b794858GOM Player version 2.0.12 universal buffer overflow exploit that creates a malicious .pls file.
d360ae5328f6041f8906620e1a8511b2GNUBoard version 4.31.04 suffers from local file inclusion, SQL injection, and file name disclosure vulnerabilities.
7c9ada9a2cc9ad5de914a8f6ec3cc9afPLE CMS version 1.0 Beta 4.2 blind SQL injection exploit that leverages login.php.
d38aa0d13694f000fee3d1b76f9760f8