<?xml version="1.0" encoding="ISO-8859-1" ?>
<rss version="2.0">
	<channel>
	<title>Packet Storm Security Last 100</title>
	<link>http://packetstormsecurity.org/</link>
	<description>100 Most Recent Packet Storm File Additions</description>
	<language>en-us</language>

<item>
	<title>soulseek157-psexec.txt</title>
	<link>http://packetstormsecurity.org/0907-exploits/soulseek157-psexec.txt</link>
	<description>Soulseek versions 157 NS below 13e and all versions of 156 suffer from a remote peer search code execution vulnerability. </description>
</item>
<item>
	<title>shopcartdx430-sql.txt</title>
	<link>http://packetstormsecurity.org/0907-exploits/shopcartdx430-sql.txt</link>
	<description>Remote SQL injection exploit for ShopCartDx version 4.30 that leverages product_detail.php. This particular vulnerability was priorly discovered but further research has been performed. </description>
</item>
<item>
	<title>shopcartdx430-blindsql.txt</title>
	<link>http://packetstormsecurity.org/0907-exploits/shopcartdx430-blindsql.txt</link>
	<description>Remote blind SQL injection exploit for ShopCartDx version 4.30 that leverages product_detail.php. </description>
</item>
<item>
	<title>cve-2008-3531.c</title>
	<link>http://packetstormsecurity.org/0907-exploits/cve-2008-3531.c</link>
	<description>Local root exploit for FreeBSD nmount(). This affects FreeBSD 7.0-RELEASE and 7.0-STABLE. </description>
</item>
<item>
	<title>axesstel-bypass.txt</title>
	<link>http://packetstormsecurity.org/0907-exploits/axesstel-bypass.txt</link>
	<description>The Axesstel MV 410R protects from malicious input by leveraging javascript, allowing an attacker to bypass all of this easily. The device is also susceptible to permanent cross site scripting vulnerabilities. </description>
</item>
<item>
	<title>opialaid-sql.txt</title>
	<link>http://packetstormsecurity.org/0907-exploits/opialaid-sql.txt</link>
	<description>Opial version 1.0 suffers from a remote SQL injection vulnerability. </description>
</item>
<item>
	<title>glsa-200907-02.txt</title>
	<link>http://packetstormsecurity.org/0907-advisories/glsa-200907-02.txt</link>
	<description>Gentoo Linux Security Advisory GLSA 200907-02 - Two vulnerabilities in ModSecurity might lead to a Denial of Service. Versions less than 2.5.9 are affected. </description>
</item>
<item>
	<title>glsa-200907-01.txt</title>
	<link>http://packetstormsecurity.org/0907-advisories/glsa-200907-01.txt</link>
	<description>Gentoo Linux Security Advisory GLSA 200907-01 - libwmf bundles an old GD version which contains a use-after-free vulnerability. The embedded fork of the GD library introduced a use-after-free vulnerability in a modification which is specific to libwmf. Versions less than 0.2.8.4-r3 are affected. </description>
</item>
<item>
	<title>rentventory-sql.txt</title>
	<link>http://packetstormsecurity.org/0907-exploits/rentventory-sql.txt</link>
	<description>Rentventory PHP suffers from multiple remote SQL injection vulnerabilities. </description>
</item>
<item>
	<title>petite-sql.txt</title>
	<link>http://packetstormsecurity.org/papers/general/petite-sql.txt</link>
	<description>This paper is a small SQL injection tutorial and is written in French. </description>
</item>
<item>
	<title>oCERT-2009-009.txt</title>
	<link>http://packetstormsecurity.org/0907-advisories/oCERT-2009-009.txt</link>
	<description>CamlImages versions 2.2 and below suffer from several integer overflows which may lead to a potentially exploitable heap overflow and result in arbitrary code execution. The vulnerability is triggered by PNG image parsing, the read_png_file and read_png_file_as_rgb24 functions do not properly validate the width and height of the image. Specific PNG images with large width and height can be crafted to trigger the vulnerability. </description>
</item>
<item>
	<title>USN-795-1.txt</title>
	<link>http://packetstormsecurity.org/0907-advisories/USN-795-1.txt</link>
	<description>Ubuntu Security Notice USN-795-1 - It was discovered that Nagios did not properly parse certain commands submitted using the WAP web interface. An authenticated user could exploit this flaw and execute arbitrary programs on the server. </description>
</item>
<item>
	<title>USN-794-1.txt</title>
	<link>http://packetstormsecurity.org/0907-advisories/USN-794-1.txt</link>
	<description>Ubuntu Security Notice USN-794-1 - It was discovered that the Compress::Raw::Zlib Perl module incorrectly handled certain zlib compressed streams. If a user or automated system were tricked into processing a specially crafted compressed stream or file, a remote attacker could crash the application, leading to a denial of service. </description>
</item>
<item>
	<title>joomla1512-xss.txt</title>
	<link>http://packetstormsecurity.org/0907-exploits/joomla1512-xss.txt</link>
	<description>Joomla! versions prior to 1.5.12 suffer from multiple cross site scripting vulnerabilities in relation to HTTP headers. </description>
</item>
<item>
	<title>HPSBUX02431-SSRT090085.txt</title>
	<link>http://packetstormsecurity.org/0907-advisories/HPSBUX02431-SSRT090085.txt</link>
	<description>HP Security Bulletin - Potential security vulnerabilities have been identified with HP-UX running Apache-based Web Server or Tomcat-based Servelet Engine. The vulnerabilities could be exploited remotely to cause a Denial of Service (DoS), or execution of arbitrary code. Apache-based Web Server and Tomcat-based Servelet Engine are contained in the Apache Web Server Suite. </description>
</item>
<item>
	<title>HPSBUX02440-SSRT090106.txt</title>
	<link>http://packetstormsecurity.org/0907-advisories/HPSBUX02440-SSRT090106.txt</link>
	<description>HP Security Bulletin - A potential security vulnerability has been identified with NFS/ONCplus running on HP-UX. The vulnerability could be exploited locally to create a Denial of Service (DoS). </description>
</item>
<item>
	<title>USN-793-1.txt</title>
	<link>http://packetstormsecurity.org/0907-advisories/USN-793-1.txt</link>
	<description>Ubuntu Security Notice USN-793-1 - Multiple vulnerabilities associated with the Linux 2.6 kernel have been addressed. These issues range from arbitrary code execution to denial of service vulnerabilities. </description>
</item>
<item>
	<title>opial-sql.txt</title>
	<link>http://packetstormsecurity.org/0907-exploits/opial-sql.txt</link>
	<description>Opial version 1.0 suffers from a remote SQL injection vulnerability that allows for authentication bypass. </description>
</item>
<item>
	<title>sourcefire-escalate.txt</title>
	<link>http://packetstormsecurity.org/0907-exploits/sourcefire-escalate.txt</link>
	<description>Sourcefire 3D Sensor and Defense Center versions 4.8.1 and below suffer from a privilege escalation vulnerability. </description>
</item>
<item>
	<title>adminlog-bypass.txt</title>
	<link>http://packetstormsecurity.org/0907-exploits/adminlog-bypass.txt</link>
	<description>AdminLog version 0.5 suffers from an authentication bypass vulnerability. </description>
</item>
<item>
	<title>almnzm-blindsql.txt</title>
	<link>http://packetstormsecurity.org/0907-exploits/almnzm-blindsql.txt</link>
	<description>Almnzm version 2.0 remote blind SQL injection exploit. </description>
</item>
<item>
	<title>conpresso-sql.txt</title>
	<link>http://packetstormsecurity.org/0907-exploits/conpresso-sql.txt</link>
	<description>conpresso version 3.4.8 suffers from a blind SQL injection vulnerability in detail.php. </description>
</item>
<item>
	<title>oracle10gsyslt-sql.txt</title>
	<link>http://packetstormsecurity.org/0907-exploits/oracle10gsyslt-sql.txt</link>
	<description>Oracle 10g SYS.LT.COMPRESSWORKSPACETREE remote SQL injection exploit. </description>
</item>
<item>
	<title>yourtube-disclose.txt</title>
	<link>http://packetstormsecurity.org/0907-exploits/yourtube-disclose.txt</link>
	<description>YourTube versions 2.0 and below suffer from a remote SQL database disclosure vulnerability. </description>
</item>
<item>
	<title>safari-crash.txt</title>
	<link>http://packetstormsecurity.org/0907-exploits/safari-crash.txt</link>
	<description>Apple Safari version 4.x javascript reload denial of service exploit. </description>
</item>
<item>
	<title>httpry-0.1.5.tar.gz</title>
	<link>http://packetstormsecurity.org/sniffers/httpry-0.1.5.tar.gz</link>
	<description>httpry is a specialized packet sniffer designed for displaying and logging HTTP traffic. It is not intended to perform analysis itself, but instead to capture, parse, and log the traffic for later analysis. It can be run in real-time displaying the live traffic on the wire, or as a daemon process that logs to an output file. It is written to be as lightweight and flexible as possible, so that it can be easily adaptable to different applications. It does not display the raw HTTP data transferred, but instead focuses on parsing and displaying the request/response line along with associated header fields.</description>
</item>
<item>
	<title>cmschainuk-lfixssshell.txt</title>
	<link>http://packetstormsecurity.org/0907-exploits/cmschainuk-lfixssshell.txt</link>
	<description>CMS Chainuk versions 1.2 and below suffer from local file inclusion, cross site scripting, and remote shell vulnerabilities. </description>
</item>
<item>
	<title>kervinet-sqlxss.txt</title>
	<link>http://packetstormsecurity.org/0907-exploits/kervinet-sqlxss.txt</link>
	<description>KerviNet Forum versions 1.1 and below suffer from SQL injection, cross site scripting, and a couple of other vulnerabilities. </description>
</item>
<item>
	<title>audiopluspls-overflow.txt</title>
	<link>http://packetstormsecurity.org/0907-exploits/audiopluspls-overflow.txt</link>
	<description>AudioPLUS version 2.00.215 local buffer overflow exploit that creates a malicious .pls file. </description>
</item>
<item>
	<title>ard9808-passwords.txt</title>
	<link>http://packetstormsecurity.org/0907-exploits/ard9808-passwords.txt</link>
	<description>The ARD-9808 DVR card security camera suffers from a password disclosure vulnerability. </description>
</item>
<item>
	<title>fipscms-disclose.txt</title>
	<link>http://packetstormsecurity.org/0907-exploits/fipscms-disclose.txt</link>
	<description>fipsCMS Light version 2.1 arbitrary database disclosure exploit. </description>
</item>
<item>
	<title>peamp-overflow.txt</title>
	<link>http://packetstormsecurity.org/0907-exploits/peamp-overflow.txt</link>
	<description>PEamp version 1.02b local buffer overflow proof of concept exploit that creates a malicious .m3u file. </description>
</item>
<item>
	<title>linux-hardening.txt</title>
	<link>http://packetstormsecurity.org/papers/general/linux-hardening.txt</link>
	<description>Whitepaper called Linux Hardening and Security. </description>
</item>
<item>
	<title>mp3nator-overflow.txt</title>
	<link>http://packetstormsecurity.org/0907-exploits/mp3nator-overflow.txt</link>
	<description>MP3-Nator version 2.0 universal buffer overflow exploit that creates a malicious .plf file. </description>
</item>
<item>
	<title>winxp-sp3_beep_shellcode.txt</title>
	<link>http://packetstormsecurity.org/shellcode/winxp-sp3_beep_shellcode.txt</link>
	<description>Microsoft Windows XP SP3 beep and exitprocess shellcode. </description>
</item>
<item>
	<title>greendam-time.txt</title>
	<link>http://packetstormsecurity.org/0907-exploits/greendam-time.txt</link>
	<description>Green Dam remote change system time exploit that leverages the fact that UDP port 1234 listens and accepts time updates unauthenticated. </description>
</item>
<item>
	<title>radware-disclose.txt</title>
	<link>http://packetstormsecurity.org/0907-advisories/radware-disclose.txt</link>
	<description>The radware AppWall Web Application Firewall suffers from a source code disclosure vulnerability on the management interface. Gateway version 4.6.0.2 and AppWall version 1.0.2.6 are affected. </description>
</item>
<item>
	<title>phion-dosexec.txt</title>
	<link>http://packetstormsecurity.org/0907-advisories/phion-dosexec.txt</link>
	<description>The phion airlock Web Application Firewall version 4.1-10.41 suffers denial of service and arbitrary command execution vulnerabilities. </description>
</item>
<item>
	<title>artofdefence-dos.txt</title>
	<link>http://packetstormsecurity.org/0907-advisories/artofdefence-dos.txt</link>
	<description>The Artofdefence Hyperguard Web Application Firewall versions 3.1.1-11637 and below, 3.0.3-11636 and below, and 2.5.5-11635 and below suffer from a remote denial of service vulnerability. </description>
</item>
<item>
	<title>0906-exploits.tgz</title>
	<link>http://packetstormsecurity.org/0906-exploits/0906-exploits.tgz</link>
	<description>This archive contains all of the 246 exploits added to Packet Storm in June, 2009. </description>
</item>
<item>
	<title>VMSA-2009-0008.txt</title>
	<link>http://packetstormsecurity.org/0907-advisories/VMSA-2009-0008.txt</link>
	<description>VMware Security Advisory - An input validation flaw in the asn1_decode_generaltime function in MIT Kerberos 5 before 1.6.4 allows remote attackers to cause a denial of service or possibly execute arbitrary code via vectors involving an invalid DER encoding that triggers a free of an uninitialized pointer. </description>
</item>
<item>
	<title>messageslib-database.txt</title>
	<link>http://packetstormsecurity.org/0907-exploits/messageslib-database.txt</link>
	<description>Messages Library version 2.0 suffers from an insecure cookie handling and database download vulnerability. </description>
</item>
<item>
	<title>messageslib-delete.txt</title>
	<link>http://packetstormsecurity.org/0907-exploits/messageslib-delete.txt</link>
	<description>Messages Library version 2.0 suffers from an arbitrary delete message vulnerability. </description>
</item>
<item>
	<title>audioplus-overflow.txt</title>
	<link>http://packetstormsecurity.org/0907-exploits/audioplus-overflow.txt</link>
	<description>AudioPLUS version 2.00.215 local buffer overflow exploit that creates a malicious .m3u file. </description>
</item>
<item>
	<title>web-security.pdf</title>
	<link>http://packetstormsecurity.org/papers/web/web-security.pdf</link>
	<description>Whitepaper called Web Vulnerabilities and Security. Written in Romanian. </description>
</item>
<item>
	<title>cracking-air.pdf</title>
	<link>http://packetstormsecurity.org/papers/wireless/cracking-air.pdf</link>
	<description>Whitepaper called Cracking The Air, The Other Way. </description>
</item>
<item>
	<title>messageslibrary-admin.txt</title>
	<link>http://packetstormsecurity.org/0906-exploits/messageslibrary-admin.txt</link>
	<description>Messages Library version 2.0 suffers from an arbitrary add administrator vulnerability. </description>
</item>
<item>
	<title>MDVSA-2009-147.txt</title>
	<link>http://packetstormsecurity.org/0906-advisories/MDVSA-2009-147.txt</link>
	<description>Mandriva Linux Security Advisory 2009-147 - Arbitrary code execution, denial of service, and overflows have been addressed in the latest Pidgin update. </description>
</item>
<item>
	<title>tsep-sqlxssdisclose.txt</title>
	<link>http://packetstormsecurity.org/0906-exploits/tsep-sqlxssdisclose.txt</link>
	<description>TSEP versions 0.942.02 and below suffer from cross site scripting, remote SQL injection, and information disclosure vulnerabilities. </description>
</item>
<item>
	<title>myegy-sql.txt</title>
	<link>http://packetstormsecurity.org/0906-exploits/myegy-sql.txt</link>
	<description>MyEgy Script suffers from a remote SQL injection vulnerability. </description>
</item>
<item>
	<title>phpmyblockchecker-insecure.txt</title>
	<link>http://packetstormsecurity.org/0906-exploits/phpmyblockchecker-insecure.txt</link>
	<description>phpMyBlockchecker version 1.0.0055 suffers from an insecure cookie handling vulnerability. </description>
</item>
<item>
	<title>bigacecms-lfi.txt</title>
	<link>http://packetstormsecurity.org/0906-exploits/bigacecms-lfi.txt</link>
	<description>BIGACE CMS version 2.6 suffers from a local file inclusion vulnerability. </description>
</item>
<item>
	<title>xampp-xssphpinfo.txt</title>
	<link>http://packetstormsecurity.org/0906-exploits/xampp-xssphpinfo.txt</link>
	<description>XAMPP for Windows suffers from phpinfo and cross site scripting vulnerabilities. Versions 1.4.9, 1.5.0, 1.5.1, and 1.6.4 are affected. </description>
</item>
<item>
	<title>hex-head.c</title>
	<link>http://packetstormsecurity.org/UNIX/utilities/hex-head.c</link>
	<description>This is a simple head utility that outputs in hexadecimal format. Characters that are non-printable are replaced with the  .  character. </description>
</item>
<item>
	<title>glsa-200906-05.txt</title>
	<link>http://packetstormsecurity.org/0906-advisories/glsa-200906-05.txt</link>
	<description>Gentoo Linux Security Advisory GLSA 200906-05 - Multiple vulnerabilities have been discovered in Wireshark which allow for Denial of Service (application crash) or remote code execution. Versions less than 1.0.8 are affected. </description>
</item>
<item>
	<title>jaxformmailer-rfi.txt</title>
	<link>http://packetstormsecurity.org/0906-exploits/jaxformmailer-rfi.txt</link>
	<description>Jax FormMailer version 3.0.0 suffers from a remote file inclusion vulnerability. </description>
</item>
<item>
	<title>smfma-sql.txt</title>
	<link>http://packetstormsecurity.org/0906-exploits/smfma-sql.txt</link>
	<description>Member Awards SMF module version 1.0.2 blind SQL injection exploit. </description>
</item>
<item>
	<title>wprelatedsites-sql.txt</title>
	<link>http://packetstormsecurity.org/0906-exploits/wprelatedsites-sql.txt</link>
	<description>The Related Sites WordPress plugin version 2.1 suffers from a blind SQL injection vulnerability. </description>
</item>
<item>
	<title>dmfilemanager-disclose.txt</title>
	<link>http://packetstormsecurity.org/0906-exploits/dmfilemanager-disclose.txt</link>
	<description>DM FileManager version 3.9.4 suffers from a remote file disclosure vulnerability. </description>
</item>
<item>
	<title>wpdmalbums-disclose.txt</title>
	<link>http://packetstormsecurity.org/0906-exploits/wpdmalbums-disclose.txt</link>
	<description>The DM Album WordPress plugin version 1.9.2 suffers from a remote file disclosure vulnerability. </description>
</item>
<item>
	<title>tfmmmplayer-overflow.txt</title>
	<link>http://packetstormsecurity.org/0906-exploits/tfmmmplayer-overflow.txt</link>
	<description>TFM MMPlayer version 2.0 universal buffer overflow exploit that creates a malicious .m3u file. </description>
</item>
<item>
	<title>Neversolved.pl.txt</title>
	<link>http://packetstormsecurity.org/0906-exploits/Neversolved.pl.txt</link>
	<description>Newsolved version 1.1.6 login grabbing remote SQL injection exploit. </description>
</item>
<item>
	<title>htmp3player10-overflow.txt</title>
	<link>http://packetstormsecurity.org/0906-exploits/htmp3player10-overflow.txt</link>
	<description>HT-MP3Player version 1.0 universal buffer overflow exploit that creates a malicious .ht3 file. </description>
</item>
<item>
	<title>cpanel-disclose.txt</title>
	<link>http://packetstormsecurity.org/0906-exploits/cpanel-disclose.txt</link>
	<description>Cpanel suffers from an arbitrary file disclosure vulnerability. </description>
</item>
<item>
	<title>glsa-200906-04.txt</title>
	<link>http://packetstormsecurity.org/0906-advisories/glsa-200906-04.txt</link>
	<description>Gentoo Linux Security Advisory GLSA 200906-04 - An error in the Apache Tomcat JK Connector might allow for an information disclosure flaw. The Red Hat Security Response Team discovered that mod_jk does not properly handle (1) requests setting the Content-Length header while not providing data and (2) clients sending repeated requests very quickly. Versions less than 1.2.27 are affected. </description>
</item>
<item>
	<title>glsa-200906-03.txt</title>
	<link>http://packetstormsecurity.org/0906-advisories/glsa-200906-03.txt</link>
	<description>Gentoo Linux Security Advisory GLSA 200906-03 - Multiple errors in phpMyAdmin might allow the remote execution of arbitrary code or a Cross-Site Scripting attack. Versions less than 2.11.9.5 are affected. </description>
</item>
<item>
	<title>dmalbums-rfi.txt</title>
	<link>http://packetstormsecurity.org/0906-exploits/dmalbums-rfi.txt</link>
	<description>DM Albums version 1.9.2 and WordPress plugin suffer from a remote file inclusion vulnerability. </description>
</item>
<item>
	<title>dmfilemanager-rfi.txt</title>
	<link>http://packetstormsecurity.org/0906-exploits/dmfilemanager-rfi.txt</link>
	<description>DM FileManager version 3.9.4 suffers from a remote file inclusion vulnerability. </description>
</item>
<item>
	<title>MDVSA-2009-146.txt</title>
	<link>http://packetstormsecurity.org/0906-advisories/MDVSA-2009-146.txt</link>
	<description>Mandriva Linux Security Advisory 2009-146 - Security vulnerabilities has been identified and fixed in University of Washington IMAP Toolkit. These include multiple stack-based buffer overflows, a pointer dereference, and an off-by-one error. </description>
</item>
<item>
	<title>punbbaffiliationsin-blindsql.txt</title>
	<link>http://packetstormsecurity.org/0906-exploits/punbbaffiliationsin-blindsql.txt</link>
	<description>Versions 1.1 and below of the IN module in PunBB suffers from a remote blind SQL injection vulnerability in Affiliations.php. </description>
</item>
<item>
	<title>punbbvoteforusout-blindsql.txt</title>
	<link>http://packetstormsecurity.org/0906-exploits/punbbvoteforusout-blindsql.txt</link>
	<description>Versions 1.0.1 and below of the OUT module in PunBB suffer from a remote blind SQL injection vulnerability in VoteForUs.php. </description>
</item>
<item>
	<title>picviz-0.6.tar.gz</title>
	<link>http://packetstormsecurity.org/UNIX/utilities/picviz-0.6.tar.gz</link>
	<description>Picviz is a parallel coordinates plotter which enables easy scripting from various types of input (such as tcpdump, syslog, iptables logs, or Apache logs) to visualize your data and discover interesting results quickly. Its primary goal is to graph data in order to be able to quickly analyze problems and find correlations among variables. With security analysis in mind, the program has been designed to be very flexible, able to graph millions of events. This tarball includes the cli, gui, and the library for picviz.</description>
</item>
<item>
	<title>aad-disclose.txt</title>
	<link>http://packetstormsecurity.org/0906-exploits/aad-disclose.txt</link>
	<description>Audio Article Directory suffers from a remote file disclosure vulnerability. </description>
</item>
<item>
	<title>joomlabookflip-sql.txt</title>
	<link>http://packetstormsecurity.org/0906-exploits/joomlabookflip-sql.txt</link>
	<description>The Joomla Bookflip component suffers from a remote SQL injection vulnerability. </description>
</item>
<item>
	<title>MDVSA-2009-145.txt</title>
	<link>http://packetstormsecurity.org/0906-advisories/MDVSA-2009-145.txt</link>
	<description>Mandriva Linux Security Advisory 2009-145 - A vulnerability has been found and corrected in PHP. The updated packages have been patched to correct these issues. </description>
</item>
<item>
	<title>phpfanfictionsploit-sql.txt</title>
	<link>http://packetstormsecurity.org/0906-exploits/phpfanfictionsploit-sql.txt</link>
	<description>phpFanfiction remote SQL injection exploit that attempts to pull the admin account. </description>
</item>
<item>
	<title>phpfanfiction-sql.txt</title>
	<link>http://packetstormsecurity.org/0906-exploits/phpfanfiction-sql.txt</link>
	<description>phpFanfiction suffers from a remote SQL injection vulnerability. </description>
</item>
<item>
	<title>clicknetcms-disclose.txt</title>
	<link>http://packetstormsecurity.org/0906-exploits/clicknetcms-disclose.txt</link>
	<description>Clicknet CMS version 2.1 suffers from a remote file disclosure vulnerability. </description>
</item>
<item>
	<title>phpsugar-lfi.txt</title>
	<link>http://packetstormsecurity.org/0906-exploits/phpsugar-lfi.txt</link>
	<description>PHP-Sugar version 0.80 suffers from a local file inclusion vulnerability. </description>
</item>
<item>
	<title>punbbvoteforus-blindsql.txt</title>
	<link>http://packetstormsecurity.org/0906-exploits/punbbvoteforus-blindsql.txt</link>
	<description>Versions 1.0.1 and below of the IN module in PunBB suffer from a remote blind SQL injection vulnerability in VoteForUs.php. </description>
</item>
<item>
	<title>punbbaffiliations-blindsql.txt</title>
	<link>http://packetstormsecurity.org/0906-exploits/punbbaffiliations-blindsql.txt</link>
	<description>Versions 1.1 and below of the OUT module in PunBB suffers from a remote blind SQL injection vulnerability in Affiliations.php. </description>
</item>
<item>
	<title>punbbapdb-sql.txt</title>
	<link>http://packetstormsecurity.org/0906-exploits/punbbapdb-sql.txt</link>
	<description>PunBB suffers from a remote SQL injection vulnerability when leveraging a cross site request forgery vulnerability in AP_DB_management.php. </description>
</item>
<item>
	<title>almnzm-sql.txt</title>
	<link>http://packetstormsecurity.org/0906-exploits/almnzm-sql.txt</link>
	<description>Almnzm suffers from a remote SQL injection vulnerability. </description>
</item>
<item>
	<title>oxygen2php113post-blindsql.txt</title>
	<link>http://packetstormsecurity.org/0906-exploits/oxygen2php113post-blindsql.txt</link>
	<description>Oxygen2PHP versions 1.1.3 and below remote blind SQL injection exploit that leverages post.php. </description>
</item>
<item>
	<title>oxygen2php113-blindsql.txt</title>
	<link>http://packetstormsecurity.org/0906-exploits/oxygen2php113-blindsql.txt</link>
	<description>Oxygen2PHP versions 1.1.3 and below remote blind SQL injection exploit that leverages forumdisplay.php. </description>
</item>
<item>
	<title>mdprocwguest-sql.txt</title>
	<link>http://packetstormsecurity.org/0906-exploits/mdprocwguest-sql.txt</link>
	<description>MDPRO CWGuestBook versions 2.1 and below suffer from a remote SQL injection vulnerability. </description>
</item>
<item>
	<title>htmp3player-overflow.txt</title>
	<link>http://packetstormsecurity.org/0906-exploits/htmp3player-overflow.txt</link>
	<description>HT-MP3Player version 1.0 local buffer overflow exploit that creates a malicious .ht3 file. </description>
</item>
<item>
	<title>baofengmp-overflow.txt</title>
	<link>http://packetstormsecurity.org/0906-exploits/baofengmp-overflow.txt</link>
	<description>The Baofeng Media Player Storm version 3.9.62 suffers from a playlist related stack overflow vulnerability. </description>
</item>
<item>
	<title>scmpx-overflow.txt</title>
	<link>http://packetstormsecurity.org/0906-exploits/scmpx-overflow.txt</link>
	<description>SCMPX version 1.5.1 local heap overflow proof of concept exploit that creates a malicious .m3u file. </description>
</item>
<item>
	<title>tor.uclibc.i686.20090627.iso</title>
	<link>http://packetstormsecurity.org/peer2peer/tor.uclibc.i686.20090627.iso</link>
	<description>Tor-ramdisk is an i686 uClibc-based micro Linux distribution whose only purpose is to host a Tor server in an environment that maximizes security and privacy. Tor is a network of virtual tunnels that allows people and groups to improve their privacy and security on the Internet. Security is enhanced by employing a monolithically compiled GRSEC/PAX patched kernel and hardened system tools. Privacy is enhanced by turning off logging at all levels so that even the Tor operator only has access to minimal information. Finally, since everything runs in ephemeral memory, no information survives a reboot, except for the Tor configuration file and the private RSA key which may be exported/imported by FTP.</description>
</item>
<item>
	<title>bopup-overflow.txt</title>
	<link>http://packetstormsecurity.org/0906-exploits/bopup-overflow.txt</link>
	<description>Remote buffer overflow exploit for the Bopup Communications Server version 3.2.26.54.60. Tested on Microsoft Windows XP SP3. </description>
</item>
<item>
	<title>ajaxportal-rfi.txt</title>
	<link>http://packetstormsecurity.org/0906-exploits/ajaxportal-rfi.txt</link>
	<description>AjaxPortal version 3.0 suffers from a remote file inclusion vulnerability. </description>
</item>
<item>
	<title>glsa-200906-02.txt</title>
	<link>http://packetstormsecurity.org/0906-advisories/glsa-200906-02.txt</link>
	<description>Gentoo Linux Security Advisory GLSA 200906-02 - A flaw in the Ruby standard library might allow remote attackers to cause a Denial of Service attack. Tadayoshi Funaba reported that BigDecimal in ext/bigdecimal/bigdecimal.c does not properly handle string arguments containing overly long numbers. Versions less than 1.8.6_p369 are affected. </description>
</item>
<item>
	<title>NGENUITY-2009-007.txt</title>
	<link>http://packetstormsecurity.org/0906-exploits/NGENUITY-2009-007.txt</link>
	<description>osTicket version 1.6 RC4 suffers from a blind SQL injection vulnerability. </description>
</item>
<item>
	<title>glsa-200906-01.txt</title>
	<link>http://packetstormsecurity.org/0906-advisories/glsa-200906-01.txt</link>
	<description>Gentoo Linux Security Advisory GLSA 200906-01 - A vulnerability has been discovered in libpng that allows for information disclosure. Jeff Phillips discovered that libpng does not properly parse 1-bit interlaced images with width values that are not divisible by 8, which causes libpng to include uninitialized bits in certain rows of a PNG file. Versions less than 1.2.37 are affected. </description>
</item>
<item>
	<title>MDVSA-2009-144.txt</title>
	<link>http://packetstormsecurity.org/0906-advisories/MDVSA-2009-144.txt</link>
	<description>Mandriva Linux Security Advisory 2009-144 - Multiple security vulnerabilities has been identified and fixed in ghostscript. This update makes ghostscript link against the shared system jasper library which makes it easier to address presumptive future security issues in the jasper library. </description>
</item>
<item>
	<title>empirecms-sql.txt</title>
	<link>http://packetstormsecurity.org/0906-exploits/empirecms-sql.txt</link>
	<description>Empire CMS version 5.1 suffers from a remote SQL injection vulnerability. </description>
</item>
<item>
	<title>joomlak2-sql.txt</title>
	<link>http://packetstormsecurity.org/0906-exploits/joomlak2-sql.txt</link>
	<description>The Joomla K2 component versions 1.0.1b and below suffer from a remote SQL injection vulnerability. </description>
</item>
<item>
	<title>joomlaphp-sql.txt</title>
	<link>http://packetstormsecurity.org/0906-exploits/joomlaphp-sql.txt</link>
	<description>The Joomla PHP component suffers from a blind SQL injection vulnerability. </description>
</item>
<item>
	<title>messageslibrary-sql.txt</title>
	<link>http://packetstormsecurity.org/0906-exploits/messageslibrary-sql.txt</link>
	<description>Messages Library version 2.0 suffers from a remote SQL injection vulnerability in cat.php. </description>
</item></channel>
</rss>
