Re: CentiPaid = 1.4.2 [$class_pwd] Remote File Include

2006-10-30 Thread Tamriel
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 Open your eyes ... [...] $class_pwd = dirname(__FILE__); include($class_pwd.'/adodb/adodb.inc.php'); [...] [EMAIL PROTECTED] wrote: Affected software description : Application : CentiPaid version : 1.4.3 URL :

Re: freenews--- fileinclude

2006-10-30 Thread Tamriel
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 I would quote the whole code arround the includes, like: [...] if (file_exists(./.$chemin./config.php)){ include ($chemin/config.php); include ($chemin/options.inc.php); include ($chemin/freenews_functions.inc.php); } [...] You could

Re: phpMyConferences_8.0.2 Remote File Inclusion

2006-10-25 Thread Tamriel
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 Are you kidding me? How can you use lvc_include_dir when it`s defined one line above? And don`t tell that you can use ROOT_DIR_PATH instead of lvc_include_dir ... [EMAIL PROTECTED] wrote: $lvc_include_dir =

XeoPort = 0.81 SQL Injection Vulnerability

2006-10-12 Thread Tamriel
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 Advisory: XeoPort = 0.81 SQL Injection Vulnerability Release Date: 10/12/2006 Last Modified: 10/12/2006 Author: Tamriel [tamriel at gmx dot net] Application: XeoPort = 0.81 Risk: Moderate Vendor Status: not contacted

Xeobook = 0.93 Multiple SQL Injection Vulnerabilities

2006-10-12 Thread Tamriel
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 Advisory: Xeobook = 0.93 Multiple SQL Injection Vulnerabilities Release Date: 10/12/2006 Last Modified: 10/12/2006 Author: Tamriel [tamriel at gmx dot net] Application: Xeobook = 0.93 Risk: Moderate Vendor Status

eXpBlog = 0.3.5 Cross Site Scripting Vulnerabilities

2006-10-10 Thread Tamriel
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 Advisory: eXpBlog = 0.3.5 Cross Site Scripting Vulnerabilities Release Date: 10/09/2006 Last Modified: 10/09/2006 Author: Tamriel [tamriel at gmx dot net] Application: eXpBlog = 0.3.5 Risk: Low Vendor Status: contaced

GaesteChaos = 0.2 Multiple Vulnerabilities

2006-08-04 Thread Tamriel
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Advisory: GaesteChaos = 0.2 Multiple Vulnerabilities Release Date: 2006/08/04 Last Modified: 2006/08/03 Author: Tamriel [tamriel at gmx dot net] Application: GaesteChaos = 0.2 Risk: Moderate Vendor Status: not contacted

CounterChaos = 0.48c SQL Injection Vulnerability

2006-08-04 Thread Tamriel
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Advisory: CounterChaos = 0.48c SQL Injection Vulnerability Release Date: 2006/08/04 Last Modified: 2006/08/03 Author: Tamriel [tamriel at gmx dot net] Application: CounterChaos = 0.48c Risk: Moderate Vendor Status

GeheimChaos = 0.5 Multiple SQL Injection Vulnerabilities

2006-08-04 Thread Tamriel
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Advisory: GeheimChaos = 0.5 Multiple SQL Injection Vulnerabilities Release Date: 2006/08/04 Last Modified: 2006/08/03 Author: Tamriel [tamriel at gmx dot net] Application: GeheimChaos = 0.5 Risk: Moderate Vendor Status

Professional Home Page Tools Login Script Cross Site Scripting Vulnerabilities

2006-07-26 Thread tamriel
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Advisory: Professional Home Page Tools Login Script Cross Site Scripting Vulnerabilities Release Date: 2006/07/25 Last Modified: 2006/07/25 Author: Tamriel [tamriel at gmx dot net] Application: Professional Home Page Tools

TP-Book = 1.00 Cross Site Scripting Vulnerabilities

2006-07-26 Thread tamriel
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Advisory: TP-Book = 1.00 Cross Site Scripting Vulnerabilities Release Date: 2006/07/25 Last Modified: 2006/07/25 Author: Tamriel [tamriel at gmx dot net] Application: TP-Book = 1.00 Risk: Low Vendor Status

Professional PHP Tools Guestbook Multiple Vulnerabilities

2006-07-18 Thread tamriel
Advisory: Professional PHP Tools Guestbook Multiple Vulnerabilities Release Date: 2006/06/17 Last Modified: 2006/07/17 Author: Tamriel [tamriel at gmx dot net] Application: Professional PHP Tools Guestbook Risk: Medium Vendor Status: contacted | no patch

hdweGUEST = 2.1.1 Cross Site Scripting Vulnerabilities

2006-07-18 Thread tamriel
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Advisory: hdweGUEST = 2.1.1 Cross Site Scripting Vulnerabilities Release Date: 2006/07/18 Last Modified: 2006/07/18 Author: Tamriel [tamriel at gmx dot net] Application: hdweGUEST 2.1.1 Risk: Low Vendor Status

Chipmailer = 1.09 Multiple Vulnerabilities

2006-06-13 Thread tamriel
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Advisory: Chipmailer = 1.09 Multiple Vulnerabilities Release Date: 2006/06/13 Last Modified: 2006/06/13 Author: Tamriel [tamriel at gmx dot net] Application: Chipmailer = 1.09 Risk: Medium Vendor Status: no patch