VegaDNS 0.99 suffers from XSS and a SQL injection vulnerability in index.php and users.php
6bee67795628d192c7db5f4ae38f226319d52bfec349b6067b8492bebe38cdc7
This paper presents a modular approach to performing thorough data validation in modern web applications so that the benefits of modular component based design; extensibility, portability and re-use can be released. The paper begins with an explanation of the vulnerabilities introduced through poor validation and then goes on to discuss the merits of a number of common data validation methodologies. A modular approach is introduced together with practical examples of how to implement such a scheme in a web application. It also provides information on common attack vectors, principles of validation, a modular solution and implementation of that solution.
d6ea21e85a8e50b5eb5abc46932d07593292a7f8f5443ced84aadf093a2415ae
Myspace.com - Intricate Script Injection Vulnerability. Includes a very detailed discussion of the vulnerability and the security / insecurity of Myspace in general.
692688d0c4169bb13ccc4016dc5c08950d2bd2ee60dea2a72faf97db2fe437cf
Autogallery v0.41 suffers from multiple XSS vulnerabilities.
8f60a89be9e855d2ddf27a907a6c2c6fd8dffd0a13f8317c2870f044c3735424
AzDGVote suffers from a remote file inclusion vulnerability.
5fe9fcb1b1ad616c7aad90e8fa4ad3129b3943b2df8ec62e4d69fdccc91306ff
Ultr@VNC 1.0.1 Client Buffer Overflow exploit. Spawns an instance of calc.exe.
2fcdc0f17a5a95906e55a96c88e2e56425da544a1bfe0f190964c31c98046b57
Manila versions less than or equal to 9.6 suffer from multiple XSS vulnerabilities.
206977f3295657c91f44b0ab165856d3325758ad6fee4078e10fc2bd36c39507
Confixx 3.1.2 suffers from a SQL injection vulnerability.
a5d4c938f23a007b9d891074dde333fd28af71057b84a4a5619621f179fad0e4
Tritanium Bulletin Board 1.2.3 suffers from XSS.
dfef64553d4a11c3c06bed9689775824f90ed34ca7cf338e13fc75d5314265a8
ZDI-06-007: Microsoft Windows Address Book (WAB) File Format Parsing Vulnerability.
cf55be54a2e2bece030d1ba75d9740572eee53a7708c5c218a80a053aef4ac17
SAXoPRESS suffers from a directory transversal vulnerability, allowing an attacker to read the contents of files on the server.
a2462c3295e432649925f198bb27e6366741793a57802a72f40d991a98dd619d
TUGZip 3.4.0.0, TUGZip 3.3.0.0, and TUGZip 3.1.0.2 do not properly sanitize archives, making it possible to overwrite arbitrary files using a directory transversal attack.
f0e5a68bc738ff61005a14d4347611b5d57d55d11ca02261473863935152eaea
PHPWebGallery 1.4.1 suffers from multiple XSS vulnerabilities.
80ee78e60b6db725b86953cccd6ab94991f3ccb5ea477c39ab4152cbfa5c95f3
phpMyForum 4.0 suffers from XSS and CRLF injection vulnerabilities.
f2549e2c71b3d354dc92b7e5b2f82ba04a6d6a21f2910b387fcc8389f1a8b450
Jbook Guestbook suffers from XSS in index.php
cc5232f78d823542a8ab0e6cbaf97015e886d131a9ea79163ee60b315ffad0ab
If register_globals is on, Sire 2.0 Nws suffers from a remote file inclusion vulnerability.
09b9f5fd33c45fc9142d354995077da4827ea5d5a7fe96e90d48da53759c1c2f
Chipmunk Guestbook suffers from SQL injection that allows for authentication bypass.
393277c7e6a2316592ce852da64df2fc657f7a3e9edf17f2910e151ce525a5aa
SaphpLesson 3.0 suffers from XSS in search.php
506a3845351062983cb38d4cdda7d622262d6830a56d4d4340a20036192a98a1
Clever Copy versions less than or equal to 3.0 allows one of its configuration files to be read remotely, resulting in critical information disclosure. Exploit included.
a4aca55e0dc9e2ab030231b253111a3938a4d6832dccebaf2a3b1c80515c72cd
Cherokee webserver versions less than 0.5.1 allows for XSS in its 400 error message.
55528cc9c26fc9ce6d1a8967aae662bf9b9a6b83bec1825bc5c99957c840c8e9
MAXDEV CMS suffers from full path disclosure and SQL injection vulnerabilities.
05e45818170dbb6231bafc88d0e5951b599caa9ea41e170a90b3329f88a6850d
HPSBUX02111 SSRT061132 rev.1 - HP-UX su(1) Local Unauthorized Access
ff0506cd180ec376306f56145ff96afcc9f66465cd78ce8417f911943b630750
HPSBUX02110 SSRT061110 rev.1 - HP-UX Running wu-ftpd Remote Denial of Service (DoS)
8baeeec24fe07e1ce24aa2a1027d3c3f9f6203cb9f4e8a82c848aa608ba69a82
HPSBUX02108 SSRT061133 rev.3 - HP-UX running Sendmail, Remote Execution of Arbitrary Code.
85ffe8b61e920ac9bfe0a7e89fb5d57b920d3381026795e50d391fe9e6aabbca
Secunia Security Advisory - Data Security has reported a vulnerability in SAXoPRESS, which can be exploited by malicious people to disclose sensitive information.
9d40d18e086168567debfb60b51b40528a90ddaf2e2f083593d8ddc570d94669