Alerts from SecurityFocus Newsletter #359
APPLICATIONS USING PHP
- Plesk Control Panel File_Manager.PHP Cross-Site Scripting Vulnerability
- LoudMouth Module For Mambo ABBC.Class.PHP Remote File Include Vulnerability
- ExtCalendar For Mambo ExtCalendar.php Remote File Include Vulnerability
- Calendar Module For Mambo Com_Calendar.PHP Remote File Include Vulnerability
- Pollxt Module For Mambo Conf.Pollxt.PHP Remote File Include Vulnerability
- VideoDB Component Module For Mambo Xml_Domit_Lite_Include.PHP Remote File Include Vulnerability
- HTMLArea3 Addon For Mambo Config.Inc.PHP Remote File Include Vulnerability
- PHPBB 3 Memberlist.PHP SQL Injection Vulnerability
- Sitemap Sitemap.XML.PHP Remote File Include Vulnerability
- Subberz Lite UserFunc Remote File Include Vulnerability
- FlushCMS Class.Rich.PHP Remote File Include Vulnerability
- Francisco Charrua Photo-Gallery Room.PHP SQL Injection Vulnerability
- Invision Power Board IPSClass.PHP SQL Injection Vulnerability
- Professional Home Page Tools Guestbook Multiple SQL Injection Vulnerabilities
- Zoho Virtual Office Message HTML Injection Vulnerability
- ListMessenger LM_Path Parameter Remote File Include Vulnerability
- IceWarp Web Mail Multiple File Include Vulnerabilities
- Eskolar CMS Multiple SQL Injection Vulnerabilities
- Mail2Forum Multiple Remote File Include Vulnerabilities
- OSDate Multiple HTML Injection Vulnerabilities
- MiniBB Multiple Remote File Include Vulnerabilities
- MyBB Client-IP SQL Injection Vulnerability
RELATED STUFF
- MySQL Server Date_Format Denial Of Service Vulnerability
Fixed in versions 4.1.18, 5.0.19, and 5.1.6.
