Packet Storm Security Last 100100 Most Recent Packet Storm File Additionsitechbids-sqlxss.txt- (Found July 15, 2008 ) ITechBids version 7.0 Gold suffers from cross site scripting and SQL injection vulnerabilities.http://packetstormsecurity.org/0807-exploits/itechbids-sqlxss.txt pluck-lfi.txt- (Found July 15, 2008 ) Pluck version 4.5.1 suffers from a local file inclusion vulnerability.http://packetstormsecurity.org/0807-exploits/pluck-lfi.txt deepsec2008-cfp.txt- (Found July 15, 2008 ) The Call For Papers for DeepSec IDSC 2008 ends tomorrow. Get your submission in today!http://packetstormsecurity.org/papers/call_for/deepsec2008-cfp.txt FreeBSD-SA-08.06.bind.txt- (Found July 15, 2008 ) FreeBSD Security Advisory - The BIND DNS implementation does not randomize the UDP source port when doing remote queries, and the query id alone does not provide adequate randomization.http://packetstormsecurity.org/0807-advisories/FreeBSD-SA-08.06.bind.txt ultrastats-blindsql.txt- (Found July 15, 2008 ) Ultrastats versions 0.2.142 and below remote blind SQL injection exploit that makes use of players-detail.php.http://packetstormsecurity.org/0807-exploits/ultrastats-blindsql.txt webcms-sql.txt- (Found July 15, 2008 ) WebCMS Portal suffers from a remote SQL injection vulnerability.http://packetstormsecurity.org/0807-exploits/webcms-sql.txt joomlanforms-sql.txt- (Found July 15, 2008 ) Joomla n-forms component version 1.01 blind SQL injection exploit.http://packetstormsecurity.org/0807-exploits/joomlanforms-sql.txt glsa-200807-08.txt- (Found July 15, 2008 ) Gentoo Linux Security Advisory GLSA 200807-08 - Dan Kaminsky of IOActive has reported a weakness in the DNS protocol related to insufficient randomness of DNS transaction IDs and query source ports. Versions less than 9.4.2_p1 are affected.http://packetstormsecurity.org/0807-advisories/glsa-200807-08.txt dsa-1607-1.txt- (Found July 15, 2008 ) Debian Security Advisory 1607-1 - Several remote vulnerabilities have been discovered in the Iceweasel webbrowser, an unbranded version of the Firefox browser.http://packetstormsecurity.org/0807-advisories/dsa-1607-1.txt NETRAGARD-20070628.txt- (Found July 15, 2008 ) Netragard, L.L.C Advisory - Core Image Fun House versions 2.0 and below for OS X suffer from a buffer overflow vulnerability when a specially crafted .funhouse file is leveraged. Proof of concept code included.http://packetstormsecurity.org/0807-exploits/NETRAGARD-20070628.txt |