Packet Storm new exploits for June, 2007.
b9db658141ad8817fcc87254542e683536444a6a5e29b100aab415c055808734
WheatBlog version 1.1 suffers from remote file inclusion and SQL injection vulnerabilities.
8e54fa6392e6f75205e7892c47600d9143739b7a26aa1230252f38e05d77f445
Buddy Zone version 1.5 suffers from a SQL injection vulnerability in view_sub_cat.php.
46248338405a840e68c93c69b7812960ba60ec782ddeb7f51f5c5c2e49edff4b
W3Filer version 2.1.3 remote stack overflow denial of service exploit.
330b528f872715332a2cc6f949e7f74e70269110ebb93d32a06d33af9aed035b
YouTube.com suffers from an age verification bypass vulnerability.
6c46137e23d311b95b370bbd8c261d175070d1384e0bff9c9b4b7c1463c5f094
VBZooM version 1.12 suffers from a SQL injection vulnerability.
b69ad7fbc699a9fed02fb26f9aead6b90284d1e389cd322a6c2434a9ddb6b812
XEForum suffers from a privilege escalation vulnerability via cookie modification.
9a75d656d5f3dff13562550554751fe24e857821970ec4e1ab63eb54fa7b8259
AMX Corp. VNC ActiveX control remote buffer overflow exploit that takes advantage of AmxVnc.dll version 1.0.13.0.
3e4b4e7e49614651ed8f8e25252d24cf8f65c7c0d33be9a44650128ae52249ce
WebChat version 0.78 suffers from a remote SQL injection vulnerability in login.php.
f9c0c2ae4469d42a69bf90751a7d343a58078a269d724bc6090f07149ced2a7c
GL-SH Deaf Forum versions 6.4.4 and below suffer from local file inclusion vulnerabilities.
ce7da4504462593985b0ed7a743e1e0699af70e3481fa8c1424155e9db9ef2fc
b1gbb version 2.24.0 suffers from SQL injection and cross site scripting vulnerabilities.
4b45467a1c35d6e0869e86f4c71491f23b0b2e6233da19f123d739e90210b687
eTicket version 1.5.5 suffers from a cross site scripting vulnerability.
3176f8061bb7ca7776fadc5667c4926d7b1c4fcf71a547e81112eacaed92f82a
Conti FTP server version 1.0 remote denial of service exploit.
ddff10bf2fa8147ea039c700a80ab1c5fe40007191288a4cce22deb9d0136dc7
Checkpoint VPN-1 UTM Edge suffers from a cross site request forgery vulnerability. Proof of concept included.
a3f09b1de8fc13110d56e12718c75492ea421af6481e32ffefd5cc94a58fc4bb
hpqxml.dll version 2.0.0.133 from the HP Photo Digital Imaging software package has a flaw that allows for arbitrary file overwrite on the underlying system.
d5ed8c3f7dc685ae2d44fdc333686f1a4233c2473a12d3a6228b16977266b09b
QuickTicket version 1.2 suffers from a local file inclusion vulnerability in qti_checkname.php.
71544a547a68d6a05fbf7e16cb9e1f8f5a8727924b0b7b3cc17fb1621087b31a
QuickTalk forum version 1.3 suffers from local file inclusion vulnerabilities.
5068c4cd8d68ec79194cf3bcbbf8697e40574eeb0fa6c4127c8a3b865ccc8a07
Sony Network Camera SNC-P5 version 1.0 ActiveX viewer heap overflow proof of concept denial of service exploit.
2848e6b5ecb0750e5005ec474e44c950ef5b91decc2778a0e20de5d37482ca14
RealNetworks RealPlayer/Helix Player SMIL wallclock stack overflow proof of concept denial of service exploit.
68e14478e4f096f8efadeb0d94891a14ff8995292a98f99547bb534907b4ee37
eNdonesia version 8.4 suffers from a SQL injection vulnerability.
39adbd09c3de049026347d06dcda7c3dd848119e60eabdf6004f1b254c5c1ddd
Avaxswf.dll, a library included in the Avax Vector ActiveX version 1.3 software package from the Company Civitech, has a flaw that allows for arbitrary file overwrite on the underlying system.
4ca55d3c8f70a52a5379bf51316724a294795bf8c806940932fe86568b7aca3a
NCTAudioEditor2 ActiveX DLL NCTWMAFile2.dll version 2.6.2.157 exploit.
28a728208a8f4004c82fff2c6ff50e58377091a3c0e399bc41dfb3662e338c47
NCTAudioStudio2 ActiveX DLL version 2.6.1.148 CreateFile() insecure method exploit.
641ca86b050b1f939e4516b7263fb460927024d0e291ff0eabbbbbf258573c45
WordPress version 2.2 arbitrary file upload exploit that makes use of wp-app.php.
e3615ba509c5134cf8c8ab046f0939498ecebfe904efdf37d2c908beacd8ee87
EVA-Web versions 1.1 through 2.2 suffer from a remote file inclusion vulnerability in index.php3.
15b51c2ca20967dfed1be0d23d5e9378dde61d5d32bfe061a3caa442b6c2038a