This advisory covers nine of the 23 vulnerabilities recently discovered in various versions of Oracle's database server.
05f58b02101062b1f57e0de5e3166ee29294c50e446a28ff4adfd2aaf99ca936
ViewCVS 0.9.2 is susceptible to cross site scripting and HTTP-response splitting flaws.
23164ad29a94dbb57e8ead3fcbc782400756468d8bf6a6c9bd963df7fb07b740
Cross site scripting and possible code execution vulnerabilities exists in SugarCRM versions 1.x.
582ee763024b5b87ca36814363d1819db4fc7309d863de9fa83ef364b76a07a7
OWL versions 0.7 and 0.8 suffer from cross site scripting and SQL injection vulnerabilities.
af9b35a1487e1076df74597581b6cd866b62c29c7a8b93bc66356aebfd04c86a
The PHP application WebCalendar is susceptible to cross site scripting, http response splitting, code execution, path disclosure, and privilege escalation vulnerabilities.
04d765060243653b3a30ecc05d58fd77ebd4ed9f01c79850ecc9c7a6106b048f
Open WorkFlow Engine version 1.4.x allows for cross site scripting attacks and to be used as a port scanner.
2f7420d7b6d05ffc8c77381aed04c7f24293e98ae186923febe58d817ec42501
Mambo versions 4.5 and below are susceptible to cross site scripting and remote command execution flaws.
f1adb6277c56b90345f1a0481e0f3f0ec78fce087033de3e0c2aa3b0ec129889
TUTOS 1.1 is susceptible to SQL injection and cross site scripting attacks.
f129e4fcfb3dcf070e7d8891ee5347a3f9ad30e61a026d6d217fe73f40a01787
phpScheduleIt 1.0.0 RC1 is susceptible to cross site scripting attacks.
83d7e1638d1df1c6ee19950e9c9c58fc8c1621aa46d9ded173e8d2257a5825eb
eGroupWare version 1.0.0.003 is susceptible to a cross site scripting flaw.
2857363dac9c43f2774402925a849c4b3610100a22158155e0488e996121c3ff
Sympa versions 4.1.x and below are susceptible to cross site scripting attacks.
dca5ea288d664feb25de06ceaa5845417be3a151f5960a1b08d989b0f6436781
Mantis suffers from a remote PHP code execution vulnerability when the REGISTER_GLOBAL variable is set.
a70413a0d6384063116146614076f527699b5ef8da05f1e7d3c3af253afadf40
MyDNS is susceptible to a SQL injection and directory traversal attack that allows for arbitrary file download. Version 1.4.2 fixes the SQL injection bug while the other bug is in all releases.
c36816d86fbea1b951d53fd79107db3a521ddd12c0f07d1c786aac6deabbedd6
Mantis is susceptible to multiple cross site scripting vulnerabilities.
a6f58dd97966c39ee1d173207fb0d4d25219702ee1bad263cc675e5318ce6bef