Mandriva Linux Security Advisory 2010-090 - client/mount.cifs.c in mount.cifs in smbfs in Samba does not verify that the (1) device name and (2) mountpoint strings are composed of valid characters, which allows local users to cause a denial of service (mtab corruption) via a crafted string. client/mount.cifs.c in mount.cifs in smbfs in Samba allows local users to mount a CIFS share on an arbitrary mountpoint, and gain privileges, via a symlink attack on the mountpoint directory file. The updated packages have been patched to correct these issues. It was discovered that the previous Samba update required libtalloc from Samba4 package. Therefore, this update provides the required packages in order to fix the issue.
5d3e9ae410d746e54c09b0cc3c671084391f0edab02e963789588bce134a392e
Fiomental and Coolsis Backoffice suffers from cross site scripting, shell upload and remote SQL injection vulnerabilities.
8135fa39d2e092e67d1b6110335a4dbfe6bbfda4e6f87891ff520ef761c722cd
724CMS version 4.59 suffers from a local file inclusion vulnerability.
7d0bbcd722c62f9b7c777a5bbf2fe00291d57c1b5b47ea327dcd78e289691059
724CMS version 4.59 suffers from a remote SQL injection vulnerability. This is the same vulnerability that also was discovered when 4.01 was the current release.
1f9a17654f70fb172586bc6afad3d13a0e3623da69ee7be0f67c279a0c095dcc
Download and execute shellcode for WinXP SP2 FR.
176023f8ce9165d98ac5be1b9b8f70e05ec99c21e597f1f7cfdf08bb9a49dc18
29o3 CMS suffers from multiple remote file inclusion vulnerabilities.
dbcae1fb15ad5b5c723341c42fc29dd066bcb688e196fe93ef2807ec18f1b518
Drupal version 6.16 with Context 6.x-2.0-rc3 suffers from a cross site scripting vulnerability.
60da3e51c76210519e7e81f11c5f70fbb360bdfc9c1cc11b08f832b7508a79c7
Tekno Portal version 0.1b suffers from a remote SQL injection vulnerability in makale.php.
ef3651933187e17a5562b3a892514f4e901a256d2d38051c16e3a0ca9378d051
OrangeHRM version 2.5.0.4 suffers from php code injection, cross site request forgery, cross site scripting and remote SQL injection vulnerabilities.
ff47cc81bc380e6b7df1cddb5ba45a72534f65bc141e04718067b6e3c0fdada2
Family Connections version 2.2.3 suffers from remote SQL and SNMP injection vulnerabilities.
e9c88ca4aa9dc46416401c8edce3be47f38c372ee599f367a671f6a24f46c477
Dark Portal suffers from a remote file inclusion vulnerability.
50f8d1632c4c8de2897def8a1dfe0765b2df8b68e1103e01878814868f327b28
Platnik version 08.01.001 suffers from a remote SQL injection vulnerability.
8bf4cf446c1a2a75fc93dd63984a25ba00228dd7b284429074378cb2735b8031
PHPKB Knowledge Base Software version 2 with multilanguage support suffers from a remote SQL injection vulnerability.
c73646493e3af23711a145610a8a86fee8ee66c42a3988177e65f76655e7921d
Xplico is an open source Network Forensic Analysis Tool (NFAT) that allows for data extraction from traffic captures. It supports extraction of mail from POP, IMAP, and SMTP, can extract VoIP streams, etc. This is the version that has a GUI allowing you to view photos, texts and videos contained in MMS messages.
12d1f3f07bb25e1e6ecedc78701debec16990a61fbe6ae2031f65891235e796d
Advanced Poll version 2.08 suffers from a cross site scripting vulnerability.
41e9eeb3b2d27c27b3b2b67eb3679909fd5fcd0f3a9f6a34d4f499ff3b4d534c
EasyPublish CMS suffers from a cross site scripting vulnerability.
67098e0b9d61e2c98f67c7af02d29876b3619aa4ff78ded44d2750c695c214a2
Xitami version 5.0a0 remote denial of service exploit.
11fd43d97a67c4cc99f55bc801ac2855980b31e3f58d6e5d0f0a8cd7102d847b
Waibrasil suffers from local file inclusion and remote file inclusion vulnerabilities.
9e43f9f6fa51d9e40ad50d774c77c81b894dab1b3cc654a64296c54611e55338
Mereo version 1.9.1 suffers from a directory traversal vulnerability.
c967a77416f79e2b9adb0daaf2d6f2b57d90a80406563360f7689eaac24692cb
Netvidade Engine version 1.0 suffers from multiple remote SQL injection vulnerabilities.
06f27151d45094b46c13a82901e8ef6fdeea3ebd8e555e388fd4efc28ab7f780
Spaceacre suffers from a remote SQL injection vulnerability.
0a21f3c5aeeab52c67b31fb7d74926965e9fd6d720c67969ebbb38e737290801
phpscripte24 Shop System SQL Injection remote SQL injection exploit.
5932640370875869a2aa4be6676f0a447cf8a9fbfdfcc5b02cb90544c67471db
phpscripte24 Live Shopping Multi Portal System remote SQL injection exploit.
38c4d3ea30e3505ef5e546ae7fa62f0ace2da89b76798e7aede03eff0e48be15
Alibaba Clone Diamond remote SQL injection exploit.
8af1bede6a6ba80fce96edadc59a7edcf2656c332255b0aa33efdee0b36fc1fa
Alibaba Clone versions 3.0 and below remote SQL injection exploit.
e13a7896a07761e2464a076893ee0f8205fbff111eb7266e17fbeb95f28fc4cf