| OSVDB ID | Disclosure Date | Title |
|
49663
Description:
(Description Provided by CVE) : Directory traversal vulnerability in the AuthCheck filter in the Admin Console in Openfire 3.6.0a and earlier allows remote attackers to bypass authentication and access the admin interface via a .. (dot dot) in a URI that matches the Exclude-Strings list, as demonstrated by a /setup/setup-/.. sequence in a URI.
|
2008-11-07
|
Openfire AuthCheck Filter URL Traversal Admin Authentication Bypass
|
|
51912
Description:
Openfire SIP Plugin CallLogDAO contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the 'sipark-log-summary.jsp' script not properly sanitizing user-supplied input to the 'type' parameter. This may allow an attacker to inject or manipulate SQL queries in the back-end database.
|
2008-11-07
|
Openfire SIP Plugin CallLogDAO sipark-log-summary.jsp type Parameter SQL Injection
|
|
49861
Description:
(Description Provided by CVE) : Buffer overflow in AKEProtect.sys 3.3.3.0 in ISecSoft Anti-Keylogger Elite 3.3.0 and earlier, and possibly other versions including 3.3.3, allows local users to gain privileges via long inputs to the (1) 0x002224A4, (2) 0x002224C0, and (3) 0x002224CC IOCTL.
|
2008-11-07
|
Anti-Keylogger Elite AKEProtect.sys IOCTL Request Local Overflow
|
|
49862
Description:
(Description Provided by CVE) : Buffer overflow in Atepmon.sys in ISecSoft Anti-Trojan Elite 4.2.1 and earlier, and possibly 4.2.2, allows local users to cause a denial of service (crash) and possibly execute arbitrary code via long inputs to the 0x00222494 IOCTL.
|
2008-11-07
|
Anti-Trojan Elite Atepmon.sys IOCTL Request Local Overflow
|
|
49679
Description:
Mini Web Calendar contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate URL variables upon submission to the 'php/cal_default.php' script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2008-11-07
|
Mini Web Calendar php/cal_default.php URL Parameter XSS
|
|
49754
Description:
TurnkeyForms Local Classifieds contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the 'listtest.php' script not properly sanitizing user-supplied input to the 'r' parameter. This may allow an attacker to inject or manipulate SQL queries in the back-end database.
|
2008-11-07
|
TurnkeyForms Local Classifieds listtest.php r Parameter SQL Injection
|
|
49680
Description:
(Description Provided by CVE) : Directory traversal vulnerability in php/cal_pdf.php in Mini Web Calendar (mwcal) 1.2 allows remote attackers to read arbitrary files via directory traversal sequences in the thefile parameter.
|
2008-11-07
|
Mini Web Calendar php/cal_pdf.php thefile Parameter Traversal Arbitrary File Access
|
|
49991
Description:
(Description Provided by CVE) : Cross-site request forgery (CSRF) vulnerability in cmd.cgi in (1) Nagios 3.0.5 and (2) op5 Monitor before 4.0.1 allows remote attackers to send commands to the Nagios process, and trigger execution of arbitrary programs by this process, via unspecified HTTP requests.
|
2008-11-07
|
Nagios Unspecified CSRF
|
|
49721
Description:
(Description Provided by CVE) : Unspecified vulnerability in the Simba MDrmSap ActiveX control in mdrmsap.dll in SAP SAPgui allows remote attackers to execute arbitrary code via unknown vectors involving instantiation by Internet Explorer.
|
2008-11-07
|
SAP AG SAPgui Simba MDrmSap ActiveX (mdrmsap.dll) Unspecified Arbitrary Code Execution
|
|
49870
Description:
(Description Provided by CVE) : Siemens SpeedStream 5200 with NetPort Software 1.1 allows remote attackers to bypass authentication via an invalid Host header, possibly involving a trailing dot in the hostname.
|
2008-11-07
|
Siemens SpeedStream 5200 HTTP Host Header Request Authentication Bypass
|
|
49994
Description:
(Description Provided by CVE) : Cross-site request forgery (CSRF) vulnerability in cmd.cgi in (1) Nagios 3.0.5 and (2) op5 Monitor before 4.0.1 allows remote attackers to send commands to the Nagios process, and trigger execution of arbitrary programs by this process, via unspecified HTTP requests.
|
2008-11-07
|
op5 Monitor Unspecified CSRF
|
|
50138
Description:
(Description Provided by CVE) : Microsoft SharePoint uses URLs with the same hostname and port number for a web site's primary files and individual users' uploaded files (aka attachments), which allows remote authenticated users to leverage same-origin relationships and conduct cross-site scripting (XSS) attacks by uploading HTML documents.
|
2008-11-07
|
Microsoft SharePoint Host Name / Port Number Persistence HTML Document Same-origin Relationship Bypass XSS
|
|
50704
Description:
Domain Shop contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the 'admin.php' script not properly sanitizing user-supplied input to the 'passfromform' variable. This may allow an attacker to inject or manipulate SQL queries in the back-end database.
|
2008-11-07
|
Domain Shop admin.php passfromform Parameter SQL Injection
|
|
50881
Description:
(Description Provided by CVE) : WordPress 2.6.3 relies on the REQUEST superglobal array in certain dangerous situations, which makes it easier for remote attackers to conduct delayed and persistent cross-site request forgery (CSRF) attacks via crafted cookies, as demonstrated by attacks that (1) delete user accounts or (2) cause a denial of service (loss of application access). NOTE: this issue relies on the presence of an independent vulnerability that allows cookie injection.
|
2008-11-07
|
WordPress REQUEST Superglobal Array Crafted Cookie Handling CSRF
|
|
51087
Description:
(Description Provided by CVE) : Multiple PHP remote file inclusion vulnerabilities in the Clickheat - Heatmap stats (com_clickheat) component 1.0.1 for Joomla! allow remote attackers to execute arbitrary PHP code via a URL in the (1) GLOBALS[mosConfig_absolute_path] parameter to (a) install.clickheat.php, (b) Cache.php and (c) Clickheat_Heatmap.php in Recly/Clickheat/, and (d) Recly/common/GlobalVariables.php; and the (2) mosConfig_absolute_path parameter to (e) _main.php and (f) main.php in includes/heatmap, and (g) includes/overview/main.php.
|
2008-11-07
|
Clickheat - Heatmap Stats Component for Joomla! install.clickheat.php GLOBALS[mosConfig_absolute_path] Parameter Remote File Inclusion
|
|
51088
Description:
(Description Provided by CVE) : Multiple PHP remote file inclusion vulnerabilities in the Clickheat - Heatmap stats (com_clickheat) component 1.0.1 for Joomla! allow remote attackers to execute arbitrary PHP code via a URL in the (1) GLOBALS[mosConfig_absolute_path] parameter to (a) install.clickheat.php, (b) Cache.php and (c) Clickheat_Heatmap.php in Recly/Clickheat/, and (d) Recly/common/GlobalVariables.php; and the (2) mosConfig_absolute_path parameter to (e) _main.php and (f) main.php in includes/heatmap, and (g) includes/overview/main.php.
|
2008-11-07
|
Clickheat - Heatmap Stats Component for Joomla! Cache.php GLOBALS[mosConfig_absolute_path] Parameter Remote File Inclusion
|
|
51089
Description:
(Description Provided by CVE) : Multiple PHP remote file inclusion vulnerabilities in the Clickheat - Heatmap stats (com_clickheat) component 1.0.1 for Joomla! allow remote attackers to execute arbitrary PHP code via a URL in the (1) GLOBALS[mosConfig_absolute_path] parameter to (a) install.clickheat.php, (b) Cache.php and (c) Clickheat_Heatmap.php in Recly/Clickheat/, and (d) Recly/common/GlobalVariables.php; and the (2) mosConfig_absolute_path parameter to (e) _main.php and (f) main.php in includes/heatmap, and (g) includes/overview/main.php.
|
2008-11-07
|
Clickheat - Heatmap Stats Component for Joomla! Clickheat_Heatmap.php GLOBALS[mosConfig_absolute_path] Parameter Remote File Inclusion
|
|
51090
Description:
(Description Provided by CVE) : Multiple PHP remote file inclusion vulnerabilities in the Clickheat - Heatmap stats (com_clickheat) component 1.0.1 for Joomla! allow remote attackers to execute arbitrary PHP code via a URL in the (1) GLOBALS[mosConfig_absolute_path] parameter to (a) install.clickheat.php, (b) Cache.php and (c) Clickheat_Heatmap.php in Recly/Clickheat/, and (d) Recly/common/GlobalVariables.php; and the (2) mosConfig_absolute_path parameter to (e) _main.php and (f) main.php in includes/heatmap, and (g) includes/overview/main.php.
|
2008-11-07
|
Clickheat - Heatmap Stats Component for Joomla! GlobalVariables.php GLOBALS[mosConfig_absolute_path] Parameter Remote File Inclusion
|
|
51091
Description:
(Description Provided by CVE) : Multiple PHP remote file inclusion vulnerabilities in the Clickheat - Heatmap stats (com_clickheat) component 1.0.1 for Joomla! allow remote attackers to execute arbitrary PHP code via a URL in the (1) GLOBALS[mosConfig_absolute_path] parameter to (a) install.clickheat.php, (b) Cache.php and (c) Clickheat_Heatmap.php in Recly/Clickheat/, and (d) Recly/common/GlobalVariables.php; and the (2) mosConfig_absolute_path parameter to (e) _main.php and (f) main.php in includes/heatmap, and (g) includes/overview/main.php.
|
2008-11-07
|
Clickheat - Heatmap Stats Component for Joomla! includes/heatmap/_main.php mosConfig_absolute_path Parameter Remote File Inclusion
|
|
51092
Description:
(Description Provided by CVE) : Multiple PHP remote file inclusion vulnerabilities in the Clickheat - Heatmap stats (com_clickheat) component 1.0.1 for Joomla! allow remote attackers to execute arbitrary PHP code via a URL in the (1) GLOBALS[mosConfig_absolute_path] parameter to (a) install.clickheat.php, (b) Cache.php and (c) Clickheat_Heatmap.php in Recly/Clickheat/, and (d) Recly/common/GlobalVariables.php; and the (2) mosConfig_absolute_path parameter to (e) _main.php and (f) main.php in includes/heatmap, and (g) includes/overview/main.php.
|
2008-11-07
|
Clickheat - Heatmap Stats Component for Joomla! includes/heatmap/main.php mosConfig_absolute_path Parameter Remote File Inclusion
|
|
51093
Description:
(Description Provided by CVE) : Multiple PHP remote file inclusion vulnerabilities in the Clickheat - Heatmap stats (com_clickheat) component 1.0.1 for Joomla! allow remote attackers to execute arbitrary PHP code via a URL in the (1) GLOBALS[mosConfig_absolute_path] parameter to (a) install.clickheat.php, (b) Cache.php and (c) Clickheat_Heatmap.php in Recly/Clickheat/, and (d) Recly/common/GlobalVariables.php; and the (2) mosConfig_absolute_path parameter to (e) _main.php and (f) main.php in includes/heatmap, and (g) includes/overview/main.php.
|
2008-11-07
|
Clickheat - Heatmap Stats Component for Joomla! includes/overview/main.php mosConfig_absolute_path Parameter Remote File Inclusion
|
|
51094
Description:
(Description Provided by CVE) : Multiple PHP remote file inclusion vulnerabilities in the Recly!Competitions (com_competitions) component 1.0 for Joomla! allow remote attackers to execute arbitrary PHP code via a URL in the (1) GLOBALS[mosConfig_absolute_path] parameter to (a) add.php and (b) competitions.php in includes/competitions/, and the (2) mosConfig_absolute_path parameter to (c) includes/settings/settings.php.
|
2008-11-07
|
Recly!Competitions Component for Joomla! add.php GLOBALS[mosConfig_absolute_path] Parameter Remote File Inclusion
|
|
51095
Description:
(Description Provided by CVE) : Multiple PHP remote file inclusion vulnerabilities in the Recly!Competitions (com_competitions) component 1.0 for Joomla! allow remote attackers to execute arbitrary PHP code via a URL in the (1) GLOBALS[mosConfig_absolute_path] parameter to (a) add.php and (b) competitions.php in includes/competitions/, and the (2) mosConfig_absolute_path parameter to (c) includes/settings/settings.php.
|
2008-11-07
|
Recly!Competitions Component for Joomla! competitions.php GLOBALS[mosConfig_absolute_path] Parameter Remote File Inclusion
|
|
51096
Description:
(Description Provided by CVE) : Multiple PHP remote file inclusion vulnerabilities in the Recly!Competitions (com_competitions) component 1.0 for Joomla! allow remote attackers to execute arbitrary PHP code via a URL in the (1) GLOBALS[mosConfig_absolute_path] parameter to (a) add.php and (b) competitions.php in includes/competitions/, and the (2) mosConfig_absolute_path parameter to (c) includes/settings/settings.php.
|
2008-11-07
|
Recly!Competitions Component for Joomla! settings.php mosConfig_absolute_path Parameter Remote File Inclusion
|
|
51097
Description:
(Description Provided by CVE) : Multiple PHP remote file inclusion vulnerabilities in the Recly Interactive Feederator (com_feederator) component 1.0.5 for Joomla! allow remote attackers to execute arbitrary PHP code via a URL in the (1) mosConfig_absolute_path parameter to (a) add_tmsp.php, (b) edit_tmsp.php and (c) tmsp.php in includes/tmsp/; and the (2) GLOBALS[mosConfig_absolute_path] parameter to (d) includes/tmsp/subscription.php.
|
2008-11-07
|
Recly Interactive Feederator Component For Joomla! add_tmsp.php mosConfig_absolute_path Parameter Remote File Inclusion
|
|
51098
Description:
(Description Provided by CVE) : Multiple PHP remote file inclusion vulnerabilities in the Recly Interactive Feederator (com_feederator) component 1.0.5 for Joomla! allow remote attackers to execute arbitrary PHP code via a URL in the (1) mosConfig_absolute_path parameter to (a) add_tmsp.php, (b) edit_tmsp.php and (c) tmsp.php in includes/tmsp/; and the (2) GLOBALS[mosConfig_absolute_path] parameter to (d) includes/tmsp/subscription.php.
|
2008-11-07
|
Recly Interactive Feederator Component For Joomla! edit_tmsp.php mosConfig_absolute_path Parameter Remote File Inclusion
|
|
51099
Description:
(Description Provided by CVE) : Multiple PHP remote file inclusion vulnerabilities in the Recly Interactive Feederator (com_feederator) component 1.0.5 for Joomla! allow remote attackers to execute arbitrary PHP code via a URL in the (1) mosConfig_absolute_path parameter to (a) add_tmsp.php, (b) edit_tmsp.php and (c) tmsp.php in includes/tmsp/; and the (2) GLOBALS[mosConfig_absolute_path] parameter to (d) includes/tmsp/subscription.php.
|
2008-11-07
|
Recly Interactive Feederator Component For Joomla! tmsp.php mosConfig_absolute_path Parameter Remote File Inclusion
|
|
51100
Description:
(Description Provided by CVE) : Multiple PHP remote file inclusion vulnerabilities in the Recly Interactive Feederator (com_feederator) component 1.0.5 for Joomla! allow remote attackers to execute arbitrary PHP code via a URL in the (1) mosConfig_absolute_path parameter to (a) add_tmsp.php, (b) edit_tmsp.php and (c) tmsp.php in includes/tmsp/; and the (2) GLOBALS[mosConfig_absolute_path] parameter to (d) includes/tmsp/subscription.php.
|
2008-11-07
|
Recly Interactive Feederator Component For Joomla! subscription.php GLOBALS[mosConfig_absolute_path] Parameter Remote File Inclusion
|
|
52278
Description:
Slide Popups contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the 'admin/admin.php' script not properly sanitizing user-supplied input to the 'password' parameter. This may allow an attacker to inject or manipulate SQL queries in the back-end database.
|
2008-11-07
|
E-topbiz Slide Popups admin/admin.php password Parameter SQL Injection
|
|
52313
Description:
(Description Provided by CVE) : Cross-site scripting (XSS) vulnerability in listtest.php in TurnkeyForms Local Classifieds allows remote attackers to inject arbitrary web script or HTML via the r parameter.
|
2008-11-07
|
TurnkeyForms Local Clasifieds listtest.php r Parameter XSS
|
|
52902
Description:
(Description Provided by CVE) : Cross-site scripting (XSS) vulnerability in login.jsp in the Admin Console in Openfire 3.6.0a and earlier allows remote attackers to inject arbitrary web script or HTML via the url parameter.
|
2008-11-07
|
Openfire Admin Console login.jsp url Parameter XSS
|
|
53081
Description:
(Description Provided by CVE) : Multiple directory traversal vulnerabilities in e-Vision CMS 2.0.2 and earlier, when magic_quotes_gpc is disabled, allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in (1) an adminlang cookie to admin/ind_ex.php; or the module parameter to (2) 3rdparty/adminpart/add3rdparty.php, (3) polling/adminpart/addpolling.php, (4) contact/adminpart/addcontact.php, (5) brandnews/adminpart/addbrandnews.php, (6) newsletter/adminpart/addnewsletter.php, (7) game/adminpart/addgame.php, (8) tour/adminpart/addtour.php, (9) articles/adminpart/addarticles.php, (10) product/adminpart/addproduct.php, or (11) plain/adminpart/addplain.php in modules/.
|
2008-11-07
|
e-Vision CMS admin/ind_ex.php adminlang Cookie Traversal Local File Inclusion
|
|
53082
Description:
(Description Provided by CVE) : Multiple directory traversal vulnerabilities in e-Vision CMS 2.0.2 and earlier, when magic_quotes_gpc is disabled, allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in (1) an adminlang cookie to admin/ind_ex.php; or the module parameter to (2) 3rdparty/adminpart/add3rdparty.php, (3) polling/adminpart/addpolling.php, (4) contact/adminpart/addcontact.php, (5) brandnews/adminpart/addbrandnews.php, (6) newsletter/adminpart/addnewsletter.php, (7) game/adminpart/addgame.php, (8) tour/adminpart/addtour.php, (9) articles/adminpart/addarticles.php, (10) product/adminpart/addproduct.php, or (11) plain/adminpart/addplain.php in modules/.
|
2008-11-07
|
e-Vision CMS 3rdparty/adminpart/add3rdparty.php module Parameter Traversal Local File Inclusion
|
|
53083
Description:
(Description Provided by CVE) : Multiple directory traversal vulnerabilities in e-Vision CMS 2.0.2 and earlier, when magic_quotes_gpc is disabled, allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in (1) an adminlang cookie to admin/ind_ex.php; or the module parameter to (2) 3rdparty/adminpart/add3rdparty.php, (3) polling/adminpart/addpolling.php, (4) contact/adminpart/addcontact.php, (5) brandnews/adminpart/addbrandnews.php, (6) newsletter/adminpart/addnewsletter.php, (7) game/adminpart/addgame.php, (8) tour/adminpart/addtour.php, (9) articles/adminpart/addarticles.php, (10) product/adminpart/addproduct.php, or (11) plain/adminpart/addplain.php in modules/.
|
2008-11-07
|
e-Vision CMS polling/adminpart/addpolling.php module Parameter Traversal Local File Inclusion
|
|
53084
Description:
(Description Provided by CVE) : Multiple directory traversal vulnerabilities in e-Vision CMS 2.0.2 and earlier, when magic_quotes_gpc is disabled, allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in (1) an adminlang cookie to admin/ind_ex.php; or the module parameter to (2) 3rdparty/adminpart/add3rdparty.php, (3) polling/adminpart/addpolling.php, (4) contact/adminpart/addcontact.php, (5) brandnews/adminpart/addbrandnews.php, (6) newsletter/adminpart/addnewsletter.php, (7) game/adminpart/addgame.php, (8) tour/adminpart/addtour.php, (9) articles/adminpart/addarticles.php, (10) product/adminpart/addproduct.php, or (11) plain/adminpart/addplain.php in modules/.
|
2008-11-07
|
e-Vision CMS contact/adminpart/addcontact.php module Parameter Traversal Local File Inclusion
|
|
53085
Description:
(Description Provided by CVE) : Multiple directory traversal vulnerabilities in e-Vision CMS 2.0.2 and earlier, when magic_quotes_gpc is disabled, allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in (1) an adminlang cookie to admin/ind_ex.php; or the module parameter to (2) 3rdparty/adminpart/add3rdparty.php, (3) polling/adminpart/addpolling.php, (4) contact/adminpart/addcontact.php, (5) brandnews/adminpart/addbrandnews.php, (6) newsletter/adminpart/addnewsletter.php, (7) game/adminpart/addgame.php, (8) tour/adminpart/addtour.php, (9) articles/adminpart/addarticles.php, (10) product/adminpart/addproduct.php, or (11) plain/adminpart/addplain.php in modules/.
|
2008-11-07
|
e-Vision CMS brandnews/adminpart/addbrandnews.php module Parameter Traversal Local File Inclusion
|
|
53086
Description:
(Description Provided by CVE) : Multiple directory traversal vulnerabilities in e-Vision CMS 2.0.2 and earlier, when magic_quotes_gpc is disabled, allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in (1) an adminlang cookie to admin/ind_ex.php; or the module parameter to (2) 3rdparty/adminpart/add3rdparty.php, (3) polling/adminpart/addpolling.php, (4) contact/adminpart/addcontact.php, (5) brandnews/adminpart/addbrandnews.php, (6) newsletter/adminpart/addnewsletter.php, (7) game/adminpart/addgame.php, (8) tour/adminpart/addtour.php, (9) articles/adminpart/addarticles.php, (10) product/adminpart/addproduct.php, or (11) plain/adminpart/addplain.php in modules/.
|
2008-11-07
|
e-Vision CMS newsletter/adminpart/addnewsletter.php module Parameter Traversal Local File Inclusion
|
|
53087
Description:
(Description Provided by CVE) : Multiple directory traversal vulnerabilities in e-Vision CMS 2.0.2 and earlier, when magic_quotes_gpc is disabled, allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in (1) an adminlang cookie to admin/ind_ex.php; or the module parameter to (2) 3rdparty/adminpart/add3rdparty.php, (3) polling/adminpart/addpolling.php, (4) contact/adminpart/addcontact.php, (5) brandnews/adminpart/addbrandnews.php, (6) newsletter/adminpart/addnewsletter.php, (7) game/adminpart/addgame.php, (8) tour/adminpart/addtour.php, (9) articles/adminpart/addarticles.php, (10) product/adminpart/addproduct.php, or (11) plain/adminpart/addplain.php in modules/.
|
2008-11-07
|
e-Vision CMS game/adminpart/addgame.php module Parameter Traversal Local File Inclusion
|
|
53088
Description:
(Description Provided by CVE) : Multiple directory traversal vulnerabilities in e-Vision CMS 2.0.2 and earlier, when magic_quotes_gpc is disabled, allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in (1) an adminlang cookie to admin/ind_ex.php; or the module parameter to (2) 3rdparty/adminpart/add3rdparty.php, (3) polling/adminpart/addpolling.php, (4) contact/adminpart/addcontact.php, (5) brandnews/adminpart/addbrandnews.php, (6) newsletter/adminpart/addnewsletter.php, (7) game/adminpart/addgame.php, (8) tour/adminpart/addtour.php, (9) articles/adminpart/addarticles.php, (10) product/adminpart/addproduct.php, or (11) plain/adminpart/addplain.php in modules/.
|
2008-11-07
|
e-Vision CMS tour/adminpart/addtour.php module Parameter Traversal Local File Inclusion
|
|
53089
Description:
(Description Provided by CVE) : Multiple directory traversal vulnerabilities in e-Vision CMS 2.0.2 and earlier, when magic_quotes_gpc is disabled, allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in (1) an adminlang cookie to admin/ind_ex.php; or the module parameter to (2) 3rdparty/adminpart/add3rdparty.php, (3) polling/adminpart/addpolling.php, (4) contact/adminpart/addcontact.php, (5) brandnews/adminpart/addbrandnews.php, (6) newsletter/adminpart/addnewsletter.php, (7) game/adminpart/addgame.php, (8) tour/adminpart/addtour.php, (9) articles/adminpart/addarticles.php, (10) product/adminpart/addproduct.php, or (11) plain/adminpart/addplain.php in modules/.
|
2008-11-07
|
e-Vision CMS articles/adminpart/addarticles.php module Parameter Traversal Local File Inclusion
|