Thinking OPEN

Contributor Archive

Php Dir Submit [Medium]

By Security Team • Nov 18th, 2009 • Category: Security Notifications

SQL injection vulnerability in index.php in PHP Dir Submit (aka WebsiteSubmitter or Submitter Script) allows remote authenticated users to execute arbitrary SQL commands via the aid parameter in a showarticle action….

CVE Identifier: CVE-2009-3970
Vulnerability Type(s):
Severity: Medium



Faslo Player 7.0 [High]

By Security Team • Nov 18th, 2009 • Category: Security Notifications

Stack-based buffer overflow in Faslo Player 7.0 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a long string in a .m3u playlist file….

CVE Identifier: CVE-2009-3969
Vulnerability Type(s):
Severity: High



Itechbids 8.0 [High]

By Security Team • Nov 18th, 2009 • Category: Security Notifications

Multiple SQL injection vulnerabilities in ITechBids 8.0 allow remote attackers to execute arbitrary SQL commands via the (1) user_id parameter to feedback.php, (2) cate_id parameter to category.php, (3) id parameter to news.php, and (4) productid parameter to itechd.php…

CVE Identifier: CVE-2009-3968
Vulnerability Type(s):
Severity: High



Supercharged Linking [High]

By Security Team • Nov 18th, 2009 • Category: Security Notifications

SQL injection vulnerability in browse.php in Ed Charkow SuperCharged Linking allows remote attackers to execute arbitrary SQL commands via the id parameter….

CVE Identifier: CVE-2009-3967
Vulnerability Type(s):
Severity: High



Arcade Trade Script 1.0 [High]

By Security Team • Nov 18th, 2009 • Category: Security Notifications

Arcade Trade Script 1.0 allows remote attackers to bypass authentication and gain administrative access by setting the adminLoggedIn cookie to true….

CVE Identifier: CVE-2009-3966
Vulnerability Type(s):
Severity: High



New5starrating 1.0 [High]

By Security Team • Nov 18th, 2009 • Category: Security Notifications

SQL injection vulnerability in rating.php in New 5 star Rating 1.0 allows remote attackers to execute arbitrary SQL commands via the det parameter….

CVE Identifier: CVE-2009-3965
Vulnerability Type(s):
Severity: High



Joomla%21 1.1.0 and prior [High]

By Security Team • Nov 18th, 2009 • Category: Security Notifications

SQL injection vulnerability in the NinjaMonials (com_ninjacentral) component 1.1.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the testimID parameter in a display action to index.php….

CVE Identifier: CVE-2009-3964
Vulnerability Type(s):
Severity: High



Xoops 2.3.2a and prior [High]

By Security Team • Nov 17th, 2009 • Category: Security Notifications

Multiple unspecified vulnerabilities in XOOPS before 2.4.0 Final have unknown impact and attack vectors….

CVE Identifier: CVE-2009-3963
Vulnerability Type(s):
Severity: High



1700hg 5.29.51 and prior [High]

By Security Team • Nov 17th, 2009 • Category: Security Notifications

The management interface on the 2wire Gateway 1700HG, 1701HG, 1800HW, 2071, 2700HG, and 2701HG-T with software before 5.29.52 allows remote attackers to cause a denial of service (reboot) via a %0d%0a sequence in the page parameter to the xslt program on TCP port 50001, a related issue to CVE-2006-4523….

CVE Identifier: CVE-2009-3962
Vulnerability Type(s):
Severity: High



Superseriousstats 1.1.2 and prior [High]

By Security Team • Nov 17th, 2009 • Category: Security Notifications

SQL injection vulnerability in user.php in Super Serious Stats (aka superseriousstats) before 1.1.2p1 allows remote attackers to execute arbitrary SQL commands via the uid parameter, related to an “incorrect regexp.” NOTE: some of these details are obtained from third party information….

CVE Identifier: CVE-2009-3961
Vulnerability Type(s):
Severity: High