PhpAdvisories
Latest security advisories about php applications
Bugtraq: Re: Aztek Forum 4.1 Multiple Vulnerabilities Exploit
- Source : SecurityFocus Vuln Link : http://www.securityfocus.com/archive/1/458123 Hits : 2
RPW "sql_language" Parameter Handling Remote PHP File Inclusion Vulnerability
- Source : frSIRT (WDM) Link : http://www.frsirt.com/english/advisories/2007/0342 Hits : 2
Inter7 vHostAdmin "MODULES_DIR" Parameter Remote PHP File Inclusion Vulnerability
- Source : frSIRT (WDM) Link : http://www.frsirt.com/english/advisories/2007/0339 Hits : 2
Xero Portal "phpbb_root_path" Parameter Multiple Remote File Inclusion Vulnerabilities
- Source : frSIRT (WDM) Link : http://www.frsirt.com/english/advisories/2007/0338 Hits : 2
[2/5 Drupal Project Issue Tracking Module Multiple Vulnerabilities]
- Source : Secunia rss Link : http://secunia.com/advisories/23887/ Hits : 2
PHProxy Multiple Parameter Handling Client-Side Cross Site Scripting Vulnerabilities
- Source : frSIRT (WDM) Link : http://www.frsirt.com/english/advisories/2007/0348 Hits : 2
[2/5 MyBB private.php Cross-Site Request Forgery and Cross-Site Scripting]
- Source : Secunia rss Link : http://secunia.com/advisories/23934/ Hits : 2
[2/5 DokuWiki "media" CRLF Injection Vulnerability]
- Source : Secunia rss Link : http://secunia.com/advisories/23926/ Hits : 2
FreeWebshop Include File Bug in '/includes/login.php' Lets Remote Users Execute Arbitrary Code
- Source : SecurityTracker Link : http://www.SecurityTracker.com/alerts/2007/Jan/1017549.html Hits : 2
Bugtraq: [Aria-Security Team MyBB Cross-Site Scripting]
- Source : SecurityFocus Vuln Link : http://www.securityfocus.com/archive/1/457929 Hits : 2
[4/5 phpXMLDOM "path" File Inclusion Vulnerabilities]
- Source : Secunia rss Link : http://secunia.com/advisories/23875/ Hits : 2
[2/5 Drupal Acidfree Module "node titles" SQL Injection Vulnerability]
- Source : Secunia rss Link : http://secunia.com/advisories/23895/ Hits : 2
[3/5 PHP Link Directory "URL" Script Insertion Vulnerability]
- Source : Secunia rss Link : http://secunia.com/advisories/23860/ Hits : 2
phpXD "path" Parameter Handling Multiple Remote PHP File Inclusion Vulnerabilities
- Source : frSIRT (WDM) Link : http://www.frsirt.com/english/advisories/2007/0309 Hits : 2
Project and Project Issue Tracking for Drupal Multiple Security Bypass Vulnerabilities
- Source : frSIRT (WDM) Link : http://www.frsirt.com/english/advisories/2007/0312 Hits : 2
Openads "admin-search.php" and "affiliate-search.php" Cross Site Scripting Issues
- Source : frSIRT (WDM) Link : http://www.frsirt.com/english/advisories/2007/0315 Hits : 2
Vote! Pro "poll_id" Parameter Handling Remote PHP Code Injection Vulnerability
- Source : frSIRT (WDM) Link : http://www.frsirt.com/english/advisories/2007/0300 Hits : 2
Website Baker "is_remembered()" Cookie Handling Remote SQL Injection Vulnerability
- Source : frSIRT (WDM) Link : http://www.frsirt.com/english/advisories/2007/0311 Hits : 3
Acidfree Module for Drupal Node Title Handling Remote SQL Injection Vulnerability
- Source : frSIRT (WDM) Link : http://www.frsirt.com/english/advisories/2007/0313 Hits : 2
[3/5 Random PHP Quote pwd.txt Password Disclosure]
- Source : Secunia rss Link : http://secunia.com/advisories/23888/ Hits : 2
Bugtraq: RANDOM PHP QUOTE 1.0 (pwd.txt) Remote Password Disclosur
- Source : SecurityFocus Vuln Link : http://www.securityfocus.com/archive/1/457825 Hits : 2
[2/5 PostNuke "cover" Cross-Site Scripting Vulnerability]
- Source : Secunia rss Link : http://secunia.com/advisories/23849/ Hits : 22
Bugtraq: Re: FishCart [injection sql] * Source : SecurityFocus Vuln Link : http://www.securityfocus.com/archive/1/457704 Hits : 21 Bugtraq: SQL Injection by using Cookie Poisoning for Website Baker Version 2.6.5 and before
- Source : SecurityFocus Vuln Link : http://www.securityfocus.com/archive/1/457684 Hits : 19
webSPELL "gallery.php" Multiple Parameter Handling Remote SQL Injection Vulnerabilities
- Source : frSIRT (WDM) Link : http://www.frsirt.com/english/advisories/2007/0270 Hits : 13
ComVironment "inc_dir" Parameter Handling Remote PHP File Inclusion Vulnerability
- Source : frSIRT (WDM) Link : http://www.frsirt.com/english/advisories/2007/0266 Hits : 14
MySpeach "my_ms[root" Parameter Handling Remote PHP File Inclusion Vulnerability]
- Source : frSIRT (WDM) Link : http://www.frsirt.com/english/advisories/2007/0269 Hits : 15
Upload-Service "maindir" Parameter Handling Remote PHP File Inclusion Vulnerability
- Source : frSIRT (WDM) Link : http://www.frsirt.com/english/advisories/2007/0265 Hits : 15
phpIndexPage "env[inc_path" Parameter Handling Remote File Inclusion Vulnerability]
- Source : frSIRT (WDM) Link : http://www.frsirt.com/english/advisories/2007/0267 Hits : 13
Bugtraq: FishCart [injection sql]
- Source : SecurityFocus Vuln Link : http://www.securityfocus.com/archive/1/457618 Hits : 14
[4/5 MySpeach "up.php" File Inclusion Vulnerability]
- Source : Secunia rss Link : http://secunia.com/advisories/23850/ Hits : 13
Bradabra "include_path" Parameter Handling Remote PHP File Inclusion Vulnerability
- Source : frSIRT (WDM) Link : http://www.frsirt.com/english/advisories/2007/0264 Hits : 12
PhpSherpa "racine" Parameter Handling Remote PHP File Inclusion Vulnerability
- Source : frSIRT (WDM) Link : http://www.frsirt.com/english/advisories/2007/0263 Hits : 13
[4/5 PhpSherpa "racine" File Inclusion Vulnerability]
- Source : Secunia rss Link : http://secunia.com/advisories/23817/ Hits : 11
Bugtraq: SMF "index.php?action=pm" Cross Site-Scripting
- Source : SecurityFocus Vuln Link : http://www.securityfocus.com/archive/1/457508 Hits : 14
Vuln: MGB Email.PHP SQL Injection Vulnerability
- Source : SecurityFocus Vuln Link : http://www.securityfocus.com/bid/22094 Hits : 60
Vuln: VirtueMart Joomla ECommerce Edition Multiple Unspecified Input Validation Vulnerabilities
- Source : SecurityFocus Vuln Link : http://www.securityfocus.com/bid/22123 Hits : 37
Vuln: Joomla CMS Multiple SQL Injection Vulnerabilities
- Source : SecurityFocus Vuln Link : http://www.securityfocus.com/bid/22122 Hits : 48
myWebland myBloggie "PHP_SELF" Variable Handling Cross Site Scripting Vulnerabilities
- Source : frSIRT (WDM) Link : http://www.frsirt.com/english/advisories/2007/0243 Hits : 41
MyBloggie Input Validation Flaws in 'index.php' and 'login.php' Permit Cross-Site Scripting Attacks
- Source : SecurityTracker Link : http://www.SecurityTracker.com/alerts/2007/Jan/1017531.html Hits : 37
[2/5 myBloggie Two Cross-Site Scripting Vulnerabilities]
- Source : Secunia rss Link : http://secunia.com/advisories/23818/ Hits : 35
Oreon "file" Parameter Handling Remote PHP File Inclusion Vulnerability
- Source : frSIRT (WDM) Link : http://www.frsirt.com/english/advisories/2007/0229 Hits : 38
PHPMyphorum "chem" Parameter Handling Remote PHP File Inclusion Vulnerability
- Source : frSIRT (WDM) Link : http://www.frsirt.com/english/advisories/2007/0231 Hits : 38
Bugtraq: [x0n3-h4ck myBloggie 2.1.5 XSS exploit]
- Source : SecurityFocus Vuln Link : http://www.securityfocus.com/archive/1/457206 Hits : 36
Indexu Multiple Parameter Handling Client-Side Cross Site Scripting Vulnerabilities
- Source : frSIRT (WDM) Link : http://www.frsirt.com/english/advisories/2007/0222 Hits : 34
[2/5 Indexu Multiple Cross-Site Scripting Vulnerabilities]
- Source : Secunia rss Link : http://secunia.com/advisories/23764/ Hits : 34
[3/5 PHP-Nuke "cat" Old Articles Block SQL Injection]
- Source : Secunia rss Link : http://secunia.com/advisories/23748/ Hits : 36
[3/5 ThWboard "board[styleid]" SQL Injection Vulnerability]
- Source : Secunia rss Link : http://secunia.com/advisories/23735/ Hits : 31
Bugtraq: PHPATM Remote Password Disclosure Vulnerablity
- Source : SecurityFocus Vuln Link : http://www.securityfocus.com/archive/1/457052 Hits : 31
Bugtraq: Gallery <= 1.4.4-pl4 (phpbb_root_path) Remote File Include Vulnerability
- Source : SecurityFocus Vuln Link : http://www.securityfocus.com/archive/1/457048 Hits : 33
Vuln: WordPress Charset Decoding SQL Injection Vulnerability
- Source : SecurityFocus Vuln Link : http://www.securityfocus.com/bid/21907 Hits : 28
PHP-Nuke Input Validation Flaw in 'block-Old_Articles.php' Lets Remote Users Inject SQL Commands
- Source : SecurityTracker Link : http://www.SecurityTracker.com/alerts/2007/Jan/1017511.html Hits : 29
Vuln: Jshop Server Remote File Include Vulnerability
- Source : SecurityFocus Vuln Link : http://www.securityfocus.com/bid/21995 Hits : 27
[4/5 LunarPoll "PollDir" File Inclusion Vulnerability]
- Source : Secunia rss Link : http://secunia.com/advisories/23760/ Hits : 25
[4/5 sNews Authentication Bypass Vulnerability]
- Source : Secunia rss Link : http://secunia.com/advisories/23746/ Hits : 28
LunarPoll "PollDir" Parameter Handling Remote PHP File Inclusion Vulnerability
- Source : frSIRT (WDM) Link : http://www.frsirt.com/english/advisories/2007/0177 Hits : 62
TLM CMS "chemin" Parameter Handling Remote PHP File Inclusion Vulnerability
- Source : frSIRT (WDM) Link : http://www.frsirt.com/english/advisories/2007/0176 Hits : 69
Bugtraq: PHP-Nuke <= 7.9 Old-Articles Block "cat" SQL Injection vulnerability
- Source : SecurityFocus Vuln Link : http://www.securityfocus.com/archive/1/456787 Hits : 70
LunarPoll Include File Bug in 'show.php' Lets Remote Users Execute Arbitrary Code
- Source : SecurityTracker Link : http://www.SecurityTracker.com/alerts/2007/Jan/1017510.html Hits : 44
Vuln: PHPMyAdmin Convcharset Cross-Site Scripting Vulnerability
- Source : SecurityFocus Vuln Link : http://www.securityfocus.com/bid/12982 Hits : 55
Edit-X ECOMMERCE "include_dir" Parameter Remote PHP File Inclusion Vulnerability
- Source : frSIRT (WDM) Link : http://www.frsirt.com/english/advisories/2007/0158 Hits : 40
Bugtraq: xss in phpmyadmin <= 2.8.1
- Source : SecurityFocus Vuln Link : http://www.securityfocus.com/archive/1/456698 Hits : 54
@lex Guestbook "lang" Parameter Handling Remote SQL Query Injection Vulnerability
- Source : frSIRT (WDM) Link : http://www.frsirt.com/english/advisories/2007/0137 Hits : 46
Magic Photo Storage "_config[site_path" Parameter Remote File Inclusion Vulnerability]
- Source : frSIRT (WDM) Link : http://www.frsirt.com/english/advisories/2007/0136 Hits : 44
[4/5 Axiom Photo/News Gallery "baseAxiomPath" File Inclusion Vulnerability]
- Source : Secunia rss Link : http://secunia.com/advisories/23715/ Hits : 44
phpMyAdmin Unspecified Parameter Handling Client-Side Cross Site Scripting Vulnerabilities
- Source : frSIRT (WDM) Link : http://www.frsirt.com/english/advisories/2007/0125 Hits : 48
Vuln: PHPKit Comment.PHP SQL Injection Vulnerability
- Source : SecurityFocus Vuln Link : http://www.securityfocus.com/bid/21962 Hits : 48
[3/5 @lex Guestbook "lang" SQL Injection Vulnerability]
- Source : Secunia rss Link : http://secunia.com/advisories/23637/ Hits : 43
[2/5 phpMyAdmin Cross-Site Scripting and Unspecified Vulnerabilities]
- Source : Secunia rss Link : http://secunia.com/advisories/23702/ Hits : 44
Axiom Photo Gallery "baseAxiomPath" Parameter Remote File Inclusion Vulnerability
- Source : frSIRT (WDM) Link : http://www.frsirt.com/english/advisories/2007/0107 Hits : 42
MediaWiki AJAX Module Unspecified Parameter Handling Cross Site Scripting Vulnerability
- Source : frSIRT (WDM) Link : http://www.frsirt.com/english/advisories/2007/0096 Hits : 43
GForge Input Validation Hole in 'advanced_search.php' Permits Cross-Site Scripting Attacks
- Source : SecurityTracker Link : http://www.SecurityTracker.com/alerts/2007/Jan/1017482.html Hits : 42
[2/5 GForge "advanced_search.php" Cross-Site Scripting Vulnerability]
- Source : Secunia rss Link : http://secunia.com/advisories/23675/ Hits : 44
[2/5 MediaWiki AJAX Unspecified Cross-Site Scripting]
- Source : Secunia rss Link : http://secunia.com/advisories/23647/ Hits : 43
[1/5 b2evolution "redirect_to" HTML Attribute Cross-Site Scripting]
- Source : Secunia rss Link : http://secunia.com/advisories/23656/ Hits : 42
Webdrivers Simple Forum message_details.php id Variable SQL Injection
- Source : OSVDB (WDM) Link : http://www.osvdb.org/displayvuln.php?osvdb_id=30201 Hits : 98
Bugtraq: GForge Cross Site Scripting vulnerability
- Source : SecurityFocus Vuln Link : http://www.securityfocus.com/archive/1/456296 Hits : 39
phpMyFAQ Unspecified Parameter Remote SQL Injection and File Upload Vulnerabilities
- Source : frSIRT (WDM) Link : http://www.frsirt.com/english/advisories/2007/0077 Hits : 39
BinGoPHP NEWS Include File Bug in 'bn_smrep1.php' Lets Remote Users Execute Arbitrary Code
- Source : SecurityTracker Link : http://www.SecurityTracker.com/alerts/2007/Jan/1017477.html Hits : 39
[3/5 Cuyahoga FCKEditor Security Bypass Issue]
- Source : Secunia rss Link : http://secunia.com/advisories/23662/ Hits : 38
[3/5 Wordpress SQL Injection and Cross-Site Scripting Vulnerabilities]
- Source : Secunia rss Link : http://secunia.com/advisories/23595/ Hits : 40
[4/5 phpMyFAQ SQL Injection and File Upload Vulnerability]
- Source : Secunia rss Link : http://secunia.com/advisories/23651/ Hits : 42
Bugtraq: [OpenPKG-SA-2007.005 OpenPKG Security Advisory (wordpress)]
- Source : SecurityFocus Vuln Link : http://www.securityfocus.com/archive/1/456131 Hits : 37
WordPress "wp-login.php" Authentication Process Information Disclosure Vulnerability
- Source : frSIRT (WDM) Link : http://www.frsirt.com/english/advisories/2007/0062 Hits : 32
Vuln: Drupal Unspecified Cross-Site Scripting Vulnerability
- Source : SecurityFocus Vuln Link : http://www.securityfocus.com/bid/21887 Hits : 32
Vuln: Drupal Page Caching Denial of Service Vulnerability
- Source : SecurityFocus Vuln Link : http://www.securityfocus.com/bid/21895 Hits : 37
WordPress Trackback Charset SQL Injection and Admin Cross Site Scripting Vulnerabilities
- Source : frSIRT (WDM) Link : http://www.frsirt.com/english/advisories/2007/0061 Hits : 31
Bugtraq: Advisory 02/2007: WordPress Trackback Charset Decoding SQL Injection Vulnerability
- Source : SecurityFocus Vuln Link : http://www.securityfocus.com/archive/1/456049 Hits : 34
Bugtraq: Advisory 01/2007: WordPress CSRF Protection XSS Vulnerability
- Source : SecurityFocus Vuln Link : http://www.securityfocus.com/archive/1/456048 Hits : 31
[4/5 iG Shop PHP "eval()" Injection and SQL Injection Vulnerabilities]
- Source : Secunia rss Link : http://secunia.com/advisories/23604/ Hits : 37
[1/5 WordPress User Account Enumeration Weakness]
- Source : Secunia rss Link : http://secunia.com/advisories/23621/ Hits : 37
[1/5 Drupal Unspecified Page Not Found Spoofing Weakness]
- Source : Secunia rss Link : http://secunia.com/advisories/23586/ Hits : 33
Aratix "current_path" Parameter Handling Remote PHP File Inclusion Vulnerability
- Source : frSIRT (WDM) Link : http://www.frsirt.com/english/advisories/2007/0054 Hits : 33
iG Shop Multiple Parameter Remote Code Execution and SQL Injection Vulnerabilities
- Source : frSIRT (WDM) Link : http://www.frsirt.com/english/advisories/2007/0056 Hits : 33
Drupal Database Update Page Cache Poisoning Remote Denial of Service Vulnerability
- Source : frSIRT (WDM) Link : http://www.frsirt.com/english/advisories/2007/0051 Hits : 34
iG Calendar "id" Parameter Handling Remote SQL Query Injection Vulnerability
- Source : frSIRT (WDM) Link : http://www.frsirt.com/english/advisories/2007/0055 Hits : 34
Drupal "Filter" and "System" Modules Multiple Arguments Cross Site Scripting Issues
- Source : frSIRT (WDM) Link : http://www.frsirt.com/english/advisories/2007/0050 Hits : 30
Vuln: iGeneric iG Calendar USER.PHP SQL Injection Vulnerability
- Source : SecurityFocus Vuln Link : http://www.securityfocus.com/bid/21873 Hits : 34
Simple Web Content Management System "id" Parameter SQL Injection Vulnerability
- Source : frSIRT (WDM) Link : http://www.frsirt.com/english/advisories/2007/0040 Hits : 95
OvBB "GetLocation()" Function Multiple Paramater Cross Site Scripting Vulnerabilities
- Source : frSIRT (WDM) Link : http://www.frsirt.com/english/advisories/2007/0039 Hits : 80
[3/5 Simple Web Content Management System "id" SQL Injection]
- Source : Secunia rss Link : http://secunia.com/advisories/23590/ Hits : 96
[3/5 OvBB Script Insertion Vulnerability]
- Source : Secunia rss Link : http://secunia.com/advisories/23484/ Hits : 83
CMS Made Simple "searchinput" Parameter Handling Cross Site Scripting Vulnerability
- Source : frSIRT (WDM) Link : http://www.frsirt.com/english/advisories/2007/0027 Hits : 75
[4/5 The Address Book Multiple Vulnerabilities]
- Source : Secunia rss Link : http://secunia.com/advisories/21694/ Hits : 76
[2/5 CMS Made Simple "searchinput" Cross-Site Scripting Vulnerability]
- Source : Secunia rss Link : http://secunia.com/advisories/23582/ Hits : 80
Zen Cart Unspecified Parameter Handling Client-Side Cross Site Scripting Vulnerabilities
- Source : frSIRT (WDM) Link : http://www.frsirt.com/english/advisories/2007/0022 Hits : 94
Vuln: SH-News Misc.PHP Remote File Include Vulnerability
- Source : SecurityFocus Vuln Link : http://www.securityfocus.com/bid/21761 Hits : 103
Bugtraq: Re: [Full-disclosure simplog 0.9.3.2 SQL injection]
- Source : SecurityFocus Vuln Link : http://www.securityfocus.com/archive/1/455676 Hits : 95
Bugtraq: Re: PHP as a secure language? PHP worms?
- Source : SecurityFocus Vuln Link : http://www.securityfocus.com/archive/1/455687 Hits : 95
[2/5 WordPress "file" Script Insertion Vulnerability]
- Source : Secunia rss Link : http://secunia.com/advisories/23587/ Hits : 112
IMGallery "users_adm/start1.php" Extension Handling Arbitrary File Upload Vulnerability
- Source : frSIRT (WDM) Link : http://www.frsirt.com/english/advisories/2007/0010 Hits : 106
MDForum "PNSVlang" Cookie Parameter Handling Local File Inclusion Vulnerability
- Source : frSIRT (WDM) Link : http://www.frsirt.com/english/advisories/2007/0017 Hits : 85
CMX Acronym Module for phpBB "id" Parameter Remote SQL Injection Vulnerability
- Source : frSIRT (WDM) Link : http://www.frsirt.com/english/advisories/2007/0009 Hits : 105
STphp EasyNews PRO "data/users.txt" Remote Information Disclosure Vulnerability
- Source : frSIRT (WDM) Link : http://www.frsirt.com/english/advisories/2007/0011 Hits : 86
[2/5 Zen Cart Unspecified Cross-Site Scripting Vulnerabilities]
- Source : Secunia rss Link : http://secunia.com/advisories/23482/ Hits : 75
Bugtraq: Re: PHP as a secure language? PHP worms? [was: Re: new linux malware]
- Source : SecurityFocus Vuln Link : http://www.securityfocus.com/archive/1/455638 Hits : 92
Vuln: Cacti Copy_Cacti_User.PHP SQL Injection Vulnerability
- Source : SecurityFocus Vuln Link : http://www.securityfocus.com/bid/21823 Hits : 84
Bugtraq: PHPIrc_bot <= Remote File Include
- Source : SecurityFocus Vuln Link : http://www.securityfocus.com/archive/1/455613 Hits : 86
Bugtraq: vBulletin vCard PRO XSS
- Source : SecurityFocus Vuln Link : http://www.securityfocus.com/archive/1/455615 Hits : 105