Several vulnerabilities in CMS Made Simple 1.1.3.1

2007-10-10 Thread Omid
version (1.1.4.1) has been released : http://blog.cmsmadesimple.org/2007/10/07/announcing-cms-made-simple-1141/ - Omid

Multiple vulnerabilities in Joomla 1.5 RC 1

2007-09-03 Thread Omid
to many .../tmpl/...php files, will expose the full installation path . Joomla has released a new version (Joomla 1.5 RC 2) . - Omid

Remote file inclusion in Joomla 1.5.0 Beta

2007-04-23 Thread Omid
- Omid

Sql injection in WordPress 2.1.2

2007-03-09 Thread Omid
: $wpdb-query( INSERT INTO $wpdb-link2cat (link_id, category_id) VALUES ($link_ID, $new_cat)); - Omid

Sql injection bugs in Joomla and Mambo

2007-02-06 Thread Omid
://test/plugins/authentication/gmail.php http://test/plugins/authentication/example.php http://test/plugins/authentication/ldap.php http://test/modules/mod_mainmenu/menu.php .. The original advisory (in Persian) is located at : http://www.hackers.ir/advisories/festival.txt - Omid

Sql injection bugs in Xoops 2.0.16 + Weblinks module

2007-02-05 Thread Omid
version is not released yet . The original advisory (in Persian) is located at : http://www.hackers.ir/advisories/festival.txt - Omid

Sql injection bugs in Virtuemart and Letterman

2007-02-05 Thread Omid
work in Joomla 1.0.12 . The original advisory (in Persian) is located at : http://www.hackers.ir/advisories/festival.txt - Omid

Sql injection in PostNuke [Admin section]

2006-09-29 Thread Omid
section, so it doesnt seem to be critical . Also, PostNuke 0.800 Milestone 2 has been released . - Omid

Sql injection in Moodle

2006-09-18 Thread Omid
Hi, There is a sql injection in Moodle 1.6.1+ (and maybe before versions) : The $blogEntry parameter passed to insert_record() function in /blog/edit.php, is not checked properly . Version 1.6.2 has been released (moodle.org). - Omid

Sql injection in Tikiwiki

2006-09-11 Thread Omid
) is located at : http://www.hackers.ir/advisories/tikiwiki.html - Omid

Sql injection in RunCMS

2006-09-07 Thread Omid
. Fixpacks can be downloaded from RunCms official website : http://www.runcms.org/modules/mydownloads/viewcat.php?cid=5 The original advisory (in Persian) is located at : http://www.hackers.ir/advisories/runcms.html - Omid

Sql injection in BLOG:CMS

2006-09-07 Thread Omid
/blogcms.html - Omid

Sql injection in SMF [Admin section]

2006-09-02 Thread Omid
('$boardOptions[board_name]', 1, 255), '', 0, '-1,0'), __FILE__, __LINE__); This is in administration section, so it doesnt seem to be critical. - Omid