netOffice Dwins 1.3 Remote code execution.

2008-02-29 Thread db
Authors were notified on 2/19, no fix is currently available. Edit the source to prevent authorization bypass. in includes/library.php change if ($demoSession == 'true') { to if ($demoSession == true) { Author: dB Email: dB [at] rawsecurity.org

my little forum XSS

2008-02-12 Thread db
issue (2/4). Upgrade to 2.0 beta 24 or disable the ability to use the [img] BBCode tag in your forum. Author: dB Email: dB [at] rawsecurity.org

PacerCMS Multiple Vulnerabilities (XSS/SQL)

2008-01-22 Thread db
issues and responded quickly. Upgrade to the latest build (0.6.1). Author: dB Email: dB [at] rawsecurity ! org

ImageAlbum Remote SQL Injection Vulnerabilities

2008-01-11 Thread db
that all user input is properly sanitised. Cheers, dB dB [at] rawsecurity ! org