Packet Storm's last 20 added files. Last Updated: Wed Aug 27 18:03:16 EDT 2008 [ USN-638-1.txt ] c3002bba563957c93b2edfad569c7c01 Ubuntu Security Notice 638-1 - Aaron Grattafiori discovered that the Gnome Help Viewer did not handle format strings correctly when displaying certain error messages. If a user were tricked into opening a specially crafted URI, a remote attacker could execute arbitrary code with user privileges. [ kyocera-traversal.txt ] b1469751eb65919a9b8435ad1055dc09 Kyocera Command Center suffers from a directory traversal vulnerability. [ searchengine-sql.txt ] 63fc260d89bd02c73d5d2647cb1356d3 Search Engine suffers from a remote SQL injection vulnerability in viewcat.php. [ igshopdisp-sql.txt ] e73b22fbec473ddd5750c3cbf0d66b60 iG Shop suffers from a remote SQL injection vulnerability in display_review.php. [ SSRT080106.txt ] a84ae83f38e250d72f3b90696e44be96 HP Security Bulletin - A potential security vulnerability has been identified in the HP Enterprise Discovery. The vulnerability could be exploited remotely by an authorized user to gain extended privileges. [ advchk-2.10.tar.gz ] 03bd5578fd6b1795710a9c67225040c3 Advchk (Advisory Check) reads security advisories so you do not have to. Advchk gathers security advisories using RSS feeds, compares them to a list of known services, and alerts you if you are vulnerable. Since adding hosts and services by hand would be quite a boring task, advchk leverages nmap for automatic service and version discovery. [ yourownbux-sql.txt ] 7e146c229cd2cc0ccbe6f6b868c695f2 YourOwnBux versions 3.1 and 3.2 Beta suffer from a remote SQL injection vulnerability. [ PLSA-2008-31.txt ] 89fde6963eee81805e587266f74bbffa Pardus Linux Security Advisory - A vulnerability has been reported in LibTIFF, which can be exploited by malicious people to cause a DoS (Denial of Service) or to potentially compromise a user's system. [ phpmyrealty109-sql.txt ] c5c0581e59881b0c55bafb406bc61e32 phpMyRealty versions 1.0.9 and below suffer from a remote SQL injection vulnerability in pages.php. [ ultra-overflow.txt ] 8efda1569b663b030992e1d6768813f9 Ultra Office Active-X Control remote buffer overflow exploit. [ ultra-corrupt.txt ] 3c538957caf9590d5e856cd27bf0f824 Ultra Office Active-X Control remote arbitrary file corruption exploit. [ MDVSA-2008-180-1.txt ] cee89e63538737ae53aedf3ab3fd7410 Mandriva Linux Security Advisory - Andreas Solberg found a denial of service flaw in how libxml2 processed certain content. If an application linked against libxml2 processed such malformed XML content, it could cause the application to stop responding. The original fix used to correct this issue caused some applications that used the libxml2 library to crash. These new updated packages use a different fix that does not cause certain linked applications to crash as the old packages did. [ fileutility.txt ] b9cc2a9b04bb9971365bc2eb05b812f3 This Metasploit exploit attacks multiple file manipulation vulnerabilities in the Kyocera Mita Scanner File Utility version 3.3.0.1. [ kyocera-upload.txt ] c188a08ce39e9da8719c911ff27e4178 The Kyocera Mita Scanner File Utility version 3.3.0.1 suffers from multiple file manipulation vulnerabilities. [ EMORY-2008-01.txt ] 46742f7d6234df7fa0b6c185fb2e534a Telartis's AWStats Totals versions 1.0 through 1.14 suffer from a remote code execution vulnerability. [ mybb1211-sql.txt ] 2b8c0145ecb2c5255a32519df1daeffe MyBulletinBoard (MyBB) versions 1.2.11 and below SQL injection exploit that leverages private.php. [ ifdate-sql.txt ] ea21be161b9c61655d9d93c6bb733611 iFdate versions 2.0.3 and below suffer from a SQL injection vulnerability. [ dsa-1631-2.txt ] f024501160502cc01f3a8a6951c7c361 Debian Security Advisory 1631-2 - The previous security update of the libxml2 package introduced some problems with other packages, most notably with librsvg. This update corrects these problems whilst still fixing the reported security problem. [ dsa-1632-1.txt ] 0e6569a1ce6eb08995b0101c1d463469 Debian Security Advisory 1632-1 - Drew Yao discovered that libTIFF, a library for handling the Tagged Image File Format, is vulnerable to a programming error allowing malformed tiff files to lead to a crash or execution of arbitrary code. [ thickboxgallery-disclose.txt ] 742dcf93f43279e1ee08f057327abcee Thickbox Gallery version 2 suffers from an administrative data disclosure vulnerability in admins.php.