lists.openwall.net   lists  /  announce  owl-users  owl-dev  john-users  john-dev  passwdqc-users  yescrypt  popa3d-users  /  oss-security  kernel-hardening  musl  sabotage  tlsify  passwords  /  crypt-dev  xvendor  /  Bugtraq  Full-Disclosure  linux-kernel  linux-netdev  linux-ext4  linux-hardening  linux-cve-announce  PHC 
Open Source and information security mailing list archives
 
Hash Suite: Windows password security audit tool. GUI, reports in PDF.
[<prev] [next>] [day] [month] [year] [list]
Date: Wed, 01 Feb 2006 19:23:09 -0600
From: Mario Oyorzabal Salgado <tuxsoul@...soul.com>
To: bugtraq@...urityfocus.com
Subject: Bug for libs in php link directory 2.0


Program: PHPLD (Php link directory)
Homepage: http://www.phplinkdirectory.com/
Language: PHP
Version: 2.0

Php link directory use lib's how adodb, smarthy, phpmailer, etc., etc.
but this lib's have bug's.

Bugs:

ADOdb PostgreSQL SQL Injection Vulnerability
<http://www.securityfocus.com/bid/16364>
2006-01-24
http://www.securityfocus.com/bid/16364

ADOdb Server.PHP SQL Injection Vulnerability
<http://www.securityfocus.com/bid/16187>
2006-01-09
http://www.securityfocus.com/bid/16187

PHPMailer Data() Function Remote Denial of Service Vulnerability
<http://www.securityfocus.com/bid/13805>
2005-05-28
http://www.securityfocus.com/bid/13805

Phpld have lib's out update.

For new version this libs to phpld:

ADOdb 4.71-1 release:
http://prdownloads.sourceforge.net/adodb/adodb471-1.tgz?download

Phpmailer 1.73 release:
http://mesh.dl.sourceforge.net/sourceforge/phpmailer/phpmailer-1.73.tar.gz

Smarty 2.6.12 release:
http://smarty.php.net/do_download.php?download_file=Smarty-2.6.12.tar.gz
<http://smarty.php.net/do_download.php?download_file=Smarty-2.6.11.tar.gz>

I have write for this bug in out update lib's in phpld forum:
http://www.phplinkdirectory.com/forum/viewtopic.php?t=1668

Too send mail to the admin the phpld site for this bug, but i don't no
have answer.

p.d. sorry my english is bad =).

-- 
"hechando a perder se aprende"
Debian Etch tuxsoul 2.6.12-1-686 2005 i686 GNU/Linux
Intel Celeron (Coppermine) stepping 06
  http://mx.dolric.com
  http://mx.tuxsoul.com
------------------BEGIN GEEK CODE BLOCK-----------------
Version: 3.12
GCS d? s: a? C+++ UL+++ P+ L++ E--- W++ N+ o K- w++
O-- M V- PS PE Y PGP++ t++ 5 X+++ R* tv++ b- DI+++ D----
G++ e- h++ !r !z
-------------------END GEEK CODE BLOCK------------------
----------BEGIN BLOGGER CODE BLOCK--------
B5 d t++ k+ s++ u-- f- i++ o+ x-- e l++ c+ 
-----------END BLOGGER CODE BLOCK---------



Powered by blists - more mailing lists

Powered by Openwall GNU/*/Linux Powered by OpenVZ