stargeek
PHP news website logo.
home    PHP scripts    articles    seo tools    links    search    contact    shop    realtors


php-Calendar File Include Vulnerability [ Command Exec ]







php-Calendar File Include Vulnerability
[ Command Exec ]

php-Calendar File Include Vulnerability
[ Command Exec ]
12/29/2004 02:18 PM

GulfTech Security (Dec 29 2004)




This is a GrokNews Entry: (what is grok?)





Similar Items

php-Calendar File Include Vulnerability [ Command Exec ]

Grok Headline matches for php-Calendar File Include Vulnerability [ Command Exec ]

SMS Installer Include Script Command


SMS Installer Include Script Command 05/11/2004 12:43 AM

Include vulnerability in GEMITEL v 3.50


Include vulnerability in GEMITEL v 3.50 04/15/2004 06:20 PM
jaguar (Apr 15 2004)

Artmedic kleinanzeigen include
vulnerability


Artmedic kleinanzeigen include
vulnerability
07/19/2004 08:07 PM
Francisco Alisson (Jul 18 2004)

AlstraSoft EPay Pro v2.0 has file
include and multiple xss vulnerabilities


AlstraSoft EPay Pro v2.0 has file
include and multiple xss vulnerabilities
04/02/2005 05:37 PM
dcrab (Apr 01 2005)

Free File: ClickTray Calendar


Free File: ClickTray Calendar 09/26/2004 03:46 AM
G4 Tech TV Sep 26 2004 8:13AM GMT

O-088: Sun passwd(1) Command
Vulnerability


O-088: Sun passwd(1) Command
Vulnerability
03/06/2004 01:52 AM
Cy Schubert (Mar 05 2004)

remote root exec vulnerability in omail


remote root exec vulnerability in omail 05/05/2004 12:29 PM
Thijs Dalhuijsen (May 04 2004)

YaPiG Arbitrary Command Execution
Vulnerability


YaPiG Arbitrary Command Execution
Vulnerability
08/22/2004 03:30 PM

Direct and Related Links for 'YaPiG Arbitrary Command Execution Vulnerability'

“Critical: Highly critical Impact: System access Where: From remote Description: aCiDBiTS has reported a vulnerability in YaPiG, which can be exploited by malicious people to compromise a vulnerable system…. The vulnerability has been confirmed in version 0.92b. Other versions may also be affected. Solution: Edit the source to ensure that user input is sanitised properly.”…

[SIG^2 G-TEC] SurgeFTP LEAK Command
Denial-Of-Service Vulnerability


[SIG^2 G-TEC] SurgeFTP LEAK Command
Denial-Of-Service Vulnerability
04/07/2005 10:50 PM
Posted by chewkeong_at_security.org.sg, Apr 07 2005

RE: Wftpd stat Command Remote
Vulnerability Exploit


RE: Wftpd stat Command Remote
Vulnerability Exploit
03/06/2004 01:52 AM
Alun Jones (Mar 03 2004)

Re: Jason Maloney's CGI Guestbook Remote
Command Execution Vulnerability.


Re: Jason Maloney's CGI Guestbook Remote
Command Execution Vulnerability.
12/03/2003 03:51 PM
Nick Cleaton (Dec 03 2003)

Jason Maloney's CGI Guestbook Remote
Command Execution Vulnerability.


Jason Maloney's CGI Guestbook Remote
Command Execution Vulnerability.
12/02/2003 12:32 AM
Shaun Colley (Dec 01 2003)

Music Industry Exec Defends Some File
Sharing


Music Industry Exec Defends Some File
Sharing
01/23/2004 07:37 PM
Coming just as the head of the International Federation of the Phonographic Industry (IFPI) is claiming that the recording industry needs a "zero tolerance" attitude on file sharing, a 30-year veteran of the music industry is opening his mind to the possibilities and admitting that file sharing appears to have some benefits to the industry. Andy Taylor, who heads the Sanctuary Group, a company that seems to do a variety of things in the music industry including representing various artists and record labels, was quoted saying: "Sharing music is not necessarily a bad thing." He points out that it's a good way for people to investigate what's out there, figure out what they like, and then go and buy it. "They (teenagers) don't have the money, so they will only spend what money they have on something they really, really care about." Fairly stunning to hear this from a recording industry exec. However, he doesn't seem to fully get it. He still complains about "those who have no intention ever of spending money on music," saying that they're the real pirates. They're not, though. If they have no intention of ever spending any money on music than they're certainly not taking away any money from the industry. The industry wouldn't have gotten it either way. In fact, by letting those people listen to music, it's possible that the industry can change those listeners' minds. In listening to the free music, those who had no intention of spending may find certain musicians interesting enough to want to go out and see them, for instance.

With Send To command, you can move file
to folder


With Send To command, you can move file
to folder
06/30/2004 09:52 AM
National Post Jun 30 2004 1:50PM GMT

Vulns: Webmin / Usermin HTML Email
Command Execution Vulnerability


Vulns: Webmin / Usermin HTML Email
Command Execution Vulnerability
09/16/2004 12:41 PM
SecurityFocus Sep 16 2004 4:36PM GMT

[vulnwatch] Titan FTP Server Long
Command Heap Overflow Vulnerability


[vulnwatch] Titan FTP Server Long
Command Heap Overflow Vulnerability
08/31/2004 11:17 AM
lion (Aug 29 2004)

[SNS Advisory No.77] Usermin Remote
Arbitrary Shell Command Execution
Vulnerability


[SNS Advisory No.77] Usermin Remote
Arbitrary Shell Command Execution
Vulnerability
09/07/2004 06:23 PM
snsadv (Sep 07 2004)

[vulnwatch] WFTPD Pro Server 3.21 MLST
Command Denial of Service Vulnerability


[vulnwatch] WFTPD Pro Server 3.21 MLST
Command Denial of Service Vulnerability
08/31/2004 11:17 AM
lion (Aug 29 2004)

appending a list of files to one file
using xargs command


appending a list of files to one file
using xargs command
09/02/2004 10:27 AM
Tech-Recipes Sep 2 2004 2:37PM GMT

MADSHEEP-05SA (security advisory):
WebHints <= v1.03 Remote Command
Execution Vulnerability


MADSHEEP-05SA (security advisory):
WebHints <= v1.03 Remote Command
Execution Vulnerability
06/17/2005 04:53 PM
Posted by Emanuele \, Tuesday, 14 June

Enlista Calendar offers multi-platform
calendar sharing


Enlista Calendar offers multi-platform
calendar sharing
02/10/2004 11:56 AM
Enlista Corp. on Tuesday announced the release of Enlista Calendar 1.0, a multi-platform peer to peer calendaring sharing application that supports Mac OS X, Windows and Linux platforms.

Monkeymen Calendar 2.0 Calendar Software
for Windows Released


Monkeymen Calendar 2.0 Calendar Software
for Windows Released
12/22/2004 01:58 AM
Monkeymen have released Monkeymen Calendar Version 2.0 for Windows 95/8, NT, ME, Windows 2000 and Windows XP; an easy to use, intuitive and fully customizable Calendar-Planner and Reminder application. [PRWEB Dec 20, 2004]

BNCweb File Disclosure Vulnerability


BNCweb File Disclosure Vulnerability 12/09/2003 01:22 PM
Matthias Bethke (Dec 08 2003)

[SCSA-024] BES-CMS including file
vulnerability


[SCSA-024] BES-CMS including file
vulnerability
12/20/2003 06:07 PM
Security Corporation Security Advisory (Dec 20 2003)

PHPlist, file injection vulnerability


PHPlist, file injection vulnerability 11/14/2003 02:51 PM
Michiel Dethmers (Nov 14 2003)

Easy File Sharing Web Server
Vulnerability


Easy File Sharing Web Server
Vulnerability
08/30/2004 02:32 AM

Direct and Related Links for 'Easy File Sharing Web Server Vulnerability'

“Critical: Moderately critical Impact: Exposure of system information, Exposure of sensitive information Where: From remote Solution Status: Unpatched. James Bercegay has discovered a vulnerability in Easy File Sharing Web Server, which can be exploited by malicious people to access sensitive information. A problem caused due to insufficient restrictions on the web server’s virtual folders can be exploited to retrieve arbitrary files from a vulnerable system. Example: http://[victim]/disk_c The vulnerability has been confirmed on version 1.25….

cdwrite 1.3 insecure tmp file handling
vulnerability.


cdwrite 1.3 insecure tmp file handling
vulnerability.
12/08/2003 12:56 PM
Shaun Colley (Dec 06 2003)

cpio TOCTOU file-permissions
vulnerability


cpio TOCTOU file-permissions
vulnerability
04/13/2005 05:15 PM
Posted by Imran Ghory, Apr 13 2005

bzip2 TOCTOU file-permissions
vulnerability


bzip2 TOCTOU file-permissions
vulnerability
03/31/2005 03:23 PM
Imran Ghory (Mar 30 2005)

WWW File Share Pro HTTP Request DoS
Vulnerability


WWW File Share Pro HTTP Request DoS
Vulnerability
07/26/2004 02:19 AM

Direct and Related Links for 'WWW File Share Pro HTTP Request DoS Vulnerability'

“nekd0 has reported a vulnerability in WWW File share Pro, which can be exploited by malicious people to cause a DoS (Denial of Service)….The vulnerability has been reported in version 2.60. Other versions may also be affected. Solution: Filter requests using a firewall or proxy server. Use another product.”…

Re: gzip TOCTOU file-permissions
vulnerability


Re: gzip TOCTOU file-permissions
vulnerability
04/13/2005 12:03 PM
Posted by Martin Pitt, Apr 12 2005

[Opera 7] Arbitrary File Delete
Vulnerability


[Opera 7] Arbitrary File Delete
Vulnerability
12/23/2003 02:10 PM
:: Operash :: (Dec 22 2003)

rpdump TOCTOU file-permissions
vulnerability


rpdump TOCTOU file-permissions
vulnerability
04/11/2005 08:25 PM
Posted by Imran Ghory, Apr 09 2005

Adobe Acrobat Reader PDF file DoS
vulnerability


Adobe Acrobat Reader PDF file DoS
vulnerability
04/12/2004 04:55 PM
Arman Nayyeri (Apr 10 2004)

Props 0.6.1 XSS and Remote File Viewing
Vulnerability


Props 0.6.1 XSS and Remote File Viewing
Vulnerability
05/01/2004 11:51 AM
Manuel Lopez (Apr 30 2004)

allery Arbitrary File Upload
Vulnerability


allery Arbitrary File Upload
Vulnerability
08/28/2004 01:14 AM

Direct and Related Links for 'allery Arbitrary File Upload Vulnerability'

“aCiDBiTS has reported a vulnerability in Gallery, potentially allowing malicious people to compromise a vulnerable system. The problem is that “save_photos.php” stores uploaded files in a temporary folder before processing them without checking if they are valid images files. This allows malicious people to upload and execute arbitrary code if the temporary folder is accessible from remote. This has been reported to affect version 1.4.4. Prior versions may also be affected. NOTE: This only affects…

Gallery Arbitrary File Upload
Vulnerability


Gallery Arbitrary File Upload
Vulnerability
08/28/2004 11:25 AM

Direct and Related Links for 'Gallery Arbitrary File Upload Vulnerability'

“aCiDBiTS has reported a vulnerability in Gallery, potentially allowing malicious people to compromise a vulnerable system. The problem is that “save_photos.php” stores uploaded files in a temporary folder before processing them without checking if they are valid images files. This allows malicious people to upload and execute arbitrary code if the temporary folder is accessible from remote. This has been reported to affect version 1.4.4. Prior versions may also be affected. NOTE: This only affects…

gzip TOCTOU file-permissions
vulnerability


gzip TOCTOU file-permissions
vulnerability
04/05/2005 12:35 PM
Imran Ghory

Re: bzip2 TOCTOU file-permissions
vulnerability


Re: bzip2 TOCTOU file-permissions
vulnerability
04/02/2005 03:36 PM
Steve Grubb (Apr 02 2005)
Grok Description matches for php-Calendar File Include Vulnerability [ Command Exec ]
GrokA matches for php-Calendar File Include Vulnerability [ Command Exec ]

php-Calendar File Include Vulnerability [ Command Exec ]

The following phrases have been identified by the grok system as matching this entry:

















Also check out:


Grok

Ipod Porn on the
Rise

Brief Abstract of
Wikipedia's
Mesothelioma Cancer
page

Get first aid
instructions in your
cell phone

IE is crap
JSPWiki gains
podcasting support

QNX crrtrap
arbitrary file
read/write
vulnerability
[RLSA_06-2004]

Sanity Worm Concepts
Motorola's new V635
in the wild

Grim Macintosh
Market Share
Forebodes Crisis

Incendiary defused
in shop

Quake victim's
wedding proposal

'Explosions rock
central Riyadh'

US forms quake
relief coalition

Football: Rooney
charged

Blair to set out new
asylum plans

Survivors tell of
amazing escapes

Murder girl's family
'destroyed'

Debunking Paul
Thurrott

Building Robots to
Learn About Humans

Cheese and Crackers:
Tsunami Video

ipod
World Vision's
Vodafone K.K.
Releases Vodafone
902SH 3G Mobile
Phone from Sharp

Nokia selected as
the first 3G handset
par

Oracle takes control
of PeopleSoft --
finally (AFP)

Risk Your PC's
Health for a Song?
(PC World)

Report: Apple to
Debut Sub-$500 iMac

Broadband Changes
Slower Than You
Might Think

Porn Spam Is So 2003
Cities Should
Control Their Wi-Fi
Fate

Muni Wireless
Threatens Control,
Not Consumers

Blitz JavaSpaces
Open Source Videora
Server

Hmong Hunter Pleads
Innocent in
Wisconsin Slayings
(Reuters)

Bush Vows More U.S.
Aid for Victims of
Tsunami (Reuters)

Red Sox Victory
Voted Top Sports
Story (AP)

First Night Races
Kick Off New Year
(AP)

Strong Storm Prompts
Evacuations in Ariz.
(AP)

OD4Contact 2 contact
management app
redesigned

CES to showcase
digital
entertainment's
evolution

IBM's Power5 worth a
second look

RapidWeaver 3.0.2
offers variety of
improvements

George Masters' 15
minutes, more Mac
radio news

Omni releases
OmniGraffle 3.2
Betas

Digital Performer
4.51 adds dynamic
CPU mgmt, more

New Xmas photo
templates for
Portraits & Prints

NewTek releases
sixth free texture
set

Apple keeps stores
open late, offers
survey coupons

GarageGames offers
TST Pro 3D
visualization tool

Callas pdfLayerMaker
makes layers in
Acrobat 7

Freeverse ships '8th
Wonder' game in
North America

Apple and IBM Power
ahead together

NewsFire monitors
news, blogs, more

ADC publishes
'Developing 64-Bit
Applications'

The Year in Games
what is grok?