SecurityAlert : 3913 CVE : CVE-2008-2491 CWE : CWE-89 SecurityRisk : High (About) Remote Exploit : Yes Local Exploit : No Victim interaction required : No Exploit Given : No Credit : a jasbi yahoo com Published : 29.05.2008
Affected Software :
Hotscripts, Ablespace, 1.0
Advisory Text :
By : s3rv3r_hack3r (Ali Jasbi)
Vendor : abk-soft.com
Name : ablespace
version : All Version
Risk : Very high
++++++++++++++++++++++++++++++++++++++++++++
adv_cat.php >>>
if(!empty($_GET['cat_id'])){
$str = '';
DB::query("select * from adv_cats where
id=".to_sql(get_param('cat_id'),"Number"));
If you have additional information or notice any errors regarding this security advisory, please use contact form or email us at info()securityreason()com.
Maksymilian Arciemowicz discovered a Integer Overflow
vulnerability in the libc library "strfmon()" function.A vulnerability could allow an attacker who successfully exploits this vulnerability to take control of the affected *BSD systems.