
|
show alle files as admin, SQL-Injection |
|
Set comments as admin, XSS, HTML-Injection, look IPs |
|
Web Interface Remote Denial of Service Vulnerability |
|
logging illegal users logins can harm system securtiy |
|
sql injection in adminpanel |
|
possible symlink attack |
|
FTP passwords work for every account of an customer |
|
possible symlink attack |
|
Directory Traversal |
|
sql injection |
|
problems with large images |
|
insecure file permissions |
|
cleartext password (root inc.) in swap |
|
viewing systems files |
|
possible symlink attack |
|
NEVER use the "%f" option in your VirusEvent action... |
|
symlink, sticky bit, and registry vulnerabilities |
|
symlink vulnerabilities in several scripts |
|
symlink vulnerability |
|
symlink vulnerability |
|
a normal user can create and overwrite every file on the system |
|
insecure file permission vulnerability |
|
XSS and HTML-injection vulnerabilities |
|
users can subscribe a thread in an internal forum |
|
post threads to protected forums and possibility to hijack internal passwords |