[VIM] Latest ECHO Advisories

str0ke str0ke at milw0rm.com
Tue Mar 17 21:33:34 UTC 2009


-----------------------------------------------------------------------------------------
[ECHO_ADV_107$2009] FubarForum <= 1.6 Critical File Disclosure Vulnerability
-----------------------------------------------------------------------------------------

-----------------------------------------------------------------------------------------
[ECHO_ADV_105$2009] chaozzDB <= 1.2 Critical File Disclosure Vulnerability
-----------------------------------------------------------------------------------------

-----------------------------------------------------------------------------------------
[ECHO_ADV_106$2009] FireAnt <= 1.3 Critical File Disclosure Vulnerability
-----------------------------------------------------------------------------------------


Anyone else seeing an .htaccess file blocking these attacks in the /db/
folders?  Looking at the date it doesn't seem that anything has been
modified by the vendor.  Dates on the .htaccess files are 2008sh and the
versions haven't changed.

/str0ke


More information about the VIM mailing list