|
81980
|
Disclosed: 2012-05-16
Description:
JCE Component for Joomla! contains a flaw that allows a remote user to execute arbitrary PHP code. This flaw exists because the components/com_jce/editor/extensions/browser/file.php script does not properly verify or sanitize user-uploaded files. By uploading a .php file, the remote system will place the file in a user-accessible path. Making a direct request to the uploaded file will allow the user to execute the script.
Comments: 0, Blogs: 0, References: 4
Vulnerability Classification
| Location | Attack Type | Impact | Solution | Exploit | Disclosure | OSVDB |
|---|
| | | | | - Vendor Verified
- Coordinated Disclosure
| - Web Related
- Authentication Required
|
|
JCE Component for Joomla! components/com_jce/editor/extensions/browser/file.php File Upload PHP Code Execution
|
|
81979
|
Disclosed: 2012-05-16
Description:
JCE Component for Joomla! contains a flaw that allows a remote cross-site scripting (XSS) attack. This flaw exists because the application does not validate the 'search' parameter upon submission to the administrator/index.php script. This may allow a user to create a specially crafted URL that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
Comments: 0, Blogs: 0, References: 4
Vulnerability Classification
| Location | Attack Type | Impact | Solution | Exploit | Disclosure | OSVDB |
|---|
| | | | | - Vendor Verified
- Coordinated Disclosure
| |
|
JCE Component for Joomla! administrator/index.php search Parameter XSS
|
|
81978
|
Disclosed: 2011-10-22
Description:
Unknown / Incomplete
Comments: 0, Blogs: 0, References: 3
Vulnerability Classification
| Location | Attack Type | Impact | Solution | Exploit | Disclosure | OSVDB |
|---|
| | | | | | |
|
W3C XML Encryption Standard Multiple Algorithm CBC Mode Modified Ciphertext Injection Cryptanalysis Weakness
|
|
81977
|
Disclosed: 2012-02-16
Description:
Unknown / Incomplete
Comments: 0, Blogs: 0, References: 9
Vulnerability Classification
| Location | Attack Type | Impact | Solution | Exploit | Disclosure | OSVDB |
|---|
| | | | | | |
|
RSA Algorithm Public Key Pair Implementation Weakness
|
|
81976
|
Disclosed: 2011-09-10
Description:
Unknown / Incomplete
Comments: 0, Blogs: 0, References: 7
Vulnerability Classification
| Location | Attack Type | Impact | Solution | Exploit | Disclosure | OSVDB |
|---|
- Context Dependent
- Wireless Vector
| | | | | | |
|
APCO P25 Protocol Multiple Cipher Known-Plaintext Exhaustive Key Search Compromise
|
|
81975
|
Disclosed: 2011-09-10
Description:
Unknown / Incomplete
Comments: 0, Blogs: 0, References: 7
Vulnerability Classification
| Location | Attack Type | Impact | Solution | Exploit | Disclosure | OSVDB |
|---|
- Context Dependent
- Wireless Vector
| | | | | | |
|
APCO P25 Protocol CRC Manipulation Message Spoofing Weakness
|
|
81974
|
Disclosed: 2011-09-10
Description:
Unknown / Incomplete
Comments: 0, Blogs: 0, References: 7
Vulnerability Classification
| Location | Attack Type | Impact | Solution | Exploit | Disclosure | OSVDB |
|---|
- Context Dependent
- Wireless Vector
| | | | | | |
|
APCO P25 Protocol “inhibit” Extended Function Command (XFC) Remote DoS
|
|
81973
|
Disclosed: 2011-09-10
Description:
Unknown / Incomplete
Comments: 0, Blogs: 0, References: 7
Vulnerability Classification
| Location | Attack Type | Impact | Solution | Exploit | Disclosure | OSVDB |
|---|
- Context Dependent
- Wireless Vector
| | | | | | |
|
APCO P25 Protocol Radio Authentication (RA) Protocol Authentication/Message Replay Weakness
|
|
81972
|
Disclosed: 2007-03-15
Description:
ImgSvr is prone to an overflow condition. The program fails to properly sanitize user-supplied input resulting in a stack-based buffer overflow. With a specially crafted request, a remote attacker can potentially execute arbitrary code.
Comments: 0, Blogs: 0, References: 2
Vulnerability Classification
| Location | Attack Type | Impact | Solution | Exploit | Disclosure | OSVDB |
|---|
| | | | | | |
|
ImgSvr template Parameter Remote Overflow
|
|
81971
|
Disclosed: 2012-03-26
Description:
eZ Online Editor Extension for eZ Publish contains a flaw that may lead to an unauthorized information disclosure. The issue is triggered when browsing for content objects, tagging, reading, and editing content nodes, which will disclose content node meta information to a remote attacker.
Comments: 0, Blogs: 0, References: 3
Vulnerability Classification
| Location | Attack Type | Impact | Solution | Exploit | Disclosure | OSVDB |
|---|
| | | | | | |
|
eZ Online Editor Extension for eZ Publish Multiple Action Content Node Meta Information Disclosure
|