| OSVDB ID | Disclosure Date | Title |
|
22191
Description:
B-net Software contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the 'title' and 'message' variables upon submission to the guestbook.php script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2006-01-02
|
B-net Software guestbook.php Multiple Parameter XSS
|
|
22190
Description:
B-net Software contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the 'name' and 'shout' variables upon submission to the shout.php script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2006-01-02
|
B-net Software shout.php Multiple Parameter XSS
|
|
36291
Description:
b1gBB contains a flaw that may allow a remote attacker to execute arbitrary commands or code. The issue is due to the 'footer.inc.php' script not properly sanitizing user input supplied to the 'tfooter' parameter. This may allow an attacker to include a file from a third-party remote host that contains commands or code that will be executed by the vulnerable script with the same privileges as the web server.
|
2007-06-25
|
b1gBB footer.inc.php tfooter Parameter Remote File Inclusion
|
|
38951
Description:
(Description Provided by CVE) : Multiple SQL injection vulnerabilities in b1gbb 2.24.0 allow remote attackers to execute arbitrary SQL commands via the id parameter to (1) showthread.php or (2) showboard.php.
|
2007-06-28
|
b1gbb showboard.php id Parameter SQL Injection
|
|
38950
Description:
(Description Provided by CVE) : Multiple SQL injection vulnerabilities in b1gbb 2.24.0 allow remote attackers to execute arbitrary SQL commands via the id parameter to (1) showthread.php or (2) showboard.php.
|
2007-06-28
|
b1gbb showthread.php id Parameter SQL Injection
|
|
38937
Description:
(Description Provided by CVE) : Cross-site scripting (XSS) vulnerability in visitenkarte.php in b1gBB 2.24.0 allows remote attackers to inject arbitrary web script or HTML via the user parameter.
|
2007-06-28
|
b1gBB visitenkarte.php user Parameter XSS
|
|
37102
Description:
(Description Provided by CVE) : Cross-site scripting (XSS) vulnerability in hilfe.php in b1gMail 6.3.1 allows remote attackers to inject arbitrary web script or HTML via the chapter parameter.
|
2007-09-17
|
b1gMail hilfe.php chapter Parameter XSS
|
|
35715
Description:
(Description Provided by CVE) : PHP remote file inclusion vulnerability in b2verifauth.php in b2 Blog 0.5 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the index parameter.
|
2006-12-23
|
b2 Blog b2verifauth.php index Parameter Remote File Inclusion
|
|
70668
Description:
B2 Portfolio Component for Joomla! contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the 'index.php' not properly sanitizing user-supplied input to the 'c' parameter. This may allow an attacker to inject or manipulate SQL queries in the back-end database, allowing for the manipulation or disclosure of arbitrary data.
|
2011-01-24
|
B2 Portfolio Component for Joomla! index.php c Parameter SQL Injection
|
|
34495
Description:
(Description Provided by CVE) : CRLF injection vulnerability in BSMTP.DLL in B21Soft BASP21 2003.0211, and BASP21 Pro 1.0.702.27 and earlier, allows remote attackers to inject arbitrary headers into e-mail messages via CRLF sequences in Subject lines.
|
2007-03-26
|
B21Soft BASP21 BSMTP.DLL SMTP Subject Line CRLF Injection
|
|
42792
Description:
(Description Provided by CVE) : Buffer overflow in the BFup ActiveX control (BFup.dll) in B21Soft BFup before 1.0.802.29 allows remote attackers to execute arbitrary code via a long FilePath parameter.
|
2008-03-06
|
B21Soft BFup ActiveX (BFup.dll) FilePath Property Overflow
|
|
54303
Description:
B2B Forward Auction Creator contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the admin.asp script not properly sanitizing user-supplied input to the 'User ID' and 'Password' parameters. This may allow an attacker to inject or manipulate SQL queries in the back-end database, allowing for the manipulation or disclosure of arbitrary data.
|
2009-02-27
|
B2B Forward Auction Creator admin.asp Multiple Parameter SQL Injection
|
|
64212
Description:
B2B Gold Script contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the 'product.html' script not properly sanitizing user-supplied input to the 'id' parameter. This may allow an attacker to inject or manipulate SQL queries in the back-end database, allowing for the manipulation or disclosure of arbitrary data.
|
2010-04-30
|
B2B Gold Script product.html id Parameter SQL Injection
|
|
54308
Description:
B2B Horizontal Marketplace Creator contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the admin.asp script not properly sanitizing user-supplied input to the 'User ID' and 'Password' parameters. This may allow an attacker to inject or manipulate SQL queries in the back-end database, allowing for the manipulation or disclosure of arbitrary data.
|
2009-02-27
|
B2B Horizontal Marketplace Creator admin.asp Multiple Parameter SQL Injection
|
|
54306
Description:
B2B Online Shop Creator contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the 'admin.asp' script not properly sanitizing user-supplied input to the 'User ID' and 'Password' parameters. This may allow an attacker to inject or manipulate SQL queries in the back-end database, allowing for the manipulation or disclosure of arbitrary data.
|
2009-02-27
|
B2B Online Shop Creator admin.asp Multiple Parameter SQL Injection
|
|
54304
Description:
B2B Reverse Auction Creator contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the admin.asp script not properly sanitizing user-supplied input to the 'User ID' and 'Password' parameters. This may allow an attacker to inject or manipulate SQL queries in the back-end database, allowing for the manipulation or disclosure of arbitrary data.
|
2009-02-27
|
B2B Reverse Auction Creator admin.asp Multiple Parameter SQL Injection
|
|
47957
Description:
B2B Trading Marketplace Script contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the listings.php script not properly sanitizing user-supplied input to the 'cid' parameter. This may allow an attacker to inject or manipulate SQL queries in the back-end database, allowing for the manipulation or disclosure of arbitrary data.
|
2008-09-07
|
B2B Trading Marketplace Script listings.php cid Parameter SQL Injection
|
|
54309
Description:
B2C StoreBuilder Designer contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the admin.asp script not properly sanitizing user-supplied input to the 'User ID' and 'Password' parameters. This may allow an attacker to inject or manipulate SQL queries in the back-end database, allowing for the manipulation or disclosure of arbitrary data.
|
2009-02-27
|
B2C StoreBuilder Designer admin.asp Multiple Parameter SQL Injection
|
|
82389
Description:
b2ePMS contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the index.php script not properly sanitizing user-supplied input to the 'phone_number', 'msg_caller','phone_msg', 'msg_options', 'msg_recipients[]', and 'signed' parameters. This may allow an attacker to inject or manipulate SQL queries in the back-end database, allowing for the manipulation or disclosure of arbitrary data.
|
2012-05-27
|
b2ePMS index.php Multiple Parameter SQL Injection
|
|
82084
Description:
b2ePMS contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the verify-user.php script not properly sanitizing user-supplied input to the username and user_passwd fields. This may allow an attacker to bypass authentication and inject or manipulate SQL queries in the back-end database, allowing for the manipulation or disclosure of arbitrary data.
|
2012-05-11
|
b2ePMS verify-user.php Multiple Field SQL Injection Authentication Bypass
|
|
92905
Description:
b2evolution contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the /blogs/admin.php script not properly sanitizing user-supplied input to the 'show_statuses[]' parameter. This may allow an attacker to inject or manipulate SQL queries in the back-end database, allowing for the manipulation or disclosure of arbitrary data.
|
2013-05-01
|
b2evolution /blogs/admin.php show_statuses[] Parameter SQL Injection
|
|
30778
Description:
(Description Provided by CVE) : Multiple cross-site scripting (XSS) vulnerabilities in b2evolution 1.8.2 through 1.9 beta allow remote attackers to inject arbitrary web script or HTML via the (1) app_name parameter in (a) _404_not_found.page.php, (b) _410_stats_gone.page.php, and (c) _referer_spam.page.php in inc/VIEW/errors/; the (2) baseurl parameter in (d) inc/VIEW/errors/_404_not_found.page.php; and the (3) ReqURI parameter in (e) inc/VIEW/errors/_referer_spam.page.php.
|
2006-11-28
|
b2evolution _404_not_found.page.php Multiple Parameter XSS
|
|
30779
Description:
(Description Provided by CVE) : Multiple cross-site scripting (XSS) vulnerabilities in b2evolution 1.8.2 through 1.9 beta allow remote attackers to inject arbitrary web script or HTML via the (1) app_name parameter in (a) _404_not_found.page.php, (b) _410_stats_gone.page.php, and (c) _referer_spam.page.php in inc/VIEW/errors/; the (2) baseurl parameter in (d) inc/VIEW/errors/_404_not_found.page.php; and the (3) ReqURI parameter in (e) inc/VIEW/errors/_referer_spam.page.php.
|
2006-11-28
|
b2evolution _410_stats_gone.page.php app_name Parameter XSS
|
|
30780
Description:
(Description Provided by CVE) : Multiple cross-site scripting (XSS) vulnerabilities in b2evolution 1.8.2 through 1.9 beta allow remote attackers to inject arbitrary web script or HTML via the (1) app_name parameter in (a) _404_not_found.page.php, (b) _410_stats_gone.page.php, and (c) _referer_spam.page.php in inc/VIEW/errors/; the (2) baseurl parameter in (d) inc/VIEW/errors/_404_not_found.page.php; and the (3) ReqURI parameter in (e) inc/VIEW/errors/_referer_spam.page.php.
|
2006-11-28
|
b2evolution _referer_spam.page.php Multiple Parameter XSS
|
|
66143
Description:
Unknown / Incomplete
|
2010-07-09
|
b2evolution Admin Password Manipulation CSRF
|
|
80672
Description:
b2evolution contains a flaw that allows a remote cross-site scripting (XSS) attack. This flaw exists because the application does not validate the message body upon submission to the blogs/blog1.php script. This may allow a user to create a specially crafted URL that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2012-03-29
|
b2evolution blogs/blog1.php Message Body XSS
|
|
71192
Description:
b2evolution contains a flaw that allows a remote cross-site scripting (XSS) attack. This flaw exists because the application does not validate the 'p' parameter upon submission to the blogs/htsrv/comment_post.php script when commenting on a blog. This may allow a user to create a specially crafted URL that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2011-03-15
|
b2evolution blogs/htsrv/comment_post.php p Parameter XSS
|
|
80671
Description:
b2evolution contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the blogs/htsrv/viewfile.php script not properly sanitizing user-supplied input to the 'root' parameter. This may allow an attacker to inject or manipulate SQL queries in the back-end database, allowing for the manipulation or disclosure of arbitrary data.
|
2012-03-30
|
b2evolution blogs/htsrv/viewfile.php root Parameter SQL Injection
|
|
34152
Description:
b2evolution has been reported to contain a flaw that may allow a remote attacker to execute arbitrary commands. The issue was supposedly due to 'blogs/index.php' not properly sanitizing user input supplied to the 'core_subdir' variable. However, third-party research indicates that file inclusions are not possible because the software uses a hard-coded value from a configuration script for this variable, which is therefore restricted from being called directly.
|
2007-04-14
|
b2evolution blogs/index.php core_subdir Parameter Remote File Inclusion
|
|
32027
Description:
(Description Provided by CVE) : Cross-site scripting (XSS) vulnerability in htsrv/login.php in b2evolution 1.8.6 allows remote attackers to inject arbitrary web script or HTML via scriptable attributes in the redirect_to parameter.
|
2007-01-09
|
b2evolution htsrv/login.php redirect_to Parameter XSS
|