| OSVDB ID | Disclosure Date | Title |
|
21179
Description:
drzes HMS contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the /customers/domains.php script not properly sanitizing user-supplied input to the 'plan_id' variable. This may allow an attacker to inject or manipulate SQL queries in the back-end database.
|
2005-11-25
|
DRZES HMS /customers/domains.php plan_id Parameter SQL Injection
|
|
21187
Description:
drzes HMS contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the /customers/ftp_users.php script not properly sanitizing user-supplied input to the 'plan_id' or 'domain' variables. This may allow an attacker to inject or manipulate SQL queries in the back-end database.
|
2005-11-25
|
DRZES HMS /customers/ftp_users.php Multiple Parameter SQL Injection
|
|
21191
Description:
drzes HMS contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the /customers/htaccess.php script not properly sanitizing user-supplied input to the 'plan_id' or 'domain' variables. This may allow an attacker to inject or manipulate SQL queries in the back-end database.
|
2005-11-25
|
DRZES HMS /customers/htaccess.php Multiple Parameter SQL Injection
|
|
21184
Description:
drzes HMS contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the /customers/listcharges.php script not properly sanitizing user-supplied input to the 'customerPlanID' variable. This may allow an attacker to inject or manipulate SQL queries in the back-end database.
|
2005-11-25
|
DRZES HMS /customers/listcharges.php customerPlanID Parameter SQL Injection
|
|
21189
Description:
drzes HMS contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the /customers/pass_dirs.php script not properly sanitizing user-supplied input to the 'plan_id' or 'domain' variables. This may allow an attacker to inject or manipulate SQL queries in the back-end database.
|
2005-11-25
|
DRZES HMS /customers/pass_dirs.php Multiple Parameter SQL Injection
|
|
21185
Description:
drzes HMS contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the /customers/pop_accounts.php script not properly sanitizing user-supplied input to the 'plan_id' or 'domain' variables. This may allow an attacker to inject or manipulate SQL queries in the back-end database.
|
2005-11-25
|
DRZES HMS /customers/pop_accounts.php Multiple Parameter SQL Injection
|
|
21182
Description:
drzes HMS contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the /customers/referred_plans.php script not properly sanitizing user-supplied input to the 'ref_id' variable. This may allow an attacker to inject or manipulate SQL queries in the back-end database.
|
2005-11-25
|
DRZES HMS /customers/referred_plans.php ref_id Parameter SQL Injection
|
|
21193
Description:
drzes HMS contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the 'Domain Availability' field upon submission to the /customers/register_domain.php script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2005-11-25
|
DRZES HMS /customers/register_domain.php Domain Availability Field XSS
|
|
21192
Description:
drzes HMS contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the /customers/software.php script not properly sanitizing user-supplied input to the 'plan_id' or 'domain' variables. This may allow an attacker to inject or manipulate SQL queries in the back-end database.
|
2005-11-25
|
DRZES HMS /customers/software.php Multiple Parameter SQL Injection
|
|
21180
Description:
drzes HMS contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the /customers/viewinvoice.php script not properly sanitizing user-supplied input to the 'invoiceID' variable. This may allow an attacker to inject or manipulate SQL queries in the back-end database.
|
2005-11-25
|
DRZES HMS /customers/viewinvoice.php invoiceID Parameter SQL Injection
|
|
21181
Description:
drzes HMS contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the /customers/viewplan.php script not properly sanitizing user-supplied input to the 'customerPlanID' variable. This may allow an attacker to inject or manipulate SQL queries in the back-end database.
|
2005-11-25
|
DRZES HMS /customers/viewplan.php customerPlanID Parameter SQL Injection
|
|
21183
Description:
drzes HMS contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the /customers/viewusage.php script not properly sanitizing user-supplied input to the 'plan_id' variable. This may allow an attacker to inject or manipulate SQL queries in the back-end database.
|
2005-11-25
|
DRZES HMS /customers/viewusage.php plan_id Parameter SQL Injection
|
|
21190
Description:
drzes HMS contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the /customers/zone_files.php script not properly sanitizing user-supplied input to the 'plan_id' or 'domain' variables. This may allow an attacker to inject or manipulate SQL queries in the back-end database.
|
2005-11-25
|
DRZES HMS /customers/zone_files.php Multiple Parameter SQL Injection
|
|
21743
Description:
DRZES HMS contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the 'customerEmailAddress' variable upon submission to the login.php script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2005-12-07
|
DRZES HMS login.php customerEmailAddress Parameter XSS
|
|
57336
Description:
DS CMS contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the 'DetailFile.php' script not properly sanitizing user-supplied input to the 'nFileId' parameter. This may allow an attacker to inject or manipulate SQL queries in the back-end database.
|
2009-08-14
|
DS CMS DetailFile.php nFileId Parameter SQL Injection
|
|
49209
Description:
DS-Syndicate Component for Joomla contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the 'index2.php' script not properly sanitizing user-supplied input to the 'feed_id' parameter. This may allow an attacker to inject or manipulate SQL queries in the back-end database.
|
2008-10-20
|
DS-Syndicate Component for Joomla index2.php feed_id Parameter SQL Injection
|
|
65358
Description:
Unknown / Incomplete
|
2010-05-22
|
DS-Syndicate for Joomla! feed_id Parameter Path Disclosure
|
|
65357
Description:
Unknown / Incomplete
|
2010-05-22
|
DS-Syndicate for Joomla! feed_id Parameter SQL Injection
|
|
65356
Description:
Unknown / Incomplete
|
2010-05-22
|
DS-Syndicate for Joomla! feed_id Parameter Traversal Arbitrary File Overwrite
|
|
25735
Description:
DSChat contains a flaw that may allow a malicious user to create a malicious PHP script with arbitrary content. The issue is triggered due to improper sanitization to the "Nickname" field when entering a chat before being used to create a file in the "users" directory. It is possible that the flaw may allow the creation of a malicious PHP script with arbitrary content resulting in a loss of integrity.
|
2006-05-24
|
DSChat Chat Nickname Arbitrary PHP Code Execution
|
|
25734
Description:
DSChat contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the 'ctext' variable upon submission to the send.php script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2006-05-22
|
DSChat send.php ctext Parameter XSS
|
|
23882
Description:
DSCounter contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the index.php script not properly sanitizing user-supplied input to the HTTP_X_FORWARDED_FOR variable. This may allow an attacker to inject or manipulate SQL queries in the back-end database.
|
2006-03-12
|
DSCounter index.php HTTP_X_FORWARDED_FOR Parameter SQL Injection
|
|
23887
Description:
DSDownload contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the downloads.php script not properly sanitizing user-supplied input to the 'key' and/or 'category' variables. This may allow an attacker to inject or manipulate SQL queries in the back-end database.
|
2006-03-12
|
DSDownload downloads.php Multiple Parameter SQL Injection
|
|
23886
Description:
DSDownload contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the search.php script not properly sanitizing user-supplied input to the 'key' and/or 'category' variables. This may allow an attacker to inject or manipulate SQL queries in the back-end database.
|
2006-03-12
|
DSDownload search.php Multiple Parameter SQL Injection
|
|
69261
Description:
DServe contains a flaw that allows a remote cross site scripting (XSS) attack. This flaw exists because the application does not validate the 'dsqField' and 'srch_AnyText' parameters upon submission to the dserve.exe script. This may allow a user to create a specially crafted URL that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2010-11-11
|
DServe dserve.exe Multiple Parameter XSS
|
|
66396
Description:
DSite CMS contains a flaw that allows a remote cross site scripting (XSS) attack. This flaw exists because the application does not validate the 'button_name' parameter upon submission to the 'admin/plugin.php' script. This may allow a user to create a specially crafted URL that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2010-07-15
|
DSite CMS admin/plugin.php button_name Parameter XSS
|
|
23896
Description:
DSLogin contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the index.php (or admin/index.php) script not properly sanitizing user-supplied input to the 'log_userid' variable. This may allow an attacker to inject or manipulate SQL queries in the back-end database.
|
2006-03-12
|
DSLogin index.php log_userid Parameter SQL Injection
|
|
19022
Description:
(Description Provided by CVE) : Directory traversal vulnerability in explorer.php in DSM Light Web File Browser 2.0 allows remote attackers to read arbitrary files via .. (dot dot) in the wdir parameter.
|
2004-05-18
|
DSM Light Web File Browser explorer.php wdir Variable Arbitrary File Retrieval
|
|
23884
Description:
DSNewsletter contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the include/confirm.php script not properly sanitizing user-supplied input to the 'email' variable. This may allow an attacker to inject or manipulate SQL queries in the back-end database.
|
2006-03-12
|
DSNewsletter include/confirm.php email Parameter SQL Injection
|
|
23883
Description:
DSNewsletter contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the include/sub.php script not properly sanitizing user-supplied input to the 'email' variable. This may allow an attacker to inject or manipulate SQL queries in the back-end database.
|
2006-03-12
|
DSNewsletter include/sub.php email Parameter SQL Injection
|