| OSVDB ID | Disclosure Date | Title |
|
10336
Description:
FreezingCold Broadboard contains a flaw that will allow an attacker to inject arbitrary SQL code. The problem is that the "keywords" variable in the search.asp module is not verified properly and will allow an attacker to inject or manipulate SQL queries.
|
2004-09-27
|
FreezingCold Broadboard search.asp SQL Injection
|
|
2373
Description:
aspBoard contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate "url" variables upon submission to the application. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2003-08-06
|
FreezingCold Broadboard url XSS
|
|
85874
Description:
Frei-Chat contains a flaw that allows a remote user to execute arbitrary PHP code. This flaw exists because the client/plugins/upload/upload.php script does not properly verify or sanitize user-uploaded files. By uploading a .php file, the remote system will place the file in a user-accessible path. Making a direct request to the uploaded file will allow the user to execute the script.
|
2012-09-29
|
Frei-Chat client/plugins/upload/upload.php File Upload PHP Code Execution
|
|
66628
Description:
(Description Provided by CVE) : Cross-site scripting (XSS) vulnerability in the (1) FreiChat component before 2.1.2 for Joomla! and the (2) FreiChatPure component before 1.2.2 for Joomla! allows remote attackers to inject arbitrary web script or HTML by entering it in an unspecified window.
|
2010-07-23
|
Frei-Chat Component for Joomla! Unspecified XSS
|
|
34308
Description:
(Description Provided by CVE) : PHP remote file inclusion vulnerability in language/lang/lang_contact_faq.php in the Prillian French 0.8.0 and earlier module for phpBB allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter. NOTE: the provenance of this information is unknown; the details are obtained from third party information.
|
2006-10-16
|
French Language Pack for phpBB Prillian lang_contact_faq.php phpbb_root_path Parameter Remote File Inclusion
|
|
29749
Description:
(Description Provided by CVE) : PHP remote file inclusion vulnerability in language/lang_french/lang_prillian_faq.php in the Prillian French 0.8.0 and earlier module for phpBB allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.
|
2006-10-12
|
French Language Pack for phpBB Prillian lang_prillian_faq.php phpbb_root_path Parameter Remote File Inclusion
|
|
38151
Description:
(Description Provided by CVE) : Multiple PHP remote file inclusion vulnerabilities in Frequency Clock 0.1b (Beta 0.1) allow remote attackers to execute arbitrary PHP code via a URL in the securelib parameter to (1) conf.php or (2) cp2.php.
|
2007-05-27
|
Frequency Clock conf.php securelib Parameter Remote File Inclusion
|
|
38152
Description:
(Description Provided by CVE) : Multiple PHP remote file inclusion vulnerabilities in Frequency Clock 0.1b (Beta 0.1) allow remote attackers to execute arbitrary PHP code via a URL in the securelib parameter to (1) conf.php or (2) cp2.php.
|
2007-05-27
|
Frequency Clock cp2.php securelib Parameter Remote File Inclusion
|
|
49849
Description:
Fresh Email Script contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the email variable upon submission to the register.php script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2008-11-10
|
Fresh Email Script register.php Email Parameter XSS
|
|
57332
Description:
Fresh Email Script contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to the 'url.php' script not properly sanitizing user input supplied to the 'tmp_sid' parameter. This may allow an attacker to include a file from an arbitrary remote host that contains commands which will be executed by the vulnerable script with the same privileges as the web server.
|
2008-11-10
|
Fresh Email Script url.php tmp_sid Parameter Remote File Inclusion
|
|
68667
Description:
Fresh FTP contains a flaw that allows a remote attacker to traverse outside of a restricted path. The issue is due to the filename specifier not properly sanitizing user input, specifically directory traversal style attacks (e.g., ../../) supplied via file names. This directory traversal attack would allow the attacker to create arbitrary files.
|
2010-10-11
|
Fresh FTP Filename Specifier Traversal Arbitrary File Write
|
|
90687
Description:
Fresh Theme for Drupal contains a flaw that allows a remote cross-site scripting (XSS) attack. This flaw exists because the application does not validate input related to the 3 slide gallery before returning it to the user. This may allow an attacker to create a specially crafted request that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2013-02-27
|
Fresh Theme for Drupal 3 Slide Gallery Unspecified XSS
|
|
35385
Description:
(Description Provided by CVE) : Buffer overflow in Fresh View 7.15 allows user-assisted remote attackers to execute arbitrary code via a crafted .PSP file.
|
2007-04-25
|
Fresh View PSP File Handling Overflow
|
|
49878
Description:
Freshlinks Module for PHP-Fusion contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the 'index.php' script not properly sanitizing user-supplied input to the 'linkid' variable. This may allow an attacker to inject or manipulate SQL queries in the back-end database.
|
2008-09-28
|
Freshlinks Module for PHP-Fusion index.php linkid Parameter SQL Injection
|
|
32923
Description:
(Description Provided by CVE) : Cross-site scripting (XSS) vulnerability in the RSS feed component in FreshReader before 1.0.07010600 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, possibly related to tag attributes.
|
2007-01-18
|
FreshReader RSS Feed Tag Attribute XSS
|
|
37818
Description:
Unknown / Incomplete
|
2001-02-11
|
FreSSH Seed Data Generation Weakness
|
|
55166
Description:
(Description Provided by CVE) : Multiple directory traversal vulnerabilities in FretsWeb 1.2 allow remote attackers to read arbitrary files via directory traversal sequences in the (1) language parameter to charts.php and the (2) fretsweb_language cookie parameter to unspecified vectors, possibly related to admin/common.php.
|
2009-06-17
|
Fretsweb admin/common.php Multiple Parameter Traversal Local File Inclusion
|
|
55196
Description:
(Description Provided by CVE) : Multiple directory traversal vulnerabilities in FretsWeb 1.2 allow remote attackers to read arbitrary files via directory traversal sequences in the (1) language parameter to charts.php and the (2) fretsweb_language cookie parameter to unspecified vectors, possibly related to admin/common.php.
|
2009-06-17
|
Fretsweb charts.php language Parameter Traversal Arbitrary File Access
|
|
55167
Description:
Fretsweb contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the 'player.php' script not properly sanitizing user-supplied input to the 'name' parameter. This may allow an attacker to inject or manipulate SQL queries in the back-end database.
|
2009-06-17
|
Fretsweb player.php name Parameter SQL Injection
|
|
55168
Description:
Fretsweb contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the 'song.php' script not properly sanitizing user-supplied input to the 'hash' parameter. This may allow an attacker to inject or manipulate SQL queries in the back-end database.
|
2009-06-17
|
Fretsweb song.php hash Parameter SQL Injection
|
|
53681
Description:
FreznoShop contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the 'product_details.php' script not properly sanitizing user-supplied input to the 'id' parameter. This may allow an attacker to inject or manipulate SQL queries in the back-end database.
|
2009-04-13
|
FreznoShop product_details.php id Parameter SQL Injection
|
|
18686
Description:
FreznoShop contains a flaw that may allow a remote attacker to carry out an SQL injection attack. The issue is due to the 'product_details.php' script not properly sanitizing user-supplied input to the 'id' variable. This may allow a remote attacker to inject or manipulate SQL queries in the back-end database.
|
2005-08-09
|
FreznoShop product_details.php id Parameter SQL Injection
|
|
3335
Description:
(Description Provided by CVE) : Cross-site scripting (XSS) vulnerability in search.php for FreznoShop 1.3.0 RC1 and earlier allows remote attackers to inject arbitrary web script or HTML via the search parameter.
|
2004-01-06
|
FreznoShop search.php search Parameter XSS
|
|
34464
Description:
(Description Provided by CVE) : SQL injection vulnerability in view.php in the Friendfinder 3.3 and earlier module for Xoops allows remote attackers to execute arbitrary SQL commands via the id parameter.
|
2007-03-29
|
FriendFinder Module for XOOPS view.php id Parameter SQL Injection
|
|
37658
Description:
(Description Provided by CVE) : Multiple PHP remote file inclusion vulnerabilities in Friendly 1.0d1 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the friendly_path parameter to (1) core/data/yaml.inc.php, or _load.php in (2) core/data/, (3) core/display/, or (4) core/support/.
|
2007-05-06
|
Friendly core/data/_load.php friendly_path Parameter Remote File Inclusion
|
|
37657
Description:
(Description Provided by CVE) : Multiple PHP remote file inclusion vulnerabilities in Friendly 1.0d1 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the friendly_path parameter to (1) core/data/yaml.inc.php, or _load.php in (2) core/data/, (3) core/display/, or (4) core/support/.
|
2007-05-06
|
Friendly core/data/yaml.inc.php friendly_path Parameter Remote File Inclusion
|
|
37659
Description:
(Description Provided by CVE) : Multiple PHP remote file inclusion vulnerabilities in Friendly 1.0d1 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the friendly_path parameter to (1) core/data/yaml.inc.php, or _load.php in (2) core/data/, (3) core/display/, or (4) core/support/.
|
2007-05-06
|
Friendly core/display/_load.php friendly_path Parameter Remote File Inclusion
|
|
37660
Description:
(Description Provided by CVE) : Multiple PHP remote file inclusion vulnerabilities in Friendly 1.0d1 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the friendly_path parameter to (1) core/data/yaml.inc.php, or _load.php in (2) core/data/, (3) core/display/, or (4) core/support/.
|
2007-05-06
|
Friendly core/support/_load.php friendly_path Parameter Remote File Inclusion
|
|
48104
Description:
(Description Provided by CVE) : Heap-based buffer overflow in a certain ActiveX control in fwRemoteCfg.dll 3.3.3.1 in Friendly Technologies FriendlyPPPoE Client 3.0.0.57 allows remote attackers to execute arbitrary code via a long third argument to the CreateURLShortcut method.
|
2008-08-28
|
Friendly Technologies fwDialerTechTool.dll ActiveX CreateURLShortcut() Method Overflow
|
|
48142
Description:
(Description Provided by CVE) : A certain ActiveX control in fwRemoteCfg.dll 3.3.3.1 in Friendly Technologies FriendlyPPPoE Client 3.0.0.57 allows remote attackers to (1) create and read arbitrary registry values via the RegistryValue method, and (2) read arbitrary files via the GetTextFile method.
|
2008-08-28
|
Friendly Technologies fwDialerTechTool.dll ActiveX RegistryValue() Method Arbitrary File Access
|