| OSVDB ID | Disclosure Date | Title |
|
9228
Description:
(Description Provided by CVE) : Cross-site scripting vulnerability in L-Forum 2.40 and earlier, when the "Enable HTML in messages" option is on, allows remote attackers to insert arbitrary script or HTML via message fields including (1) From, (2) E-Mail, (3) Subject and (4) Body.
|
2002-08-14
|
L-Forum HTML Message Multiple Field XSS
|
|
10113
Description:
L-Forum contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the 'search.php' script not properly sanitizing user-supplied input to the 'search' parameter. This may allow an attacker to inject or manipulate SQL queries in the back-end database.
|
2002-08-13
|
L-Forum search.php search Parameter SQL Injection
|
|
14493
Description:
(Description Provided by CVE) : L-Forum 2.40 and earlier does not properly verify whether a file was uploaded or if the associated variables were set by POST (attachment, attachment_name, attachment_size and attachment_type), which allows remote attackers to read arbitrary files.
|
2002-08-14
|
L-Forum Upload Form Arbitrary File Retrieval
|
|
17112
Description:
LISTSERV contains a flaw that may lead to an unauthorized information disclosure. The issue is triggered when a remote attacker sends the "lists" command (and possibly others). The list manager will return mail with valid mail lists, as well as other system information including the CPU type and machine load. This may disclose the remote operating system which can assist an attacker in more focused attacks.
|
1997-11-14
|
L-Soft LISTSERV Mail Command Output Information Disclosure
|
|
16852
Description:
(Description Provided by CVE) : Multiple unknown vulnerabilities in L-Soft LISTSERV 14.3, 1.8e, and 1.8d allow remote attackers to execute arbitrary code or cause a denial of service. NOTE: this candidate may be SPLIT in the future when more precise technical details become available.
|
2005-05-25
|
L-Soft LISTSERV Multiple Unspecified Issues
|
|
11512
Description:
(Description Provided by CVE) : Buffer overflow in listserv allows arbitrary command execution.
|
1994-01-01
|
L-Soft LISTSERV SMTP Command Remote Overflow
|
|
3223
Description:
Unknown / Incomplete
|
2003-12-28
|
L-Soft LISTSERV WA CGI Script XSS
|
|
23684
Description:
(Description Provided by CVE) : Multiple buffer overflows in LISTSERV 14.3 and 14.4, including LISTSERV Lite and HPO, with the web archive interface enabled, allow remote attackers to execute arbitrary code via unknown attack vectors related to the WA CGI. NOTE: technical details will be released after the grace period has ended on 20060603.
|
2006-03-03
|
L-Soft LISTSERV wa.exe Script Multiple Remote Overflow
|
|
84801
Description:
L-Soft LISTSERV contains a flaw that allows a remote cross-site scripting (XSS) attack. This flaw exists because input passed via the 'SHOWTPL' parameter to WA.exe is not properly sanitized before being returned to the user. This may allow a user to create a specially crafted request that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2012-08-16
|
L-Soft LISTSERV WA.exe SHOWTPL Parameter XSS
|
|
66139
Description:
LISTSERV contains a flaw that allows a remote cross site scripting (XSS) attack. This flaw exists because the application does not validate the 'T' parameter upon submission to the 'wa.exe' executable. This may allow a user to create a specially crafted URL that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2010-07-09
|
L-Soft LISTSERV wa.exe T Parameter XSS
|
|
1311
Description:
(Description Provided by CVE) : Buffer overflow in the Web Archives component of L-Soft LISTSERV 1.8 allows remote attackers to execute arbitrary commands.
|
2000-05-05
|
L-Soft LISTSERV Web Archives Buffer Overflow
|
|
1470
Description:
(Description Provided by CVE) : Buffer overflow in the web archive component of L-Soft Listserv 1.8d and earlier allows remote attackers to execute arbitrary commands via a long query string.
|
2000-07-17
|
L-Soft LISTSERV Web Archives Long QUERY_STRING Overflow
|
|
915
Description:
L0phtCrack contains a flaw that may allow a local attacker to obtain password hashes of systems being tested. The issue is due to the program storing information in the /tmp directory, in files accessable to anyone.
|
1999-01-06
|
L0phtcrack /tmp File Password Exposure
|
|
67786
Description:
L0phtCrack is prone to a flaw in the way it loads dynamic-link libraries (e.g. dwmapi.dll). The program uses a fixed path to look for specific files or libraries. This path includes directories that may not be trusted or under user control. By placing a custom version of the file or library in the path, the program will load it before the legitimate version. This allows an attacker to inject custom code that will be run with the privilege of the program or user executing the program. This can be done by tricking a user into opening a LCS file from the local file system or a USB drive in some cases. This attack can be leveraged remotely in some cases by placing the malicious file or library on a network share or extracted archive downloaded from a remote source.
|
2010-09-03
|
L0phtCrack Path Subversion Arbitrary DLL Injection Code Execution
|
|
20140
Description:
Unknown / Incomplete
|
2001-11-08
|
l2 l2_ch_syslog Unspecified Issue
|
|
55765
Description:
Unknown / Incomplete
|
2009-01-02
|
L2J Server TvT Unspecified Issue
|
|
6726
Description:
A remote overflow exists in l2tpd. The l2tpd program fails to check the boundary in the write_packet() function in control.c, resulting in a buffer overflow. By establishing an L2TP tunnel and then sending a specially crafted packet, a remote attacker can overflow a buffer, resulting in a loss of integrity.
|
2004-06-07
|
l2tpd control.c write_packet Function Remote Overflow
|
|
55135
Description:
Unknown / Incomplete
|
2003-03-14
|
l2tpd Malformed Data Remote DoS
|
|
5062
Description:
(Description Provided by CVE) : l2tpd 0.67 does not initialize the random number generator, which allows remote attackers to hijack sessions.
|
2004-04-08
|
l2tpd Random Number Generator Failure Session Hijacking
|
|
5061
Description:
(Description Provided by CVE) : Vulnerability in l2tpd 0.67 allows remote attackers to overwrite the vendor field via a long value in an attribute/value pair, possibly via a buffer overflow.
|
2004-04-08
|
l2tpd Vendor Field Remote Overflow
|
|
31780
Description:
(Description Provided by CVE) : Buffer overflow in the cluster_process_heartbeat function in cluster.c in layer 2 tunneling protocol network server (l2tpns) before 2.1.21 allows remote attackers to cause a denial of service via a large heartbeat packet.
|
2006-12-05
|
l2tpns cluster_process_heartbeat Function Remote Overflow DoS
|
|
72348
Description:
La Fonera+ contains a flaw that may allow a remote denial of service. The issue is triggered when an unspecified condition occurs, and will result in loss of availability for the service.
|
2011-05-11
|
La Fonera+ Unspecified Remote DoS
|
|
79069
Description:
Unknown / Incomplete
|
2011-06-06
|
LA Times for Android / iPhone User Accounts Local Disclosure
|
|
15918
Description:
Unknown / Incomplete
|
2005-04-20
|
LA-MPI SIGCHLD Signal Handling Issue
|
|
83323
Description:
LabStoRe contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the index.php script not properly sanitizing user-supplied input to the 'where_clause' parameter. This may allow an attacker to inject or manipulate SQL queries in the back-end database, allowing for the manipulation or disclosure of arbitrary data.
|
2011-11-06
|
LabStoRe index.php where_clause Parameter SQL Injection
|
|
83324
Description:
LabStoRe contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the index_long.php script not properly sanitizing user-supplied input to the 'where_clause' parameter. This may allow an attacker to inject or manipulate SQL queries in the back-end database, allowing for the manipulation or disclosure of arbitrary data.
|
2011-11-06
|
LabStoRe index_long.php where_clause Parameter SQL Injection
|
|
83322
Description:
LabStoRe contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the index_short.php script not properly sanitizing user-supplied input to the 'where_clause' parameter. This may allow an attacker to inject or manipulate SQL queries in the back-end database, allowing for the manipulation or disclosure of arbitrary data.
|
2011-11-07
|
LabStoRe index_short.php where_clause Parameter SQL Injection
|
|
7351
Description:
Unknown / Incomplete
|
2003-05-05
|
LabVIEW Remote FPGA Device Conflicting IP DoS
|
|
5119
Description:
LabVIEW contains a flaw that may allow a remote denial of service. The issue is triggered when a client sends a malformed HTTP request, using two new line sequences instead of the traditional <CR><LF> combination, and will result in loss of availability for the service.
|
2002-04-19
|
LabVIEW Web Server HTTP Get Newline DoS
|
|
76933
Description:
(Description Provided by CVE) : ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.
|
2011-11-09
|
LabWiki edit.php userfile Parameter Arbitrary File Upload
|