| OSVDB ID | Disclosure Date | Title |
|
9228
Description:
(Description Provided by CVE) : Cross-site scripting vulnerability in L-Forum 2.40 and earlier, when the "Enable HTML in messages" option is on, allows remote attackers to insert arbitrary script or HTML via message fields including (1) From, (2) E-Mail, (3) Subject and (4) Body.
|
2002-08-14
|
L-Forum HTML Message Multiple Field XSS
|
|
10113
Description:
L-Forum contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the 'search.php' script not properly sanitizing user-supplied input to the 'search' parameter. This may allow an attacker to inject or manipulate SQL queries in the back-end database.
|
2002-08-13
|
L-Forum search.php search Parameter SQL Injection
|
|
14493
Description:
(Description Provided by CVE) : L-Forum 2.40 and earlier does not properly verify whether a file was uploaded or if the associated variables were set by POST (attachment, attachment_name, attachment_size and attachment_type), which allows remote attackers to read arbitrary files.
|
2002-08-14
|
L-Forum Upload Form Arbitrary File Retrieval
|
|
17112
Description:
LISTSERV contains a flaw that may lead to an unauthorized information disclosure. The issue is triggered when a remote attacker sends the "lists" command (and possibly others). The list manager will return mail with valid mail lists, as well as other system information including the CPU type and machine load. This may disclose the remote operating system which can assist an attacker in more focused attacks.
|
1997-11-13
|
L-Soft LISTSERV Mail Command Output Information Disclosure
|
|
16852
Description:
(Description Provided by CVE) : Multiple unknown vulnerabilities in L-Soft LISTSERV 14.3, 1.8e, and 1.8d allow remote attackers to execute arbitrary code or cause a denial of service. NOTE: this candidate may be SPLIT in the future when more precise technical details become available.
|
2005-05-25
|
L-Soft LISTSERV Multiple Unspecified Issues
|
|
11512
Description:
(Description Provided by CVE) : Buffer overflow in listserv allows arbitrary command execution.
|
1994-01-01
|
L-Soft LISTSERV SMTP Command Remote Overflow
|
|
3223
Description:
Unknown / Incomplete
|
2003-12-28
|
L-Soft LISTSERV WA CGI Script XSS
|
|
23684
Description:
(Description Provided by CVE) : Multiple buffer overflows in LISTSERV 14.3 and 14.4, including LISTSERV Lite and HPO, with the web archive interface enabled, allow remote attackers to execute arbitrary code via unknown attack vectors related to the WA CGI. NOTE: technical details will be released after the grace period has ended on 20060603.
|
2006-03-03
|
L-Soft LISTSERV wa.exe Script Multiple Remote Overflow
|
|
1311
Description:
(Description Provided by CVE) : Buffer overflow in the Web Archives component of L-Soft LISTSERV 1.8 allows remote attackers to execute arbitrary commands.
|
2000-05-05
|
L-Soft LISTSERV Web Archives Buffer Overflow
|
|
1470
Description:
(Description Provided by CVE) : Buffer overflow in the web archive component of L-Soft Listserv 1.8d and earlier allows remote attackers to execute arbitrary commands via a long query string.
|
2000-07-17
|
L-Soft LISTSERV Web Archives Long QUERY_STRING Overflow
|
|
915
Description:
L0phtCrack contains a flaw that may allow a local attacker to obtain password hashes of systems being tested. The issue is due to the program storing information in the /tmp directory, in files accessable to anyone.
|
1999-01-06
|
L0phtcrack /tmp File Password Exposure
|
|
20140
Description:
Unknown / Incomplete
|
2001-11-08
|
l2 l2_ch_syslog Unspecified Issue
|
|
55765
Description:
Unknown / Incomplete
|
2009-01-02
|
L2J Server TvT Unspecified Issue
|
|
6726
Description:
A remote overflow exists in l2tpd. The l2tpd program fails to check the boundary in the write_packet() function in control.c, resulting in a buffer overflow. By establishing an L2TP tunnel and then sending a specially crafted packet, a remote attacker can overflow a buffer, resulting in a loss of integrity.
|
2004-06-07
|
l2tpd control.c write_packet Function Remote Overflow
|
|
55135
Description:
Unknown / Incomplete
|
2003-03-14
|
l2tpd Malformed Data Remote DoS
|
|
5062
Description:
(Description Provided by CVE) : l2tpd 0.67 does not initialize the random number generator, which allows remote attackers to hijack sessions.
|
2004-04-08
|
l2tpd Random Number Generator Failure Session Hijacking
|
|
5061
Description:
(Description Provided by CVE) : Vulnerability in l2tpd 0.67 allows remote attackers to overwrite the vendor field via a long value in an attribute/value pair, possibly via a buffer overflow.
|
2004-04-08
|
l2tpd Vendor Field Remote Overflow
|
|
31780
Description:
(Description Provided by CVE) : Buffer overflow in the cluster_process_heartbeat function in cluster.c in layer 2 tunneling protocol network server (l2tpns) before 2.1.21 allows remote attackers to cause a denial of service via a large heartbeat packet.
|
2006-12-05
|
l2tpns cluster_process_heartbeat Function Remote Overflow DoS
|
|
15918
Description:
Unknown / Incomplete
|
2005-04-20
|
LA-MPI SIGCHLD Signal Handling Issue
|
|
7351
Description:
Unknown / Incomplete
|
2003-05-05
|
LabVIEW Remote FPGA Device Conflicting IP DoS
|
|
5119
Description:
LabVIEW contains a flaw that may allow a remote denial of service. The issue is triggered when a client sends a malformed HTTP request, using two new line sequences instead of the traditional <CR><LF> combination, and will result in loss of availability for the service.
|
2002-04-19
|
LabVIEW Web Server HTTP Get Newline DoS
|
|
25963
Description:
LabWiki contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate 'help' variable upon submission to the recentchanges.php script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2006-06-05
|
LabWiki recentchanges.php help Parameter XSS
|
|
26597
Description:
LabWiki contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the 'query' variable upon submission to the search.php script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2006-06-19
|
LabWiki search.php query Parameter XSS
|
|
45423
Description:
Unknown / Incomplete
|
1997-01-20
|
Ladder-DES Cipher Chosen-plaintext Attack Weakness
|
|
17940
Description:
Unknown / Incomplete
|
2004-06-09
|
Laffer get_pr Unspecified Security Issue
|
|
17941
Description:
(Description Provided by CVE) : PHP remote file inclusion vulnerability in im.php in Laffer 0.3.2.6 and 0.3.2.7 allows remote attackers to execute arbitrary PHP code via the CFG_PATH variable.
|
2005-07-09
|
Laffer im.php CFG_PATH Parameter Remote File Inclusion
|
|
11382
Description:
(Description Provided by CVE) : LakeWeb Filemail CGI script allows remote attackers to execute arbitrary commands via shell metacharacters in the recipient email address.
|
1998-11-09
|
LakeWeb Filemail Recipient Address Command Execution
|
|
11381
Description:
(Description Provided by CVE) : LakeWeb Mail List CGI script allows remote attackers to execute arbitrary commands via shell metacharacters in the recipient email address.
|
1998-11-09
|
LakeWeb Mail List Recipient Address Command Execution
|
|
16305
Description:
(Description Provided by CVE) : The LAM runtime environment package (lam-runtime-7.0.6-2mdk) on Mandrake Linux installs the mpi user without a password, which allows local users to gain privileges.
|
2005-04-28
|
lam-runtime RPM Default Account
|
|
40446
Description:
(Description Provided by CVE) : Multiple PHP remote file inclusion vulnerabilities in Lama Software allow remote attackers to execute arbitrary PHP code via a URL in the MY_CONF[classRoot] parameter to (1) inc.steps.access_error.php, (2) inc.steps.check_login.php, or (3) inc.steps.init_system.php in admin/functions/.
|
2008-01-21
|
Lama Software inc.steps.access_error.php MY_CONF[classRoot] Parameter Remote File Inclusion
|