| OSVDB ID | Disclosure Date | Title |
|
69870
Description:
Lantern CMS contains a flaw that allows a remote cross-site scripting (XSS) attack. This flaw exists because the application does not validate the 'intPassedLocationID' parameter upon submission to the 11-login.asp script. This may allow a user to create a specially crafted URL that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2010-10-08
|
Lantern CMS 11-login.asp intPassedLocationID Parameter XSS
|
|
69871
Description:
Lantern CMS contains a flaw that allows a remote cross-site scripting (XSS) attack. This flaw exists because the application does not validate the 'signupemail' parameter upon submission to the 7-home-page.asp script. This may allow a user to create a specially crafted URL that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2010-10-08
|
Lantern CMS 7-home-page.asp signupemail Parameter XSS
|
|
18597
Description:
A local buffer overflow exists in the "edituser" comand on Lantronix console servers. The "edituser" command fails to check its command line arguments resulting in a stack overflow. With a specially crafted argument, an attacker can gain administrative privileges resulting in a full compromise.
|
2005-08-05
|
Lantonix Secure Console Server edituser Local Overflow
|
|
18595
Description:
Lantronix Secure Console Server contains a flaw that may allow a malicious local user to modify arbitrary files on the system. Due to insecure permissions set on the /tmp directory, an attacker can exploit a race condition against the creation of the /tmp/listen_fifo_server pipe to modify arbitrary files on the system resulting in a loss of integrity.
|
2005-08-05
|
Lantonix Secure Console Server listen_fifo_server Symlink Arbitrary Privileged File Overwrite
|
|
18596
Description:
Lantronix Secure Console Server contains a flaw that allows a local console user to execute system binaries. The issue is due to the console software not properly sanitizing user input, specifically traversal style attacks (../../) supplied via the command line variables. Sysadmin user can abuse this bug to become root user, and gain privileges usally not granted by the console software.
|
2005-08-05
|
Lantonix Secure Console Server Traversal Arbitrary Privileged Command Execution
|
|
51003
Description:
(Description Provided by CVE) : Lantronix MSS485-T allows remote attackers to cause a denial of service (unstable performance and service loss) via certain vulnerability scans, as demonstrated using (1) Nessus and (2) nmap.
|
2008-01-15
|
Lantronix MSS485-T Vulnerability Scan Remote DoS
|
|
39188
Description:
Lantronix SCS3200 contains a flaw in the public-key request handling that may allow a remote denial of service. With a specially crafted keyscan request, a remote attacker can cause the device to stop responding.
|
2007-11-11
|
Lantronix SCS3200 Unspecified Keyscan Requests Remote DoS
|
|
82317
Description:
Laoy8! CMS contains a flaw that allows a remote cross-site scripting (XSS) attack. This flaw exists because the application does not validate the 'ID' parameter upon submission to the mood.asp script. This may allow a user to create a specially crafted URL that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2012-03-24
|
Laoy8! CMS mood.asp ID Parameter XSS
|
|
71069
Description:
Lara contains a flaw that allows a remote Cross-site Request Forgery (CSRF / XSRF) attack. The flaw exists because the /_ui/changepassword script does not require multiple steps or explicit confirmation for sensitive transactions for the manipulation of passwords. By using a crafted URL (e.g., a crafted GET request inside an "img" tag), an attacker may trick the victim into clicking on the image to take advantage of the trust relationship between the authenticated victim and the application. Such an attack could trick the victim into executing arbitrary commands in the context of their session with the application, without further prompting or verification.
|
2010-10-11
|
Lara /_ui/changepassword Password Manipulation CSRF
|
|
13125
Description:
(Description Provided by CVE) : Lars Ellingsen guestserver.cgi allows remote attackers to execute arbitrary commands via shell metacharacters in the "email" parameter.
|
2001-01-29
|
Lars Ellingsen guestserver.cgi email Parameter Arbitrary Command Execution
|
|
42902
Description:
(Description Provided by CVE) : Format string vulnerability in the logging function in Larson Network Print Server (LstNPS) 9.4.2 build 105 and earlier for Windows might allow remote attackers to execute arbitrary code via format string specifiers in a USEP command on TCP port 3114.
|
2008-02-11
|
Larson Network Print Server (LstNPS) Logging Function USEP Command Remote Format String
|
|
42901
Description:
(Description Provided by CVE) : Stack-based buffer overflow in NPSpcSVR.exe in Larson Network Print Server (LstNPS) 9.4.2 build 105 and earlier allows remote attackers to execute arbitrary code via a long argument in a LICENSE command on TCP port 3114.
|
2008-02-11
|
Larson Network Print Server (LstNPS) NPSpcSVR.exe License Command Remote Overflow
|
|
5986
Description:
LaserFiche, when running on Netware, contains a flaw that may lead to an unauthorized password exposure. The Btreive tables that contain usernames, passwords, and group membership information do not require administrative privileges for write access. Additionally, any operations directly on the tables are not logged. This may lead to a loss of confidentiality and/or integrity.
|
1999-01-28
|
LaserFiche on NetWare User Database Privilege Escalation
|
|
5885
Description:
LaserFiche, when running on Netware, contains a flaw that may lead to an unauthorized password exposure. The Btreive tables that contain usernames, passwords, and group membership information are available for any user to read. The data inside those tables is not encrypted, which exposes the passwords in plaintext to any user. Included in the tables is the password for the administrative account. This may lead to a loss of confidentiality and/or integrity.
|
1999-01-28
|
LaserFiche on NetWare User Database Unencrypted
|
|
44401
Description:
LASERnet CMS contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the index.php script not properly sanitizing user-supplied input to the 'new' variable and that variable is assigned to the 'id' variable. This may allow an attacker to inject or manipulate SQL queries in the back-end database.
|
2008-04-15
|
Lasernet CMS index.php new Parameter SQL Injection
|
|
18671
Description:
(Description Provided by CVE) : Unknown vulnerability in Lasso Professional Server8.0.4 and 8.0.5 allows attackers to bypass authentication, related to [Auth] tags.
|
2005-08-02
|
Lasso Professional Auth Tag Restricted Page Bypass
|
|
8960
Description:
(Description Provided by CVE) : Directory traversal vulnerability in lastlines.cgi for Last Lines 2.0 allows remote attackers to read arbitrary files via '..' sequences in the $error_log variable.
|
2001-12-30
|
Last Lines lastlines.cgi Double Dot Traversal Arbitrary File Access
|
|
68789
Description:
(Description Provided by CVE) : lastfm 1.5.4 places a zero-length directory name in the LD_LIBRARY_PATH, which allows local users to gain privileges via a Trojan horse shared library in the current working directory.
|
2010-09-28
|
lastfm LD_LIBRARY_PATH Zero-length Directory Name Path Subversion Local Privilege Escalation
|
|
80023
Description:
LastGuru ASP GuestBook contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the View.asp script not properly sanitizing user-supplied input to the 'E_Mail' parameter. This may allow an attacker to inject or manipulate SQL queries in the back-end database, allowing for the manipulation or disclosure of arbitrary data.
|
2012-03-03
|
LastGuru ASP GuestBook View.asp E_Mail Parameter SQL Injection
|
|
54862
Description:
(Description Provided by CVE) : Mole Group Lastminute Script 4.0 and earlier stores passwords in cleartext, which allows context-dependent attackers to obtain sensitive information. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
|
2008-07-08
|
Lastminute Script Cleartext Password Disclosure
|
|
46858
Description:
Lastminute Script contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the 'index.php' script not properly sanitizing user-supplied input to the 'cid' parameter. This may allow an attacker to inject or manipulate SQL queries in the back-end database, allowing for the manipulation or disclosure of arbitrary data.
|
2008-07-08
|
Lastminute Script index.php cid Parameter SQL Injection
|
|
29736
Description:
(Description Provided by CVE) : PHP remote file inclusion vulnerability in lat2cyr.php in the lat2cyr 1.0.1 and earlier phpbb module allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.
|
2006-10-12
|
lat2cyr for phpBB lat2cyr.php phpbb_root_path Parameter Remote File Inclusion
|
|
90006
Description:
The LAT (Local Area Transport) daemon contains an overflow condition in the LATCP_VERSION function of llogincircuit.cc. The issue is triggered as user-supplied input is not properly validated when parsing version headers or generating an error message. With a specially crafted message or header, a remote attacker can cause a buffer overflow, resulting in a denial of service or potentially executing arbitrary code.
|
2013-02-02
|
latd llogincircuit.cc LATCP_VERSION Function Remote Overflow
|
|
60648
Description:
Lateral Arts Photobox Uploader ActiveX is prone to an overflow condition. The ActiveX control fails to properly sanitize user-supplied input assigned to various properties (e.g. LogURL, ConnectURL, SkinURL, AlbumCreateURL, ErrorURL, and httpsinglehost), resulting in a stack-based buffer overflow. With a specially crafted web page, a context-dependent attacker can execute arbitrary code on a user's system.
|
2009-12-02
|
Lateral Arts Photobox Uploader ActiveX Multiple Property Overflows
|
|
81350
Description:
latex2man contains a flaw that may allow a malicious local user to overwrite arbitrary files on the system. The issue is due to the program creating temporary files insecurely. It is possible for a local attacker to use a symlink attack to cause the program to unexpectedly write to, or overwrite an attacker specified file.
|
2012-04-14
|
latex2man Temporary File Symlink Arbitrary File Overwrite
|
|
10216
Description:
(Description Provided by CVE) : Multiple buffer overflows in LaTeX2rtf 1.9.15, and possibly other versions, allow remote attackers to execute arbitrary code via (1) the expandmacro function, and possibly (2) Environments and (3) TranslateCommand.
|
2004-09-21
|
LaTeX2rtf expandmacro() Function Overflow
|
|
81998
Description:
Lattice Diamond contains a flaw related to the libbaspd.dll libary. The issue is triggered when a virtual function is called from arbitrary memory when handling PCF files, which may allow a context-dependent attacker to execute arbitrary code.
|
2012-05-16
|
Lattice Diamond libbaspd.dll PCF File Handling Arbitrary Memory Virtual Function Call Remote Code Execution
|
|
81997
Description:
A memory corruption flaw exists in Lattice Diamond. The libbasut.dll library fails to sanitize user-supplied input resulting in memory corruption. With a specially crafted NCD file, a context-dependent attacker can execute arbitrary code.
|
2012-05-16
|
Lattice Diamond libbasut.dll NCD File Handling Memory Corruption
|
|
83280
Description:
Lattice Diamond is prone to an overflow condition. The program fails to properly sanitize user-supplied input resulting in a buffer overflow. With a specially crafted XCF file, a context-dependent attacker can potentially execute arbitrary code.
|
2012-06-21
|
Lattice Diamond XCF File Handling Overflow
|
|
37790
Description:
LaVague contains a flaw that may allow a remote attacker to execute arbitrary commands or code. The issue is due to the 'views/print/printbar.php' script not properly sanitizing user input supplied to the 'views_path' parameter. This may allow an attacker to include a file from a third-party remote host that contains commands or code that will be executed by the vulnerable script with the same privileges as the web server.
|
2007-05-08
|
LaVague views/print/printbar.php views_path Parameter Remote File Inclusion
|