| OSVDB ID | Disclosure Date | Title |
|
42745
Description:
(Description Provided by CVE) : Unrestricted file upload vulnerability in uploadrequest.asp in Layton HelpBox 3.7.1 allows remote authenticated users to upload and execute arbitrary ASP files, related to not properly checking file extensions.
|
2008-01-08
|
Layton HelpBox uploadrequest.asp Unrestricted File Upload Arbitrary ASP Execution
|
|
42751
Description:
(Description Provided by CVE) : Multiple SQL injection vulnerabilities in Layton HelpBox 3.7.1 allow (1) remote attackers to execute arbitrary SQL commands via the sys_request_id parameter to editrequestenduser.asp; and allow remote authenticated users to execute arbitrary SQL commands via (2) the oldpassword parameter to writepwdenduser.asp, and the sys_request_id parameter to (3) changerequeststatus.asp, (4) editrequestuser.asp, (5) requestcommentsuser.asp, and (6) useractions.asp, different vectors than CVE-2004-2551.
|
2008-01-08
|
Layton HelpBox useractions.asp sys_request_id Parameter SQL Injection
|
|
42757
Description:
(Description Provided by CVE) : Multiple cross-site scripting (XSS) vulnerabilities in Layton HelpBox 3.7.1 allow remote authenticated users to inject arbitrary web script or HTML via the (1) Forename, (2) Surname, (3) Telephone, and (4) Fax fields to writeenduserenduser.asp; the (5) Filter field to statsrequestypereport.asp; and the (6) sys_request_id parameter to requestattach.asp; and allow remote authenticated users to inject arbitrary web script or HTML via the (7) Asset, (8) Location, and (9) Problem fields to editrequestenduser.asp; the (10) Asset, (11) Asset Location, (12) Problem Desc, and (13) Solution Desc fields to editrequestuser.asp; and the (14) End User and (15) Description fields to usersearchrequests.asp. NOTE: vectors 5 and 6 do not require authentication to exploit.
|
2008-01-08
|
Layton HelpBox usersearchrequests.asp Multiple Field XSS
|
|
86740
Description:
Layton HelpBox contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the validateenduserlogin.asp script not properly sanitizing user-supplied input to the 'sys_userpwd' parameter. This may allow an attacker to inject or manipulate SQL queries in the back-end database, allowing for the manipulation or disclosure of arbitrary data.
|
2012-10-26
|
Layton HelpBox validateenduserlogin.asp sys_userpwd Parameter SQL Injection
|
|
86736
Description:
Layton HelpBox contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the validateuserlogin.asp script not properly sanitizing user-supplied input to the 'sys_userpwd' parameter. This may allow an attacker to inject or manipulate SQL queries in the back-end database, allowing for the manipulation or disclosure of arbitrary data.
|
2012-10-26
|
Layton HelpBox validateuserlogin.asp sys_userpwd Parameter SQL Injection
|
|
42752
Description:
(Description Provided by CVE) : Multiple cross-site scripting (XSS) vulnerabilities in Layton HelpBox 3.7.1 allow remote authenticated users to inject arbitrary web script or HTML via the (1) Forename, (2) Surname, (3) Telephone, and (4) Fax fields to writeenduserenduser.asp; the (5) Filter field to statsrequestypereport.asp; and the (6) sys_request_id parameter to requestattach.asp; and allow remote authenticated users to inject arbitrary web script or HTML via the (7) Asset, (8) Location, and (9) Problem fields to editrequestenduser.asp; the (10) Asset, (11) Asset Location, (12) Problem Desc, and (13) Solution Desc fields to editrequestuser.asp; and the (14) End User and (15) Description fields to usersearchrequests.asp. NOTE: vectors 5 and 6 do not require authentication to exploit.
|
2008-01-08
|
Layton HelpBox writeenduserenduser.asp Multiple Field XSS
|
|
42747
Description:
(Description Provided by CVE) : Multiple SQL injection vulnerabilities in Layton HelpBox 3.7.1 allow (1) remote attackers to execute arbitrary SQL commands via the sys_request_id parameter to editrequestenduser.asp; and allow remote authenticated users to execute arbitrary SQL commands via (2) the oldpassword parameter to writepwdenduser.asp, and the sys_request_id parameter to (3) changerequeststatus.asp, (4) editrequestuser.asp, (5) requestcommentsuser.asp, and (6) useractions.asp, different vectors than CVE-2004-2551.
|
2008-01-08
|
Layton HelpBox writepwdenduser.asp oldpassword Parameter SQL Injection
|
|
86750
Description:
Layton HelpBox contains a flaw that allows a remote cross-site scripting (XSS) attack. This flaw exists because the application does not validate the 'sys_solution_id', 'sys_requesttype_id', 'sys_problem_desc', 'sys_solution_desc', 'sys_problemsummary', 'usr_Action_testing', 'usr_Escalation', and 'usr_Additional_Resources' parameters upon submission to the writesolutionuser.asp script. This may allow a user to create a specially crafted request that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2012-10-26
|
Layton HelpBox writesolutionuser.asp Multiple Parameter XSS
|
|
49681
Description:
(Description Provided by CVE) : create_lazarus_export_tgz.sh in lazarus 0.9.24 allows local users to overwrite or delete arbitrary files via a symlink attack on a (1) /tmp/lazarus.tgz temporary file or a (2) /tmp/lazarus temporary directory.
|
2008-08-24
|
lazarus create_lazarus_export_tgz.sh Multiple Temporary File / Directory Symlink Arbitrary File Manipulation
|
|
27089
Description:
Lazarus Guestbook contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the 'show' variable upon submission to the codes-english.php script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2006-07-12
|
Lazarus Guestbook codes-english.php show Parameter XSS
|
|
27090
Description:
Lazarus Guestbook contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the 'img' variable upon submission to the picture.php script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2006-07-12
|
Lazarus Guestbook picture.php img Parameter XSS
|
|
34474
Description:
(Description Provided by CVE) : PHP remote file inclusion vulnerability in template.class.php in Carbonize Lazarus Guestbook before 1.7.3 allows remote attackers to execute arbitrary PHP code via a URL in the include_path parameter to admin.php, probably due to a dynamic variable evaluation vulnerability.
|
2007-03-07
|
Lazarus Guestbook template.class.php include_path Parameter Remote File Inclusion
|
|
77493
Description:
Lazyest Backup Plugin for WordPress contains a flaw that allows a remote cross-site scripting (XSS) attack. This flaw exists because the application does not validate the 'xml_or_all' parameter upon submission to the lazyest-backup.php script. This may allow a user to create a specially crafted URL that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2011-12-04
|
Lazyest Backup Plugin for WordPress lazyest-backup.php xml_or_all Parameter XSS
|
|
71058
Description:
Lazyest Gallery Plugin for WordPress contains a flaw that may lead to an unauthorized information disclosure. The issue is triggered when a remote attacker generates an error in the /wp-content/plugins/lazyest-gallery/lazyest-img.php script, which discloses the software's installation path resulting in a loss of confidentiality. While such information is relatively low risk, it is often useful in carrying out additional, more focused attacks.
|
2011-03-10
|
Lazyest Gallery Plugin for WordPress /wp-content/plugins/lazyest-gallery/lazyest-img.php file Parameter Path Disclosure
|
|
71057
Description:
Lazyest Gallery Plugin for WordPress contains a flaw that allows a remote cross-site scripting (XSS) attack. This flaw exists because the application does not validate the 'image' parameter upon submission to the wp-content/plugins/lazyest-gallery/lazyest-popup.php script. This may allow a user to create a specially crafted URL that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2011-03-10
|
Lazyest Gallery Plugin for WordPress /wp-content/plugins/lazyest-gallery/lazyest-popup.php image Parameter XSS
|
|
83017
Description:
LB Mixed Slideshow Plugin for WordPress contains a flaw that allows a remote user to execute arbitrary PHP code. This flaw exists because the wp-content/plugins/lb-mixed-slideshow/libs/uploadify/upload.php script does not properly verify or sanitize user-uploaded files. By uploading a .php file, the remote system will place the file in a user-accessible path. Making a direct request to the uploaded file will allow the user to execute the script.
|
2012-06-17
|
LB Mixed Slideshow Plugin for WordPress wp-content/plugins/lb-mixed-slideshow/libs/uploadify/upload.php File Upload PHP Code Execution
|
|
7753
Description:
(Description Provided by CVE) : Directory traversal vulnerability in Search.cgi in Leoboard LB5000 LB5000II 1029 and earlier allows remote attackers to overwrite files and gain privileges via .. (dot dot) sequences in the amembernamecookie cookie.
|
2001-10-30
|
LB5000 Search.cgi amembernamecookie Cookie Privilege Escalation
|
|
8181
Description:
LBE Web HelpDesk contains a flaw that will allow an attacker to inject arbitrary SQL code. The problem is that the 'id' parameter within jobedit.asp is not verified properly and will allow an attacker to inject or manipulate SQL queries.
|
2004-07-22
|
LBE Web HelpDesk jobedit.asp id Parameter SQL Injection
|
|
33367
Description:
(Description Provided by CVE) : lblog stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for a certain file in admin/db/newFolder/.
|
2007-01-02
|
lblog /admin/db/newFolder/ Direct Request Database Disclosure
|
|
28036
Description:
LBlog contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the 'comments.asp' script not properly sanitizing user-supplied input to the 'id' variable. This may allow an attacker to inject or manipulate SQL queries in the back-end database.
|
2006-08-20
|
LBlog comments.asp id Parameter SQL Injection
|
|
1584
Description:
(Description Provided by CVE) : Heap overflow in savestr function in LBNL traceroute 1.4a5 and earlier allows a local user to execute arbitrary commands via the -g option.
|
2000-09-28
|
LBNL traceroute -g Option Local Overflow
|
|
4025
Description:
LBreakout contains a flaw that may allow a malicious user to escalate their privileges on a vulnerable system. The issue is triggered by a boundary error in the handling of the HOME environment variables. It is possible that the flaw may allow a buffer overflow and potentially execute code with group "games" privileges resulting in a loss of confidentiality, integrity, and/or availability.
|
2004-02-23
|
LBreakout HOME Environment Variable Local Overflow
|
|
16569
Description:
Unknown / Incomplete
|
2002-11-24
|
LBreakout Unspecified Input Validation Issues
|
|
16570
Description:
A local overflow exists in LBreakout2. This issue exist because of a boundary error in the handling of certain environment variables resulting in a buffer overflow. With a specially crafted request, a malicious user can cause cause a buffer overflow and potentially execute code with group "games" privileges resulting in a loss of integrity or availability.
|
2004-02-22
|
LBreakout2 lbreakout2 HOME Environment Variable Handling Local Overflow
|
|
91547
Description:
LBreakout2 has been reported to contain a buffer overflow in the lbreakout2 binary. The original report states that when processing the HOME environment variable, the software may crash. Since the game is distributed with SGID privileges on Debian, this is a concern. However, subsequent examination indicates that in main.c, the GID is immediately dropped after opening the high-score file, making privilege escalation not possible.
|
2011-01-05
|
LBreakout2 lbreakout2 main.c HOME Environment Variable Handling Local Overflow
|
|
91540
Description:
LBreakout2 contains an overflow condition in the lbreakout2 binary that is triggered as user-supplied input is not properly validated when handling -D and -a command line arguments. This may allow a local attacker to cause an overflow, resulting in a denial of service or potentially allowing the execution of arbitrary code.
|
2004-02-22
|
LBreakout2 lbreakout2 Multiple Command Arguments Local Overflow
|
|
91541
Description:
LBreakout2 contains multiple unspecified overflow conditions in the lbreakout2 binary that are triggered during the handling of user-supplied input. This may allow an attacker to cause an overflow, resulting in a denial of service or potentially allowing the execution of arbitrary code.
|
2005-02-14
|
LBreakout2 lbreakout2 Multiple Unspecified Overflows
|
|
91538
Description:
LBreakout2 contains an unspecified overflow condition in the lbreakout2 binary that is triggered as user-supplied input is not properly validated. This may allow an attacker to cause an overflow, resulting in a denial of service or potentially allowing the execution of arbitrary code.
|
2002-11-24
|
LBreakout2 lbreakout2 Unspecified Overflow
|
|
2217
Description:
Unknown / Incomplete
|
2003-06-24
|
LBreakout2 lbreakout2server server/server.c Remote Format String
|
|
83811
Description:
Lc Flickr Carousel contains a flaw that allows a remote attacker to traverse outside of a restricted path. The issue is due to the scripts/getImage.php script not properly sanitizing user input, specifically directory traversal style attacks (e.g., ../../) supplied via the 'file' parameter. This directory traversal attack would allow the attacker to gain access to arbitrary files.
|
2012-07-12
|
Lc Flickr Carousel scripts/getImage.php file Parmeter Traversal Arbitrary File Access
|