| OSVDB ID | Disclosure Date | Title |
|
45456
Description:
By default, many O'Neill Bluetooth devices contain a default hardcoded PIN. During the bluetooth pairing process, the device uses a PIN with the value of 8761 which is publicly known and documented. This allows attackers to trivially access the device to intercept audio traffic or push audio content.
|
2005-07-01
|
O'Neill Bluetooth Pairing Process Default Hardcoded PIN
|
|
12963
Description:
WebSite Pro contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is triggered due to the 'args.bat' script not properly sanitizing user-supplied input. It is possible that the flaw may allow a remote attacker to execute arbitrary commands resulting in a loss of integrity.
|
1999-02-16
|
O'Reilly WebSite Pro args.bat Arbitrary Command Execution
|
|
12962
Description:
WebSite Pro contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is triggered due to the 'args.cmd' script not properly sanitizing user-supplied input. It is possible that the flaw may allow a remote attacker to execute arbitrary commands resulting in a loss of integrity.
|
1999-02-16
|
O'Reilly WebSite Pro args.cmd Arbitrary Command Execution
|
|
375
Description:
(Description Provided by CVE) : Buffer overflow in O'Reilly WebSite Professional web server 2.4 and earlier allows remote attackers to execute arbitrary commands via a long GET request or Referrer header.
|
2000-07-19
|
O'Reilly WebSite Pro GET Request Remote Overflow
|
|
374
Description:
(Description Provided by CVE) : Buffer overflow in Webfind CGI program in O'Reilly WebSite Professional web server 2.x allows remote attackers to execute arbitrary commands via a URL containing a long "keywords" parameter.
|
2000-07-19
|
O'Reilly WebSite Pro webfind.exe keywords Parameter Remote Overflow
|
|
1775
Description:
(Description Provided by CVE) : O'Reilly Website Professional 2.5.4 and earlier allows remote attackers to determine the physical path to the root directory via a URL request containing a ":" character.
|
2000-01-20
|
O'Reilly Website Professional Malformed Request Path Disclosure
|
|
229
Description:
(Description Provided by CVE) : The uploader program in the WebSite web server allows a remote attacker to execute arbitrary programs.
|
1997-09-04
|
O'Reilly WebSite uploader.exe Arbitrary File Upload
|
|
8
Description:
O'Reilly WebSite contains a flaw that may allow a remote attacker to execute arbitrary code. The issue is due to the 'win-c-sample' program containing a remote overflow. The program fails to validate unspecified user-supplied input resulting in a buffer overflow. With a specially crafted request, an attacker can execute custom code under the privileges of the web server process.
|
1997-01-06
|
O'Reilly WebSite win-c-sample Remote Overflow
|
|
21268
Description:
O-Kiraku Nikki contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the okiraku.php script not properly sanitizing user-supplied input to the 'day_id' variable. This may allow an attacker to inject or manipulate SQL queries in the back-end database.
|
2005-11-29
|
O-Kiraku Nikki okiraku.php day_id Parameter SQL Injection
|
|
82924
Description:
o0mBBS contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the NewTopic.asp script not properly sanitizing user-supplied input to the 'Forum' parameter. This may allow an attacker to inject or manipulate SQL queries in the back-end database, allowing for the manipulation or disclosure of arbitrary data.
|
2012-06-12
|
o0mBBS NewTopic.asp Forum Parameter SQL Injection
|
|
12457
Description:
(Description Provided by CVE) : Buffer overflow in the parse_html function in o3read.c for o3read 0.0.3 allows remote attackers to execute arbitrary code via a crafted SXW file.
|
2004-12-16
|
o3read parse_html Function SXW Document Overflow
|
|
17925
Description:
oaboard contains a flaw that may lead to an unauthorized information disclosure. The issue is triggered when an attacker makes a direct request to the a_channels.php script, which will disclose the full installation path resulting in a loss of confidentiality.
|
2005-07-13
|
oaboard a_channels.php Direct Request Path Disclosure
|
|
17924
Description:
oaboard contains a flaw that may lead to an unauthorized information disclosure. The issue is triggered when an attacker makes a direct request to the a_user.php script, which will disclose the full installation path resulting in a loss of confidentiality.
|
2005-07-13
|
oaboard a_user.php Direct Request Path Disclosure
|
|
17928
Description:
oaboard contains a flaw that may lead to an unauthorized information disclosure. The issue is triggered when an attacker makes a direct request to the admin.php script, which will disclose the full installation path resulting in a loss of confidentiality.
|
2005-07-13
|
oaboard admin.php Direct Request Path Disclosure
|
|
17932
Description:
oaboard contains a flaw that may lead to an unauthorized information disclosure. The issue is triggered when an attacker makes a direct request to the channels.php script, which will disclose the full installation path resulting in a loss of confidentiality.
|
2005-07-13
|
oaboard channels.php Direct Request Path Disclosure
|
|
22219
Description:
(Description Provided by CVE) : PHP remote file include vulnerability in forum.php in oaBoard 1.0 allows remote attackers to execute arbitrary PHP code via a URL in the inc parameter.
|
2006-01-01
|
oaboard forum.php Multiple Parameter Remote File Inclusion
|
|
20420
Description:
oaboard contains a flaw that may allow a remote attacker to carry out an SQL injection attack. The issue is due to the 'forum.php' script not properly sanitizing user-supplied input to the 'channel' and 'topic' variables. This may allow a remote attacker to inject or manipulate SQL queries in the back-end database.
|
2005-10-30
|
oaboard forum.php Multiple Parameter SQL Injection
|
|
17929
Description:
oaboard contains a flaw that may lead to an unauthorized information disclosure. The issue is triggered when an attacker makes a direct request to the info.php script, which will disclose the full installation path resulting in a loss of confidentiality.
|
2005-07-13
|
oaboard info.php Direct Request Path Disclosure
|
|
17927
Description:
oaboard contains a flaw that may lead to an unauthorized information disclosure. The issue is triggered when an attacker makes a direct request to the posting.php script, which will disclose the full installation path resulting in a loss of confidentiality.
|
2005-07-13
|
oaboard posting.php Direct Request Path Disclosure
|
|
17930
Description:
oaboard contains a flaw that may lead to an unauthorized information disclosure. The issue is triggered when an attacker makes a direct request to the profil.php script, which will disclose the full installation path resulting in a loss of confidentiality.
|
2005-07-13
|
oaboard profil.php Direct Request Path Disclosure
|
|
17931
Description:
oaboard contains a flaw that may lead to an unauthorized information disclosure. The issue is triggered when an attacker makes a direct request to the tickets.php script, which will disclose the full installation path resulting in a loss of confidentiality.
|
2005-07-13
|
oaboard tickets.php Direct Request Path Disclosure
|
|
17926
Description:
oaboard contains a flaw that may lead to an unauthorized information disclosure. The issue is triggered when an attacker makes a direct request to the topics.php script, which will disclose the full installation path resulting in a loss of confidentiality.
|
2005-07-13
|
oaboard topics.php Direct Request Path Disclosure
|
|
21095
Description:
OASYS Lite contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the 'keyword' variable upon submission to the 'search.asp' script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2005-11-25
|
OASYS Lite search.asp keyword Parameter XSS
|
|
53867
Description:
Unknown / Incomplete
|
2009-04-22
|
OAuth Access Token Session Fixation
|
|
38263
Description:
(Description Provided by CVE) : Cross-site scripting (XSS) vulnerability in the save function in Obedit 3.03 allows user-assisted remote attackers to inject arbitrary web script or HTML via unknown vectors, as demonstrated by a SCRIPT element in an unspecified context when saving a document. NOTE: because the details of the attack are uncertain, it is unclear whether this crosses privilege boundaries.
|
2007-09-18
|
Obedit save Function XSS
|
|
88454
Description:
Oberliga Theme for WordPress contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the /wp-content/themes/oberliga_theme/ajax/team.php script not properly sanitizing user-supplied input to the 'team' parameter. This may allow an attacker to inject or manipulate SQL queries in the back-end database, allowing for the manipulation or disclosure of arbitrary data.
|
2012-11-26
|
Oberliga Theme for WordPress /wp-content/themes/oberliga_theme/ajax/team.php team Parameter SQL Injection
|
|
87404
Description:
Oberthur ID-One COSMO Smart Card contains a flaw that is due to the program generating non-compliant public keys. This may allow a remote attacker to more easily bypass cryptographic protection mechanisms.
|
2012-11-09
|
Oberthur ID-One COSMO Smart Card Non-compliant Public Key Generation Cryptographic Weakness
|
|
70424
Description:
Objectivity/DB contains a flaw related to the some components' allowing multiple administrative operations to be performed without authentication. This may allow a remote attacker to bypass authentication.
|
2011-01-14
|
Objectivity/DB Multiple Administrative Operations Authentication Bypass
|
|
14728
Description:
By default, Oblivion/2 installs with a default password. The SYSOP account has a password of "SYSOP" which is publicly known and documented. This allows attackers to trivially access the program or system.
|
1992-01-01
|
Oblivion/2 BBS Default SYSOP Password
|
|
14411
Description:
(Description Provided by CVE) : The account lockout capability in Oblix NetPoint 5.2 and earlier only locks out users once for the specified lockout period, which makes it easier for remote attackers to conduct brute force password guessing by waiting until the lockout period ends, then guessing passwords without being locked out again.
|
2002-03-14
|
Oblix NetPoint Account Lockout Weakness
|