| OSVDB ID | Disclosure Date | Title |
|
60907
Description:
(Description Provided by CVE) : Multiple cross-site request forgery (CSRF) vulnerabilities in oBlog allow remote attackers to hijack the authentication of administrators for requests that (1) change the admin password, (2) force an admin logout, (3) change the visibility of posts, (4) remove links, and (5) change the name fields of a blog.
|
2009-12-10
|
oBlog Admin Account Manipulation CSRF
|
|
65821
Description:
oBlog contains a flaw that allows a remote cross site scripting (XSS) attack. This flaw exists because the application does not validate the 'blogroll_id' and 'title' parameters upon submission to the 'admin/blogroll.php' script. This may allow a user to create a specially crafted URL that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2009-12-10
|
oBlog admin/blogroll.php Multiple Parameter XSS
|
|
65820
Description:
oBlog contains a flaw that allows a remote cross site scripting (XSS) attack. This flaw exists because the application does not validate the 'category_id' and 'category_name' parameters upon submission to the 'admin/groups.php' script. This may allow a user to create a specially crafted URL that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2009-12-10
|
oBlog admin/groups.php Multiple Parameter XSS
|
|
65823
Description:
(Description Provided by CVE) : admin/index.php in oBlog allows remote attackers to conduct brute-force password guessing attacks via HTTP requests.
|
2009-12-10
|
oBlog admin/index.php HTTP Request Brute Force Password Guessing Weakness
|
|
65822
Description:
oBlog contains a flaw that allows a remote cross site scripting (XSS) attack. This flaw exists because the application does not validate the 'blog_name' and 'tag_line' parameters upon submission to the 'admin/settings.php' script. This may allow a user to create a specially crafted URL that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2009-12-10
|
oBlog admin/settings.php Multiple Parameter XSS
|
|
65819
Description:
oBlog contains a flaw that allows a remote cross site scripting (XSS) attack. This flaw exists because the application does not validate the 'article_id' and 'title' parameters upon submission to the 'admin/write.php' script. This may allow a user to create a specially crafted URL that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2009-12-10
|
oBlog admin/write.php Multiple Parameter XSS
|
|
65818
Description:
(Description Provided by CVE) : article.php in oBlog does not properly restrict comments, which allows remote attackers to cause a denial of service (blog spam) via a comment=new action.
|
2009-12-10
|
oBlog article.php comment=new Action Remote DoS
|
|
60906
Description:
oBlog contains a flaw that allows a remote cross site scripting (XSS) attack. This flaw exists because the application does not validate the 'commentName', 'commentEmail', 'commentWeb', and 'commentText' parameters upon submission to the 'article.php' script. This may allow a user to create a specially crafted URL that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2009-12-10
|
oBlog article.php Multiple Parameter XSS
|
|
51639
Description:
(Description Provided by CVE) : Cross-site scripting (XSS) vulnerability in err.asp in Oblog allows remote attackers to inject arbitrary web script or HTML via the message parameter.
|
2009-01-23
|
Oblog err.asp message Parameter XSS
|
|
60905
Description:
oBlog contains a flaw that allows a remote cross site scripting (XSS) attack. This flaw exists because the application does not validate the 'search' parameter upon submission to the 'index.php' script. This may allow a user to create a specially crafted URL that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2009-12-10
|
oBlog index.php search Parameter XSS
|
|
32599
Description:
Unknown / Incomplete
|
2007-01-03
|
OBM Admin Script Information Disclosure
|
|
76730
Description:
Unknown / Incomplete
|
2011-09-13
|
Oboinus Image Filename Processing system() Call Arbitrary Shell Command Execution
|
|
57869
Description:
OBOphiX contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to the 'fonctions_racine.php' script not properly sanitizing user input supplied to the 'chemin_lib' parameter. This may allow an attacker to include a file from an arbitrary remote host that contains commands which will be executed by the vulnerable script with the same privileges as the web server.
|
2009-09-09
|
OBOphiX fonctions_racine.php chemin_lib Parameter Remote File Inclusion
|
|
35278
Description:
(Description Provided by CVE) : Session fixation vulnerability in onelook obo Shop allows remote attackers to hijack web sessions by setting a PHPSESSID cookie.
|
2007-04-06
|
oboShop PHPSESSID Cookie Session Fixation
|
|
48913
Description:
(Description Provided by CVE) : Observer 0.3.2.1 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the query parameter to (1) whois.php or (2) netcmd.php.
|
2008-09-24
|
Observer netcmd.php query Variable Arbitrary Shell Command Execution
|
|
48912
Description:
(Description Provided by CVE) : Observer 0.3.2.1 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the query parameter to (1) whois.php or (2) netcmd.php.
|
2008-09-24
|
Observer whois.php query Variable Arbitrary Shell Command Execution
|
|
61605
Description:
Obsession-Design Image-Gallery contains a flaw that allows a remote cross site scripting (XSS) attack. This flaw exists because the application does not validate the 'folder' parameter upon submission to the 'display.php' script. This may allow a user to create a specially crafted URL that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2010-01-02
|
Obsession-Design Image-Gallery display.php folder Parameter XSS
|
|
77157
Description:
obSuggest Component for Joomla! contains a flaw that may allow a remote attacker to execute arbitrary commands or code. The issue is due to the index.php script not properly sanitizing user input, specifically directory traversal style attacks (e.g., ../../) supplied to the 'controller' parameter. This may allow an attacker to include a file from the targeted host that contains arbitrary commands or code that will be executed by the vulnerable script. Such attacks are limited due to the script only calling files already on the target host. In addition, this flaw can potentially be used to disclose the contents of any file on the system accessible by the web server.
|
2011-07-31
|
obSuggest Component for Joomla! index.php controller Parameter Traversal Local File Inclusion
|
|
78898
Description:
OCaml contains a flaw that may allow a remote denial of service. The issue is triggered when an attacker sends multiple crafted parameters which trigger hash collisions, and will result in loss of availability for the program via CPU consumption.
|
2011-12-31
|
OCaml Hash Collision CPU Consumption Remote DoS
|
|
84847
Description:
OCaml Xml-Light Library contains a flaw that may allow a remote denial of service. The issue is triggered when a hash collision occurs between multiple hash functions. This will result in a consumption of CPU resources and a loss of availability for the program.
|
2012-08-20
|
OCaml Xml-Light Library Hash Collision CPU Consumption Remote DoS
|
|
12820
Description:
Unknown / Incomplete
|
2005-01-07
|
OCC theme Variable Arbitrary Command Execution
|
|
91490
Description:
Occasions Plugin for WordPress contains a flaw that allows a persistent cross-site scripting (XSS) attack. This flaw exists because the application does not validate the 'occ_content1' parameter upon submission to the occasions/occasions.php script, which is called via the wp-admin/options-general.php script. This may allow an attacker to create a specially crafted request that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2013-03-19
|
Occasions Plugin for WordPress occasions/occasions.php occ_content1 Parameter XSS
|
|
91489
Description:
Occasions Plugin for WordPress contains a flaw that allows a remote Cross-site Request Forgery (CSRF / XSRF) attack. The flaw exists because the application does not require multiple steps or explicit confirmation for sensitive transactions. By using a crafted URL (e.g., a crafted GET request inside an "img" tag), an attacker may trick the victim into clicking on the image to take advantage of the trust relationship between the authenticated victim and the application. Such an attack could trick the victim into adding or deleting occasions in the context of their session with the application, without further prompting or verification.
|
2013-03-19
|
Occasions Plugin for WordPress Occassion Manipulation CSRF
|
|
61924
Description:
Ocean CMS contains a flaw that may allow a remote attacker to execute arbitrary commands or code. The issue is due to the 'css.php' script not properly sanitizing user input supplied to the 'CONFIGS','CAKE' and 'LIBS' parameters. This may allow an attacker to include a file from a third-party remote host that contains commands or code that will be executed by the vulnerable script with the same privileges as the web server.
|
2009-07-23
|
Ocean CMS css.php Multiple Parameter Remote File Inclusion
|
|
14916
Description:
(Description Provided by CVE) : Code Ocean FTP server 1.0 allows remote attackers to cause a denial of service via a large number of connections.
|
2005-03-21
|
Ocean FTP Server Connection Saturation DoS
|
|
22638
Description:
(Description Provided by CVE) : Ocean12 Calendar Manager Pro 1.01 allows remote attackers to bypass authentication and obtain sensitive information via a direct request to /admin/view.asp. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
|
2005-11-04
|
Ocean12 /admin/view.asp Direct Request Authentication Bypass
|
|
52975
Description:
Unknown / Incomplete
|
2003-04-11
|
Ocean12 ASP Guestbook Manager /admin/o12guest.mdb Direct Request User Database Disclosure
|
|
25346
Description:
Ocean12 Calendar Manager Pro contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the 'admin/edit.asp' script not properly sanitizing user-supplied input to the 'ID' variable. This may allow an attacker to inject or manipulate SQL queries in the back-end database.
|
2006-05-08
|
Ocean12 Calendar Manager Pro admin/edit.asp ID Parameter SQL Injection
|
|
15696
Description:
Ocean12 Calendar Manager Pro contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the /admin/index.php script not properly sanitizing user-supplied input to the 'Admin_id' and 'Admin_password' variables. This may allow an attacker to inject or manipulate SQL queries in the back-end database.
|
2005-04-19
|
Ocean12 Calendar Manager Pro admin/index.php Admin_ID Parameter SQL Injection
|
|
25344
Description:
Ocean12 Calendar Manager Pro contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the 'admin/main.asp' script not properly sanitizing user-supplied input to the 'date' variable. This may allow an attacker to inject or manipulate SQL queries in the back-end database.
|
2006-05-08
|
Ocean12 Calendar Manager Pro admin/main.asp date Parameter SQL Injection
|