| OSVDB ID | Disclosure Date | Title |
|
49715
Description:
Unknown / Incomplete
|
2001-02-11
|
Q Algorithm Linear Cryptanalysis Weakness
|
|
21137
Description:
(Description Provided by CVE) : PHP remote file inclusion vulnerability in q-news.php in Q-News 2.0 allows remote attackers to execute arbitrary PHP code via a URL in the id parameter.
|
2005-11-28
|
Q-News q-news.php id Remote File Inclusion
|
|
63894
Description:
Q-Personel Component for Joomla! contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the 'index.php' script not properly sanitizing user-supplied input to the 'katid' parameter. This may allow an attacker to inject or manipulate SQL queries in the back-end database, allowing for the manipulation or disclosure of arbitrary data.
|
2010-04-13
|
Q-Personel Component for Joomla! index.php katid Parameter SQL Injection
|
|
61354
Description:
Q-Personel Component for Joomla! contains a flaw that allows a remote cross site scripting (XSS) attack. This flaw exists because the application does not validate the 'personel_sira' parameter upon submission to the 'index.php' script. This may allow a user to create a specially crafted URL that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2009-12-27
|
Q-Personel Component for Joomla! index.php personel_sira Parameter XSS
|
|
60421
Description:
Q-Proje Siirler Bileseni contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the 'index.php' script not properly sanitizing user-supplied input to the 'sid' parameter. This may allow an attacker to inject or manipulate SQL queries in the back-end database, allowing for the manipulation or disclosure of arbitrary data.
|
2009-08-25
|
Q-Proje Siirler Bileseni Component for Joomla! index.php sid Parameter SQL Injection
|
|
89989
Description:
By default, Mutliple Q-See MPEG4 DVRs install with default user credentials (username/password combination). The administrator account has a password of '0000', which is publicly known and documented. This allows remote attackers to trivially access the program or system and gain privileged access.
|
2009-10-27
|
Q-See Multiple MPEG4 DVR Default User Credentials
|
|
28917
Description:
Q-Shop contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the browse.asp script not properly sanitizing user-supplied input to the 'OrderBy' variable. This may allow an attacker to inject or manipulate SQL queries in the back-end database.
|
2006-09-17
|
Q-Shop browse.asp OrderBy Parameter SQL Injection
|
|
50173
Description:
Q-Shop contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the 'srkeys' parameter upon submission to the 'search.asp' script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2008-11-17
|
Q-Shop search.asp srkeys Parameter XSS
|
|
50169
Description:
Q-Shop contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the 'users.asp' script not properly sanitizing user-supplied input to the 'UserID' and 'Pwd' parameters. This may allow an attacker to inject or manipulate SQL queries in the back-end database.
|
2008-11-17
|
Q-Shop users.asp Multiple Parameter SQL Injection
|
|
27600
Description:
QaTraq contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the 'msg', 'component_name', and 'component_desc' variables upon submission to the components_copy_content.php script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2006-06-23
|
QaTraq components_copy_content.php Multiple Parameter XSS
|
|
27601
Description:
QaTraq contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the 'msg', 'component_name', and 'component_desc' variables upon submission to the components_modify_content.php script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2006-06-23
|
QaTraq components_modify_content.php Multiple Parameter XSS
|
|
27602
Description:
QaTraq contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the 'msg', 'component_name', and 'component_desc' variables upon submission to the components_new_content.php script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2006-06-23
|
QaTraq components_new_content.php Multiple Parameter XSS
|
|
27603
Description:
QaTraq contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the 'title', 'version', and 'content' variables upon submission to the design_copy_content.php script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2006-06-23
|
QaTraq design_copy_content.php Multiple Parameter XSS
|
|
27604
Description:
QaTraq contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the 'plan_title' and 'plan_content' variables upon submission to the design_copy_plan_search.php script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2006-06-23
|
QaTraq design_copy_plan_search.php Multiple Parameter XSS
|
|
27605
Description:
QaTraq contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the 'title', 'minor_version', 'new_version', and 'content' variables upon submission to the design_modify_content.php script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2006-06-23
|
QaTraq design_modify_content.php Multiple Parameter XSS
|
|
27606
Description:
QaTraq contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the 'title', 'version', and 'content' variables upon submission to the design_new_content.php script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2006-06-23
|
QaTraq design_new_content.php Multiple Parameter XSS
|
|
27607
Description:
QaTraq contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the 'plan_name' and 'plan_desc' variables upon submission to the design_new_search.php script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2006-06-23
|
QaTraq design_new_search.php Multiple Parameter XSS
|
|
27608
Description:
QaTraq contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the 'file_name' variable upon submission to the download.php script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2006-06-23
|
QaTraq download.php file_name Parameter XSS
|
|
27609
Description:
QaTraq contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the 'username' and 'password' variables upon submission to the login.php script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2006-06-23
|
QaTraq login.php Multiple Parameter XSS
|
|
27617
Description:
QaTraq contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate unspecified variables upon submission to multiple unspecified scripts. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2006-06-23
|
QaTraq Multiple Unspecified XSS
|
|
27610
Description:
QaTraq contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the 'title', 'version', and 'content' variables upon submission to the phase_copy_content.php script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2006-06-23
|
QaTraq phase_copy_content.php Multiple Parameter XSS
|
|
27611
Description:
QaTraq contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the 'content' variable upon submission to the phase_delete_search.php script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2006-06-23
|
QaTraq phase_delete_search.php content Parameter XSS
|
|
27612
Description:
QaTraq contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the 'title', 'minor_version', 'new_version', and 'content' variables upon submission to the phase_modify_content.php script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2006-06-23
|
QaTraq phase_modify_content.php Multiple Parameter XSS
|
|
27613
Description:
QaTraq contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the 'content', 'title', 'version', and 'content' variables upon submission to the phase_modify_search.php script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2006-06-23
|
QaTraq phase_modify_search.php Multiple Parameter XSS
|
|
27614
Description:
QaTraq contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the 'content' variable upon submission to the phase_view_search.php script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2006-06-23
|
QaTraq phase_view_search.php content Parameter XSS
|
|
27615
Description:
QaTraq contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the 'msg', 'product_name', and 'product_desc' variables upon submission to the products_copy_content.php script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2006-06-23
|
QaTraq products_copy_content.php Multiple Parameter XSS
|
|
27616
Description:
QaTraq contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the 'product_name' and 'product_desc' variables upon submission to the products_copy_search.php script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2006-06-23
|
QaTraq products_copy_search.php Multiple Parameter XSS
|
|
27599
Description:
QaTraq contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the 'link_print', 'link_upgrade', 'link_sql', 'link_next', 'link_prev', and 'link_list' variables upon submission to the top.inc script, before being called by queries_view_search.php script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2006-06-23
|
QaTraq top.inc Multiple Parameter XSS
|
|
77723
Description:
QContacts Component for Joomla! contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the index.php script not properly sanitizing user-supplied input to the 'filter_order' parameter. This may allow an attacker to inject or manipulate SQL queries in the back-end database, allowing for the manipulation or disclosure of arbitrary data.
|
2011-12-08
|
QContacts Component for Joomla! index.php filter_order Parameter SQL Injection
|
|
35746
Description:
(Description Provided by CVE) : Multiple SQL injection vulnerabilities in authenticate.php in Quick and Dirty Blog (QDBlog) 0.4, and possibly earlier, allow remote attackers to execute arbitrary SQL commands via the (1) username and (2) password parameters.
|
2007-04-13
|
QDBlog authenticate.php Multiple Parameter SQL Injection
|