| OSVDB ID | Disclosure Date | Title |
|
74711
Description:
U BuddyPress Forum Attachment for WordPress contains a flaw that allows a remote attacker to traverse outside of a restricted path. The issue is due to the program not properly sanitizing user input, specifically directory traversal style attacks (e.g., ../../) supplied via the 'fileurl' parameter. This directory traversal attack would allow the attacker to access arbitrary files.
|
2011-08-19
|
U BuddyPress Forum Attachment for WordPress fileurl Parameter Traversal Arbitrary File Access
|
|
74710
Description:
U Extended Comment Plugin for WordPress contains a flaw that allows a remote attacker to traverse outside of a restricted path. The issue is due to the wp-content/plugins/u-extended-comment/includes/attachment.php script not properly sanitizing user input, specifically directory traversal style attacks (e.g., ../../) supplied via the 'fileurl' parameter to the index.php script. This directory traversal attack would allow the attacker to access arbitrary files.
|
2011-08-21
|
U Extended Comment Plugin for WordPress index.php fileurl Parameter Traversal Arbitrary File Access
|
|
79752
Description:
The U+Box 2.0 application for Android contains an unspecified flaw that may allow a remote attacker to have an unspecified impact. No further details have been provided.
|
2012-03-01
|
U+Box 2.0 (lg.uplusbox) Application for Android Unspecified Issue
|
|
79753
Description:
The U+Box 2.0 Pad application for Android contains an unspecified flaw that may allow a remote attacker to have an unspecified impact. No further details have been provided.
|
2012-03-01
|
U+Box 2.0 Pad (lg.uplusbox.pad) Application for Android Unspecified Issue
|
|
64367
Description:
Unknown / Incomplete
|
2010-01-12
|
U-disk FTP PASS Command Remote Overflow DoS
|
|
49542
Description:
(Description Provided by CVE) : webmail/modules/filesystem/edit.php in U-Mail Webmail server 4.91 allows remote attackers to overwrite arbitrary files via an absolute pathname in the path parameter and arbitrary content in the content parameter. NOTE: this can be leveraged for code execution by writing to a file under the web document root.
|
2008-10-30
|
U-Mail Webmail edit.php Multiple Variable Arbitrary Remote File Overwrite
|
|
53371
Description:
Unknown / Incomplete
|
2004-06-08
|
U.S. Robotics Broadband Router 8003 menu.htm Admin Password Disclosure
|
|
57533
Description:
Unknown / Incomplete
|
1999-06-22
|
U.S. Robotics Broadband-Router 8000A/8000-2 HTTP GET Request Remote Overflow
|
|
64996
Description:
U.S. Robotics USR5463 Router contains a flaw that allows a remote cross site scripting (XSS) attack. This flaw exists because the application does not validate the 'ddns_domainame' parameter upon submission to the 'cgi-bin/setup_ddns.exe' script. This may allow a user to create a specially crafted URL that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2010-05-20
|
U.S. Robotics USR5463 Router cgi-bin/setup_ddns.exe ddns_domainame Parameter XSS
|
|
13046
Description:
(Description Provided by CVE) : Infopop UBB.Threads 5.4 and Wired Community Software WWWThreads 5.0 through 5.0.9 allows remote attackers to upload arbitrary files by using a filename that contains an accepted extension, but ends in a different extension.
|
2002-01-30
|
UBB.threads / WWWThreads Malformed Extension Arbitrary File Upload
|
|
17521
Description:
UBB.threads contains a flaw that allows a remote cross site request forgery attack. This flaw exists because the application does not validate input upon submission to the 'addaddress.php' script. This could allow a malicious user to create a specially crafted URL that would execute arbitrary code in a user's browser, with the permissions of the user viewing the URL, within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2005-06-23
|
UBB.threads addaddress.php CSRF
|
|
17530
Description:
UBB.threads contains a flaw that may allow a remote attacker to carry out an SQL injection attack. The issue is due to the 'addfav.php' script not properly sanitizing user-supplied input to the 'main' variable. This may allow a remote attacker to inject or manipulate SQL queries in the back-end database.
|
2005-06-23
|
UBB.threads addfav.php main Parameter SQL Injection
|
|
25714
Description:
UBB.threads contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to addpost_newpoll.php not properly sanitizing user input supplied to the 'thispath' variable. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script.
|
2006-05-22
|
UBB.threads addpost_newpoll.php thispath Parameter Remote File Inclusion
|
|
32322
Description:
(Description Provided by CVE) : Multiple direct static code injection vulnerabilities in Groupee UBB.threads 6.5.1.1 allow remote attackers to (1) inject PHP code via a theme[] array parameter to admin/doedittheme.php, which is injected into includes/theme.inc.php; (2) inject PHP code via a config[] array parameter to admin/doeditconfig.php, and then execute the code via includes/config.inc.php; and inject a reference to PHP code via a URL in the config[path] parameter, and then execute the code via (3) dorateuser.php, (4) calendar.php, and unspecified other scripts.
|
2006-09-29
|
UBB.threads admin/doeditconfig.php config[] Variable PHP Code Injection
|
|
32321
Description:
(Description Provided by CVE) : Multiple direct static code injection vulnerabilities in Groupee UBB.threads 6.5.1.1 allow remote attackers to (1) inject PHP code via a theme[] array parameter to admin/doedittheme.php, which is injected into includes/theme.inc.php; (2) inject PHP code via a config[] array parameter to admin/doeditconfig.php, and then execute the code via includes/config.inc.php; and inject a reference to PHP code via a URL in the config[path] parameter, and then execute the code via (3) dorateuser.php, (4) calendar.php, and unspecified other scripts.
|
2006-09-29
|
UBB.threads admin/doedittheme.php theme[] Variable PHP Code Injection
|
|
12365
Description:
UBB.threads contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate 'Cat' variables upon submission to the 'calendar.php' script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2004-12-13
|
UBB.threads calendar.php Cat Parameter XSS
|
|
17526
Description:
UBB.threads contains a flaw that may allow a remote attacker to carry out an SQL injection attack. The issue is due to the 'calendar.php' script not properly sanitizing user-supplied input to the 'year' or 'month' variables. This may allow a remote attacker to inject or manipulate SQL queries in the back-end database.
|
2005-06-23
|
UBB.threads calendar.php Multiple Parameter SQL Injection
|
|
17512
Description:
UBB.threads contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to language preferences extracted from the cookie not properly sanitizing the 'language' parameter. This may allow an attacker to include an arbitrary file location, appended with a null byte (%00), that contains arbitrary commands which will be executed by the vulnerable script.
|
2005-06-23
|
UBB.threads Cookie Data language Parameter Local File Inclusion
|
|
32320
Description:
(Description Provided by CVE) : Groupee UBB.threads 6.5.1.1 allows remote attackers to obtain sensitive information via a direct request for cron/php/subscriptions.php, which reveals the path in an error message.
|
2006-09-29
|
UBB.threads cron/php/subscriptions.php Direct Request Path Disclosure
|
|
47954
Description:
UBB.threads contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the 'dosearch.inc.php' script not properly sanitizing user-supplied input to the 'Forum[]' parameter. This may allow an attacker to inject or manipulate SQL queries in the back-end database.
|
2008-09-02
|
UBB.threads dosearch.inc.php Forum[] Parameter SQL Injection
|
|
11050
Description:
UBB.threads contains a flaw that will allow an attacker to inject arbitrary SQL code. The problem is that the Name variable in the dosearch.php module is not verified properly and will allow an attacker to inject or manipulate SQL queries.
|
2004-10-21
|
UBB.threads dosearch.php Name Parameter SQL Injection
|
|
17517
Description:
UBB.thread contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the 'Searchpage' variable upon submission to the 'dosearch.php' script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2005-06-23
|
UBB.threads dosearch.php Searchpage Parameter XSS
|
|
17525
Description:
UBB.threads contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the 'download.php' script not properly sanitizing user-supplied input to the 'Number' variable. This may allow an attacker to inject or manipulate SQL queries in the back-end database.
|
2005-06-23
|
UBB.threads download.php Number Parameter SQL Injection
|
|
14744
Description:
UBB.threads contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the 'editpost.php' script not properly sanitizing user-supplied input to the 'Number' parameter. This may allow an attacker to inject or manipulate SQL queries in the back-end database, allowing for the manipulation or disclosure of arbitrary data.
|
2005-03-11
|
UBB.threads editpost.php Number Parameter SQL Injection
|
|
78192
Description:
UBB.threads contains a flaw that allows a remote cross-site scripting (XSS) attack. This flaw exists because the application does not validate the 'Loginname' parameter upon submission to the forums/ubbthreads.php script. This may allow a user to create a specially crafted URL that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2012-01-05
|
UBB.threads forums/ubbthreads.php Loginname Parameter XSS
|
|
17532
Description:
UBB.threads contains a flaw that may allow a remote attacker to carry out an SQL injection attack. The issue is due to the 'grabnext.php' script not properly sanitizing user-supplied input to the 'posted' variable. This may allow a remote attacker to inject or manipulate SQL queries in the back-end database.
|
2005-06-23
|
UBB.threads grabnext.php posted Parameter SQL Injection
|
|
26122
Description:
Unknown / Incomplete
|
2006-05-27
|
UBB.threads includepollresults.php Multiple Parameter Local File Inclusion
|
|
26120
Description:
(Description Provided by CVE) : Cross-site scripting (XSS) vulnerability in index.php in UBBThreads 5.x and earlier allows remote attackers to inject arbitrary web script or HTML via the debug parameter, as demonstrated by stealing MD5 hashes of passwords.
|
2006-05-27
|
UBB.threads index.php debug Parameter XSS
|
|
12366
Description:
UBB.threads contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate 'Cat' variables upon submission to the 'login.php' script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2004-12-13
|
UBB.threads login.php Cat Parameter XSS
|
|
17528
Description:
UBB.threads contains a flaw that may allow a remote attacker to carry out an SQL injection attack. The issue is due to the 'mailthread.php' script not properly sanitizing user-supplied input to the 'Number' variable. This may allow a remote attacker to inject or manipulate SQL queries in the back-end database.
|
2005-06-23
|
UBB.threads mailthread.php Number Parameter SQL Injection
|