| OSVDB ID | Disclosure Date | Title |
|
87389
Description:
uploadify-amazon-s3 for Uploadify contains a flaw that allows a remote user to execute arbitrary PHP code. This flaw exists because the uploadify.php script does not properly verify or sanitize user-uploaded files. By uploading a .php file, the remote system will place the file in a user-accessible path. Making a direct request to the uploaded file will allow the user to execute the script, and therefore their own code.
|
2012-06-21
|
uploadify-amazon-s3 for Uploadify uploadify.php File Upload Arbitrary Code Execution
|
|
42617
Description:
(Description Provided by CVE) : admin.php in UploadImage 1.0 does not check for the original password before making a change to a new password, which allows remote attackers to gain administrator privileges via the pass parameter in a nopass (Set Password) action.
|
2008-01-09
|
UploadImage admin.php pass Variable Remote Privilege Escalation
|
|
42936
Description:
UploadScript contains a flaw that may allow a malicious user to gain access to unauthorized privileges. The issue is triggered when 'admin.php' does not check for the original password before making a change to a new password. This flaw may lead to a loss of integrity.
|
2008-01-09
|
UploadScript admin.php nopass Action pass Variable Remote Privilege Escalation
|
|
31850
Description:
(Description Provided by CVE) : Uploadscript 1.2 and earlier stores sensitive data under the web root with insufficient access control, which allows remote attackers to obtain the admin password hash via a direct request for /password.txt.
|
2006-12-06
|
Uploadscript password.txt Administrator Password Hash Disclosure
|
|
66614
Description:
Unknown / Incomplete
|
2010-02-18
|
UplusFTP Server list.html path Parameter Remote Overflow
|
|
62134
Description:
UplusFtp Server is prone to an overflow condition. The server fails to properly sanitize user-supplied input resulting in a stack overflow. With a specially crafted command argument, a remote attacker can potentially cause arbitrary code execution.
|
2010-02-05
|
UplusFtp Server Multiple FTP Command Handling Remote Overflow
|
|
66758
Description:
Unknown / Incomplete
|
2010-07-29
|
UPlusFtp Server Web Interface HTTP Request Handling Unspecified Overflow
|
|
77633
Description:
UPM Polls Plugin for WordPress contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the wp-admin/admin-ajax.php script not properly sanitizing user-supplied input to the 'PID' parameter. This may allow an attacker to inject or manipulate SQL queries in the back-end database, allowing for the manipulation or disclosure of arbitrary data.
|
2011-12-11
|
UPM Polls Plugin for WordPress wp-admin/admin-ajax.php PID Parameter SQL Injection
|
|
74377
Description:
UPM Polls Plugin for WordPress contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the wp-content/plugins/upm-polls/includes/poll_logs.php script not properly sanitizing user-supplied input to the 'qid' parameter. This may allow an attacker to inject or manipulate SQL queries in the back-end database, allowing for the manipulation or disclosure of arbitrary data.
|
2011-08-06
|
UPM Polls Plugin for WordPress wp-content/plugins/upm-polls/includes/poll_logs.php qid Parameter SQL Injection
|
|
32061
Description:
(Description Provided by CVE) : Multiple SQL injection vulnerabilities in Superfreaker Studios UPublisher 1.0 allow remote attackers to execute arbitrary SQL commands via unspecified vectors in (a) sendarticle.asp and (b) printarticle.asp, and the ID parameter to (c) index.asp and (d) preferences.asp, different vectors than CVE-2006-5888.
|
2006-12-04
|
UPublisher index.asp ID Parameter SQL Injection
|
|
35830
Description:
(Description Provided by CVE) : SQL injection vulnerability in Superfreaker Studios UPublisher 1.0 allows remote attackers to execute arbitrary SQL commands via the Username parameter in login.asp. NOTE: the provenance of this information is unknown; details are obtained from third party sources.
|
2006-11-13
|
UPublisher login.asp Username Parameter SQL Injection
|
|
32062
Description:
(Description Provided by CVE) : Multiple SQL injection vulnerabilities in Superfreaker Studios UPublisher 1.0 allow remote attackers to execute arbitrary SQL commands via unspecified vectors in (a) sendarticle.asp and (b) printarticle.asp, and the ID parameter to (c) index.asp and (d) preferences.asp, different vectors than CVE-2006-5888.
|
2006-12-04
|
UPublisher preferences.asp ID Parameter SQL Injection
|
|
32060
Description:
(Description Provided by CVE) : Multiple SQL injection vulnerabilities in Superfreaker Studios UPublisher 1.0 allow remote attackers to execute arbitrary SQL commands via unspecified vectors in (a) sendarticle.asp and (b) printarticle.asp, and the ID parameter to (c) index.asp and (d) preferences.asp, different vectors than CVE-2006-5888.
|
2006-12-04
|
UPublisher printarticle.asp SQL Injection
|
|
32059
Description:
(Description Provided by CVE) : Multiple SQL injection vulnerabilities in Superfreaker Studios UPublisher 1.0 allow remote attackers to execute arbitrary SQL commands via unspecified vectors in (a) sendarticle.asp and (b) printarticle.asp, and the ID parameter to (c) index.asp and (d) preferences.asp, different vectors than CVE-2006-5888.
|
2006-12-04
|
UPublisher sendarticle.asp SQL Injection
|
|
30331
Description:
(Description Provided by CVE) : SQL injection vulnerability in viewarticle.asp in Superfreaker Studios UPublisher 1.0 allows remote attackers to execute arbitrary SQL commands via the ID parameter.
|
2006-11-12
|
UPublisher viewarticle.asp ID Parameter SQL Injection
|
|
61396
Description:
UranyumSoft contains a flaw that may lead to an unauthorized information disclosure. The issue is triggered when a malicious hacker requests the file "database/db.mdb" via browser, which will disclose the whole database to a remote attacker.
|
2009-12-31
|
UranyumSoft Listing Service database/db.mdb Direct Request Database Disclosure
|
|
19435
Description:
(Description Provided by CVE) : URBAN 1.5.3_1 allows local users to overwrite arbitrary files via a symlink attack on the (1) high score or (2) save game files.
|
2005-09-16
|
URBAN .urban Symlink Arbitrary File Overwrite
|
|
19212
Description:
(Description Provided by CVE) : Multiple stack-based buffer overflows in urban before 1.5.3 allow local users to gain privileges via a long HOME environment variable to (1) config.cc, (2) game.cc, (3) highscor.cc, or (4) meny.cc.
|
2005-09-03
|
URBAN config/config.cc HOME Environment Variable Local Overflow
|
|
19213
Description:
(Description Provided by CVE) : Multiple stack-based buffer overflows in urban before 1.5.3 allow local users to gain privileges via a long HOME environment variable to (1) config.cc, (2) game.cc, (3) highscor.cc, or (4) meny.cc.
|
2005-09-03
|
URBAN engine/game.cc HOME Environment Variable Local Overflow
|
|
19214
Description:
(Description Provided by CVE) : Multiple stack-based buffer overflows in urban before 1.5.3 allow local users to gain privileges via a long HOME environment variable to (1) config.cc, (2) game.cc, (3) highscor.cc, or (4) meny.cc.
|
2005-09-03
|
URBAN highscor/highscor.cc HOME Environment Variable Local Overflow
|
|
19215
Description:
(Description Provided by CVE) : Multiple stack-based buffer overflows in urban before 1.5.3 allow local users to gain privileges via a long HOME environment variable to (1) config.cc, (2) game.cc, (3) highscor.cc, or (4) meny.cc.
|
2005-09-03
|
URBAN meny/meny.cc HOME Environment Variable Local Overflow
|
|
19434
Description:
(Description Provided by CVE) : URBAN 1.5.3_1 allows local users to overwrite arbitrary files via a symlink attack on the (1) high score or (2) save game files.
|
2005-09-16
|
URBAN savegame.dat Symlink Arbitrary File Overwrite
|
|
42334
Description:
(Description Provided by CVE) : report.cgi in Google Urchin allows remote attackers to bypass authentication and obtain sensitive information (web server logs) via certain modified query parameters, as demonstrated using the profile, rid, prefs, n, vid, bd, ed, dt, and gtype parameters, a different vulnerability than CVE-2007-5112.
|
2007-10-10
|
Urchin report.cgi Multiple Variable Authentication Bypass
|
|
38578
Description:
(Description Provided by CVE) : Cross-site scripting (XSS) vulnerability in session.cgi (aka the login page) in Google Urchin 5 5.7.03 and earlier allows remote attackers to inject arbitrary web script or HTML via the query string, a different vulnerability than CVE-2007-4713. NOTE: this can be leveraged to capture login credentials in some browsers that support remembered (auto-completed) passwords.
|
2007-09-23
|
Urchin session.cgi Query String XSS
|
|
36807
Description:
(Description Provided by CVE) : Multiple cross-site scripting (XSS) vulnerabilities in urchin.cgi in Urchin 5.6.00r2 allow remote attackers to inject arbitrary web script or HTML via the (1) dtc, (2) vid, (3) n, (4) dt, (5) ed, and (6) bd parameters.
|
2007-09-01
|
Urchin urchin.cgi Multiple Parameter XSS
|
|
55300
Description:
URD contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate certain variables upon submission to the fatal_error.php script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2009-06-24
|
URD Multiple Unspecified XSS
|
|
20955
Description:
(Description Provided by CVE) : Unspecified vulnerability in the administration interface in Uresk Links 2.0 Lite allows remote attackers to bypass authentication via unspecified vectors in index.php.
|
2005-11-17
|
Uresk Links index.php Admin Authentication Bypass
|
|
1129
Description:
URL Live! contains a flaw that allows a remote attacker to access arbitrary files outside of the web path. The issue is due to the server not properly sanitizing user input, specifically traversal style attacks (../../) supplied via the URI.
|
1999-10-28
|
URL Live! Traversal Arbitrary File Access
|
|
47571
Description:
URL Rotator Script contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the 'tr.php' script not properly sanitizing user-supplied input to the 'id' variable. This may allow an attacker to inject or manipulate SQL queries in the back-end database.
|
2008-08-20
|
URL Rotator Script tr.php id Parameter SQL Injection
|
|
83885
Description:
URL Shortener Script contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the show.php script not properly sanitizing user-supplied input to the 'id' parameter. This may allow an attacker to inject or manipulate SQL queries in the back-end database, allowing for the manipulation or disclosure of arbitrary data.
|
2011-10-07
|
URL Shortener Script show.php id Parameter SQL Injection
|