| OSVDB ID | Disclosure Date | Title |
|
51640
Description:
Walking Club contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the login.aspx script not properly sanitizing user-supplied input to the 'username' and 'password' parameters. This may allow an attacker to inject or manipulate SQL queries in the back-end database, allowing for the manipulation or disclosure of arbitrary data.
|
2009-01-16
|
Walking Club login.aspx Multiple Parameter SQL Injection
|
|
20885
Description:
(Description Provided by CVE) : ts.exe (aka ts.cgi) in Walla TeleSite 3.0 and earlier allows remote attackers to access arbitrary local files via the querystring.
|
2005-11-14
|
Walla TeleSite ts.cgi File Existence Enumeration
|
|
20884
Description:
Unknown / Incomplete
|
2005-11-14
|
Walla TeleSite ts.exe Invalid Parameter Path Disclosure
|
|
20883
Description:
Walla TeleSite contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the ts.exe (also know as ts.cgi) script not properly sanitizing user-supplied input to the 'sug' variable. This may allow an attacker to inject or manipulate SQL queries in the back-end database.
|
2005-11-14
|
Walla TeleSite ts.exe sug Parameter SQL Injection
|
|
20882
Description:
Walla TeleSite contains a flaw that allows a remote cross-site scripting (XSS) attack. This flaw exists because the application does not validate the 'sug' parameter upon submission to the 'ts.exe' script. This may allow a user to create a specially crafted URL that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2005-11-14
|
Walla TeleSite ts.exe sug Parameter XSS
|
|
20881
Description:
(Description Provided by CVE) : ts.exe in Walla TeleSite 3.0 and earlier allows remote attackers to access privileged information by entering the article number in tsurl parameter.
|
2005-11-14
|
Walla TeleSite ts.exe tsurl Variable Arbitrary Article Access
|
|
40368
Description:
(Description Provided by CVE) : Multiple SQL injection vulnerabilities in Wallpaper Site 1.0.09 allow remote attackers to execute arbitrary SQL commands via (1) the catid parameter to category.php or (2) the groupid parameter to editadgroup.php.
|
2007-12-22
|
Wallpaper Site category.php catid Parameter SQL Injection
|
|
40369
Description:
(Description Provided by CVE) : Multiple SQL injection vulnerabilities in Wallpaper Site 1.0.09 allow remote attackers to execute arbitrary SQL commands via (1) the catid parameter to category.php or (2) the groupid parameter to editadgroup.php.
|
2007-12-22
|
Wallpaper Site editadgroup.php groupid Parameter SQL Injection
|
|
35986
Description:
Wallpaper Website contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the 'dlwallpaper.php' script not properly sanitizing user-supplied input to the 'wallpaperid' parameter. This may allow an attacker to inject or manipulate SQL queries in the back-end database, allowing for the manipulation or disclosure of arbitrary data.
|
2006-11-24
|
Wallpaper Website dlwallpaper.php wallpaperid Parameter SQL Injection
|
|
35985
Description:
(Description Provided by CVE) : Multiple SQL injection vulnerabilities in Wallpaper Website (Wallpaper Complete Website) 1.0.09 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) login or (2) password parameter to (a) process.php, or the (3) wallpaperid parameter to (b) dlwallpaper.php.
|
2006-11-24
|
Wallpaper Website process.php Multiple Parameter SQL Injection
|
|
30680
Description:
(Description Provided by CVE) : SQL injection vulnerability in wallpaper.php in Wallpaper Website (Wallpaper Complete Website) 1.0.09 allows remote attackers to execute arbitrary SQL commands via the wallpaperid parameter.
|
2006-11-23
|
Wallpaper Website wallpaper.php wallpaperid Parameter SQL Injection
|
|
73217
Description:
(Description Provided by CVE) : WalRack 1.x before 1.1.9 and 2.x before 2.0.7 does not properly restrict file uploads, which allows remote attackers to execute arbitrary PHP code via vectors involving a double extension, as demonstrated by a .php.zzz file.
|
2011-05-26
|
WalRack Unrestricted Double-extension File Upload Arbitrary PHP Code Execution
|
|
73216
Description:
(Description Provided by CVE) : Unspecified vulnerability in WalRack 1.x before 1.1.8 and 2.x before 2.0.6 has unknown impact and attack vectors, possibly related to file deletion and an encoded URL, a different vulnerability than CVE-2011-1329.
|
2011-06-02
|
WalRack Unspecified Issue
|
|
37187
Description:
(Description Provided by CVE) : Unspecified vulnerability in Walter Zorn wz_tooltip.js (aka wz_tooltips) before 4.01, as used by eGroupWare before 1.2.107-2 and other packages, has unknown impact and remote attack vectors.
|
2007-06-08
|
Walter Zorn wz_tooltip.js (aka wz_tooltips) Unspecified Issue
|
|
62481
Description:
WampServer contains a flaw that allows a remote cross site scripting (XSS) attack. This flaw exists because the application does not validate the 'lang' parameter upon submission to the 'index.php' script. This may allow a user to create a specially crafted URL that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2010-02-22
|
WampServer index.php lang Parameter XSS
|
|
85344
Description:
WanEm contains a flaw that may allow an attacker to gain access to unauthorized privileges. The issue is triggered by the dosu binary file being installed setuid root, allowing a local attacker to gain root privileges.
|
2012-08-12
|
WAN Emulator dosu Setuid File Privilege Escalation
|
|
85345
Description:
WanEm contains a flaw related to the result.php script. The issue is triggered when a remote attacker passes an arbitary command via the 'pc' parameter. This may allow an attacker to execute arbitrary commands.
|
2012-08-12
|
WAN Emulator result.php pc Parameter Arbitrary Command Execution
|
|
85346
Description:
WanEM contains a flaw that allows a remote cross-site scripting (XSS) attack. This flaw exists because the application does not validate URI input upon submission to multiple scripts. This may allow a user to create a specially crafted request that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2012-08-12
|
WAN Emulator URI XSS
|
|
21867
Description:
Wandsoft e-Search contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the 'keywords' variable. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2005-12-22
|
WANDSOFT e-SEARCH keywords Parameter XSS
|
|
76230
Description:
WAnewsletter contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the 'index.php' script not properly sanitizing user-supplied input to the 'id' parameter. This may allow an attacker to inject or manipulate SQL queries in the back-end database, allowing for the manipulation or disclosure of arbitrary data.
|
2010-09-23
|
WAnewsletter index.php id Parameter SQL Injection
|
|
38812
Description:
WAnewsletter contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to 'newsletter.php' not properly sanitizing user input supplied to the 'waroot' variable. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script.
|
2007-05-28
|
WAnewsletter newsletter.php waroot Parameter Remote File Inclusion
|
|
83636
Description:
WANGKONGBAO CNS-1000 and 1100 Network Security Platform contains a flaw that allows a remote attacker to traverse outside of a restricted path. The issue is due to the /src/acloglogin.php not properly sanitizing user input, specifically directory traversal style attacks (e.g., ../../) supplied via the 'landid' and 'lang' cookie parameters. This directory traversal attack would allow the attacker to create or access arbitrary files.
|
2012-07-02
|
WANGKONGBAO CNS-1000 / 1100 Network Security Platform /src/acloglogin.php Multiple Parameter Traversal Arbitrary File Creation
|
|
48840
Description:
(Description Provided by CVE) : Multiple race conditions in WANPIPE before 3.3.6 have unknown impact and attack vectors related to "bri restart logic."
|
2008-04-18
|
WANPIPE bri Restart Logic Unspecified Race Condition
|
|
14392
Description:
Unknown / Incomplete
|
2005-02-28
|
WANPIPE Unspecified PCI Related Issue
|
|
33672
Description:
(Description Provided by CVE) : Multiple PHP remote file inclusion vulnerabilities in Wap Portal Server 1.x allow remote attackers to execute arbitrary PHP code via a URL in the language parameter to (1) index.php and (2) admin/index.php.
|
2007-02-03
|
Wap Portal Serve admin/index.php language Parameter Remote File Inclusion
|
|
33671
Description:
(Description Provided by CVE) : Multiple PHP remote file inclusion vulnerabilities in Wap Portal Server 1.x allow remote attackers to execute arbitrary PHP code via a URL in the language parameter to (1) index.php and (2) admin/index.php.
|
2007-02-03
|
Wap Portal Serve index.php language Parameter Remote File Inclusion
|
|
35770
Description:
(Description Provided by CVE) : Multiple PHP remote file inclusion vulnerabilities in Wap Portal Server 1.x allow remote attackers to execute arbitrary PHP code via a URL in the language parameter to (1) index.php and (2) admin/index.php.
|
2007-02-03
|
Wap Portal Server language Multiple Variable File Inclusion
|
|
85951
Description:
WAP Proof 2008 contains a flaw that may allow a remote denial of service. This issue is triggered during the handling of a malformed table element that contains an incorrect integer value for a column attribute, which will result in a loss of availability for the program.
|
2012-09-08
|
WAP Proof 2008 Malformed Table Element Handling DoS
|
|
57426
Description:
(Description Provided by CVE) : Directory traversal vulnerability in gallery/gallery.php in Wap-Motor before 18.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the image parameter.
|
2009-08-27
|
Wap-motor gallery/gallery.php image Parameter Traversal Arbitrary File Access
|
|
90643
Description:
War FTP Daemon contains a flaw that may allow a remote denial of service. The issue is triggered when handling malformed FTP commands. With a specially crafted CDUP command, a remote attacker can cause the program to crash.
|
2013-02-25
|
War FTP Daemon Crafted CDUP Command Handling Remote DoS
|