| OSVDB ID | Disclosure Date | Title |
|
27358
Description:
(Description Provided by CVE) : Cross-site scripting (XSS) vulnerability in Zoho Virtual Office 3.2 Build 3210 allows remote attackers to execute arbitrary web script or HTML via an HTML message.
|
2006-07-17
|
Zoho Virtual Office HTML Message XSS
|
|
39550
Description:
(Description Provided by CVE) : Zoidcom 0.6.7 and earlier allows remote attackers to cause a denial of service (application crash) via a JOIN packet (aka connection packet) containing 0x69 in the ninth byte, which triggers a "double-delete" of trace data, a different vulnerability than CVE-2005-1643.
|
2007-08-14
|
Zoidcom JOIN Packet Double-free Remote DoS
|
|
16495
Description:
A remote overflow exists in Zoidcom. The ZCom_Bitstream::Deserialize function fails to validate packet size data resulting in a buffer overflow. With a specially crafted request, an attacker can cause denial of service resulting in a loss of availability.
|
2005-05-10
|
Zoidcom ZCom_BitStream::Deserialize Function Remote Overflow DoS
|
|
59047
Description:
(Description Provided by CVE) : ZoIPer 2.22, and possibly other versions before 2.24 Library 5324, allows remote attackers to cause a denial of service (crash) via a SIP INVITE request with an empty Call-Info header.
|
2009-10-14
|
ZoIPer Crafted SIP INVITE Request Remote DoS
|
|
55104
Description:
Zoki Catalog contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the 'system/application/controllers/catalog.php' script not properly sanitizing user-supplied input to the 'search_text' parameter. This may allow an attacker to inject or manipulate SQL queries in the back-end database.
|
2009-06-15
|
Zoki Catalog system/application/controllers/catalog.php search_text Parameter SQL Injection
|
|
64507
Description:
Zolsoft Office Server contains a flaw that allows a remote Cross-site Request Forgery (CSRF / XSRF) attack. The flaw exists because the application does not require multiple steps or explicit confirmation for sensitive transactions for the manipulation of a user's password. By using a crafted URL (e.g., a crafted GET request inside an "img" tag), an attacker may trick the victim into clicking on the image to take advantage of the trust relationship between the authenticated victim and the application. Such an attack could trick the victim into executing arbitrary commands in the context of their session with the application, without further prompting or verification.
|
2010-05-06
|
Zolsoft Office Server User Password Manipulation CSRF
|
|
83854
Description:
Zom-Mail is prone to an overflow condition. The program fails to properly sanitize user-supplied input resulting in a buffer overflow. With an overly long name of a file attachment, a remote attacker can potentially execute arbitrary code.
|
1999-11-02
|
Zom-Mail File Attachment Name Handling Remote Overflow
|
|
71318
Description:
Zomplog contains a flaw that allows a remote cross-site scripting (XSS) attack. This flaw exists because the application does not validate the 'id' parameter upon submission to the /admin/editor_pages.php script. This may allow a user to create a specially crafted URL that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2010-10-27
|
Zomplog /admin/editor_pages.php id Parameter XSS
|
|
71317
Description:
Zomplog contains a flaw that allows a remote cross-site scripting (XSS) attack. This flaw exists because the application does not validate the 'weblog_subtitle' parameter upon submission to the /admin/settings.php script. This may allow a user to create a specially crafted URL that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2010-10-27
|
Zomplog /admin/settings.php weblog_subtitle Parameter XSS
|
|
71319
Description:
Zomplog contains a flaw that allows a remote cross-site scripting (XSS) attack. This flaw exists because the application does not validate the 'about' parameter upon submission to the /admin/settings_menu.php script. This may allow a user to create a specially crafted URL that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2010-10-27
|
Zomplog /admin/settings_menu.php about Parameter XSS
|
|
71320
Description:
Zomplog contains a flaw that allows a remote Cross-site Request Forgery (CSRF / XSRF) attack. The flaw exists because the /admin/users.php script does not require multiple steps or explicit confirmation for sensitive transactions for the creation of users. By using a crafted URL (e.g., a crafted GET request inside an "img" tag), an attacker may trick the victim into clicking on the image to take advantage of the trust relationship between the authenticated victim and the application. Such an attack could trick the victim into executing arbitrary commands in the context of their session with the application, without further prompting or verification.
|
2010-10-27
|
Zomplog /admin/users.php Arbitrary User Creation CSRF
|
|
44808
Description:
Zomplog contains a flaw that allows a remote cross site scripting (XSS) attack. This flaw exists because the application does not validate the 'catname' parameter upon submission to the 'admin/category.php' script. This may allow a user to create a specially crafted URL that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2008-05-02
|
Zomplog admin/category.php catname Parameter XSS
|
|
41410
Description:
(Description Provided by CVE) : Unrestricted file upload vulnerability in admin/upload_files.php in Zomplog 3.8.1 and earlier allows remote authenticated administrators to upload and execute arbitrary .php files by sending a modified MIME type. NOTE: this can be exploited by unauthenticated attackers by leveraging CVE-2007-5230.
|
2007-09-28
|
Zomplog admin/upload_files.php Crafted MIME Type Arbitrary File Upload
|
|
41409
Description:
(Description Provided by CVE) : admin/upload_files.php in Zomplog 3.8.1 and earlier does not check for administrative credentials, which allows remote attackers to perform administrative actions via a direct request. NOTE: this can be leveraged for code execution by exploiting CVE-2007-5231.
|
2007-09-28
|
Zomplog admin/upload_files.php Direct Request Administrator Credential Bypass
|
|
67214
Description:
Zomplog contains a flaw that allows a remote cross site scripting (XSS) attack. This flaw exists because the application does not validate the 'message' parameter upon submission to the 'category.php' script. This may allow a user to create a specially crafted URL that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2010-08-15
|
Zomplog category.php message Parameter XSS
|
|
67221
Description:
Zomplog contains a flaw that allows a remote cross site scripting (XSS) attack. This flaw exists because the application does not validate the 'message' parameter upon submission to the 'changeclothes.php' script. This may allow a user to create a specially crafted URL that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2010-08-15
|
Zomplog changeclothes.php message Parameter XSS
|
|
67217
Description:
Zomplog contains a flaw that allows a remote cross site scripting (XSS) attack. This flaw exists because the application does not validate the 'message' parameter upon submission to the 'comments.php' script. This may allow a user to create a specially crafted URL that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2010-08-15
|
Zomplog comments.php message Parameter XSS
|
|
20250
Description:
Zomplog contains a flaw that may allow a remote attacker to carry out an SQL injection attack. The issue is due to the 'detail.php' script not properly sanitizing user-supplied input to the 'id' variable. This may allow a remote attacker to inject or manipulate SQL queries in the back-end database.
|
2005-10-20
|
Zomplog detail.php id Parameter SQL Injection
|
|
20253
Description:
Zomplog contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the 'name' variable upon submission to the 'detail.php' script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2005-10-20
|
Zomplog detail.php name Parameter XSS
|
|
41411
Description:
(Description Provided by CVE) : Zomplog 3.8.1 and earlier stores potentially sensitive information under the web root with insufficient access control, which allows remote attackers to download files that were uploaded by users, as demonstrated by obtaining a directory listing via a direct request to /upload and then retrieving individual files. NOTE: in a non-default configuration, the directory listing is denied, but filenames may be predicable.
|
2007-09-28
|
Zomplog Direct Request Uploaded File Access
|
|
67215
Description:
Zomplog contains a flaw that allows a remote cross site scripting (XSS) attack. This flaw exists because the application does not validate the 'message' parameter upon submission to the 'entry.php' script. This may allow a user to create a specially crafted URL that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2010-08-15
|
Zomplog entry.php message Parameter XSS
|
|
20251
Description:
Zomplog contains a flaw that may allow a remote attacker to carry out an SQL injection attack. The issue is due to the 'get.php' script not properly sanitizing user-supplied input to the 'catid' variable. This may allow a remote attacker to inject or manipulate SQL queries in the back-end database.
|
2005-10-20
|
Zomplog get.php catid Parameter SQL Injection
|
|
20254
Description:
Zomplog contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the 'username' variable upon submission to the 'get.php' script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2005-10-20
|
Zomplog get.php username Parameter XSS
|
|
20252
Description:
Zomplog contains a flaw that may allow a remote attacker to carry out an SQL injection attack. The issue is due to the 'index.php' script not properly sanitizing user-supplied input to the 'catid' variable. This may allow a remote attacker to inject or manipulate SQL queries in the back-end database.
|
2005-10-20
|
Zomplog index.php catid Parameter SQL Injection
|
|
20255
Description:
Zomplog contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the 'search' variable upon submission to the 'index.php' script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2005-10-20
|
Zomplog index.php search Parameter XSS
|
|
45513
Description:
(Description Provided by CVE) : Zomplog 3.8.2 and earlier allows remote attackers to gain administrative access by creating an admin account via a direct request to install/newuser.php with the admin parameter set to 1.
|
2008-05-16
|
Zomplog install/newuser.php admin Variable Direct Request Authentication Bypass
|
|
35017
Description:
(Description Provided by CVE) : SQL injection vulnerability in plugins/mp3playlist/mp3playlist.php in Zomplog 3.8 and earlier allows remote attackers to execute arbitrary SQL commands via the speler parameter.
|
2007-05-20
|
Zomplog mp3playlist.php speler Parameter SQL Injection
|
|
67225
Description:
Zomplog contains a flaw that allows a remote Cross-site Request Forgery (CSRF / XSRF) attack. The flaw exists because the application does not require multiple steps or explicit confirmation for sensitive transactions such as add an administrative user or change an administrator's password. By using a crafted URL (e.g., a crafted GET request inside an "img" tag), an attacker may trick the victim into clicking on the image to take advantage of the trust relationship between the authenticated victim and the application. Such an attack could trick the victim into executing arbitrary commands in the context of their session with the application, without further prompting or verification.
|
2010-08-15
|
Zomplog Multiple Admin Functions CSRF
|
|
67216
Description:
Zomplog contains a flaw that allows a remote cross site scripting (XSS) attack. This flaw exists because the application does not validate the 'message' parameter upon submission to the 'newentry.php' script. This may allow a user to create a specially crafted URL that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2010-08-15
|
Zomplog newentry.php message Parameter XSS
|
|
67218
Description:
Zomplog contains a flaw that allows a remote cross site scripting (XSS) attack. This flaw exists because the application does not validate the 'message' parameter upon submission to the 'newpage.php' script. This may allow a user to create a specially crafted URL that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2010-08-15
|
Zomplog newpage.php message Parameter XSS
|