| OSVDB ID | Disclosure Date | Title |
|
55200
Description:
TorrentTrader contains a flaw that may lead to an unauthorized information disclosure. The issue is triggered by unrestricted access to backup-database.php, which will create a full database backup in an easily-guessed and accessible location which will disclose database contents resulting in a loss of confidentiality.
|
2009-06-15
|
TorrentTrader Classic backup-database.php Direct Request Database Disclosure
|
|
55202
Description:
TorrentTrader contains a flaw that may lead to an unauthorized information disclosure. The issue is triggered by unrestricted access to check.php, which will disclose local installation information resulting in a loss of confidentiality.
|
2009-06-15
|
TorrentTrader Classic check.php Direct Request Information Disclosure
|
|
55203
Description:
TorrentTrader contains a flaw that may lead to an unauthorized information disclosure. The issue is triggered by unrestricted access to the phpinfo.php script, which will disclose local installation information resulting in a loss of confidentiality.
|
2009-06-15
|
TorrentTrader Classic phpinfo.php Direct Request Information Disclosure
|
|
55207
Description:
TorrentTrader contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the report.php script not properly sanitizing user-supplied input to the 'user,' 'torrent,' 'forumid' and 'forumpost' variables. This may allow an attacker to inject or manipulate SQL queries in the back-end database.
|
2009-06-15
|
TorrentTrader Classic report.php Multiple Parameter SQL Injection
|
|
55214
Description:
TorrentTrader contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the 'Title' field upon submission to the requests.php script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2009-06-15
|
TorrentTrader Classic Torrent requests.php Title Field XSS
|
|
55215
Description:
TorrentTrader contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the 'Torrent Name' field upon submission to the torrents-upload.php script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2009-06-15
|
TorrentTrader Classic torrents-upload.php Torrent Name Field XSS
|
|
55218
Description:
TorrentTrader contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate 'CURUSER' and 'SITENAME' variables upon submission to the themes/default/header.php script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2009-06-15
|
TorrentTrader Classic themes/default/header.php Multiple Parameter XSS
|
|
53499
Description:
Unknown / Incomplete
|
2009-01-15
|
MKPortal /modules/blog/index.php upload_imm() Function File Upload Validation Bypass
|
|
20524
Description:
Phorum contains a flaw that may allow a remote attacker to carry out an SQL injection attack. The issue is due to the 'search.php' script not properly sanitizing user-supplied input to the 'forum_ids' variable. This may allow a remote attacker to inject or manipulate SQL queries in the back-end database.
|
2005-11-04
|
Phorum search.php forum_ids Parameter SQL Injection
|
|
11879
Description:
PHPNuke Event Calendar contains a flaw that may lead to an unauthorized information disclosure. The issue is triggered when an attacker directly accesses "config.php" and receives error messages, which will disclose server path information resulting in a loss of confidentiality.
|
2004-11-16
|
PHP-Nuke Event Calendar Module config.php Path Disclosure
|
|
11880
Description:
PHPNuke Event Calendar contains a flaw that may lead to an unauthorized information disclosure. The issue is triggered when an attacker directly accesses "index.php" and receives error messages, which will disclose server path information resulting in a loss of confidentiality.
|
2004-11-16
|
PHP-Nuke Event Calendar Module index.php Path Disclosure
|
|
11881
Description:
PHPNuke Event Calendar contains a flaw that may lead to an unauthorized information disclosure. The issue is triggered when an attacker directly accesses "submit.php" and receives error messages, which will disclose server path information resulting in a loss of confidentiality.
|
2004-11-16
|
PHP-Nuke Event Calendar Module submit.php Path Disclosure
|
|
11882
Description:
PHPNuke Event Calendar contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the "type", "day", "month" and "year" variables upon submission to the "modules.php" script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2004-11-16
|
PHP-Nuke Event Calendar Module Multiple Parameter XSS
|
|
11883
Description:
PHP-Nuke Event Calendar contains a flaw that will allow an attacker to inject arbitrary script. The problem is that the field "event comment" does not suffiiciently sanitize variable, which will allow an attacker to inject arbitrary javascript code.
|
2004-11-16
|
PHP-Nuke Event Calendar Module Comments Field XSS
|
|
11884
Description:
PHP-Nuke Event Calendar contains a flaw that will allow an attacker to inject arbitrary SQL code. The problem is that the "$eid" and "$cid" variables in the "modules.php" module are not verified properly and will allow an attacker to inject or manipulate SQL queries.
|
2004-11-16
|
PHP-Nuke Event Calendar Module Multiple Parameter SQL Injection
|
|
11676
Description:
Phorum contains a flaw that will allow an attacker to inject arbitrary SQL code. The problem is that the thread variable in the follow.php module is not verified properly and will allow an attacker to inject or manipulate SQL queries.
|
2004-11-11
|
Phorum follow.php thread Parameter SQL Injection
|
|
8506
Description:
PHP-Nuke contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate Web_Links, Journal, Stories Archive or Topic Archive variables upon submission to the search script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2004-08-11
|
PHP-Nuke Search Box Multiple Parameter XSS
|
|
7949
Description:
PHP-Nuke contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate input variables upon submission to the Search module. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2004-07-16
|
PHP-Nuke Search Module index.php Multiple Parameter XSS
|
|
7950
Description:
PHP-Nuke contains a flaw that will allow an attacker to inject arbitrary SQL code. The problem is that the instory variable in the Search module is not verified properly and will allow an attacker to inject or manipulate SQL queries.
|
2004-07-16
|
PHP-Nuke Search Module instory Parameter SQL Injection
|
|
7808
Description:
phpBB contains a flaw that may lead to an unauthorized information disclosure. The issue is triggered when a remote attacker provides an invalid argument to the category_rows variable in the index.php script occurs, which will disclose the physical path of the installation resulting in a loss of confidentiality.
|
2004-07-13
|
phpBB index.php category_rows Variable Path Disclosure
|
|
7810
Description:
phpBB contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the category_rows variable upon submission to the index.php script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2004-07-13
|
phpBB index.php category_rows Parameter XSS
|
|
7944
Description:
phpBB contains a flaw that may lead to an unauthorized information disclosure. The issue is triggered when a remote attacker provides an invalid argument to the faq variable in the language\lang_english\lang_faq.php script occurs, which will disclose the physical path of the installation resulting in a loss of confidentiality.
|
2004-07-13
|
phpBB lang_faq.php faq Variable Path Disclosure
|
|
7945
Description:
phpBB contains a flaw that may lead to an unauthorized information disclosure. The issue is triggered when a remote attacker provides an invalid argument to the faq variable in the language\lang_english\lang_bbcode.php script occurs, which will disclose the physical path of the installation resulting in a loss of confidentiality.
|
2004-07-13
|
phpBB lang_bbcode.php Path Disclosure
|
|
7946
Description:
phpBB contains a flaw that may lead to an unauthorized information disclosure. The issue is triggered when a remote attacker provides an invalid argument to the ranksrow variable in the includes\usercp_viewprofile.php script occurs, which will disclose the physical path of the installation resulting in a loss of confidentiality.
|
2004-07-13
|
phpBB usercp_viewprofile.php ranksrow Variable Path Disclosure
|
|
7947
Description:
phpBB contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the "faq" variable upon submission to the lang_faq.php script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2004-07-13
|
phpBB lang_faq.php faq Parameter XSS
|
|
7948
Description:
phpBB contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the "faq" variable upon submission to the lang_bbcode.php script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2004-07-13
|
phpBB lang_bbcode.php faq Parameter XSS
|
|
7223
Description:
PHP-Nuke contains a flaw that may lead to an unauthorized information disclosure. The issue is triggered when a remote attacker requests an invalid parameter of the voteinclude.php file in the Web Links module, which will disclose the physical path of the web server resulting in a loss of confidentiality.
|
2004-06-23
|
PHP-Nuke Web_Links Module voteinclude.php Path Disclosure
|
|
7224
Description:
PHP-Nuke contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the "jid" variable upon submission to the "delete.php" script in the Journal module. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2004-06-23
|
PHP-Nuke Journal Module delete.php jid Parameter XSS
|
|
7225
Description:
PHP-Nuke contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the "onwhat" variable upon submission to the "comment.php" script in the Journal module. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2004-06-23
|
PHP-Nuke Journal Module comment.php onwhat Parameter XSS
|
|
7226
Description:
PHP-Nuke contains a flaw that may lead to an unauthorized information disclosure. The issue is triggered when a remote attacker requests an invalid parameter of the convert_month() function of the Statistics module, which will disclose the physical path of the web server resulting in a loss of confidentiality.
|
2004-06-23
|
PHP-Nuke Statistics Module convert_month() Function Path Disclosure
|
|
7227
Description:
PHP-Nuke contains a flaw that may lead to an unauthorized information disclosure. The issue is triggered when a remote attacker requests an invalid parameter of the add.php file in the Journal module, which will disclose the physical path of the web server resulting in a loss of confidentiality.
|
2004-06-23
|
PHP-Nuke Journal Module add.php Path Disclosure
|
|
7228
Description:
PHP-Nuke contains a flaw that may lead to an unauthorized information disclosure. The issue is triggered when a remote attacker requests an invalid parameter of the modify.php file in the Journal module, which will disclose the physical path of the web server resulting in a loss of confidentiality.
|
2004-06-23
|
PHP-Nuke Journal Module modify.php Path Disclosure
|
|
7229
Description:
PHP-Nuke contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the "yun" or "ye" variables upon submission to the "friend.php" script in the Journal module. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2004-06-23
|
PHP-Nuke Journal Module friend.php Multiple Parameter XSS
|
|
7230
Description:
PHP-Nuke contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the "filelist" variable upon submission to the "add.php" script in the Journal module. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2004-06-23
|
PHP-Nuke Journal Module add.php filelist Parameter XSS
|
|
7231
Description:
PHP-Nuke contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the "filelist" variable upon submission to the "modify.php" script in the Journal module. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2004-06-23
|
PHP-Nuke Journal Module modify.php filelist Parameter XSS
|
|
7232
Description:
PHP-Nuke contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the "rid" variable upon submission to the "commentsave.php" script in the Journal module. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2004-06-23
|
PHP-Nuke Journal Module commentsave.php rid Parameter XSS
|
|
7233
Description:
PHP-Nuke contains a flaw that will allow an attacker to inject arbitrary SQL code. The problem is that the "forwhat" variable in the Journal module search.php script is not verified properly and will allow an attacker to inject or manipulate SQL queries.
|
2004-06-23
|
PHP-Nuke Journal Module search.php SQL Injection
|
|
7234
Description:
PHP-Nuke contains a flaw that may allow a remote attacker to inject arbitrary javascript in a journal entry. The flaw is due to the Journal module not properly sanitize journal entry input. By creating a new journal entry with malicious java script, an attacker can have it executed under arbitrary privileges when another user attempts to list or read the journal entry.
|
2004-06-23
|
PHP-Nuke Journal Module Java Script Injection
|
|
7235
Description:
PHP-Nuke contains a flaw that may allow a remote attacker to delete arbitrary journal entries. The flaw is due to the Journal module not properly checking for authentication credentials during a request to the commentkill.php script. If an attacker directly requests the script via a GET request, he can delete any journal entry.
|
2004-06-23
|
PHP-Nuke Journal Module commentkill.php Arbitrary Comment Deletion
|
|
7236
Description:
PHP-Nuke contains a flaw that may allow a remote attacker to insert arbitrary journal entries. The flaw is due to the Journal module not properly checking for authentication credentials during a request to the savenew.php script. If an attacker directly requests the script via a GET request, he can insert a new journal entry without authenticating.
|
2004-06-23
|
PHP-Nuke Journal Module savenew.php Arbitrary Entry Insertion
|