| OSVDB ID | Disclosure Date | Title |
|
57515
Description:
(Description Provided by CVE) : Microsoft Internet Explorer 6 through 8 allows remote attackers to spoof the address bar, via window.open with a relative URI, to show an arbitrary URL on the web site visited by the victim, as demonstrated by a visit to an attacker-controlled web page, which triggers a spoofed login form for the site containing that page.
|
2009-08-15
|
Microsoft IE window.open() New Window URL Path Spoofing Weakness
|
|
57754
Description:
(Description Provided by CVE) : K-Meleon 1.5.3 allows context-dependent attackers to spoof the address bar, via window.open with a relative URI, to show an arbitrary file: URL after a victim has visited any file: URL, as demonstrated by a visit to a file: document written by the attacker.
|
2009-08-15
|
K-Meleon window.open() New Window URL Path Spoofing Weakness
|
|
57758
Description:
(Description Provided by CVE) : Mozilla Firefox 3.5.1 and SeaMonkey 1.1.17, and Flock 2.5.1, allow context-dependent attackers to spoof the address bar, via window.open with a relative URI, to show an arbitrary file: URL after a victim has visited any file: URL, as demonstrated by a visit to a file: document written by the attacker.
|
2009-08-15
|
Mozilla Multiple Browsers window.open() New Window URL Path Spoofing Weakness
|
|
57759
Description:
(Description Provided by CVE) : Mozilla Firefox 3.5.1 and SeaMonkey 1.1.17, and Flock 2.5.1, allow context-dependent attackers to spoof the address bar, via window.open with a relative URI, to show an arbitrary file: URL after a victim has visited any file: URL, as demonstrated by a visit to a file: document written by the attacker.
|
2009-08-15
|
Flock Browser window.open() New Window URL Path Spoofing Weakness
|
|
57756
Description:
(Description Provided by CVE) : Lunascape 5.1.3 and 5.1.4 allows remote attackers to spoof the address bar, via window.open with a relative URI, to show an arbitrary URL on the web site visited by the victim, as demonstrated by a visit to an attacker-controlled web page, which triggers a spoofed login form for the site containing that page. NOTE: a related attack was reported in which an arbitrary file: URL is shown.
|
2009-08-15
|
Lunascape window.open() New Window URL Path Spoofing Weakness
|
|
57748
Description:
Multiple web browsers contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate and allow the attacker to spoof the URL or content from a non existing file or path. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2009-08-15
|
Avant Browser window.open Relative URI Address Bar Spoofing Weakness
|
|
56651
Description:
Avant Browser contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate 'Most Visited','History' and 'Recently Bookmarked' sections upon submission to the 'Browser:home' dynamic content. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the 'Browser:home' dynamic content, leading to a loss of integrity.
|
2009-07-30
|
Avant Browser browser:home Multiple Section XSS
|
|
56238
Description:
By default, COMTREND HG-536 routers install with multiple default passwords. The 'user' account has a password of 'user', the 'support' account has a password of 'support' and the 'admin' account has a default password of 'admin', which are publicly known and documented. This allows attackers to trivially access the program or system.
|
2009-04-27
|
COMTREND HG-536 Multiple Default Accounts
|
|
52491
Description:
Unknown / Incomplete
|
2009-01-31
|
Apple Safari for Windows Multiple Protocol Handler Null Dereference DoS
|
|
52490
Description:
(Description Provided by CVE) : Apple Safari 3.2.1 (aka AppVer 3.525.27.1) on Windows allows remote attackers to cause a denial of service (infinite loop or access violation) via a link to an http URI in which the authority (aka hostname) portion is either a (1) . (dot) or (2) .. (dot dot) sequence.
|
2009-01-27
|
Apple Safari for Windows http URI Handler Malformed Domain Name DoS
|
|
49556
Description:
DHCart contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate 'domain' and 'd1' variables upon submission to the 'order.php' script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2008-11-04
|
DHCart order.php Multiple Parameter XSS
|
|
57065
Description:
Unknown / Incomplete
|
2008-09-29
|
Google Chrome window.open DMK.alert DoS
|
|
57066
Description:
Unknown / Incomplete
|
2008-09-29
|
Apple Safari window.open DMK.alert DoS
|
|
49128
Description:
(Description Provided by CVE) : Stack-based buffer overflow in Safer Networking FileAlyzer 1.6.0.0 and 1.6.0.4 beta, and possibly other versions, allows user-assisted remote attackers to execute arbitrary code via an executable with malformed version data.
|
2008-09-28
|
FileAlyzer Malformed Executable Version Data Overflow
|
|
48265
Description:
Unknown / Incomplete
|
2008-09-20
|
Google Chrome tab_strip_model.cc Malformed Content DoS
|
|
51685
Description:
Avant Browser contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate URI dialog 'about:'. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2008-09-05
|
Avant Browser URI about: Dialog XSS
|
|
51686
Description:
Maxthon Browser contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the URI dialog 'about:'. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship
|
2008-09-05
|
Maxthon Browser URI about: Dialog XSS
|
|
47802
Description:
PopnupBlog Module for XOOPS contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate 'cat_id' and 'view' variables upon submission to the 'index.php' script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2008-08-25
|
PopnupBlog Module for XOOPS index.php Multiple Parameter XSS
|
|
47560
Description:
PHPizabi contains a flaw that allows a remote attacker to arbitrary file access outside of the web path. The issue is due to the 'index.php' script not properly sanitizing user input, specifically directory traversal style attacks (../../) supplied via the 'id' variable(s)wen 'L' param is set to 'admin.templates.edittemplate'.
|
2008-08-15
|
PHPizabi index.php id Parameter Traversal Arbitrary File Access
|
|
47561
Description:
PHPizabi contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the 'query' variable upon submission to the 'index.php' script, when the 'L' param is set to 'blogs.search'. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2008-08-15
|
PHPizabi index.php query Parameter XSS
|
|
47641
Description:
Yogurt Social Network contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate 'uid' variables upon submission to the 'friends.php' script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2008-08-09
|
Yogurt Social Network Module for XOOPS friends.php uid Parameter XSS
|
|
47642
Description:
Yogurt Social Network contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate 'uid' variables upon submission to the 'seutubo.php' script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2008-08-09
|
Yogurt Social Network Module for XOOPS seutubo.php uid Parameter XSS
|
|
47643
Description:
Yogurt Social Network contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate 'uid' variables upon submission to the 'album.php' script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2008-08-09
|
Yogurt Social Network Module for XOOPS album.php uid Parameter XSS
|
|
47644
Description:
Yogurt Social Network contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate 'uid' variables upon submission to the 'scrapbook.php' script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2008-08-09
|
Yogurt Social Network Module for XOOPS scrapbook.php uid Parameter XSS
|
|
47645
Description:
Yogurt Social Network contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate 'uid' variable upon submission to the 'index.php' script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2008-08-09
|
Yogurt Social Network Module for XOOPS index.php uid Parameter XSS
|
|
47646
Description:
Yogurt Social Network contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate 'uid' variables upon submission to the 'tribes.php' script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2008-08-09
|
Yogurt Social Network Module for XOOPS tribes.php uid Parameter XSS
|
|
47647
Description:
(Description Provided by CVE) : Multiple cross-site scripting (XSS) vulnerabilities in the Yogurt Social Network module 3.2 rc1 for XOOPS allow remote attackers to inject arbitrary web script or HTML via the uid parameter to (1) friends.php, (2) seutubo.php, (3) album.php, (4) scrapbook.php, (5) index.php, or (6) tribes.php; or (7) the description field of a new scrap.
|
2008-08-09
|
Yogurt Social Network Module for XOOPS New Scrap Description Field XSS
|
|
48841
Description:
(Description Provided by CVE) : Multiple cross-site scripting (XSS) vulnerabilities in the RMSOFT Downloads Plus (rmdp) module 1.5 and 1.7 for Xoops allow remote attackers to inject arbitrary web script or HTML via the (1) key parameter to search.php and the (2) id parameter to down.php.
|
2008-08-09
|
RMSOFT Downloads Plus (rmdp) Module for XOOPS search.php key Parameter XSS
|
|
48842
Description:
(Description Provided by CVE) : Multiple cross-site scripting (XSS) vulnerabilities in the RMSOFT Downloads Plus (rmdp) module 1.5 and 1.7 for Xoops allow remote attackers to inject arbitrary web script or HTML via the (1) key parameter to search.php and the (2) id parameter to down.php.
|
2008-08-09
|
RMSOFT Downloads Plus (rmdp) Module for XOOPS down.php id Parameter XSS
|
|
48843
Description:
RMSOFT MiniShop Module for XOOPS contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the 'search.php' script not properly sanitizing user-supplied input to the 'itemsxpag' parameter. This may allow an attacker to inject or manipulate SQL queries in the back-end database.
|
2008-08-09
|
RMSOFT MiniShop Module for XOOPS search.php itemsxpag Parameter SQL Injection
|
|
48849
Description:
(Description Provided by CVE) : Cross-site scripting (XSS) vulnerability in search.php in the RMSOFT MiniShop module 1.0 for Xoops allows remote attackers to inject arbitrary web script or HTML via the itemsxpag parameter.
|
2008-08-09
|
RMSOFT MiniShop Module for XOOPS search.php itemsxpag Parameter XSS
|
|
47343
Description:
Kshop contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate 'search' variables upon submission to the 'Kshop_search.php' script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2008-08-06
|
Kshop Module for Xoops kshop_search.php search Parameter XSS
|
|
51469
Description:
gTalk contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate 'mailto:' and 'http:' autolinks upon submission to Message Body. This could allow a user to create a specially crafted Message Body that would execute arbitrary code in a user's gTalk within the trust relationship between the client and the server, leading to a loss of integrity.
|
2008-06-25
|
Google Talk (gTalk) Message Body XSS
|
|
45338
Description:
bcoos contains a flaw that allows a remote attacker to access to all files with extension outside of the web path. The issue is due to the 'highlight.php' not properly sanitizing user input, specifically directory traversal style attacks (../../) or full fisical path supplied via the 'file' variable(s).
|
2008-05-18
|
bcoos highlight.php file Parameter Arbitrary File Access
|
|
44334
Description:
bcoos contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate 'order_by' & 'direction' variables upon submission to the index.php script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2008-02-04
|
bcoos DevTracker Module Multiple Parameter XSS
|
|
44335
Description:
(Description Provided by CVE) : Multiple cross-site scripting (XSS) vulnerabilities in index.php in DevTracker module 3.0 for bcoos 1.1.11 and earlier, and DevTracker module 0.20 for E-XooPS 1.0.8 and earlier, allow remote attackers to inject arbitrary web script or HTML via the (1) direction and (2) order_by parameters.
|
2008-02-04
|
E-xoops DevTracker Module Multiple Parameter XSS
|
|
40190
Description:
PHCDownload contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate 'string' variables upon submission to the 'search.php' script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2007-12-28
|
PHCDownload search.php string Parameter XSS
|
|
43681
Description:
e-Xoops contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the 'modules/mylinks/ratelink.php' script not properly sanitizing user-supplied input to the 'lid' variable. This may allow an attacker to inject or manipulate SQL queries in the back-end database.
|
2007-12-09
|
e-Xoops mylinks/ratelink.php lid Parameter SQL Injection
|
|
43679
Description:
e-Xoops contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the 'modules/adresses/ratefile.php' script not properly sanitizing user-supplied input to the 'lid' variable. This may allow an attacker to inject or manipulate SQL queries in the back-end database.
|
2007-12-09
|
e-Xoops adresses/ratefile.php lid Parameter SQL Injection
|
|
43680
Description:
e-Xoops contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the 'modules/mydownloads/ratefile.php' script not properly sanitizing user-supplied input to the 'lid' variable. This may allow an attacker to inject or manipulate SQL queries in the back-end database.
|
2007-12-09
|
e-Xoops mydownloads/ratefile.php lid Parameter SQL Injection
|