| OSVDB ID | Disclosure Date | Title |
|
8984
Description:
PlaySMS contains a flaw that will allow an attacker to inject arbitrary SQL code. The problem is that if the magic_quotes_gpc option is disabled, the "vc2" variable in the cookie is not verified properly and will allow an attacker to inject or manipulate SQL queries. (NOTE: Note that setting "magic_quotes_gpc" to "Off" is discouraged by the author of the program in the INSTALL file).
|
2004-08-18
|
PlaySMS Cookie SQL Injection
|
|
8181
Description:
LBE Web HelpDesk contains a flaw that will allow an attacker to inject arbitrary SQL code. The problem is that the 'id' parameter within jobedit.asp is not verified properly and will allow an attacker to inject or manipulate SQL queries.
|
2004-07-22
|
LBE Web HelpDesk jobedit.asp id Parameter SQL Injection
|
|
8180
Description:
Web+Center contains a flaw that may allow a malicious user to add a privelleged user account to the server. The issue is triggered when a user sends a specially crafted SQL statement to the cookie object. It is possible that the flaw may allow the user remote Administrative access, resulting in a loss of integrity.
|
2004-07-22
|
Web+Center DoCustomerOptions.asp Cookie Object SQL Injection
|
|
8168
Description:
Polar HelpDesk contains a flaw that may allow a malicious user to gain access to unauthorized privileges. The issue is triggered when a user sends a specially crafted cookie to the server. This flaw may lead to a loss of integrity.
|
2004-07-22
|
Polar HelpDesk Cookie Modification Privilege Escalation
|
|
8169
Description:
NetSupport DNA HelpDesk contains a flaw that will allow an attacker to inject arbitrary SQL code. The problem is that the 'where' parameter in problist.asp is not verified properly and will allow an attacker to inject or manipulate SQL queries.
|
2004-07-22
|
NetSupport DNA HelpDesk problist.asp where Parameter SQL Injection
|
|
8182
Description:
Serena TeamTrack contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate 'Message' variables upon submission to the 'tmtrack.dll' library. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2004-07-21
|
Serena TeamTrack tmtrack.dll Message Parameter XSS
|
|
8183
Description:
Serena TeamTrack contains a flaw that may allow a malicious user to access unauthorized information. The issue is due to insufficient access control for the "LoginPage drective" of "tmtrack.dll". By sending a specially crafted URL, a remote attacker can enumerate users resulting in a loss of confidentiality.
|
2004-07-21
|
Serena TeamTrack LoginPage User Enumeration
|
|
8170
Description:
HelpBox contains a flaw that will allow a remote attacker to inject arbitrary SQL code. The problem is that the 'sys_comment_id' variable in the 'editcommentenduser.asp' script is not verified properly and will allow an attacker to inject or manipulate SQL queries.
|
2004-07-21
|
HelpBox editcommentenduser.asp sys_comment_id Parameter SQL Injection
|
|
8171
Description:
HelpBox contains a flaw that will allow a remote attacker to inject arbitrary SQL code. The problem is that the 'sys_suspend_id' variable in the 'editsuspensionuser.asp' script is not verified properly and will allow an attacker to inject or manipulate SQL queries.
|
2004-07-21
|
HelpBox editsuspensionuser.asp sys_suspend_id Parameter SQL Injection
|
|
8172
Description:
HelpBox contains a flaw that will allow a remote attacker to inject arbitrary SQL code. The problem is that the 'table' variable in the 'export_data.asp' script is not verified properly and will allow an attacker to inject or manipulate SQL queries.
|
2004-07-21
|
HelpBox export_data.asp table Parameter SQL Injection
|
|
8173
Description:
HelpBox contains a flaw that will allow a remote attacker to inject arbitrary SQL code. The problem is that the 'sys_analgroup' variable in the 'manageanalgrouppreference.asp' script is not verified properly and will allow an attacker to inject or manipulate SQL queries.
|
2004-07-21
|
HelpBox manageanalgrouppreference.asp sys_analgroup Parameter SQL Injection
|
|
8174
Description:
HelpBox contains a flaw that will allow a remote attacker to inject arbitrary SQL code. The problem is that the 'sys_asset_id' variable in the 'quickinfoassetrequests.asp' script is not verified properly and will allow an attacker to inject or manipulate SQL queries.
|
2004-07-21
|
HelpBox quickinfoassetrequests.asp sys_asset_id Parameter SQL Injection
|
|
8175
Description:
HelpBox contains a flaw that will allow a remote attacker to inject arbitrary SQL code. The problem is that the 'sys_eusername' variable in the 'quickinfoenduserrequests.asp' script is not verified properly and will allow an attacker to inject or manipulate SQL queries.
|
2004-07-21
|
HelpBox quickinfoenduserrequests.asp sys_eusername Parameter SQL Injection
|
|
8176
Description:
HelpBox contains a flaw that will allow a remote attacker to inject arbitrary SQL code. The problem is that the 'sys_request_id' variable in the 'requestauditlog.asp' script is not verified properly and will allow an attacker to inject or manipulate SQL queries.
|
2004-07-21
|
HelpBox requestauditlog.asp sys_request_id Parameter SQL Injection
|
|
8177
Description:
HelpBox contains a flaw that will allow a remote attacker to inject arbitrary SQL code. The problem is that the 'sys_request_id' variable in the 'requestcommentsenduser.asp' script is not verified properly and will allow an attacker to inject or manipulate SQL queries.
|
2004-07-21
|
HelpBox requestcommentsenduser.asp sys_request_id Parameter SQL Injection
|
|
8178
Description:
HelpBox contains a flaw that will allow a remote attacker to inject arbitrary SQL code. The problem is that the 'sys_request_id' variable in the 'selectrequestapplytemplate.asp' script is not verified properly and will allow an attacker to inject or manipulate SQL queries.
|
2004-07-21
|
HelpBox selectrequestapplytemplate.asp sys_request_id Parameter SQL Injection
|
|
8179
Description:
HelpBox contains a flaw that will allow a remote attacker to inject arbitrary SQL code. The problem is that the 'sys_request_id' variable in the 'selectrequestlink.asp' script is not verified properly and will allow an attacker to inject or manipulate SQL queries.
|
2004-07-21
|
HelpBox selectrequestlink.asp sys_request_id Parameter SQL Injection
|
|
2155
Description:
Mailtraq contains a flaw that allows a remote attacker to access arbitrary files and directories outside of the web path. The issue is due to the server not properly sanitizing user input, specifically traversal style attacks (../../) supplied via the URI.
|
2003-06-09
|
Mailtraq Arbitrary File/Directory Access
|
|
4089
Description:
Mailtraq contains a flaw that may allow a remote denial of service. The issue is triggered when sending repeated SMTP commands (from, rcpt to, helo) with "%s%p%n" as the argument, and will result in loss of availability for the service.
|
2003-06-09
|
Mailtraq SMTP Commands DoS
|
|
4090
Description:
Mailtraq contains a flaw that may allow a remote denial of service. The issue is triggered when an overly long string is supplied to the username or password field of the logon CGI script, and will result in loss of availability for the service.
|
2003-06-09
|
Mailtraq Logon CGI Long String DoS
|
|
4091
Description:
Mailtraq contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the e-mail subject variables upon submission to the e-mail script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2003-06-09
|
Mailtraq E-mail Subject XSS
|
|
4092
Description:
Mailtraq allows an attacker to trivially decrypt stored passwords. The issue is due to the software using a weak obscuring scheme to protect passwords. Using a short perl script, an attacker can reverse the hash to obtain the password.
|
2003-06-09
|
Mailtraq Weak Password Encryption
|