| OSVDB ID | Disclosure Date | Title |
|
18965
Description:
A local overflow exists in Linux ifenslave. The utility fails to validate the length of command line options resulting in a buffer overflow. With a specially crafted request, an attacker can cause execution of arbitrary code with root privileges resulting in a loss of integrity.
|
2005-07-12
|
Linux ifenslave Local Overflow
|
|
18441
Description:
Dragonfly Commerce contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the dc_Categoriesview.asp script not properly sanitizing user-supplied input to the 'key' variable. This may allow an attacker to inject or manipulate SQL queries in the back-end database.
|
2005-07-12
|
Dragonfly Commerce dc_Categoriesview.asp key Parameter SQL Injection
|
|
18442
Description:
Dragonfly Commerce contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the dc_productslist_Clearance.asp script not properly sanitizing user-supplied input. This may allow an attacker to inject or manipulate SQL queries in the back-end database.
|
2005-07-12
|
Dragonfly Commerce dc_productslist_Clearance.asp SQL Injection
|
|
18443
Description:
Dragonfly Commerce contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the ratings.asp script not properly sanitizing user-supplied input to the 'PID' variable. This may allow an attacker to inject or manipulate SQL queries in the back-end database.
|
2005-07-12
|
Dragonfly Commerce ratings.asp PID Parameter SQL Injection
|
|
18444
Description:
Dragonfly Commerce contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the dc_Productsview.asp script not properly sanitizing user-supplied input. This may allow an attacker to inject or manipulate SQL queries in the back-end database.
|
2005-07-12
|
Dragonfly Commerce dc_Productsview.asp SQL Injection
|
|
18445
Description:
Dragonfly Commerce contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the dc_forum_Postslist.asp script not properly sanitizing user-supplied input to the 'start', 'key_mp', 'searchtype', or 'psearch' variable. This may allow an attacker to inject or manipulate SQL queries in the back-end database.
|
2005-07-12
|
Dragonfly Commerce dc_forum_Postslist.asp SQL Injection
|
|
18446
Description:
Dragonfly Commerce contains a flaw that may allow a remote attacker to manipulate prices without authorization. The issue is due to the dc_Categoriesview.asp script not properly sanitizing user input. By modifying the 'x_DragonflyCartProductPrice' hidden field before submission, it is possible for an attacker to manipulate prices in the system before purchasing an item.
|
2005-07-12
|
Dragonfly Commerce dc_Categoriesview.asp Hidden Field Modification Product Price Manipulation
|
|
18447
Description:
Dragonfly Commerce contains a flaw that may allow a remote attacker to manipulate prices without authorization. The issue is due to the dc_productslist.asp script not properly sanitizing user input. By modifying the 'x_DragonflyCartProductPrice' hidden field before submission, it is possible for an attacker to manipulate prices in the system before purchasing an item.
|
2005-07-12
|
Dragonfly Commerce dc_productslist.asp Hidden Field Modification Product Price Manipulation
|
|
18448
Description:
Dragonfly Commerce contains a flaw that may allow a remote attacker to manipulate prices without authorization. The issue is due to the dc_productslist_Clearance.asp script not properly sanitizing user input. By modifying the 'x_DragonflyCartProductPrice' hidden field before submission, it is possible for an attacker to manipulate prices in the system before purchasing an item.
|
2005-07-12
|
Dragonfly Commerce dc_productslist_Clearance.asp Hidden Field Modification Product Price Manipulation
|
|
18449
Description:
Dragonfly Commerce contains a flaw that may allow a remote attacker to manipulate prices without authorization. The issue is due to the dc_Categorieslist.asp script not properly sanitizing user input. By modifying the 'x_DragonflyCartProductPrice' hidden field before submission, it is possible for an attacker to manipulate prices in the system before purchasing an item.
|
2005-07-12
|
Dragonfly Commerce dc_Categorieslist.asp Hidden Field Modification Product Price Manipulation
|
|
17972
Description:
Comersus Cart contains a flaw that may allow a remote attacker to carry out an SQL injection attack. The issue is due to the 'comersus_optAffiliateRegistrationExec.asp' script not properly sanitizing user-supplied input to the 'email' variable. This may allow a remote attacker to inject or manipulate SQL queries in the back-end database.
|
2005-07-07
|
Comersus comersus_optAffiliateRegistrationExec.asp email Parameter SQL Injection
|
|
17973
Description:
Comersus Cart contains a flaw that may allow a remote attacker to carry out an SQL injection attack. The issue is due to the 'comersus_optReviewReadExec.asp' script not properly sanitizing user-supplied input to the 'idProduct' variable. This may allow a remote attacker to inject or manipulate SQL queries in the back-end database.
|
2005-07-07
|
Comersus comersus_optReviewReadExec.asp idProduct Parameter SQL Injection
|
|
17974
Description:
Comersus Cart contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate 'name' variables upon submission to the 'comersus_backoffice_listAssignedPricesToCustomer.asp' script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2005-07-07
|
Comersus comersus_backoffice_listAssignedPricesToCustomer.asp name Parameter XSS
|
|
17975
Description:
Comersus Cart contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the 'message' variable upon submission to the 'comersus_backoffice_message.asp' script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2005-07-07
|
Comersus comersus_backoffice_message.asp message Parameter XSS
|
|
17976
Description:
CartWIZ contains a flaw that may allow a remote attacker to carry out an SQL injection attack. The issue is due to the 'tellAFriend.asp' script not properly sanitizing user-supplied input to the 'idProduct' variable. This may allow a remote attacker to inject or manipulate SQL queries in the back-end database.
|
2005-07-07
|
CartWIZ tellAFriend.asp idProduct Parameter SQL Injection
|
|
17977
Description:
CartWIZ contains a flaw that may allow a remote attacker to carry out an SQL injection attack. The issue is due to the 'viewSupportTickets.asp' script not properly sanitizing user-supplied input to the 'sortType' variable. This may allow a remote attacker to inject or manipulate SQL queries in the back-end database.
|
2005-07-07
|
CartWIZ viewSupportTickets.asp sortType Parameter SQL Injection
|
|
17978
Description:
CartWIZ contains a flaw that may allow a remote attacker to carry out an SQL injection attack. The issue is due to the 'updateCreditCards.asp' script not properly sanitizing user-supplied input to the 'id' variable. This may allow a remote attacker to inject or manipulate SQL queries in the back-end database.
|
2005-07-07
|
CartWIZ updateCreditCards.asp id Parameter SQL Injection
|
|
17979
Description:
CartWIZ contains a flaw that may allow a remote attacker to carry out an SQL injection attack. The issue is due to the 'deleteCreditCards.asp' script not properly sanitizing user-supplied input to the 'id' variable. This may allow a remote attacker to inject or manipulate SQL queries in the back-end database.
|
2005-07-07
|
CartWIZ deleteCreditCards.asp id Parameter SQL Injection
|
|
17980
Description:
CartWIZ contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the 'message' variable upon submission to the 'login.asp' script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2005-07-07
|
CartWIZ login.asp message Parameter XSS
|
|
17788
Description:
phpWebSite contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the index.php script not properly sanitizing user-supplied input to the 'Search' module. This may allow an attacker to inject or manipulate SQL queries in the back-end database.
|
2005-07-07
|
phpWebSite index.php Search Module Multiple Parameter SQL Injection
|
|
17789
Description:
phpWebSite contains a flaw that allows a remote attacker to read files outside of the web path. The issue is due to the index.php script not properly sanitizing user input, specifically traversal style attacks (../../) supplied via the 'Search' module 'mod' variable.
|
2005-07-07
|
phpWebSite index.php Search Module mod Parameter Traversal Arbitrary File Access
|
|
16731
Description:
PhotoPost contains a flaw that may allow a remote attacker to inject arbitrary SQL queries. The issue is due to the 'uid' variable in the 'member.php' script not being properly sanitized and may allow a remote attacker to inject or manipulate SQL queries.
|
2005-05-13
|
PhotoPost PHP Pro member.php uid Parameter SQL Injection
|
|
16179
Description:
ArticleLive contains a flaw that may allow a remote attacker to gain administrative privileges. The issue can be exploited in one of two ways. First, by providing a malformed request to the /admin/ routines, an attacker may bypass the authentication check. Second, by editing the cookie sent to the remote site, it is possible to authenticate as the administrative user.
|
2005-05-03
|
Interspire ArticleLive 2005 Multiple Method Administrator Authentication Bypass
|
|
16180
Description:
ArticleLive contains a flaw that may lead to an unauthorized information disclosure. The issue is triggered when a remote attacker provides a malformed query string to the search routine, which will disclose the full installation path resulting in a loss of confidentiality.
|
2005-05-03
|
Interspire ArticleLive 2005 search Malformed Query Path Disclosure
|
|
16181
Description:
ArticleLive contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the 'Query' variable upon submission to the search routine. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2005-05-03
|
Interspire ArticleLive 2005 search Query Parameter XSS
|
|
16182
Description:
ArticleLive contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the 'Username', 'FirstName', 'LastName', 'Email' or 'Biography' variables upon submission to the registration routine. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2005-05-03
|
Interspire ArticleLive 2005 register Multiple Parameter XSS
|
|
16183
Description:
ArticleLive contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the 'BlogId' variable upon submission to the newcomment routine. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2005-05-03
|
Interspire ArticleLive 2005 newcomment BlogId Parameter XSS
|
|
16280
Description:
FishCart contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the 'nlst' variable upon submission to the display.php script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2005-05-03
|
FishCart display.php nlst Parameter XSS
|
|
16281
Description:
FishCart contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the 'trackingnum', 'reqagree', or 'm' variables upon submission to the upstracking.php script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2005-05-03
|
FishCart upstracking.php Multiple Parameter XSS
|
|
16282
Description:
FishCart has been reported to contain a flaw that may allow an attacker to inject arbitrary SQL queries. The issue is supposedly due to the 'psku' variable in the display.php script not being properly sanitized and may allow an attacker to inject or manipulate SQL queries. However, the vendor disputes this claim saying that it is nothing more than a forced SQL error, not a method for injection.
|
2005-05-03
|
FishCart display.php psku Parameter SQL Injection
|
|
16283
Description:
FishCart has been reported to contain a flaw that may allow an attacker to inject arbitrary SQL queries. The issue is supposedly due to the 'cartid' variable in the upstnt.php script not being properly sanitized and may allow an attacker to inject or manipulate SQL queries. However, the vendor disputes this claim saying that it is nothing more than a forced SQL error, not a method for injection.
|
2005-05-03
|
FishCart upstnt.php cartid Parameter SQL Injection
|
|
15964
Description:
enVivo!CMS contains a flaw that may allow a remote attacker to gain administrative privileges. The issue is due to the admin_login.asp script not properly validating cookie data sent from the user. By modifying the cookie username and password values to "a' or 'a' = 'a", the application will authenticate the user as the legitimate administrator.
|
2005-04-29
|
enVivo!CMS admin_login.asp Cookie Manipulation Authentication Bypass
|
|
15965
Description:
enVivo!CMS contains a flaw that may allow an attacker to inject arbitrary SQL queries. The issue is due to the Username field in the admin_login.asp script not being properly sanitized and may allow an attacker to inject or manipulate SQL queries.
|
2005-04-29
|
enVivo!CMS admin_login.asp Username Field SQL Injection
|
|
15966
Description:
enVivo!CMS contains a flaw that may allow an attacker to inject arbitrary SQL queries. The issue is due to the 'searchstring' or 'ID' variable in the default.asp script not being properly sanitized and may allow an attacker to inject or manipulate SQL queries.
|
2005-04-29
|
enVivo!CMS default.asp Multiple Parameter SQL Injection
|
|
16353
Description:
phpCOIN contains a flaw that may allow a remote attacker to inject arbitrary SQL queries. The issue is due to the 'phpcoinsessid' variable in the 'login.php' script not being properly sanitized and may allow a remote attacker to inject or manipulate SQL queries.
|
2005-04-28
|
phpCOIN login.php phpcoinsessid Parameter SQL Injection
|
|
16354
Description:
phpCOIN contains a flaw that may allow a remote attacker to inject arbitrary SQL queries. The issue is due to the 'topic_id' and 'dcat_id' variable in the Pages module not being properly sanitized and may allow a remote attacker to inject or manipulate SQL queries.
|
2005-04-28
|
phpCOIN Pages Module Multiple Parameter SQL Injection
|
|
15868
Description:
MetaBid contains a flaw that may allow a remote attacker to inject arbitrary SQL queries. The issue is due to the 'Username' and 'Password' fields in the 'login.asp' script are not being properly sanitized and may allow a remote attacker to inject or manipulate SQL queries.
|
2005-04-26
|
MetaBid login.asp Multiple Field SQL Injection
|
|
15869
Description:
MetaBid contains a flaw that may allow a remote attacker to inject arbitrary SQL queries. The issue is due to the 'intAuctionID' variable in the 'item.asp' script not being properly sanitized and may allow a remote attacker to inject or manipulate SQL queries.
|
2005-04-26
|
MetaBid item.asp intAuctionID Parameter SQL Injection
|
|
15870
Description:
MetaCart (multiple products) contains a flaw that may allow an attacker to inject arbitrary SQL queries. The issue is due to the 'intProdID' variable in the product.asp script not being properly sanitized and may allow an attacker to inject or manipulate SQL queries.
|
2005-04-26
|
MetaCart product.asp intProdID Parameter SQL Injection
|
|
15871
Description:
MetaCart (multiple products) contains a flaw that may allow an attacker to inject arbitrary SQL queries. The issue is due to multiple variables in the productsByCategory.asp script not being properly sanitized and may allow an attacker to inject or manipulate SQL queries.
|
2005-04-26
|
MetaCart productsByCategory.asp Multiple Parameter SQL Injection
|