| OSVDB ID | Disclosure Date | Title |
|
20848
Description:
Pearl Forums contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the index.php script not properly sanitizing user-supplied input to the 'forumsId' and 'topicId' variables. This may allow an attacker to inject or manipulate SQL queries in the back-end database.
|
2005-11-15
|
Pearl Forums index.php Multiple Parameter SQL Injection
|
|
20849
Description:
Pearl Forums contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to index.php not properly sanitizing user input supplied to the 'mode' variable. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script.
|
2005-11-15
|
Pearl Forums index.php mode Parameter Local File Inclusion
|
|
20523
Description:
Tonio Gallery contains a flaw that may allow a remote attacker to carry out an SQL injection attack. The issue is due to the 'showGallery.php' script not properly sanitizing user-supplied input to the 'galid' variable. This may allow a remote attacker to inject or manipulate SQL queries in the back-end database.
|
2005-11-04
|
Tonio Gallery showGallery.php galid Parameter SQL Injection
|
|
20420
Description:
oaboard contains a flaw that may allow a remote attacker to carry out an SQL injection attack. The issue is due to the 'forum.php' script not properly sanitizing user-supplied input to the 'channel' and 'topic' variables. This may allow a remote attacker to inject or manipulate SQL queries in the back-end database.
|
2005-10-30
|
oaboard forum.php Multiple Parameter SQL Injection
|
|
20305
Description:
TClanPortal contains a flaw that may allow a remote attacker to carry out an SQL injection attack. The issue is due to the 'index.php' script not properly sanitizing user-supplied input to the 'id' variable. This may allow a remote attacker to inject or manipulate SQL queries in the back-end database.
|
2005-10-25
|
TClanPortal index.php id Parameter SQL Injection
|
|
20245
Description:
FlatNuke contains a flaw that may allow a remote attacker to include arbitrary files. The issue is due to the 'index.php' script not properly sanitizing user input, specifically traversal style attacks supplied via the 'user' and 'quale' variables, which may allow a remote attacker to disclose the content of arbitrary files resulting in a loss of confidentiality.
|
2005-10-22
|
FlatNuke index.php Traversal Arbitrary File Inclusion
|
|
20246
Description:
FlatNuke contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the 'user' or 'nome' variables upon submission to the 'index.php' script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2005-10-22
|
FlatNuke index.php Multiple Parameter XSS
|
|
19404
Description:
DeluxeBB contains a flaw that may allow a remote attacker to carry out an SQL injection attack. The issue is due to the 'topic.php' script not properly sanitizing user-supplied input to the 'tid' variable. This may allow a remote attacker to inject or manipulate SQL queries in the back-end database.
|
2005-09-15
|
DeluxeBB topic.php tid Parameter SQL Injection
|
|
19405
Description:
DeluxeBB contains a flaw that may allow a remote attacker to carry out an SQL injection attack. The issue is due to the 'misc.php' script not properly sanitizing user-supplied input to the 'uid' variable. This may allow a remote attacker to inject or manipulate SQL queries in the back-end database.
|
2005-09-15
|
DeluxeBB misc.php uid Parameter SQL Injection
|
|
19406
Description:
DeluxeBB contains a flaw that may allow a remote attacker to carry out an SQL injection attack. The issue is due to the 'forums.php' script not properly sanitizing user-supplied input to the 'fid' variable. This may allow a remote attacker to inject or manipulate SQL queries in the back-end database.
|
2005-09-15
|
DeluxeBB forums.php fid Parameter SQL Injection
|
|
19407
Description:
DeluxeBB contains a flaw that may allow a remote attacker to carry out an SQL injection attack. The issue is due to the 'pm.php' script not properly sanitizing user-supplied input to the 'uid' variable. This may allow a remote attacker to inject or manipulate SQL queries in the back-end database.
|
2005-09-15
|
DeluxeBB pm.php uid Parameter SQL Injection
|
|
19408
Description:
DeluxeBB contains a flaw that may allow a remote attacker to carry out an SQL injection attack. The issue is due to the 'newpost.php' script not properly sanitizing user-supplied input to the 'fid' variable. This may allow a remote attacker to inject or manipulate SQL queries in the back-end database.
|
2005-09-15
|
DeluxeBB newpost.php fid Parameter SQL Injection
|
|
18685
Description:
PortailPHP contains a flaw that may allow a remote attacker to carry out an SQL injection attack. The issue is due to the 'read_message.php' script not properly sanitizing user-supplied input to the 'id' variable. This may allow a remote attacker to inject or manipulate SQL queries in the back-end database.
|
2005-08-04
|
PortailPhp mod_forum/read_message.php id Parameter SQL Injection
|
|
18296
Description:
VBZooM contains a flaw that may allow a remote attacker to carry out an SQL injection attack. The issue is due to the 'show.php' script not properly sanitizing user-supplied input to the 'SubjectID' variable. This may allow a remote attacker to inject or manipulate SQL queries in the back-end database.
|
2005-07-26
|
VBZooM show.php SubjectID Parameter SQL Injection
|
|
17399
Description:
cPanel contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the 'user' variable upon submission to the 'cpsrvd.pl' script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2005-06-22
|
cPanel cpsrvd.pl user Parameter XSS
|