| OSVDB ID | Disclosure Date | Title |
|
36458
Description:
StoreSprite contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the next variable upon submission to the secure/addaddress.php script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2007-08-10
|
StoreSprite secure/addaddress.php next Parameter XSS
|
|
36459
Description:
(Description Provided by CVE) : Multiple cross-site scripting (XSS) vulnerabilities in Storesprite 7 and earlier allow remote attackers to inject arbitrary web script or HTML via the next parameter to (1) addaddress.php, (2) editshipdetails.php, (3) register.php, or (4) login.php in secure/.
|
2007-08-10
|
StoreSprite secure/editshipdetails.php next Parameter XSS
|
|
36460
Description:
(Description Provided by CVE) : Multiple cross-site scripting (XSS) vulnerabilities in Storesprite 7 and earlier allow remote attackers to inject arbitrary web script or HTML via the next parameter to (1) addaddress.php, (2) editshipdetails.php, (3) register.php, or (4) login.php in secure/.
|
2007-08-10
|
StoreSprite secure/register.php next Parameter XSS
|
|
36461
Description:
(Description Provided by CVE) : Multiple cross-site scripting (XSS) vulnerabilities in Storesprite 7 and earlier allow remote attackers to inject arbitrary web script or HTML via the next parameter to (1) addaddress.php, (2) editshipdetails.php, (3) register.php, or (4) login.php in secure/.
|
2007-08-10
|
StoreSprite secure/login.php next Parameter XSS
|
|
38720
Description:
phpMyAdmin contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate 'unlim_num_rows', 'sql_query' and 'pos_parameter' variables upon submission to the tbl_export.php script, 'session_max_rows' and 'pos_parameter' variables upon submission to the sql.php script, 'username' variable upon submission to the server_privileges.php script and 'sql_query' variable upon submission to the main.php script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2007-08-10
|
phpMyAdmin Multiple Parameter XSS
|
|
36433
Description:
(Description Provided by CVE) : Multiple cross-site scripting (XSS) vulnerabilities in VisionProject 3.1 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) projectIssueId parameter in EditProjectIssue.do, the (2) projectId parameter in ProjectSelected.do, the (3) folderId parameter in ProjectDocuments.do and the (4) sortField parameter in ProjectIssues.do.
|
2007-08-07
|
VisionProject EditProjectIssue.do projectIssueId Parameter XSS
|
|
36434
Description:
(Description Provided by CVE) : Multiple cross-site scripting (XSS) vulnerabilities in VisionProject 3.1 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) projectIssueId parameter in EditProjectIssue.do, the (2) projectId parameter in ProjectSelected.do, the (3) folderId parameter in ProjectDocuments.do and the (4) sortField parameter in ProjectIssues.do.
|
2007-08-07
|
VisionProject ProjectSelected.do projectId Parameter XSS
|
|
36435
Description:
(Description Provided by CVE) : Multiple cross-site scripting (XSS) vulnerabilities in VisionProject 3.1 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) projectIssueId parameter in EditProjectIssue.do, the (2) projectId parameter in ProjectSelected.do, the (3) folderId parameter in ProjectDocuments.do and the (4) sortField parameter in ProjectIssues.do.
|
2007-08-07
|
VisionProject ProjectDocuments.do folderId Parameter XSS
|
|
36436
Description:
(Description Provided by CVE) : Multiple cross-site scripting (XSS) vulnerabilities in VisionProject 3.1 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) projectIssueId parameter in EditProjectIssue.do, the (2) projectId parameter in ProjectSelected.do, the (3) folderId parameter in ProjectDocuments.do and the (4) sortField parameter in ProjectIssues.do.
|
2007-08-07
|
VisionProject ProjectIssues.do sortField Parameter XSS
|
|
36439
Description:
(Description Provided by CVE) : Cross-site scripting (XSS) vulnerability in index.php in WebDirector 2.2 and earlier allows remote attackers to inject arbitrary web script or HTML via the deslocal parameter.
|
2007-08-01
|
WebDirector index.php deslocal Parameter XSS
|
|
36332
Description:
(Description Provided by CVE) : Multiple cross-site scripting (XSS) vulnerabilities in login.php in AdMan 1.0.20051202 FF 3 patch and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) user and (2) pwd parameters.
|
2007-07-25
|
AdMan login.php Multiple Parameter XSS
|
|
36339
Description:
(Description Provided by CVE) : Cross-site scripting (XSS) vulnerability in CMD_USER_STATS in DirectAdmin 1.30.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the domain parameter, a different vector than CVE-2007-1508.
|
2007-06-28
|
DirectAdmin CMD_USER_STATS domain Parameter XSS
|
|
36347
Description:
(Description Provided by CVE) : Multiple cross-site scripting (XSS) vulnerabilities in search.asp in rwAuction Pro 5.0 allow remote attackers to inject arbitrary web script or HTML via the (1) search, (2) show, (3) searchtype, (4) catid, and (5) searchtxt parameters, a different version and vectors than CVE-2005-4060.
|
2007-06-27
|
rwAuction Pro search.asp Multiple Parameter XSS
|
|
37750
Description:
access2asp contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the 'od' and 'search' variables upon submission to the suppliersList.asp script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2007-06-22
|
access2asp suppliersList.asp Multiple Parameter XSS
|
|
37751
Description:
access2asp contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the 'od' and 'search' variables upon submission to the contactsList.asp script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2007-06-22
|
access2asp contactsList.asp Multiple Parameter XSS
|
|
36384
Description:
(Description Provided by CVE) : Multiple cross-site scripting (XSS) vulnerabilities in comments.cgi in Sporum Forum 3.0.9 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) view and (2) mode parameters.
|
2007-06-12
|
Sporum Forum comments.cgi Multiple Parameter XSS
|
|
36370
Description:
(Description Provided by CVE) : SQL injection vulnerability in edit_image.asp in ClickGallery Server 5.1 and earlier allows remote attackers to execute arbitrary SQL commands via the image_id parameter.
|
2007-05-02
|
ClickGallery edit_image.asp image_id Parameter SQL Injection
|
|
36371
Description:
(Description Provided by CVE) : Cross-site scripting (XSS) vulnerability in edit_image.asp in ClickGallery Server 5.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the from parameter.
|
2007-05-02
|
ClickGallery edit_image.asp from Parameter XSS
|
|
31036
Description:
MusicBox contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the index.php script not properly sanitizing user-supplied input to the 'type' parameter. This may allow an attacker to inject or manipulate SQL queries in the back-end database.
|
2006-07-24
|
MusicBox index.php type Parameter SQL Injection
|
|
27411
Description:
IDevSpot PhpHostBot contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to order/index.php not properly sanitizing user input supplied to the 'page' variable. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script.
|
2006-07-20
|
PhpHostBot order/index.php page Parameter Remote File Inclusion
|
|
27410
Description:
PhpLinkExchange contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to index.php script not properly sanitizing user input supplied to the 'page' variable. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script.
|
2006-07-20
|
PhpLinkExchange index.php page Parameter Remote File Inclusion
|
|
27099
Description:
HiveMail contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the search.results.php script not properly sanitizing user-supplied input to the 'fields[]' variable. This may allow an attacker to inject or manipulate SQL queries in the back-end database.
|
2006-07-11
|
HiveMail search.results.php fields[] Parameter SQL Injection
|
|
27100
Description:
HiveMail contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the "email", "cond", and "name" variables upon submission to the addressbook.view.php script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2006-07-11
|
HiveMail addressbook.view.php Multiple Parameter XSS
|
|
27101
Description:
HiveMail contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the 'daysprune' variable upon submission to the index.php script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2006-07-11
|
HiveMail index.php daysprune Parameter XSS
|
|
27102
Description:
HiveMail contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the 'date[to]' variable upon submission to the compose.email.php script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2006-07-11
|
HiveMail compose.email.php data[to] Parameter XSS
|
|
27103
Description:
HiveMail contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the 'markas' variable upon submission to the read.markas.php script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2006-07-11
|
HiveMail read.markas.php markas Parameter XSS
|
|
27104
Description:
HiveMail contains a flaw that may lead to an unauthorized information disclosure. The issue is triggered when a remote attacker defines the "searchdate" and "folderids" variables in the search.results.php script, which will disclose the software's installation path resulting in a loss of confidentiality. While such information is relatively low risk, it is often useful in carrying out additional, more focused attacks.
|
2006-07-11
|
HiveMail search.results.php Multiple Variable Path Disclosure
|
|
26863
Description:
H-Sphere contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the 'next_template', 'start', 'curr_menu_id' and 'arid' variables upon submission to the psoft.hsphere.CP script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2006-06-27
|
H-Sphere psoft.hsphere.CP Multiple Parameter XSS
|
|
26872
Description:
Hostflow Help Desk contains a flaw that may allow a malicious user to gain unauthorized access. The issue is triggered when an attacker gains access to the URL used by an authenticated user, which contains all necessary authentication information. It is possible that the flaw may allow unauthorized access resulting in a loss of integrity.
|
2006-06-27
|
Hostflow Help Desk new_ticket.cgi Authentication Replay
|
|
27627
Description:
(Description Provided by CVE) : Multiple SQL injection vulnerabilities in HSPcomplete 3.2.2 and 3.3 Beta and earlier allow remote attackers to execute arbitrary SQL commands via the (1) type parameter in report.php and (2) level parameter in custom_buttons.php.
|
2006-06-27
|
HSPcomplete report.php type Parameter SQL Injection
|
|
27628
Description:
(Description Provided by CVE) : Multiple SQL injection vulnerabilities in HSPcomplete 3.2.2 and 3.3 Beta and earlier allow remote attackers to execute arbitrary SQL commands via the (1) type parameter in report.php and (2) level parameter in custom_buttons.php.
|
2006-06-27
|
HSPcomplete custom_buttons.php level Parameter SQL Injection
|
|
43500
Description:
(Description Provided by CVE) : Cross-domain vulnerability in MYweb4net Browser 3.8.8.0 allows remote attackers to access restricted information from other domains via an object tag with a data parameter that references a link on the attacker's originating site that specifies a Location HTTP header that references the target site, which then makes that content available through the outerHTML attribute of the object, a similar vulnerability to CVE-2006-3280.
|
2006-06-27
|
MYweb4net Browser Object Tag outerHTML Attribute Cross-domain Information Disclosure
|
|
27625
Description:
(Description Provided by CVE) : SQL injection vulnerability in index.php in Zorum Forum 3.5 allows remote attackers to execute arbitrary SQL commands via the (1) offset, (2) tid, (3) fromid, (4) sortby, (5) fromfrommethod, and (6) fromfromlist parameters.
|
2006-06-26
|
Zorum index.php Multiple Parameter SQL Injection
|
|
27626
Description:
(Description Provided by CVE) : Cross-site scripting (XSS) vulnerability in index.php in Zorum Forum 3.5 allows remote attackers to inject web script or HTML via the multiple unspecified parameters, including the (1) frommethod, (2) list, and (3) method, which are reflected in an error message. NOTE: some of these vectors might be resultant from SQL injection.
|
2006-06-26
|
Zorum index.php Multiple Parameter XSS
|
|
27623
Description:
OpenForum contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the 'ofdisp' and 'ofmsgid' variables upon submission to the 'openforum.asp' script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2006-06-25
|
OpenForum openforum.asp Multiple Parameter XSS
|
|
26848
Description:
(Description Provided by CVE) : Multiple cross-site scripting (XSS) vulnerabilities in phpQLAdmin 2.2.7 and earlier allow remote attackers to inject arbitrary web script or HTML via the domain parameter in (1) user_add.php or (2) unit_add.php.
|
2006-06-25
|
phpQLAdmin user_add.php domain Parameter XSS
|
|
26849
Description:
(Description Provided by CVE) : Multiple cross-site scripting (XSS) vulnerabilities in phpQLAdmin 2.2.7 and earlier allow remote attackers to inject arbitrary web script or HTML via the domain parameter in (1) user_add.php or (2) unit_add.php.
|
2006-06-25
|
phpQLAdmin unit_add.php domain Parameter XSS
|
|
26840
Description:
(Description Provided by CVE) : Multiple cross-site scripting (XSS) vulnerabilities in pm.php in DeluxeBB 1.07 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) subject or (2) to parameters.
|
2006-06-25
|
DeluxeBB pm.php Multiple Parameter XSS
|
|
26804
Description:
GL-SH Deaf Forum contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate 'sort', 'search', 'page', and 'action' variables upon submission to the show.php script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2006-06-25
|
GL-SH Deaf Forum show.php Multiple Parameter XSS
|
|
26798
Description:
(Description Provided by CVE) : SQL injection vulnerability in index.php in Infinite Core Technologies (ICT) 1.0 Gold and earlier allows remote attackers to execute arbitrary SQL commands via the post parameter.
|
2006-06-25
|
ICT index.php post Parameter SQL Injection
|