| OSVDB ID | Disclosure Date | Title |
|
22151
Description:
eFileGo contains a flaw that allows a remote attacker to execute programs outside of the web path. The issue is due to the eFileGo server not properly sanitizing user input, specifically traversal style attacks (../../) supplied to the server.
|
2005-12-31
|
eFileGo Server Traversal Arbitrary Command Execution
|
|
22152
Description:
eFileGo contains a flaw that may allow a remote denial of service. The issue is triggered when an attempt is made to upload a file to an invalid directory. This will result in the 'upload'exe' program consuming large amounts of CPU resources on the system, potentially leading to loss of availability for the platform.
|
2005-12-31
|
eFileGo upload.exe CPU Consumption DoS
|
|
22159
Description:
MyBB contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the inc/function_upload.php script not properly sanitizing user-supplied input to the file extension of the uploaded file. This may allow an attacker to inject or manipulate SQL queries in the back-end database.
|
2005-12-31
|
MyBulletinBoard (MyBB) function_upload.php SQL Injection
|
|
22485
Description:
(Description Provided by CVE) : The default configuration of Recruitment Software installs admin/site.xml under the web document root with insufficient access control, which might allow remote attackers to obtain sensitive information (MySQL database credentials) via a direct request.
|
2005-12-31
|
Recruitment Software admin/site.xml MySQL Authentication Credential Disclosure
|
|
22142
Description:
Bugport contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the index.php script not properly sanitizing user-supplied input to the 'orderBy', 'where' and 'devWherePair[1][0]' variables. This may allow an attacker to inject or manipulate SQL queries in the back-end database.
|
2005-12-31
|
BugPort index.php Multiple Parameter SQL Injection
|
|
22143
Description:
Bugport contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate 'ids', 'action', 'report_id', 'devWherePair' and 'binds' variables upon submission to the index.php script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2005-12-31
|
BugPort index.php Multiple Parameter XSS
|
|
22144
Description:
BugPort contains a flaw that may lead to an unauthorized information disclosure. The issue is triggered when a remote attacker passes invalid data to the 'action' variable in the index.php script, which will disclose the software's installation path resulting in a loss of confidentiality. While such information is relatively low risk, it is often useful in carrying out additional, more focused attacks.
|
2005-12-31
|
BugPort index.php action Variable Path Disclosure
|
|
22112
Description:
OOApp Guestbook contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the 'page' variable upon submission to the 'home.php' script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2005-12-30
|
OOApp Guestbook home.php page Parameter XSS
|
|
22118
Description:
iPei Guestbook contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the email field upon submission to the 'index.php' script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2005-12-30
|
iPei Guestbook index.php Email Field XSS
|
|
22119
Description:
VMware ESX Server contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate variables upon submission to the Management Interface. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2005-12-30
|
VMware ESX Server Management Interface Unspecified XSS
|
|
22120
Description:
A local overflow exists in TUGZip. TUGZip fails to handle long filenames of ARJ archives, resulting in a stack overflow. With an ARJ archive with a specially crafted name, an attacker can cause execution of arbitrary code, resulting in a loss of integrity.
|
2005-12-30
|
TUGZip ARJ Archive Filename Overflow
|
|
22111
Description:
AdesGuestbook contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the 'totalRows_rsRead' variable upon submission to the 'read.php' script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2005-12-30
|
AdesGuestbook read.php totalRows_rsRead Parameter XSS
|
|
22148
Description:
Web Wiz News, Web Wiz Journal, Web Wiz Polls and Web Wiz Database Login contain a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the check_user.asp script not properly sanitizing user-supplied input to the 'txtUserName' variable. This may allow an attacker to inject or manipulate SQL queries in the back-end database.
|
2005-12-30
|
Web Wiz Multiple Products check_user.asp txtUserName Parameter SQL Injection
|
|
22161
Description:
phpBB contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the 'bbcode' submitted to the 'url' variable upon submission to an unspecified script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity. Note that this vulnerability only affects Microsoft Internet Explorer (MSIE).
|
2005-12-30
|
phpBB url bbcode in MSIE Arbitrary Script Insertion
|
|
22162
Description:
phpBB contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the 'url' variable upon submission to an unspecified script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity. Note that this vulnerability only affects Microsoft Internet Explorer (MSIE).
|
2005-12-30
|
phpBB HTML Tags in MSIE Arbitrary Script Insertion
|
|
22145
Description:
(Description Provided by CVE) : Buffer overflow in MTink in the printer-filters-utils package allows local users to execute arbitrary code via a long HOME environment variable.
|
2005-12-30
|
mtink HOME Environment Variable Local Overflow
|
|
22155
Description:
(Description Provided by CVE) : Research in Motion (RIM) BlackBerry Router allows remote attackers to cause a denial of service (communication disruption) via crafted Server Routing Protocol (SRP) packets.
|
2005-12-30
|
BlackBerry Enterprise Server Crafted SRP Packet Remote DoS
|
|
22292
Description:
Unknown / Incomplete
|
2005-12-30
|
phpDocumentor bug-559668.php FORUM[LIB] Parameter XSS
|
|
22224
Description:
Kayako Supportsuite contains a flaw that allows a remote cross-site scripting (XSS) attack. This flaw exists because the application does not validate the 'nav' parameter upon submission to the 'index.php' script. This may allow a user to create a specially crafted URL that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2005-12-30
|
Kayako SupportSuite index.php nav Parameter XSS
|
|
22225
Description:
(Description Provided by CVE) : Multiple cross-site scripting (XSS) vulnerabilities in index.php in Kayako SupportSuite 3.00.26 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) nav parameter in the downloads module, (2) Full Name and (3) Email fields in the core module, (4) Full Name, (5) Email, and (6) Subject fields in the tickets module, or (7) Registered Email field in the lostpassword feature in the core module.
|
2005-12-30
|
Kayako SupportSuite New User Registration Multiple Field XSS
|
|
22226
Description:
Kayako SupportSuite contains a flaw that may lead to an unauthorized information disclosure. The issue is triggered when a remote attacker to take advantage of unsanitized input to the '_a' and 'newsid' parameters in the news module, the 'downloaditemid' parameter in the downloads module, and the 'kbarticleid' parameter in the 'knowledgebase' module, which discloses the software's installation path resulting in a loss of confidentiality. While such information is relatively low risk, it is often useful in carrying out additional, more focused attacks.
|
2005-12-30
|
Kayako SupportSuite index.php Multiple Parameter Path Disclosure
|
|
23196
Description:
Unknown / Incomplete
|
2005-12-30
|
T2 extend_initrd Unspecified Path Disclosure
|
|
22125
Description:
A remote overflow exists in dopewars. The dopewars server fails to handle user data safely resulting in a format string overflow. With a specially crafted request, an attacker can cause the server to treat user-supplied data as a format string resulting in a loss of integrity.
|
2005-12-30
|
dopewars on Win32 Remote Format String
|
|
22195
Description:
(Description Provided by CVE) : The m_join function in channel.c for PTnet ircd 1.5 and 1.6 allows remote attackers to cause a denial of service (memory exhaustion that triggers a daemon restart) via a large number of requests to join a "charmed channel" such as PTnet, #PTnoticias and #*.log, which causes ircd to open the channel even though it does not have any valid users.
|
2005-12-30
|
PTnet IRCd Crafted Channel Join Saturation DoS
|
|
22180
Description:
(Description Provided by CVE) : Research in Motion (RIM) BlackBerry Handheld web browser for BlackBerry Handheld before 4.0.2 allows remote attackers to cause a denial of service (hang) via a Java Application Description (JAD) file with a long application name and vendor string, which prevents a browser dialog from being properly dismissed.
|
2005-12-30
|
BlackBerry Handheld Browser Crafted JAD DoS
|
|
22181
Description:
(Description Provided by CVE) : Heap-based buffer overflow in Research in Motion (RIM) BlackBerry Attachment Service allows remote attackers to cause a denial of service (hang) via an e-mail attachment with a crafted TIFF file.
|
2005-12-30
|
BlackBerry Attachment Service Crafted TIFF Overflow DoS
|
|
41717
Description:
Unknown / Incomplete
|
2005-12-30
|
Wesnoth Campaign Download Name Unspecified Issue
|
|
41718
Description:
Unknown / Incomplete
|
2005-12-30
|
Wesnoth File/Directory Upload Campaign Mismatch Unspecified Issue
|
|
22093
Description:
NView contains a flaw that may allow a malicious user to gain access to unauthorized privileges. The issue caused by an insecure RPATH and is triggered when the application is launched within a shared directory containing a malicious library. This flaw may lead to a loss of confidentiality or integrity through arbitrary code execution.
|
2005-12-29
|
NView RPATH Subversion Local Privilege Escalation
|
|
22094
Description:
XnView contains a flaw that may allow a malicious user to gain access to unauthorized privileges. The issue caused by an insecure RPATH and is triggered when the application is launched within a shared directory containing a malicious library. This flaw may lead to a loss of confidentiality or integrity through arbitrary code execution.
|
2005-12-29
|
XnView RPATH Subversion Local Privilege Escalation
|
|
22083
Description:
GmailSite/GFHost contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the 'lng' variable upon submission to the 'index.php' script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2005-12-29
|
GFHost / GmailSite index.php lng Parameter XSS
|
|
22095
Description:
Gmailsite/GFHost contains a flaw that may allow a remote attacker to display the contents of arbitrary files. The issue is due to the 'index.php' script not properly sanitizing user input supplied to the 'lng'variable. This may allow an attacker to include a file from a remote host, resulting in a loss of confidentiality.
|
2005-12-29
|
GFHost / GmailSite index.php lng Parameter Local File Inclusion
|
|
22116
Description:
TinyMCE Compressor contains a flaw that allows a remote attacker to view fieles outside of the web path. The issue is due to the tiny_mce_gzip.php script not sanitizing input to the 'theme', 'language', 'plugins', or 'lang parameter'. By requesting a file and appending a null byte (%00), an attacker can access any file on the system that the web server has privileges to read.
|
2005-12-29
|
TinyMCE Compressor tiny_mce_gzip.php Traversal Arbitrary File Access
|
|
22117
Description:
TinyMCE Compressor contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the 'index' variable and others upon submission. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2005-12-29
|
TinyMCE Compressor Editor Imported Content XSS
|
|
22121
Description:
Various ImageMagick utilities fail to correctly validate image file names. The issue is triggered when specially crafted shell commands are part of the file name provided. It is possible that the flaw may allow execution of arbitrary shell commands, resulting in a loss of integrity.
|
2005-12-29
|
ImageMagick Delegate Code Multiple Utility Crafted File Name Arbitrary Shell Command Injection
|
|
22114
Description:
phpdocumentor contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to "Documentation/tests/bug-559668.php" not properly sanitizing user input supplied to the "FORUM[LIB]" variable. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script. However successful exploitation requires that "register_globals" is enabled.
|
2005-12-29
|
phpDocumentor bug-559668.php FORUM[LIB] Parameter Remote File Inclusion
|
|
22115
Description:
phpDocumentor contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to "docbuilder/file_dialog.php" not properly sanitizing user input supplied to the "root_dir" variable. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script. However successful exploitation requires that "register_globals" is enabled.
|
2005-12-29
|
phpDocumentor file_dialog.php root_dir Parameter Remote File Inclusion
|
|
22154
Description:
(Description Provided by CVE) : Direct static code injection vulnerability in phpBook 1.3.2 and earlier allows remote attackers to execute arbitrary PHP code via the e-mail field (mail variable) in a new message, which is written to a PHP file.
|
2005-12-29
|
phpBook New Message E-mail Field Arbitrary PHP Code Execution
|
|
22150
Description:
PHPenpals contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the profile.php script not properly sanitizing user-supplied input to the 'personalID' variable. This may allow an attacker to inject or manipulate SQL queries in the back-end database.
|
2005-12-29
|
PHPenpals profile.php personalID Parameter SQL Injection
|
|
22141
Description:
(Description Provided by CVE) : Cross-site scripting (XSS) vulnerability in addentry.php in Chipmunk Guestbook 1.4 and earlier allows remote attackers to inject arbitrary web script or HTML via the homepage parameter.
|
2005-12-29
|
Chipmunk GuestBook addentry.php XSS
|