| OSVDB ID | Disclosure Date | Title |
|
12719
Description:
Personal Web Server contains a flaw that may allow a remote denial of service. The issue is triggered when a specially crafted URL occurs, and will result in loss of availability for the service.
|
2005-01-06
|
Jeuce Personal Web Server Malformed URL DoS
|
|
12717
Description:
b2evolution contains a flaw that will allow a remote attacker to inject arbitrary SQL code. The problem is that the 'title' parameter in the 'index.php' script is not verified properly and will allow an attacker to inject or manipulate SQL queries.
|
2005-01-06
|
b2evolution index.php title Parameter SQL Injection
|
|
12848
Description:
(Description Provided by CVE) : Buffer overflow in htdigest in Apache 2.0.52 may allow attackers to execute arbitrary code via a long realm argument. NOTE: since htdigest is normally only locally accessible and not setuid or setgid, there are few attack vectors which would lead to an escalation of privileges, unless htdigest is executed from a CGI program. Therefore this may not be a vulnerability.
|
2005-01-05
|
Apache HTTP Server htdigest realm Variable Overflow
|
|
12814
Description:
PHPKIT contains a flaw that will allow a remote attacker to inject arbitrary SQL code. The problem is that the 'id' parameter in the 'userinfo.php' script is not verified properly and will allow a remote attacker to inject or manipulate SQL queries.
|
2005-01-05
|
PHPKIT userinfo.php id Parameter SQL Injection
|
|
53439
Description:
Unknown / Incomplete
|
2005-01-05
|
VideoDB edit.php Database Editing Unspecified Unauthorized Access
|
|
53438
Description:
Unknown / Incomplete
|
2005-01-05
|
VideoDB Unspecified SQL Injection
|
|
12785
Description:
Unknown / Incomplete
|
2005-01-05
|
Dillo Web Browser Table HTML Tag Multiple Attribute DoS
|
|
12790
Description:
A buffer overflow exists in NetWare. The CIFS.NLM driver fails to validate unspecified data resulting in a stack overflow. With a specially crafted request, a remote attacker can cause arbitrary code execution resulting in a loss of integrity.
|
2005-01-05
|
Novell NetWare Unspecified CIFS.NLM Remote Overflow
|
|
12799
Description:
Unknown / Incomplete
|
2005-01-05
|
MyCart settings.ini Remote Information Disclosure
|
|
22312
Description:
(Description Provided by CVE) : NetSarang Xlpd 2.1 allows remote attackers to cause a denial of service (crash) via a large number of connections from the same IP address.
|
2005-01-05
|
Xlpd Connection Saturation Remote DoS
|
|
12796
Description:
Unknown / Incomplete
|
2005-01-05
|
VideoDB Unspecified XSS
|
|
12808
Description:
(Description Provided by CVE) : TFTP in 3Com 3CDaemon 2.0 revision 10 allows remote attackers to cause a denial of service (application crash) via a GET request containing an MS-DOS device name.
|
2005-01-04
|
3Com 3CDaemon TFTP Reserved Device Name Remote DoS
|
|
12712
Description:
(Description Provided by CVE) : Directory traversal vulnerability in index.php in QwikiWiki allows remote attackers to read arbitrary files via a .. (dot dot) and a %00 at the end of the filename in the page parameter.
|
2005-01-04
|
QwikiWiki index.php Traversal Arbitrary File Retrieval
|
|
12720
Description:
(Description Provided by CVE) : The mod_dosevasive module 1.9 and earlier for Apache creates temporary files with predictable filenames, which could allow remote attackers to overwrite arbitrary files via a symlink attack.
|
2005-01-04
|
mod_dosevasive for Apache HTTP Server Symlink Arbitrary File Create/Overwrite
|
|
12714
Description:
(Description Provided by CVE) : Soldner Secret Wars 30830 and earlier does not properly handle the "message too long" socket error, which allows remote attackers to cause a denial of service (socket termination) via a long UDP packet.
|
2005-01-04
|
Soldner Secret Wars UDP Socket Termination DoS
|
|
12715
Description:
(Description Provided by CVE) : Format string vulnerability in Soldner Secret Wars 30830 and earlier allows remote attackers to cause a denial of service (server crash) and possibly execute arbitrary code via format string specifiers in a message.
|
2005-01-04
|
Soldner Secret Wars Remote Format String Arbitrary Command Execution
|
|
12716
Description:
(Description Provided by CVE) : Cross-site scripting (XSS) vulnerability in the web interface in Soldner Secret Wars 30830 allows remote attackers to inject arbitrary web script or HTML via a user message, which is not filtered or quoted when the administrator views the server logs.
|
2005-01-04
|
Soldner Secret Wars Web Interface XSS
|
|
14829
Description:
Unknown / Incomplete
|
2005-01-04
|
KDE Konqueror Download Dialog Source Spoofing
|
|
13242
Description:
(Description Provided by CVE) : A logic error in the CRAM-MD5 code for the University of Washington IMAP (UW-IMAP) server, when Challenge-Response Authentication Mechanism with MD5 (CRAM-MD5) is enabled, does not properly enforce all the required conditions for successful authentication, which allows remote attackers to authenticate as arbitrary users.
|
2005-01-04
|
UW-imapd CRAM-MD5 Authentication Bypass
|
|
12783
Description:
(Description Provided by CVE) : Format string vulnerability in the a_Interface_msg function in Dillo before 0.8.3-r4 allows remote attackers to execute arbitrary code via format string specifiers in a web page.
|
2005-01-04
|
Dillo Web Browser a_Interface_msg() Remote Format String
|
|
12809
Description:
(Description Provided by CVE) : Multiple format string vulnerabilities in the FTP service in 3Com 3CDaemon 2.0 revision 10 allow remote attackers to cause a denial of service (application crash) via format string specifiers in (1) the username, (2) cd, (3) delete, (4) rename, (5) rmdir, (6) literal, (7) stat, or (8) CWD commands.
|
2005-01-04
|
3Com 3CDaemon FTP Username Format String DoS
|
|
12810
Description:
A remote overflow exists in 3CDaemon. The FTP application fails to perform proper bounds checking resulting in a buffer overflow. With a specially crafted request containing an overly long username, a remote attacker can cause arbitrary code execution resulting in a loss of integrity.
|
2005-01-04
|
3Com 3CDaemon FTP Username Remote Overflow
|
|
12811
Description:
A remote overflow exists in 3CDaemon. Multiple FTP commands fail to perform proper bounds checking resulting in a buffer overflow. With a specially crafted request containing an overly long parameter, a remote attacker can cause arbitrary code execution resulting in a loss of integrity.
|
2005-01-04
|
3Com 3CDaemon Multiple FTP Command Long Parameter Overflow
|
|
12812
Description:
(Description Provided by CVE) : Multiple format string vulnerabilities in the FTP service in 3Com 3CDaemon 2.0 revision 10 allow remote attackers to cause a denial of service (application crash) via format string specifiers in (1) the username, (2) cd, (3) delete, (4) rename, (5) rmdir, (6) literal, (7) stat, or (8) CWD commands.
|
2005-01-04
|
3Com 3CDaemon Multiple FTP Command Format String
|
|
12813
Description:
(Description Provided by CVE) : The FTP service in 3Com 3CDaemon 2.0 revision 10 allows remote attackers to gain sensitive information via a cd command that contains an MS-DOS device name, which reveals the installation path in an error message.
|
2005-01-04
|
3Com 3CDaemon Multiple FTP Command Reserved Device Name Path Disclosure
|
|
12740
Description:
(Description Provided by CVE) : Firefox before 1.0.1 and Mozilla before 1.7.6 truncates long sub-domains or paths for display, which may allow remote malicious web sites to spoof legitimate sites and facilitate phishing attacks.
|
2005-01-04
|
Mozilla Browsers Download Source Spoofing
|
|
12798
Description:
MyBB contains a flaw that will allow a remote attacker to inject arbitrary SQL code. The problem is that the 'uid' parameter in the 'member.php' script is not verified properly and will allow a remote attacker to inject or manipulate SQL queries.
|
2005-01-04
|
MyBulletinBoard (MyBB) member.php uid Parameter SQL Injection
|
|
15341
Description:
Unknown / Incomplete
|
2005-01-03
|
Microsoft Windows Server 2003 SMB Redirector Processing DoS
|
|
14627
Description:
Unknown / Incomplete
|
2005-01-03
|
Executer executer.cgi Remote File Inclusion
|
|
14625
Description:
Unknown / Incomplete
|
2005-01-03
|
The Includer includer.cgi Secret Password Weak Encryption
|
|
14626
Description:
(Description Provided by CVE) : includer.cgi in The Includer allows remote attackers to read arbitrary files via a full pathname in the argument, a similar vulnerability to CVE-2005-0801.
|
2005-01-03
|
The Includer includer.cgi Full Pathname Arbitrary File Access
|
|
12721
Description:
Apache Tomcat contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate user-supplied input upon submission to the /examples/jsp2/el/functions.jsp script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2005-01-03
|
Apache Tomcat examples/jsp2/el/functions.jsp XSS
|
|
34878
Description:
Apache Tomcat contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate user-supplied input upon submission to the /examples/jsp2/el/implicit-objects.jsp script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2005-01-03
|
Apache Tomcat examples/jsp2/el/implicit-objects.jsp XSS
|
|
34879
Description:
Apache Tomcat contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate user-supplied input upon submission to the /examples/jsp2/jspx/textRotate.jspx script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2005-01-03
|
Apache Tomcat examples/jsp2/jspx/textRotate.jspx XSS
|
|
12681
Description:
HtmlHeadLine.sh contains a flaw that may allow a malicious user to overwrite arbitrary files. The issue is triggered when temp files are created insecurely. It is possible that the flaw may allow arbitrary files to be overwritten resulting in a loss of integrity.
|
2005-01-03
|
HtmlHeadLine.sh Symlink Arbitrary File Overwrite
|
|
12703
Description:
ReviewPost PHP Pro contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate 'si' variables upon submission to the 'showcat.php' script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2005-01-03
|
ReviewPost PHP Pro showcat.php si Parameter XSS
|
|
12704
Description:
ReviewPost PHP Pro contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate multiple variables upon submission to the 'showproduct.php' script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2005-01-03
|
ReviewPost PHP Pro showproduct.php Multiple Parameter XSS
|
|
12705
Description:
ReviewPost PHP Pro contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate 'report' variables upon submission to the 'reportproduct.php' script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2005-01-03
|
ReviewPost PHP Pro reportproduct.php report Parameter XSS
|
|
12706
Description:
ReviewPost PHP Pro contains a flaw that will allow a remote attacker to inject arbitrary SQL code. The problem is that the 'cat' parameter in the 'showcat.php' script is not verified properly and will allow an attacker to inject or manipulate SQL queries.
|
2005-01-03
|
ReviewPost PHP Pro showcat.php cat Parameter SQL Injection
|
|
12707
Description:
ReviewPost PHP Pro contains a flaw that will allow a remote attacker to inject arbitrary SQL code. The problem is that the 'product' parameter in the 'addfav.php' script is not verified properly and will allow an attacker to inject or manipulate SQL queries.
|
2005-01-03
|
ReviewPost PHP Pro addfav.php product Parameter SQL Injection
|