| OSVDB ID | Disclosure Date | Title |
|
14282
Description:
PostNuke contains a flaw that may allow an attacker to inject arbitrary SQL queries. The issue is due to the "$show" and "$orderby" variable in the "/modules/Downloads/dl-search.php" script not being properly sanitized and may allow an attacker to inject or manipulate SQL queries.
|
2005-02-28
|
PostNuke dl-search.php Multiple Parameter SQL Injection
|
|
14283
Description:
Unknown / Incomplete
|
2005-02-28
|
PostNuke dl-search.php Path Disclosure
|
|
14284
Description:
PostNuke contains a flaw that may allow an attacker to inject arbitrary SQL queries. The issue is due to the "getArticles()" function in the "modules/News/funcs.php" script not being properly sanitized and may allow an attacker to inject or manipulate SQL queries.
|
2005-02-28
|
PostNuke funcs.php getArticles Function SQL Injection
|
|
14285
Description:
(Description Provided by CVE) : Multiple cross-site scripting (XSS) vulnerabilities in the Download module for PostNuke 0.750 and 0.760-RC2 allow remote attackers to inject arbitrary web script or HTML via the (1) Program name, (2) File link, (3) Author name (4) Author e-mail address, (5) File size, (6) Version, or (7) Home page variables.
|
2005-02-28
|
PostNuke Download Module admin.php Multiple Parameter XSS
|
|
14286
Description:
Unknown / Incomplete
|
2005-02-28
|
PostNuke pnadmin.php Input Validation Weakness
|
|
14287
Description:
Unknown / Incomplete
|
2005-02-28
|
PostNuke past.php Input Validation Weakness
|
|
14288
Description:
Unknown / Incomplete
|
2005-02-28
|
PostNuke Downloads Module dl-util.php Input Validation Weakness
|
|
14289
Description:
Unknown / Incomplete
|
2005-02-28
|
PostNuke News Module index.php Path Disclosure
|
|
14244
Description:
(Description Provided by CVE) : reportbug 3.2 includes settings from .reportbugrc in bug reports, which exposes sensitive information such as smtpuser and smtppasswd.
|
2005-02-28
|
reportbug .reportbugrc Permission Weakness Information Disclosure
|
|
14245
Description:
Reportbug contains a flaw that may allow a malicious user to read possibly sensitive information in the "reportbugrc" file. The issue exists because by default the file is world readable. It is possible that the flaw may allow loss of confidentiality since the file might contain the smtppasswd.
|
2005-02-28
|
reportbug Report smtppasswd Setting Information Disclosure
|
|
14272
Description:
(Description Provided by CVE) : Scrapland 1.0 and earlier allows remote attackers to cause a denial of service (server termination) by triggering an error, which is treated as a fatal error by the server, as demonstrated using (1) signed integers for size values, (2) an invalid model, (3) a "newpos" value that is less than or equal to a size value, or (4) partial packets.
|
2005-02-28
|
Scrapland Server Malformed Packet DoS
|
|
14275
Description:
(Description Provided by CVE) : KPPP 2.1.2 in KDE 3.1.5 and earlier, when setuid root without certain wrappers, does not properly close a privileged file descriptor for a domain socket, which allows local users to read and write to /etc/hosts and /etc/resolv.conf and gain control over DNS name resolution by opening a number of file descriptors before executing kppp.
|
2005-02-28
|
KDE kppp Privileged File Descriptor Leak
|
|
14277
Description:
(Description Provided by CVE) : The web management interface for Mitel 3300 Integrated Communications Platform (ICP) before 4.2.2.11 generates easily predictable web session IDs, which allows remote attackers to hijack other sessions via the parentsessionid cookie.
|
2005-02-28
|
Mitel 3300 ICP Web Management Interface Session Hijacking
|
|
14278
Description:
(Description Provided by CVE) : The web management interface for Mitel 3300 Integrated Communications Platform (ICP) before 4.2.2.11 allows remote authenticated users to cause a denial of service (resource exhaustion) via a large number of active sessions, which exceeds ICP's maximum.
|
2005-02-28
|
Mitel 3300 ICP Web Management Interface Session Exhaustion DoS
|
|
14276
Description:
OpenBSD contains a flaw related to the copy(9) function that may allow an attacker to overwrite kernel memory. No further details have been provided.
|
2005-02-28
|
OpenBSD Unspecified copy(9) Function Issue
|
|
14271
Description:
(Description Provided by CVE) : The SMTP binding function in Symantec Firewall/VPN Appliance 200/200R firmware after 1.5Z and before 1.68, Gateway Security 360/360R and 460/460R firmware before vuild 858, and Nexland Pro800turbo, when configured for load balancing between two WANs, might send SMTP traffic to a trusted network through an untrusted network.
|
2005-02-28
|
Symantec Multiple Firewall SMTP Binding Configuration Bypass
|
|
14390
Description:
UnZip contains a flaw that may allow an attacker to gain access to unauthorized privileges. The issue is triggered when extracting setuid or setgid files, allowing a local attacker to gain root privileges.
|
2005-02-28
|
UnZip Extracted File setuid/setgid Weakness
|
|
14250
Description:
(Description Provided by CVE) : nxagent in FreeNX before 0.2.8 does not properly handle when the XAUTHORITY environment variable is not set, which allows local users to access the X server without X authentication.
|
2005-02-28
|
FreeNX X Server Authority File Absense Local Privilege Escalation
|
|
14290
Description:
(Description Provided by CVE) : Unknown vulnerability in FCKeditor 2.0 RC2, when used with PHP-Nuke, allows remote attackers to upload arbitrary files.
|
2005-02-28
|
PHP-Nuke FCKeditor connector.php File Upload Arbitrary PHP Code Execution
|
|
14317
Description:
(Description Provided by CVE) : lnss.exe in GFI Languard Network Security Scanner 5.0 stores the username and password in memory in plaintext, which could allow local administrators to obtain domain administrator credentials.
|
2005-02-28
|
GFI LANguard NSS MS-SQL/DOMAIN Local Password Disclosure
|
|
14242
Description:
phpBB contains a flaw that may allow a remote attacker to gain access to unauthorized privileges. The issue is triggered due to an error in the comparison of "sessiondata['autologinid']" and "auto_login_key". Further, phpBB does not reset the $userdata['user_level'] variable after a failed autologin. It is possible for a remote attacker to set a specially crafted cookie to change the user_id to that of an administrator resulting in a loss of integrity.
|
2005-02-27
|
phpBB sessions.php autologinid Remote Privilege Escalation
|
|
23394
Description:
LinPHA contains a flaw related to the Edit_File_Info.php, Edit_File_Info_Example.php and Write_File_Info.php scripts that may allow an attacker to manipulate files without proper permission. No further details have been provided.
|
2005-02-27
|
LinPHA Multiple Script Unspecified File Manipulation Issue
|
|
23395
Description:
LinPHA contains a flaw related to the exif thumbnail features invoked by the get_*_thumb.php files. This may allow a remote attacker to gain access to private images. No further details have been provided.
|
2005-02-27
|
LinPHA Unspecified Thumbnail Image Disclosure
|
|
27680
Description:
Unknown / Incomplete
|
2005-02-27
|
Mamblog WYSIWYG Editor Unauthorized Media Folder File Deletion
|
|
14212
Description:
Einstein contains a flaw that may lead to an unauthorized information disclosure. The issue is due to plaintext storage of passwords in the registry, which may disclose username (mail address) and passwords to local users resulting in a loss of confidentiality.
|
2005-02-27
|
Einstein Registry Cleartext Password Disclosure
|
|
14247
Description:
(Description Provided by CVE) : PHP 4 (PHP4) allows attackers to cause a denial of service (daemon crash) by using the readfile function on a file whose size is a multiple of the page size.
|
2005-02-26
|
PHP4 readfile() Function DoS
|
|
14273
Description:
(Description Provided by CVE) : Multiple vulnerabilities in Pixel-Apes SafeHTML before 1.3.0 allow remote attackers to bypass cross-site scripting (XSS) protection via (1) "decimal HTML entities" or (2) "the \x00 symbol."
|
2005-02-26
|
SafeHTML Decimal HTML Entities Bypass
|
|
14274
Description:
Unknown / Incomplete
|
2005-02-26
|
SafeHTML x00 Symbol Bypass
|
|
14243
Description:
phpBB contains a flaw that may lead to an unauthorized information disclosure. The issue is triggered when an invalid date is passed to the viewtopic.php script, which will disclose the software installation path resulting in a loss of confidentiality.
|
2005-02-26
|
phpBB viewtopic.php Path Disclosure
|
|
29045
Description:
Various SISCO products contain a flaw in the OSI Stack that may allow a remote denial of service. The issue is triggered when handling unspecified packet data. With a specially crafted request, a remote attacker can cause an affected process to terminate.
|
2005-02-26
|
SISCO OSI Stack Vulnerability Scan Remote DoS
|
|
15298
Description:
Unknown / Incomplete
|
2005-02-26
|
cPanel/WHM SSH Port Forwarding Anonymous Proxy
|
|
14198
Description:
(Description Provided by CVE) : Firefox before 1.0.1 and Mozilla Suite before 1.7.6 use a predictable filename for the plugin temporary directory, which allows local users to delete arbitrary files of other users via a symlink attack on the plugtmp directory.
|
2005-02-25
|
Mozilla Browsers Predictable Plugin Temp Directory Arbitrary File Deletion
|
|
14197
Description:
Firefox contains a flaw that may allow a malicious user to execute arbitrary code. The issue is triggered when downloading a malformed HTML document that includes Firefox XPCOM code to perform actions that are triggered by scrollbar actions. It is possible that the flaw may allow writing to an arbitrary local file.
|
2005-02-25
|
Mozilla Browsers XPCOM Scrollbar Arbitrary Code Execution
|
|
14138
Description:
Unknown / Incomplete
|
2005-02-25
|
DelphiTurk e-Posta profiles.adt Local Password Disclosure
|
|
14137
Description:
(Description Provided by CVE) : DelphiTurk FTP 1.0 stores usernames and passwords in the profile.dat file, which allows local users to gain privileges.
|
2005-02-25
|
DelphiTurk FTP profile.dat Local Password Disclosure
|
|
14577
Description:
(Description Provided by CVE) : Evolution 2.0.3 allows remote attackers to cause a denial of service (application crash or hang) via crafted messages, possibly involving charsets in attachment filenames.
|
2005-02-25
|
Ximian Evolution Email Attachment Saturation DoS
|
|
14239
Description:
Stormy Studios KNet contains an overflow condition that is triggered as user-supplied input is not properly validated when handling HTTP GET requests. With a specially crafted request, a remote attacker can cause a stack-based buffer overflow, allowing the execution of arbitrary code.
|
2005-02-25
|
Stormy Studios KNet HTTP GET Request Handling Remote Buffer Overflow
|
|
14293
Description:
Unknown / Incomplete
|
2005-02-25
|
Java FSP Library TCP Sequence Prediction
|
|
14294
Description:
Unknown / Incomplete
|
2005-02-25
|
Java FSP Library Received Packet Command And File Issue
|
|
14246
Description:
(Description Provided by CVE) : bsmtpd 2.3 and earlier does not properly sanitize e-mail addresses, which allows remote attackers to execute arbitrary commands.
|
2005-02-25
|
bsmtpd Malformed Address Arbitrary Command Injection
|