| OSVDB ID | Disclosure Date | Title |
|
17322
Description:
(Description Provided by CVE) : Multiple cross-site scripting (XSS) vulnerabilities in Annuaire 1Two 1.1 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the id parameter to index.php, or the (2) site_id, (3) nom, (4) email, or (5) commentaire parameters in commentaires.php.
|
2005-05-17
|
1Two Comment Multiple Field Script Insertion
|
|
16646
Description:
Shop-Script FREE contains a flaw that may allow a remote attacker to inject arbitrary SQL queries. The issue is due to the 'categoryID' and 'ProductID' variables in the 'index.php' script not being properly sanitized and may allow a remote attacker to inject or manipulate SQL queries.
|
2005-05-17
|
Shop-Script FREE index.php Multiple Parameter SQL Injection
|
|
16776
Description:
A local overflow exists in the vmstat utility, distributed as part of the procps package. The 'partition' variable fails to perform proper bounds checking resulting in a buffer overflow. With a specially crafted request to the '-p' argument, a malicious user can cause arbitrary code execution resulting in a loss of integrity.
|
2005-05-17
|
procps vmstat -p Argument Local Overflow
|
|
28015
Description:
Unknown / Incomplete
|
2005-05-17
|
Globus Toolkit MDS3 Index Service ScriptExecutionProvider Arbitrary Command Execution
|
|
28014
Description:
Unknown / Incomplete
|
2005-05-17
|
Globus Toolkit Aggregator Execution Source aggrexec Arbitrary Command Execution
|
|
16621
Description:
Fastream NETFile FTP/Web Server contains a flaw that may lead to an information disclosure. The problem is that the FTP server does not validate IP addresses supplied via the PORT command while in passive(PASV) mode. It is possible for a remote attacker to establish a connection between the FTP server and an arbitrary port on a third-party system, essentially conducting a port-scan. This can be used to obscure the the source of the port-scan, as well as scan internal systems that may be protected by a screening device.
|
2005-05-17
|
Fastream NETFile FTP/Web Server Port Scan Bounce Weakness
|
|
18207
Description:
(Description Provided by CVE) : Multiple buffer overflows in HP Tru64 UNIX 5.1a, 5.1, 5.0a, 4.0g, and 4.0f allow local users to gain root privileges via (1) su, (2) chsh, (3) passwd, (4) chfn, (5) dxchpwd, and (6) libc.
|
2005-05-16
|
HP Tru64 UNIX dxchpwd Local Overflow
|
|
18808
Description:
(Description Provided by CVE) : vlan_dev.c in the VLAN code for Linux kernel 2.6.8 allows remote attackers to cause a denial of service (kernel oops from null dereference) via certain UDP packets that lead to a function call with the wrong argument, as demonstrated using snmpwalk on snmpd.
|
2005-05-16
|
Linux Kernel vlan_dev.c UDP Packet NULL Pointer Dereference DoS
|
|
16575
Description:
Woltlab Burning Board contains a flaw that may allow an attacker to inject arbitrary SQL queries. The issue is due to the $email variable in the verify_email() function not being properly sanitized and may allow an attacker to inject or manipulate SQL queries.
|
2005-05-16
|
WoltLab Burning Board verify_email() Function SQL Injection
|
|
16612
Description:
SafeHTML contains a flaw that may allow a malicious user to bypass security in the quoting of HTML entrires. The issue is triggered when the _writeAttrs() function incorrectly handles specifically crafted HTML. It is possible that the flaw may allow a security bypass resulting in a loss of integrity.
|
2005-05-16
|
SafeHTML _writeAttrs() Quote Handling Security Bypass
|
|
16628
Description:
pServ contains a flaw that may allow a malicious user to view arbitrary files on the system. The issue is due to the web server not differentiating between files and symbolic links. It is possible for a local user with access to the web server directory to create a symbolic link from a critical file on the system to a file in the web server. Visiting the link via the server will disclose the contents of the linked file resulting in a loss of confidentiality.
|
2005-05-16
|
Pico Server (pServ) Symlink Privileged File Disclosure
|
|
16629
Description:
pServ contains a flaw that may lead to an unauthorized information disclosure. The issue is due to pServ only treating URLs beginning with "cgi-bin" as valid CGI script requests. By sending a crafted command such as "/somedir/../cgi-bin/file.cgi", the server will treat it as a standard request for a file and not process the CGI requested; displaying the source code instead.
|
2005-05-16
|
Pico Server (pServ) Crafted Request CGI Source Disclosure
|
|
16630
Description:
pServ contains a flaw that allows a remote attacker to execute arbitrary commands outside of the web path. The issue is due to the server not properly sanitizing user input, specifically traversal style attacks (../../) supplied via the URI.
|
2005-05-16
|
Pico Server (pServ) Traversal Arbitrary Command Execution
|
|
16618
Description:
(Description Provided by CVE) : Keyvan1 ImageGallery stores the image.mdb database under the web document root with insufficient access control, which allows remote attackers to obtain sensitive information.
|
2005-05-16
|
ImageGallery image.mdb User Database Disclosure
|
|
16614
Description:
(Description Provided by CVE) : Multiple cross-site scripting (XSS) vulnerabilities in DotNetNuke before 3.0.12 allow remote attackers to inject arbitrary web script or HTML via the (1) register a new user page, (2) User-Agent, or (3) Username, which is not properly quoted before sending to the error log.
|
2005-05-16
|
DotNetNuke New User Registration XSS
|
|
16615
Description:
(Description Provided by CVE) : Multiple cross-site scripting (XSS) vulnerabilities in DotNetNuke before 3.0.12 allow remote attackers to inject arbitrary web script or HTML via the (1) register a new user page, (2) User-Agent, or (3) Username, which is not properly quoted before sending to the error log.
|
2005-05-16
|
DotNetNuke User-Agent String XSS
|
|
16616
Description:
(Description Provided by CVE) : Multiple cross-site scripting (XSS) vulnerabilities in DotNetNuke before 3.0.12 allow remote attackers to inject arbitrary web script or HTML via the (1) register a new user page, (2) User-Agent, or (3) Username, which is not properly quoted before sending to the error log.
|
2005-05-16
|
DotNetNuke Username Field Log Viewer XSS
|
|
16617
Description:
(Description Provided by CVE) : Directory traversal vulnerability in the pnModFunc function in pnMod.php for PostNuke 0.750 through 0.760rc4 allows remote attackers to read arbitrary files via a .. (dot dot) in the func parameter to index.php.
|
2005-05-16
|
PostNuke Blocks Module index.php func Parameter Traversal Arbitrary File Access
|
|
16664
Description:
JGS-Portal for Woltlab Burning Board contains a flaw that may lead to an unauthorized information disclosure. The issue is triggered when an attacker makes a direct request to a script and provides no arguments, which will disclose the installation path of the application resulting in a loss of confidentiality.
|
2005-05-16
|
JGS-Portal for WoltLab Burning Board Error Routine Path Disclosure
|
|
16665
Description:
JGS-Portal for Woltlab Burning Board contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the 'anzahl_beitraege' variable upon submission to the jgs_portal.php script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2005-05-16
|
JGS-Portal for WoltLab Burning Board jgs_portal.php anzahl_beitraege Parameter XSS
|
|
16666
Description:
JGS-Portal for Woltlab Burning Board contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the 'year' variable upon submission to the jgs_portal_statistik.php script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2005-05-16
|
JGS-Portal for WoltLab Burning Board jgs_portal_statistik.php year Parameter XSS
|
|
16667
Description:
JGS-Portal for Woltlab Burning Board contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the 'year' variable upon submission to the jgs_portal_beitraggraf.php script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2005-05-16
|
JGS-Portal for WoltLab Burning Board jgs_portal_beitraggraf.php year Parameter XSS
|
|
16668
Description:
JGS-Portal for Woltlab Burning Board contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the 'tag' variable upon submission to the jgs_portal_viewsgraf.php script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2005-05-16
|
JGS-Portal for WoltLab Burning Board jgs_portal_viewsgraf.php tag Parameter XSS
|
|
16669
Description:
JGS-Portal for Woltlab Burning Board contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the 'year' variable upon submission to the jgs_portal_themengraf.php script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2005-05-16
|
JGS-Portal for WoltLab Burning Board jgs_portal_themengraf.php year Parameter XSS
|
|
16670
Description:
JGS-Portal for Woltlab Burning Board contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the 'id' variable upon submission to the jgs_portal_sponsor.php script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2005-05-16
|
JGS-Portal for WoltLab Burning Board jgs_portal_sponsor.php id Parameter XSS
|
|
16671
Description:
JGS-Portal for Woltlab Burning Board contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the 'id' variable upon submission to the jgs_portal_box.php script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2005-05-16
|
JGS-Portal for WoltLab Burning Board jgs_portal_box.php id Parameter XSS
|
|
16672
Description:
JGS-Portal for Woltlab Burning Board contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the 'year' variable upon submission to the jgs_portal_mitgraf.php script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2005-05-16
|
JGS-Portal for WoltLab Burning Board jgs_portal_mitgraf.php year Parameter XSS
|
|
16673
Description:
JGS-Portal for Woltlab Burning Board contains a flaw that may allow an attacker to inject arbitrary SQL queries. The issue is due to the 'year' variable in the jgs_portal_statistik.php script not being properly sanitized and may allow an attacker to inject or manipulate SQL queries.
|
2005-05-16
|
JGS-Portal for WoltLab Burning Board jgs_portal_statistik.php year Parameter SQL Injection
|
|
16674
Description:
JGS-Portal for Woltlab Burning Board contains a flaw that may allow an attacker to inject arbitrary SQL queries. The issue is due to the 'year' variable in the jgs_portal_beitraggraf.php script not being properly sanitized and may allow an attacker to inject or manipulate SQL queries.
|
2005-05-16
|
JGS-Portal for WoltLab Burning Board jgs_portal_beitraggraf.php year Parameter SQL Injection
|
|
16675
Description:
JGS-Portal for Woltlab Burning Board contains a flaw that may allow an attacker to inject arbitrary SQL queries. The issue is due to the 'tag' variable in the jgs_portal_viewsgraf.php script not being properly sanitized and may allow an attacker to inject or manipulate SQL queries.
|
2005-05-16
|
JGS-Portal for WoltLab Burning Board jgs_portal_viewsgraf.php tag Parameter SQL Injection
|
|
16676
Description:
JGS-Portal for Woltlab Burning Board contains a flaw that may allow an attacker to inject arbitrary SQL queries. The issue is due to the 'year' variable in the jgs_portal_themengraf.php script not being properly sanitized and may allow an attacker to inject or manipulate SQL queries.
|
2005-05-16
|
JGS-Portal for WoltLab Burning Board jgs_portal_themengraf.php year Parameter SQL Injection
|
|
16677
Description:
JGS-Portal for Woltlab Burning Board contains a flaw that may allow an attacker to inject arbitrary SQL queries. The issue is due to the 'anzahl_beitraege' variable in the jgs_portal.php script not being properly sanitized and may allow an attacker to inject or manipulate SQL queries.
|
2005-05-16
|
JGS-Portal for WoltLab Burning Board jgs_portal.php anzahl_beitraege Parameter SQL Injection
|
|
16678
Description:
JGS-Portal for Woltlab Burning Board contains a flaw that may allow an attacker to inject arbitrary SQL queries. The issue is due to the 'year' variable in the jgs_portal_mitgraf.php script not being properly sanitized and may allow an attacker to inject or manipulate SQL queries.
|
2005-05-16
|
JGS-Portal for WoltLab Burning Board jgs_portal_mitgraf.php year Parameter SQL Injection
|
|
16679
Description:
JGS-Portal for Woltlab Burning Board contains a flaw that may allow an attacker to inject arbitrary SQL queries. The issue is due to the 'id' variable in the jgs_portal_sponsor.php script not being properly sanitized and may allow an attacker to inject or manipulate SQL queries.
|
2005-05-16
|
JGS-Portal for WoltLab Burning Board jgs_portal_sponsor.php id Parameter SQL Injection
|
|
16680
Description:
JGS-Portal for Woltlab Burning Board contains a flaw that may allow an attacker to inject arbitrary SQL queries. The issue is due to the Accept-Language header field in the jgs_portal_log.php script not being properly sanitized and may allow an attacker to inject or manipulate SQL queries.
|
2005-05-16
|
JGS-Portal for WoltLab Burning Board jgs_portal_log.php Accept-Language Header SQL Injection
|
|
16681
Description:
JGS-Portal for Woltlab Burning Board contains a flaw that may allow an attacker to inject arbitrary SQL queries. The issue is due to the 'id' variable in the jgs_portal_box.php script not being properly sanitized and may allow an attacker to inject or manipulate SQL queries.
|
2005-05-16
|
JGS-Portal for WoltLab Burning Board jgs_portal_box.php id Parameter SQL Injection
|
|
16725
Description:
SecurityAgent in Mac OS X contains a flaw that may allow a malicious user to bypass screensaver restrictions. The issue is triggered when opening a URL from a text input field via the contextual menu. It is possible that the flaw may allow a malicious user to launch an arbitrary application behind a locked screensaver window resulting in a loss of integrity.
|
2005-05-16
|
Apple Mac OS X SecurityAgent ScreenSaver Bypass
|
|
16726
Description:
Mac OS X contains a flaw that may lead to an unauthorized information disclosure. The issue is due to the incorrect checking of permissions on enclosing directories without the POSIX read, but with the POSIX execute bits set for group and other, which will disclose file names in restricted directories resulting in a loss of confidentiality.
|
2005-05-16
|
Apple Mac OS X File System Search Arbitrary File Name Disclosure
|
|
16608
Description:
(Description Provided by CVE) : The pkt_ioctl function in the pktcdvd block device ioctl handler (pktcdvd.c) in Linux kernel 2.6.12-rc4 and earlier calls the wrong function before passing an ioctl to the block device, which crosses security boundaries by making kernel address space accessible from user space and allows local users to cause a denial of service and possibly execute arbitrary code, a similar vulnerability to CVE-2005-1264.
|
2005-05-16
|
Linux Kernel pktcdvd Device ioctl_by_bdev() Function Kernel Memory Corruption
|
|
16609
Description:
The Linux Kernel contains a flaw that may allow a malicious user to gain access to unauthorized privileges. The issue is triggered when input to the raw Device ioctl_by_bdev() function is not validated correctly. This flaw may lead to execution of arbitrary code with kernel level privileges and a loss of Integrity.
|
2005-05-16
|
Linux Kernel raw Device ioctl_by_bdev() Function Kernel Memory Corruption
|