| OSVDB ID | Disclosure Date | Title |
|
19088
Description:
(Description Provided by CVE) : forum_post.php in e107 0.6 allows remote attackers to post to non-existent forums by modifying the forum number.
|
2005-08-30
|
e107 forum_post.php Non-existant Forum Post DoS
|
|
19079
Description:
Unknown / Incomplete
|
2005-08-30
|
FreeStyle Wiki Management Page Arbitrary Command Injection
|
|
19083
Description:
(Description Provided by CVE) : lockmail in maildrop before 1.5.3 does not drop privileges before executing commands, which allows local users to gain privileges via command line arguments.
|
2005-08-30
|
maildrop lockmail Privileged Local Command Execution
|
|
19114
Description:
(Description Provided by CVE) : Cross-site scripting (XSS) vulnerability in FlatNuke 2.5.6 allows remote attackers to inject arbitrary web script or HTML via the usr parameter in a vis_reg operation to index.php.
|
2005-08-30
|
FlatNuke index.php usr Variable XSS
|
|
19115
Description:
(Description Provided by CVE) : print.php in FlatNuke 2.5.6 allows remote attackers to obtain sensitive information (path disclosure on error) or cause a denial of service (resource consumption) via an MS-DOS device name in the news parameter to print.php, such as (1) AUX, (2) CON, (3) PRN, (4) COM1, or (5) LPT1.
|
2005-08-30
|
FlatNuke print.php news Variable MS-DOS Device Request Path Disclosure
|
|
19116
Description:
(Description Provided by CVE) : print.php in FlatNuke 2.5.6 allows remote attackers to obtain sensitive information (path disclosure on error) or cause a denial of service (resource consumption) via an MS-DOS device name in the news parameter to print.php, such as (1) AUX, (2) CON, (3) PRN, (4) COM1, or (5) LPT1.
|
2005-08-30
|
FlatNuke print.php Null Byte Resource Consumption DoS
|
|
19117
Description:
Unknown / Incomplete
|
2005-08-30
|
FlatNuke index.php Null Byte Resource Consumption DoS
|
|
19118
Description:
(Description Provided by CVE) : Directory traversal vulnerability in FlatNuke 2.5.6 and possibly earlier allows remote attackers to read arbtirary files via ".." sequences and "%00" (trailing null byte) characters in the id parameter to the read mod in index.php.
|
2005-08-30
|
FlatNuke index.php id Variable Traversal Arbitrary File Access
|
|
19077
Description:
(Description Provided by CVE) : cosmoshop 8.10.78 and earlier stores passwords in plaintext in the database, which allows local users to obtain sensitive information.
|
2005-08-30
|
Cosmoshop Database Cleartext Password Storage
|
|
19082
Description:
(Description Provided by CVE) : Multiple stack-based buffer overflows in University of Minnesota gopher client 3.0.9 allow remote malicious servers to execute arbitrary code via (1) a long "+VIEWS:" reply, which is not properly handled in the VIfromLine function, and (2) certain arguments when launching third party programs such as a web browser from a web link, which is not properly handled in the FIOgetargv function.
|
2005-08-30
|
UMN Gopher +VIEWS: Reply VIfromLine() Function Overflow
|
|
19067
Description:
(Description Provided by CVE) : phpldapadmin before 0.9.6c allows remote attackers to gain anonymous access to the LDAP server, even when disable_anon_bind is set, via an HTTP request to login.php with the anonymous_bind parameter set.
|
2005-08-30
|
phpLDAPadmin Unspecified Anonymous Bind Policy Bypass
|
|
20707
Description:
(Description Provided by CVE) : db2fmp process in IBM DB2 Content Manager before 8.2 Fix Pack 10 allows local users to cause a denial of service (CPU consumption) by importing a corrupted Microsoft Excel file, aka "CORRUPTED EXEL FILE WILL CAUSE TEXT SEARCH PROCESS LOOPING."
|
2005-08-30
|
IBM DB2 Content Manager Malformed Excel File db2fmp Process DoS
|
|
24605
Description:
(Description Provided by CVE) : Cross-site scripting (XSS) vulnerability in WebHost Automation Ltd Helm before 3.2.6 allows remote attackers to inject arbitrary web script or HTML via unknown vectors involving the default page.
|
2005-08-30
|
Helm Control Panel Default Page Unspecified XSS
|
|
20312
Description:
Unknown / Incomplete
|
2005-08-29
|
Sun Java System Directory Server passwordRetryCount Increment Failure
|
|
19089
Description:
Unknown / Incomplete
|
2005-08-29
|
Microsoft IE Unspecified Remote Code Execution
|
|
19068
Description:
(Description Provided by CVE) : PHP remote file inclusion vulnerability in welcome.php in phpLDAPadmin 0.9.6 and 0.9.7 allows remote attackers to execute arbitrary PHP code via the custom_welcome_page parameter.
|
2005-08-29
|
phpLDAPadmin welcome.php custom_welcome_page Variable Arbitrary File Inclusion
|
|
19732
Description:
(Description Provided by CVE) : Multiple cross-site scripting (XSS) vulnerabilities in MediaWiki before 1.4.9 allow remote attackers to inject arbitrary web script or HTML via (1) <math> tags or (2) Extension or <nowiki> sections that "bypass HTML style attribute restrictions" that are intended to protect against XSS vulnerabilities in Internet Explorer clients.
|
2005-08-29
|
MediaWiki math Tag XSS
|
|
19733
Description:
(Description Provided by CVE) : Multiple cross-site scripting (XSS) vulnerabilities in MediaWiki before 1.4.9 allow remote attackers to inject arbitrary web script or HTML via (1) <math> tags or (2) Extension or <nowiki> sections that "bypass HTML style attribute restrictions" that are intended to protect against XSS vulnerabilities in Internet Explorer clients.
|
2005-08-29
|
MediaWiki Extension / <nowiki> Table Syntax XSS
|
|
19069
Description:
(Description Provided by CVE) : client.cpp in BNBT EasyTracker 7.7r3.2004.10.27 and earlier allows remote attackers cause a denial of service (application hang) via an HTTP header containing only a ":" (colon), possibly leading to an integer signedness error due to a missing field name or value.
|
2005-08-29
|
BNBT EasyTracker Malformed GET Request DoS
|
|
19047
Description:
(Description Provided by CVE) : Cross-site scripting (XSS) vulnerability in SqWebMail 5.0.4 and possibly other versions allows remote attackers to inject arbitrary web script or HTML via an HTML e-mail containing tags with strings that contain ">" or other special characters, which is not properly sanitized by SqWebMail.
|
2005-08-29
|
SqWebMail HTML Email img src Tag Arbitrary Script Insertion
|
|
19055
Description:
(Description Provided by CVE) : The xntpd ntp (ntpd) daemon before 4.2.0b, when run with the -u option and using a string to specify the group, uses the group ID of the user instead of the group, which causes xntpd to run with different privileges than intended.
|
2005-08-29
|
NTP ntpd -u Group Permission Weakness
|
|
19071
Description:
(Description Provided by CVE) : Helpdesk software Hesk 0.92 does not properly verify usernames and passwords, which allows remote attackers to bypass authentication via a direct request to admin_main.php.
|
2005-08-29
|
Hesk Helpdesk Admin Authentication Bypass
|
|
19073
Description:
(Description Provided by CVE) : BFCommand & Control Server Manager BFCC 1.22_A and earlier, and BFVCC 2.14_B and earlier, allows remote attackers to bypass authentication via (1) an unknown attack vector or (2) a NULL (0x00) as a username.
|
2005-08-29
|
BFCommand & Control Server Authentication Bypass
|
|
19074
Description:
(Description Provided by CVE) : BFCommand & Control Server Manager BFCC 1.22_A and earlier, and BFVCC 2.14_B and earlier, relies on the client to enforce permissions and perform actions such as disconnections, which allows remote attackers to bypass administrative restrictions via a modified client.
|
2005-08-29
|
BFCommand & Control Server Client-Side Command Weakness
|
|
19075
Description:
(Description Provided by CVE) : BFCommand & Control Server Manager BFCC 1.22_A and earlier, and BFVCC 2.14_B and earlier, allows remote attackers to cause a denial of service (refused new connections) via a series of connections and disconnections without sending the login command.
|
2005-08-29
|
BFCommand & Control Server Connection Saturation DoS
|
|
19076
Description:
(Description Provided by CVE) : SQL injection vulnerability in the login function for the administration login panel in cosmoshop 8.10.78 allows remote attackers to execute arbitrary SQL commands and bypass authentication via unspecified vectors.
|
2005-08-29
|
Cosmoshop Login SQL Injection
|
|
19078
Description:
(Description Provided by CVE) : Directory traversal vulnerability in bestmail_edit.cgi in cosmoshop 8.10.78 and earlier allows remote administrators to read arbitrary files via ".." sequences in the file parameter.
|
2005-08-29
|
Cosmoshop bestmail_edit.cgi file Variable Traversal Arbitrary File Access
|
|
19165
Description:
(Description Provided by CVE) : smb4k 0.4 and other versions before 0.6.3 allows local users to read sensitive files via a symlink attack on the (1) smb4k.tmp or (2) sudoers temporary files.
|
2005-08-29
|
Smb4k kdesu Dialog super.tab File Disclosure
|
|
19299
Description:
Land Down Under (LDU) contains a flaw that may allow a remote attacker to carry out an SQL injection attack. The issue is due to the 'index.php' script not properly sanitizing user-supplied input to the 'c' variable. This may allow a remote attacker to inject or manipulate SQL queries in the backend database.
|
2005-08-29
|
Land Down Under (LDU) index.php c Variable SQL Injection
|
|
19300
Description:
Land Down Under (LDU) contains a flaw that may allow a remote attacker to carry out an SQL injection attack. The issue is due to the 'events.php' script not properly sanitizing user-supplied input to the 'c' variable. This may allow a remote attacker to inject or manipulate SQL queries in the backend database.
|
2005-08-29
|
Land Down Under (LDU) events.php c Variable SQL Injection
|
|
24885
Description:
Unknown / Incomplete
|
2005-08-29
|
Dnsmasq Config File Name Format String
|
|
21580
Description:
(Description Provided by CVE) : The (1) cgiwrap and (2) php-cgiwrap packages before 3.9 in Debian GNU/Linux provide access to debugging CGIs under the web document root, which allows remote attackers to obtain sensitive information via direct requests to those CGIs.
|
2005-08-28
|
CGIWrap Debugging CGI Remote Information Disclosure
|
|
21579
Description:
(Description Provided by CVE) : The CGIwrap program before 3.9 on Debian GNU/Linux uses an incorrect minimum value of 100 for a UID to determine whether it can perform a seteuid operation, which could allow attackers to execute code as other system UIDs that are greater than the minimum value, which should be 1000 on Debian systems.
|
2005-08-28
|
CGIWrap on Debian UID Mismatch Privilege Escalation
|
|
19070
Description:
(Description Provided by CVE) : comment_delete_cgi.php in Simple PHP Blog allows remote attackers to delete arbitrary files via the comment parameter.
|
2005-08-28
|
Simple PHP Blog (SPHPBlog) comment_delete_cgi.php Arbitrary File Deletion
|
|
19072
Description:
(Description Provided by CVE) : Cross-site scripting (XSS) vulnerability in PHP-Fusion 6.00.107 and earlier allows remote attackers to inject arbitrary web script or HTML via nested, malformed URL BBCode tags.
|
2005-08-28
|
PHP-Fusion Nested URL BBcode XSS
|
|
19298
Description:
(Description Provided by CVE) : Cross-site scripting (XSS) vulnerability in Land Down Under (LDU) allows remote attackers to inject arbitrary web script or HTML via a signature.
|
2005-08-28
|
Land Down Under (LDU) User Signature XSS
|
|
19066
Description:
(Description Provided by CVE) : PHP remote file inclusion vulnerability in al_initialize.php for AutoLinks Pro 2.1 allows remote attackers to execute arbitrary PHP code via an "ftp://" URL in the alpath parameter, which bypasses the incomplete blacklist that only checks for "http" and "https" URLs.
|
2005-08-28
|
AutoLinks Pro al_initialize.php alpath Variable Remote File Inclusion
|
|
19091
Description:
(Description Provided by CVE) : php_api.php in phpWebNotes 2.0.0 uses the extract function to modify key variables such as $t_path_core, which leads to a PHP file inclusion vulnerability that allows remote attackers to execute arbitrary PHP code via the t_path_core parameter.
|
2005-08-27
|
phpWebNotes api.php t_path_core Variable Remote File Inclusion
|
|
19090
Description:
Unknown / Incomplete
|
2005-08-27
|
vBulletin backup.php Backup File Remote Disclosure
|
|
29350
Description:
(Description Provided by CVE) : Unspecified vulnerability in the stats module in Gallery 1.5.1-RC2 and earlier allows remote attackers to obtain sensitive information via unspecified attack vectors, related to "two file exposure bugs."
|
2005-08-27
|
The Gallery Stats Module Unspecified File Disclosure
|