| OSVDB ID | Disclosure Date | Title |
|
31217
Description:
(Description Provided by CVE) : Multiple PHP remote file inclusion vulnerabilities in MWChat Pro 7.0 allow remote attackers to execute arbitrary PHP code via a URL in the CONFIG[MWCHAT_Libs] parameter to (1) about.php, (2) buddy.php, (3) chat.php, (4) dialog.php, (5) head.php, (6) help.php, (7) index.php, and (8) license.php, different vectors than CVE-2005-1869.
|
2006-11-03
|
MWChat license.php CONFIG[MWCHAT_Libs] Parameter Remote File Inclusion
|
|
32632
Description:
Unknown / Incomplete
|
2006-11-03
|
Simplog Admin Panel user.php Multiple Field XSS
|
|
32633
Description:
Unknown / Incomplete
|
2006-11-03
|
Simplog Admin Panel news.php URL XSS
|
|
32634
Description:
Unknown / Incomplete
|
2006-11-03
|
Simplog Admin Panel edit.php Multiple Field XSS
|
|
32635
Description:
Unknown / Incomplete
|
2006-11-03
|
Simplog archive.php pid Parameter XSS
|
|
32636
Description:
Unknown / Incomplete
|
2006-11-03
|
Simplog archive.php Multiple Parameter SQL Injection
|
|
32637
Description:
Unknown / Incomplete
|
2006-11-03
|
Simplog index.php blogid Parameter SQL Injection
|
|
30186
Description:
MODx contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to Thumbnail.php not properly sanitizing user input supplied to the 'base_path' variable. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script.
|
2006-11-03
|
MODx Thumbnail.php base_path Parameter Remote File Inclusion
|
|
33951
Description:
(Description Provided by CVE) : Unspecified vulnerabilities in PHP, probably before 5.2.0, allow local users to bypass open_basedir restrictions and perform unspecified actions via unspecified vectors involving the (1) chdir and (2) tempnam functions. NOTE: the tempnam vector might overlap CVE-2006-1494.
|
2006-11-02
|
PHP Multiple Function open_basedir Restriction Unspecified Bypass
|
|
36647
Description:
(Description Provided by CVE) : Unspecified vulnerability in the tab editor for Personal .NET Portal before 2.0.0 has unknown impact and attack vectors related to a "Security leak."
|
2006-11-02
|
Personal .NET Portal Tab Editor Unspecified
|
|
33968
Description:
(Description Provided by CVE) : PHP remote file inclusion vulnerability in volume.php in Article System 0.6 allows remote attackers to execute arbitrary PHP code via a URL in the config[public_dir] parameter.
|
2006-11-02
|
Article System volume.php config[public_dir] Parameter Remote File Inclusion
|
|
30178
Description:
(Description Provided by CVE) : Buffer overflow in PHP before 5.2.0 allows remote attackers to execute arbitrary code via crafted UTF-8 inputs to the (1) htmlentities or (2) htmlspecialchars functions.
|
2006-11-02
|
PHP htmlentities() Function UTF-8 Input Overflow
|
|
30179
Description:
(Description Provided by CVE) : Buffer overflow in PHP before 5.2.0 allows remote attackers to execute arbitrary code via crafted UTF-8 inputs to the (1) htmlentities or (2) htmlspecialchars functions.
|
2006-11-02
|
PHP htmlspecialchars() Function UTF-8 Input Overflow
|
|
30217
Description:
(Description Provided by CVE) : Directory traversal vulnerability in classes/index.php in Lithium CMS 4.04c and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the siteconf[curl] parameter, as demonstrated by a POST to news/comment.php containing PHP code, which is stored under db/comments/news/ and included by classes/index.php.
|
2006-11-02
|
Lithium CMS /classes/index.php siteconf[curl] Traversal Arbitrary File Execution
|
|
30192
Description:
(Description Provided by CVE) : Double free vulnerability in squashfs module in the Linux kernel 2.6.x, as used in Fedora Core 5 and possibly other distributions, allows local users to cause a denial of service by mounting a crafted squashfs filesystem.
|
2006-11-02
|
Linux Kernel squashfs Crafted Filesystem Mount Local DoS
|
|
30190
Description:
(Description Provided by CVE) : Yazd Discussion Forum before 3.0 beta does not properly manage forum permissions, which allows remote authenticated users to (1) reply to a message in an arbitrary forum, if authorized to create a message in any forum; and (2) perform certain unauthorized forum actions, related to an "error in how the permissions were assembled" that assigns extra permissions to users.
|
2006-11-02
|
Yazd Discussion Forum Unspecified User Privilege Escalation
|
|
30191
Description:
(Description Provided by CVE) : Yazd Discussion Forum before 3.0 beta does not properly manage forum permissions, which allows remote authenticated users to (1) reply to a message in an arbitrary forum, if authorized to create a message in any forum; and (2) perform certain unauthorized forum actions, related to an "error in how the permissions were assembled" that assigns extra permissions to users.
|
2006-11-02
|
Yazd Discussion Forum Message Cross Forum Privilege Escalation
|
|
83878
Description:
PHP contains a flaw that may allow a remote denial of service. The issue is triggered during the handling of a malformed color index, which causes an infinite loop. This will result in loss of availability for the program.
|
2006-11-02
|
PHP imagefill Malformed Color Index Handling Infinite Loop DoS
|
|
31704
Description:
(Description Provided by CVE) : Stack-based buffer overflow in Visual Studio Crystal Reports for Microsoft Visual Studio .NET 2002 and 2002 SP1, .NET 2003 and 2003 SP1, and 2005 and 2005 SP1 (formerly Business Objects Crystal Reports XI Professional) allows user-assisted remote attackers to execute arbitrary code via a crafted RPT file.
|
2006-11-02
|
Business Objects Crystal Reports Unspecified RPT Processing Overflow
|
|
30187
Description:
(Description Provided by CVE) : Multiple SQL injection vulnerabilities in index.php in FreeWebshop 2.2.1 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) password and (2) prod parameter.
|
2006-11-02
|
FreeWebshop.org Script index.php Multiple Parameter SQL Injection
|
|
30188
Description:
(Description Provided by CVE) : Directory traversal vulnerability in index.php in FreeWebshop 2.2.1 and earlier allows remote attackers to read arbitrary files and disclose the installation path via a .. (dot dot) in the action parameter.
|
2006-11-02
|
FreeWebshop.org Script index.php action Parameter Traversal Arbitrary File Access
|
|
41212
Description:
Unknown / Incomplete
|
2006-11-02
|
RunCMS Avatar Image Upload Arbitrary PHP Code Execution
|
|
32624
Description:
Unknown / Incomplete
|
2006-11-02
|
Microsoft IE mhtml Overflow DoS
|
|
41036
Description:
Unknown / Incomplete
|
2006-11-02
|
Microsoft IE DLL Search Path Subversion Local Privilege Escalation
|
|
42075
Description:
Unknown / Incomplete
|
2006-11-02
|
Archiva Password Reset Request Failure Weakness
|
|
30181
Description:
Unknown / Incomplete
|
2006-11-02
|
iodine DNS Response Overflow
|
|
53073
Description:
(Description Provided by CVE) : PHP remote file inclusion vulnerability in mod/nc_phpmyadmin/core/libraries/Theme_Manager.class.php in Ixprim 2.0 allows remote attackers to execute arbitrary PHP code via a URL in an unspecified parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
|
2006-11-02
|
Ixprim mod/nc_phpmyadmin/core/libraries/Theme_Manager.class.php Unspecified Parameter Remote File Inclusion
|
|
58603
Description:
FreeWebshop contains a flaw that may lead to an unauthorized information disclosure. The issue is triggered when a remote attacker passes an invalid 'action' parameter to the index.php script, which will disclose the software's installation path resulting in a loss of confidentiality. While such information is relatively low risk, it is often useful in carrying out additional, more focused attacks.
|
2006-11-02
|
FreeWebshop index.php action Parameter Traversal Error Message Path Disclosure
|
|
59234
Description:
(Description Provided by CVE) : ** DISPUTED ** Firefox 1.5.0.7 on Kubuntu Linux allows remote attackers to cause a denial of service (crash) via a long URL in an A tag. NOTE: this issue has been disputed by several vendors, who could not reproduce the report. In addition, the scope of the impact - system freeze - suggests an issue that is not related to Firefox. Due to this impact, CVE concurs with the dispute.
|
2006-11-02
|
Mozilla Firefox on Kubuntu A Tag URL Handling DoS
|
|
83877
Description:
PHP contains a flaw in the filter extension that is triggered when magic_quotes_gpc fails to be applied during the usage of RAW filters. This may allow an attacker to bypass authentication.
|
2006-11-02
|
PHP Filter Extension RAW Filter magic_quotes_gpc Restriction Bypass
|
|
41550
Description:
(Description Provided by CVE) : Multiple unspecified vulnerabilities in Firebird 1.5 allow remote attackers to (1) cause a denial of service (application crash) by sending many remote protocol versions; and (2) cause a denial of service (connection drop) via certain network traffic, as demonstrated by Nessus vulnerability scanning.
|
2006-11-01
|
Firebird Crafted Protocol Versions Remote DoS
|
|
41551
Description:
(Description Provided by CVE) : Multiple unspecified vulnerabilities in Firebird 1.5 allow remote attackers to (1) cause a denial of service (application crash) by sending many remote protocol versions; and (2) cause a denial of service (connection drop) via certain network traffic, as demonstrated by Nessus vulnerability scanning.
|
2006-11-01
|
Firebird Malformed Traffic (Vulnerability Scan) Remote DoS
|
|
41549
Description:
(Description Provided by CVE) : Firebird 1.5 allows remote authenticated users without SYSDBA and owner permissions to overwrite a database by creating a database.
|
2006-11-01
|
Firebird Database Creation Arbitrary Database Overwrite
|
|
41547
Description:
(Description Provided by CVE) : Multiple buffer overflows in Firebird 1.5, one of which affects WNET, have unknown impact and attack vectors. NOTE: this issue might overlap CVE-2006-1240.
|
2006-11-01
|
Firebird Multiple Unspecified Overflows
|
|
41548
Description:
(Description Provided by CVE) : Multiple buffer overflows in Firebird 1.5, one of which affects WNET, have unknown impact and attack vectors. NOTE: this issue might overlap CVE-2006-1240.
|
2006-11-01
|
Firebird WNET Unspecified Overflows
|
|
41546
Description:
(Description Provided by CVE) : fb_lock_mgr in Firebird 1.5 uses weak permissions (0666) for the semaphore array, which allows local users to cause a denial of service (blocked query processing) by locking semaphores.
|
2006-11-01
|
Firebird fb_lock_mgr Semaphore Array Locking Local DoS
|
|
30173
Description:
TikiWiki contains a flaw that allows a remote cross-site scripting (XSS) attack. This flaw exists because the application does not validate the 'url' parameter upon submission to the 'tiki-featured_link.php' script. This may allow a user to create a specially crafted URL that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2006-11-01
|
TikiWiki tiki-featured_link.php url Parameter Nested Tag XSS
|
|
30180
Description:
A remote overflow exists in Mac OS X. The Orinoco Airport driver fails to validate Probe Response Frames resulting in a heap overflow. With a specially crafted probe response, an attacker can cause arbitrary code execution resulting in a loss of integrity.
|
2006-11-01
|
Apple Mac OS X Orinoco Airport Crafted Probe Response Frame Arbitrary Code Execution
|
|
30753
Description:
(Description Provided by CVE) : Unspecified vulnerability in enserver.exe in SAP Web Application Server 6.40 before patch 136 and 7.00 before patch 66 allows remote attackers to read arbitrary files via crafted data on a "3200+SYSNR" TCP port, as demonstrated by port 3201. NOTE: this issue can be leveraged by local users to access a named pipe as the SAPServiceJ2E user.
|
2006-11-01
|
SAP Web Application Server Unspecified Arbitrary File Access
|
|
30754
Description:
(Description Provided by CVE) : Unspecified vulnerability in SAP Web Application Server 6.40 before patch 136 and 7.00 before patch 66 allows remote attackers to cause a denial of service (enserver.exe crash) via a 0x72F2 sequence on UDP port 64999.
|
2006-11-01
|
SAP Web Application Server enserver.exe Unspecified Remote DoS
|