| OSVDB ID | Disclosure Date | Title |
|
23569
Description:
(Description Provided by CVE) : Directory traversal vulnerability in HP System Management Homepage (SMH) 2.0.0 through 2.1.4 on Windows allows remote attackers to access certain files via unspecified vectors.
|
2006-02-09
|
HP System Management Homepage (SMH) on Windows Unspecified Traversal Arbitrary File Access
|
|
23191
Description:
(Description Provided by CVE) : mail_html template in Squishdot 1.5.0 and earlier does not properly validate the (1) email and (2) title variables, which allows remote attackers to bypass spam filters by injecting SMTP headers, probably due to a CRLF injection vulnerability.
|
2006-02-09
|
Squishdot mail_html Templates Mail Header Injection Arbitrary Mail Relay
|
|
22973
Description:
(Description Provided by CVE) : Multiple directory traversal vulnerabilities in PHP iCalendar 2.0.1, 2.1, and 2.2 allow remote attackers to include arbitrary files via the (1) getdate and possibly other parameters used in the replace_files function in search.php and (2) $file variable as used in the parse function in functions/template.php.
|
2006-02-09
|
PHP iCalendar template.php file Variable File Inclusion
|
|
22974
Description:
(Description Provided by CVE) : Multiple directory traversal vulnerabilities in PHP iCalendar 2.0.1, 2.1, and 2.2 allow remote attackers to include arbitrary files via the (1) getdate and possibly other parameters used in the replace_files function in search.php and (2) $file variable as used in the parse function in functions/template.php.
|
2006-02-09
|
PHP iCalendar search.php getdate Variable File Inclusion
|
|
23154
Description:
(Description Provided by CVE) : Multiple SQL injection vulnerabilities in cms/index.php in Magic Calendar Lite 1.02, with magic_quotes_gpc disabled, allow remote attackers to execute arbitrary SQL commands via the (1) $total_login and (2) $total_password parameter.
|
2006-02-09
|
Magic Calendar Lite cms/index.php Multiple Field SQL Injection
|
|
23176
Description:
(Description Provided by CVE) : settings.php in Reamday Enterprises Magic Downloads 1.1.3, when register_globals is enabled, allows remote attackers to modify program behavior, potentially bypassing authentication controls, via modified (1) action, (2) passwd, (3) admin_password, (4) new_passwd, and (5) confirm_passwd variables, which are not initialized.
|
2006-02-09
|
Magic Downloads settings.php Unauthorized Data Modification
|
|
23177
Description:
(Description Provided by CVE) : PHP remote file inclusion vulnerability in preview.php in Reamday Enterprises Magic News Lite 1.2.3, when register_globals is enabled, allows remote attackers to include arbitrary files via a URL in the php_script_path parameter.
|
2006-02-09
|
Magic News Lite preview.php php_script_path Variable Arbitrary PHP Code Execution
|
|
23178
Description:
(Description Provided by CVE) : profile.php in Reamday Enterprises Magic News Lite 1.2.3, when register_globals is enabled, allows remote attackers to modify program behavior, potentially bypassing authentication controls, via modified (1) action, (2) passwd, (3) admin_password, (4) new_passwd, and (5) confirm_passwd variables, which are not initialized.
|
2006-02-09
|
Magic News Lite profile.php Unauthorized Data Modification
|
|
22989
Description:
Indexu contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the 'base_path' variable upon submission to the application.php script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2006-02-09
|
INDEXU application.php base_path Parameter Remote File Inclusion
|
|
30949
Description:
(Description Provided by CVE) : Pioneers meta-server before 0.9.55, when the server-console is not installed, allows remote attackers to cause a denial of service (crash) via certain requests from an older gnocatan client to create a new game.
|
2006-02-08
|
Pioneers meta-server gnocatan Client New Game Request DoS
|
|
22997
Description:
WiredRed e/pop Conferencing software contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the topic name upon submission to the public or private conference. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2006-02-08
|
WiredRed e/pop Conference Topic Name XSS
|
|
22972
Description:
Unknown / Incomplete
|
2006-02-08
|
cPanel Null Login Administrator Username Disclosure
|
|
22971
Description:
cPanel contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the 'fwd' variable upon submission to the 'dowebmailforward.cgi' script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2006-02-08
|
cPanel dowebmailforward.cgi fwd Parameter XSS
|
|
25230
Description:
(Description Provided by CVE) : The TIFFToRGB function in libtiff before 3.8.1 allows remote attackers to cause a denial of service (crash) via a crafted TIFF image with Yr/Yg/Yb values that exceed the YCR/YCG/YCB values, which triggers an out-of-bounds read.
|
2006-02-08
|
LibTIFF libtiff/tif_color.c TIFFToRGB() Color Mapping Value Overflows
|
|
23058
Description:
CPG-Nuke Dragonfly CMS contains a flaw that allows a remote attacker to include outside of the web path. The issue is due to the install.php not properly sanitizing user input, specifically traversal style attacks (../../) supplied via the 'newlang' variable. This flaw permits the inclusion of files controlled by remote user input, which may be leveraged to execute arbitrary code, resulting in a loss of integrity.
|
2006-02-08
|
CPG Dragonfly CMS install.php newlang Parameter Local File Inclusion
|
|
23086
Description:
SPIP contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to the spip_rss.php script not properly sanitizing user input supplied to the 'type_urls' variable. This may allow an attacker to include an arbitrary file from the local system that contains arbitrary commands which will be executed by the vulnerable script.
|
2006-02-08
|
SPIP spip_rss.php type_urls Parameter Traversal Local File Inclusion
|
|
23087
Description:
SPIP contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the 'spip_acces_doc.php3' script not properly sanitizing user-supplied input to the 'file' variable. This may allow an attacker to inject or manipulate SQL queries in the back-end database.
|
2006-02-08
|
SPIP spip_acces_doc.php3 file Parameter SQL Injection
|
|
23173
Description:
(Description Provided by CVE) : edituser.php in TTS Time Tracking Software 3.0 does not verify that the name and password are correct, which allows remote attackers to overwrite arbitrary data belonging to any account.
|
2006-02-08
|
Time Tracking Software edituser.php Unauthorized Data Modification
|
|
23174
Description:
(Description Provided by CVE) : Multiple SQL injection vulnerabilities in TTS Time Tracking Software 3.0 allow remote attackers to execute arbitrary SQL commands via unspecified vectors.
|
2006-02-08
|
Time Tracking Software Multiple Unspecified SQL Injection
|
|
23175
Description:
(Description Provided by CVE) : Cross-site scripting (XSS) vulnerability in the Registration Form in TTS Time Tracking Software 3.0 allows remote attackers to inject arbitrary web script or HTML via the UserName parameter.
|
2006-02-08
|
Time Tracking Software Registration Form UserName Field XSS
|
|
23126
Description:
(Description Provided by CVE) : Buffer overflow in the arp command of IBM AIX 5.3 L, 5.3, 5.2.2, 5.2 L, and 5.2 allows local users to cause a denial of service (crash) via a long iftype argument.
|
2006-02-08
|
IBM AIX arp iftype Argument Local Overflow
|
|
23039
Description:
(Description Provided by CVE) : Cross-site scripting (XSS) vulnerability in DataparkSearch before 4.37 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
|
2006-02-08
|
DataparkSearch Unspecified XSS
|
|
23198
Description:
Unknown / Incomplete
|
2006-02-08
|
Apache WSS4J Library SOAP Signature Verification Bypass
|
|
22996
Description:
(Description Provided by CVE) : LDAP service in Sun Java System Directory Server 5.2, running on Linux and possibly other platforms, allows remote attackers to cause a denial of service (memory allocation error) via an LDAP packet with a crafted subtree search request, as demonstrated using the ProtoVer LDAP test suite.
|
2006-02-08
|
Sun Java System Directory Server LDAP Malformed Packet DoS
|
|
22969
Description:
Whomp! Real Estate Manager XP contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the login function not properly sanitizing user-supplied input to the 'username' or 'password' fields. This may allow an attacker to inject or manipulate SQL queries in the back-end database.
|
2006-02-08
|
Whomp Real Estate Manager XP Admin Login Multiple Field SQL Injection
|
|
23044
Description:
(Description Provided by CVE) : Microsoft Windows XP SP1 and SP2 before August 2004, and possibly other operating systems and versions, uses insecure default ACLs that allow the Authenticated Users group to gain privileges by modifying critical configuration information for the (1) Simple Service Discovery Protocol (SSDP), (2) Universal Plug and Play Device Host (UPnP), (3) NetBT, (4) SCardSvr, (5) DHCP, and (6) DnsCache services, aka "Permissive Windows Services DACLs." NOTE: the NetBT, SCardSvr, DHCP, DnsCache already require privileged access to exploit.
|
2006-02-08
|
Microsoft Windows UPnP SERVICE_CHANGE_CONFIG Permission Weakness Privilege Escalation
|
|
23045
Description:
(Description Provided by CVE) : Microsoft Windows XP SP1 and SP2 before August 2004, and possibly other operating systems and versions, uses insecure default ACLs that allow the Authenticated Users group to gain privileges by modifying critical configuration information for the (1) Simple Service Discovery Protocol (SSDP), (2) Universal Plug and Play Device Host (UPnP), (3) NetBT, (4) SCardSvr, (5) DHCP, and (6) DnsCache services, aka "Permissive Windows Services DACLs." NOTE: the NetBT, SCardSvr, DHCP, DnsCache already require privileged access to exploit.
|
2006-02-08
|
Microsoft Windows NetBT SERVICE_CHANGE_CONFIG Permission Weakness Privilege Escalation
|
|
23046
Description:
(Description Provided by CVE) : Microsoft Windows XP SP1 and SP2 before August 2004, and possibly other operating systems and versions, uses insecure default ACLs that allow the Authenticated Users group to gain privileges by modifying critical configuration information for the (1) Simple Service Discovery Protocol (SSDP), (2) Universal Plug and Play Device Host (UPnP), (3) NetBT, (4) SCardSvr, (5) DHCP, and (6) DnsCache services, aka "Permissive Windows Services DACLs." NOTE: the NetBT, SCardSvr, DHCP, DnsCache already require privileged access to exploit.
|
2006-02-08
|
Microsoft Windows SCardSvr SERVICE_CHANGE_CONFIG Permission Weakness Privilege Escalation
|
|
23047
Description:
(Description Provided by CVE) : Microsoft Windows XP SP1 and SP2 before August 2004, and possibly other operating systems and versions, uses insecure default ACLs that allow the Authenticated Users group to gain privileges by modifying critical configuration information for the (1) Simple Service Discovery Protocol (SSDP), (2) Universal Plug and Play Device Host (UPnP), (3) NetBT, (4) SCardSvr, (5) DHCP, and (6) DnsCache services, aka "Permissive Windows Services DACLs." NOTE: the NetBT, SCardSvr, DHCP, DnsCache already require privileged access to exploit.
|
2006-02-08
|
Microsoft Windows SSDP SERVICE_CHANGE_CONFIG Permission Weakness Privilege Escalation
|
|
22970
Description:
(Description Provided by CVE) : Untrusted search path vulnerability in opcontrol in OProfile 0.9.1 and earlier allows local users to execute arbitrary commands via a modified PATH that references malicious (1) which or (2) dirname programs. NOTE: while opcontrol normally is not run setuid, a common configuration suggests accessing opcontrol using sudo. In such a context, this is a vulnerability.
|
2006-02-07
|
OProfile opcontrol Path Subversion Privilege Escalation
|
|
23509
Description:
GA's Forum Light has been reported to contain an SQL injection issue in the archive.asp script. Subsequent testing by SecurityTracker after the vendor disputed the issue indicates the software uses flat files to store data, not a back-end database. Therefore, the SQL injection report is incorrect and was likely diagnosed due to a vbscript parsing error.
|
2006-02-07
|
GA's Forum Light archive.asp Multiple Parameter SQL Injection
|
|
23156
Description:
(Description Provided by CVE) : Multiple SQL injection vulnerabilities in Carey Briggs PHP/MYSQL Timesheet 1 and 2 allow remote attackers to execute arbitrary SQL commands via the (1) yr, (2) month, (3) day, and (4) job parameters in (a) index.php and (b) changehrs.php.
|
2006-02-07
|
PHP/MYSQL Timesheet index.php Multiple Parameter SQL Injection
|
|
23157
Description:
(Description Provided by CVE) : Multiple SQL injection vulnerabilities in Carey Briggs PHP/MYSQL Timesheet 1 and 2 allow remote attackers to execute arbitrary SQL commands via the (1) yr, (2) month, (3) day, and (4) job parameters in (a) index.php and (b) changehrs.php.
|
2006-02-07
|
PHP/MYSQL Timesheet changehrs.php Multiple Parameter SQL Injection
|
|
22987
Description:
(Description Provided by CVE) : Unspecified vulnerability in the Lexmark Printer Sharing LexBce Server Service (LexPPS), possibly 8.29 and 9.41, allows remote attackers to execute arbitrary code via unspecified vectors. NOTE: This information is based on a vague initial disclosure; details will be updated after the grace period has ended.
|
2006-02-07
|
Lexmark Printer Sharing LexBce Server (LexPPS) Unspecified Arbitrary Code Execution
|
|
22988
Description:
(Description Provided by CVE) : Lexmark X1185 printer allows local users to gain SYSTEM privileges by navigating to the "Appearance" dialog and selecting the "Additional styles (skins) are available on the Lexmark web site" option, which launches a web browser that is running with SYSTEM privileges.
|
2006-02-07
|
Lexmark X1100 Series Printing Software Appearance Icon Privilege Escalation
|
|
23005
Description:
(Description Provided by CVE) : The crypt_gensalt functions for BSDI-style extended DES-based and FreeBSD-sytle MD5-based password hashes in crypt_blowfish 0.4.7 and earlier do not evenly and randomly distribute salts, which makes it easier for attackers to guess passwords from a stolen password file due to the increased number of collisions.
|
2006-02-07
|
crypt_blowfish crypt_gensalt*() Functions Salt Generation Weakness
|
|
22958
Description:
QNX Neutrino RTOS contains a flaw that may allow a local user to gain elevated privileges. The issue is due to the /etc/rc.d/rc.local file installing with world writeable permissions. This allows any user to add arbitrary commands that will be executed with root privileges upon the next system startup.
|
2006-02-07
|
QNX Neutrino RTOS rc.local Permission Weakness Privilege Escalation
|
|
22959
Description:
A local overflow exists in QNX Neutrino RTOS. The 'passwd' binary fails to properly check user-supplied input as the first argument to the program resulting in a buffer overflow. With a specially crafted request, an attacker can cause the execution of arbitrary code with root priveleges.
|
2006-02-07
|
QNX Neutrino RTOS passwd First Parameter Local Overflow
|
|
22960
Description:
QNX Neutrino RTOS contains a flaw that may allow a local denial of service. The issue is triggered when a local user sends a crafted break signal (0xb032d59) to the gdb utility, and will result in loss of availability for the system.
|
2006-02-07
|
QNX Neutrino RTOS gdb Crafted String Local DoS
|
|
22961
Description:
A local overflow exists in QNX Neutrino RTOS. The 'su' binary fails to properly check user-supplied input as the first argument to the program resulting in a buffer overflow. With a specially crafted request, an attacker can cause the execution of arbitrary code with root priveleges.
|
2006-02-07
|
QNX Neutrino RTOS su First Parameter Local Overflow
|