| OSVDB ID | Disclosure Date | Title |
|
27534
Description:
Safari contains a flaw that may allow a malicious user to execute arbitrary code. The issue is caused due to an error in the 'KHTMLParser::popOneBlock()' function that can be exploited to cause a memory corruption via a script element in a div element redefining the document body. It is possible that the flaw may allow remote arbitrary code execution resulting in a loss of integrity.
|
2006-07-31
|
Apple Safari KHTMLParser::popOneBlock Code Execution
|
|
29868
Description:
(Description Provided by CVE) : PHP remote file inclusion vulnerability in administrator/components/com_bayesiannaivefilter/lang.php in the bayesiannaivefilter component (com_bayesiannaivefilter) 1.1 for Mambo allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.
|
2006-07-30
|
bayesiannaivefilter for Mambo lang.php mosConfig_absolute_path Variable Remote File Inclusion
|
|
39200
Description:
Unknown / Incomplete
|
2006-07-30
|
Seir Anphin CMS index.php m Variable SQL Injection
|
|
39201
Description:
Unknown / Incomplete
|
2006-07-30
|
Seir Anphin CMS article.php id Variable SQL Injection
|
|
39202
Description:
Unknown / Incomplete
|
2006-07-30
|
Seir Anphin CMS blog.php id Variable SQL Injection
|
|
39203
Description:
Unknown / Incomplete
|
2006-07-30
|
Seir Anphin CMS member.php id Variable SQL Injection
|
|
29074
Description:
(Description Provided by CVE) : PHP remote file inclusion vulnerability in phpAdsNew/view.inc.php in Albasoftware Phpauction 2.1 and possibly later versions, with phpAdsNew 2.0.5, allows remote attackers to execute arbitrary PHP code via a URL in the phpAds_path parameter.
|
2006-07-30
|
phpAdsNew view.inc.php phpAds_path Variable Remote File Inclusion
|
|
29073
Description:
(Description Provided by CVE) : PHP remote file inclusion vulnerability in component/option,com_moskool/Itemid,34/admin.moskool.php in MamboXChange Moskool 1.5 allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.
|
2006-07-30
|
MamboXChange Moskool admin.moskool.php mosConfig_absolute_path Variable Remote File Inclusion
|
|
27647
Description:
BomberClone contains a flaw that may allow a malicious user to cause a denial of service. The issue is triggered when sending a specially crafted packet that is processed and used incorrectly in a memcpy function. Due to a big-endian check bypass it is possible that the flaw may cause a NULL dereference or overwrite of parts of the memory resulting in a loss availability.
|
2006-07-30
|
BomberClone rscache_add Crafted Packet Remote DoS
|
|
27648
Description:
BomberClone contains a flaw that may lead to an unauthorized information disclosure. The issue is triggered when sending a specialy crafted packet (containing a huge word value related to the length of the packet), which will disclose part of the memory in the answering packet payload resulting in a loss of confidentiality.
|
2006-07-30
|
BomberClone send_pkg Function Remote Information Disclosure
|
|
27649
Description:
BomberClone contains a flaw that may allow a malicious user to crash the server. The issue is triggered when sending an error message packet (normaly sent to clients) to the server. It is possible that the flaw may cause the server to crash resulting in a loss of availability.
|
2006-07-30
|
BomberClone Error Message Server Termination DoS
|
|
27651
Description:
UHP for Mambo and Joomla contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to the uhp_config.php script not properly sanitizing user input supplied to the 'mosConfig_absolute_path' variable. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script.
|
2006-07-30
|
UHP for Mambo uhp_config.php mosConfig_absolute_path Variable Remote File Inclusion
|
|
27652
Description:
UHP for Mambo and Joomla contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to footer.php not properly sanitizing user input supplied to the "mosConfig_absolute_path" variable. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script.
|
2006-07-30
|
UHP for Mambo footer.php mosConfig_absolute_path Variable Remote File Inclusion
|
|
28111
Description:
UHP for Mambo and Joomla contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to install.uhp.php not properly sanitizing user input supplied to the "mosConfig_absolute_path" variable. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script.
|
2006-07-30
|
UHP for Mambo install.uhp.php mosConfig_absolute_path Variable Remote File Inclusion
|
|
28112
Description:
UHP for Mambo and Joomla contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to functions.php not properly sanitizing user input supplied to the "mosConfig_absolute_path" variable. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script.
|
2006-07-30
|
UHP for Mambo functions.php mosConfig_absolute_path Variable Remote File Inclusion
|
|
28113
Description:
UHP for Mambo and Joomla contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to uninstall.uhp.php not properly sanitizing user input supplied to the "mosConfig_absolute_path" variable. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script.
|
2006-07-30
|
UHP for Mambo uninstall.uhp.php mosConfig_absolute_path Variable Remote File Inclusion
|
|
27665
Description:
ATutor contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the "links/index.php" script not properly sanitizing user-supplied input to the 'asc' and 'desc' variables. This may allow an attacker to inject or manipulate SQL queries in the backend database.
|
2006-07-30
|
ATutor links/index.php Multiple Variable SQL Injection
|
|
28078
Description:
(Description Provided by CVE) : PHP remote file inclusion vulnerability in artlinks.dispnew.php in the Artlinks component (com_artlinks) for Mambo allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.
|
2006-07-29
|
artlinks for Mambo/Joomla artlinks.dispnew.php mosConfig_absolute_path Variable Remote File Inclusion
|
|
29087
Description:
(Description Provided by CVE) : PHP remote file inclusion vulnerability in tpl.inc.php in Falko Timme and Till Brehm SQLiteWebAdmin 0.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the conf[classpath] parameter.
|
2006-07-29
|
SQLiteWebAdmin tpl.inc.php conf[classpath] Variable Remote File Inclusion
|
|
29088
Description:
(Description Provided by CVE) : PHP remote file inclusion vulnerability in tpl.inc.php in Falko Timme and Till Brehm SQLiteWebAdmin 0.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the conf[classpath] parameter.
|
2006-07-29
|
SQLiteWebAdmin table_editfield.php table Variable SQL Injection
|
|
29089
Description:
(Description Provided by CVE) : Multiple SQL injection vulnerabilities in Banex PHP MySQL Banner Exchange 2.21 allow remote attackers to execute arbitrary SQL commands via the (1) site_name parameter to (a) signup.php, and the (2) id, (3) deleteuserbanner, (4) viewmem, (5) viewmemunb, (6) viewunmem,or (7) deleteuser parameters to (b) admin.php.
|
2006-07-29
|
Banex signup.php site_name Variable SQL Injection
|
|
29090
Description:
(Description Provided by CVE) : Multiple SQL injection vulnerabilities in Banex PHP MySQL Banner Exchange 2.21 allow remote attackers to execute arbitrary SQL commands via the (1) site_name parameter to (a) signup.php, and the (2) id, (3) deleteuserbanner, (4) viewmem, (5) viewmemunb, (6) viewunmem,or (7) deleteuser parameters to (b) admin.php.
|
2006-07-29
|
Banex admin.php Multiple Variable SQL Injection
|
|
29091
Description:
(Description Provided by CVE) : PHP remote file inclusion vulnerability in members.php in Banex PHP MySQL Banner Exchange 2.21 allows remote attackers to execute arbitrary PHP code via a URL in the cfg_root parameter.
|
2006-07-29
|
Banex members.php cfg_root Variable Remote File Inclusion
|
|
29092
Description:
(Description Provided by CVE) : Banex PHP MySQL Banner Exchange 2.21 stores lib.inc under the web document root with insufficient access control, which allows remote attackers to obtain sensitive information such as database usernames and passwords.
|
2006-07-29
|
Banex lib.inc Authentication Credential Disclosure
|
|
29069
Description:
(Description Provided by CVE) : The ip2long function in PHP 5.1.4 and earlier may incorrectly validate an arbitrary string and return a valid network IP address, which allows remote attackers to obtain network information and facilitate other attacks, as demonstrated using SQL injection in the X-FORWARDED-FOR Header in index.php in MiniBB 2.0. NOTE: it could be argued that the ip2long behavior represents a risk for security-relevant issues in a way that is similar to strcpy's role in buffer overflows, in which case this would be a class of implementation bugs that would require separate CVE items for each PHP application that uses ip2long in a security-relevant manner.
|
2006-07-29
|
PHP ip2long() Function String Validation Weakness
|
|
43945
Description:
Unknown / Incomplete
|
2006-07-29
|
InspIRCd m_timedbans.so Unspecified Issue
|
|
27634
Description:
X-Poll contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the top.php script not properly sanitizing user-supplied input to the 'poll' variable. This may allow an attacker to inject or manipulate SQL queries in the backend database.
|
2006-07-29
|
X-Poll top.php poll Variable SQL Injection
|
|
27633
Description:
WordPress contains a flaw related to some unspecified errors that can cause unknown impacts. No further details have been provided.
|
2006-07-29
|
WordPress Multiple Unspecified Issues
|
|
27635
Description:
X-Protection contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the protect.php script not properly sanitizing user-supplied input to the password and username variables via the POST method. This may allow an attacker to inject or manipulate SQL queries in the backend database.
|
2006-07-29
|
X-Protection protect.php password username Variables POST Method SQL Injection
|
|
27642
Description:
Ajax Chat contains a flaw that allows a remote attacker to disclose the content of arbitrary files outside of the web path. The issue is due to the operator_chattranscript.php script not properly sanitizing user input, specifically directory traversal style attacks (../../) supplied via the 'chatid' variable.
|
2006-07-29
|
Ajax Chat operator_chattranscript.php chatid Variable Traversal Arbitrary File Access
|
|
27643
Description:
Ajax Chat contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate 'userid' variable upon submission to the chat.php script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2006-07-29
|
Ajax Chat chat.php userid Variable XSS
|
|
27659
Description:
Colophon for Joomla contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to the admin.colophon.php script not properly sanitizing user input supplied to the 'mosConfig_absolute_path' variable. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script.
|
2006-07-29
|
Colophon for Joomla admin.colophon.php mosConfig_absolute_path Variable Remote File Inclusion
|
|
27629
Description:
AWBS contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the 'Name', 'AccountUsername' and 'Message' variables upon submission to the contact.php script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2006-07-29
|
AWBS contact.php Multiple Variable XSS
|
|
27636
Description:
X-Statistics contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the x-statistics.php script not properly sanitizing user-supplied input to the 'User-Agent' HTTP header. This may allow an attacker to inject or manipulate SQL queries in the backend database.
|
2006-07-29
|
X-Statistics x-statistics.php User-Agent HTTP Header SQL Injection
|
|
27704
Description:
(Description Provided by CVE) : Directory traversal vulnerability in index.php in vbPortal 3.0.2 through 3.6.0 Beta 1, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the bbvbplang cookie, as demonstrated by injecting PHP sequences into an Apache HTTP Server log file, which is then included by index.php.
|
2006-07-29
|
vbPortal bbvbplang Cookie Variable Local File Inclusion
|
|
28312
Description:
(Description Provided by CVE) : Cross-site scripting (XSS) vulnerability in usercp.php in MyBB (aka MyBulletinBoard) 1.x allows remote attackers to inject arbitrary web script or HTML via the gallery parameter.
|
2006-07-29
|
MyBulletinBoard (MyBB) usercp.php gallery Variable XSS
|
|
28313
Description:
(Description Provided by CVE) : Directory traversal vulnerability in usercp.php in MyBB (aka MyBulletinBoard) 1.x allows remote attackers to read arbitrary files via a .. (dot dot) in the gallery parameter in a (1) avatar or (2) do_avatar action.
|
2006-07-29
|
MyBulletinBoard (MyBB) usercp.php gallery Variable Traversal Arbitrary File Access
|
|
27532
Description:
Internet Explorer contains a flaw that may allow a local denial of service. The issue is triggered when opening a web page containing a script which calls the 'ADODB.Recordset' ActiveX object's 'NextRecordset' method several times with a long argument. This will result in an invalid memory access causing the browser to crash.
|
2006-07-29
|
Microsoft IE ADODB.Recordset SysFreeString Invalid Length
|
|
27533
Description:
Microsoft IE contains a flaw that may allow a local denial of service. The issue is triggered when a NULL pointer is referenced by accessing the property of an object that is inside a deleted frame, and will result in loss of availability for the service.
|
2006-07-29
|
Microsoft IE Orphan Object Property Access NULL Dereference
|
|
29128
Description:
(Description Provided by CVE) : The Graphical Device Interface Plus library (gdiplus.dll) in Microsoft Windows XP SP2 allows context-dependent attackers to cause a denial of service (application crash) via certain images that trigger a divide-by-zero error, as demonstrated by a (1) .ico file, (2) .png file that crashes MSN Messenger, and (3) .jpg file that crashes Internet Explorer. NOTE: another researcher has not been able to reproduce this issue.
|
2006-07-28
|
Microsoft Windows gdiplus.dll Divide-by-zero DoS
|