| OSVDB ID | Disclosure Date | Title |
|
29355
Description:
PHlyMail Lite has been reported to contain a flaw that may allow a remote attacker to execute arbitrary commands. The issue is supposedly due to the mod.output.php script not properly sanitizing user input supplied to the '_PM_[path][handler]' variable. However, the script must be called directly to manipulate this variable, but in calling the script directly it will die without code execution.
|
2006-08-18
|
PHlyMail Lite handlers/email/mod.output.php _PM_[path][handler] Parameter Remote File Inclusion
|
|
29351
Description:
(Description Provided by CVE) : The Terminal Services COM object (tsuserex.dll) allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code by instantiating it as an ActiveX object in Internet Explorer 6.0 SP1 on Microsoft Windows 2003 EE SP1 CN.
|
2006-08-18
|
Microsoft Windows Terminal Services tsuserex.dll COM Object Instantiation
|
|
28100
Description:
Unknown / Incomplete
|
2006-08-18
|
Poll Component for Joomla pollAddVote Function Vote Manipulation
|
|
28098
Description:
(Description Provided by CVE) : PHP remote file inclusion vulnerability in config.kochsuite.php in the Kochsuite (com_kochsuite) 0.9.4 component for Mambo and Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.
|
2006-08-18
|
Kochsuite for Joomla config.kochsuite.php mosConfig_absolute_path Parameter Remote File Inclusion
|
|
28096
Description:
Joomla Rssxt has been reported to contain a flaw that may allow a remote attacker to execute arbitrary commands. The issue is supposedly due to multiple scripts not properly sanitizing user input supplied to the 'mosConfig_absolute_path' variable. Subsequent evaluation has revealed that for each script, an attacker does not have the ability to manipulate the variable.
|
2006-08-18
|
Joomla Rssxt Multiple Script mosConfig_absolute_path Parameter Remote File Inclusion
|
|
28095
Description:
Joomla x-shop has been reported to contain a flaw that may allow a remote attacker to execute arbitrary commands. The issue is supposedly due to the admin.x-shop script not properly sanitizing user input supplied to the 'mosConfig_absolute_path' variable. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script.
|
2006-08-18
|
Joomla x-shop admin.x-shop mosConfig_absolute_path Parameter Remote File Inclusion
|
|
30716
Description:
(Description Provided by CVE) : idmlib.sh in nxdrv in Novell Identity Manager (IDM) 3.0.1 allows local users to execute arbitrary commands via unspecified vectors, possibly involving the " (quote) and \ (backslash) characters and eval injection.
|
2006-08-18
|
Novell Identity Manager nxdrv idmlib.sh Arbitrary ommand Execution
|
|
28089
Description:
(Description Provided by CVE) : PHP remote file inclusion vulnerability in MamboLogin.php in the MamboWiki component (com_mambowiki) 0.9.6 and earlier for Mambo and Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the IP parameter.
|
2006-08-18
|
MamboWiki for Joomla MamboLogin.php IP Parameter Remote File Inclusion
|
|
28151
Description:
mambo-phpShop contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to mod_phpshop.php not properly sanitizing user input supplied to the 'mosConfig_absolute_path' variable. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script.
|
2006-08-18
|
mambo-phpShop mod_phpshop.php mosConfig_absolute_path Parameter Remote File Inclusion
|
|
28152
Description:
mambo-phpShop contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to mod_phpshop_allinone.php not properly sanitizing user input supplied to the 'mosConfig_absolute_path' variable. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script.
|
2006-08-18
|
mambo-phpShop mod_phpshop_allinone.php mosConfig_absolute_path Parameter Remote File Inclusion
|
|
28153
Description:
mambo-phpShop contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to mod_phpshop_cart.php not properly sanitizing user input supplied to the 'mosConfig_absolute_path' variable. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script.
|
2006-08-18
|
mambo-phpShop mod_phpshop_cart.php mosConfig_absolute_path Parameter Remote File Inclusion
|
|
28154
Description:
mambo-phpShup contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to mod_phpshop_featureprod.php not properly sanitizing user input supplied to the 'mosConfig_absolute_path' variable. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script.
|
2006-08-18
|
mambo-phpShop mod_phpshop_featureprod.php mosConfig_absolute_path Parameter Remote File Inclusion
|
|
28155
Description:
mambo-phpShop contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to mod_phpshop_latestprod.php not properly sanitizing user input supplied to the 'mosConfig_absolute_path' variable. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script.
|
2006-08-18
|
mambo-phpShop mod_phpshop_latestprod.php mosConfig_absolute_path Parameter Remote File Inclusion
|
|
28156
Description:
mambo-phpShop contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to mod_product_categories.php not properly sanitizing user input supplied to the 'mosConfig_absolute_path' variable. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script.
|
2006-08-18
|
mambo-phpShop mod_product_categories.php mosConfig_absolute_path Parameter Remote File Inclusion
|
|
28157
Description:
mambo-phpShop contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to mod_productscroller.php not properly sanitizing user input supplied to the 'mosConfig_absolute_path' variable. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script.
|
2006-08-18
|
mambo-phpShop mod_productscroller.php mosConfig_absolute_path Parameter Remote File Inclusion
|
|
28158
Description:
mambo-phpShop contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to mosproductsnap.php not properly sanitizing user input supplied to the 'mosConfig_absolute_path' variable. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script.
|
2006-08-18
|
mambo-phpShop mosproductsnap.php mosConfig_absolute_path Parameter Remote File Inclusion
|
|
84079
Description:
PHP on Win32 contains a flaw that may allow a denial of service. The issue is triggered when an error occurs in the GetNamedPipeInfo() function during the handling of streams. This will result in loss of availability for the program.
|
2006-08-18
|
PHP on Win32 GetNamedPipeInfo() Function Stream Handling DoS
|
|
52440
Description:
Unknown / Incomplete
|
2006-08-17
|
SHACAL-1 Algorithm (Full Round) Related-key Rectangle Attack Cryptanalysis Compromise
|
|
29477
Description:
(Description Provided by CVE) : PHP remote file inclusion vulnerability in pageheaderdefault.inc.php in Invisionix Roaming System Remote (IRSR) 0.2 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the _sysSessionPath parameter.
|
2006-08-17
|
Roaming System Remote (IRSR) pageheaderdefault.inc.php _sysSessionPath Parameter Remote File Inclusion
|
|
29476
Description:
(Description Provided by CVE) : SQL injection vulnerability in torrents.php in WebTorrent (WTcom) 0.2.4 and earlier allows remote attackers to execute arbitrary SQL commands via the cat parameter in category mode.
|
2006-08-17
|
WebTorrent torrents.php cat Parameter SQL Injection
|
|
27997
Description:
Unknown / Incomplete
|
2006-08-17
|
Gallery Unspecified Minor Information Disclosure
|
|
27998
Description:
Unknown / Incomplete
|
2006-08-17
|
Gallery Unspecified Session ID Disclosure
|
|
32195
Description:
(Description Provided by CVE) : Mantis before 1.1.0a2 does not implement per-item access control for Issue History (Bug History), which allows remote attackers to obtain sensitive information by reading the Change column, as demonstrated by the Change column of a custom field.
|
2006-08-17
|
Mantis Issue History Custom Field Information Disclosure
|
|
29185
Description:
(Description Provided by CVE) : Untrusted search path vulnerability in uucp in IBM AIX 5.2.0 and 5.3.0 allows local users to local users to gain privileges via a Trojan horse program involving uux.
|
2006-08-17
|
IBM AIX bos.net.uucp uucp Path Subversion Privilege Escalation
|
|
29183
Description:
(Description Provided by CVE) : Unspecified vulnerability in bos.net.tcp.client in IBM AIX 5.2.0 and 5.3.0 allows local users to execute arbitrary commands via unspecified vectors involving /etc/slip.login.
|
2006-08-17
|
IBM AIX bos.net.tcp.client slip.login Privilege Escalation
|
|
27960
Description:
A vulnerability which affects the as_bad() function of the GNU Binutils Assembler can be exploited by tricking a user into assembling a specially crafted source file. Successful exploitation can execute arbitrary code under the context of the logged on user.
|
2006-08-17
|
GNU Binutils Assembler as_bad() Function Local Overflow
|
|
28783
Description:
(Description Provided by CVE) : Race condition in Deja Vu, as used in Roxio Toast Titanium 7 and possibly other products, allows local users to execute arbitrary code via temporary files, including dejavu_manual.rb, which are executed with raised privileges.
|
2006-08-17
|
Roxio Toast Titanium dejavu_manual.rb Temp File Creation Privilege Escalation
|
|
27989
Description:
(Description Provided by CVE) : PHP remote file inclusion vulnerability in mambelfish.class.php in the mambelfish component (com_mambelfish) 1.1 and earlier for Mambo allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.
|
2006-08-17
|
MambelFish for Mambo/Joomla mambelfish.class.php mosConfig_absolute_path Parameter Remote File Inclusion
|
|
27990
Description:
(Description Provided by CVE) : PHP remote file inclusion vulnerability in install.jim.php in the JIM 1.0.1 component for Joomla or Mambo allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.
|
2006-08-17
|
JIM for Joomla install.jim.php mosConfig_absolute_path Parameter Remote File Inclusion
|
|
27971
Description:
(Description Provided by CVE) : PHP remote file inclusion vulnerability in archive.php in the mosListMessenger Component (com_lm) before 20060719 for Mambo and Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.
|
2006-08-17
|
mosListMessenger for Mambo archive.php mosConfig_absolute_path Parameter Remote File Inclusion
|
|
27991
Description:
a6MamboCredits contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to administrator/components/com_a6mambocredits/admin.a6mambocredits.php not properly sanitizing user input supplied to the 'mosConfig_absolute_path' variable. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script.
|
2006-08-17
|
a6MamboCredits for Mambo admin.a6mambocredits.php mosConfig_live_site Parameter Remote File Inclusion
|
|
27999
Description:
(Description Provided by CVE) : The cURL extension files (1) ext/curl/interface.c and (2) ext/curl/streams.c in PHP before 5.1.5 permit the CURLOPT_FOLLOWLOCATION option when open_basedir or safe_mode is enabled, which allows attackers to perform unauthorized actions, possibly related to the realpath cache.
|
2006-08-17
|
PHP cURL CURLOPT_FOLLOWLOCATION open_basedir/safe_mode Bypass
|
|
28001
Description:
(Description Provided by CVE) : Integer overflow in memory allocation routines in PHP before 5.1.6, when running on a 64-bit system, allows context-dependent attackers to bypass the memory_limit restriction.
|
2006-08-17
|
PHP on 64-bit memory_limit Unspecified Issue
|
|
28002
Description:
(Description Provided by CVE) : Buffer overflow in the LWZReadByte_ function in ext/gd/libgd/gd_gif_in.c in the GD extension in PHP before 5.1.5 allows remote attackers to have an unknown impact via a GIF file with input_code_size greater than MAX_LWZ_BITS, which triggers an overflow when initializing the table array.
|
2006-08-17
|
PHP GD Extension GIF Processing Overflow
|
|
28003
Description:
(Description Provided by CVE) : Multiple heap-based buffer overflows in the (1) str_repeat and (2) wordwrap functions in ext/standard/string.c in PHP before 5.1.5, when used on a 64-bit system, have unspecified impact and attack vectors, a different vulnerability than CVE-2006-1990.
|
2006-08-17
|
PHP on 64-bit str_repeat() Function Overflow
|
|
28004
Description:
(Description Provided by CVE) : Multiple heap-based buffer overflows in the (1) str_repeat and (2) wordwrap functions in ext/standard/string.c in PHP before 5.1.5, when used on a 64-bit system, have unspecified impact and attack vectors, a different vulnerability than CVE-2006-1990.
|
2006-08-17
|
PHP on 64-bit wordwrap() Function Overflow
|
|
28005
Description:
PHP contains a flaw that may allow an attacker to bypass security restrictions. The issue is due to the imap_body() function not properly sanitizing user-supplied input. By using crafted input, an attacker may be able to bypass the safe_mode and open_basedir security restrictions.
|
2006-08-17
|
PHP imap_body() Function open_basedir/safe_mode Bypass
|
|
28006
Description:
PHP contains a flaw that may allow an attacker to bypass security restrictions. The issue is due to the error_log() function not properly sanitizing user-supplied input. By using crafted input, an attacker may be able to bypass the safe_mode and open_basedir security restrictions.
|
2006-08-17
|
PHP error_log() Function open_basedir/safe_mode Bypass
|
|
28007
Description:
PHP contains a flaw that may allow an attacker to bypass security restrictions. The issue is due to the file_exists() function not properly sanitizing user-supplied input. By using crafted input, an attacker may be able to bypass the safe_mode and open_basedir security restrictions.
|
2006-08-17
|
PHP file_exists() Function open_basedir/safe_mode Bypass
|
|
28009
Description:
PHP contains a flaw that may allow an attacker to bypass security restrictions. The issue is due to the imap_reopen() function not properly sanitizing user-supplied input. By using crafted input, an attacker may be able to bypass the safe_mode and open_basedir security restrictions.
|
2006-08-17
|
PHP imap_reopen() Function open_basedir/safe_mode Bypass
|