| OSVDB ID | Disclosure Date | Title |
|
27796
Description:
(Description Provided by CVE) : Cross-site scripting (XSS) vulnerability in cake/libs/error.php in CakePHP before 1.1.7.3363 allows remote attackers to inject arbitrary web script or HTML via the URL, which is reflected back in a 404 ("Not Found") error page. NOTE: some of these details are obtained from third party information.
|
2006-08-06
|
CakePHP error.php XSS
|
|
27793
Description:
(Description Provided by CVE) : Multiple stack-based buffer overflows in Lhaz before 1.32 allow user-assisted attackers to execute arbitrary code via a long filename in (1) an LHZ archive, when saving the filename during extraction; and (2) an LHZ archive with an invalid CRC checksum, when constructing an error message.
|
2006-08-06
|
Lhaz LZH File Handling Filename Overflow
|
|
27794
Description:
(Description Provided by CVE) : Multiple stack-based buffer overflows in Lhaz before 1.32 allow user-assisted attackers to execute arbitrary code via a long filename in (1) an LHZ archive, when saving the filename during extraction; and (2) an LHZ archive with an invalid CRC checksum, when constructing an error message.
|
2006-08-06
|
Lhaz LZH File CRC Checksum Error Message Overflow
|
|
41607
Description:
(Description Provided by CVE) : Unspecified vulnerability in IBM WebSphere Application Server (WAS) before 5.1.1.14, and WAS for z/OS 601 before 6.0.2.13, has unknown impact and attack vectors, related to a "Potential security exposure," aka PK26123.
|
2006-08-06
|
IBM WebSphere Application Server (WAS) Unspecified Exposure (PK26123)
|
|
27823
Description:
Simplog contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate 'keyw' variables upon submission to the 'archive.php' script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2006-08-06
|
Simplog archive.php keyw Parameter XSS
|
|
29083
Description:
(Description Provided by CVE) : Cross-site scripting (XSS) vulnerability in blursoft blur6ex 0.3 allows remote attackers to inject arbitrary web script or HTML via a comment title.
|
2006-08-06
|
blur6ex Comment Title XSS
|
|
29100
Description:
(Description Provided by CVE) : Multiple PHP remote file inclusion vulnerabilities in Fabian Hainz phpCC Beta 4.2 allow remote attackers to execute arbitrary PHP code via a URL in the base_dir parameter to (1) login.php, (2) reactivate.php, or (3) register.php.
|
2006-08-06
|
phpCodeCabinet (phpCC) login.php base_dir Parameter Remote File Inclusion
|
|
29101
Description:
(Description Provided by CVE) : Multiple PHP remote file inclusion vulnerabilities in Fabian Hainz phpCC Beta 4.2 allow remote attackers to execute arbitrary PHP code via a URL in the base_dir parameter to (1) login.php, (2) reactivate.php, or (3) register.php.
|
2006-08-06
|
phpCodeCabinet (phpCC) reactivate.php base_dir Parameter Remote File Inclusion
|
|
29102
Description:
(Description Provided by CVE) : Multiple PHP remote file inclusion vulnerabilities in Fabian Hainz phpCC Beta 4.2 allow remote attackers to execute arbitrary PHP code via a URL in the base_dir parameter to (1) login.php, (2) reactivate.php, or (3) register.php.
|
2006-08-06
|
phpCodeCabinet (phpCC) register.php base_dir Parameter Remote File Inclusion
|
|
45259
Description:
(Description Provided by CVE) : Microsoft Internet Explorer allows remote attackers to cause a denial of service (crash) via an IFRAME with a certain XML file and XSL stylesheet that triggers a crash in mshtml.dll when a refresh is called, probably a null pointer dereference.
|
2006-08-06
|
Microsoft IE mshtml.dll Malformed IFRAME XML File / XSL Stylesheet Handling DoS
|
|
39605
Description:
(Description Provided by CVE) : Research in Motion BlackBerry Enterprise Server 4.0 through 4.1 has a default configuration that permits installation of arbitrary third-party applications on BlackBerry devices, which might facilitate loading of malware.
|
2006-08-05
|
BlackBerry Enterprise Server Third-party Application Installation Weakness
|
|
27797
Description:
(Description Provided by CVE) : Sign extension vulnerability in the createBrushIndirect function in the GDI library (gdi32.dll) in Microsoft Windows XP, Server 2003, and possibly other versions, allows user-assisted attackers to cause a denial of service (application crash) via a crafted WMF file.
|
2006-08-05
|
Microsoft Windows GDI library (gdi32.dll) createBrushIndirect Function WMF Parsing DoS
|
|
27826
Description:
(Description Provided by CVE) : SQL injection vulnerability in profile.php in XennoBB 2.1.0 and earlier allows remote authenticated users to execute arbitrary SQL commands via the (1) bday_day, (2) bday_month, and (3) bday_year parameters in the personal section.
|
2006-08-05
|
XennoBB profile.php Multiple Variable POST Method SQL Injection
|
|
27791
Description:
(Description Provided by CVE) : Multiple SQL injection vulnerabilities in trackback.php in myWebland myBloggie 2.1.4 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) title, (2) url, (3) excerpt, or (4) blog_name parameters.
|
2006-08-05
|
myBloggie trackback.php Multiple Parameter SQL Injection
|
|
27792
Description:
(Description Provided by CVE) : index.php in myWebland myBloggie 2.1.4 and earlier allows remote attackers to obtain sensitive information via a query that only specifies the viewdate mode, which reveals the table prefix in a SQL error message.
|
2006-08-05
|
myBloggie index.php viewdata Mode Table Prefix Disclosure
|
|
29082
Description:
(Description Provided by CVE) : Cross-site scripting (XSS) vulnerability in Fill Threads Database (FTD) 3.7.3 allows remote attackers to inject arbitrary web script or HTML via the (1) search field or (2) an e-mail message.
|
2006-08-05
|
Fill Threads Database (FTD) Multiple Field XSS
|
|
29411
Description:
(Description Provided by CVE) : Cross-site scripting (XSS) vulnerability in TinyPortal before 0.8.6 allows remote attackers to inject arbitrary web script or HTML via the shoutbox.
|
2006-08-05
|
Tinyportal Shoutbox username Field XSS
|
|
27807
Description:
(Description Provided by CVE) : Linksys WRT54g firmware 1.00.9 does not require credentials when making configuration changes, which allows remote attackers to modify arbitrary configurations via a direct request to Security.tri, as demonstrated using the SecurityMode and layout parameters, a different issue than CVE-2006-2559.
|
2006-08-05
|
Cisco Linksys WRT54G Security.tri Unauthenticated Configuration Modification
|
|
27808
Description:
(Description Provided by CVE) : Linksys WRT54g firmware 1.00.9 does not require credentials when making configuration changes, which allows remote attackers to modify arbitrary configurations via a direct request to Security.tri, as demonstrated using the SecurityMode and layout parameters, a different issue than CVE-2006-2559.
|
2006-08-05
|
Cisco Linksys WRT54G Web Admin Console CSRF
|
|
27878
Description:
(Description Provided by CVE) : The libXm library in LessTif 0.95.0 and earlier allows local users to gain privileges via the DEBUG_FILE environment variable, which is used to create world-writable files when libXm is run from a setuid program.
|
2006-08-04
|
LessTif libXm library DEBUG_FILE Variable Symlink Local Privilege Escalation
|
|
27806
Description:
(Description Provided by CVE) : PHP remote file inclusion vulnerability in auto_check_renewals.php in phpAutoMembersArea (phpAMA) 3.2.4 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the installed_config_file parameter.
|
2006-08-04
|
phpAutoMembersArea auto_check_renewals.php installed_config_file Parameter Remote File Inclusion
|
|
29780
Description:
By default, Spam Firewall contains hard-coded admin and guest accounts. The guest account, with a password of 'bnadmin99' may allow an attacker to access the contents of arbitrary files, leading to a loss of confidentiality. With the admin account, an attacker could make arbitrary changes to the system, leading to a loss of integrity.
|
2006-08-04
|
Barracuda Spam Firewall Multiple Account Hardcoded Credentials
|
|
27779
Description:
vBulletin contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the '_tmp[csscolors]' variable upon submission to the /forum/mods/global.php script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2006-08-04
|
vBulletin global.php Encoded URL XSS
|
|
27795
Description:
(Description Provided by CVE) : PHP remote file inclusion vulnerability in Beautifier/Core.php in Brad Fears phpCodeCabinet 0.5 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the BEAUT_PATH parameter.
|
2006-08-04
|
phpCodeCabinet (phpCC) include/Beautifier/Core.php BEAUT_PATH Parameter Remote File Inclusion
|
|
27824
Description:
PHP contains a flaw that may allow a context-dependent attacker to elevate privileges. The issue is due to the sscanf function in scanf.c not properly sanitizing user-supplied input. Passing a crafted string to this function may trigger a buvver over-read allowing the execution of arbitrary code.
|
2006-08-04
|
PHP sscanf() Function Argument Swapping Overflow
|
|
29081
Description:
(Description Provided by CVE) : Buffer overflow in the preview_create function in gui.cpp in Mitch Murray Eremove 1.4 allows remote attackers to cause a denial of service (application crash), and possibly execute arbitrary code, via a large email attachment.
|
2006-08-04
|
Eremove gui.cpp preview_create Function Overflow
|
|
27766
Description:
ME Download System contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to inc/sett_style.php not properly sanitizing user input supplied to the 'Vb8878b936c2bd8ae0cab' variable. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script.
|
2006-08-04
|
ME Download System inc/sett_style.php Vb8878b936c2bd8ae0cab Parameter Remote File Inclusion
|
|
27767
Description:
ME Download System contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to inc/sett_smilies.php not properly sanitizing user input supplied to the 'Vb8878b936c2bd8ae0cab' variable. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script.
|
2006-08-04
|
ME Download System inc/sett_smilies.php Vb8878b936c2bd8ae0cab Parameter Remote File Inclusion
|
|
27768
Description:
ME Download System contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to inc/datei.php not properly sanitizing user input supplied to the 'Vb6c4d0e18a204a63b38f', 'V18a78b93c3adaaae84e2' and 'V9ae5d2ca9e9e787969ff' variables. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script.
|
2006-08-04
|
ME Download System inc/datei.php Multiple Parameter Remote File Inclusion
|
|
29777
Description:
(Description Provided by CVE) : The pswd.js script relies on the client to calculate whether a username and password match hard-coded hashed values for a server, and uses a hashing scheme that creates a large number of collisions, which makes it easier for remote attackers to conduct offline brute force attacks. NOTE: this script might also allow attackers to generate the server-side "secret" URL without determining the original password, but this possibility was not discussed by the original researcher.
|
2006-08-03
|
pswd.js Offline Brute Force Password Weakness
|
|
27760
Description:
CME (CallManager Express) contains unspecified flaw(s) that may lead to an unauthorized information disclosure. The issue is triggered when receiving specially crafted SIP (Session Initiation Protocol) messages, which will disclose usernames from the SIP user directory resulting in a loss of confidentiality.
|
2006-08-03
|
Cisco CallManager Express SIP Message User Enumeration
|
|
41608
Description:
(Description Provided by CVE) : IBM WebSphere Application Server (WAS) 5.0 through 5.1.1.0 allows remote attackers to obtain JSP source code and other sensitive information via certain "special URIs."
|
2006-08-03
|
IBM WebSphere Application Server (WAS) Special URI Unspecified Information Disclosure
|
|
27750
Description:
PC Tools AntiVirus contains a flaw that may allow an attacker to gain access to unauthorized privileges. The "Everyone" group is granted full control of the "PC Tools AntiVirus" directory and all child objects by default, allowing a local attacker to add, delete, or manipulate application files.
|
2006-08-03
|
PC Tools AntiVirus Insecure Directory Permission Privilege Escalation
|
|
27785
Description:
(Description Provided by CVE) : Unspecified vulnerability in CA eTrust Antivirus WebScan before 1.1.0.1048 allows remote attackers to install arbitrary files.
|
2006-08-03
|
CA eTrust Antivirus WebScan ActiveX Control Crafted File Update Subversion
|
|
27786
Description:
(Description Provided by CVE) : Unspecified vulnerability in CA eTrust Antivirus WebScan before 1.1.0.1048 has unknown impact and remote attackers related to "improper processing of outdated WebScan components."
|
2006-08-03
|
CA eTrust Antivirus WebScan ActiveX Control Crafted File Protection Weakness
|
|
27787
Description:
(Description Provided by CVE) : Unspecified vulnerability in CA eTrust Antivirus WebScan allows remote attackers to execute arbitrary code due to "improper bounds checking when processing certain user input."
|
2006-08-03
|
CA eTrust Antivirus WebScan ActiveX Control Update Manifest Processing Overflow
|
|
27749
Description:
(Description Provided by CVE) : preview_email.cgi in Barracuda Spam Firewall (BSF) 3.3.01.001 through 3.3.03.053 allows remote attackers to execute commands via shell metacharacters ("|" pipe symbol) in the file parameter. NOTE: the attack can be extended to arbitrary commands by the presence of CVE-2006-4000.
|
2006-08-03
|
Barracuda Spam Firewall preview_email.cgi file Parameter Arbitrary Command Execution
|
|
27757
Description:
(Description Provided by CVE) : Unspecified vulnerability in Fenestrae Faxination Server allows remote attackers to execute arbitrary code via a crafted packet.
|
2006-08-03
|
Fenestrae Faxination Server Unspecified Remote Code Execution
|
|
27782
Description:
Unknown / Incomplete
|
2006-08-03
|
sendcard admin/prepend.php Administrative Authentication Bypass
|
|
27783
Description:
Unknown / Incomplete
|
2006-08-03
|
sendcard admin/mod_plugins.php plugin_file Variable Traversal Arbitrary File Manipulation
|