| OSVDB ID | Disclosure Date | Title |
|
34086
Description:
(Description Provided by CVE) : SQL injection vulnerability in oku.asp in Hunkaray Duyuru Scripti allows remote attackers to execute arbitrary SQL commands via the id parameter.
|
2007-01-31
|
Hunkaray Duyuru Scripti oku.asp id Variable SQL Injection
|
|
31965
Description:
(Description Provided by CVE) : thttpd before 2.25b-r6 in Gentoo Linux is started from the system root directory (/) by the Gentoo baselayout 1.12.6 package, which allows remote attackers to read arbitrary files.
|
2007-01-31
|
Gentoo thttpd Improper / Web Root
|
|
33604
Description:
(Description Provided by CVE) : PHP remote file inclusion vulnerability in includes/functions.php in Omegaboard 1.0beta4 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.
|
2007-01-31
|
Omegaboard includes/functions.php phpbb_root_path Variable Remote File Inclusion
|
|
33605
Description:
(Description Provided by CVE) : PHP remote file inclusion vulnerability in portal.php in Cerulean Portal System 0.7b allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.
|
2007-01-31
|
Cerulean Portal System portal.php phpbb_root_path Variable Remote File Inclusion
|
|
36027
Description:
(Description Provided by CVE) : SQL injection vulnerability in faq.php in ExoPHPDesk 1.2.1 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.
|
2007-01-31
|
ExoPHPDesk faq.php id Variable SQL Injection
|
|
36037
Description:
(Description Provided by CVE) : SQL injection vulnerability in oku.asp in Hunkaray Duyuru Scripti allows remote attackers to execute arbitrary SQL commands via the id parameter.
|
2007-01-31
|
Hunkaray Duyuru Scripti oku.asp id Variable SQL Injection
|
|
36038
Description:
(Description Provided by CVE) : SQL injection vulnerability in i-search.php in Michelle's L2J Dropcalc 4 and earlier allows remote authenticated users to execute arbitrary SQL commands via the itemid parameter.
|
2007-01-31
|
Michelle's L2J Dropcalc i-search.php itemid Variable SQL Injection
|
|
36039
Description:
(Description Provided by CVE) : PHP remote file inclusion vulnerability in lang/leslangues.php in Nicolas Grandjean PHPMyRing 4.1.3b and earlier allows remote attackers to execute arbitrary PHP code via a URL in the fichier parameter.
|
2007-01-31
|
PHPMyRing lang/leslangues.php fichier Variable Remote File Inclusion
|
|
36041
Description:
(Description Provided by CVE) : SQL injection vulnerability in windows.asp in Fullaspsite Asp Hosting Sitesi allows remote attackers to execute arbitrary SQL commands via the kategori_id parameter.
|
2007-01-31
|
Fullaspsite Asp Hosting Sitesi windows.asp kategori_id Variable
|
|
36476
Description:
(Description Provided by CVE) : Cross-site scripting (XSS) vulnerability in the IFrame module before 03.02.01 for DotNetNuke (DNN) allows remote attackers to inject arbitrary web script or HTML via unspecified vectors related to "Pass through values."
|
2007-01-31
|
DotNetNuke IFrame module Pass Through Value XSS
|
|
36149
Description:
(Description Provided by CVE) : Internet Explorer on Windows Mobile 5.0 and Windows Mobile 2003 and 2003SE for Smartphones and PocketPC allows attackers to cause a denial of service (application crash and device instability) via unspecified vectors, possibly related to a buffer overflow.
|
2007-01-30
|
Microsoft IE on Windows Mobile Unspecified Overflow DoS
|
|
36148
Description:
(Description Provided by CVE) : Pictures and Videos on Windows Mobile 5.0 and Windows Mobile 2003 and 2003SE for Smartphones and PocketPC allows user-assisted remote attackers to cause a denial of service (device hang) via a malformed JPEG file.
|
2007-01-30
|
Microsoft Windows Mobile Pictures and Videos Malformed JPEG DoS
|
|
38129
Description:
(Description Provided by CVE) : Buffer overflow in the open_sty function in mkind.c for makeindex 2.14 in teTeX might allow user-assisted remote attackers to overwrite files and possibly execute arbitrary code via a long filename. NOTE: other overflows exist but might not be exploitable, such as a heap-based overflow in the check_idx function.
|
2007-01-30
|
teTeX makeindex mkind.c open_sty Function Filename Overflow
|
|
37351
Description:
Unknown / Incomplete
|
2007-01-30
|
Dead Souls Mail Code Unspecified Issue
|
|
37353
Description:
Unknown / Incomplete
|
2007-01-30
|
Dead Souls efuns Overide Unspecified Issue
|
|
35848
Description:
(Description Provided by CVE) : Multiple unspecified vulnerabilities in vbDrupal before 4.7.6.0 have unknown impact and remote attack vectors. NOTE: the vector related to Drupal is covered by CVE-2007-0626. These vulnerabilities might be associated with other CVE identifiers.
|
2007-01-30
|
vbDrupal Multiple Unspecified Remote Issues
|
|
34983
Description:
(Description Provided by CVE) : Nortel Networks CallPilot and Meridian Mail voicemail systems, when a mailbox has auto logon enabled, allow remote attackers to retrieve or remove messages, or reconfigure the mailbox, by spoofing Calling Number Identification (CNID, aka Caller ID).
|
2007-01-30
|
Nortel Networks Multiple Voice Mail System Calling Number Identification (CNID) Spoofing Arbitrary Mailbox Manipulation
|
|
34984
Description:
(Description Provided by CVE) : Sprint Nextel Sprint voice mail systems allow remote attackers to retrieve or remove messages, or reconfigure mailboxes, by spoofing Calling Number Identification (CNID, aka Caller ID).
|
2007-01-30
|
Sprint Nextel Sprint Calling Number Identification (CNID) Spoofing Arbitrary Mailbox Manipulation
|
|
34985
Description:
(Description Provided by CVE) : Alcatel-Lucent Lucent Technologies voice mail systems allow remote attackers to retrieve or remove messages, or reconfigure mailboxes, by spoofing Calling Number Identification (CNID, aka Caller ID).
|
2007-01-30
|
Alcatel-Lucent Lucent Technologies Calling Number Identification (CNID) Spoofing Arbitrary Mailbox Manipulation
|
|
34986
Description:
(Description Provided by CVE) : T-Mobile voice mail systems allow remote attackers to retrieve or remove messages, or reconfigure mailboxes, by spoofing Calling Number Identification (CNID, aka Caller ID).
|
2007-01-30
|
T-Mobile Voice Mail Calling Number Identification (CNID) Spoofing Arbitrary Mailbox Manipulation
|
|
32949
Description:
(Description Provided by CVE) : LGSERVER.EXE in BrightStor Mobile Backup 4.0 allows remote attackers to cause a denial of service (disk consumption and daemon hang) via a value of 0xFFFFFF7F at a certain point in an authentication negotiation packet, which writes a large amount of data to a .USX file in CA_BABLDdata\Server\data\transfer\.
|
2007-01-30
|
CA BrightStor Mobile Backup LGSERVER.EXE Malformed Authentication Packet DoS
|
|
32138
Description:
(Description Provided by CVE) : The (1) Textimage 4.7.x before 4.7-1.2 and 5.x before 5.x-1.1 module for Drupal and the (2) Captcha 4.7.x before 4.7-1.2 and 5.x before 5.x-1.1 module for Drupal allow remote attackers to bypass the CAPTCHA test via an empty captcha element in $_SESSION.
|
2007-01-30
|
Drupal Textimage Module Bypass
|
|
33070
Description:
(Description Provided by CVE) : show.php in Vlad Alexa Mancini PHPFootball 1.6 allows remote attackers to obtain sensitive information (database contents) via a % (percent) character in the dbfieldv parameter.
|
2007-01-30
|
PHPFootball show.php dbfieldv Field Database Content Disclosure
|
|
32137
Description:
(Description Provided by CVE) : The (1) Textimage 4.7.x before 4.7-1.2 and 5.x before 5.x-1.1 module for Drupal and the (2) Captcha 4.7.x before 4.7-1.2 and 5.x before 5.x-1.1 module for Drupal allow remote attackers to bypass the CAPTCHA test via an empty captcha element in $_SESSION.
|
2007-01-30
|
Drupal Captcha Module Bypass
|
|
33034
Description:
(Description Provided by CVE) : Multiple PHP remote file inclusion vulnerabilities in EncapsCMS 0.3.6 allow remote attackers to execute arbitrary PHP code via a URL in the (1) config[path] parameter to (a) common_foot.php or (b) blogs.php, or (2) the config[theme] parameter to (c) admin/gallery_head.php.
|
2007-01-30
|
EncapsCMS common_foot.php config[path] Variable Remote File Inclusion
|
|
33035
Description:
(Description Provided by CVE) : Multiple PHP remote file inclusion vulnerabilities in EncapsCMS 0.3.6 allow remote attackers to execute arbitrary PHP code via a URL in the (1) config[path] parameter to (a) common_foot.php or (b) blogs.php, or (2) the config[theme] parameter to (c) admin/gallery_head.php.
|
2007-01-30
|
EncapsCMS blogs.php config[path] Variable Remote File Inclusion
|
|
33036
Description:
(Description Provided by CVE) : Multiple PHP remote file inclusion vulnerabilities in EncapsCMS 0.3.6 allow remote attackers to execute arbitrary PHP code via a URL in the (1) config[path] parameter to (a) common_foot.php or (b) blogs.php, or (2) the config[theme] parameter to (c) admin/gallery_head.php.
|
2007-01-30
|
EncapsCMS admin/gallery_head.php config[theme] Variable Remote File Inclusion
|
|
33033
Description:
(Description Provided by CVE) : Directory traversal vulnerability in zd_numer.php in Galeria Zdjec 3.0 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the galeria parameter, as demonstrated by injecting PHP sequences into an Apache HTTP Server log file, which is then included by zd_numer.php.
|
2007-01-30
|
Galeria zd_numer.php galeria Variable Traversal Local File Inclusion
|
|
33627
Description:
(Description Provided by CVE) : ** DISPUTED ** The Speech Recognition feature of Windows Vista allows user-assisted remote attackers to delete arbitrary files, and conduct other unauthorized activities, via a web page with an embedded sound object that contains voice commands to an enabled microphone, allowing for interaction with Windows Explorer. NOTE: the vendor disputes the severity of this issue, stating that "there is little if any need to worry about the effects of this issue on your new Windows Vista installation." Since little user interaction is required, and the relevant operating environment is common, CVE considers this a vulnerability.
|
2007-01-30
|
Microsoft Vista Speech Recognition Web Page Arbitrary Command Execution
|
|
33019
Description:
(Description Provided by CVE) : PHP remote file inclusion vulnerability in include/themes/themefunc.php in MyNews 4.2.2 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the myNewsConf[path][sys][index] parameter.
|
2007-01-30
|
MyNews include/themes/themefunc.php myNewsConf[path][sys][index] Variable Remote File Inclusion
|
|
32707
Description:
A local format string flaw exists in Mac OS X. The Help Viewer fails to validate the filename for .help files resulting in possible format string execution. With a specially crafted file, an attacker can cause arbitrary code execution resulting in a loss of integrity.
|
2007-01-30
|
Apple Mac OS X Help Viewer .help Filename Format String
|
|
32708
Description:
(Description Provided by CVE) : Format string vulnerability in iMovie HD 6.0.3, and Safari in Apple Mac OS X 10.4 through 10.4.10, allows remote user-assisted attackers to cause a denial of service (crash) via format string specifiers in a filename, which is not properly handled when calling the NSRunCriticalAlertPanel Apple AppKit function.
|
2007-01-30
|
Apple iMovie HD .imovieproj Filename Format String
|
|
32709
Description:
Unknown / Incomplete
|
2007-01-30
|
Apple Safari .download Filename Format String
|
|
32710
Description:
Mac OS X contains a flaw that may allow a malicious user to execute arbitrary code via a format string flaw. The issue is triggered when Safari opens a specially crafted HTML file containing a malformed string passed to window.console.log(). It is possible that the flaw may allow arbitrary code execution resulting in a loss of integrity.
|
2007-01-30
|
Apple Safari window.console.log Format String
|
|
32711
Description:
iPhoto contains a format string flaw that may allow a malicious user to execute arbitrary code. The issue is triggered when a specially crafted photo:// string is passed to iPhoto. It is possible that the flaw may allow arbitrary code execution resulting in a loss of integrity.
|
2007-01-30
|
Apple iPhoto photo:// URL Handling Format String
|
|
31878
Description:
(Description Provided by CVE) : Unspecified vulnerability in Sun Solaris 10 before 20070130 allows remote attackers to cause a denial of service (system crash) via certain ICMP packets.
|
2007-01-30
|
Solaris Unspecified ICMP Packet Handling DoS
|
|
33630
Description:
(Description Provided by CVE) : ** DISPUTED ** Multiple PHP remote file inclusion vulnerabilities in Atsphp 5.0.1 allow remote attackers to execute arbitrary PHP code via a URL in the CONF[path] parameter to (1) index.php, (2) sources/usercp.php, or (3) sources/admin.php. NOTE: Another researcher has disputed this vulnerability, noting that CONF[path] is defined before use in index.php, that CONF[path] inclusion cannot occur through a direct request to other affected files, and that usercp.php is a typo of user_cp.php.
|
2007-01-30
|
Atsphp Multiple Script CONF[path] Variable Remote File Inclusion
|
|
32198
Description:
Siebel CRM Server contains a flaw that may lead to an unauthorized information disclosure. The issue is triggered when a user navigates to the server statistics page (http://www.example.com/[app_name]/_stats.swe. This discloses information about the additional applications installed on the server, the server version, installation location and, if the SessionMonitor parameter is enabled, the session information of the clients connected.
|
2007-01-30
|
Siebel _stats.swe Remote Information Disclosure
|
|
36018
Description:
(Description Provided by CVE) : PHP remote file inclusion vulnerability in includes/functions.php in phpBB2-MODificat 0.2.0 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.
|
2007-01-30
|
phpBB2-MODificat includes/functions.php phpbb_root_path Variable Remote File Inclusion
|
|
38131
Description:
(Description Provided by CVE) : Stack-based buffer overflow in Bloodshed Dev-C++ 4.9.9.2 allows user-assisted remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a long line in a .cpp file.
|
2007-01-30
|
Bloodshed Dev-C++ .cpp Handling Line Overflow
|