| OSVDB ID | Disclosure Date | Title |
|
35356
Description:
(Description Provided by CVE) : Multiple PHP remote file inclusion vulnerabilities in Robert Ladstaetter ActionPoll 1.1.0, and possibly 1.1.1, allow remote attackers to execute arbitrary PHP code via a URL in (1) the CONFIG_POLLDB parameter to actionpoll.php or (2) the CONFIG_DB parameter to db/DataReaderWriter.php, different vectors than CVE-2001-1297.
|
2007-04-15
|
ActionPoll actionpoll.php CONFIG_POLLDB Parameter Remote File Inclusion
|
|
35357
Description:
(Description Provided by CVE) : Multiple PHP remote file inclusion vulnerabilities in Robert Ladstaetter ActionPoll 1.1.0, and possibly 1.1.1, allow remote attackers to execute arbitrary PHP code via a URL in (1) the CONFIG_POLLDB parameter to actionpoll.php or (2) the CONFIG_DB parameter to db/DataReaderWriter.php, different vectors than CVE-2001-1297.
|
2007-04-15
|
ActionPoll db/DataReaderWriter.php CONFIG_DB Parameter Remote File Inclusion
|
|
34151
Description:
Jambook for Joomla/Mambo has been reported to contain a flaw that may allow a remote attacker to execute arbitrary commands. The issue was supposedly due to jambook.php not properly sanitizing user input supplied to the 'mosConfig_absolute_path' variable. However, third party research indicates that file inclusions are not possible because jambook.php is restricted from being called directly.
|
2007-04-15
|
Jambook for Joomla/Mambo jambook.php mosConfig_absolute_path Parameter Remote File Inclusion
|
|
35239
Description:
(Description Provided by CVE) : vsdatant.sys in Check Point Zone Labs ZoneAlarm Pro before 7.0.302.000 does not validate certain arguments before being passed to hooked SSDT function handlers, which allows local users to cause a denial of service (system crash) or possibly execute arbitrary code via crafted arguments to the (1) NtCreateKey and (2) NtDeleteFile functions.
|
2007-04-15
|
ZoneAlarm vsdatant.sys Hooked SSDT Function Local Privilege Escalation
|
|
35392
Description:
(Description Provided by CVE) : Direct static code injection vulnerability in admin/settings.php in MyBlog 0.9.8 and earlier allows remote authenticated admin users to inject arbitrary PHP code via the content parameter, which can be executed by accessing index.php. NOTE: a separate vulnerability could be leveraged to make this issue exploitable by remote unauthenticated attackers.
|
2007-04-15
|
MyBlogd admin/settings.php content Variable Arbitrary PHP Code Execution
|
|
35388
Description:
Gallery contains a flaw that may allow a remote attacker to execute arbitrary commands or code. The issue is due to the 'errors/needinit.php' script not properly sanitizing user input supplied to the 'GALLERY_BASEDIR' parameter. This may allow an attacker to include a file from a third-party remote host that contains commands or code that will be executed by the vulnerable script with the same privileges as the web server.
|
2007-04-15
|
Gallery errors/needinit.php GALLERY_BASEDIR Parameter Remote File Inclusion
|
|
35389
Description:
Gallery contains a flaw that may allow a remote attacker to execute arbitrary commands or code. The issue is due to the 'errors/reconfigure.php' script not properly sanitizing user input supplied to the 'GALLERY_BASEDIR' parameter. This may allow an attacker to include a file from a third-party remote host that contains commands or code that will be executed by the vulnerable script with the same privileges as the web server.
|
2007-04-15
|
Gallery errors/reconfigure.php GALLERY_BASEDIR Parameter Remote File Inclusion
|
|
35390
Description:
Gallery contains a flaw that may allow a remote attacker to execute arbitrary commands or code. The issue is due to the 'errors/unconfigured.php' script not properly sanitizing user input supplied to the 'GALLERY_BASEDIR' parameter. This may allow an attacker to include a file from a third-party remote host that contains commands or code that will be executed by the vulnerable script with the same privileges as the web server.
|
2007-04-15
|
Gallery errors/unconfigured.php GALLERY_BASEDIR Parameter Remote File Inclusion
|
|
35391
Description:
Gallery contains a flaw that may allow a remote attacker to execute arbitrary commands or code. The issue is due to the 'errors/configmode.php' script not properly sanitizing user input supplied to the 'GALLERY_BASEDIR' parameter. This may allow an attacker to include a file from a third-party remote host that contains commands or code that will be executed by the vulnerable script with the same privileges as the web server.
|
2007-04-15
|
Gallery errors/configmode.php GALLERY_BASEDIR Parameter Remote File Inclusion
|
|
39293
Description:
Unknown / Incomplete
|
2007-04-15
|
ELinks Malformed BitTorrent URL DoS
|
|
39292
Description:
Unknown / Incomplete
|
2007-04-15
|
ELinks Malformed FTP Server Response Memory Corruption
|
|
35477
Description:
(Description Provided by CVE) : SQL injection vulnerability in kontakt.php in Papoo 3.02 and earlier allows remote attackers to execute arbitrary SQL commands via the menuid parameter, a different vector than CVE-2005-4478.
|
2007-04-15
|
Papoo CMS kontakt.php menuid Parameter SQL Injection
|
|
34977
Description:
Pixaria Gallery contains a flaw that may allow a remote attacker to execute arbitrary commands or code. The issue is due to the psg.smarty.lib.php' script not properly sanitizing user input supplied to the 'cfg[sys][base_path]' parameter. This may allow an attacker to include a file from a third-party remote host that contains commands or code that will be executed by the vulnerable script with the same privileges as the web server.
|
2007-04-15
|
Pixaria Gallery psg.smarty.lib.php cfg[sys][base_path] Parameter Remote File Inclusion
|
|
34978
Description:
Pixaria Gallery contains a flaw that may allow a remote attacker to execute arbitrary commands or code. The issue is due to unspecified scripts in the 'library/include' directory not properly sanitizing user input supplied to unspecified parameter(s). This may allow an attacker to include a file from a third-party remote host that contains commands or code that will be executed by the vulnerable script with the same privileges as the web server.
|
2007-04-15
|
Pixaria Gallery library/include Multiple Unspecified Remote File Inclusion
|
|
34979
Description:
CNStats contains a flaw that may allow a remote attacker to execute arbitrary commands or code. The issue is due to the who_r.php script not properly sanitizing user input supplied to the 'bj' parameter. This may allow an attacker to include a file from a third-party remote host that contains commands or code that will be executed by the vulnerable script with the same privileges as the web server.
|
2007-04-15
|
CNStats who_r.php bj Parameter Remote File Inclusion
|
|
34980
Description:
CNStats contains a flaw that may allow a remote attacker to execute arbitrary commands or code. The issue is due to the 'who_s.php' script not properly sanitizing user input supplied to the 'bj' parameter. This may allow an attacker to include a file from a third-party remote host that contains commands or code that will be executed by the vulnerable script with the same privileges as the web server.
|
2007-04-15
|
CNStats who_s.php bj Parameter Remote File Inclusion
|
|
34997
Description:
(Description Provided by CVE) : Directory traversal vulnerability in includes/footer.php in News Manager Deluxe (NMDeluxe) 1.0.1 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the template parameter.
|
2007-04-15
|
NMDeluxe includes/footer.php template Variable Traveral Local File Inclusion
|
|
34972
Description:
(Description Provided by CVE) : Cross-site scripting (XSS) vulnerability in oe2edit.cgi in oe2edit CMS allows remote attackers to inject arbitrary web script or HTML via the q parameter.
|
2007-04-15
|
oe2edit oe2edit.cgi q Parameter XSS
|
|
35834
Description:
(Description Provided by CVE) : SQL injection vulnerability in kontakt.php in Papoo 3.02 and earlier allows remote attackers to execute arbitrary SQL commands via the menuid parameter, a different vector than CVE-2005-4478.
|
2007-04-15
|
Papoo kontakt.php menuid SQL Injection
|
|
37436
Description:
(Description Provided by CVE) : Multiple PHP remote file inclusion vulnerabilities in Marco Antonio Islas Cruz Web Slider (WebSlider) 0.6 allow remote attackers to execute arbitrary PHP code via a URL in the path parameter to (1) index.php, (2) modules/pdf.php, (3) plugins/highlight.php, or (4) include/modules.php.
|
2007-04-15
|
WebSlider index.php path Parameter Remote File Inclusion
|
|
37437
Description:
(Description Provided by CVE) : Multiple PHP remote file inclusion vulnerabilities in Marco Antonio Islas Cruz Web Slider (WebSlider) 0.6 allow remote attackers to execute arbitrary PHP code via a URL in the path parameter to (1) index.php, (2) modules/pdf.php, (3) plugins/highlight.php, or (4) include/modules.php.
|
2007-04-15
|
WebSlider modules/pdf.php path Parameter Remote File Inclusion
|
|
37438
Description:
(Description Provided by CVE) : Multiple PHP remote file inclusion vulnerabilities in Marco Antonio Islas Cruz Web Slider (WebSlider) 0.6 allow remote attackers to execute arbitrary PHP code via a URL in the path parameter to (1) index.php, (2) modules/pdf.php, (3) plugins/highlight.php, or (4) include/modules.php.
|
2007-04-15
|
WebSlider plugins/highlight.php path Parameter Remote File Inclusion
|
|
37439
Description:
WebSlider contains a flaw that may allow a remote attacker to execute arbitrary commands or code. The issue is due to the 'include/modules.php' script not properly sanitizing user input supplied to the 'path' parameter. This may allow an attacker to include a file from a third-party remote host that contains commands or code that will be executed by the vulnerable script with the same privileges as the web server.
|
2007-04-15
|
WebSlider include/modules.php path Parameter Remote File Inclusion
|
|
37440
Description:
(Description Provided by CVE) : Multiple SQL injection vulnerabilities in XAMPP 1.6.0a for Windows allow remote attackers to execute arbitrary SQL commands via unspecified vectors in certain test scripts.
|
2007-04-15
|
XAMPP Test Script Unspecified SQL Injection
|
|
37565
Description:
(Description Provided by CVE) : Multiple PHP remote file inclusion vulnerabilities in AjPortal2Php allow remote attackers to execute arbitrary PHP code via a URL in the PagePrefix parameter to (1) begin.inc.php, (2) connection.inc.php, (3) events.inc.php, (4) footer.inc.php, (5) header.inc.php, (6) menuleft.inc.php, or (7) pages.inc.php in includes/.
|
2007-04-15
|
AjPortal2Php includes/begin.inc.php PagePrefix Parameter Remote File Inclusion
|
|
37566
Description:
(Description Provided by CVE) : Multiple PHP remote file inclusion vulnerabilities in AjPortal2Php allow remote attackers to execute arbitrary PHP code via a URL in the PagePrefix parameter to (1) begin.inc.php, (2) connection.inc.php, (3) events.inc.php, (4) footer.inc.php, (5) header.inc.php, (6) menuleft.inc.php, or (7) pages.inc.php in includes/.
|
2007-04-15
|
AjPortal2Php includes/connection.inc.php PagePrefix Parameter Remote File Inclusion
|
|
37567
Description:
(Description Provided by CVE) : Multiple PHP remote file inclusion vulnerabilities in AjPortal2Php allow remote attackers to execute arbitrary PHP code via a URL in the PagePrefix parameter to (1) begin.inc.php, (2) connection.inc.php, (3) events.inc.php, (4) footer.inc.php, (5) header.inc.php, (6) menuleft.inc.php, or (7) pages.inc.php in includes/.
|
2007-04-15
|
AjPortal2Php includes/events.inc.php PagePrefix Parameter Remote File Inclusion
|
|
37568
Description:
(Description Provided by CVE) : Multiple PHP remote file inclusion vulnerabilities in AjPortal2Php allow remote attackers to execute arbitrary PHP code via a URL in the PagePrefix parameter to (1) begin.inc.php, (2) connection.inc.php, (3) events.inc.php, (4) footer.inc.php, (5) header.inc.php, (6) menuleft.inc.php, or (7) pages.inc.php in includes/.
|
2007-04-15
|
AjPortal2Php includes/footer.inc.php PagePrefix Parameter Remote File Inclusion
|
|
37569
Description:
(Description Provided by CVE) : Multiple PHP remote file inclusion vulnerabilities in AjPortal2Php allow remote attackers to execute arbitrary PHP code via a URL in the PagePrefix parameter to (1) begin.inc.php, (2) connection.inc.php, (3) events.inc.php, (4) footer.inc.php, (5) header.inc.php, (6) menuleft.inc.php, or (7) pages.inc.php in includes/.
|
2007-04-15
|
AjPortal2Php includes/header.inc.php PagePrefix Parameter Remote File Inclusion
|
|
37570
Description:
(Description Provided by CVE) : Multiple PHP remote file inclusion vulnerabilities in AjPortal2Php allow remote attackers to execute arbitrary PHP code via a URL in the PagePrefix parameter to (1) begin.inc.php, (2) connection.inc.php, (3) events.inc.php, (4) footer.inc.php, (5) header.inc.php, (6) menuleft.inc.php, or (7) pages.inc.php in includes/.
|
2007-04-15
|
AjPortal2Php includes/menuleft.inc.php PagePrefix Parameter Remote File Inclusion
|
|
37571
Description:
(Description Provided by CVE) : Multiple PHP remote file inclusion vulnerabilities in AjPortal2Php allow remote attackers to execute arbitrary PHP code via a URL in the PagePrefix parameter to (1) begin.inc.php, (2) connection.inc.php, (3) events.inc.php, (4) footer.inc.php, (5) header.inc.php, (6) menuleft.inc.php, or (7) pages.inc.php in includes/.
|
2007-04-15
|
AjPortal2Php includes/pages.inc.php PagePrefix Parameter Remote File Inclusion
|
|
35393
Description:
Sitebar contains a flaw that may allow a remote attacker to execute arbitrary commands or code. The issue is due to the 'index.php' script not properly sanitizing user input supplied to the 'writerFile' parameter. This may allow an attacker to include a file from a third-party remote host that contains commands or code that will be executed by the vulnerable script with the same privileges as the web server.
|
2007-04-14
|
Sitebar index.php writerFile Parameter Remote File Inclusion
|
|
35394
Description:
Sitebar contains a flaw that may allow a remote attacker to execute arbitrary commands or code. The issue is due to the 'Integrator.php' script not properly sanitizing user input supplied to the 'file' parameter. This may allow an attacker to include a file from a third-party remote host that contains commands or code that will be executed by the vulnerable script with the same privileges as the web server.
|
2007-04-14
|
Sitebar Integrator.php file Parameter Remote File Inclusion
|
|
35359
Description:
(Description Provided by CVE) : ** DISPUTED ** PHP remote file inclusion vulnerability in phpMyChat.php3 in phpMyChat 0.14.5 allows remote attackers to execute arbitrary PHP code via a URL in the {ChatPath} parameter. NOTE: this has been disputed by multiple third parties and CVE because $ChatPath is set to a constant value.
|
2007-04-14
|
phpMyChat phpMyChat.php3 ChatPath Parameter Remote File Inclusion
|
|
35360
Description:
(Description Provided by CVE) : ** DISPUTED ** PHP remote file inclusion vulnerability in index.php in Maian Weblog 3.1 allows remote attackers to execute arbitrary PHP code via a URL in the path_to_folder parameter. NOTE: this issue was disputed by a third party researcher, since the path_to_folder variable is initialized before use.
|
2007-04-14
|
Maian Weblog index.php path_to_folder Parameter Remote File Inclusion
|
|
34147
Description:
Flip-search-add-on contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to everything.php not properly sanitizing user input supplied to the 'incpath' variable. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script.
|
2007-04-14
|
Flip-search-add-on everything.php incpath Parameter Remote File Inclusion
|
|
34148
Description:
OpenConcept Back-End CMS has been reported to contain a flaw that may allow a remote attacker to execute arbitrary commands. The issue is supposedly due to the 'cilck.php', 'pollcollector.php', 'site-admin/index.php', 'site-admin/articlepages.php', 'site-admin/articles.php', 'site-admin/articleform.php', 'site-admin/articlesections.php', 'site-admin/createArticlesPage.php', 'site-admin/guestbook.php', 'site-admin/helpguide.php', 'site-admin/helpguideeditor.php', 'site-admin/links.php', 'site-admin/upload.php', 'site-admin/sitestatistics.php', 'site-admin/nav.php', 'site-admin/tpl_upload.php', 'site-admin/linksections', and 'site-admin/pophelp.php' scripts not properly sanitizing user input supplied to the 'includes_path' variable. Additional third-party examination indicates this is not an issue, because the variable is always overridden by an internally configured value.
|
2007-04-14
|
Back-End CMS Multiple Script includes_path Parameter Remote File Inclusion
|
|
35358
Description:
(Description Provided by CVE) : PHP remote file inclusion vulnerability in chat.php in MySpeach 1.9 allows remote attackers to execute arbitrary PHP code via a URL in the my[root] parameter, a different vector than CVE-2007-0498.
|
2007-04-14
|
MySpeach chat.php my[root] Parameter Remote File Inclusion
|
|
34152
Description:
b2evolution has been reported to contain a flaw that may allow a remote attacker to execute arbitrary commands. The issue was supposedly due to 'blogs/index.php' not properly sanitizing user input supplied to the 'core_subdir' variable. However, third-party research indicates that file inclusions are not possible because the software uses a hard-coded value from a configuration script for this variable, which is therefore restricted from being called directly.
|
2007-04-14
|
b2evolution blogs/index.php core_subdir Parameter Remote File Inclusion
|
|
34149
Description:
Maian Gallery contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to index.php not properly sanitizing user input supplied to the 'path_to_folder' variable. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script.
|
2007-04-14
|
Maian Gallery index.php path_to_folder Parameter Remote File Inclusion
|