| OSVDB ID | Disclosure Date | Title |
|
37432
Description:
(Description Provided by CVE) : PHP remote file inclusion vulnerability in games.php in Sam Crew MyBlog, possibly 1.0 through 1.6, allows remote attackers to execute arbitrary PHP code via a URL in the id parameter, a different vector than CVE-2007-1968. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
|
2007-04-09
|
MyBlog games.php id Parameter Remote File Inclusion
|
|
35579
Description:
Unknown / Incomplete
|
2007-04-08
|
Smb4k smb4k_mount Privileged Share Mount
|
|
35580
Description:
Unknown / Incomplete
|
2007-04-08
|
Smb4k Multiple Utility findprog() Function Function Freed Memory Pointer Issue
|
|
35581
Description:
Unknown / Incomplete
|
2007-04-08
|
Smb4k Share Mounting replace_special_characters() Function Freed Memory Pointer Issue
|
|
35564
Description:
Unknown / Incomplete
|
2007-04-08
|
Ethereal Realms Source Trust Unspecified Issue
|
|
35565
Description:
Unknown / Incomplete
|
2007-04-08
|
Ethereal Realms LWPx::ParanoidAgent Unspecified Issue
|
|
35566
Description:
Unknown / Incomplete
|
2007-04-08
|
Ethereal Realms OpenID Encryption Options Unspecified Issue
|
|
35567
Description:
Unknown / Incomplete
|
2007-04-08
|
Ethereal Realms Fortune Display Unspecified Issue
|
|
35291
Description:
(Description Provided by CVE) : ** DISPUTED ** Unspecified vulnerability in administration.php in xodagallery allows remote attackers to execute arbitrary code via the cmd parameter. NOTE: CVE disputes this vulnerability because administration.php does not use the cmd parameter for inclusion.
|
2007-04-08
|
xodagallery administration.php cmd Parameter Remote File Inclusion
|
|
35290
Description:
(Description Provided by CVE) : Multiple PHP remote file inclusion vulnerabilities in Guernion Sylvain Portail Web Php (aka Gsylvain35 Portail Web, PwP) allow remote attackers to execute arbitrary PHP code via a URL in the pageAll parameter to index.php in (1) template/Vert/, or (2) template/Noir/.
|
2007-04-08
|
Gsylvain35 Portail Web Php (PWP) index.php pageAll Parameter Remote File Inclusion
|
|
35289
Description:
(Description Provided by CVE) : Multiple PHP remote file inclusion vulnerabilities in Pineapple Technologies Lore 1 allow remote attackers to execute arbitrary PHP code via a URL in the (1) lang_path parameter to third_party/phpmailer/class.phpmailer.php or the (2) get_plugin_file_path parameter to third_party/smarty/libs/plugins/function.html_checkboxes.php. NOTE: the affected files might be from other software packages, so this might not be a vulnerability in Lore itself. NOTE: (1) might be the same issue as CVE-2006-5734.4.
|
2007-04-08
|
Lore class.phpmailer.php lang_path Parameter Remote File Inclusion
|
|
35049
Description:
(Description Provided by CVE) : Cross-site scripting (XSS) vulnerability in mysql/phpinfo.php in phpMyAdmin 2.6.1 allows remote attackers to inject arbitrary web script or HTML via the lang[] parameter.
|
2007-04-08
|
phpMyAdmin phpinfo.php lang[] Parameter XSS
|
|
35288
Description:
(Description Provided by CVE) : SQL injection vulnerability in ubbthreads.php in Groupee UBB.threads 6.1.1 and earlier allows remote attackers to execute arbitrary SQL commands via the C parameter.
|
2007-04-08
|
UBB.threads ubbthreads.php C Parameter SQL Injection
|
|
35287
Description:
(Description Provided by CVE) : Cross-site scripting (XSS) vulnerability in the embedded webserver in Daniel Naber LanguageTool before 0.8.9 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors involving an error message, possibly the demultiplex method in HTTPServer.java.
|
2007-04-08
|
LanguageTool Unspecified XSS
|
|
34777
Description:
(Description Provided by CVE) : Cross-site scripting (XSS) vulnerability in auth.php in Pineapple Technologies QuizShock 1.6.1 and earlier allows remote attackers to inject arbitrary web script or HTML via encoded special characters in the forward_to parameter, as demonstrated using "<"<".
|
2007-04-08
|
QuizShock auth.php forward_to Parameter XSS
|
|
34746
Description:
(Description Provided by CVE) : Directory traversal vulnerability in scarnews.inc.php in ScarNews 1.2.1 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the sn_admin_dir parameter.
|
2007-04-08
|
ScarNews scarnews.inc.php sn_admin_dir Parameter Local File Inclusion
|
|
34754
Description:
(Description Provided by CVE) : PHP remote file inclusion vulnerability in smilies.php in Scorp Book 1.0 allows remote attackers to execute arbitrary PHP code via a URL in the config parameter.
|
2007-04-08
|
Scorp Book smilies.php config Parameter Remote File Inclusion
|
|
34960
Description:
(Description Provided by CVE) : Unrestricted file upload vulnerability in the UpLoad feature (lib/plugin/UpLoad.php) in PhpWiki 1.3.x allows remote attackers to upload arbitrary PHP files with a (1) php3, (2) php4, or (3) php5 extension.
|
2007-04-08
|
PhpWiki UpLoad.php Unrestricted File Upload
|
|
34721
Description:
(Description Provided by CVE) : Cross-site scripting (XSS) vulnerability in login.php in DeskPro 2.0.1 allows remote attackers to inject arbitrary web script or HTML via the username parameter.
|
2007-04-08
|
DeskPRO login.php username Parameter XSS
|
|
34806
Description:
(Description Provided by CVE) : Directory traversal vulnerability in member.php in the eBoard 1.0.7 module for PHP-Nuke allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the GLOBALS[name] parameter.
|
2007-04-08
|
eBoard member.php GLOBALS[name] Parameter Traversal Local File Inclusion
|
|
38459
Description:
(Description Provided by CVE) : Multiple directory traversal vulnerabilities in PcP-Guestbook (PcP-Book) 3.0 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the lang parameter to (1) index.php, (2) gb.php, or (3) faq.php.
|
2007-04-08
|
PcP-Guestbook index.php lang Parameter Traversal Local File Inclusion
|
|
38460
Description:
(Description Provided by CVE) : Multiple directory traversal vulnerabilities in PcP-Guestbook (PcP-Book) 3.0 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the lang parameter to (1) index.php, (2) gb.php, or (3) faq.php.
|
2007-04-08
|
PcP-Guestbook gb.php lang Parameter Traversal Local File Inclusion
|
|
38461
Description:
(Description Provided by CVE) : Multiple directory traversal vulnerabilities in PcP-Guestbook (PcP-Book) 3.0 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the lang parameter to (1) index.php, (2) gb.php, or (3) faq.php.
|
2007-04-08
|
PcP-Guestbook faq.php lang Parameter Traversal Local File Inclusion
|
|
58751
Description:
Unknown / Incomplete
|
2007-04-08
|
Apache Geronimo GeronimoIdentityResolver Subject Handling Multiple Issues
|
|
56060
Description:
(Description Provided by CVE) : FCKeditor.Java 2.4 allows remote attackers to cause a denial of service (infinite loop) via a malformed request parameter that contains "ctrl" characters.
|
2007-04-07
|
FCKeditor.Java ctrl Character Handling Infinite Loop DoS
|
|
35285
Description:
(Description Provided by CVE) : Cross-site scripting (XSS) vulnerability in index_cms.php in WebBlizzard CMS allows remote attackers to inject arbitrary web script or HTML via the Suchzeile parameter.
|
2007-04-07
|
WebBlizzard CMS index_cms.php Suchzeile XSS
|
|
35286
Description:
(Description Provided by CVE) : Session fixation vulnerability in WebBlizzard CMS allows remote attackers to hijack web sessions by setting a PHPSESSID cookie.
|
2007-04-07
|
WebBlizzard CMS PHPSESSID Cookie Session Fixation
|
|
35284
Description:
(Description Provided by CVE) : Unspecified vulnerability in phpTodo before 0.8.1 allows remote attackers to have an unknown impact via newlines in regular expressions to (1) index.php, (2) feed.php, (3) prefs.php, and (4) todolist.php; and (5) classTodoItem.php and (6) phpTodoUser.php in libs/. NOTE: some of these details are obtained from third party information.
|
2007-04-07
|
phpTodo Unspecified Regular Expression Newline Injection
|
|
34120
Description:
(Description Provided by CVE) : Cross-site scripting (XSS) vulnerability in mail/signup.asp in CmailServer WebMail 5.4.3, and possibly earlier, allows remote attackers to inject arbitrary web script or HTML via the Comment parameter, a different vector than CVE-2007-1927.
|
2007-04-07
|
CMailServer mail/signup.asp Comment Parameter XSS
|
|
33962
Description:
PHP's ext/filter extension contains a flaw that may allow a malicious user to inject specially crafted mail headers. The issue is triggered due to the FILTER_VALIDATE_EMAIL function using an incorrect regular expression which can be trivially bypassed. By using a newline character, an attacker could potentially use this to send unsolicited e-mail from the host.
|
2007-04-07
|
PHP ext/filter FILTER_VALIDATE_EMAIL Newline Injection
|
|
79036
Description:
Unknown / Incomplete
|
2007-04-07
|
Links Multiple Document / Image Handling Overflows
|
|
35280
Description:
(Description Provided by CVE) : Cross-site scripting (XSS) vulnerability in index.php in Arizona Dream Livre d'or (livor) 2.5 allows remote attackers to inject arbitrary web script or HTML via the page parameter.
|
2007-04-06
|
Livre d'or (livor) index.php page Parameter XSS
|
|
35277
Description:
(Description Provided by CVE) : Session fixation vulnerability in onelook courts on-line allows remote attackers to hijack web sessions by setting a PHPSESSID cookie.
|
2007-04-06
|
courts on-line PHPSESSID Cookie Session Fixation
|
|
35278
Description:
(Description Provided by CVE) : Session fixation vulnerability in onelook obo Shop allows remote attackers to hijack web sessions by setting a PHPSESSID cookie.
|
2007-04-06
|
oboShop PHPSESSID Cookie Session Fixation
|
|
35279
Description:
(Description Provided by CVE) : Session fixation vulnerability in onelook onebyone CMS allows remote attackers to hijack web sessions by setting a PHPSESSID cookie.
|
2007-04-06
|
onebyone CMS PHPSESSID Cookie Session Fixation
|
|
35276
Description:
phpContact contains a flaw that may allow a remote attacker to execute arbitrary commands or code. The issue is due to the 'contact_business.php ' and the 'contact_person.php' scripts not properly sanitizing user input supplied to the 'include_path' parameter. This may allow an attacker to include a file from a third-party remote host that contains commands or code that will be executed by the vulnerable script with the same privileges as the web server.
|
2007-04-06
|
phpContact Multiple Script include_path Parameter Remote File Inclusion
|
|
34430
Description:
(Description Provided by CVE) : The Impulse Tracker (IT) and ScreamTracker 3 (S3M) modules in IN_MOD.DLL in AOL Nullsoft Winamp 5.33 allows remote attackers to execute arbitrary code via a crafted (1) .IT or (2) .S3M file containing integer values that are used as memory offsets, which triggers memory corruption.
|
2007-04-06
|
Winamp IN_MOD.DLL Impulse Tracker (IT) File Handling Memory Corruption
|
|
34431
Description:
(Description Provided by CVE) : The Impulse Tracker (IT) and ScreamTracker 3 (S3M) modules in IN_MOD.DLL in AOL Nullsoft Winamp 5.33 allows remote attackers to execute arbitrary code via a crafted (1) .IT or (2) .S3M file containing integer values that are used as memory offsets, which triggers memory corruption.
|
2007-04-06
|
Winamp IN_MOD.DLL ScreamTracker 3 (S3M) File Handling Memory Corruption
|
|
35479
Description:
(Description Provided by CVE) : Cross-site scripting (XSS) vulnerability in LAN Management System (LMS) before 1.6.9 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, probably involving the OD parameter to contrib/formularz_przelewu_wplaty/druk.php.
|
2007-04-06
|
LAN Management System (LMS) druk.php OD Parameter XSS
|
|
34432
Description:
(Description Provided by CVE) : LIBSNDFILE.DLL, as used by AOL Nullsoft Winamp 5.33 and possibly other products, allows remote attackers to execute arbitrary code via a crafted .MAT (MATLAB sound) file that contains a value that is used as an offset, which triggers memory corruption.
|
2007-04-06
|
Winamp LIBSNDFILE.DLL .MAT File Handling NULL Byte Overwrite
|