| OSVDB ID | Disclosure Date | Title |
|
37484
Description:
(Description Provided by CVE) : Multiple stack-based buffer overflows in Ingres database server 2006 9.0.4, r3, 2.6, and 2.5, as used in multiple CA (Computer Associates) products, allow remote attackers to execute arbitrary code via the (1) uuid_from_char or (2) duve_get_args functions.
|
2007-06-25
|
Ingres Database verifydb Utility duveutil.c duve_get_args Function Local Overflow
|
|
37485
Description:
(Description Provided by CVE) : wakeup in Ingres database server 2006 9.0.4, r3, 2.6, and 2.5, as used in multiple CA (Computer Associates) products, allows local users to truncate arbitrary files via a symlink attack on the alarmwkp.def file.
|
2007-06-25
|
Ingres Database wakeup Utility Symlink Arbitrary File Truncation
|
|
37486
Description:
(Description Provided by CVE) : Multiple "pointer overwrite" vulnerabilities in Ingres database server 2006 9.0.4, r3, 2.6, and 2.5, as used in multiple CA (formerly Computer Associates) products, allow remote attackers to execute arbitrary code by sending certain TCP data at different times to the Ingres Communications Server Process (iigcc), which calls the (1) QUinsert or (2) QUremove functions with attacker-controlled input.
|
2007-06-25
|
Ingres 2006 Ingres Communications Server Process (iigcc) Multiple Function Arbitrary Code Execution
|
|
37674
Description:
(Description Provided by CVE) : The NCTAudioEditor2 ActiveX control in NCTWMAFile2.dll 2.6.2.157, as distributed in NCTAudioEditor and NCTAudioStudio 2.7, allows remote attackers to overwrite arbitrary files via the CreateFile method.
|
2007-06-25
|
NCTsoft Multiple Products NCTAudioEditor2 ActiveX (NCTWMAFile2.dll) CreateFile Method Arbitrary File Overwrite
|
|
45385
Description:
(Description Provided by CVE) : Unrestricted file upload vulnerability in upload.php in dreamLog (aka dreamblog) 0.5 allows remote attackers to upload and execute arbitrary PHP code in uploads/images/ via the uploadedFile[] parameter.
|
2007-06-25
|
dreamLog (dreamblog) upload.php Unrestricted File Upload Arbitrary PHP Code Execution
|
|
89717
Description:
Libxml2 contains a flaw in xmlschemas.c that may allow a denial of service. The issue is triggered when handling a malformed xsd:schema root element. With a specially crafted element, a context-dependent attacker can cause the program to crash.
|
2007-06-25
|
Libxml2 on Solaris xmlschemas.c Malformed xsd:schema Root Element Handling DoS
|
|
44708
Description:
Unknown / Incomplete
|
2007-06-25
|
IBM DB2 Universal Database sqlno_fix_depend_qun Unspecified Query DoS
|
|
40163
Description:
Unknown / Incomplete
|
2007-06-25
|
SILC Client / Toolkit Multiple Unspecified Issues
|
|
34274
Description:
(Description Provided by CVE) : SQL injection vulnerability in admin.php in MyNews 0.10, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the authacc cookie.
|
2007-06-25
|
MyNews admin.php authacc Cookie SQL Injection
|
|
35373
Description:
(Description Provided by CVE) : Multiple SQL injection vulnerabilities in Calendarix 0.7.20070307, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) month and (2) year parameters to calendar.php and the (3) search string to cal_search.php.
|
2007-06-25
|
Calendarix calendar.php Multiple Parameter SQL Injection
|
|
35694
Description:
(Description Provided by CVE) : Multiple SQL injection vulnerabilities in Calendarix 0.7.20070307, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) month and (2) year parameters to calendar.php and the (3) search string to cal_search.php.
|
2007-06-25
|
Calendarix cal_search.php Search String SQL Injection
|
|
35695
Description:
(Description Provided by CVE) : Multiple cross-site scripting (XSS) vulnerabilities in Calendarix 0.7.20070307, when register_globals is enabled, allow remote attackers to inject arbitrary web script or HTML via the (1) year and (2) month parameters to calendar.php, and the (3) leftfooter parameter to cal_footer.inc.php. NOTE: the ycyear parameter to yearcal.php is already covered by CVE-2006-1835.
|
2007-06-25
|
Calendarix cal_footer.inc.php leftfooter Parameter XSS
|
|
35696
Description:
(Description Provided by CVE) : Multiple cross-site scripting (XSS) vulnerabilities in Calendarix 0.7.20070307, when register_globals is enabled, allow remote attackers to inject arbitrary web script or HTML via the (1) year and (2) month parameters to calendar.php, and the (3) leftfooter parameter to cal_footer.inc.php. NOTE: the ycyear parameter to yearcal.php is already covered by CVE-2006-1835.
|
2007-06-25
|
Calendarix calendar.php Multiple Parameter XSS
|
|
35697
Description:
(Description Provided by CVE) : Calendarix 0.7.20070307 allows remote attackers to obtain sensitive information via (1) an invalid month[] parameter to calendar.php, (2) an invalid catview[] parameter to cal_week.php in a week operation, (3) an invalid ycyear[] parameter to yearcal.php, or (4) a direct request to cal_functions.inc.php, which reveals the installation path in various error messages.
|
2007-06-25
|
Calendarix cal_week.php catview Variable Path Disclosure
|
|
35698
Description:
(Description Provided by CVE) : Calendarix 0.7.20070307 allows remote attackers to obtain sensitive information via (1) an invalid month[] parameter to calendar.php, (2) an invalid catview[] parameter to cal_week.php in a week operation, (3) an invalid ycyear[] parameter to yearcal.php, or (4) a direct request to cal_functions.inc.php, which reveals the installation path in various error messages.
|
2007-06-25
|
Calendarix yearcal.php ycyear Variable Path Disclosure
|
|
35699
Description:
(Description Provided by CVE) : Calendarix 0.7.20070307 allows remote attackers to obtain sensitive information via (1) an invalid month[] parameter to calendar.php, (2) an invalid catview[] parameter to cal_week.php in a week operation, (3) an invalid ycyear[] parameter to yearcal.php, or (4) a direct request to cal_functions.inc.php, which reveals the installation path in various error messages.
|
2007-06-25
|
Calendarix cal_functions.inc.php Direct Request Path Disclosure
|
|
36291
Description:
b1gBB contains a flaw that may allow a remote attacker to execute arbitrary commands or code. The issue is due to the 'footer.inc.php' script not properly sanitizing user input supplied to the 'tfooter' parameter. This may allow an attacker to include a file from a third-party remote host that contains commands or code that will be executed by the vulnerable script with the same privileges as the web server.
|
2007-06-25
|
b1gBB footer.inc.php tfooter Parameter Remote File Inclusion
|
|
36292
Description:
(Description Provided by CVE) : SQL injection vulnerability in essentials/minutes/doc.php in eDocStore allows remote attackers to execute arbitrary SQL commands via the doc_id parameter in an inline action.
|
2007-06-25
|
eDocStore essentials/minutes/doc.php doc_id Parameter SQL Injection
|
|
37012
Description:
(Description Provided by CVE) : SQL injection vulnerability in member.php in 6ALBlog allows remote attackers to execute arbitrary SQL commands via the newsid parameter.
|
2007-06-25
|
6ALBlog member.php Multiple Parameter SQL Injection
|
|
37013
Description:
6ALBlog contains a flaw that may allow a remote attacker to execute arbitrary commands or code. The issue is due to the 'admin/index.php' script not properly sanitizing user input supplied to the 'pg' parameter. This may allow an attacker to include a file from a third-party remote host that contains commands or code that will be executed by the vulnerable script with the same privileges as the web server.
|
2007-06-25
|
6ALBlog admin/index.php pg Parameter Remote File Inclusion
|
|
37529
Description:
(Description Provided by CVE) : Multiple cross-site scripting (XSS) vulnerabilities in defter_yaz.asp in Lebisoft zdefter 4.0 allow remote attackers to inject arbitrary web script or HTML via the (1) ad and (2) konu parameters. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
|
2007-06-25
|
Lebisoft zdefter defter_yaz.asp Multiple Parameter XSS
|
|
38205
Description:
(Description Provided by CVE) : Cross-site scripting (XSS) vulnerability in index.php in BugMall Shopping Cart 2.5 and earlier allows remote attackers to inject arbitrary web script or HTML via the msgs parameter. NOTE: 4.0.2 and other versions might also be affected.
|
2007-06-25
|
BugMall Shopping Cart index.php msgs Parameter XSS
|
|
38223
Description:
(Description Provided by CVE) : SQL injection vulnerability in BugMall Shopping Cart 2.5 and earlier allows remote attackers to execute arbitrary SQL commands via the "basic search box." NOTE: 4.0.2 and other versions might also be affected.
|
2007-06-25
|
BugMall Shopping Cart Basic Search Box SQL Injection
|
|
38225
Description:
(Description Provided by CVE) : SQL injection vulnerability in index.php in pagetool 1.07 allows remote attackers to execute arbitrary SQL commands via the news_id parameter in a pagetool_news action.
|
2007-06-25
|
Pagetool index.php news_id Parameter SQL Injection
|
|
38229
Description:
(Description Provided by CVE) : SQL injection vulnerability in include/get_userdata.php in Power Phlogger (PPhlogger) 2.2.5 and earlier allows remote attackers to execute arbitrary SQL commands via the username parameter to login.php.
|
2007-06-25
|
PowerPhlogger include/get_userdata.php username Parameter SQL Injection
|
|
38603
Description:
(Description Provided by CVE) : Directory traversal vulnerability in ShowImage.php in SiteDepth CMS 3.44 allows remote attackers to read arbitrary files via a .. (dot dot) in the name parameter.
|
2007-06-25
|
SiteDepth CMS ShowImage.php name Parameter Traversal Arbitrary File Access
|
|
45426
Description:
(Description Provided by CVE) : Unrestricted file upload vulnerability in signup.php in e107 0.7.8 and earlier, when photograph upload is enabled, allows remote attackers to upload and execute arbitrary PHP code via a filename with a double extension such as .php.jpg.
|
2007-06-24
|
e107 signup.php Double Extension Unrestricted File Upload Arbitrary Code Execution
|
|
40882
Description:
(Description Provided by CVE) : Stack-based buffer overflow in bookmark handling in Apple Safari 3 Beta before Update 3.0.3 on Windows allows user-assisted remote attackers to cause a denial of service (application crash) or execute arbitrary code via a bookmark with a long title.
|
2007-06-24
|
Apple Safari on Windows Bookmark Title Overflow
|
|
37474
Description:
(Description Provided by CVE) : Directory traversal vulnerability in index.php in phpTrafficA 1.4.2 and earlier allows remote attackers to include arbitrary local files via the lang parameter, a different vector and version than CVE-2007-1076.2.
|
2007-06-24
|
phpTrafficA index.php lang Parameter Traversal Local File Inclusion
|
|
37475
Description:
(Description Provided by CVE) : Cross-site scripting (XSS) vulnerability in index.php in phpTrafficA 1.4.2 and earlier allows remote attackers to inject arbitrary web script or HTML via the lang parameter.
|
2007-06-24
|
phpTrafficA index.php lang Parameter XSS
|
|
37476
Description:
(Description Provided by CVE) : SQL injection vulnerability in index.php in phpTrafficA 1.4.2 and earlier allows remote attackers to execute arbitrary SQL commands via the pageid parameter in a stats action.
|
2007-06-24
|
phpTrafficA index.php Stats Action pageid Parameter SQL Injection
|
|
36293
Description:
(Description Provided by CVE) : SQL injection vulnerability in index.php in Simple Invoices 2007 05 25 allows remote attackers to execute arbitrary SQL commands via the submit parameter in an email action.
|
2007-06-24
|
Simple Invoices index.php email Action submit Parameter SQL Injection
|
|
36302
Description:
Dagger contains a flaw that may allow a remote attacker to execute arbitrary commands or code. The issue is due to the 'cal.func.php' script not properly sanitizing user input supplied to the 'dir_edge_lang' parameter. This may allow an attacker to include a file from a third-party remote host that contains commands or code that will be executed by the vulnerable script with the same privileges as the web server.
|
2007-06-24
|
Dagger cal.func.php dir_edge_lang Parameter Remote File Inclusion
|
|
37578
Description:
(Description Provided by CVE) : index.php in Pharmacy System 2 and earlier allows remote attackers to obtain sensitive information via a ' (quote) character in the page parameter, which reveals the table prefix in an error message.
|
2007-06-24
|
Pharmacy System index.php page Parameter SQL Injection
|
|
38224
Description:
(Description Provided by CVE) : SQL injection vulnerability in index.php in Pharmacy System 2 and earlier allows remote attackers to execute arbitrary SQL commands via the ID parameter in an add action.
|
2007-06-24
|
Pharmacy System index.php ID Parameter SQL Injection
|
|
38890
Description:
(Description Provided by CVE) : Cross-site scripting (XSS) vulnerability in admin/auth.php in Pluxml 0.3.1 allows remote attackers to inject arbitrary web script or HTML via the msg parameter.
|
2007-06-24
|
Pluxml admin/auth.php msg Parameter XSS
|
|
42420
Description:
(Description Provided by CVE) : Unrestricted file upload vulnerability in admin/images.php in Pluxml 0.3.1 allows remote attackers to upload and execute arbitrary PHP code via a .jpg filename.
|
2007-06-24
|
Pluxml admin/images.php Unrestricted File Upload JPG Filename Arbitrary Code Execution
|
|
37294
Description:
(Description Provided by CVE) : Unrestricted file upload vulnerability in (1) wp-app.php and (2) app.php in WordPress 2.2.1 and WordPress MU 1.2.3 allows remote authenticated users to upload and execute arbitrary PHP code via unspecified vectors, possibly related to the wp_postmeta table and the use of custom fields in normal (non-attachment) posts. NOTE: this issue reportedly exists because of an incomplete fix for CVE-2007-3543.
|
2007-06-23
|
WordPress / MU Multiple Script Unrestricted File Upload
|
|
37295
Description:
(Description Provided by CVE) : Unrestricted file upload vulnerability in WordPress before 2.2.1 and WordPress MU before 1.2.3 allows remote authenticated users to upload and execute arbitrary PHP code by making a post that specifies a .php filename in the _wp_attached_file metadata field; and then sending this file's content, along with its post_ID value, to (1) wp-app.php or (2) app.php.
|
2007-06-23
|
WordPress / MU _wp_attached_file Metadata Unrestricted File Upload
|
|
37482
Description:
The ActiveX component of the RKD Barcode Application is prone to an overflow condition. The ActiveX BarCodeAx.dll Control fails to properly sanitize user-supplied input resulting in a stack overflow within the BeginPrint() method. With a specially crafted request, a remote attacker can potentially execute arbitrary code.
|
2007-06-23
|
RKD Software BarCode ActiveX (BarCodeAx.dll) BeginPrint Method Overflow
|