| OSVDB ID | Disclosure Date | Title |
|
38298
Description:
(Description Provided by CVE) : Multiple cross-site scripting (XSS) vulnerabilities in (1) Request-spk.xuda and (2) Add-msie-request.xuda in RSA KEON Registration Authority Web Interface 1.0 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
|
2007-07-31
|
RSA KEON Registration Authority Request-spk.xuda Unspecified Variable XSS
|
|
38299
Description:
(Description Provided by CVE) : Multiple cross-site scripting (XSS) vulnerabilities in (1) Request-spk.xuda and (2) Add-msie-request.xuda in RSA KEON Registration Authority Web Interface 1.0 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
|
2007-07-31
|
RSA KEON Registration Authority Add-msie-request.xuda Unspecified XSS
|
|
38987
Description:
(Description Provided by CVE) : Directory traversal vulnerability in inc/lib/language.lib.php in Claroline before 1.8.6 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the language parameter.
|
2007-07-31
|
Claroline inc/lib/language.lib.php language Variable Traversal Local File Inclusion
|
|
39048
Description:
(Description Provided by CVE) : Heap-based buffer overflow in the BlueSkychat (BlueSkyCat) ActiveX control (V2.V2Ctrl.1) in v2.ocx 8.1.2.0 and earlier allows remote attackers to execute arbitrary code via a long string in the second argument to the ConnecttoServer method.
|
2007-07-31
|
BlueSkyCat ActiveX v2.ocx (V2.V2Ctrl.1) ConnecttoServer Method Remote Overflow
|
|
39192
Description:
(Description Provided by CVE) : SQL injection vulnerability in index.php in the Firestorm Technologies GMaps (com_gmaps) 1.00 component for Joomla! allows remote attackers to execute arbitrary SQL commands via the mapId parameter in a viewmap action.
|
2007-07-31
|
GMaps Component for Joomla! index.php viewmap Action mapId Variable SQL Injection
|
|
39216
Description:
WebEvent contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the 'cmd' variable upon submission to the 'webevent.cgi' script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2007-07-31
|
WebEvent webevent.cgi cmd Variable XSS
|
|
39295
Description:
(Description Provided by CVE) : irc-channel.c in ngIRCd before 0.10.3 allows remote attackers to cause a denial of service (crash) via a JOIN command without a channel argument.
|
2007-07-31
|
ngIRCd irc-channel.c Null channel Argument JOIN Command Remote DoS
|
|
39371
Description:
Wordpress contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the 'options-general.php' script not properly sanitizing user-supplied input to the 'page_options' variable. This may allow an attacker to inject or manipulate SQL queries in the backend database.
|
2007-07-31
|
Wordpress options-general.php page_options Variable SQL Injection
|
|
39372
Description:
Wordpress contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the 'options-writing.php' script not properly sanitizing user-supplied input to the 'page_options' variable. This may allow an attacker to inject or manipulate SQL queries in the backend database.
|
2007-07-31
|
Wordpress options-writing.php page_options Variable SQL Injection
|
|
39373
Description:
Wordpress contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the 'options-reading.php' script not properly sanitizing user-supplied input to the 'page_options' variable. This may allow an attacker to inject or manipulate SQL queries in the backend database.
|
2007-07-31
|
Wordpress options-reading.php page_options Variable SQL Injection
|
|
39374
Description:
Wordpress contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the 'options-discussion.php' script not properly sanitizing user-supplied input to the 'page_options' variable. This may allow an attacker to inject or manipulate SQL queries in the backend database.
|
2007-07-31
|
Wordpress options-discussion.php page_options Variable SQL Injection
|
|
39375
Description:
Wordpress contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the 'options-privacy.php' script not properly sanitizing user-supplied input to the 'page_options' variable. This may allow an attacker to inject or manipulate SQL queries in the backend database.
|
2007-07-31
|
Wordpress options-privacy.php page_options Variable SQL Injection
|
|
39376
Description:
Wordpress contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the 'options-permalink.php' script not properly sanitizing user-supplied input to the 'page_options' variable. This may allow an attacker to inject or manipulate SQL queries in the backend database.
|
2007-07-31
|
Wordpress options-permalink.php page_options Variable SQL Injection
|
|
39377
Description:
Wordpress contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the 'options-misc.php' script not properly sanitizing user-supplied input to the 'page_options' variable. This may allow an attacker to inject or manipulate SQL queries in the backend database.
|
2007-07-31
|
Wordpress options-misc.php page_options Variable SQL Injection
|
|
39029
Description:
Unknown / Incomplete
|
2007-07-30
|
vBulletin Multiple Script Remote File Inclusion
|
|
39030
Description:
(Description Provided by CVE) : PHP remote file inclusion vulnerability in includes/functions.inc.php in phpVoter 0.6 allows remote attackers to execute arbitrary PHP code via a URL in the sitepath parameter.
|
2007-07-30
|
phpVoter functions.inc.php sitepath Variable Remote File Inclusion
|
|
39033
Description:
Unknown / Incomplete
|
2007-07-30
|
Phorm fileupload.php Arbitrary PHP File Upload
|
|
39369
Description:
(Description Provided by CVE) : Multiple buffer overflows in Konst CenterICQ 4.9.11 through 4.21 allow remote attackers to execute arbitrary code via unspecified vectors. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. NOTE: this might overlap CVE-2007-0160.
|
2007-07-30
|
CenterICQ Multiple Unspecified Remote Overflows
|
|
37706
Description:
(Description Provided by CVE) : A certain ActiveX control in BaiduBar.dll in Baidu Soba Search Bar 5.4 allows remote attackers to execute arbitrary code via a request containing "a link to download and a file to execute," possibly involving remote file inclusion.
|
2007-07-30
|
Baidu Soba Search Bar ActiveX (BaiduBar.dll) Arbitrary Code Execution
|
|
36352
Description:
(Description Provided by CVE) : Multiple SQL injection vulnerabilities in wolioCMS allow remote attackers to execute arbitrary SQL commands via (1) the id parameter to member.php in a page action, related to a SELECT statement in common.php; and the (2) loginid parameter (uid variable), and possibly the (3) pwd parameter, to admin/index.php.
|
2007-07-30
|
WolioCMS admin/index.php Multiple Variable SQL Injection
|
|
38120
Description:
(Description Provided by CVE) : Integer overflow in the StreamPredictor::StreamPredictor function in xpdf 3.02, as used in (1) poppler before 0.5.91, (2) gpdf before 2.8.2, (3) kpdf, (4) kdegraphics, (5) CUPS, (6) PDFedit, and other products, might allow remote attackers to execute arbitrary code via a crafted PDF file that triggers a stack-based buffer overflow in the StreamPredictor::getNextLine function.
|
2007-07-30
|
Xpdf StreamPredictor::StreamPredictor() PDF Handling Overflow
|
|
38739
Description:
(Description Provided by CVE) : CRLF injection vulnerability in Joomla! before 1.0.13 (aka Sunglow) allows remote attackers to inject arbitrary HTTP headers and probably conduct HTTP response splitting attacks via CRLF sequences in the url parameter. NOTE: this can be leveraged for cross-site scripting (XSS) attacks. NOTE: some of these details are obtained from third party information.
|
2007-07-30
|
Joomla! url Parameter CRLF Injection
|
|
36613
Description:
(Description Provided by CVE) : Unspecified vulnerability in the dynamic tracing framework (DTrace) on Sun Solaris 10 before 20070730 allows local users with PRIV_DTRACE_USER privileges to cause a denial of service (panic or hang) via unspecified use of certain DTrace programs.
|
2007-07-30
|
Solaris DTrace PRIV_DTRACE_USER Local DoS
|
|
36453
Description:
(Description Provided by CVE) : Multiple heap-based buffer overflows in the Perl Compatible Regular Expressions (PCRE) library in the JavaScript engine in WebKit in Apple Safari 3 Beta before Update 3.0.3, and iPhone before 1.0.1, allow remote attackers to execute arbitrary code via certain JavaScript regular expressions. NOTE: this issue was originally reported only for MobileSafari on the iPhone. NOTE: it is not clear whether this stems from an issue in the original distribution of PCRE, which might already have a separate CVE identifier.
|
2007-07-30
|
Apple Safari / iPhone WebKit Perl Compatible Regular Expressions (PCRE) Multiple Overflows
|
|
38026
Description:
(Description Provided by CVE) : Mozilla Firefox 2.0.0.5, Thunderbird 2.0.0.5 and before 1.5.0.13, and SeaMonkey 1.1.3 allows remote attackers to conduct cross-site scripting (XSS) attacks with chrome privileges via an addon that inserts a (1) javascript: or (2) data: link into an about:blank document loaded by chrome via (a) the window.open function or (b) a content.location assignment, aka "Cross Context Scripting." NOTE: this issue is caused by a CVE-2007-3089 regression.
|
2007-07-30
|
Mozilla Multiple Products Addon Chrome Cross-Context Scripting
|
|
39560
Description:
(Description Provided by CVE) : The GDM daemon in GNOME Display Manager (GDM) before 2.14.13, 2.16.x before 2.16.7, 2.18.x before 2.18.4, and 2.19.x before 2.19.5 does not properly handle NULL return values from the g_strsplit function, which allows local users to cause a denial of service (persistent daemon crash) via a crafted command to the daemon's socket, related to (1) gdm.c and (2) gdmconfig.c in daemon/, and (3) gdmconfig.c and (4) gdmflexiserver.c in gui/.
|
2007-07-30
|
GNOME Display Manager (GDM) g_strsplit Function Local DoS
|
|
37680
Description:
(Description Provided by CVE) : Memory leak in TIBCO Rendezvous (RV) daemon (rvd) 7.5.2, 7.5.3 and 7.5.4 allows remote attackers to cause a denial of service (memory consumption) via a packet with a length field of zero, a different vulnerability than CVE-2006-2830.
|
2007-07-30
|
TIBCO Rendezvous (RV) rvd Crafted Packet Remote Memory Consumption DoS
|
|
37681
Description:
(Description Provided by CVE) : rvd in TIBCO Rendezvous (RV) 7.5.2, when -no-lead-wc is omitted, might allow remote attackers to cause a denial of service (network instability) via a subject name with a leading (1) '*' (asterisk) or (2) '>' (greater than) wildcard character.
|
2007-07-30
|
TIBCO Rendezvous (RV) rvd Crafted Subject Name Remote DoS
|
|
43977
Description:
Unknown / Incomplete
|
2007-07-30
|
InspIRCd w/o m_safelist Secret Channel Disclosure
|
|
38031
Description:
(Description Provided by CVE) : Mozilla Firefox before 2.0.0.6, Thunderbird before 1.5.0.13 and 2.x before 2.0.0.6, and SeaMonkey before 1.1.4 allow remote attackers to execute arbitrary commands via certain vectors associated with launching "a file handling program based on the file extension at the end of the URI," a variant of CVE-2007-4041. NOTE: the vendor states that "it is still possible to launch a filetype handler based on extension rather than the registered protocol handler."
|
2007-07-30
|
Mozilla Multiple Products Crafted URI Unspecified File Handling Arbitrary Command Execution
|
|
36351
Description:
(Description Provided by CVE) : Multiple SQL injection vulnerabilities in wolioCMS allow remote attackers to execute arbitrary SQL commands via (1) the id parameter to member.php in a page action, related to a SELECT statement in common.php; and the (2) loginid parameter (uid variable), and possibly the (3) pwd parameter, to admin/index.php.
|
2007-07-30
|
WolioCMS member.php page Action id Variable SQL Injection
|
|
37254
Description:
(Description Provided by CVE) : Multiple cross-site scripting (XSS) vulnerabilities in IT!CMS (itcms) 0.2 allow remote attackers to inject arbitrary web script or HTML via the wndtitle parameter to (1) lang-en.php, (2) menu-ed.php, or (3) titletext-ed.php.
|
2007-07-30
|
IT!CMS lang-en.php wndtitle Variable XSS
|
|
37255
Description:
(Description Provided by CVE) : Multiple cross-site scripting (XSS) vulnerabilities in IT!CMS (itcms) 0.2 allow remote attackers to inject arbitrary web script or HTML via the wndtitle parameter to (1) lang-en.php, (2) menu-ed.php, or (3) titletext-ed.php.
|
2007-07-30
|
IT!CMS menu-ed.php wndtitle Variable XSS
|
|
37256
Description:
(Description Provided by CVE) : Multiple cross-site scripting (XSS) vulnerabilities in IT!CMS (itcms) 0.2 allow remote attackers to inject arbitrary web script or HTML via the wndtitle parameter to (1) lang-en.php, (2) menu-ed.php, or (3) titletext-ed.php.
|
2007-07-30
|
IT!CMS titletext-ed.php wndtitle Variable XSS
|
|
37262
Description:
(Description Provided by CVE) : Multiple PHP remote file inclusion vulnerabilities in Madoa Poll 1.1 allow remote attackers to execute arbitrary PHP code via the Madoa parameter to (1) index.php, (2) vote.php, and (3) admin.php.
|
2007-07-30
|
Madoa Poll index.php Madoa Variable Remote File Inclusion
|
|
37263
Description:
(Description Provided by CVE) : Multiple PHP remote file inclusion vulnerabilities in Madoa Poll 1.1 allow remote attackers to execute arbitrary PHP code via the Madoa parameter to (1) index.php, (2) vote.php, and (3) admin.php.
|
2007-07-30
|
Madoa Poll vote.php Madoa Variable Remote File Inclusion
|
|
37264
Description:
(Description Provided by CVE) : Multiple PHP remote file inclusion vulnerabilities in Madoa Poll 1.1 allow remote attackers to execute arbitrary PHP code via the Madoa parameter to (1) index.php, (2) vote.php, and (3) admin.php.
|
2007-07-30
|
Madoa Poll admin.php Madoa Variable Remote File Inclusion
|
|
39034
Description:
(Description Provided by CVE) : ** DISPUTED ** PHP remote file inclusion vulnerability in index.php in phpWebFileManager 0.5 allows remote attackers to execute arbitrary PHP code via a URL in the PN_PathPrefix parameter. NOTE: this issue is disputed by a reliable third party, who demonstrates that PN_PathPrefix is defined before use.
|
2007-07-30
|
phpWebFileManager index.php PN_PathPrefix Variable Remote File Inclusion
|
|
39031
Description:
(Description Provided by CVE) : SQL injection vulnerability in administrator/popups/pollwindow.php in Joomla! 1.0.12 allows remote attackers to execute arbitrary SQL commands via the pollid parameter.
|
2007-07-29
|
Joomla! pollwindow.php pollid Variable SQL Injection
|
|
39028
Description:
Unknown / Incomplete
|
2007-07-29
|
Commute small_head.php retun Variable XSS
|