| OSVDB ID | Disclosure Date | Title |
|
44055
Description:
Unknown / Incomplete
|
2008-01-31
|
Sympa sympa.pl Malformed Multipart Command Message Handling DoS
|
|
27531
Description:
Novell GroupWise WebAccess contains a flaw that may allow a remote cross-site scripting attack. The 'webacc' program fails to validate the 'User.html', 'Error', 'User.Theme.index' and 'User.lang' variables before being returned to the user. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server.
|
2008-01-31
|
Novell GroupWise WebAccess webacc Multiple Parameter XSS
|
|
40833
Description:
(Description Provided by CVE) : Stack-based buffer overflow in Aurigma Image Uploader ActiveX control (ImageUploader4.ocx) 4.5.70 and earlier, as used in MySpace MySpaceUploader.ocx 1.0.0.4, allows remote attackers to execute arbitrary code via a long Action property.
|
2008-01-31
|
MySpace Uploader Control MySpace.Uploader ActiveX (MySpaceUploader.ocx) Action Property Overflow
|
|
40887
Description:
(Description Provided by CVE) : Multiple directory traversal vulnerabilities in Nilson's Blogger 0.11 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in (1) the permalink parameter in core.php, accessed through index.php; and (2) the thispost parameter in comments.php.
|
2008-01-31
|
Nilsons Blogger index.php permalink Parameter Local File Inclusion
|
|
40888
Description:
(Description Provided by CVE) : Multiple directory traversal vulnerabilities in Nilson's Blogger 0.11 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in (1) the permalink parameter in core.php, accessed through index.php; and (2) the thispost parameter in comments.php.
|
2008-01-31
|
Nilsons Blogger comments.php thispost Parameter Local File Inclusion
|
|
40889
Description:
(Description Provided by CVE) : Stack-based buffer overflow in Aurigma Image Uploader ActiveX control (ImageUploader4.ocx) 4.5.70 and earlier, as used in MySpace MySpaceUploader.ocx 1.0.0.4, allows remote attackers to execute arbitrary code via a long Action property.
|
2008-01-31
|
Aurigma Image Uploader Aurigma.ImageUploader ActiveX (ImageUploader4.ocx) Action Property Overflow Arbitrary Code Execution
|
|
41128
Description:
Mindmeld contains a flaw that may allow a remote attacker to execute arbitrary commands or code. The issue is due to the 'acweb/admin_index.php' script not properly sanitizing user input supplied to the 'MM_GLOBALS[home]' parameter. This may allow an attacker to include a file from a third-party remote host that contains commands or code that will be executed by the vulnerable script with the same privileges as the web server.
|
2008-01-31
|
Mindmeld acweb/admin_index.php MM_GLOBALS[home] Parameter Remote File Inclusion
|
|
41129
Description:
Mindmeld contains a flaw that may allow a remote attacker to execute arbitrary commands or code. The issue is due to the 'include/ask.inc.php' script not properly sanitizing user input supplied to the 'MM_GLOBALS[home]' parameter. This may allow an attacker to include a file from a third-party remote host that contains commands or code that will be executed by the vulnerable script with the same privileges as the web server.
|
2008-01-31
|
Mindmeld include/ask.inc.php MM_GLOBALS[home] Parameter Remote File Inclusion
|
|
41130
Description:
Mindmeld contains a flaw that may allow a remote attacker to execute arbitrary commands or code. The issue is due to the 'include/learn.inc.php' script not properly sanitizing user input supplied to the 'MM_GLOBALS[home]' parameter. This may allow an attacker to include a file from a third-party remote host that contains commands or code that will be executed by the vulnerable script with the same privileges as the web server.
|
2008-01-31
|
Mindmeld include/learn.inc.php MM_GLOBALS[home] Parameter Remote File Inclusion
|
|
41131
Description:
Mindmeld contains a flaw that may allow a remote attacker to execute arbitrary commands or code. The issue is due to the 'include/manage.inc.php' script not properly sanitizing user input supplied to the 'MM_GLOBALS[home]' parameter. This may allow an attacker to include a file from a third-party remote host that contains commands or code that will be executed by the vulnerable script with the same privileges as the web server.
|
2008-01-31
|
Mindmeld include/manage.inc.php MM_GLOBALS[home] Parameter Remote File Inclusion
|
|
41132
Description:
Mindmeld contains a flaw that may allow a remote attacker to execute arbitrary commands or code. The issue is due to the 'include/mind.inc.php' script not properly sanitizing user input supplied to the 'MM_GLOBALS[home]' parameter. This may allow an attacker to include a file from a third-party remote host that contains commands or code that will be executed by the vulnerable script with the same privileges as the web server.
|
2008-01-31
|
Mindmeld include/mind.inc.php MM_GLOBALS[home] Parameter Remote File Inclusion
|
|
41133
Description:
Mindmeld contains a flaw that may allow a remote attacker to execute arbitrary commands or code. The issue is due to the 'include/sensory.inc.php' script not properly sanitizing user input supplied to the 'MM_GLOBALS[home]' parameter. This may allow an attacker to include a file from a third-party remote host that contains commands or code that will be executed by the vulnerable script with the same privileges as the web server.
|
2008-01-31
|
Mindmeld include/sensory.inc.php MM_GLOBALS[home] Parameter Remote File Inclusion
|
|
41213
Description:
(Description Provided by CVE) : SQL injection vulnerability in index.php in the Restaurant (com_restaurant) 1.0 component for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a detail action.
|
2008-01-31
|
Restaurant Component for Mambo / Joomla! index.php id Parameter SQL Injection
|
|
41214
Description:
(Description Provided by CVE) : SQL injection vulnerability in index.php in the Arthur Konze AkoGallery (com_akogallery) 2.5 beta component for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a detail action.
|
2008-01-31
|
AkoGallery Component for Mambo / Joomla! index.php id Parameter SQL Injection
|
|
41216
Description:
cforms Plugin for Wordpress contains a flaw that may allow a remote attacker to execute arbitrary commands or code. The issue is due to the 'cforms-css.php' script not properly sanitizing user input supplied to the 'tm' parameter. This may allow an attacker to include a file from a third-party remote host that contains commands or code that will be executed by the vulnerable script with the same privileges as the web server.
|
2008-01-31
|
cforms Plugin for Wordpress cforms-css.php tm Parameter Remote File Inclusion
|
|
41219
Description:
(Description Provided by CVE) : SQL injection vulnerability in index.php in the CatalogShop (com_catalogshop) 1.0b1 componenent for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a detail action.
|
2008-01-31
|
CatalogShop Component for Mambo and Joomla! index.php id Parameter SQL Injection
|
|
41522
Description:
(Description Provided by CVE) : Multiple directory traversal vulnerabilities in sflog! 0.96 allow remote attackers to read arbitrary files via a .. (dot dot) in the (1) permalink or (2) section parameter to index.php, possibly involving includes/entries.inc.php and other files included by index.php.
|
2008-01-31
|
sflog! index.php Multiple Parameter Traversal Arbitrary File Access
|
|
49167
Description:
(Description Provided by CVE) : Insecure method vulnerability in the Chilkat FTP 2.0 ActiveX component (ChilkatCert.dll) allows remote attackers to overwrite arbitrary files via a full pathname in the SavePkcs8File method.
|
2008-01-31
|
Chilkat FTP ActiveX (ChilkatCert.dll) SavePkcs8File Method Arbitrary File Overwrite
|
|
57915
Description:
(Description Provided by CVE) : Coppermine Photo Gallery (CPG) 1.4.14 does not restrict access to update.php, which allows remote attackers to obtain sensitive information such as the database table prefix via a direct request. NOTE: this might be leveraged for attacks against CVE-2008-0504.
|
2008-01-31
|
Coppermine Photo Gallery update.php Direct Request Information Disclosure
|
|
57916
Description:
(Description Provided by CVE) : Coppermine Photo Gallery (CPG) 1.4.14 allows remote attackers to obtain sensitive information via a direct request to include/slideshow.inc.php, which leaks the installation path in an error message.
|
2008-01-31
|
Coppermine Photo Gallery include/slideshow.inc.php Direct Request Path Disclosure
|
|
41761
Description:
(Description Provided by CVE) : Unspecified vulnerability in the product view functionality in VirtueMart 1.0.13a and earlier allows remote attackers to read arbitrary files via vectors related to a template file.
|
2008-01-30
|
VirtueMart Product View Unspecified Arbitrary File Access
|
|
41762
Description:
(Description Provided by CVE) : Cross-site request forgery (CSRF) vulnerability in VirtueMart 1.0.13a and earlier allows remote attackers to hijack the authentication of administrators via unspecified vectors.
|
2008-01-30
|
VirtueMart Unspecified CSRF
|
|
40854
Description:
(Description Provided by CVE) : Multiple SQL injection vulnerabilities in main.php in the WassUp plugin 1.4 through 1.4.3 for WordPress allow remote attackers to execute arbitrary SQL commands via the (1) from_date or (2) to_date parameter to spy.php.
|
2008-01-30
|
WassUp Plugin for WordPress spy.php Multiple Parameter SQL Injection
|
|
43849
Description:
(Description Provided by CVE) : Mozilla Firefox before 2.0.0.13 and SeaMonkey before 1.1.9, when generating the HTTP Referer header, does not list the entire URL when it contains Basic Authentication credentials without a username, which makes it easier for remote attackers to bypass application protection mechanisms that rely on Referer headers, such as with some Cross-Site Request Forgery (CSRF) mechanisms.
|
2008-01-30
|
Mozilla Multiple Browsers Basic Authentication Referrer Header Spoofing
|
|
41068
Description:
(Description Provided by CVE) : The Comment Upload 4.7.x before 4.7.x-0.1 and 5.x before 5.x-0.1 module for Drupal does not properly use functions in the upload module, which allows remote attackers to bypass upload validation, and upload arbitrary files and possibly execute arbitrary code, via unspecified vectors.
|
2008-01-30
|
Comment Upload Module for Drupal Arbitrary File Upload
|
|
42199
Description:
(Description Provided by CVE) : Buffer overflow in url.c in MPlayer 1.0rc2 and SVN before r25823 allows remote attackers to execute arbitrary code via a crafted URL that prevents the IPv6 parsing code from setting a pointer to NULL, which causes the buffer to be reused by the unescape code.
|
2008-01-30
|
MPlayer url.c IPv6 Parsing Code Crafted URL Overflow
|
|
42200
Description:
(Description Provided by CVE) : Buffer overflow in stream_cddb.c in MPlayer 1.0rc2 and SVN before r25824 allows remote user-assisted attackers to execute arbitrary code via a CDDB database entry containing a long album title.
|
2008-01-30
|
MPlayer stream_cddb.c CDDB Database Album Title Handling Overflow
|
|
41069
Description:
(Description Provided by CVE) : Unspecified vulnerability in the IP-authentication feature in the Secure Site 5.x-1.0 and 4.7.x-1.0 module for Drupal allows remote attackers to gain the privileges of a user who has authenticated from behind the same proxy server as the attacker.
|
2008-01-30
|
Secure Site Module for Drupal Authentication Bypass
|
|
42834
Description:
(Description Provided by CVE) : Stack-based buffer overflow in Pierre-emmanuel Gougelet (1) XnView 1.91 and 1.92, (2) NConvert 4.85, and (3) libgfl280.dll in GFL SDK 2.870 for Windows allows user-assisted remote attackers to execute arbitrary code via a crafted Radiance RGBE (.hdr) file.
|
2008-01-30
|
GFL SDK libgfl280.dll Radiance RGBE (.hdr) Handling Overflow
|
|
42150
Description:
(Description Provided by CVE) : Cross-site scripting (XSS) vulnerability in the Project Issue Tracking module 5.x-2.x-dev before 20080130 in the 5.x-2.x series, 5.x-1.2 and earlier in the 5.x-1.x series, 4.7.x-2.6 and earlier in the 4.7.x-2.x series, and 4.7.x-1.6 and earlier in the 4.7.x-1.x series for Drupal allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors that write to summary table pages.
|
2008-01-30
|
Drupal Project Issue Tracking Module Comment Summary XSS
|
|
42151
Description:
(Description Provided by CVE) : The Project Issue Tracking module 5.x-2.x-dev before 20080130 in the 5.x-2.x series, 5.x-1.2 and earlier in the 5.x-1.x series, 4.7.x-2.6 and earlier in the 4.7.x-2.x series, and 4.7.x-1.6 and earlier in the 4.7.x-1.x series for Drupal (1) does not restrict the extensions of attached files when the Upload module is enabled for issue nodes, which allows remote attackers to upload and possibly execute arbitrary files; and (2) accepts the .html extension within the bundled file-upload functionality, which allows remote attackers to upload files containing arbitrary web script or HTML.
|
2008-01-30
|
Drupal Project Issue Tracking Module Arbitrary File Upload
|
|
42832
Description:
(Description Provided by CVE) : Stack-based buffer overflow in Pierre-emmanuel Gougelet (1) XnView 1.91 and 1.92, (2) NConvert 4.85, and (3) libgfl280.dll in GFL SDK 2.870 for Windows allows user-assisted remote attackers to execute arbitrary code via a crafted Radiance RGBE (.hdr) file.
|
2008-01-30
|
XnView Radiance RGBE (.hdr) Handling Overflow
|
|
42833
Description:
(Description Provided by CVE) : Stack-based buffer overflow in Pierre-emmanuel Gougelet (1) XnView 1.91 and 1.92, (2) NConvert 4.85, and (3) libgfl280.dll in GFL SDK 2.870 for Windows allows user-assisted remote attackers to execute arbitrary code via a crafted Radiance RGBE (.hdr) file.
|
2008-01-30
|
NConvert Radiance RGBE (.hdr) Handling Overflow
|
|
41685
Description:
(Description Provided by CVE) : Unspecified vulnerability in Electronic Logbook (ELOG) before 2.7.2 has unknown impact and attack vectors when the "logbook contains HTML code," probably cross-site scripting (XSS).
|
2008-01-30
|
ELOG Logbook Unspecified XSS
|
|
41677
Description:
(Description Provided by CVE) : Multiple cross-site scripting (XSS) vulnerabilities in docs/showdoc.php in Coppermine Photo Gallery (CPG) before 1.4.15 allow remote attackers to inject arbitrary web script or HTML via the (1) h and (2) t parameters.
|
2008-01-30
|
Coppermine Photo Gallery docs/showdoc.php Multiple Parameter XSS
|
|
41676
Description:
Coppermine Photo Gallery contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is triggered when include/imageObjectIM.class.php fails to validate data passed to the 'quality,' 'angle' and 'clipval' parameters.
|
2008-01-30
|
Coppermine Photo Gallery include/imageObjectIM.class.php Multiple Parameter Remote Command Execution
|
|
41679
Description:
(Description Provided by CVE) : Multiple SQL injection vulnerabilities in Coppermine Photo Gallery (CPG) before 1.4.15 allow remote authen ticated administrators to execute arbitrary SQL commands via the (1) albumid, (2) startpic, and (3) numpics parameters to util.php; and (4) cid_array parameter to reviewcom.php.
|
2008-01-30
|
Coppermine Photo Gallery reviewcom.php cid_array Parameter SQL Injection
|
|
40775
Description:
SoftCart contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the 'License_Plate', 'License_State', 'Ticket_Date', and 'Ticket_Number' variables upon submission to the 'SoftCart.exe' script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2008-01-30
|
SoftCart SoftCart.exe Multiple Parameter XSS
|
|
40779
Description:
(Description Provided by CVE) : SQL injection vulnerability in adclick.php in the AdServe 0.2 plugin for WordPress allows remote attackers to execute arbitrary SQL commands via the id parameter.
|
2008-01-30
|
AdServe Plugin for WordPress adclick.php id Parameter SQL Injection
|
|
40781
Description:
SQLiteManager contains a flaw that may allow a remote attacker to execute arbitrary commands or code. The issue is due to the 'spaw/dialogs/confirm.php' script not properly sanitizing user input supplied to the 'spaw_root' parameter. This may allow an attacker to include a file from a third-party remote host that contains commands or code that will be executed by the vulnerable script with the same privileges as the web server.
|
2008-01-30
|
SQLiteManager spaw/dialogs/confirm.php spaw_root Parameter Remote File Inclusion
|