| OSVDB ID | Disclosure Date | Title |
|
43730
Description:
(Description Provided by CVE) : BolinOS 4.6.1 allows remote attackers to obtain sensitive information via a direct request to system/actionspages/_b/contentFiles/gBphpInfo.php, which calls the phpinfo function.
|
2008-03-25
|
BolinOS gBphpInfo.php System Information Disclosure
|
|
43668
Description:
phpAddressBook contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate 'info' variable upon submission to the index.php script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2008-03-25
|
phpAddressBook index.php info Parameter XSS
|
|
43686
Description:
ManageEngine EventLog Analyzer contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the 'searchText' variable upon submission to the 'searchAction.do' script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2008-03-25
|
ManageEngine EventLog Analyzer searchAction.do searchText Parameter XSS
|
|
43713
Description:
(Description Provided by CVE) : Absolute path traversal vulnerability in dload.php in the my_gallery 2.3 plugin for e107 allows remote attackers to obtain sensitive information via a full pathname in the file parameter. NOTE: some of these details are obtained from third party information.
|
2008-03-25
|
my_gallery Plugin for e107 dload.php file Variable Arbitrary File PHP Source Disclosure
|
|
43740
Description:
A remote overflow exists in MPlayer. MPlayer fails to sanitize the 'StreamCount' variable resulting in an integer overflow. With a specially crafted request, an attacker can execute arbitrary code, resulting in a loss of integrity.
|
2008-03-25
|
MPlayer stream/realrtsp/sdpplin.c sdpplin_parse Function StreamCount Variable Remote Overflow
|
|
43762
Description:
(Description Provided by CVE) : The silc_pkcs1_decode function in the silccrypt library (silcpkcs1.c) in Secure Internet Live Conferencing (SILC) Toolkit before 1.1.7, SILC Client before 1.1.4, and SILC Server before 1.1.2 allows remote attackers to execute arbitrary code via a crafted PKCS#1 message, which triggers an integer underflow, signedness error, and a buffer overflow. NOTE: the researcher describes this as an integer overflow, but CVE uses the "underflow" term in cases of wraparound from unsigned subtraction.
|
2008-03-25
|
SILC Multiple Products lib/silccrypt/silcpkcs1.c silc_pkcs1_decode Function Overflow
|
|
43923
Description:
(Description Provided by CVE) : Directory traversal vulnerability in mod.php in TopperMod 1.0 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the to parameter.
|
2008-03-25
|
TopperMod mod.php to Parameter Traversal Local File Inclusion
|
|
43940
Description:
(Description Provided by CVE) : Directory traversal vulnerability in forum/irc/irc.php in the PJIRC 0.5 module for phpBB allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the phpEx parameter.
|
2008-03-25
|
PJIRC Module for phpBB forum/irc/irc.php phpEx Parameter Traversal Local File Inclusion
|
|
43941
Description:
(Description Provided by CVE) : SQL injection vulnerability in the Bernard Gilly AlphaContent (com_alphacontent) 2.5.8 component for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a view action to index.php.
|
2008-03-25
|
AlphaContent Component for Joomla! index.php id Parameter SQL Injection
|
|
43944
Description:
(Description Provided by CVE) : SQL injection vulnerability in account/index.php in TopperMod 2.0, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via a non-alphanumeric first character the localita parameter, which bypasses a protection mechanism.
|
2008-03-25
|
TopperMod account/index.php localita Parameter SQL Injection
|
|
43949
Description:
Aeries Browser Interface contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the 'loginproc.asp' script not properly sanitizing user-supplied input to the 'SchlCode' variable. This may allow an attacker to inject or manipulate SQL queries in the back-end database.
|
2008-03-25
|
Aeries Browser Interface GradebookOptions.asp GrdBk Parameter SQL Injection
|
|
44166
Description:
(Description Provided by CVE) : SQL injection vulnerability in haberoku.php in Serbay Arslanhan Bomba Haber 2.0 allows remote attackers to execute arbitrary SQL commands via the haber parameter.
|
2008-03-25
|
Bomba Haber haberoku.php haber Parameter SQL Injection
|
|
44167
Description:
Clever Copy contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the 'postview.php' script not properly sanitizing user-supplied input to the 'ID' variable. This may allow an attacker to inject or manipulate SQL queries in the back-end database.
|
2008-03-25
|
Clever Copy postview.php ID Parameter SQL Injection
|
|
44729
Description:
(Description Provided by CVE) : The server in Blackboard Academic Suite 7.x stores MD5 password hashes that are provided directly by clients, which makes it easier for remote attackers to access accounts via a modified client that skips the javascript/md5.js hash calculation, and instead sends an arbitrary MD5 string.
|
2008-03-25
|
Blackboard Academic Suite Crafted MD5 String Remote Authentication Bypass
|
|
43692
Description:
(Description Provided by CVE) : Stack-based buffer overflow in the DoLBURPRequest function in libnldap in ndsd in Novell eDirectory 8.7.3.9 and earlier, and 8.8.1 and earlier in the 8.8.x series, allows remote attackers to cause a denial of service (daemon crash or CPU consumption) or execute arbitrary code via a long delRequest LDAP Extended Request message, probably involving a long Distinguished Name (DN) field.
|
2008-03-24
|
Novell eDirectory LDAP Extended Request Message Processing DoLBURPRequest Overflow
|
|
43690
Description:
(Description Provided by CVE) : The SOAP interface to the eMBox module in Novell eDirectory 8.7.3.9 and earlier, and 8.8.x before 8.8.2, relies on client-side authentication, which allows remote attackers to bypass authentication via requests for /SOAP URIs, and cause a denial of service (daemon shutdown) or read arbitrary files. NOTE: it was later reported that 8.7.3.10 (aka 8.7.3 SP10) is also affected.
|
2008-03-24
|
Novell eDirectory eMBox Utility Unauthenticated Local File Access
|
|
43613
Description:
Unknown / Incomplete
|
2008-03-24
|
Undernet ircu s_user.c send_user_mode Function Remote DoS
|
|
43614
Description:
(Description Provided by CVE) : The send_user_mode function in s_user.c in (1) Undernet ircu 2.10.12.12 and earlier, (2) snircd 1.3.4 and earlier, and unspecified other ircu derivatives allows remote attackers to cause a denial of service (daemon crash) via a malformed MODE command.
|
2008-03-24
|
Undernet snircd s_user.c send_user_mode Function Remote DoS
|
|
43722
Description:
(Description Provided by CVE) : Directory traversal vulnerability in pb_inc/admincenter/index.php in PowerScripts PowerBook 1.21 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the page parameter. NOTE: in some environments, this can be leveraged for remote file inclusion by using a UNC share pathname or an ftp, ftps, or ssh2.sftp URL.
|
2008-03-24
|
PowerBook pb_inc/admincenter/index.php page Parameter Traversal Local File Inclusion
|
|
43918
Description:
(Description Provided by CVE) : Multiple directory traversal vulnerabilities in PowerPHPBoard 1.00b allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the (1) settings[footer] parameter to footer.inc.php and the (2) settings[header] parameter to header.inc.php.
|
2008-03-24
|
PowerPHPBoard footer.inc.php settings[footer] Parameter Traversal Local File Inclusion
|
|
43919
Description:
(Description Provided by CVE) : Multiple directory traversal vulnerabilities in PowerPHPBoard 1.00b allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the (1) settings[footer] parameter to footer.inc.php and the (2) settings[header] parameter to header.inc.php.
|
2008-03-24
|
PowerPHPBoard header.inc.php settings[header] Parameter Traversal Local File Inclusion
|
|
44578
Description:
(Description Provided by CVE) : VLC before 0.8.6f allow remote attackers to cause a denial of service (crash) via a crafted Cinepak file that triggers an out-of-bounds array access and memory corruption.
|
2008-03-24
|
VLC Crafted Cinepak File Memory Corruption DoS
|
|
48876
Description:
(Description Provided by CVE) : The password_checker function in config/multiconfig.py in MoinMoin 1.6.1 uses the cracklib and python-crack features even though they are not thread-safe, which allows remote attackers to cause a denial of service (segmentation fault and crash) via unknown vectors.
|
2008-03-24
|
MoinMoin config/multiconfig.py password_checker Function DoS
|
|
48877
Description:
(Description Provided by CVE) : The rst parser (parser/text_rst.py) in MoinMoin 1.6.1 does not check the ACL of an included page, which allows attackers to read unauthorized include files via unknown vectors.
|
2008-03-24
|
MoinMoin rst Parser Include Directive Included Page ACL Unspecified Weakness
|
|
43665
Description:
(Description Provided by CVE) : Directory traversal vulnerability in admin/admin_xs.php in eXtreme Styles module (XS-Mod) 2.3.1 and 2.4.0 for phpBB allows remote attackers to include and execute arbitrary files via a .. (dot dot) in the phpEx parameter. NOTE: some of these details are obtained from third party information.
|
2008-03-24
|
eXtreme Styles Module for phpBB admin/admin_xs.php phpEx Parameter Traversal Local File Inclusion
|
|
43688
Description:
Photo Cart contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the 'amessage' variable upon submission to the 'index.php' script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2008-03-24
|
Photo Cart index.php amessage Parameter XSS
|
|
43744
Description:
(Description Provided by CVE) : Directory traversal vulnerability in cgi-bin/his-webshop.pl in HIS Webshop 2.50 allows remote attackers to read arbitrary files via a .. (dot dot) in the t parameter.
|
2008-03-24
|
HIS-Webshop cgi-bin/his-webshop.pl t Parameter Traversal Arbitrary File Access
|
|
44602
Description:
(Description Provided by CVE) : Linksys SPA-2102 Phone Adapter 3.3.6 allows remote attackers to cause a denial of service (crash) via a long ping packet ("ping of death"). NOTE: the severity of this issue has been disputed since there are limited attack scenarios.
|
2008-03-24
|
Cisco Linksys SPA2102 Phone Adapter Crafted Ping Packet DoS
|
|
44669
Description:
(Description Provided by CVE) : Absolute path traversal vulnerability in SugarCRM Sugar Community Edition 4.5.1 and 5.0.0 allows remote attackers to read arbitrary files via a full path in the URL parameter to modules/Feeds/Feed.php, which places the contents into a related cache file in the .cache/feeds directory.
|
2008-03-24
|
SugarCRM RSS Module cache/feeds Directory Traversal Remote Information Disclosure
|
|
51115
Description:
Unknown / Incomplete
|
2008-03-24
|
Hamachi VPN Client Local Password Disclosure
|
|
53023
Description:
Quick Classifieds contains a flaw that may allow a remote attacker to execute arbitrary commands or code. The issue is due to the 'index.php3' script not properly sanitizing user input supplied to the 'DOCUMENT_ROOT' parameter. This may allow an attacker to include a file from a third-party remote host that contains commands or code that will be executed by the vulnerable script with the same privileges as the web server.
|
2008-03-24
|
Quick Classifieds index.php3 DOCUMENT_ROOT Parameter Remote File Inclusion
|
|
53024
Description:
Quick Classifieds contains a flaw that may allow a remote attacker to execute arbitrary commands or code. The issue is due to the 'locate.php3' script not properly sanitizing user input supplied to the 'DOCUMENT_ROOT' parameter. This may allow an attacker to include a file from a third-party remote host that contains commands or code that will be executed by the vulnerable script with the same privileges as the web server.
|
2008-03-24
|
Quick Classifieds locate.php3 DOCUMENT_ROOT Parameter Remote File Inclusion
|
|
53025
Description:
Quick Classifieds contains a flaw that may allow a remote attacker to execute arbitrary commands or code. The issue is due to the 'search_results.php' script not properly sanitizing user input supplied to the 'DOCUMENT_ROOT' parameter. This may allow an attacker to include a file from a third-party remote host that contains commands or code that will be executed by the vulnerable script with the same privileges as the web server.
|
2008-03-24
|
Quick Classifieds search_results.php3 DOCUMENT_ROOT Parameter Remote File Inclusion
|
|
53026
Description:
Quick Classifieds contains a flaw that may allow a remote attacker to execute arbitrary commands or code. The issue is due to the 'classifieds/index.php3' script not properly sanitizing user input supplied to the 'DOCUMENT_ROOT' parameter. This may allow an attacker to include a file from a third-party remote host that contains commands or code that will be executed by the vulnerable script with the same privileges as the web server.
|
2008-03-24
|
Quick Classifieds classifieds/index.php3 DOCUMENT_ROOT Parameter Remote File Inclusion
|
|
53027
Description:
Quick Classifieds contains a flaw that may allow a remote attacker to execute arbitrary commands or code. The issue is due to the 'classifieds/view.php3' script not properly sanitizing user input supplied to the 'DOCUMENT_ROOT' parameter. This may allow an attacker to include a file from a third-party remote host that contains commands or code that will be executed by the vulnerable script with the same privileges as the web server.
|
2008-03-24
|
Quick Classifieds classifieds/view.php3 DOCUMENT_ROOT Parameter Remote File Inclusion
|
|
53028
Description:
Quick Classifieds contains a flaw that may allow a remote attacker to execute arbitrary commands or code. The issue is due to the 'controlcenter/index.php3' script not properly sanitizing user input supplied to the 'DOCUMENT_ROOT' parameter. This may allow an attacker to include a file from a third-party remote host that contains commands or code that will be executed by the vulnerable script with the same privileges as the web server.
|
2008-03-24
|
Quick Classifieds controlcenter/index.php3 DOCUMENT_ROOT Parameter Remote File Inclusion
|
|
53029
Description:
Quick Classifieds contains a flaw that may allow a remote attacker to execute arbitrary commands or code. The issue is due to the 'controlcenter/manager.php3' script not properly sanitizing user input supplied to the 'DOCUMENT_ROOT' parameter. This may allow an attacker to include a file from a third-party remote host that contains commands or code that will be executed by the vulnerable script with the same privileges as the web server.
|
2008-03-24
|
Quick Classifieds controlcenter/manager.php3 DOCUMENT_ROOT Parameter Remote File Inclusion
|
|
53030
Description:
Quick Classifieds contains a flaw that may allow a remote attacker to execute arbitrary commands or code. The issue is due to the 'controlcenter/pass.php3' script not properly sanitizing user input supplied to the 'DOCUMENT_ROOT' parameter. This may allow an attacker to include a file from a third-party remote host that contains commands or code that will be executed by the vulnerable script with the same privileges as the web server.
|
2008-03-24
|
Quick Classifieds controlcenter/pass.php3 DOCUMENT_ROOT Parameter Remote File Inclusion
|
|
53031
Description:
Quick Classifieds contains a flaw that may allow a remote attacker to execute arbitrary commands or code. The issue is due to the 'controlcenter/remember.php3' script not properly sanitizing user input supplied to the 'DOCUMENT_ROOT' parameter. This may allow an attacker to include a file from a third-party remote host that contains commands or code that will be executed by the vulnerable script with the same privileges as the web server.
|
2008-03-24
|
Quick Classifieds controlcenter/remember.php3 DOCUMENT_ROOT Parameter Remote File Inclusion
|
|
53032
Description:
Quick Classifieds contains a flaw that may allow a remote attacker to execute arbitrary commands or code. The issue is due to the 'controlcenter/sign-up.php3' script not properly sanitizing user input supplied to the 'DOCUMENT_ROOT' parameter. This may allow an attacker to include a file from a third-party remote host that contains commands or code that will be executed by the vulnerable script with the same privileges as the web server.
|
2008-03-24
|
Quick Classifieds controlcenter/sign-up.php3 DOCUMENT_ROOT Parameter Remote File Inclusion
|