| OSVDB ID | Disclosure Date | Title |
|
44855
Description:
(Description Provided by CVE) : Multiple PHP remote file inclusion vulnerabilities Harris Yusuf Arifin Harris Wap Chat 1.0, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the sysFileDir parameter to (1) eng.writeMsg.php, (2) eng.adCreate.php, (3) eng.adCreateSave.php, (4) eng.adDispByTypeOptions.php, (5) eng.createRoom.php, (6) eng.forward.php, (7) eng.pageLogout.php, (8) eng.resultMember.php, (9) eng.roomDeleteConfirm.php, (10) eng.saveNewRoom.php, and (11) eng.searchMember.php in src/.
|
2008-04-30
|
Harris Wap Chat eng.writeMsg.php sysFileDir Variable Remote File Inclusion
|
|
44856
Description:
(Description Provided by CVE) : Multiple PHP remote file inclusion vulnerabilities Harris Yusuf Arifin Harris Wap Chat 1.0, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the sysFileDir parameter to (1) eng.writeMsg.php, (2) eng.adCreate.php, (3) eng.adCreateSave.php, (4) eng.adDispByTypeOptions.php, (5) eng.createRoom.php, (6) eng.forward.php, (7) eng.pageLogout.php, (8) eng.resultMember.php, (9) eng.roomDeleteConfirm.php, (10) eng.saveNewRoom.php, and (11) eng.searchMember.php in src/.
|
2008-04-30
|
Harris Wap Chat eng.adCreate.php sysFileDir Variable Remote File Inclusion
|
|
44857
Description:
(Description Provided by CVE) : Multiple PHP remote file inclusion vulnerabilities Harris Yusuf Arifin Harris Wap Chat 1.0, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the sysFileDir parameter to (1) eng.writeMsg.php, (2) eng.adCreate.php, (3) eng.adCreateSave.php, (4) eng.adDispByTypeOptions.php, (5) eng.createRoom.php, (6) eng.forward.php, (7) eng.pageLogout.php, (8) eng.resultMember.php, (9) eng.roomDeleteConfirm.php, (10) eng.saveNewRoom.php, and (11) eng.searchMember.php in src/.
|
2008-04-30
|
Harris Wap Chat eng.adCreateSave.php sysFileDir Variable Remote File Inclusion
|
|
44858
Description:
(Description Provided by CVE) : Multiple PHP remote file inclusion vulnerabilities Harris Yusuf Arifin Harris Wap Chat 1.0, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the sysFileDir parameter to (1) eng.writeMsg.php, (2) eng.adCreate.php, (3) eng.adCreateSave.php, (4) eng.adDispByTypeOptions.php, (5) eng.createRoom.php, (6) eng.forward.php, (7) eng.pageLogout.php, (8) eng.resultMember.php, (9) eng.roomDeleteConfirm.php, (10) eng.saveNewRoom.php, and (11) eng.searchMember.php in src/.
|
2008-04-30
|
Harris Wap Chat eng.adDispByTypeOptions.php sysFileDir Variable Remote File Inclusion
|
|
44859
Description:
(Description Provided by CVE) : Multiple PHP remote file inclusion vulnerabilities Harris Yusuf Arifin Harris Wap Chat 1.0, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the sysFileDir parameter to (1) eng.writeMsg.php, (2) eng.adCreate.php, (3) eng.adCreateSave.php, (4) eng.adDispByTypeOptions.php, (5) eng.createRoom.php, (6) eng.forward.php, (7) eng.pageLogout.php, (8) eng.resultMember.php, (9) eng.roomDeleteConfirm.php, (10) eng.saveNewRoom.php, and (11) eng.searchMember.php in src/.
|
2008-04-30
|
Harris Wap Chat eng.createRoom.php sysFileDir Variable Remote File Inclusion
|
|
44860
Description:
(Description Provided by CVE) : Multiple PHP remote file inclusion vulnerabilities Harris Yusuf Arifin Harris Wap Chat 1.0, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the sysFileDir parameter to (1) eng.writeMsg.php, (2) eng.adCreate.php, (3) eng.adCreateSave.php, (4) eng.adDispByTypeOptions.php, (5) eng.createRoom.php, (6) eng.forward.php, (7) eng.pageLogout.php, (8) eng.resultMember.php, (9) eng.roomDeleteConfirm.php, (10) eng.saveNewRoom.php, and (11) eng.searchMember.php in src/.
|
2008-04-30
|
Harris Wap Chat eng.forward.php sysFileDir Variable Remote File Inclusion
|
|
44861
Description:
(Description Provided by CVE) : Multiple PHP remote file inclusion vulnerabilities Harris Yusuf Arifin Harris Wap Chat 1.0, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the sysFileDir parameter to (1) eng.writeMsg.php, (2) eng.adCreate.php, (3) eng.adCreateSave.php, (4) eng.adDispByTypeOptions.php, (5) eng.createRoom.php, (6) eng.forward.php, (7) eng.pageLogout.php, (8) eng.resultMember.php, (9) eng.roomDeleteConfirm.php, (10) eng.saveNewRoom.php, and (11) eng.searchMember.php in src/.
|
2008-04-30
|
Harris Wap Chat eng.pageLogout.php sysFileDir Variable Remote File Inclusion
|
|
44862
Description:
(Description Provided by CVE) : Multiple PHP remote file inclusion vulnerabilities Harris Yusuf Arifin Harris Wap Chat 1.0, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the sysFileDir parameter to (1) eng.writeMsg.php, (2) eng.adCreate.php, (3) eng.adCreateSave.php, (4) eng.adDispByTypeOptions.php, (5) eng.createRoom.php, (6) eng.forward.php, (7) eng.pageLogout.php, (8) eng.resultMember.php, (9) eng.roomDeleteConfirm.php, (10) eng.saveNewRoom.php, and (11) eng.searchMember.php in src/.
|
2008-04-30
|
Harris Wap Chat eng.resultMember.php sysFileDir Variable Remote File Inclusion
|
|
44863
Description:
(Description Provided by CVE) : Multiple PHP remote file inclusion vulnerabilities Harris Yusuf Arifin Harris Wap Chat 1.0, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the sysFileDir parameter to (1) eng.writeMsg.php, (2) eng.adCreate.php, (3) eng.adCreateSave.php, (4) eng.adDispByTypeOptions.php, (5) eng.createRoom.php, (6) eng.forward.php, (7) eng.pageLogout.php, (8) eng.resultMember.php, (9) eng.roomDeleteConfirm.php, (10) eng.saveNewRoom.php, and (11) eng.searchMember.php in src/.
|
2008-04-30
|
Harris Wap Chat eng.roomDeleteConfirm.php sysFileDir Variable Remote File Inclusion
|
|
44864
Description:
(Description Provided by CVE) : Multiple PHP remote file inclusion vulnerabilities Harris Yusuf Arifin Harris Wap Chat 1.0, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the sysFileDir parameter to (1) eng.writeMsg.php, (2) eng.adCreate.php, (3) eng.adCreateSave.php, (4) eng.adDispByTypeOptions.php, (5) eng.createRoom.php, (6) eng.forward.php, (7) eng.pageLogout.php, (8) eng.resultMember.php, (9) eng.roomDeleteConfirm.php, (10) eng.saveNewRoom.php, and (11) eng.searchMember.php in src/.
|
2008-04-30
|
Harris Wap Chat eng.saveNewRoom.php sysFileDir Variable Remote File Inclusion
|
|
44865
Description:
(Description Provided by CVE) : Multiple PHP remote file inclusion vulnerabilities Harris Yusuf Arifin Harris Wap Chat 1.0, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the sysFileDir parameter to (1) eng.writeMsg.php, (2) eng.adCreate.php, (3) eng.adCreateSave.php, (4) eng.adDispByTypeOptions.php, (5) eng.createRoom.php, (6) eng.forward.php, (7) eng.pageLogout.php, (8) eng.resultMember.php, (9) eng.roomDeleteConfirm.php, (10) eng.saveNewRoom.php, and (11) eng.searchMember.php in src/.
|
2008-04-30
|
Harris Wap Chat eng.searchMember.php sysFileDir Variable Remote File Inclusion
|
|
44881
Description:
Unknown / Incomplete
|
2008-04-30
|
Nortel Multimedia Communication Server PC Client Overflow Remote DoS
|
|
44882
Description:
(Description Provided by CVE) : The Akamai Download Manager (aka DLM or dlmanager) ActiveX control (DownloadManagerV2.ocx) before 2.2.3.5 allows remote attackers to force the download and execution of arbitrary code via unspecified "undocumented object parameters."
|
2008-04-30
|
Akamai Download Manager ActiveX (DownloadManagerV2.ocx) Undocumented Object Parameters Arbitrary Code Execution
|
|
44885
Description:
Unknown / Incomplete
|
2008-04-30
|
SNMPc Network Manager SNMP TRAP Crafted UDP Packet Handling Overflow
|
|
44886
Description:
Unknown / Incomplete
|
2008-04-30
|
Project-Based Calendaring System src/yopy_sync.php filename Variable Traversal Local File Access
|
|
44887
Description:
Unknown / Incomplete
|
2008-04-30
|
Project-Based Calendaring System plugins/system-logger/print_logs.php filename Variable Traversal Local File Access
|
|
45082
Description:
Unknown / Incomplete
|
2008-04-29
|
mrxvt X11 :0 Default Display Local Privilege Escalation
|
|
44927
Description:
(Description Provided by CVE) : The bdx_ioctl_priv function in the tehuti driver (tehuti.c) in Linux kernel 2.6.x before 2.6.25 does not properly check certain information related to register size, which has unspecified impact and local attack vectors, probably related to reading or writing kernel memory.
|
2008-04-29
|
Linux Kernel Tehuti Driver (tehuti.c) bdx_ioctl_priv Function Unspecified Local Issue
|
|
45084
Description:
Unknown / Incomplete
|
2008-04-29
|
wterm X11 :0 Default Display Local Privilege Escalation
|
|
45083
Description:
Unknown / Incomplete
|
2008-04-29
|
rxvt-unicode X11 :0 Default Display Local Privilege Escalation
|
|
45081
Description:
Unknown / Incomplete
|
2008-04-29
|
aterm X11 :0 Default Display Local Privilege Escalation
|
|
44668
Description:
(Description Provided by CVE) : Cross-site scripting (XSS) vulnerability in bb_admin.php in miniBB 2.2a allows remote attackers to inject arbitrary web script or HTML via the whatus parameter in a searchusers2 action.
|
2008-04-29
|
miniBB bb_admin.php whatus Variable XSS
|
|
44830
Description:
(Description Provided by CVE) : Unspecified vulnerability in Plain Black WebGUI 7.4.34 has unknown impact and attack vectors related to "data form list view."
|
2008-04-29
|
WebGUI Data Form List View Unspecified Security Issue
|
|
44844
Description:
(Description Provided by CVE) : Cross-site scripting (XSS) vulnerability in index.php in Softpedia SiteXS CMS 0.1.1 Pre-Alpha allows remote attackers to inject arbitrary web script or HTML via the user parameter.
|
2008-04-29
|
SiteXS CMS index.php user Variable XSS
|
|
44924
Description:
(Description Provided by CVE) : Stack-based buffer overflow in the HTTP::getAuthUserPass function (core/common/http.cpp) in Peercast 0.1218 and gnome-peercast allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a Basic Authentication string with a long (1) username or (2) password.
|
2008-04-29
|
PeerCast HTTP::getAuthUserPass() Function Basic Authentication String Remote Overflow DoS
|
|
44942
Description:
(Description Provided by CVE) : Unspecified vulnerability in Juniper JUNOS 7.3 through 8.4 allows remote attackers to cause a denial of service (crash) via malformed BGP packets, possibly BGP UPDATE packets that trigger session flapping.
|
2008-04-28
|
Hitachi GR Series Malformed BGP Update Message Remote DoS
|
|
44957
Description:
Unknown / Incomplete
|
2008-04-28
|
IBM WebSphere Application Server (WAS) Java Plugin Untrusted Applet Privilege Escalation
|
|
44953
Description:
Unknown / Incomplete
|
2008-04-28
|
GraphicsMagick Insecure File Extension Handling Program Invocation
|
|
44681
Description:
(Description Provided by CVE) : ldm in Linux Terminal Server Project (LTSP) 0.99 and 2 passes the -ac option to the X server on each LTSP client, which allows remote attackers to connect to this server via TCP port 6006 (aka display :6).
|
2008-04-28
|
ldm X11 Forwarding LTSP Client Connection Restriction Bypass
|
|
44608
Description:
(Description Provided by CVE) : VicFTPS 5.0 allows remote attackers to cause a denial of service (crash) via a crafted LIST command, which triggers a NULL pointer dereference. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
|
2008-04-28
|
VicFTPS Crafted LIST Command NULL Dereference Remote DoS
|
|
44611
Description:
(Description Provided by CVE) : Cross-site scripting (XSS) vulnerability in installControl.php3 in F5 FirePass 4100 SSL VPN 5.4.2-5.5.2 and 6.0-6.2 allows remote attackers to inject arbitrary web script or HTML via the query string. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
|
2008-04-28
|
F5 FirePass 4100 SSL VPN installControl.php3 XSS
|
|
44612
Description:
(Description Provided by CVE) : The FTP service in Acritum Femitter Server 1.03 allows remote attackers to cause a denial of service (crash) by sending multiple crafted RETR commands. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
|
2008-04-28
|
Femitter Server FTP Server Crafted RETR Command Remote DoS
|
|
44614
Description:
Unknown / Incomplete
|
2008-04-28
|
MegaBBS send-private-message.asp toid Variable XSS
|
|
44622
Description:
(Description Provided by CVE) : The cookie authentication method in WordPress 2.5 relies on a hash of a concatenated string containing USERNAME and EXPIRY_TIME, which allows remote attackers to forge cookies by registering a username that results in the same concatenated string, as demonstrated by registering usernames beginning with "admin" to obtain administrator privileges, aka a "cryptographic splicing" issue. NOTE: this vulnerability exists because of an incomplete fix for CVE-2007-6013.
|
2008-04-28
|
WordPress Crafted Cookie Remote Authentication Bypass
|
|
44615
Description:
(Description Provided by CVE) : Multiple SQL injection vulnerabilities in PD9 Software MegaBBS 2.2 allow remote attackers to execute arbitrary SQL commands via the (1) invisible and (2) timeoffset parameters to profile/controlpanel.asp and the (3) attachmentid parameter to forums/attach-file.asp.
|
2008-04-28
|
MegaBBS profile/controlpanel.asp Multiple Variable SQL Injection
|
|
44616
Description:
(Description Provided by CVE) : SQL injection vulnerability in wp-download_monitor/download.php in the Download Monitor 2.0.6 plugin for WordPress allows remote attackers to execute arbitrary SQL commands via the id parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
|
2008-04-28
|
Download Monitor Plugin for WordPress wp-download_monitor/download.php id Variable SQL Injection
|
|
44624
Description:
(Description Provided by CVE) : Sun Java System Directory Proxy Server 6.0, 6.1, and 6.2 classifies a connection using the "bind-dn" criteria, which can cause an incorrect application of policy and allows remote attackers to bypass intended access restrictions for the server.
|
2008-04-28
|
Sun Java System Directory Server bind-dn Remote Privilege Escalation
|
|
44621
Description:
(Description Provided by CVE) : Heap-based buffer overflow in Lhaplus before 1.57 allows remote attackers to execute arbitrary code via a long comment field in a ZOO archive.
|
2008-04-28
|
Lhaplus ZOO Archive Handling Remote Overflow
|
|
44623
Description:
(Description Provided by CVE) : Cross-site scripting (XSS) vulnerability in WordPress 2.5 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
|
2008-04-28
|
WordPress Unspecified XSS
|
|
44655
Description:
(Description Provided by CVE) : SQL injection vulnerability in directory.php in Prozilla Hosting Index, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the cat_id parameter in a list action.
|
2008-04-28
|
Prozilla Hosting Index directory.php cat_id Variable SQL Injection
|