| OSVDB ID | Disclosure Date | Title |
|
44247
Description:
(Description Provided by CVE) : Directory traversal vulnerability in the NeffyLauncher 1.0.5 ActiveX control (NeffyLauncher.dll) in CDNetworks Nefficient Download allows remote attackers to download arbitrary code onto a client system via a .. (dot dot) in the SkinPath parameter and a .zip URL in the HttpSkin parameter. NOTE: this can be leveraged for code execution by writing to a Startup folder.
|
2008-04-07
|
CDNetworks Nefficient Download NeffyLauncher ActiveX (NeffyLauncher.dll) SkinPath Property Traversal Arbitrary File Download
|
|
44252
Description:
There is a stack overflow in the vcst_eu.dll FileTransfer Module (1.0.0.5) ActiveX control in the Tumbleweed SecureTransport suite. By sending an overly long string to the TransferFile() 'remotefile' function, an attacker may be able to execute arbitrary code.
|
2008-04-07
|
Tumbleweed SecureTransport FileTransfer ActiveX TransferFile() Method remoteFile Variable Overflow
|
|
44384
Description:
Dragoon contains a flaw that may allow a remote attacker to execute arbitrary commands or code. The issue is due to the 'includes/header.inc.php' script not properly sanitizing user input supplied to the 'root' parameter. This may allow an attacker to include a file from a third-party remote host that contains commands or code that will be executed by the vulnerable script with the same privileges as the web server.
|
2008-04-07
|
Dragoon includes/header.inc.php root Parameter Remote File Inclusion
|
|
44411
Description:
(Description Provided by CVE) : SQL injection vulnerability in ladder.php in My Gaming Ladder 7.5 and earlier allows remote attackers to execute arbitrary SQL commands via the ladderid parameter.
|
2008-04-07
|
My Gaming Ladder ladder.php ladderid Parameter SQL Injection
|
|
44426
Description:
(Description Provided by CVE) : SQL injection vulnerability in index.php in 724Networks 724CMS 4.01 and earlier allows remote attackers to execute arbitrary SQL commands via the ID parameter.
|
2008-04-07
|
724CMS index.php ID Parameter SQL Injection
|
|
44437
Description:
(Description Provided by CVE) : phpdemo/viewsource.php in Advanced Software Engineering ChartDirector 4.1 allows remote attackers to read sensitive files via the file parameter.
|
2008-04-07
|
ChartDirector phpdemo/viewsource.php file Variable Remote File Access
|
|
44438
Description:
(Description Provided by CVE) : Multiple cross-site request forgery (CSRF) vulnerabilities in Nuke ET 3.2 and 3.4 allow remote attackers to perform actions as administrators, as demonstrated by inserting an XSS sequence into a document.
|
2008-04-07
|
Nuke ET Privilege Escalation CSRF
|
|
44460
Description:
(Description Provided by CVE) : The NeffyLauncher 1.0.5 ActiveX control (NeffyLauncher.dll) in CDNetworks Nefficient Download uses weak cryptography for a KeyCode that blocks unauthorized use of the control, which allows remote attackers to bypass this protection mechanism by calculating the required KeyCode. NOTE: this can be used by arbitrary web sites to host exploit code that targets this control.
|
2008-04-07
|
CDNetworks Nefficient Download NeffyLauncher ActiveX (NeffyLauncher.dll) KeyCode Cryptography Weakness
|
|
49402
Description:
(Description Provided by CVE) : SQL injection vulnerability in member.php in Oxygen Bulletin Board 1.1.3 allows remote attackers to execute arbitrary SQL commands via the member parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
|
2008-04-07
|
Oxygen Bulletin Board member.php member Parameter SQL Injection
|
|
50076
Description:
(Description Provided by CVE) : Multiple stack-based buffer overflows in ovalarmsrv in HP OpenView Network Node Manager (OV NNM) 7.51, and possibly 7.01, 7.50, and 7.53, allow remote attackers to execute arbitrary code via a long (1) REQUEST_SEV_CHANGE (aka number 47), (2) REQUEST_SAVE_STATE (aka number 61), or (3) REQUEST_RESTORE_STATE (aka number 62) request to TCP port 2954.
|
2008-04-07
|
HP OpenView Network Node Manager (OV NNM) ovalarmsrv Multiple Remote Overflows
|
|
52107
Description:
(Description Provided by CVE) : Cross-site scripting (XSS) vulnerability in seeurl.php in Xavier Flahaut URLStreet 1.0 allows remote attackers to inject arbitrary web script or HTML via the (1) language, (2) order, and (3) filter parameters. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
|
2008-04-07
|
URLStreet seeurl.php Multiple Parameter XSS
|
|
52758
Description:
(Description Provided by CVE) : SQL injection vulnerability in the guestbook component (components/guestbook/guestbook.php) in Drake CMS 0.4.11 and earlier allows remote attackers to execute arbitrary SQL commands via the Via HTTP header (HTTP_VIA) to index.php.
|
2008-04-07
|
Drake CMS Guestbook Component index.php Via HTTP Header SQL Injection
|
|
91599
Description:
By default, Sun Embedded Lights Out Manager (ELOM) installs with default admin credentials (username/password combination). The 'root' account has a password of 'changeme', which is publicly known and documented. This allows remote attackers to trivially access the program or system and gain privileged access.
|
2008-04-07
|
Sun Embedded Lights Out Manager (ELOM) Default Admin Credentials
|
|
44277
Description:
(Description Provided by CVE) : Prozilla Topsites 1.0 allows remote attackers to perform administrative actions via a direct request to (1) addu.php, (2) editu.php, and (3) uidx.php in siteadmin/.
|
2008-04-06
|
Prozilla Topsites Admin Pages Direct Request Authentication Bypass
|
|
44140
Description:
Site Sift Listings contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the 'detail.php' script not properly sanitizing user-supplied input to the 'id' variable. This may allow an attacker to inject or manipulate SQL queries in the back-end database.
|
2008-04-06
|
Site Sift Listings detail.php id Parameter SQL Injection
|
|
44143
Description:
libfishsound contains an array-indexing error condition in the Speex decoder component. The issue is triggered as user-supplied input is not properly validated when handling header structures. With a specially crafted header structure with a negative offset, a context-dependent attacker can cause data to be written to an arbitrary memory location, resulting in arbitrary code execution.
|
2008-04-06
|
libfishsound Speex Decoder Header Structure Handling Arbitrary Code Execution
|
|
44237
Description:
(Description Provided by CVE) : SQL injection vulnerability in view_reviews.php in Prozilla Cheat Script (aka Cheats) 2.0 allows remote attackers to execute arbitrary SQL commands via the id parameter.
|
2008-04-06
|
Prozilla Cheats view_reviews.php id Parameter SQL Injection
|
|
44409
Description:
(Description Provided by CVE) : SQL injection vulnerability in forum.php in Prozilla Forum allows remote attackers to execute arbitrary SQL commands via the forum parameter.
|
2008-04-06
|
Prozilla Forum forum.php forum Parameter SQL Injection
|
|
44432
Description:
(Description Provided by CVE) : SQL injection vulnerability in Blog Pixel Motion (aka Blog PixelMotion) allows remote attackers to execute arbitrary SQL commands via the categorie parameter to index.php, possibly related to include/requetesIndex.php.
|
2008-04-06
|
Blog Pixel Motion index.php categorie Parameter SQL Injection
|
|
44433
Description:
(Description Provided by CVE) : admin/sauvBase.php in Blog Pixel Motion (aka Blog PixelMotion) does not require authentication, which allows remote attackers to trigger a database backup dump, and obtain the resulting blogPM.sql file that contains sensitive information.
|
2008-04-06
|
Blog Pixel Motion admin/sauvBase.php Database Backup Remote Information Disclosure
|
|
44436
Description:
(Description Provided by CVE) : delete.php in Prozilla Top 100 1.2 allows remote authenticated users to delete statistics and accounts of arbitrary users via a modified s parameter.
|
2008-04-06
|
Prozilla Top 100 delete.php s Variable Remote User Account Deletion
|
|
44440
Description:
(Description Provided by CVE) : Stack-based buffer overflow in the msx_readnode function in libmosix.c in openmosix-tools (aka userspace-tools) in openMosix might allow local users to cause a denial of service (application crash) via a third-party program that calls this function with a long item argument. NOTE: the vendor does not provide any program that is capable of causing this overflow.
|
2008-04-06
|
openMosix openmosix-tools libmosix.c msx_readnode Function Local Overflow DoS
|
|
44689
Description:
(Description Provided by CVE) : admin/modif_config.php in Blog Pixel Motion (aka PixelMotion) does not require admin authentication, which allows remote authenticated users to upload arbitrary PHP scripts in a ZIP archive, which is written to templateZip/ and then automatically extracted under templates/ for execution via a direct request.
|
2008-04-06
|
Blog Pixel Motion admin/modif_config.php ZIP Archive Arbitrary PHP Script Upload
|
|
44692
Description:
(Description Provided by CVE) : Unspecified vulnerability in GNU m4 before 1.4.11 might allow context-dependent attackers to execute arbitrary code, related to improper handling of filenames specified with the -F option. NOTE: it is not clear when this issue crosses privilege boundaries.
|
2008-04-06
|
GNU m4 -F Parameter Filename Handling Unspecified Code Execution
|
|
52117
Description:
(Description Provided by CVE) : SQL injection vulnerability in pages.php in Custom Pages 1.0 plugin for MyBulletinBoard (MyBB) allows remote attackers to execute arbitrary SQL commands via the page parameter.
|
2008-04-06
|
Custom Pages Plugin for MyBulletinBoard (MyBB) pages.php pages Parameter SQL Injection
|
|
51227
Description:
(Description Provided by CVE) : _blogadata/include/init_pass2.php in Blogator-script 0.95 allows remote attackers to change the password for arbitrary users via a modified "a" parameter with a "%" wildcard symbol in the b parameter.
|
2008-04-05
|
Blogator-script init_pass2.php Arbitrary User Password Manipulation
|
|
44139
Description:
Links Directory contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the 'links.php' script not properly sanitizing user-supplied input to the 'cat_id' variable. This may allow an attacker to inject or manipulate SQL queries in the back-end database.
|
2008-04-05
|
Links Directory links.php cat_id Parameter SQL Injection
|
|
44147
Description:
Software Index Script contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the 'showcategory.php' script not properly sanitizing user-supplied input to the 'cid' variable. This may allow an attacker to inject or manipulate SQL queries in the back-end database.
|
2008-04-05
|
Software Index Script showcategory.php cid Parameter SQL Injection
|
|
44236
Description:
(Description Provided by CVE) : SQL injection vulnerability in directory.php in Prozilla Entertainers 1.1 and earlier allows remote attackers to execute arbitrary SQL commands via the cat parameter. NOTE: some of these details are obtained from third party information.
|
2008-04-05
|
Prozilla Entertainers directory.php cat Parameter SQL Injection
|
|
44428
Description:
VisualPic contains a flaw that may allow a remote attacker to execute arbitrary commands or code. The issue is due to the 'index.ph' script not properly sanitizing user input supplied to the '_CONFIG[files][functions_page]' parameter. This may allow an attacker to include a file from a third-party remote host that contains commands or code that will be executed by the vulnerable script with the same privileges as the web server.
|
2008-04-05
|
VisualPic index.php _CONFIG[files][functions_page] Parameter Remote File Inclusion
|
|
44475
Description:
(Description Provided by CVE) : The default configuration of SAP NetWeaver before 7.0 SP15 does not enable the "Always Use Secure HTML Editor" (aka Editor Security or Secure Editing) parameter, which allows remote attackers to conduct cross-site scripting (XSS) attacks by entering feedback for a file.
|
2008-04-05
|
SAP Netweaver Editor Security File Feedback XSS
|
|
52112
Description:
(Description Provided by CVE) : SQL injection vulnerability in CoBaLT 1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter to (1) urun.asp, (2) admin/bayi_listele.asp, (3) admin/urun_grup_listele.asp, and (4) admin/urun_listele.asp.
|
2008-04-05
|
CoBaLT urun.asp id Parameter SQL Injection
|
|
52113
Description:
(Description Provided by CVE) : SQL injection vulnerability in CoBaLT 1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter to (1) urun.asp, (2) admin/bayi_listele.asp, (3) admin/urun_grup_listele.asp, and (4) admin/urun_listele.asp.
|
2008-04-05
|
CoBaLT admin/bayi_listele.asp id Parameter SQL Injection
|
|
52114
Description:
(Description Provided by CVE) : SQL injection vulnerability in CoBaLT 1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter to (1) urun.asp, (2) admin/bayi_listele.asp, (3) admin/urun_grup_listele.asp, and (4) admin/urun_listele.asp.
|
2008-04-05
|
CoBaLT admin/urun_grup_listele.asp id Parameter SQL Injection
|
|
52115
Description:
(Description Provided by CVE) : SQL injection vulnerability in CoBaLT 1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter to (1) urun.asp, (2) admin/bayi_listele.asp, (3) admin/urun_grup_listele.asp, and (4) admin/urun_listele.asp.
|
2008-04-05
|
CoBaLT admin/urun_listele.asp id Parameter SQL Injection
|
|
58794
Description:
Unknown / Incomplete
|
2008-04-05
|
Apache Roller Admin Protocol (RAP) Malformed Header Authentication Bypass
|
|
44218
Description:
(Description Provided by CVE) : The PPTP VPN service in Watchguard Firebox before 10, when performing the MS-CHAPv2 authentication handshake, generates different error codes depending on whether the username is valid or invalid, which allows remote attackers to enumerate valid usernames.
|
2008-04-04
|
WatchGuard Firebox Products PPTP VPN Service Username Enumeration
|
|
48926
Description:
Unknown / Incomplete
|
2008-04-04
|
PhpGedView Indi/Fam List Event Privacy Setting Honor Weakness
|
|
46706
Description:
(Description Provided by CVE) : Untrusted search path vulnerability in (1) hvdisp and (2) rcvm in ReliantHA 1.1.4 in SCO UnixWare 7.1.4 allows local users to gain root privileges by modifying the RELIANT_PATH environment variable to point to a malicious bin/hvenv program.
|
2008-04-04
|
SCO UnixWare ReliantHA /usr/opt/reliant/bin/hvdisp Local Privilege Escalation
|
|
46707
Description:
(Description Provided by CVE) : Untrusted search path vulnerability in (1) hvdisp and (2) rcvm in ReliantHA 1.1.4 in SCO UnixWare 7.1.4 allows local users to gain root privileges by modifying the RELIANT_PATH environment variable to point to a malicious bin/hvenv program.
|
2008-04-04
|
SCO UnixWare ReliantHA /usr/opt/reliant/bin/rcvm Local Privilege Escalation
|