| OSVDB ID | Disclosure Date | Title |
|
51167
Description:
(Description Provided by CVE) : Multiple cross-site scripting (XSS) vulnerabilities in Gallarific Free Edition allow remote attackers to inject arbitrary web script or HTML via (1) the e-mail address, (2) a comment, which is not properly handled during moderation, and (3) the tag parameter to gallery/tags.php.
|
2008-04-15
|
Gallarific Comment Moderation XSS
|
|
51168
Description:
(Description Provided by CVE) : Multiple cross-site scripting (XSS) vulnerabilities in Gallarific Free Edition allow remote attackers to inject arbitrary web script or HTML via (1) the e-mail address, (2) a comment, which is not properly handled during moderation, and (3) the tag parameter to gallery/tags.php.
|
2008-04-15
|
Gallarific gallery/tags.php tag Parameter XSS
|
|
52934
Description:
Unknown / Incomplete
|
2008-04-15
|
OpenOffice.org (OOo) Document Styles Handling DoS
|
|
44421
Description:
(Description Provided by CVE) : db2dasrrm in the DB2 Administration Server (DAS) in IBM DB2 Universal Database 9.5 before Fix Pack 1, 9.1 before Fix Pack 4a, and 8 before FixPak 16 allows local users to overwrite arbitrary files via a symlink attack on files used for initialization.
|
2008-04-15
|
IBM DB2 Universal Database Administration Server (DAS) db2dasrrm Symlink Arbitrary File Overwrite
|
|
44420
Description:
(Description Provided by CVE) : Stack-based buffer overflow in db2dasrrm in the DB2 Administration Server (DAS) in IBM DB2 Universal Database 9.5 before Fix Pack 1, 9.1 before Fix Pack 4a, and 8 before FixPak 16 allows local users to execute arbitrary code via a long DASPROF environment variable.
|
2008-04-15
|
IBM DB2 Universal Database Administration Server (DAS) db2dasrrm DASPROF Environment Variable Local Overflow
|
|
44454
Description:
A remote overflow exists in BigAnt IM Server. The AntServer.exe process fails to use bounds checking resulting in a stack overflow. With a specially crafted request, an attacker can execute arbitrary code resulting in a loss of confidentiality, integrity, and/or availability.
|
2008-04-15
|
BigAnt Messenger IM Server AntServer Module (AntServer.exe) URI Handling Remote Overflow
|
|
50228
Description:
Unknown / Incomplete
|
2008-04-15
|
LinPHA metadata_editor.php SQL Injection
|
|
50227
Description:
(Description Provided by CVE) : Multiple cross-site scripting (XSS) vulnerabilities in LinPHA before 1.3.4 might allow remote attackers to inject arbitrary web script or HTML via (1) new_images.php, (2) login.php, and unspecified vectors.
|
2008-04-15
|
LinPHA Multiple Unspecified XSS
|
|
44441
Description:
Unknown / Incomplete
|
2008-04-15
|
DotClear ecrire/images.php File Upload Arbitrary PHP Code Execution
|
|
44465
Description:
(Description Provided by CVE) : Multiple unspecified vulnerabilities in phpBB before 3.0.1 have unknown impact and attack vectors, related to "two minor security-related bugs."
|
2008-04-15
|
phpBB Memberlist Functionality Information Disclosure
|
|
44466
Description:
(Description Provided by CVE) : Multiple unspecified vulnerabilities in phpBB before 3.0.1 have unknown impact and attack vectors, related to "two minor security-related bugs."
|
2008-04-15
|
phpBB PM Attachment Functionality Unspecified Arbitrary User PM Access
|
|
44520
Description:
(Description Provided by CVE) : ClamAV before 0.93 allows remote attackers to cause a denial of service (CPU consumption) via a crafted ARJ archive, as demonstrated by the PROTOS GENOME test suite for Archive Formats.
|
2008-04-15
|
ClamAV ARJ Archive Handling Unspecified Resource Consumption DoS
|
|
48865
Description:
(Description Provided by CVE) : cookiecheck.php in CookieCheck 1.0 stores tmp/cc_sessions under the web root with insufficient access control, which allows remote attackers to obtain session data via a direct request related to the "default session save path."
|
2008-04-15
|
CookieCheck Default Session Save Path Unspecified Issue
|
|
44374
Description:
(Description Provided by CVE) : Nortel MG1000S, Signaling Server, and Call Server on the Communications Server 1000 (CS1K) 4.50.x contain multiple unspecified hard-coded accounts and passwords, which allows remote attackers to gain privileges.
|
2008-04-15
|
Nortel Networks Communication Server 1000 Multiple Default Hardcoded Accounts
|
|
44373
Description:
WORK system e-commerce contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate "day", "month", and "year" variables upon submission to the module/main.php script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2008-04-15
|
WORK system e-commerce module/main.php Multiple Parameter XSS
|
|
44424
Description:
(Description Provided by CVE) : lib/prefs.tcl in Cecilia 2.0.5 allows local users to overwrite arbitrary files via a symlink attack on the csvers temporary file.
|
2008-04-15
|
Cecilia lib/prefs.tcl /tmp/csvers Symlink Arbitrary File Overwrite
|
|
44402
Description:
A local overflow exists in DivX Player. The video player fails to check bounds on subtitle lines resulting in a stack-based overflow. With a specially crafted SRT file, an attacker can cause arbitrary code execution resulting in a loss of integrity.
|
2008-04-15
|
DivX Player Subtitle Parsing Crafted SRT File Handling Overflow
|
|
44401
Description:
LASERnet CMS contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the index.php script not properly sanitizing user-supplied input to the 'new' variable and that variable is assigned to the 'id' variable. This may allow an attacker to inject or manipulate SQL queries in the back-end database.
|
2008-04-15
|
Lasernet CMS index.php new Parameter SQL Injection
|
|
44448
Description:
(Description Provided by CVE) : Integer overflow in the ws_getpostvars function in Firefly Media Server (formerly mt-daapd) 0.2.4.1 (0.9~r1696-1.2 on Debian) allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via an HTTP POST request with a large Content-Length.
|
2008-04-15
|
Firefly Media Server ws_getpostvars Function Content-Length Header HTTP Request Handling Overflow
|
|
44453
Description:
W2B Online Banking contains a flaw that may allow a remote attacker to execute arbitrary commands or code. The issue is due to the 'index.php' script not properly sanitizing user input supplied to the 'ilang' parameter. This may allow an attacker to include a file from a third-party remote host that contains commands or code that will be executed by the vulnerable script with the same privileges as the web server.
|
2008-04-15
|
W2B Online Banking index.php ilang Parameter Remote File Inclusion
|
|
44541
Description:
(Description Provided by CVE) : SQL injection vulnerability in index.php in Classifieds Caffe allows remote attackers to execute arbitrary SQL commands via the cat_id parameter in an add action. NOTE: this issue might be site-specific.
|
2008-04-15
|
Classifieds Caffe index.php cat_id Parameter SQL Injection
|
|
44545
Description:
(Description Provided by CVE) : Multiple cross-site scripting (XSS) vulnerabilities in AMFPHP 1.2 allow remote attackers to inject arbitrary web script or HTML via the (1) class parameter to (a) methodTable.php, (b) code.php, and (c) details.php in browser/; and the (2) location parameter to browser/code.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
|
2008-04-15
|
AMFPHP browser/methodTable.php class Parameter XSS
|
|
44546
Description:
(Description Provided by CVE) : Multiple cross-site scripting (XSS) vulnerabilities in AMFPHP 1.2 allow remote attackers to inject arbitrary web script or HTML via the (1) class parameter to (a) methodTable.php, (b) code.php, and (c) details.php in browser/; and the (2) location parameter to browser/code.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
|
2008-04-15
|
AMFPHP browser/code.php Multiple Parameter XSS
|
|
44547
Description:
(Description Provided by CVE) : Multiple cross-site scripting (XSS) vulnerabilities in AMFPHP 1.2 allow remote attackers to inject arbitrary web script or HTML via the (1) class parameter to (a) methodTable.php, (b) code.php, and (c) details.php in browser/; and the (2) location parameter to browser/code.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
|
2008-04-15
|
AMFPHP browser/details class Parameter XSS
|
|
44682
Description:
(Description Provided by CVE) : Directory traversal vulnerability in WEBrick in Ruby 1.8.4 and earlier, 1.8.5 before 1.8.5-p231, 1.8.6 before 1.8.6-p230, 1.8.7 before 1.8.7-p22, and 1.9.0 before 1.9.0-2, when using NTFS or FAT filesystems, allows remote attackers to read arbitrary CGI files via a trailing (1) + (plus), (2) %2b (encoded plus), (3) . (dot), (4) %2e (encoded dot), or (5) %20 (encoded space) character in the URI, possibly related to the WEBrick::HTTPServlet::FileHandler and WEBrick::HTTPServer.new functionality and the :DocumentRoot option.
|
2008-04-15
|
WEBrick in Ruby URI Multiple Encoded Traversal Arbitrary File Access
|
|
44986
Description:
(Description Provided by CVE) : Multiple unspecified vulnerabilities in eGroupWare before 1.4.004 have unspecified attack vectors and "grave" impact when the web server has write access to a directory under the web document root.
|
2008-04-15
|
eGroupWare Web Server Write Access Unspecified "Grave" Issue
|
|
45515
Description:
(Description Provided by CVE) : SubSonic allows remote attackers to bypass pagesize limits and cause a denial of service (CPU consumption) via a pageindex (aka data page number) of -1.
|
2008-04-15
|
SubSonic Negative Pageindex Pagesize Limit Bypass Remote DoS
|
|
49565
Description:
Istant-Replay contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to 'read.php' not properly sanitizing user input supplied to the 'data' variable. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script.
|
2008-04-15
|
Istant-Replay read.php data Parameter Remote File Inclusion
|
|
51683
Description:
Unknown / Incomplete
|
2008-04-15
|
BosNews newsadmin.php Arbitrary Admin Account Creation
|
|
91098
Description:
IBM WebSphere Application Server (WAS) contains a flaw that may allow a remote denial of service. The issue is triggered during the handling of a GET for an esi:include JSP and waiting for the AppServer response. With a specially crafted request that contains duplicate request headers, a remote attacker can crash the server.
|
2008-04-15
|
IBM WebSphere Application Server (WAS) esi:include JSP GET Request Remote DoS
|
|
92723
Description:
Trashbin Plugin for WordPress contains a flaw that allows a remote cross-site scripting (XSS) attack. This flaw exists because the application does not validate the 'mtb_undelete' parameter upon submission to the mtb_trashbin/trashbin.php script. This may allow an attacker to create a specially crafted request that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2008-04-15
|
Trashbin Plugin for WordPress mtb_trashbin/trashbin.php mtb_undelete Parameter XSS
|
|
44380
Description:
(Description Provided by CVE) : Unspecified vulnerability in the "session limitation technique" in the FTP service on Nortel Communications Server 1000 (CS1K) 4.50.x, when running on VGMC or signaling nodes, allows remote attackers to cause a denial of service (resource exhaustion and failed updates) via unknown vectors that causes consumption of all available sessions.
|
2008-04-14
|
Nortel Networks Communication Server 1000 FTP Service Unspecified DoS
|
|
44379
Description:
(Description Provided by CVE) : Nortel UNIStim protocol, as used in Communication Server 1000 and other products, uses predictable sequence numbers, which allows remote attackers to hijack sessions via sniffing or brute force attacks.
|
2008-04-14
|
Nortel Networks UNIStim Client Sequence Number Disclosure Weakness
|
|
44377
Description:
(Description Provided by CVE) : Nortel Communication Server 1000 4.50.x allows remote attackers to obtain Web application structure via unknown vectors related to "web resources to phones and administrators."
|
2008-04-14
|
Nortel Networks Communication Server 1000 Web Resources Unspecified Information Disclosure
|
|
44375
Description:
(Description Provided by CVE) : Multiple unspecified vulnerabilities in Nortel Communication Server 1000 4.50.x allow remote attackers to execute arbitrary commands to gain privileges, obtain sensitive information, or cause a denial of service via unknown vectors.
|
2008-04-14
|
Nortel Networks Communication Server 1000 Multiple Unspecified Command Injection
|
|
46090
Description:
(Description Provided by CVE) : Off-by-one error in the ppscan function (preproc.c) in Netwide Assembler (NASM) 2.02 allows context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted file that triggers a stack-based buffer overflow.
|
2008-04-14
|
NASM preproc.c ppscan() Function ASM File Handling Overflow
|
|
50225
Description:
(Description Provided by CVE) : Multiple cross-site scripting (XSS) vulnerabilities in LinPHA before 1.3.4 might allow remote attackers to inject arbitrary web script or HTML via (1) new_images.php, (2) login.php, and unspecified vectors.
|
2008-04-14
|
LinPHA login.php XSS
|
|
50226
Description:
(Description Provided by CVE) : Multiple cross-site scripting (XSS) vulnerabilities in LinPHA before 1.3.4 might allow remote attackers to inject arbitrary web script or HTML via (1) new_images.php, (2) login.php, and unspecified vectors.
|
2008-04-14
|
LinPHA new_images.php XSS
|
|
44519
Description:
(Description Provided by CVE) : Heap-based buffer overflow in spin.c in libclamav in ClamAV 0.92.1 allows remote attackers to execute arbitrary code via a crafted PeSpin packed PE binary with a modified length value.
|
2008-04-14
|
ClamAV libclamav spin.c Crafted PeSpin Packed PE Binary Handling Overflow
|
|
44518
Description:
(Description Provided by CVE) : Directory traversal vulnerability in help.php in the eskuel module in KwsPHP 1.3.456, as available before 20080416, allows remote attackers to execute arbitrary commands via the action parameter. NOTE: some of these details are obtained from third party information.
|
2008-04-14
|
KwsPHP eskuel/help.php action Parameter Traversal Local File Inclusion
|