| OSVDB ID | Disclosure Date | Title |
|
46475
Description:
EXP Shop component for Joomla! contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the index.php script not properly sanitizing user-supplied input to the 'catid' variable. This may allow an attacker to inject or manipulate SQL queries in the back-end database.
|
2008-06-22
|
EXP Shop Component for Joomla! index.php catid Parameter SQL Injection
|
|
46482
Description:
RSS-aggregator contains a flaw that may allow a remote attacker to execute arbitrary commands or code. The issue is due to the 'display.php' script not properly sanitizing user input supplied to the 'path' parameter. This may allow an attacker to include a file from a third-party remote host that contains commands or code that will be executed by the vulnerable script with the same privileges as the web server.
|
2008-06-22
|
RSS-aggregator display.php path Parameter Remote File Inclusion
|
|
46480
Description:
(Description Provided by CVE) : Directory traversal vulnerability in includes/header.php in Hedgehog-CMS 1.21 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the c_temp_path parameter. NOTE: in some environments, this can be leveraged for remote file inclusion by using a UNC share pathname or an ftp, ftps, or ssh2.sftp URL.
|
2008-06-22
|
Hedgehog-CMS includes/header.php c_temp_path Parameter Traversal Local File Inclusion
|
|
46487
Description:
Unknown / Incomplete
|
2008-06-22
|
Call of Duty 4: Modern Warfare callvote map Command MAP Variable Remote Overflow
|
|
46476
Description:
(Description Provided by CVE) : SQL injection vulnerability in cgi-bin/igsuite in IGSuite 3.2.4 allows remote attackers to execute arbitrary SQL commands via the formid parameter.
|
2008-06-22
|
IGSuite cgi-bin/igsuite formid Parameter SQL Injection
|
|
46486
Description:
ODARS contains a flaw that may allow a remote attacker to execute arbitrary commands or code. The issue is due to the 'resource_categories_view.php' script not properly sanitizing user input supplied to the 'CLASSES_ROOT' parameter. This may allow an attacker to include a file from a third-party remote host that contains commands or code that will be executed by the vulnerable script with the same privileges as the web server.
|
2008-06-22
|
ODARS resource_categories_view.php CLASSES_ROOT Parameter Remote File Inclusion
|
|
46488
Description:
Unknown / Incomplete
|
2008-06-22
|
Call of Duty 4: Modern Warfare va() Function Command Handling Remote DoS
|
|
46533
Description:
(Description Provided by CVE) : World in Conflict (WIC) 1.008 and earlier allows remote attackers to cause a denial of service (access violation and crash) via a zero-byte data block to TCP port 48000, which triggers a NULL pointer dereference.
|
2008-06-22
|
World in Conflict Crafted Packet NULL Dereference Remote DoS
|
|
46797
Description:
(Description Provided by CVE) : sHibby sHop 2.2 and earlier stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request to Db/urun.mdb.
|
2008-06-22
|
sHibby sHop Db/urun.mdb Direct Request Database Disclosure
|
|
46819
Description:
(Description Provided by CVE) : SQL injection vulnerability in index.php in PageSquid CMS 0.3 Beta allows remote attackers to execute arbitrary SQL commands via the page parameter.
|
2008-06-22
|
PageSquid CMS index.php page Parameter SQL Injection
|
|
46828
Description:
(Description Provided by CVE) : Multiple directory traversal vulnerabilities in view/index.php in CMS Mini 0.2.2 allow remote attackers to read arbitrary local files via a .. (dot dot) in the (1) path and (2) p parameter.
|
2008-06-22
|
CMS Mini view/index.php Multiple Parameter Traversal Local File Inclusion
|
|
46864
Description:
HomePH Design contains a flaw that may allow a remote attacker to execute arbitrary commands or code. The issue is due to the 'admin/templates/template_thumbnail.php' script not properly sanitizing user input supplied to the 'thumb_template' parameter. This may allow an attacker to include a file from a third-party remote host that contains commands or code that will be executed by the vulnerable script with the same privileges as the web server.
|
2008-06-22
|
HomePH Design admin/templates/template_thumbnail.php thumb_template Parameter Remote File Inclusion
|
|
46866
Description:
(Description Provided by CVE) : Cross-site scripting (XSS) vulnerability in backend/umleitung.php in CMReams CMS 1.3.1.1 Beta 2 allows remote attackers to inject arbitrary web script or HTML via the lang[be_red_text] parameter.
|
2008-06-22
|
CMReams CMS backend/umleitung.php lang[be_red_text] Parameter XSS
|
|
46868
Description:
(Description Provided by CVE) : Directory traversal vulnerability in load_language.php in CMReams CMS 1.3.1.1 Beta 2, when register_globals is enabled, allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the page_language parameter.
|
2008-06-22
|
CMReams CMS load_language.php page_language Parameter Traversal Local File Inclusion
|
|
46869
Description:
(Description Provided by CVE) : Multiple PHP remote file inclusion vulnerabilities in phpDMCA 1.0.0 allow remote attackers to execute arbitrary PHP code via a URL in the ourlinux_root_path parameter to (1) adodb-errorpear.inc.php and (2) adodb-pear.inc.php in adodb/.
|
2008-06-22
|
phpDMCA adodb-errorpear.inc.php ourlinux_root_path Parameter Remote File Inclusion
|
|
46870
Description:
(Description Provided by CVE) : Multiple PHP remote file inclusion vulnerabilities in phpDMCA 1.0.0 allow remote attackers to execute arbitrary PHP code via a URL in the ourlinux_root_path parameter to (1) adodb-errorpear.inc.php and (2) adodb-pear.inc.php in adodb/.
|
2008-06-22
|
phpDMCA adodb-pear.inc.php ourlinux_root_path Parameter Remote File Inclusion
|
|
46891
Description:
(Description Provided by CVE) : Multiple directory traversal vulnerabilities in HomePH Design 2.10 RC2, when register_globals is enabled, allow remote attackers to include and execute arbitrary local files via directory traversal sequences in the (1) thumb_template parameter to (a) admin/templates/template_thumbnail.php, and the (2) language parameter to (b) account/account.php, (c) downloads/downloads.php, (d) forum/forum.php, (e) fotogalerie/delete.php, and (f) fotogalerie/fotogalerie.php in admin/features/.
|
2008-06-22
|
HomePH Design admin/templates/template_thumbnail.php thumb_template Parameter Traversal Local File Inclusion
|
|
46892
Description:
(Description Provided by CVE) : Multiple directory traversal vulnerabilities in HomePH Design 2.10 RC2, when register_globals is enabled, allow remote attackers to include and execute arbitrary local files via directory traversal sequences in the (1) thumb_template parameter to (a) admin/templates/template_thumbnail.php, and the (2) language parameter to (b) account/account.php, (c) downloads/downloads.php, (d) forum/forum.php, (e) fotogalerie/delete.php, and (f) fotogalerie/fotogalerie.php in admin/features/.
|
2008-06-22
|
HomePH Design account/account.php language Parameter Traversal Local File Inclusion
|
|
46893
Description:
(Description Provided by CVE) : Multiple directory traversal vulnerabilities in HomePH Design 2.10 RC2, when register_globals is enabled, allow remote attackers to include and execute arbitrary local files via directory traversal sequences in the (1) thumb_template parameter to (a) admin/templates/template_thumbnail.php, and the (2) language parameter to (b) account/account.php, (c) downloads/downloads.php, (d) forum/forum.php, (e) fotogalerie/delete.php, and (f) fotogalerie/fotogalerie.php in admin/features/.
|
2008-06-22
|
HomePH Design downloads/downloads.php language Parameter Traversal Local File Inclusion
|
|
46894
Description:
(Description Provided by CVE) : Multiple directory traversal vulnerabilities in HomePH Design 2.10 RC2, when register_globals is enabled, allow remote attackers to include and execute arbitrary local files via directory traversal sequences in the (1) thumb_template parameter to (a) admin/templates/template_thumbnail.php, and the (2) language parameter to (b) account/account.php, (c) downloads/downloads.php, (d) forum/forum.php, (e) fotogalerie/delete.php, and (f) fotogalerie/fotogalerie.php in admin/features/.
|
2008-06-22
|
HomePH Design forum/forum.php language Parameter Traversal Local File Inclusion
|
|
46895
Description:
(Description Provided by CVE) : Multiple directory traversal vulnerabilities in HomePH Design 2.10 RC2, when register_globals is enabled, allow remote attackers to include and execute arbitrary local files via directory traversal sequences in the (1) thumb_template parameter to (a) admin/templates/template_thumbnail.php, and the (2) language parameter to (b) account/account.php, (c) downloads/downloads.php, (d) forum/forum.php, (e) fotogalerie/delete.php, and (f) fotogalerie/fotogalerie.php in admin/features/.
|
2008-06-22
|
HomePH Design fotogalerie/delete.php language Parameter Traversal Local File Inclusion
|
|
46896
Description:
(Description Provided by CVE) : Multiple directory traversal vulnerabilities in HomePH Design 2.10 RC2, when register_globals is enabled, allow remote attackers to include and execute arbitrary local files via directory traversal sequences in the (1) thumb_template parameter to (a) admin/templates/template_thumbnail.php, and the (2) language parameter to (b) account/account.php, (c) downloads/downloads.php, (d) forum/forum.php, (e) fotogalerie/delete.php, and (f) fotogalerie/fotogalerie.php in admin/features/.
|
2008-06-22
|
HomePH Design fotogalerie/fotogalerie.php language Parameter Traversal Local File Inclusion
|
|
46897
Description:
(Description Provided by CVE) : Multiple cross-site scripting (XSS) vulnerabilities in HomePH Design 2.10 RC2 allow remote attackers to inject arbitrary web script or HTML via the (1) error_meldung parameter to admin/features/register/register.php, the (2) feature_language[ueberschrift] parameter to admin/features/memberlist/memberlist.php, the (3) language_array[ueberschrift] parameter to admin/features/lostpassword/lostpassword.php, the (4) language_feature[titel] parameter to admin/features/kalender/eingabe.php, and the (5) language_feature[bildmenu] parameter to admin/features/fotogalerie/eingabe.php.
|
2008-06-22
|
HomePH Design admin/features/register/register.php error_meldung Parameter XSS
|
|
46898
Description:
(Description Provided by CVE) : Multiple cross-site scripting (XSS) vulnerabilities in HomePH Design 2.10 RC2 allow remote attackers to inject arbitrary web script or HTML via the (1) error_meldung parameter to admin/features/register/register.php, the (2) feature_language[ueberschrift] parameter to admin/features/memberlist/memberlist.php, the (3) language_array[ueberschrift] parameter to admin/features/lostpassword/lostpassword.php, the (4) language_feature[titel] parameter to admin/features/kalender/eingabe.php, and the (5) language_feature[bildmenu] parameter to admin/features/fotogalerie/eingabe.php.
|
2008-06-22
|
HomePH Design admin/features/memberlist/memberlist.php feature_language[ueberschrift] Parameter XSS
|
|
46899
Description:
(Description Provided by CVE) : Multiple cross-site scripting (XSS) vulnerabilities in HomePH Design 2.10 RC2 allow remote attackers to inject arbitrary web script or HTML via the (1) error_meldung parameter to admin/features/register/register.php, the (2) feature_language[ueberschrift] parameter to admin/features/memberlist/memberlist.php, the (3) language_array[ueberschrift] parameter to admin/features/lostpassword/lostpassword.php, the (4) language_feature[titel] parameter to admin/features/kalender/eingabe.php, and the (5) language_feature[bildmenu] parameter to admin/features/fotogalerie/eingabe.php.
|
2008-06-22
|
HomePH Design admin/features/lostpassword/lostpassword.php language_array[ueberschrift] Parameter XSS
|
|
46900
Description:
(Description Provided by CVE) : Multiple cross-site scripting (XSS) vulnerabilities in HomePH Design 2.10 RC2 allow remote attackers to inject arbitrary web script or HTML via the (1) error_meldung parameter to admin/features/register/register.php, the (2) feature_language[ueberschrift] parameter to admin/features/memberlist/memberlist.php, the (3) language_array[ueberschrift] parameter to admin/features/lostpassword/lostpassword.php, the (4) language_feature[titel] parameter to admin/features/kalender/eingabe.php, and the (5) language_feature[bildmenu] parameter to admin/features/fotogalerie/eingabe.php.
|
2008-06-22
|
HomePH Design admin/features/kalender/eingabe.php language_feature[titel] Parameter XSS
|
|
46901
Description:
(Description Provided by CVE) : Multiple cross-site scripting (XSS) vulnerabilities in HomePH Design 2.10 RC2 allow remote attackers to inject arbitrary web script or HTML via the (1) error_meldung parameter to admin/features/register/register.php, the (2) feature_language[ueberschrift] parameter to admin/features/memberlist/memberlist.php, the (3) language_array[ueberschrift] parameter to admin/features/lostpassword/lostpassword.php, the (4) language_feature[titel] parameter to admin/features/kalender/eingabe.php, and the (5) language_feature[bildmenu] parameter to admin/features/fotogalerie/eingabe.php.
|
2008-06-22
|
HomePH Design admin/features/fotogalerie/eingabe.php language_feature[bildmenu] Parameter XSS
|
|
47086
Description:
(Description Provided by CVE) : upgrade.asp in sHibby sHop 2.2 and earlier does not require administrative authentication, which allows remote attackers to update a file or have unspecified other impact via a direct request.
|
2008-06-22
|
sHibby sHop upgrade.asp Direct Request Insecure Permission Arbitrary File Manipulation
|
|
53905
Description:
HoMaP-CMS contains a flaw that may allow a remote attacker to execute arbitrary commands or code. The issue is due to the 'html/admin/modules/plugin_admin.php' script not properly sanitizing user input supplied to the '_settings[pluginpath]' parameter. This may allow an attacker to include a file from a third-party remote host that contains commands or code that will be executed by the vulnerable script with the same privileges as the web server.
|
2008-06-22
|
HoMaP-CMS html/admin/modules/plugin_admin.php _settings[pluginpath] Parameter Remote File Inclusion
|
|
46471
Description:
CCLeague Pro contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the admin.php script not properly sanitizing user-supplied input to the 'u' cookie variable. This may allow an attacker to inject or manipulate SQL queries in the back-end database.
|
2008-06-21
|
CCleague Pro admin.php u Parameter SQL Injection
|
|
46470
Description:
CCLeague Pro contains a flaw that may allow a malicious user to gain access to unauthorized privileges. The issue is triggered when a user manipulates cookie data and sets the 'type' field to 'admin'. This flaw may lead to a loss of integrity.
|
2008-06-21
|
CCleague Pro admin.php type Cookie Admin Authentication Bypass
|
|
46474
Description:
AJ HYIP contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the news.php script not properly sanitizing user-supplied input to the 'id' variable. This may allow an attacker to inject or manipulate SQL queries in the back-end database.
|
2008-06-21
|
AJ HYIP news.php id Parameter SQL Injection
|
|
46498
Description:
(Description Provided by CVE) : admin/upload.php in le.cms 1.4 and earlier allows remote attackers to bypass administrative authentication, and upload and execute arbitrary files in images/, via a nonzero value for the submit0 parameter in conjunction with filenames in the filename and upload parameters.
|
2008-06-21
|
le.cms cms/admin/upload.php submit0 Variable Arbitrary Remote File Execution
|
|
46483
Description:
(Description Provided by CVE) : Multiple SQL injection vulnerabilities in Online Fantasy Football League (OFFL) 0.2.6 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) fflteam_id parameter to teams.php, the (2) league_id parameter to leagues.php, and the (3) player_id parameter to players.php.
|
2008-06-21
|
Online Fantasy Football League teams.php fflteam_id Parameter SQL Injection
|
|
46477
Description:
Jamroom contains a flaw that may allow a remote attacker to execute arbitrary commands or code. The issue is due to the 'purchase.php' script not properly sanitizing user input supplied to the 'jamroom[jm_dir] parameter. This may allow an attacker to include a file from a third-party remote host that contains commands or code that will be executed by the vulnerable script with the same privileges as the web server.
|
2008-06-21
|
Jamroom purchase.php jamroom[jm_dir] Parameter Remote File Inclusion
|
|
46478
Description:
Jamroom contains a flaw that may allow a remote attacker to execute arbitrary commands or code. The issue is due to the 'payment.php' script not properly sanitizing user input supplied to the 'jamroom[jm_dir]' parameter. This may allow an attacker to include a file from a third-party remote host that contains commands or code that will be executed by the vulnerable script with the same privileges as the web server.
|
2008-06-21
|
Jamroom payment.php jamroom[jm_dir] Parameter Remote File Inclusion
|
|
46479
Description:
(Description Provided by CVE) : Directory traversal vulnerability in index.php in AproxEngine 5.1.0.4 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the page parameter.
|
2008-06-21
|
AproxEngine index.php page Parameter Traversal Local File Inclusion
|
|
46484
Description:
(Description Provided by CVE) : Multiple SQL injection vulnerabilities in Online Fantasy Football League (OFFL) 0.2.6 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) fflteam_id parameter to teams.php, the (2) league_id parameter to leagues.php, and the (3) player_id parameter to players.php.
|
2008-06-21
|
Online Fantasy Football League leagues.php league_id Parameter SQL Injection
|
|
46485
Description:
(Description Provided by CVE) : Multiple SQL injection vulnerabilities in Online Fantasy Football League (OFFL) 0.2.6 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) fflteam_id parameter to teams.php, the (2) league_id parameter to leagues.php, and the (3) player_id parameter to players.php.
|
2008-06-21
|
Online Fantasy Football League players.php player_id Parameter SQL Injection
|
|
46499
Description:
(Description Provided by CVE) : SQL injection vulnerability in projects.php in Scientific Image DataBase 0.41 allows remote attackers to execute arbitrary SQL commands via the id parameter.
|
2008-06-21
|
Scientific Image DataBase projects.php id Parameter SQL Injection
|