| OSVDB ID | Disclosure Date | Title |
|
40076
Description:
(Description Provided by CVE) : SQL injection vulnerability in index.php in SmallNuke 2.0.4 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via (1) the user_email parameter and possibly (2) username parameter in a Members action.
|
2008-01-08
|
SmallNuke index.php Multiple Parameter SQL Injection
|
|
41652
Description:
(Description Provided by CVE) : Multiple stack-based buffer overflows in the WebLaunch.WeblaunchCtl.1 (aka CWebLaunchCtl) ActiveX control in weblaunch.ocx 1.0.0.1 in Gateway Weblaunch allow remote attackers to execute arbitrary code via a long string in the (1) second or (2) fourth argument to the DoWebLaunch method. NOTE: some of these details are obtained from third party information.
|
2008-01-08
|
Gateway Weblaunch weblaunch.ocx WebLaunch.WeblaunchCtl DoWebLaunch Method Overflow Arbitrary Code Execution
|
|
42767
Description:
(Description Provided by CVE) : ssh-signer in SSH Tectia Client and Server 5.x before 5.2.4, and 5.3.x before 5.3.6, on Unix and Linux allows local users to gain privileges via unspecified vectors.
|
2008-01-08
|
SSH Tectia Client/Server ssh-signer Unspecified Local Privilege Escalation
|
|
40206
Description:
(Description Provided by CVE) : SQL injection vulnerability in index.php in EvilBoard 0.1a (Alpha) allows remote attackers to execute arbitrary SQL commands the c parameter.
|
2008-01-08
|
EvilBoard index.php c Parameter SQL Injection
|
|
40207
Description:
(Description Provided by CVE) : Cross-site scripting (XSS) vulnerability in index.php in EvilBoard 0.1a (Alpha) allows remote attackers to inject arbitrary web script or HTML via the c parameter.
|
2008-01-08
|
EvilBoard index.php c Parameter XSS
|
|
40221
Description:
(Description Provided by CVE) : Cross-site scripting (XSS) vulnerability in admin/index.html in Merak IceWarp Mail Server allows remote attackers to inject arbitrary web script or HTML via the message parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
|
2008-01-08
|
IceWarp Mail Server admin/index.html message Parameter XSS
|
|
40383
Description:
(Description Provided by CVE) : SQL injection vulnerability in soporte_horizontal_w.php in PHP Webquest 2.6 allows remote attackers to execute arbitrary SQL commands via the id_actividad parameter, a different vector than CVE-2007-4920.
|
2008-01-08
|
PHP Webquest soporte_horizontal_w.php id_actividad Parameter SQL Injection
|
|
41094
Description:
Zero CMS contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the index.php script not properly sanitizing user-supplied input to the id variable. This may allow an attacker to inject or manipulate SQL queries in the back-end database.
|
2008-01-08
|
Zero CMS index.php id Parameter SQL Injection
|
|
41095
Description:
(Description Provided by CVE) : Multiple SQL injection vulnerabilities in Zero CMS 1.0 Alpha allow remote attackers to execute arbitrary SQL commands via (1) the id parameter to index.php, or the (2) f or t parameters to forums/index.php.
|
2008-01-08
|
Zero CMS forums/index.php Multiple Parameter SQL Injection
|
|
41653
Description:
(Description Provided by CVE) : Directory traversal vulnerability in the WebLaunch.WeblaunchCtl.1 (aka CWebLaunchCtl) ActiveX control in weblaunch.ocx 1.0.0.1 in Gateway Weblaunch allows remote attackers to execute arbitrary programs via a ..\ (dot dot backslash) in the second argument to the DoWebLaunch method. NOTE: some of these details are obtained from third party information.
|
2008-01-08
|
Gateway Weblaunch weblaunch.ocx WebLaunch.WeblaunchCtl DoWebLaunch Method Traversal Arbitrary Program Execution
|
|
42313
Description:
(Description Provided by CVE) : Absolute path traversal vulnerability in index.php in Sys-Hotel on Line System allows remote attackers to read arbitrary files via an encoded "/" ("%2F") in the file parameter.
|
2008-01-08
|
Sys-Hotel on Line System index.php file Parameter Traversal Arbitrary File Access
|
|
42749
Description:
(Description Provided by CVE) : Multiple SQL injection vulnerabilities in Layton HelpBox 3.7.1 allow (1) remote attackers to execute arbitrary SQL commands via the sys_request_id parameter to editrequestenduser.asp; and allow remote authenticated users to execute arbitrary SQL commands via (2) the oldpassword parameter to writepwdenduser.asp, and the sys_request_id parameter to (3) changerequeststatus.asp, (4) editrequestuser.asp, (5) requestcommentsuser.asp, and (6) useractions.asp, different vectors than CVE-2004-2551.
|
2008-01-08
|
Layton HelpBox editrequestuser.asp sys_request_id Parameter SQL Injection
|
|
43340
Description:
(Description Provided by CVE) : Unrestricted file upload vulnerability in Zero CMS 1.0 Alpha and earlier allows remote attackers to bypass intended access restrictions and upload and execute arbitrary files by uploading an avatar file with an accepted Content-Type such as image/jpeg.
|
2008-01-08
|
Zero CMS Crafted Content-Type Avatar File Unrestricted File Upload
|
|
43435
Description:
(Description Provided by CVE) : Sun JRE 5.0 before update 14 allows remote attackers to cause a denial of service (Internet Explorer crash) via an object tag with an encoded applet and an undefined name attribute, which triggers a NULL pointer dereference in jpiexp32.dll when the applet is decoded and passed to the JVM.
|
2008-01-08
|
Sun Java JRE jpiexp32.dll JVM NULL Pointer Dereference Remote DoS
|
|
58140
Description:
A remote overflow exists in xtacacsd. xtacacsd fails to check bounds on the report() function resulting in a buffer overflow. With a specially crafted CONNECT TACACS request, an attacker can cause execute arbitrary code resulting in a loss of integrity.
|
2008-01-08
|
xtacacsd CONNECT TACACS Command Report Function Remote Overflow
|
|
40202
Description:
(Description Provided by CVE) : Directory traversal vulnerability in the _get_file_path function in (1) lib/sessions.py in CherryPy 3.0.x up to 3.0.2, (2) filter/sessionfilter.py in CherryPy 2.1, and (3) filter/sessionfilter.py in CherryPy 2.x allows remote attackers to create or delete arbitrary files, and possibly read and write portions of arbitrary files, via a crafted session id in a cookie.
|
2008-01-07
|
CherryPy Session ID Directory Traversal
|
|
51057
Description:
OneCMS contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the a_login.php script not properly sanitizing user-supplied input to the usernameb parameter. This may allow an attacker to inject or manipulate SQL queries in the back-end database.
|
2008-01-07
|
OneCMS a_login.php usernameb Parameter SQL Injection
|
|
51058
Description:
OneCMS contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the staff.php script not properly sanitizing user-supplied input to the user parameter. This may allow an attacker to inject or manipulate SQL queries in the back-end database.
|
2008-01-07
|
OneCMS staff.php user Parameter SQL Injection
|
|
40217
Description:
(Description Provided by CVE) : Multiple unspecified vulnerabilities in Shareaza before 2.3.1.0 have unknown impact and attack vectors related to "very important security fixes," possibly involving update notifications and a domain that is no longer controlled by the vendor.
|
2008-01-07
|
Shareaza Update Notifications Security Spoofing
|
|
43074
Description:
TCP Port 5679
|
2008-01-07
|
SynCE vdccm src/utils.cpp Utils::runScripts Function Remote Command Execution
|
|
40106
Description:
(Description Provided by CVE) : The NantSys device 5.0.0.115 in Motorola netOctopus 5.1.2 build 1011 has weak permissions for the \\.\NantSys device interface (nantsys.sys), which allows local users to gain privileges or cause a denial of service (system crash), as demonstrated by modifying the SYSENTER_EIP_MSR CPU Model Specific Register (MSR) value.
|
2008-01-07
|
Motorola netOctopus Agent nantsys.sys MSR Write Local Privilege Escalation
|
|
39995
Description:
ZENworks Endpoint Security Management contains a flaw that may allow a malicious user to gain access to unauthorized privileges. The issue is triggered when a local user places a trojaned shell in a directory where dynamic scripts are generated during the generation of a diagnostic report by the application.
|
2008-01-07
|
Novell ZENworks Endpoint Security Management STEngine Privilege Escalation
|
|
43305
Description:
Unknown / Incomplete
|
2008-01-07
|
Multiple Unspecified Passport Reader Photo Processing Overflow
|
|
46252
Description:
(Description Provided by CVE) : SQL injection vulnerability in Slashdot Like Automated Storytelling Homepage (Slash) (aka Slashcode) R_2_5_0_94 and earlier allows remote attackers to execute SQL commands and read table information via the id parameter.
|
2008-01-07
|
Slash id Parameter SQL Injection
|
|
46253
Description:
(Description Provided by CVE) : Cross-site scripting (XSS) vulnerability in Slashdot Like Automated Storytelling Homepage (Slash) (aka Slashcode) R_2_5_0_94 and earlier allows remote attackers to inject arbitrary web script or HTML via the userfield parameter.
|
2008-01-07
|
Slash userfield Parameter XSS
|
|
40906
Description:
(Description Provided by CVE) : The regular expression parser in TCL before 8.4.17, as used in PostgreSQL 8.2 before 8.2.6, 8.1 before 8.1.11, 8.0 before 8.0.15, and 7.4 before 7.4.19, allows remote authenticated users to cause a denial of service (backend crash) via an out-of-bounds backref number.
|
2008-01-07
|
TCL in PostgreSQL Out-of-bounds Backref Number Remote DoS
|
|
40905
Description:
(Description Provided by CVE) : The regular expression parser in TCL before 8.4.17, as used in PostgreSQL 8.2 before 8.2.6, 8.1 before 8.1.11, 8.0 before 8.0.15, and 7.4 before 7.4.19, allows context-dependent attackers to cause a denial of service (infinite loop) via a crafted regular expression.
|
2008-01-07
|
TCL in PostgreSQL Crafted Regexp Infinite Loop Remote DoS
|
|
40904
Description:
(Description Provided by CVE) : PostgreSQL 8.2 before 8.2.6, 8.1 before 8.1.11, 8.0 before 8.0.15, 7.4 before 7.4.19, and 7.3 before 7.3.21 uses superuser privileges instead of table owner privileges for (1) VACUUM and (2) ANALYZE operations within index functions, and supports (3) SET ROLE and (4) SET SESSION AUTHORIZATION within index functions, which allows remote authenticated users to gain privileges.
|
2008-01-07
|
PostgreSQL Multiple Operation Remote Privilege Escalation
|
|
40903
Description:
(Description Provided by CVE) : The DBLink module in PostgreSQL 8.2 before 8.2.6, 8.1 before 8.1.11, 8.0 before 8.0.15, 7.4 before 7.4.19, and 7.3 before 7.3.21, when local trust or ident authentication is used, allows remote attackers to gain privileges via unspecified vectors. NOTE: this issue exists because of an incomplete fix for CVE-2007-3278.
|
2008-01-07
|
PostgreSQL DBLink Module Unspecified Remote Privilege Escalation
|
|
40902
Description:
(Description Provided by CVE) : Algorithmic complexity vulnerability in the regular expression parser in TCL before 8.4.17, as used in PostgreSQL 8.2 before 8.2.6, 8.1 before 8.1.11, 8.0 before 8.0.15, and 7.4 before 7.4.19, allows remote authenticated users to cause a denial of service (memory consumption) via a crafted "complex" regular expression with doubly-nested states.
|
2008-01-07
|
TCL in PostgreSQL Regular Expression Parser Crafted Doubly-nested State Regexp Parsing DoS
|
|
42743
Description:
(Description Provided by CVE) : TUTOS 1.3 does not restrict access to php/admin/cmd.php, which allows remote attackers to execute arbitrary shell commands via the cmd parameter in a direct request.
|
2008-01-07
|
TUTOS php/admin/cmd.php cmd Variable Arbitrary Command Execution
|
|
42030
Description:
(Description Provided by CVE) : Double free vulnerability in the process_browse_data function in CUPS 1.3.5 allows remote attackers to cause a denial of service (daemon crash) and possibly execute arbitrary code via crafted UDP Browse packets to the cupsd port (631/udp), related to an unspecified manipulation of a remote printer. NOTE: some of these details are obtained from third party information.
|
2008-01-07
|
CUPS process_browse_data() Function Double-free Arbitrary Code Execution
|
|
42744
Description:
(Description Provided by CVE) : TUTOS 1.3 allows remote attackers to read system information via a direct request to php/admin/phpinfo.php, which calls the phpinfo function.
|
2008-01-07
|
TUTOS php/admin/phpinfo.php Remote Information Disclosure
|
|
40105
Description:
(Description Provided by CVE) : Cross-site request forgery (CSRF) vulnerability in apply.cgi in the Linksys WRT54GL Wireless-G Broadband Router with firmware 4.30.9 allows remote attackers to perform actions as administrators.
|
2008-01-07
|
Cisco Linksys WRT54GL apply.cgi Multiple Admin Action CSRF
|
|
50224
Description:
(Description Provided by CVE) : Unspecified vulnerability in Small Footprint CIM Broker (SFCB) before 1.2.5 has unknown impact and attack vectors.
|
2008-01-07
|
Small Footprint CIM Broker Multiple Unspecified Issues
|
|
39981
Description:
(Description Provided by CVE) : Cross-site scripting (XSS) vulnerability in Default.asp in RapidShare Database allows remote attackers to inject arbitrary web script or HTML via the Arayalim parameter.
|
2008-01-07
|
RapidShare Database Default.asp Arayalim Parameter XSS
|
|
40068
Description:
(Description Provided by CVE) : Cross-site scripting (XSS) vulnerability in Forums/setup.asp in Snitz Forums 2000 3.4.06 and earlier allows remote attackers to inject arbitrary web script or HTML via the MAIL parameter.
|
2008-01-07
|
Snitz Forums 2000 setup.asp Multiple Parameter XSS
|
|
40078
Description:
(Description Provided by CVE) : SQL injection vulnerability in FlexBB 0.6.3 and earlier allows remote attackers to execute arbitrary SQL commands via the flexbb_temp_id parameter in a cookie.
|
2008-01-07
|
FlexBB index.php flexbb_temp_id Parameter SQL Injection
|
|
40208
Description:
(Description Provided by CVE) : Buffer overflow in JustSystems JSFC.DLL, as used in multiple JustSystems products such as Ichitaro, allows remote attackers to execute arbitrary code via a crafted .JTD file.
|
2008-01-07
|
JustSystems Ichitaro JSFC.DLL Crafted JTD File Arbitrary Remote Code Execution
|
|
40209
Description:
eggBlog contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the 'index.php' script not properly sanitizing user-supplied input to the eggblogpassword cookie. This may allow an attacker to inject or manipulate SQL queries in the back-end database, allowing for the manipulation or disclosure of arbitrary data.
|
2008-01-07
|
eggBlog index.php eggblogpassword Cookie SQL Injection
|