| OSVDB ID | Disclosure Date | Title |
|
52459
Description:
Unknown / Incomplete
|
2009-01-29
|
ImageField Module for Drupal Image File Upload Arbitrary PHP Code Execution
|
|
51714
Description:
Unknown / Incomplete
|
2009-01-29
|
D-Link DVG-2001S Forms/page_CfgDevInfo_Set URL XSS
|
|
51715
Description:
Unknown / Incomplete
|
2009-01-29
|
D-Link DVG-2001S Firmware Manipulation CSRF
|
|
51736
Description:
(Description Provided by CVE) : parse.c in sudo 1.6.9p17 through 1.6.9p19 does not properly interpret a system group (aka %group) in the sudoers file during authorization decisions for a user who belongs to that group, which allows local users to leverage an applicable sudoers file and gain root privileges via a sudo command.
|
2009-01-29
|
sudo parse.c System Group Interpretation Local Privilege Escalation
|
|
51790
Description:
Car Portal contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the Login Feature not properly sanitizing user-supplied input to the 'username' and 'password' parameter. This may allow an attacker to inject or manipulate SQL queries in the back-end database, allowing for the manipulation or disclosure of arbitrary data.
|
2009-01-29
|
Car Portal Login Feature Multiple Parameter SQL Injection
|
|
51791
Description:
Pre Lecture Exercises CMS contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the 'login.php' script not properly sanitizing user-supplied input to the 'school' variable. This may allow an attacker to inject or manipulate SQL queries in the back-end database.
|
2009-01-29
|
Pre Lecture Exercises CMS login.php school Parameter SQL Injection
|
|
51792
Description:
(Description Provided by CVE) : Cross-site scripting (XSS) vulnerability in sysconf.cgi in Motorola Wimax modem CPEi300 allows remote authenticated users to inject arbitrary web script or HTML via the page parameter.
|
2009-01-29
|
Motorola Wimax CPEi300 sysconf.cgi page Parameter XSS
|
|
51793
Description:
(Description Provided by CVE) : Directory traversal vulnerability in sysconf.cgi in Motorola Wimax modem CPEi300 allows remote authenticated users to read arbitrary files via a .. (dot dot) in the page parameter.
|
2009-01-29
|
Motorola Wimax CPEi300 sysconf.cgi page Parameter Traversal Arbitrary File Access
|
|
51824
Description:
SkaLinks contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the admin script not properly sanitizing user-supplied input to the '$_COOKIE' variable. This may allow an attacker to login as admin, or inject or manipulate SQL queries in the back-end database.
|
2009-01-29
|
SkaLinks admin/ URI Admin Name Field SQL Injection
|
|
51909
Description:
(Description Provided by CVE) : Array index error in the gst_qtp_trak_handler function in gst/qtdemux/qtdemux.c in GStreamer Plug-ins (aka gstreamer-plugins) 0.6.0 allows remote attackers to have an unknown impact via a crafted QuickTime media file.
|
2009-01-29
|
GStreamer Plug-ins gst/qtdemux/qtdemux.c gst_qtp_trak_handler Function Array Index Handling Unspecified Issue
|
|
52460
Description:
Unknown / Incomplete
|
2009-01-29
|
ImageField Module for Drupal index.php description Parameter XSS
|
|
52850
Description:
(Description Provided by CVE) : Untrusted search path vulnerability in trickle 1.07 allows local users to execute arbitrary code via a Trojan horse trickle-overload.so in the current working directory, which is referenced in the LD_PRELOAD path.
|
2009-01-29
|
trickle trickle-overload.so LD_PRELOAD Search Path Subversion Local Arbitrary Code Execution
|
|
53979
Description:
(Description Provided by CVE) : CRLF injection vulnerability in the WebContainer component in IBM WebSphere Application Server (WAS) 5.1.1.19 and earlier 5.1.x versions allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via unspecified vectors.
|
2009-01-29
|
IBM WebSphere Application Server (WAS) WebContainer Component Unspecified CRLF Injection
|
|
53990
Description:
(Description Provided by CVE) : Open redirect vulnerability in the ibm_security_logout servlet in IBM WebSphere Application Server (WAS) 5.1.1.19 and earlier 5.x versions, 6.0.x before 6.0.2.33, and 6.1.x before 6.1.0.23 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via the logoutExitPage feature.
|
2009-01-29
|
IBM WebSphere Application Server (WAS) ibm_security_logout Servlet logoutExitPage Feature Arbitrary Site Redirect
|
|
56432
Description:
(Description Provided by CVE) : Microsoft Internet Explorer 7 allows remote attackers to trick a user into visiting an arbitrary URL via an onclick action that moves a crafted element to the current mouse position, related to a "Clickjacking" vulnerability.
|
2009-01-29
|
Microsoft IE onclick Action Mouse Click Subversion (Clickjacking)
|
|
55720
Description:
(Description Provided by CVE) : Multiple stack-based buffer overflows in W3C Amaya Web Browser 10.0 and 11.0 allow remote attackers to execute arbitrary code via (1) a long type parameter in an input tag, which is not properly handled by the EndOfXmlAttributeValue function; (2) an "HTML GI" in a start tag, which is not properly handled by the ProcessStartGI function; and unspecified vectors in (3) html2thot.c and (4) xml2thot.c, related to the msgBuffer variable. NOTE: these are different vectors than CVE-2008-6005.
|
2009-01-28
|
Amaya Web Browser Xml2thot.c Multiple Function Overflow
|
|
55721
Description:
(Description Provided by CVE) : Multiple stack-based buffer overflows in W3C Amaya Web Browser 10.0 and 11.0 allow remote attackers to execute arbitrary code via (1) a long type parameter in an input tag, which is not properly handled by the EndOfXmlAttributeValue function; (2) an "HTML GI" in a start tag, which is not properly handled by the ProcessStartGI function; and unspecified vectors in (3) html2thot.c and (4) xml2thot.c, related to the msgBuffer variable. NOTE: these are different vectors than CVE-2008-6005.
|
2009-01-28
|
Amaya Web Browser html2toth.c Multiple Function Overflow
|
|
51644
Description:
SocialEngine contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the blog.php script not properly sanitizing user-supplied input to the category_id parameter when the user parameter is set to a valid username. This may allow an attacker to inject or manipulate SQL queries in the back-end database.
|
2009-01-28
|
SocialEngine blog.php category_id Parameter SQL Injection
|
|
52555
Description:
(Description Provided by CVE) : The IP-in-IP packet processing implementation in the IPsec and IP stacks in the kernel in Sun Solaris 9 and 10, and OpenSolaris snv_01 though snv_85, allows local users to cause a denial of service (panic) via a self-encapsulated packet that lacks IPsec protection.
|
2009-01-28
|
Solaris IP-in-IP Processing Crafted self-encapsulated Packet Local DoS
|
|
51648
Description:
GameScript contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the search parameter upon submission to the games.php script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2009-01-28
|
GameScript games.php search Parameter XSS
|
|
51649
Description:
GameScript contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the page.php script not properly sanitizing user-supplied input to the user parameter. This may allow an attacker to inject or manipulate SQL queries in the back-end database.
|
2009-01-28
|
GameScript page.php user Parameter SQL Injection
|
|
51654
Description:
GameScript contains a flaw that allows a remote attacker to access files outside of the web path. The issue is due to the page.php not properly sanitizing user input, specifically directory traversal style attacks (../../) supplied via the page parameter.
|
2009-01-28
|
GameScript page.php page Parameter Traversal Local File Inclusion
|
|
51645
Description:
Max.Blog contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the offline_auth.php script not properly sanitizing user-supplied input to the username parameter. This may allow an attacker to inject or manipulate SQL queries in the back-end database.
|
2009-01-28
|
Max.Blog offline_auth.php username Parameter SQL Injection
|
|
52577
Description:
(Description Provided by CVE) : Unspecified vulnerability in the Embedded Lights Out Manager (ELOM) on the Sun Fire X2100 M2 and X2200 M2 x86 platforms before SP/BMC firmware 3.20 allows remote attackers to obtain privileged ELOM login access or execute arbitrary Service Processor (SP) commands via unknown vectors, aka Bug ID 6648082, a different vulnerability than CVE-2007-5717.
|
2009-01-28
|
Sun Fire X2100 / X2200 Embedded Lights Out Manager (ELOM) Unspecified Remote Privilege Escalation (6648082)
|
|
52845
Description:
(Description Provided by CVE) : Cross-site scripting (XSS) vulnerability in system/index.php in ExpressionEngine 1.6.4 through 1.6.6, and possibly earlier versions, allows remote attackers to inject arbitrary web script or HTML via the avatar parameter.
|
2009-01-28
|
ExpressionEngine system/index.php avatar Parameter XSS
|
|
51605
Description:
osCommerce contains a flaw that allows a remote Cross-Site Request Forgery (CSRF / XSRF) attack. The flaw exists because the application does not require multiple steps and/or confirmation for sensitive transactions for the <FUNCTIONALITY>. By using a crafted URL (e.g. a crafted GET request inside an "img" tag), an attacker may trick the victim into clicking on the image to take advantage of the trust relationship between the authenticated victim and the application. Such an attack could trick the victim into executing arbitrary commands in the context of their session with the application, without further prompting or verification, including creation of additional administrator accounts by tricking an administrative user into visiting a malicious web site. The vulnerability is confirmed in version 2.2 Release Candidate 2a. Other versions may also be affected.
|
2009-01-28
|
osCommerce Admin Account Creation CSRF
|
|
51643
Description:
(Description Provided by CVE) : Integer signedness error in the fourxm_read_header function in libavformat/4xm.c in FFmpeg before revision 16846 allows remote attackers to execute arbitrary code via a malformed 4X movie file with a large current_track value, which triggers a NULL pointer dereference.
|
2009-01-28
|
FFmpeg libavformat/4xm.c fourxm_read_header Function 4xm File Handling Memory Corruption
|
|
51680
Description:
(Description Provided by CVE) : Cross-site scripting (XSS) vulnerability in HP Select Access 6.1 and 6.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
|
2009-01-28
|
HP Select Access Unspecified XSS
|
|
51687
Description:
Unknown / Incomplete
|
2009-01-28
|
PSCS VPOP3 Email Server Email Message XSS
|
|
51785
Description:
Community CMS contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the 'index.php' script not properly sanitizing user-supplied input to the 'id' parameter. This may allow an attacker to inject or manipulate SQL queries in the back-end database.
|
2009-01-28
|
Community CMS index.php id Parameter SQL Injection
|
|
51786
Description:
smartSite CMS contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the 'articles.php' script not properly sanitizing user-supplied input to the 'var' variable. This may allow an attacker to inject or manipulate SQL queries in the back-end database.
|
2009-01-28
|
smartSite CMS articles.php var Parameter SQL Injection
|
|
51787
Description:
Chipmunk Blogger Script contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the admin/authenticate.php script not properly sanitizing user-supplied input to the 'username' and 'password' parameters. This may allow an attacker to inject or manipulate SQL queries in the back-end database, allowing for the manipulation or disclosure of arbitrary data.
|
2009-01-28
|
Chipmunk Blogger Script admin/authenticate.php Multiple Parameter SQL Injection
|
|
51789
Description:
(Description Provided by CVE) : Chipmunk Blogger Script allows remote attackers to gain administrator privileges via a direct request to admin/reguser.php. NOTE: this is only a vulnerability when the administrator does not properly follow installation directions.
|
2009-01-28
|
Chipmunk Blogger Script admin/reguser.php Direct Request Admin Privilege Escalation
|
|
52498
Description:
(Description Provided by CVE) : Integer overflow in the 4xm demuxer (demuxers/demux_4xm.c) in xine-lib 1.1.16.1 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a 4X movie file with a large current_track value, a similar issue to CVE-2009-0385.
|
2009-01-28
|
xine-lib demuxers/demux_4xm.c current_track Value Handling Overflow
|
|
52935
Description:
(Description Provided by CVE) : Multiple buffer overflows in the CheckUniqueName function in W3C Amaya Web Browser 10.0.1, and possibly other versions including 11.0.1, might allow remote attackers to execute arbitrary code via "duplicated" attribute value inputs.
|
2009-01-28
|
Amaya Web Browser CheckUniqueName Function Duplicated Attribute Value Inputs Overflows
|
|
77350
Description:
Unknown / Incomplete
|
2009-01-28
|
Arch Linux Shaman Root Authentication Bypass Local Privilege Escalation
|
|
52671
Description:
(Description Provided by CVE) : The shell32 module in Microsoft Internet Explorer 7.0 on Windows XP SP3 might allow remote attackers to execute arbitrary code via a long VALUE attribute in an INPUT element, possibly related to a stack consumption vulnerability.
|
2009-01-27
|
Microsoft IE shell32 Module Unspecified Form Data Handling Overflow
|
|
52490
Description:
(Description Provided by CVE) : Apple Safari 3.2.1 (aka AppVer 3.525.27.1) on Windows allows remote attackers to cause a denial of service (infinite loop or access violation) via a link to an http URI in which the authority (aka hostname) portion is either a (1) . (dot) or (2) .. (dot dot) sequence.
|
2009-01-27
|
Apple Safari for Windows http URI Handler Malformed Domain Name DoS
|
|
52028
Description:
Max.Blog contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the submit_post.php script not properly sanitizing user-supplied input to the draft parameter. This may allow an attacker to inject or manipulate SQL queries in the back-end database.
|
2009-01-27
|
Max.Blog submit_post.php draft Parameter SQL Injection
|
|
52029
Description:
Max.Blog contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the show_post.php script not properly sanitizing user-supplied input to the id parameter. This may allow an attacker to inject or manipulate SQL queries in the back-end database.
|
2009-01-27
|
Max.Blog show_post.php id Parameter SQL Injection
|