| OSVDB ID | Disclosure Date | Title |
|
76887
Description:
NetArt Media iBoutique contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the index.php script not properly sanitizing user-supplied input to the 'page' parameter. This may allow an attacker to inject or manipulate SQL queries in the back-end database, allowing for the manipulation or disclosure of arbitrary data. Additionally, if a failed query is performed, the program will render the user's input without sanitizing it. This causes the resulting error message to potentially be used as a cross-site scripting (XSS) vector.
|
2010-06-20
|
NetArt Media iBoutique index.php page Parameter SQL Injection
|
|
65644
Description:
Plone CMS contains a flaw that allows a remote cross site scripting (XSS) attack. Users who can create content can exploit this flaw to circumvent the normal HTML filtering. This may allow a user to create a specially crafted URL that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2010-06-19
|
Plone PortalTransforms safe_html HTML Filter XSS
|
|
65726
Description:
RSComments Component for Joomla! contains a flaw that allows a remote cross site scripting (XSS) attack. This flaw exists because the application does not validate the 'website' and 'name' parameters upon submission to the 'index.php' script. This may allow a user to create a specially crafted URL that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2010-06-19
|
RSComments Component for Joomla! index.php Multiple Parameter XSS
|
|
65693
Description:
Unknown / Incomplete
|
2010-06-19
|
Wolfenstein idGameLocal::GetGameStateObject() connectResponse Packet Arbitrary Code Execution
|
|
65789
Description:
(Description Provided by CVE) : Stack-based buffer overflow in MoreAmp allows remote attackers to execute arbitrary code via a long line in a song list (.maf file).
|
2010-06-19
|
MoreAmp MAF File Handling Overflow
|
|
65926
Description:
CMS RedAks contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the /search/ Controller script not properly sanitizing user-supplied input to the 'search_area' parameter. This may allow an attacker to inject or manipulate SQL queries in the back-end database, allowing for the manipulation or disclosure of arbitrary data.
|
2010-06-19
|
CMS RedAks /search/ Controller search_area Parameter SQL Injection
|
|
76890
Description:
Elite Gaming Ladders contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the standings.php script not properly sanitizing user-supplied input to the 'ladder[id]' parameter. This may allow an attacker to inject or manipulate SQL queries in the back-end database, allowing for the manipulation or disclosure of arbitrary data.
|
2010-06-19
|
Elite Gaming Ladders standings.php ladder[id] Parameter SQL Injection
|
|
66659
Description:
Unknown / Incomplete
|
2010-06-18
|
Fujitsu Internet Navigware Multiple Products Unspecified Information Disclosure
|
|
65721
Description:
JForum contains a flaw that allows a remote cross site scripting (XSS) attack. This flaw exists because the application does not validate the 'username' parameter upon submission to the 'jforum.page' script. This may allow a user to create a specially crafted URL that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2010-06-18
|
JForum jforum.page username Parameter XSS
|
|
65722
Description:
Unknown / Incomplete
|
2010-06-18
|
JForum Bookmark Function Multiple Parameter XSS
|
|
65723
Description:
Unknown / Incomplete
|
2010-06-18
|
JForum Multiple Method CSRF
|
|
65655
Description:
WebKit contains an unspecified flaw. No further details have been provided by Apple.
|
2010-06-18
|
WebKit Unspecified Issue (2010-1769)
|
|
65657
Description:
WebKit contains a use-after-free error in JavaScriptCore that is triggered when handling page transitions. With a specially crafted web page, a context-dependent attacker can dereference already freed memory and potentially execute arbitrary code.
|
2010-06-18
|
WebKit JavaScriptCore Page Transition Handling Use-after-free Issue
|
|
65764
Description:
DotNetNuke contains a flaw that allows a remote Cross-site Request Forgery (CSRF / XSRF) attack. The flaw exists because the application does not require multiple steps or explicit confirmation for sensitive transactions for the unspecified functionality. By using a crafted URL (e.g., a crafted GET request inside an "img" tag), an attacker may trick the victim into clicking on the image to take advantage of the trust relationship between the authenticated victim and the application. Such an attack could trick the victim into executing arbitrary commands in the context of their session with the application, without further prompting or verification.
|
2010-06-18
|
DotNetNuke Unspecified CSRF
|
|
72673
Description:
Unknown / Incomplete
|
2010-06-18
|
Microsoft IIS File Extension Parsing Weakness Local Privilege Escalation
|
|
65632
Description:
Unknown / Incomplete
|
2010-06-18
|
TurboFTP Server mkdir Command Traversal Arbitrary Directory Creation
|
|
65763
Description:
DotNetNuke contains a flaw that may lead to an unauthorized information disclosure. The issue is triggered when error occurs during installation or upgrade, which will disclose version information to a remote attacker.
|
2010-06-18
|
DotNetNuke Install Log Information Disclosure
|
|
65760
Description:
Unknown / Incomplete
|
2010-06-18
|
Atlassian JIRA FishEye Plugin Unspecified XSS
|
|
66216
Description:
Unknown / Incomplete
|
2010-06-18
|
Atlassian JIRA Multiple Unspecified Script Query String XSS
|
|
65690
Description:
Unknown / Incomplete
|
2010-06-18
|
XEROX WorkCentre Multiple Unspecified Issues
|
|
65687
Description:
(Description Provided by CVE) : Open&Compact FTP Server (Open-FTPD) 1.2 and earlier allows remote attackers to bypass authentication by sending (1) LIST, (2) RETR, (3) STOR, or other commands without performing the required login steps first.
|
2010-06-18
|
Open&Compact FTP Server (Open-FTPD) Multiple Command Authentication Bypass
|
|
65642
Description:
Banner Management contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the 'trackads.php' script not properly sanitizing user-supplied input to the 'id' parameter. This may allow an attacker to inject or manipulate SQL queries in the back-end database, allowing for the manipulation or disclosure of arbitrary data.
|
2010-06-18
|
Banner Management trackads.php id Parameter SQL Injection
|
|
65718
Description:
Listbingo Component for Joomla! contains a flaw that allows a remote cross site scripting (XSS) attack. This flaw exists because the application does not validate the 'title' and 'address2' parameters upon submission to the 'index.php' script. This may allow a user to create a specially crafted URL that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2010-06-18
|
Listbingo Component for Joomla! index.php Multiple Parameter XSS
|
|
65660
Description:
(Description Provided by CVE) : H264WebCam 3.7 allows remote attackers to cause a denial of service (crash) via a long URI in a GET request, which triggers a NULL pointer dereference. NOTE: some of these details are obtained from third party information.
|
2010-06-18
|
H264WebCam GET Request NULL Dereference Remote DoS
|
|
65758
Description:
Unknown / Incomplete
|
2010-06-18
|
Enemy Territory: Quake Wars Multiple Command Error Message Overflow
|
|
65689
Description:
Unknown / Incomplete
|
2010-06-18
|
UFO: Alien Invasion IRC Client Irc_Proto_ParseServerMsg() Function Overflow
|
|
65720
Description:
Listbingo Component for Joomla! contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the 'index.php' script not properly sanitizing user-supplied input to the 'search_from_price' parameter. This may allow an attacker to inject or manipulate SQL queries in the back-end database, allowing for the manipulation or disclosure of arbitrary data.
|
2010-06-18
|
Listbingo Component for Joomla! index.php search_from_price Parameter SQL Injection
|
|
65761
Description:
Unknown / Incomplete
|
2010-06-18
|
Atlassian JIRA FishEye Plugin Unspecified CSRF
|
|
65762
Description:
Unknown / Incomplete
|
2010-06-18
|
Atlassian JIRA FishEye Plugin Unspecified Arbitrary Code Execution
|
|
65765
Description:
DotNetNuke contains a flaw that allows a remote cross site scripting (XSS) attack. This flaw exists because the application does not validate the invalid HTML tags upon submission to the blacklist function. This may allow a user to create a specially crafted URL that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2010-06-18
|
DotNetNuke Blacklist Function XSS
|
|
65766
Description:
Unknown / Incomplete
|
2010-06-18
|
DotNetNuke Message Store Arbitrary Email Access
|
|
65767
Description:
Unknown / Incomplete
|
2010-06-18
|
DotNetNuke User Profile Information Disclosure
|
|
65975
Description:
(Description Provided by CVE) : Buffer overflow in Dan Pascu python-cjson 1.0.5, when UCS-4 encoding is enabled, allows context-dependent attackers to cause a denial of service (application crash) or possibly have unspecified other impact via vectors involving crafted Unicode input to the cjson.encode function.
|
2010-06-18
|
python-cjson Unicode Character Encoding String Handling Overflow
|
|
66220
Description:
Unknown / Incomplete
|
2010-06-18
|
Notifier for Google Wave Chrome Extension Mail Body XSS
|
|
66222
Description:
Unknown / Incomplete
|
2010-06-18
|
Google Services Notifier Extension for Google Chrome Mail Subject XSS
|
|
66217
Description:
Unknown / Incomplete
|
2010-06-18
|
Atlassian JIRA Crowd SSO Unauthorized Login
|
|
66218
Description:
Unknown / Incomplete
|
2010-06-18
|
Atlassian JIRA Unspecified Triggered User Logout
|
|
66221
Description:
Unknown / Incomplete
|
2010-06-18
|
Notifier for Google Wave Chrome Extension Logout Action CSRF
|
|
66223
Description:
Unknown / Incomplete
|
2010-06-18
|
Google Services Notifier Chrome Extension Logout Action CSRF
|
|
65835
Description:
(Description Provided by CVE) : Citrix XenServer 5.0 Update 2 and earlier, and 5.5 Update 1 and earlier, when using a pvops kernel, allows guest users to cause a denial of service in the host via unspecified vectors that trigger "incorrectly set flags."
|
2010-06-17
|
Citrix XenServer Guest pvops Kernel Unspecified DoS
|