| OSVDB ID | Disclosure Date | Title |
|
88008
Description:
PRODUCT contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the /nagiosql/admin/services.php script not properly sanitizing user-supplied input to the 'chbActive' parameter. This may allow an attacker to inject or manipulate SQL queries in the back-end database, allowing for the manipulation or disclosure of arbitrary data.
|
2012-11-30
|
Nagios XI Network Monitor /nagiosql/admin/services.php chbActive Parameter SQL Injection
|
|
88009
Description:
PRODUCT contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the /nagiosql/admin/hosts.php script not properly sanitizing user-supplied input to the 'chbActive', 'tfCheckIntervalm', 'tfMaxCheckAttempts', or 'tfRetryInterval' parameters. This may allow an attacker to inject or manipulate SQL queries in the back-end database, allowing for the manipulation or disclosure of arbitrary data.
|
2012-11-30
|
Nagios XI Network Monitor /nagiosql/admin/hosts.php Multiple Parameter SQL Injection
|
|
88010
Description:
PRODUCT contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the /nagiosql/admin/servicegroups.php script not properly sanitizing user-supplied input to the 'chbActive' or 'selCommandType' parameters. This may allow an attacker to inject or manipulate SQL queries in the back-end database, allowing for the manipulation or disclosure of arbitrary data.
|
2012-11-30
|
Nagios XI Network Monitor /nagiosql/admin/servicegroups.php Multiple Parameter SQL Injection
|
|
88004
Description:
McAfee Email Gateway contains a flaw that may allow a remote denial of service. The issue is triggered when an error occurs in Secure Web Mail during the handling of a saturation of client messages. This will result in a consumption of disk space, resulting in a loss of availability for the program.
|
2012-11-30
|
McAfee Email Gateway Secure Web Mail Client Message Saturation Disk Space Consumption DoS
|
|
88003
Description:
McAfee Email Gateway contains a flaw that allows a remote cross-site scripting (XSS) attack. This flaw exists because the application does not validate attachment names before returning it to the user. This may allow a user to create a specially crafted request that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2012-11-30
|
McAfee Email Gateway Attachment Name XSS
|
|
88063
Description:
Free Hosting Manager contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the packages.php script not properly sanitizing user-supplied input to the 'id' parameter. This may allow an attacker to inject or manipulate SQL queries in the back-end database, allowing for the manipulation or disclosure of arbitrary data.
|
2012-11-30
|
Free Hosting Manager packages.php id Parameter SQL Injection
|
|
88084
Description:
RSA NetWitness contains a flaw that allows a remote Cross-site Request Forgery (CSRF / XSRF) attack. The flaw exists because the application does not require multiple steps or explicit confirmation for sensitive transactions. By using a crafted URL (e.g., a crafted GET request inside an "img" tag), an attacker may trick the victim into clicking on the image to take advantage of the trust relationship between the authenticated victim and the application. Such an attack could trick the victim into performing an unspecified action in the context of their session with the application, without further prompting or verification.
|
2012-11-30
|
RSA NetWitness Unspecified CSRF
|
|
88083
Description:
RSA NetWitness contains a flaw that is triggered when the application fails to properly sanitize unspecified user-supplied input. This may allow a context-dependent attacker to more easily conduct a clickjacking attack.
|
2012-11-30
|
RSA NetWitness Unspecified Click-jacking Weakness
|
|
88164
Description:
Buffalo LinkStation contains a flaw that may lead to an unauthorized information disclosure. The issue is triggered during the handling of a direct request, which may allow an unauthenticated remote attacker gain access to arbitrary files including perm.conf, password, lighttpd.conf, and host.pem. Such requests will disclose sensitive information that can be used to elevate privileges on the server.
|
2012-11-30
|
Buffalo LinkStation Direct Request Unauthenticated Remote File Disclosure
|
|
88163
Description:
Buffalo LinkStation contains a flaw that that is triggered during the handling of POST requests requesting a password change. Due to the application not enforcing user access, an attacker can change the username in the request in order to change an arbitrary user's password. By changing the administrator password, an attacker can gain elevated privileges.
|
2012-11-30
|
Buffalo LinkStation Arbitrary User Password Manipulation
|
|
88165
Description:
Symantec Messaging Gateway contains a flaw that allows a remote attacker to traverse outside of a restricted path. The issue is due to the /brightmail/export script not properly sanitizing user input, specifically directory traversal style attacks (e.g., ../../) supplied via the 'logfile' parameter. This directory traversal attack would allow the attacker to gain access to arbitrary files.
|
2012-11-30
|
Symantec Messaging Gateway /brightmail/export logfile Parameter Traversal Arbitrary File Access
|
|
88294
Description:
Qt contains a flaw that may lead to an unauthorized information disclosure. The issue is triggered when an error occurs in the XmlHttpRequest object, which causes an insecure redirection on a file: URL. This may allow a remote attacker to gain access to potentially sensitive information stored in local files via a Man-in-the-Middle attack.
|
2012-11-30
|
Qt XmlHttpRequest Object Insecure Redirection MitM Information Disclosure
|
|
88005
Description:
The Post Oak AWAM Bluetooth Reader Traffic System contains a flaw related to authentication. The issue is due to the system not using sufficient entropy when generating authentication and host keys. A remote attacker that is able to monitor network traffic (i.e. MiTM) can use sniffed nonunique host keys to calculate private authentication keys and gain access to the system.
|
2012-11-30
|
Post Oak AWAM Bluetooth Reader Traffic System Authentication / Host Key Entropy Weakness
|
|
88085
Description:
Multiple KYOCERA mobile devices contain a flaw that may allow a remote denial of service. The issue is triggered during the parsing of an email in an invalid message format, which will result in a loss of availability for the device.
|
2012-11-30
|
KYOCERA Multiple Mobile Device Invalid Message Format Parsing DoS
|
|
88116
Description:
OurWebFTP contains a flaw that allows a remote cross-site scripting (XSS) attack. This flaw exists because the application does not validate the 'ftp_host' and 'ftp_user' parameters upon submission to the index.php script. This may allow a user to create a specially crafted request that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2012-11-30
|
OurWebFTP index.php Multiple Parameter XSS
|
|
88115
Description:
Axis contains a flaw that allows a remote cross-site scripting (XSS) attack. This flaw exists because the application does not validate the 'data' parameter upon submission to the admin/core/site/batch-save script. This may allow a user to create a specially crafted request that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2012-11-30
|
Axis admin/core/site/batch-save data Parameter XSS
|
|
88114
Description:
Axis contains a flaw that allows a remote cross-site scripting (XSS) attack. This flaw exists because the application does not validate the 'answer[][]' and 'description[]' parameters upon submission to the admin/poll/save script. This may allow a user to create a specially crafted request that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2012-11-30
|
Axis admin/poll/save Multiple Parameter XSS
|
|
90291
Description:
IBM Lotus Domino contains a flaw that allows a remote cross-site scripting (XSS) attack. This flaw exists because the application does not validate the 'RedirectTo' parameter upon submission to the /names.nsf script. This may allow an attacker to create a specially crafted request that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2012-11-30
|
IBM Lotus Domino /names.nsf RedirectTo Parameter XSS
|
|
90290
Description:
IBM Lotus Domino contains a flaw that allows a remote cross site redirection attack. This flaw exists because the application does not validate the 'RedirectTo' parameter upon submission to the /names.nsf script. This could allow a user to create a specially crafted URL, that if clicked, would redirect a victim from the intended legitimate web site to an arbitrary web site of the attacker's choosing. Such attacks are useful as the crafted URL initially appear to be a web page of a trusted site. This could be leveraged to direct an unsuspecting user to a web page containing attacks that target client side software such as a web browser or document rendering programs.
|
2012-11-30
|
IBM Lotus Domino /names.nsf RedirectTo Parameter Arbitrary Site Redirect
|
|
88002
Description:
Video Lead Form Plugin for WordPress contains a flaw that allows a remote cross-site scripting (XSS) attack. This flaw exists because the application does not validate the 'errMsg' parameter upon submission to the admin.php script. This may allow a user to create a specially crafted request that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2012-11-29
|
Video Lead Form Plugin for WordPress admin.php errMsg Parameter XSS
|
|
88001
Description:
Safend Data Protector contains a flaw that may allow an attacker to gain access to unauthorized privileges. The issue is due to the SDBagent and SDPagent installation paths having spaces and being unquoted. This may allow a local attacker to gain escalated privileges by placing their own executable in a location that will be searched before the actual program.
|
2012-11-29
|
Safend Data Protector SDBagent / SDPagent Unquoted Path Local Privilege Escalation Weakness
|
|
87998
Description:
SilverStripe contains a flaw that allows a remote cross-site scripting (XSS) attack. This flaw exists because the application does not validate input passed via the 'Site Title' field before returning it to the user. This may allow a user to create a specially crafted request that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2012-11-29
|
SilverStripe Site Title Field XSS
|
|
87997
Description:
SilverStripe contains a flaw that allows a remote Cross-site Request Forgery (CSRF / XSRF) attack. The flaw exists because the application does not require multiple steps or explicit confirmation for sensitive transactions for /admin/security/EditForm/. By using a crafted URL (e.g., a crafted GET request inside an "img" tag), an attacker may trick the victim into clicking on the image to take advantage of the trust relationship between the authenticated victim and the application. Such an attack could trick the victim into creating an arbitrary administrative user in the context of their session with the application, without further prompting or verification.
|
2012-11-29
|
SilverStripe /admin/security/EditForm/ Arbitrary Admin User Creation CSRF
|
|
88062
Description:
Google Chrome contains a flaw in the 'HasPermissionsForFile' function in browser/child_process_security_policy_impl.cc when handling file paths. With a specially crafted path containing directory traversal character sequences (e.g. "../../"), a context-dependent attacker can bypass the sandbox to read/write files on the system.
|
2012-11-29
|
Google Chrome HasPermissionsForFile Function Incorrect File Path Handling Renderer Sandbox Bypass
|
|
88061
Description:
WebKit contains a use-after-free error in the 'HTMLMediaElement::clearMediaPlayer' function and HTMLMediaElement destructor in WebCore/html/HTMLMediaElement.cpp when handling media sources. With a specially crafted web page, a context-dependent attacker can dereference already freed memory and execute arbitrary code.
|
2012-11-29
|
WebKit Media Source Handling Use-after-free Arbitrary Code Execution
|
|
88059
Description:
Elastix contains a flaw that allows a remote cross-site scripting (XSS) attack. This flaw exists because the application does not validate the 'Page' parameter upon submission to the xmlservices/E_book.php script. This may allow a user to create a specially crafted request that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2012-11-29
|
Elastix xmlservices/E_book.php Page Parameter XSS
|
|
88058
Description:
Dovecot contains a flaw that may allow a remote denial of service. The issue is triggered when an error occurs in lib-storage/mail-search.c during the handling of a multiple keyword search. This will result in an infinite loop, which will cause a loss of availability.
|
2012-11-29
|
Dovecot lib-storage/mail-search.c Multiple Keyword Search Handling Remote DoS
|
|
88082
Description:
Fortinet FortiDB contains a flaw that allows a remote cross-site scripting (XSS) attack. This flaw exists because the application does not validate the 'conversationContext' parameter upon submission to multiple scripts in the Java Number Format Exception Handling module. This may allow a user to create a specially crafted request that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2012-11-29
|
Fortinet FortiDB Java Number Format Exception Handling Module conversationContext Parameter XSS
|
|
88113
Description:
JSUpload contains a flaw that allows a remote attacker to traverse outside of a restricted path. The issue is due to the program not properly sanitizing user input, specifically directory traversal style attacks (e.g., ../../) supplied via the writeItemContent() function in jsupload.cgi.pl. This directory traversal attack would allow the attacker to manipulate arbitrary files.
|
2012-11-29
|
JSUpload jsupload.cgi.pl writeItemContent() Function Traversal Arbitrary File Manipulation
|
|
89281
Description:
Simple Gmail Login Plugin for WordPress contains a flaw that may lead to an unauthorized information disclosure. The issue is triggered when a remote attacker sends a request which is lacking a timezone to the simple-gmail-login.php script, which discloses the software's installation path resulting in a loss of confidentiality. While such information is relatively low risk, it is often useful in carrying out additional, more focused attacks.
|
2012-11-29
|
Simple Gmail Login Plugin for WordPress simple-gmail-login.php Crafted Request Parsing Path Disclosure
|
|
88161
Description:
UMPlayer Portable Edition contains a flaw that may allow a remote denial of service. The issue is triggered when opening the umplayer.ini file via the recent files option. With a specially crafted file, a context-dependent attacker can cause the program to crash.
|
2012-11-29
|
UMPlayer Portable Edition Recent Files umplayer.ini Handling DoS
|
|
88055
Description:
SmartCMS contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the index.php script not properly sanitizing user-supplied input to the 'menuitem' parameter. This may allow an attacker to inject or manipulate SQL queries in the back-end database, allowing for the manipulation or disclosure of arbitrary data.
|
2012-11-29
|
SmartCMS index.php menuitem Parameter SQL Injection
|
|
88056
Description:
SmartCMS contains a flaw that allows a remote cross-site scripting (XSS) attack. This flaw exists because the application does not validate the 'menuitem' parameter upon submission to the index.php script. This may allow a user to create a specially crafted request that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2012-11-29
|
SmartCMS index.php menuitem Parameter XSS
|
|
88265
Description:
Agilebits 1Password contains a flaw that allows a remote cross-site scripting (XSS) attack. This flaw exists because the application does not validate the 'User Agent' field in the new user agent upon submission to the troubleshooting.html script. This may allow a user to create a specially crafted request that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2012-11-29
|
Agilebits 1Password troubleshooting.html New User Agent User Agent Field XSS
|
|
88603
Description:
Apache OpenOffice.org (OOo) contains a flaw that may lead to an unauthorized information disclosure. The issue is triggered when an unspecified error occurs, which may allow a remote attacker to gain access to potentially sensitive information.
|
2012-11-29
|
Apache OpenOffice.org (OOo) Unspecified Information Disclosure
|
|
91614
Description:
Zend Framework contains a flaw in Zend\View\Helper\ServerUrl that is due to the helper generating URLs based on the proxy host, even if it's not desired. This may allow a remote attacker to more easily inject content into proxied traffic.
|
2012-11-29
|
Zend Framework Zend\View\Helper\ServerUrl Helper URL Generation Weakness
|
|
88000
Description:
afend Data Protector contains a flaw that may lead to an unauthorized information disclosure. The issue is due to private key data being stored in the securitylayer.log file in the logs.9772 directory. This may allow a local attacker to gain access to key information, which could allow them to modify security policies on a user's system.
|
2012-11-29
|
Safend Data Protector securitylayer.log Private Key Local Disclosure
|
|
87999
Description:
Safend Data Protector contains a flaw that may allow an attacker to gain access to unauthorized privileges. The issue is due to the SDBagent and SDPagent services being given the insecure 'WRITE_DAC' permissions for all local users. This may allow a local attacker to modify the ACL and gain escalated privileges.
|
2012-11-29
|
Safend Data Protector SDBagent / SDPagent Permission Weakness Local Privilege Escalation
|
|
88060
Description:
MariaDB is prone to an overflow condition. The program fails to properly sanitize user-supplied input resulting in a buffer overflow. This may allow a remote attacker to execute arbitrary code under the permissions of the mysql daemon. No further details have been provided.
|
2012-11-29
|
MariaDB Unspecified Overflow
|
|
88057
Description:
IBM WebSphere Message contains a flaw that may allow an attacker to gain access to unauthorized privileges. The issue is due to insecure permissions on the uninstaller file. This may allow a local attacker to gain escalated privileges.
|
2012-11-29
|
IBM WebSphere Message Broker Uninstaller File Permissions Local Privilege Escalation
|