| OSVDB ID | Disclosure Date | Title |
|
79493
Description:
Notmuch contains a flaw that may lead to an unauthorized information disclosure. The issue is due to /emacs/notmuch-mua.el not properly sanitizing user-supplied input when parsing MML tags, which will disclose attached files to a context-dependent attacker.
|
2012-02-03
|
Notmuch emacs/notmuch-mua.el MML Tag Parsing Attached File Information Disclosure
|
|
78785
Description:
Category-System Extension for TYPO3 contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to certain unspecified input not being properly sanitized before use in SQL queries. This may allow an attacker to inject or manipulate SQL queries in the back-end database, allowing for the manipulation or disclosure of arbitrary data.
|
2012-02-03
|
Category-System Extension for TYPO3 Unspecified SQL Injection
|
|
78787
Description:
Documents download Extension for TYPO3 contains a flaw that allows a remote cross-site scripting (XSS) attack. This flaw exists because the application does not validate certain unspecified input before returning it to the user. This may allow a user to create a specially crafted URL that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2012-02-03
|
Documents download (rtg_files) Extension for TYPO3 Unspecified XSS
|
|
78820
Description:
WP-RecentComments Plugin for WordPress contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the index.php script not properly sanitizing user-supplied input to the 'id' parmaeter. This may allow an attacker to inject or manipulate SQL queries in the back-end database, allowing for the manipulation or disclosure of arbitrary data.
|
2012-02-03
|
WP-RecentComments Plugin for WordPress index.php id Parameter SQL Injection
|
|
78823
Description:
project-open contains a flaw that allows a remote cross-site scripting (XSS) attack. This flaw exists because the register/account-closed.adp script does not validate the 'message' parameter upon submission to register/account-closed. This may allow a user to create a specially crafted URL that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2012-02-03
|
project-open register/account-closed.adp message Parameter XSS
|
|
78827
Description:
Foswiki contains a flaw that allows a remote cross-site scripting (XSS) attack. This flaw exists because the application does not validate the 'text', FirstName', 'LastName', 'OrganisationName', 'OrganisationUrl', 'Profession', 'Country', 'State', 'Address', 'Location', 'Telephone', 'VoIP', 'InstantMessagingIM', 'Email', 'HomePage', and 'Comment' parameters upon submission to UI/Register.pm. This may allow a user to create a specially crafted request that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2012-02-03
|
Foswiki UI/Register.pm Multiple Parameter XSS
|
|
78925
Description:
GForge Advanced Server contains a flaw that allows a remote cross-site scripting (XSS) attack. This flaw exists because the application does not validate the 'subdir' parameter upon submission to the project/test/docman/index.php script. This may allow a user to create a specially crafted URL that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2012-02-03
|
GForge Advanced Server project/test/docman/index.php subdir Parameter XSS
|
|
78929
Description:
GForge Advanced Server contains a flaw related to an unspecified bypassing of authentication settings, that may allow an attacker to login to the application prior to an administrator's approval. No further details have been provided.
|
2012-02-03
|
GForge Advanced Server Unspecified Authentication Bypass
|
|
79988
Description:
SquirrelMail Autocomplete plugin contains a flaw that allows a remote cross-site scripting (XSS) attack. The flaw occurs in specific fields when searching for registered email addresses in user contacts. This may allow a user to create a specially crafted URL that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2012-02-03
|
Autocomplete Plugin for SquirrelMail Address Book Contact XSS
|
|
78784
Description:
Category-System Extension for TYPO3 contains a flaw that allows a remote cross-site scripting (XSS) attack. This flaw exists because the application does not validate certain unspecified input before returning it to the user. This may allow a user to create a specially crafted URL that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2012-02-03
|
Category-System Extension for TYPO3 Unspecified XSS
|
|
78924
Description:
GForge Advanced Server contains a flaw that allows a remote cross-site scripting (XSS) attack. This flaw exists because the application does not validate the 'startdate' and 'enddate' parameters upon submission to the search/index.php script. This may allow a user to create a specially crafted URL that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2012-02-03
|
GForge Advanced Server search/index.php Multiple Parameter XSS
|
|
80047
Description:
OllyDBG is prone to an overflow condition. The program fails to properly sanitize user-supplied input resulting in an integer overflow. With a specially crafted export table, a context-dependent attacker can potentially cause arbitrary code execution.
|
2012-02-03
|
OllyDBG Export Table Handling Remote Overflow
|
|
80221
Description:
FTPServer for Android contains a flaw related to the authentication mechanism. The issue is due to the application not providing proper validation of credentials, which may allow a remote attacker to bypass authentication and execute arbitrary FTP commands.
|
2012-02-03
|
FTPServer for Android FTP Command Execution Authentication Bypass
|
|
80870
Description:
phpPgAdmin contains a flaw that allows a remote cross-site scripting (XSS) attack. This flaw exists because the application does not validate certain unspecified user-supplied input upon submission to the functions.php script. This may allow a user to create a specially crafted request that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2012-02-03
|
phpPgAdmin functions.php Unspecified XSS
|
|
81484
Description:
PHP is prone to an overflow condition. The 'htmlspecialchars()' function fails to properly sanitize user-supplied input resulting in a buffer overflow. With a specially crafted request containing overly long entities, a remote attacker can potentially cause the service to crash resulting in a loss of availability.
|
2012-02-03
|
PHP htmlspecialchars Entities Handling Remote Overflow DoS
|
|
81485
Description:
torrent-stats contains a flaw that may allow a local denial of service. The issue is due to an error within httpd.c when parsing malformed requests, which may causes the service to crash resulting in a loss of availability.
|
2012-02-03
|
torrent-stats httpd.c Request Parsing LocalDoS
|
|
78788
Description:
Documents download Extension for TYPO3 contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to certain unspecified input not being properly sanitized before use in SQL queries. This may allow an attacker to inject or manipulate SQL queries in the back-end database, allowing for the manipulation or disclosure of arbitrary data.
|
2012-02-03
|
Documents download (rtg_files) Extension for TYPO3 Unspecified SQL Injection
|
|
78918
Description:
Simple Groupware contains a flaw that allows a remote cross-site scripting (XSS) attack. This flaw exists because the sys_die() function in the bin/core/functions.php script does not validate the 'export' parameter upon submission to the bin/index.php script. This may allow a user to create a specially crafted URL that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2012-02-03
|
Simple Groupware bin/core/functions.php sys_die() Function export Parameter XSS
|
|
78981
Description:
zenphoto contains a flaw that allows a remote cross-site scripting (XSS) attack. This flaw exists because the application does not validate the 'msg' parameter or input passed via the URL upon submission to the zp-core/admin.php script. This may allow a user to create a specially crafted URL that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2012-02-03
|
zenphoto zp-core/admin.php Multiple Parameter XSS
|
|
78982
Description:
zenphoto contains a flaw that allows a remote cross-site scripting (XSS) attack. This flaw exists because the application does not validate the 'album' parameter upon submission to the zp-core/admin-edit.php script. This may allow a user to create a specially crafted URL that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2012-02-03
|
zenphoto zp-core/admin-edit.php album Parameter XSS
|
|
78996
Description:
OpenConf contains a flaw that may allow an attacker to carry out a blind SQL injection attack. The issue is due to the author/edit.php script not properly sanitizing user-supplied input passed via the 'pid' POST parameter. This may allow an attacker to inject or manipulate SQL queries in the back-end database, allowing for the manipulation or disclosure of arbitrary data.
|
2012-02-03
|
OpenConf author/edit.php pid Parameter SQL Injection
|
|
82471
Description:
OSCommerce Online Merchant contains a flaw that allows a remote cross-site scripting (XSS) attack. This flaw exists because the application does not validate the 'value_title' parameter upon submission to the main.php script. This may allow a user to create a specially crafted URL that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2012-02-03
|
OSCommerce Online Merchant main.php value_title Parameter XSS
|
|
84154
Description:
WebKit contains a use-after-free error in the 'ContainerNode::appendChild' function in WebCore/dom/ContainerNode.cpp, when nodes are created as a part of setting document.title and simultaneously removing the body. With a specially crafted web page, a context-dependent attacker can dereference already freed memory and potentially execute arbitrary code.
|
2012-02-03
|
WebKit 'ContainerNode::appendChild' Function Use-after-free Issue
|
|
78750
Description:
Modern FAQ Extension for TYPO3 contains a flaw that allows a remote cross site redirection attack. This flaw exists because the application does not validate certain unspecified input before use in site redirection. This could allow a user to create a specially crafted URL, that if clicked, would redirect a victim from the intended legitimate web site to an arbitrary web site of the attacker's choosing. Such attacks are useful as the crafted URL initially appear to be a web page of a trusted site. This could be leveraged to direct an unsuspecting user to a web page containing attacks that target client side software such as a web browser or document rendering programs.
|
2012-02-02
|
Modern FAQ Extension for TYPO3 Unspecified Arbitrary Site Redirect
|
|
78790
Description:
Post data records to facebook Extension for TYPO3 contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to certain unspecified input not being properly sanitized before use in SQL queries. This may allow an attacker to inject or manipulate SQL queries in the back-end database, allowing for the manipulation or disclosure of arbitrary data.
|
2012-02-02
|
Post data records to facebook Extension for TYPO3 Unspecified SQL Injection
|
|
78792
Description:
Webservices Extension for TYPO3 contains an unspecified flaw that may allow a remote attacker to execute arbitrary code. No further details have been provided.
|
2012-02-02
|
Webservices Extension for TYPO3 Unspecified Remote Code Execution
|
|
78794
Description:
Euro Calculator Extension for TYPO3 contains a flaw that allows a remote cross-site scripting (XSS) attack. This flaw exists because the application does not validate certain unspecified input before returning it to the user. This may allow a user to create a specially crafted URL that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2012-02-02
|
Euro Calculator Extension for TYPO3 Unspecified XSS
|
|
78795
Description:
Yet another Google search Extension for TYPO3 contains a flaw that allows a remote cross-site scripting (XSS) attack. This flaw exists because the application does not validate certain unspecified input before returning it to the user. This may allow a user to create a specially crafted URL that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2012-02-02
|
Yet another Google search Extension for TYPO3 Unspecified XSS
|
|
78798
Description:
BE User Switch Extension for TYPO3 contains a flaw that allows a remote cross-site scripting (XSS) attack. This flaw exists because the application does not validate certain unspecified input before returning it to the user. This may allow a user to create a specially crafted URL that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2012-02-02
|
BE User Switch Extension for TYPO3 Unspecified XSS
|
|
78799
Description:
BE User Switch Extension for TYPO3 contains a flaw that may lead to an unauthorized information disclosure. The issue is triggered when a remote attacker takes certain unspecified action.
|
2012-02-02
|
BE User Switch Extension for TYPO3 Unspecified Information Disclosure
|
|
78818
Description:
Skype contains an unspecified flaw that may allow a remote attacker to have an unspecified impact. No further details have been provided.
|
2012-02-02
|
Skype Unspecified Remote Issue
|
|
78825
Description:
(Description Provided by CVE) : Unspecified vulnerability in Joomla! 1.7.x before 1.7.5 allows attackers to read the error log via unknown vectors.
|
2012-02-02
|
Joomla! Unspecified Error Log Disclosure
|
|
78826
Description:
(Description Provided by CVE) : Joomla! 1.7.x before 1.7.5 and 2.5.x before 2.5.1 allows attackers to obtain the installation path via unspecified vectors related to "administrator."
|
2012-02-02
|
Joomla! Administrator Section Unspecified Path Disclosure
|
|
78896
Description:
Mathopd contains a flaw that allows a remote attacker to traverse outside of a restricted path. The issue is due to the application not properly sanitizing user input, specifically directory traversal style attacks (e.g., ../../) supplied via the Host Headers. This directory traversal attack would allow the attacker to access arbitrary files.
|
2012-02-02
|
Mathopd HTTP Server Host Header Traversal Arbitrary File Access
|
|
78979
Description:
ZENphoto contains a flaw related to the viewing of uploaded images. The issue is due to the 'viewer_size_image_saved' cookie value not properly sanitizing user-supplied input before being used in an 'eval()' call. This may allow a remote attacker to execute arbitrary PHP code.
|
2012-02-02
|
zenphoto viewer_size_image_saved Cookie Value eval() Call Remote PHP Code Execution
|
|
78980
Description:
ZENphoto contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the zp-core/admin-albumsort.php script not properly sanitizing user-supplied input to the 'sortableList' parameter. This may allow an attacker to inject or manipulate SQL queries in the back-end database, allowing for the manipulation or disclosure of arbitrary data.
|
2012-02-02
|
zenphoto zp-core/admin-albumsort.php sortableList Parameter SQL Injection
|
|
78989
Description:
Opera is reportedly prone to multiple overflow conditions. The applications fails to properly sanitize user-supplied input resulting in an integer overflow. With a specially crafted request containing large integer arguments, a remote attacker can potentially cause the application to crash resulting in a loss of availability.
|
2012-02-02
|
Opera Multiple Array Large Integer Argument Parsing Remote Overflow DoS
|
|
78748
Description:
Kitchen recipe Extension for TYPO3 contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to certain unspecified input not being properly sanitized before use in SQL queries. This may allow an attacker to inject or manipulate SQL queries in the back-end database, allowing for the manipulation or disclosure of arbitrary data.
|
2012-02-02
|
Kitchen recipe Extension for TYPO3 Unspecified SQL Injection
|
|
78749
Description:
Modern FAQ Extension for TYPO3 contains a flaw that allows a remote cross-site scripting (XSS) attack. This flaw exists because the application does not validate certain unspecified input before returning it to the user. This may allow a user to create a specially crafted URL that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2012-02-02
|
Modern FAQ Extension for TYPO3 Unspecified XSS
|
|
78786
Description:
White Papers Extension for TYPO3 contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to certain unspecified input not being properly sanitized before use in SQL queries. This may allow an attacker to inject or manipulate SQL queries in the back-end database, allowing for the manipulation or disclosure of arbitrary data.
|
2012-02-02
|
White Papers Extension for TYPO3 Unspecified SQL Injection
|