| OSVDB ID | Disclosure Date | Title |
|
80794
Description:
SocialCMS contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the my_admin/admin1_list_pages.php script not properly sanitizing user-supplied input to the 'TR_title' parameter and the 'title' field. This may allow an attacker to inject or manipulate SQL queries in the back-end database, allowing for the manipulation or disclosure of arbitrary data.
|
2012-03-31
|
SocialCMS my_admin/admin1_list_pages.php Multiple Parameter XSS
|
|
80746
Description:
SyndeoCMS contains a flaw that allows a remote cross-site scripting (XSS) attack. This flaw exists because the application does not validate the 'Email Address' field upon submission to the starnet/index.php script. This may allow a user to create a specially crafted URL that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2012-03-31
|
SyndeoCMS starnet/index.php Email Address Field XSS
|
|
80914
Description:
World Graphics contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the blog-detail.php script not properly sanitizing user-supplied input to the 'id_post' parameter. This may allow an attacker to inject or manipulate SQL queries in the back-end database, allowing for the manipulation or disclosure of arbitrary data.
|
2012-03-31
|
World Graphics blog-detail.php id_post Parameter SQL Injection
|
|
80915
Description:
Flock contains a flaw that may allow a denial of service. The issue is triggered when handling unicode, and will result in loss of availability for the application.
|
2012-03-31
|
Flock Malformed Unicode Handling DoS
|
|
80764
Description:
[WN]KT KickTipp Addon for Woltlab Burning Board contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the kt_main.php script not properly sanitizing user-supplied input to the 'liga_id' parameter. This may allow an attacker to inject or manipulate SQL queries in the back-end database, allowing for the manipulation or disclosure of arbitrary data.
|
2012-03-31
|
[WN]KT KickTipp Addon for Woltlab Burning Board kt_main.php liga_id Parameter SQL Injection
|
|
80916
Description:
Anden sal contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the page.php script not properly sanitizing user-supplied input to the 'id' parameter. This may allow an attacker to inject or manipulate SQL queries in the back-end database, allowing for the manipulation or disclosure of arbitrary data.
|
2012-03-31
|
Anden sal page.php id Parameter SQL Injection
|
|
80819
Description:
QuickBooks contains a flaw related to HelpAsyncPluggableProtocol.dll that may lead to an unauthorized information disclosure. The issue is triggered when a attacker supplies the path and file name of a .ZIP help file which uses backslashes, which will disclose sensitive information to a remote attacker.
|
2012-03-30
|
Intuit QuickBooks HelpAsyncPluggableProtocol.dll Help File Access
|
|
80871
Description:
IBM Tivoli Directory Server contains a flaw that allows a remote cross-site scripting (XSS) attack. This flaw exists because certain unspecified input passed via the web admin tool is not properly sanitized before being returned to the user. This may allow a user to create a specially crafted URL that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2012-03-30
|
IBM Tivoli Directory Server Web Admin Tool Unspecified XSS
|
|
80745
Description:
Dalbum contains a flaw that allows a remote Cross-site Request Forgery (CSRF / XSRF) attack. The flaw exists because the application does not require multiple steps or explicit confirmation for sensitive transactions for the addition of a user, removal of a user, or changing the password of a user. By using a crafted URL (e.g., a crafted GET request inside an "img" tag), an attacker may trick the victim into clicking on the image to take advantage of the trust relationship between the authenticated victim and the application. Such an attack could trick the victim into executing arbitrary commands in the context of their session with the application, without further prompting or verification.
|
2012-03-30
|
Dalbum /photo/pass.php Multiple Function CSRF
|
|
80768
Description:
Havalite CMS contains a flaw related to the hava_upload.php script. The issue may allow an attack to upload arbitrary files.
|
2012-03-30
|
Havalite CMS hava_upload.php Arbitrary File Upload
|
|
80769
Description:
Havalite CMS contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the hava_post.php script not properly sanitizing user-supplied input to the 'postId' parameter. This may allow an attacker to inject or manipulate SQL queries in the back-end database, allowing for the manipulation or disclosure of arbitrary data.
|
2012-03-30
|
Havalite CMS hava_post.php postId Parameter SQL Injection
|
|
80770
Description:
Havalite CMS contains a flaw that may lead to an unauthorized information disclosure. The issue is triggered when an error in data/havalite.db3 occurs, which will disclose database information to a remote attacker.
|
2012-03-30
|
Havalite CMS data/havalite.db3 CONFIG Database Information Disclosure
|
|
80778
Description:
PHP contains a flaw related to the eregi() function. By exhausting available memory, the memory_limit directive restrictions can be bypassed.
|
2012-03-30
|
PHP eregi() Function Memory Exhaustion memory_limit Bypass
|
|
80796
Description:
LandShop contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the landshop/admin/action/objects.php script not properly sanitizing user-supplied input to the 'OB_ID' parameter. This may allow an attacker to inject or manipulate SQL queries in the back-end database, allowing for the manipulation or disclosure of arbitrary data.
|
2012-03-30
|
Landshop landshop/admin/action/objects.php OB_ID Parameter SQL Injection
|
|
80799
Description:
Landshop contains a flaw that allows a remote cross-site scripting (XSS) attack. This flaw exists because the application does not validate input passed to the create object function. This may allow a user to create a specially crafted URL that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2012-03-30
|
Landshop Create Object Function XSS
|
|
80800
Description:
Landshop contains a flaw that allows a remote Cross-site Request Forgery (CSRF / XSRF) attack. The flaw exists because the application does not require multiple steps or explicit confirmation for sensitive transactions for the manipulation of the user form. By using a crafted URL (e.g., a crafted GET request inside an "img" tag), an attacker may trick the victim into clicking on the image to take advantage of the trust relationship between the authenticated victim and the application. Such an attack could trick the victim into executing arbitrary commands in the context of their session with the application, without further prompting or verification.
|
2012-03-30
|
Landshop User Form Manipulation CSRF
|
|
80891
Description:
Multiple products for Invensys are prone to an overflow condition related to the WWCabFile ActiveX control. The Open() and AddFile() methods fail to properly sanitize user-supplied input resulting in a heap-based buffer overflow. With a specially crafted overly long string, a remote attacker can potentially execute arbitrary code.
|
2012-03-30
|
Invensys Multiple Product WWCabFile ActiveX (WWCabFile.dll) Multiple Method String Handling Overflow
|
|
81807
Description:
Intuit QuickBooks contains a flaw that may allow a remote denial of service. The issue is triggered when an error in intu-help-qb helpers within HelpAsyncPluggableProtocol.dll occurs when parsing inpt passed via the URL, and will result in loss of availability for the program.
|
2012-03-30
|
Intuit QuickBooks HelpAsyncPluggableProtocol.dll intu-help-qb URI Parsing Remote DoS
|
|
80744
Description:
MailMax is prone to an overflow condition. The program fails to properly sanitize user-supplied input resulting in a buffer overflow. With a specially crafted POP3 USER command, a remote attacker can potentially execute arbitrary code.
|
2012-03-30
|
SmartMax MailMax POP3 USER Command Remote Overflow
|
|
80772
Description:
GetSimple CMS contains a flaw that may lead to an unauthorized information disclosure. The issue is triggered when backups/pages/ is accessed, which will disclose backup information to a remote attacker.
|
2012-03-30
|
GetSimple CMS backups/pages/ Backup Information Disclosure
|
|
80773
Description:
PTK contains a flaw that may lead to an unauthorized information disclosure. The issue may allow a remote attacker uses a direct request to gain access to log, evidence, and report files.
|
2012-03-30
|
PTK Direct Request Multiple Sensitive File Access
|
|
80774
Description:
PTK contains a flaw that allows a remote cross-site scripting (XSS) attack. This flaw exists because the application does not validate the 'arg4' parameter upon submission to the ptk/lib/modal_bookmark.php script. This may allow a user to create a specially crafted URL that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2012-03-30
|
PTK ptk/lib/modal_bookmark.php arg4 Parameter XSS
|
|
80781
Description:
ArticleSetup contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the upload/feed.php script not properly sanitizing user-supplied input to the 'cat' parameter. This may allow an attacker to inject or manipulate SQL queries in the back-end database, allowing for the manipulation or disclosure of arbitrary data.
|
2012-03-30
|
ArticleSetup upload/feed.php cat Parameter SQL Injection
|
|
80782
Description:
ArticleSetup contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the upload/search.php script not properly sanitizing user-supplied input to the 's' parameter. This may allow an attacker to inject or manipulate SQL queries in the back-end database, allowing for the manipulation or disclosure of arbitrary data.
|
2012-03-30
|
ArticleSetup upload/search.php s Parameter SQL Injection
|
|
80791
Description:
WebMatter CMS contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the subcategoria.asp script not properly sanitizing user-supplied input to the 'id_subcat' parameter. This may allow an attacker to inject or manipulate SQL queries in the back-end database, allowing for the manipulation or disclosure of arbitrary data.
|
2012-03-30
|
WebMatter CMS subcategoria.asp id_subcat Parameter SQL Injection
|
|
80792
Description:
WebMatter CMS contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the lista_productos.asp script not properly sanitizing user-supplied input to the 'id_cat' parameter. This may allow an attacker to inject or manipulate SQL queries in the back-end database, allowing for the manipulation or disclosure of arbitrary data.
|
2012-03-30
|
WebMatter CMS lista_productos.asp id_cat Parameter SQL Injection
|
|
80795
Description:
JAMWiki contains a flaw that allows a remote cross-site scripting (XSS) attack. This flaw exists because the application does not validate the 'num' parameter upon submission to Special:AllPages. This may allow a user to create a specially crafted URL that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2012-03-30
|
JAMWiki Special:AllPages num Parameter XSS
|
|
80797
Description:
LandShop contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the landshop/admin/action/pdf.php script not properly sanitizing user-supplied input to the 'start' parameter. This may allow an attacker to inject or manipulate SQL queries in the back-end database, allowing for the manipulation or disclosure of arbitrary data.
|
2012-03-30
|
Landshop landshop/admin/action/pdf.php start Parameter SQL Injection
|
|
80798
Description:
Landshop contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the landshop/admin/action/areas.php script not properly sanitizing user-supplied input to the 'AREA_ID' parameter. This may allow an attacker to inject or manipulate SQL queries in the back-end database, allowing for the manipulation or disclosure of arbitrary data.
|
2012-03-30
|
Landshop landshop/admin/action/areas.php AREA_ID Parameter SQL Injection
|
|
80793
Description:
Php Agenda contains a flaw that allows a remote Cross-site Request Forgery (CSRF / XSRF) attack. The flaw exists because the application does not require multiple steps or explicit confirmation for sensitive transactions for the Add Administrator, Delete Existing Administrator, Add a New Event, Delete an Existing Event. By using a crafted URL (e.g., a crafted GET request inside an "img" tag), an attacker may trick the victim into clicking on the image to take advantage of the trust relationship between the authenticated victim and the application. Such an attack could trick the victim into executing arbitrary commands in the context of their session with the application, without further prompting or verification.
|
2012-03-30
|
PHP Agenda Multiple Function CSRF
|
|
80727
Description:
VMware contains a flaw in multiple products that may allow an attacker to gain access to unauthorized privileges. The issue is triggered when a local attacker may direct input via REP INSB instructions to the high-bandwidth backdoor in order to modify the content of read-only memory, leading to an escalation of privileges.
|
2012-03-30
|
VMware Multiple Product High-Bandwidth Backdoor REP INSB Read-Only Memory Manipulation Local Privilege Escalation
|
|
80779
Description:
ArticleSetup contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the upload/login.php script not properly sanitizing user-supplied input to the 'userid' and 'password' parameters. This may allow an attacker to inject or manipulate SQL queries in the back-end database, allowing for the manipulation or disclosure of arbitrary data.
|
2012-03-30
|
ArticleSetup upload/login.php Multiple Parameter SQL Injection
|
|
80775
Description:
PTK contains a flaw that may lead to an unauthorized information disclosure. The issue is triggered when the HTTPOnly attribute is not set on a cookie, allowing the value to be read or set, allowing a remote attacker to obtain sensitive information via accessing the cookie.
|
2012-03-30
|
PTK HTTPOnly Flag Set-Cookie Information Disclosure
|
|
80776
Description:
PHP Designer contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the announce.php script not properly sanitizing user-supplied input to the 'id' parameter. This may allow an attacker to inject or manipulate SQL queries in the back-end database, allowing for the manipulation or disclosure of arbitrary data.
|
2012-03-30
|
PHP Designer announce.php id Parameter SQL Injection
|
|
80777
Description:
PHP Designer contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the read_news.php script not properly sanitizing user-supplied input to the 'news_id' parameter. This may allow an attacker to inject or manipulate SQL queries in the back-end database, allowing for the manipulation or disclosure of arbitrary data.
|
2012-03-30
|
PHP Designer read_news.php news_id Parameter SQL Injection
|
|
80780
Description:
ArticleSetup contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the upload/admin/login.php script not properly sanitizing user-supplied input to the 'userid' and 'password' parameters. This may allow an attacker to inject or manipulate SQL queries in the back-end database, allowing for the manipulation or disclosure of arbitrary data.
|
2012-03-30
|
ArticleSetup upload/admin/login.php Multiple Parameter SQL Injection
|
|
80783
Description:
ArticleSetup contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the upload/admin/pageedit.php script not properly sanitizing user-supplied input to the 'id' parameter. This may allow an attacker to inject or manipulate SQL queries in the back-end database, allowing for the manipulation or disclosure of arbitrary data.
|
2012-03-30
|
ArticleSetup upload/admin/pageedit.php id Parameter SQL Injection
|
|
80784
Description:
ArticleSetup contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the upload/admin/authoredit.php script not properly sanitizing user-supplied input to the 'id' parameter. This may allow an attacker to inject or manipulate SQL queries in the back-end database, allowing for the manipulation or disclosure of arbitrary data.
|
2012-03-30
|
ArticleSetup upload/admin/authoredit.php id Parameter SQL Injection
|
|
80785
Description:
ArticleSetup contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the admin/categoryedit.php script not properly sanitizing user-supplied input to the 'id' parameter. This may allow an attacker to inject or manipulate SQL queries in the back-end database, allowing for the manipulation or disclosure of arbitrary data.
|
2012-03-30
|
ArticleSetup admin/categoryedit.php id Parameter SQL Injection
|
|
80786
Description:
ArticleSetup contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the upload/search.php script not properly sanitizing user-supplied input to the 's' parameter. This may allow an attacker to inject or manipulate SQL queries in the back-end database, allowing for the manipulation or disclosure of arbitrary data.
|
2012-03-30
|
ArticleSetup upload/search.php s Parameter XSS
|