| Blogs | OSVDB ID | Disclosure Date | Title |
| Views: 34788 |
18293
Description:
By default, many of Belkin wireless routers using a default ssid of "belkin54g" are preconfigured with a default password. The "admin" account has a null password which is publicly known and documented. This allows attackers to trivially access the program or system.
|
2005-07-15
|
Belkin 54G Routers Admin Account Default Null Password
|
| Views: 19709 |
40621
Description:
Simple PHP Blog contains a flaw that allows a remote Cross-Site Request Forgery (CSRF / XSRF) attack. The flaw exists because the application does not require multiple steps and/or confirmation for sensitive transactions to delete posts. By using a crafted URL (e.g. a crafted GET request inside an "img" tag), an attacker may trick the victim into clicking on the image to take advantage of the trust relationship between the authenticated victim and the application. Such an attack could trick the victim into executing arbitrary commands in the context of their session with the application, without further prompting or verification.
|
2007-10-17
|
Simple PHP Blog (SPHPBlog) add_link.php link_id Parameter CSRF
|
| Views: 14705 |
821
Description:
By default, Linksys routers install with a default password. The administrative account has a password of admin which is publicly known and documented. This allows attackers to trivially access the program or system.
|
2002-09-12
|
Linksys Router Default Password
|
| Views: 12261 |
28946
Description:
A remote stack-based buffer overflow exists in Microsoft Internet Explorer. The browser's vml rendering engine fails to check the length of a fill parameter on the rect tag resulting in a stack-based buffer overflow. With a specially crafted request that contains a vml graphics, an attacker can cause arbitrary code execution resulting in a loss of integrity.
|
2006-09-19
|
Microsoft IE Vector Markup Language (VML) Arbitrary Code Execution
|
| Views: 9804 |
592
Description:
By default, Zyxel routers install with a default password. The administrative account has a password of 1234 which is publicly known and documented. This allows attackers to trivially access the program or system.
|
2002-09-12
|
ZyXEL Multiple Routers Default Administrator Password
|
| Views: 8339 |
44643
Description:
A buffer overflow exists in HD Audio Codec Driver. RTKVHDA.sys and RTKVHDA64.sys fail to validate IOCTL requests resulting in an integer overflow. With a specially crafted request, an attacker can cause arbitrary code execution resulting in a loss of integrity.
|
2008-04-23
|
Realtek HD Audio Codec Driver RTKVHDA.sys / RTKVHDA64.sys IOCTL Request Handling Overflow
|
| Views: 6907 |
16866
Description:
A remote overflow exists in Terminator 3: War of the Machines. The application fails to perform proper bounds checking resulting in a buffer overflow. With a specially crafted request containing an overly long CD-key hash, a remote attacker can cause arbitrary code execution resulting in a loss of integrity.
|
2005-05-26
|
Terminator 3: War of the Machines Client CD-key Overflow
|
| Views: 6477 |
877
Description:
RFC compliant web servers support the TRACE HTTP method, which contains a flaw that may lead to an unauthorized information disclosure. The TRACE method is used to debug web server connections and allows the client to see what is being received at the other end of the request chain. Enabled by default in all major web servers, a remote attacker may abuse the HTTP TRACE functionality, i.e. cross-site scripting (XSS), which will disclose sensitive configuration information resulting in a loss of confidentiality.
|
2003-01-20
|
Multiple Web Server Dangerous HTTP Method TRACE
|
| Views: 6056 |
382
Description:
By default, PostgresSQL installs without a default password for the postgres user account. This username and password combination is publicly known and documented. This allows attackers to trivially access the program or system with administrative priveleges.
|
1999-07-17
|
PostgreSQL Server Default Password
|
| Views: 5297 |
4030
Description:
The TCP stack implementation of numerous vendors contains a flaw that may allow a remote denial of service. The issue is triggered when spoofed TCP Reset packets are received by the targeted TCP stack, and will result in loss of availability for the attacked TCP services.
|
2004-04-20
|
TCP/IP Sequence Prediction Blind Reset Spoofing DoS
|
| Views: 4881 |
25257
Description:
Big Webmaster Guestbook contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the 'name', 'mail', 'site', 'city', 'state' and 'country' fields upon submission to the 'addguest.cgi' script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2006-05-04
|
Big Webmaster Guestbook addguest.cgi Multiple Field XSS
|
| Views: 4126 |
22297
Description:
VenomBoard contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the add_post.php3 script not properly sanitizing user-supplied input to the 'topic_id', 'root' and 'parent' variables. This may allow an attacker to inject or manipulate SQL queries in the backend database.
|
2006-01-09
|
VenomBoard add_post.php3 Multiple Parameter SQL Injection
|
| Views: 4100 |
12627
Description:
PHProxy contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the error variable upon submission to the index.php script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2004-12-27
|
PHProxy index.php error Parameter XSS
|
| Views: 3452 |
16876
Description:
BookReview contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the 'node' variable upon submission to the 'add_url.htm' script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2005-05-26
|
BookReview add_url.htm node Parameter XSS
|
| Views: 3411 |
3092
Description:
A potentially interesting file, directory or CGI was found on the web server. While there is no known vulnerability or exploit associated with this, it may contain sensitive information which can be disclosed to unauthenticated remote users, or aid in more focused attacks.
|
1994-01-01
|
Interesting Web Document Found
|
| Views: 3305 |
944
Description:
Allaire Forums contains a flaw that allows remote attackers to retrieve arbitrary files from the system through the GetFile.cfm program. This could allow information disclosure and lead to system compromise.
|
1999-02-11
|
Allaire Forums GetFile.cfm File Retrieval
|
| Views: 3302 |
49243
Description:
Microsoft Windows Server Service contains a flaw that may allow a malicious user to remotely execute arbitrary code. The issue is triggered when a crafted RPC request is handled. It is possible that the flaw may allow remote code execution resulting in a loss of integrity.
|
2008-10-23
|
Microsoft Windows Server Service Crafted RPC Request Handling Unspecified Remote Code Execution
|
| Views: 3270 |
36385
Description:
A buffer overflow exists in Windows Media Player 11. The player fails to handle the space allocated for uncompressing a compressed skin file resulting in a heap overflow. With a specially crafted file, a remote attacker can cause arbitrary code execution resulting in a loss of integrity.
|
2007-08-14
|
Microsoft Windows Media Player Skin File Handling Overflow
|
| Views: 3246 |
25261
Description:
(Description Provided by CVE) : PHP remote file inclusion vulnerability in admin/addentry.php in phpBB Advanced Guestbook 2.4.0 and earlier, when register_globals is enabled, allows remote attackers to include arbitrary files via the phpbb_root_path parameter.
|
2006-04-28
|
phpBB Advanced GuestBook addentry.php phpbb_root_path Parameter Remote File Inclusion
|
| Views: 3141 |
3592
Description:
dotProject contains a flaw that allows a remote attacker to include arbitrary files. The issue is due to numerous scripts that call the classdefs/date.php script without defining or restricting the $root_dir variable. This allows an attacker to set the variable to an arbitrary server/path/file name which may include malicious commands that would be executed on the vulnerable server.
|
2003-01-29
|
dotProject classdefs/date.php $root_dir Arbitrary File Include
|
| Views: 3138 |
29725
Description:
AFGB Guestbook contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to add.php not properly sanitizing user input supplied to the 'Htmls' variable. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script.
|
2006-10-12
|
AFGB Guestbook add.php Htmls Parameter Remote File Inclusion
|
| Views: 3016 |
132
Description:
By default, HP Jet Direct printers install without a password. This lack of password is publicly known and documented. This allows attackers to trivially access the system.
|
1997-10-04
|
HP JetDirect Default Password
|
| Views: 2932 |
6704
Description:
MoinMoin contains a flaw that may allow a malicious user to gain access to unauthorized privileges. The issue is triggered when an attacker creates a user with the same name as an administrative group. This flaw may lead to a loss of integrity.
|
2004-05-04
|
MoinMoin Group ACL Bypass
|
| Views: 2860 |
26127
Description:
myNewsletter contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the adminLogin.asp script not properly sanitizing user-supplied input to the 'UserName' variable. This may allow an attacker to inject or manipulate SQL queries in the backend database.
|
2006-06-06
|
myNewsletter adminLogin.asp UserName Parameter SQL Injection
|
| Views: 2794 |
23246
Description:
By default, some Kyocera printers install with an default password. The 'admin' account has an empty password, which is publicly known and documented. This allows attackers to trivially access the system.
|
2006-02-16
|
Kyocera Telnet Default Admin Account
|
| Views: 2756 |
34323
Description:
A remote overflow exists in the Download Manager Active X Control. The 'GetPrivateProfileSectionW()' function gets passed the wrong value for its 'nSize' parameter for wide characters, resulting in a stack overflow. With a specially crafted request, an attacker can execute arbitrary code in the trust relationship between the client and the browser, resulting in a loss of integrity.
|
2007-04-16
|
Akamai Technologies Download Manager ActiveX Control (DownloadManagerV2.ocx) GetPrivateProfileSectionW Function Overflow
|
| Views: 2703 |
38669
Description:
Boinc Forum contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate 'search_string' variables upon submission to the forum_text_search_action.php script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2007-11-12
|
Boinc Forum forum_text_search_action.php search_string Parameter XSS
|
| Views: 2683 |
24120
Description:
ssCMS contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the 'keywords' variable upon submission to the search.aspx script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2006-03-25
|
ssCMS search.aspx keywords Parameter XSS
|
| Views: 2601 |
30768
Description:
By default, APC installs with a default password on the integrated HTTP server (TCP Port 3052). The 'apc' account has a password of 'apc' which is publicly known and documented. This allows attackers to trivially access the program or system.
|
2000-09-15
|
APC PowerChute HTTP Server Default Account
|
| Views: 2596 |
44642
Description:
HD Audio Codec Driver contains a flaw that may allow a malicious user to gain access to unauthorized privileges. The issue is triggered by a specially crafted IOCTL request, and allows an attacker to create, read and write arbitrary registry keys. This flaw may lead to a loss of integrity.
|
2008-04-23
|
Realtek HD Audio Codec Driver RTKVHDA.sys / RTKVHDA64.sys Crafted IOCT Request Arbitrary Registry Key Manipulation
|
| Views: 2571 |
26352
Description:
Content*Builder contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to the /modules/guestbook/guestbook.inc.php script not properly sanitizing user input supplied to the 'path[cb]' variable. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script.
|
2006-06-11
|
Content*Builder guestbook/guestbook.inc.php path[cb] Parameter Remote File Inclusion
|
| Views: 2505 |
20712
Description:
ASP-Programmers ASPKnowledgebase contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the adminlogin.asp script not properly sanitizing user-supplied input to the pwd variable. This may allow an attacker to inject or manipulate SQL queries in the backend database.
|
2005-11-08
|
ASP-Programmers ASPKnowledgebase adminlogin.asp pwd Variable Login SQL Injection
|
| Views: 2371 |
3511
Description:
By default, the EDIMAX AR-6004 Full Rate ADSL Router installs with a default password. The admin account has a password of 1234 which is publicly known and documented. This allows attackers to trivially access the program or system.
|
2004-01-08
|
EDIMAX AR-6004 Broadband Router Default Password
|
| Views: 2286 |
18695
Description:
Veritas Backup Exec for Windows Servers contains a flaw that may lead to an unauthorized information disclosure. The issue is triggered when a remote user sends a CONNECT_CLIENT_AUTH request with a hardcoded password value to trigger the flaw. If successful, the flaw will disclose arbitrary files that are accessible via the Windows system account, resulting in a loss of confidentiality.
|
2005-08-12
|
VERITAS Backup Exec Remote Agent Arbitrary File Download
|
| Views: 2273 |
32397
Description:
opentaps contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the 'SEARCH_STRING' variable upon submission to the keywordsearch script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2006-12-21
|
opentaps ecommerce/control/keywordsearch SEARCH_STRING Parameter XSS
|
| Views: 2225 |
630
Description:
Microsoft IIS contains a flaw that may lead to an unauthorized information disclosure. The issue is triggered when attempting to access an area protected via basic HTTP authentication without providing realm information, making a request without a host: header, or by trying to access a resource that has been moved (302). This may disclose the internal IP address or network name in the response header resulting in a loss of confidentiality.
|
2000-07-13
|
Microsoft IIS Multiple Malformed Header Field Internal IP Address Disclosure
|
| Views: 2182 |
20954
Description:
VP-ASP Shopping Cart contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the "UserName" variable upon submission to the shopadmin.asp script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2005-11-18
|
VP-ASP Shopping Cart shopadmin.asp UserName Parameter XSS
|
| Views: 2155 |
12548
Description:
ASP-Rider contains a flaw that will allow a remote attacker to inject arbitrary SQL code. The problem is that the 'username' parameter in the 'verify.asp' script is not verified properly and will allow an attacker to inject or manipulate SQL queries.
|
2004-12-14
|
ASP-Rider verify.asp username Parameter SQL Injection
|
| Views: 2148 |
22191
Description:
B-net Software contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the 'title' and 'message' variables upon submission to the guestbook.php script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2006-01-02
|
B-net Software guestbook.php Multiple Parameter XSS
|
| Views: 2098 |
31367
Description:
BirdBlog contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the 'entryid' variable upon submission to the 'comment.php' script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2006-09-25
|
BirdBlog comment.php entryid Parameter XSS
|