| Blogs | OSVDB ID | Disclosure Date | Title |
| Views: 9258 |
76929
Description:
Unknown / Incomplete
|
2011-08-08
|
Juniper Junos MX Series BGP Update Ktree::createFourWayNode MPC DoS
|
| Views: 9235 |
397
Description:
Web Servers contains a flaw that may allow a remote attacker to upload arbitrary files. The issue is triggered when the HTTP method 'PUT' is allowed. It is possible that the flaw may allow a remote attacker to upload arbitrary files resulting in a loss of integrity.
|
1994-01-01
|
Multiple Web Server Dangerous HTTP Method PUT
|
| Views: 9169 |
23246
Description:
By default, some Kyocera printers install with an default password. The 'admin' account has an empty password, which is publicly known and documented. This allows attackers to trivially access the system.
|
2006-02-16
|
Kyocera Telnet Default Admin Account
|
| Views: 8894 |
35144
Description:
Mac OS X contains a flaw that may allow a malicious user to gain access to unauthorized privileges. The issue is triggered when the pppd plugin command-line option is used by a local attacker, which does not properly check if the local user has root privileges. This flaw may lead to a loss of integrity.
|
2007-05-25
|
Apple Mac OS X PPP Daemon (pppd) Local Privilege Escalation
|
| Views: 8863 |
63032
Description:
CKForms Component for Joomla! contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the 'index.php' script not properly sanitizing user-supplied input to the 'fid' parameter (when "option" is set to "com_ckforms", "controller" is set to "ckdata", and "layout" is set to "detail"). This may allow an attacker to inject or manipulate SQL queries in the back-end database, allowing for the manipulation or disclosure of arbitrary data.
|
2010-03-17
|
CKForms Component for Joomla! index.php fid Parameter SQL Injection
|
| Views: 8850 |
14988
Description:
XMB Forum contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate multiple user supplied arguments upon submission to the forumdisplay.php script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2004-03-26
|
XMB Forum forumdisplay.php Multiple Parameter XSS
|
| Views: 8572 |
55895
Description:
(Description Provided by CVE) : The design of the W3C XML Signature Syntax and Processing (XMLDsig) recommendation, as implemented in products including (1) the Oracle Security Developer Tools component in Oracle Application Server 10.1.2.3, 10.1.3.4, and 10.1.4.3IM; (2) the WebLogic Server component in BEA Product Suite 10.3, 10.0 MP1, 9.2 MP3, 9.1, 9.0, and 8.1 SP6; (3) Mono before 2.4.2.2; (4) XML Security Library before 1.2.12; (5) IBM WebSphere Application Server Versions 6.0 through 6.0.2.33, 6.1 through 6.1.0.23, and 7.0 through 7.0.0.1; (6) Sun JDK and JRE Update 14 and earlier; (7) Microsoft .NET Framework 3.0 through 3.0 SP2, 3.5, and 4.0; and other products uses a parameter that defines an HMAC truncation length (HMACOutputLength) but does not require a minimum for this length, which allows attackers to spoof HMAC-based signatures and bypass authentication by specifying a truncation length with a small number of bits.
|
2009-07-14
|
Oracle Application Server Security Developer Tools HMACOutputLength Signature Spoofing Weakness
|
| Views: 8495 |
56767
Description:
(Description Provided by CVE) : A certain debugging component in IBM AIX 5.3 and 6.1 does not properly handle the (1) _LIB_INIT_DBG and (2) _LIB_INIT_DBG_FILE environment variables, which allows local users to gain privileges by leveraging a setuid-root program to create an arbitrary root-owned file with world-writable permissions, related to libC.a (aka the XL C++ runtime library) in AIX 5.3 and libc.a in AIX 6.1.
|
2009-08-04
|
IBM AIX libC XL C++ Runtime Library Multiple Variable Arbitrary File Overwrite Local Privilege Escalation
|
| Views: 8461 |
63031
Description:
CKForms Component for Joomla! contains a flaw that may allow a remote attacker to disclose potentially sensitive information. The issue is due to the 'index.php' script not properly sanitizing user input, specifically directory traversal style attacks (e.g., ../../)and URL-encoded NULL bytes, supplied to the 'controller' parameter (when "option" is set to "com_ckforms"). This may allow an attacker to include a file from the targeted host that contains arbitrary commands or code that will be executed by the vulnerable script. Such attacks are limited due to the script only calling files already on the target host. In addition, this flaw can potentially be used to disclose the contents of any file on the system accessible by the web server.
|
2010-03-17
|
CKForms Component for Joomla! index.php controller Parameter Traversal Local File Inclusion
|
| Views: 8305 |
55907
Description:
(Description Provided by CVE) : The design of the W3C XML Signature Syntax and Processing (XMLDsig) recommendation, as implemented in products including (1) the Oracle Security Developer Tools component in Oracle Application Server 10.1.2.3, 10.1.3.4, and 10.1.4.3IM; (2) the WebLogic Server component in BEA Product Suite 10.3, 10.0 MP1, 9.2 MP3, 9.1, 9.0, and 8.1 SP6; (3) Mono before 2.4.2.2; (4) XML Security Library before 1.2.12; (5) IBM WebSphere Application Server Versions 6.0 through 6.0.2.33, 6.1 through 6.1.0.23, and 7.0 through 7.0.0.1; (6) Sun JDK and JRE Update 14 and earlier; (7) Microsoft .NET Framework 3.0 through 3.0 SP2, 3.5, and 4.0; and other products uses a parameter that defines an HMAC truncation length (HMACOutputLength) but does not require a minimum for this length, which allows attackers to spoof HMAC-based signatures and bypass authentication by specifying a truncation length with a small number of bits.
|
2009-07-14
|
Oracle BEA WebLogic Server Web Services Package HMACOutputLength Signature Spoofing Weakness
|
| Views: 8193 |
132
Description:
By default, HP Jet Direct printers install without a password. This lack of password is publicly known and documented. This allows attackers to trivially access the system.
|
1997-10-04
|
HP JetDirect Default Unpassworded Account
|
| Views: 7914 |
25257
Description:
Big Webmaster Guestbook contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the 'name', 'mail', 'site', 'city', 'state' and 'country' fields upon submission to the 'addguest.cgi' script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2006-05-04
|
Big Webmaster Guestbook addguest.cgi Multiple Field XSS
|
| Views: 7640 |
32774
Description:
PHP contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not escape the content of user supplied arrays in GET, POST or COOKIE variables upon submission to phpinfo(). This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2007-03-03
|
PHP phpinfo() Multiple Method User Supplied Array XSS
|
| Views: 7569 |
3268
Description:
Directory indexing has been found to be enabled on the web server. While there is no known vulnerability or exploit associated with this, it may reveal sensitive or "hidden" files or directories to remote users, or aid in more focused attacks.
|
1994-01-01
|
Directory Indexing Enabled
|
| Views: 7553 |
23596
Description:
Gallery contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate 'X_FORWARDED_FOR' HTTP header field upon submission to the GalleryUtilities.class script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2006-03-02
|
Gallery GalleryUtilities.class X_FORWARDED_FOR HTTP Header Field XSS
|
| Views: 7508 |
13834
Description:
(Description Provided by CVE) : awstats.pl in AWStats 6.3 and 6.4 allows remote attackers to obtain sensitive information by setting the debug parameter.
|
2005-02-14
|
AWStats awstats.pl debug mode Information Disclosure
|
| Views: 7313 |
630
Description:
Microsoft IIS contains a flaw that may lead to an unauthorized information disclosure. The issue is triggered when attempting to access an area protected via basic HTTP authentication without providing realm information, making a request without a host: header, or by trying to access a resource that has been moved (302). This may disclose the internal IP address or network name in the response header resulting in a loss of confidentiality.
|
2000-07-13
|
Microsoft IIS Multiple Malformed Header Field Internal IP Address Disclosure
|
| Views: 6965 |
12627
Description:
PHProxy contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the error variable upon submission to the index.php script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2004-12-27
|
PHProxy index.php error Parameter XSS
|
| Views: 6962 |
62929
Description:
Ninja RSS Syndicator Component for Joomla!contains a flaw that may allow a remote attacker to disclose potentially sensitive information. The issue is due to the 'components/com_ninjarsssyndicator/ninjarsssyndicator.php' script not properly sanitizing user input, specifically directory traversal style attacks (e.g., ../../) supplied to the 'controller' parameter. This may allow an attacker to include a file from the targeted host that contains arbitrary commands or code that will be executed by the vulnerable script. Such attacks are limited due to the script only calling files already on the target host. In addition, this flaw can potentially be used to disclose the contents of any file on the system accessible by the web server.
|
2010-03-15
|
Ninja RSS Syndicator Component for Joomla! components/com_ninjarsssyndicator/ninjarsssyndicator.php Controller Parameter Traversal Local File Inclusion
|
| Views: 6846 |
22111
Description:
AdesGuestbook contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the 'totalRows_rsRead' variable upon submission to the 'read.php' script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2005-12-30
|
AdesGuestbook read.php totalRows_rsRead Parameter XSS
|
| Views: 6753 |
79640
Description:
OxWall contains a flaw that allows a remote cross-site scripting (XSS) attack. This flaw exists because the application does not validate the 'tag' parameter upon submission to the '/blogs/browse-by-tag' script. This may allow a user to create a specially crafted URL that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2012-02-20
|
OxWall /blogs/browse-by-tag tag Parameter XSS
|
| Views: 6450 |
61697
Description:
Internet Explorer contains a flaw that may allow a context-dependent attacker to execute arbitrary code. The issue is triggered when a specially crafted website causes mshtml.dll to access memory that has been freed, allowing code execution.
|
2010-01-15
|
Microsoft IE mshtml.dll Use-After-Free Arbitrary Code Execution (Aurora)
|
| Views: 6298 |
27110
Description:
Internet Explorer contains a flaw that may allow a remote denial of service. The issue is triggered when calling the 'setSlice' method of the WebViewFolderIcon.WebViewFolderIcon.1 ActiveX object with the first parameter set to 0x7fffffff. This causes an invalid memory copy and may result in arbitrary code execution and/or a loss of availability for the browser.
|
2006-07-17
|
Microsoft IE WebViewFolderIcon setSlice Overflow
|
| Views: 6261 |
3093
Description:
A potentially dangerous file was found on the web server. While there is no known vulnerability or exploit associated with this file, it has been found in logs after web servers have come under attack from unknown sources and software. This may indicate the presence of an undisclosed vulnerability that is being exploited in the wild.
|
1994-01-01
|
Potentially Dangerous Web Document Found
|
| Views: 6108 |
27920
Description:
XMB contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate data posted in the forum. Especially the <IMG SRC> tag. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2006-01-18
|
XMB IMG Element SRC Attribute XSS
|
| Views: 6055 |
5646
Description:
Web Servers support the DELETE HTTP method. If enabled, a remote client may have the ability to delete objects from the web server. This could allow an arbitrary user to alter web site content causing a loss of integrity or availability.
|
1994-01-01
|
Multiple Web Server Dangerous HTTP Method DELETE
|
| Views: 5970 |
57799
Description:
Microsoft Windows contains a flaw that may allow a malicious user to execute arbitrary code. The issue is triggered when a malicious user sends a specially crafted NEGOTIATE PROTOCOL REQUEST SMBv2 packet with an & (ampersand) character in a Process ID High header field, causing an attempted dereference of an out-of-bounds memory location. It is possible that the flaw may allow arbitrary code execution resulting in a loss of integrity.
|
2009-09-08
|
Microsoft Windows srv2.sys Kernel Driver SMB2 Malformed NEGOTIATE PROTOCOL REQUEST Remote DoS
|
| Views: 5817 |
22297
Description:
VenomBoard contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the add_post.php3 script not properly sanitizing user-supplied input to the 'topic_id', 'root' and 'parent' variables. This may allow an attacker to inject or manipulate SQL queries in the back-end database.
|
2006-01-09
|
VenomBoard add_post.php3 Multiple Parameter SQL Injection
|
| Views: 5714 |
3601
Description:
b2evolution contains a flaw that will allow an attacker to inject arbitrary SQL code. The problem is that the "s" variable in the noskin_a.php module is not verified properly and will allow an attacker to inject or manipulate SQL queries.
|
2003-09-09
|
b2evolution noskin_a.php SQL Injection
|
| Views: 5624 |
60980
Description:
Acrobat and Reader contain a flaw that may allow an attacker to execute arbitrary code. The issue is triggered by a use-after-free condition in Doc.media.newPlayer when parsing a specially crafted PDF file.
|
2009-12-15
|
Adobe Reader / Acrobat Doc.media.newPlayer Use-After-Free Arbitrary Code Execution
|
| Views: 5600 |
28068
Description:
Guestbook contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the 'page' form field parameter upon submission to the gbook.php script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2006-08-21
|
Doika Guestbook gbook.php page XSS
|
| Views: 5591 |
3604
Description:
b2evolution contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the "s" variable upon submission to the noskin_all.php script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2003-09-09
|
b2evolution noskin_all.php XSS
|
| Views: 5577 |
2526
Description:
b2evolution contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the "s" variable upon submission to the noskin_a.php script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2003-09-09
|
b2evolution noskin_a.php XSS
|
| Views: 5525 |
62810
Description:
Microsoft Windows Internet Explorer contains a flaw that may allow an attacker to gain access to unauthorized privileges. The issue is triggered when an attacker utilizes a remote memory-corruption vulnerability in Internet Explorer by inserting malicious code into a site and when Internet Explorer attempts to parse the attack page, the remote attacker to gain privileges of the currently logged-in user viewing the malicious site.
|
2010-03-09
|
Microsoft IE iepeers.dll Use-After-Free Arbitrary Code Execution
|
| Views: 5520 |
18695
Description:
Veritas Backup Exec for Windows Servers contains a flaw that may lead to an unauthorized information disclosure. The issue is triggered when a remote user sends a CONNECT_CLIENT_AUTH request with a hardcoded password value to trigger the flaw. If successful, the flaw will disclose arbitrary files that are accessible via the Windows system account, resulting in a loss of confidentiality.
|
2005-08-12
|
VERITAS Backup Exec Remote Agent Static Password Arbitrary File Download
|
| Views: 5507 |
42518
Description:
Juniper Networks Secure Access 2000 contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate 'delivery_mode' variables upon submission to the 'dana-na/auth/rdremediate.cgi' script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2008-03-04
|
Juniper Networks Secure Access 2000 dana-na/auth/rdremediate.cgi delivery_mode Parameter XSS
|
| Views: 5504 |
56387
Description:
Secure Sockets Layer (SSL) version 2 (v2) has been found to contain several weaknesses. Depending on the time and resources of an attacker, any communication protected by SSLv2 may be vulnerable to Man-in-The-Middle (MiTM) attacks that could allow data tampering or disclosure. SSLv2 flaws in summary: - SSL encrypted web requests traffic analysis can disclose which pages were downloaded, length of data downloaded, what web servers were accessed and more. This requires sniffing or physical access and is considered a passive attack. - Bellovin cut-and-paste attack. This requires sniffing and MiTM manipulation and is considered an active attack. - Bellovin short-block attack. This requires sniffing and MiTM manipulation and is considered an active attack. - Insecure MAC use post-encryption. This is considered a design flaw weakness. - Horton Principle failure. This requires sniffing and MiTM manipulation and is considered an active attack. - Ciphersuite rollback attack. This requires sniffing and MiTM manipulation. - Diffie-hellman Key-exchange MiTM attack. - 40-bit MAC use. This is considered a design flaw weakness.
|
1996-11-01
|
SSLv2 Protocol Multiple Weaknesses
|
| Views: 5414 |
3606
Description:
b2evolution contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the "s" variable upon submission to the noskin_b.php script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2003-09-09
|
b2evolution noskin_b.php XSS
|
| Views: 5386 |
25211
Description:
WebSense contains a flaw that may allow a malicious user to bypass URL filtering policies. The issue is triggered when appending a '/?' to the end of a URL which is part of the 'uncategorized' WebSense category, and will allow the user to bypass any restrictions set on 'uncategorized' websites, resulting in a loss of integrity.
|
2006-04-20
|
Websense Crafted URL Uncategorized Filter Bypass
|
| Views: 5336 |
875
Description:
WarFTPD contains a flaw that allows a remote attacker execute arbitrary code. The issue is due to improper bounds checking for the USER and PASS commands. If an attacker supplies a specially crafted request they may be able to overflow the buffer and execute arbitrary code with the same privileges as the server.
|
1998-03-19
|
WarFTPd USER/PASS Command Remote Overflow
|