| Blogs | OSVDB ID | Disclosure Date | Title |
| Views: 9329 |
33868
Description:
HyperBook Guestbook contains a flaw that may lead to an unauthorized information disclosure. The issue is triggered when requesting data/gbconfiguration.dat directly, which will disclose the administrator's MD5 password hash to a remote attacker.
|
2007-02-28
|
HyperBook Guestbook data/gbconfiguration.dat Direct Request Information Disclosure
|
| Views: 2044 |
81355
Description:
DokuWiki contains a flaw that allows a remote cross-site scripting (XSS) attack. This flaw exists because the application does not validate the 'target' parameter upon submission to the doku.php script. This may allow a user to create a specially crafted URL that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2012-04-19
|
DokuWiki doku.php target Parameter XSS
|
| Views: 1368 |
89337
Description:
IP.Gallery contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the index.php script not properly sanitizing user-supplied input to the 'img' parameter. This may allow an attacker to inject or manipulate SQL queries in the back-end database, allowing for the manipulation or disclosure of arbitrary data.
|
2013-01-17
|
IP.Gallery index.php img Parameter SQL Injection
|
| Views: 1127 |
79640
Description:
OxWall contains a flaw that allows a remote cross-site scripting (XSS) attack. This flaw exists because the application does not validate the 'tag' parameter upon submission to the '/blogs/browse-by-tag' script. This may allow a user to create a specially crafted URL that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2012-02-20
|
OxWall /blogs/browse-by-tag tag Parameter XSS
|
| Views: 733 |
32774
Description:
PHP contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not escape the content of user supplied arrays in GET, POST or COOKIE variables upon submission to phpinfo(). This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2007-03-03
|
PHP phpinfo() Multiple Method User Supplied Array XSS
|
| Views: 688 |
20954
Description:
VP-ASP Shopping Cart contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the "UserName" variable upon submission to the shopadmin.asp script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2005-11-18
|
VP-ASP Shopping Cart shopadmin.asp UserName Parameter XSS
|
| Views: 584 |
31612
Description:
(Description Provided by CVE) : SQL injection vulnerability in email.php in MGB OpenSource Guestbook 0.5.4.5 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.
|
2007-01-17
|
MGB email.php id Parameter SQL Injection
|
| Views: 573 |
32781
Description:
PHP contains a flaw that may allow a malicious user to access arbitrary memory addresses. The issue is due to the shared memory (shmop) function failing to verify if the type of resource supplied is a shmop resource. By using other types of resources it is possible to read and write to shared memory addresses resulting in a loss of integrity and/or availability.
|
2007-03-08
|
PHP shmop Function Arbitrary Memory Manipulation
|
| Views: 550 |
21221
Description:
Gallery contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the remote image url upon submission to the "Add Image From Web" feature. This could allow a user to create a specially crafted page that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2005-11-29
|
Gallery Add Image From Web XSS
|
| Views: 522 |
27920
Description:
XMB contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate data posted in the forum. Especially the <IMG SRC> tag. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2006-01-18
|
XMB IMG Element SRC Attribute XSS
|
| Views: 393 |
65465
Description:
WMS-CMS contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the 'printpage.asp' script not properly sanitizing user-supplied input to the 'psPrice', 'pr' and 'sbr' parameters. This may allow an attacker to inject or manipulate SQL queries in the back-end database, allowing for the manipulation or disclosure of arbitrary data.
|
2010-06-06
|
WMS-CMS printpage.asp Multiple Parameter SQL Injection
|
| Views: 306 |
72005
Description:
Joostina contains a flaw that allows a remote cross-site scripting (XSS) attack. This flaw exists because the com_search component does not validate the 'ordering' parameter upon submission to the index.php script. This may allow a user to create a specially crafted URL that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2011-01-08
|
Joostina index.php com_search Component ordering Parameter XSS
|
| Views: 224 |
3606
Description:
b2evolution contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the "s" variable upon submission to the noskin_b.php script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2003-09-09
|
b2evolution noskin_b.php XSS
|
| Views: 219 |
3601
Description:
b2evolution contains a flaw that will allow an attacker to inject arbitrary SQL code. The problem is that the "s" variable in the noskin_a.php module is not verified properly and will allow an attacker to inject or manipulate SQL queries.
|
2003-09-09
|
b2evolution noskin_a.php SQL Injection
|
| Views: 216 |
3604
Description:
b2evolution contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the "s" variable upon submission to the noskin_all.php script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2003-09-09
|
b2evolution noskin_all.php XSS
|
| Views: 216 |
2526
Description:
b2evolution contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the "s" variable upon submission to the noskin_a.php script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2003-09-09
|
b2evolution noskin_a.php XSS
|
| Views: 214 |
3607
Description:
b2evolution contains a flaw that will allow an attacker to inject arbitrary SQL code. The problem is that the "s" variable in the noskin_roll.php module is not verified properly and will allow an attacker to inject or manipulate SQL queries.
|
2003-09-09
|
b2evolution noskin_roll.php SQL Injection
|
| Views: 201 |
67580
Description:
PHP Gästebuch Script contains a flaw that may allow a remote attacker to execute arbitrary commands or code. The issue is due to the 'guestbook/gbook.php' script not properly sanitizing user input, specifically directory traversal style attacks (e.g., ../../) supplied to the 'script_pfad' parameter. This may allow an attacker to include a file from the targeted host that contains arbitrary commands or code that will be executed by the vulnerable script. Such attacks are limited due to the script only calling files already on the target host. In addition, this flaw can potentially be used to disclose the contents of any file on the system accessible by the web server.
|
2010-08-27
|
PHP Gästebuch Script guestbook/gbook.php script_pfad Parameter Local File Inclusion
|
| Views: 200 |
37432
Description:
(Description Provided by CVE) : PHP remote file inclusion vulnerability in games.php in Sam Crew MyBlog, possibly 1.0 through 1.6, allows remote attackers to execute arbitrary PHP code via a URL in the id parameter, a different vector than CVE-2007-1968. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
|
2007-04-09
|
MyBlog games.php id Parameter Remote File Inclusion
|
| Views: 198 |
69546
Description:
Pandora FMS contains a flaw that may allow a remote attacker to execute arbitrary commands or code. The issue is due to the ajax.php script not properly sanitizing user input supplied to the 'page' parameter. This may allow an attacker to include a file from a third-party remote host that contains commands or code that will be executed by the vulnerable script with the same privileges as the web server.
|
2010-11-30
|
Pandora FMS ajax.php page Parameter Remote File Inclusion
|
| Views: 195 |
33370
Description:
(Description Provided by CVE) : Multiple directory traversal vulnerabilities in openmedia allow remote attackers to read arbitrary files via a .. (dot dot) in the (1) src parameter to page.php or the (2) format parameter to search_form.php.
|
2007-01-02
|
openmedia page.php src Parameter Traversal Arbitrary File Access
|
| Views: 193 |
36568
Description:
Ahhp-Portal contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to the page.php script not properly sanitizing user input supplied to the 'fp' or the 'sc' variable. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script.
|
2007-04-25
|
Ahhp-Portal page.php Multiple Parameter Remote File Inclusion
|
| Views: 190 |
24987
Description:
Instant Photo Gallery contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the portfolio_photo_popup.php script not properly sanitizing user-supplied input to the 'id' variable. This may allow an attacker to inject or manipulate SQL queries in the back-end database.
|
2006-04-26
|
Instant Photo Gallery portfolio_photo_popup.php id Parameter SQL Injection
|
| Views: 189 |
70954
Description:
Photopad contains a flaw that allows a remote cross-site scripting (XSS) attack. This flaw exists because the application does not validate the 'id' parameter upon submission to the gallery.php script. This may allow a user to create a specially crafted URL that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2011-02-15
|
Photopad gallery.php id Parameter XSS
|
| Views: 186 |
65994
Description:
phpaaCMS contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the 'show.php' script not properly sanitizing user-supplied input to the 'id' parameter. This may allow an attacker to inject or manipulate SQL queries in the back-end database, allowing for the manipulation or disclosure of arbitrary data.
|
2010-07-04
|
phpaaCMS show.php id Parameter SQL Injection
|
| Views: 185 |
28364
Description:
Cybozu Garoon contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the phonemessage Facility not properly sanitizing user-supplied input to the 'uid' variable. This may allow an attacker to inject or manipulate SQL queries in the back-end database.
|
2006-08-28
|
Cybozu Garoon phonemessage Facility uid Parameter SQL Injection
|
| Views: 184 |
17563
Description:
paFAQ contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate 'id' variable upon submission to the index.php script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2005-06-20
|
paFAQ index.php id Parameter XSS
|
| Views: 184 |
24986
Description:
Instant Photo Gallery contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the 'id' variable upon submission to the portfolio_photo_popup.php script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2006-04-25
|
Instant Photo Gallery portfolio_photo_popup.php id Parameter XSS
|
| Views: 184 |
25275
Description:
Fast Click SQL Lite contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to show.php not properly sanitizing user input supplied to the 'path' variable. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script.
|
2006-05-02
|
Fast Click SQL Lite show.php path Parameter Remote File Inclusion
|
| Views: 180 |
21696
Description:
EncapsGallery contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the 'gallery.php' script not properly sanitizing user-supplied input to the 'id' variable. This may allow an attacker to inject or manipulate SQL queries in the back-end database.
|
2005-12-13
|
EncapsGallery gallery.php id Parameter SQL Injection
|
| Views: 177 |
94023
Description:
ownCloud contains multiple flaws that allow persistent cross-site scripting (XSS) attacks. These flaw exists because the application does not validate certain unspecified input upon submission to the core/js/oc-dialogs.js script. This may allow an attacker to create a specially crafted request that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2013-06-07
|
ownCloud core/js/oc-dialogs.js Multiple Unspecified XSS
|
| Views: 151 |
94127
Description:
Microsoft Office contains an overflow condition that is triggered as user-supplied input is not properly validated when handling a specially crafted PNG file. This PNG file may be embedded in another office file, such as a .doc, .ppt, etc. This may allow a context-dependent attacker to cause a buffer overflow, resulting in a denial of service or potentially allowing the execution of arbitrary code.
|
2013-06-11
|
Microsoft Office PNG File Handling Buffer Overflow
|
| Views: 142 |
94128
Description:
Adobe Flash Player and AIR contain an unspecified flaw that is triggered as user-supplied input is not properly sanitized. This may allow a context-dependent attacker to corrupt memory and cause a denial of service or potentially execute arbitrary code.
|
2013-06-11
|
Adobe Flash Player / AIR Unspecified Memory Corruption
|
| Views: 135 |
4030
Description:
The TCP stack implementation of numerous vendors contains a flaw that may allow a remote denial of service. The issue is triggered when spoofed TCP Reset packets are received by the targeted TCP stack, and will result in loss of availability for the attacked TCP services.
|
2004-04-20
|
TCP/IP Sequence Prediction Blind Reset Spoofing DoS
|
| Views: 129 |
12184
Description:
PHP contains a flaw that may lead to an unauthorized information disclosure. The issue is triggered when a remote attacker makes certain HTTP requests with crafted arguments, which will disclose PHP version and another sensitive information resulting in a loss of confidentiality.
|
2004-11-28
|
PHP expose_php Directive Version / Information Disclosure
|
| Views: 128 |
90582
Description:
Nagios Remote Plugin Executor (NRPE) contains a flaw that is triggered when input passed via $() is not properly sanitized before being used in plugins/scripts. When used under bash this will cause the injected shell command to be executed under a subprocess.
|
2013-02-21
|
Nagios NRPE Crafted Request Arbitrary Command Injection
|
| Views: 121 |
94105
Description:
Microsoft Internet Explorer contains an unspecified flaw that is triggered as user-supplied input is not properly sanitized. This may allow a context-dependent attacker to corrupt memory and cause a denial of service or potentially execute arbitrary code.
|
2013-06-11
|
Microsoft IE Unspecified Memory Corruption (2013-3110)
|
| Views: 115 |
23597
Description:
Gallery contains a flaw that allows a remote attacker to delete files outside of the web path. The issue is due to the GallerySession.class not properly sanitizing user input, specifically directory traversal style attacks (../../) supplied via the sessionId variable(s).
|
2006-03-02
|
Gallery Session Handling Class (GallerySession.class) Cookie Traversal Arbitrary File Manipulation
|
| Views: 114 |
94193
Description:
Juniper Junos Pulse Secure Access Service and Pulse Access Control Service contains a flaw related to certificate validation. The issue is due to the program placing a test Certification Authority (CA) in the Trusted Server CA list. This may allow an attacker with access to network traffic (e.g. MiTM, DNS cache poisoning) to spoof the SSL server via this certificate. Such an attack would allow for the interception of sensitive traffic, and potentially allow for the injection of content into the SSL stream.
|
2013-06-12
|
Juniper Junos Pulse Secure Access Service (SSL VPN) / Pulse Access Control Service (UAC) Test CA MiTM Spoofing Weakness
|
| Views: 114 |
70
Description:
(Description Provided by CVE) : A service or application has a backdoor password that was placed there by the developer.
|
1990-01-01
|
Multiple Linux FTP Default Login
|