| Blogs | OSVDB ID | Disclosure Date | Title |
| Views: 2 |
36279
Description:
BBS E-Market contains a flaw that may allow a remote attacker to execute arbitrary commands or code. The issue is due to the 'postscript/postscript.php' script not properly sanitizing user input supplied to the 'p_mode' parameter. This may allow an attacker to include a file from a third-party remote host that contains commands or code that will be executed by the vulnerable script with the same privileges as the web server.
|
2007-07-18
|
BBS E-Market postscript/postscript.php p_mode Parameter Remote File Inclusion
|
| Views: 2 |
37369
Description:
(Description Provided by CVE) : Unspecified vulnerability in the info request mechanism in LAN Messenger before 1.5.1.2 allows remote attackers to cause a denial of service (application crash) or transmit spam via unspecified vectors.
|
2007-06-16
|
LAN Messenger Info Request Mechanism Unspecified Remote DoS
|
| Views: 2 |
38090
Description:
Unknown / Incomplete
|
2007-07-12
|
IAIK XSECT / IXSIL XSLT Stylesheet Handling Arbitrary Code Execution
|
| Views: 2 |
38405
Description:
(Description Provided by CVE) : SQL injection vulnerability in articles.php in E-Vendejo 0.2 allows remote attackers to execute arbitrary SQL commands via the id parameter.
|
2007-10-29
|
E-Vendejo articles.php id Parameter SQL Injection
|
| Views: 2 |
38824
Description:
E-Lite POS contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the 'default.asp' script not properly sanitizing user-supplied input to the 'username' variable. This may allow an attacker to inject or manipulate SQL queries in the back-end database.
|
2007-11-24
|
E-Lite POS default.asp username Parameter SQL Injection
|
| Views: 2 |
38825
Description:
Unknown / Incomplete
|
2007-11-24
|
E-Lite POS Error Message User Account Information Disclosure
|
| Views: 2 |
38827
Description:
JAF CMS contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the 'show' variable upon submission to the 'index.php' script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2007-11-26
|
JAF CMS index.php show Parameter XSS
|
| Views: 2 |
39317
Description:
Indexu contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to 'admin/message_delete.php' not properly sanitizing user input supplied to the 'admin_template_path' variable. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script.
|
2006-06-16
|
Indexu admin/message_delete.php admin_template_path Parameter Remote File Inclusion
|
| Views: 2 |
39299
Description:
Indexu contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to 'admin/user_delete.php' not properly sanitizing user input supplied to the 'admin_template_path' variable. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script.
|
2006-06-16
|
Indexu admin/user_delete.php admin_template_path Parameter Remote File Inclusion
|
| Views: 2 |
39300
Description:
Indexu contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to 'admin/template_modify.php' not properly sanitizing user input supplied to the 'admin_template_path' variable. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script.
|
2006-06-16
|
Indexu admin/template_modify.php admin_template_path Parameter Remote File Inclusion
|
| Views: 2 |
39302
Description:
Indexu contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to 'admin/template_manager.php' not properly sanitizing user input supplied to the 'admin_template_path' variable. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script.
|
2006-06-16
|
Indexu admin/template_manager.php admin_template_path Parameter Remote File Inclusion
|
| Views: 2 |
39319
Description:
Indexu contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to 'admin/link_edit.php' not properly sanitizing user input supplied to the 'admin_template_path' variable. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script.
|
2006-06-16
|
Indexu admin/link_edit.php admin_template_path Parameter Remote File Inclusion
|
| Views: 2 |
39320
Description:
Indexu contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to 'admin/link_premium_sponsored.php' not properly sanitizing user input supplied to the 'admin_template_path' variable. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script.
|
2006-06-16
|
Indexu admin/link_premium_sponsored.php admin_template_path Parameter Remote File Inclusion
|
| Views: 2 |
39303
Description:
Indexu contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to 'admin/template_import.php' not properly sanitizing user input supplied to the 'admin_template_path' variable. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script.
|
2006-06-16
|
Indexu admin/template_import.php admin_template_path Parameter Remote File Inclusion
|
| Views: 2 |
39304
Description:
Indexu contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to 'admin/template_rename.php' not properly sanitizing user input supplied to the 'admin_template_path' variable. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script.
|
2006-06-16
|
Indexu admin/template_rename.php admin_template_path Parameter Remote File Inclusion
|
| Views: 2 |
39306
Description:
Indexu contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to 'admin/template_duplicate.php' not properly sanitizing user input supplied to the 'admin_template_path' variable. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script.
|
2006-06-16
|
Indexu admin/template_duplicate.php admin_template_path Parameter Remote File Inclusion
|
| Views: 2 |
39307
Description:
Indexu contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to 'admin/template_delete_file.php' not properly sanitizing user input supplied to the 'admin_template_path' variable. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script.
|
2006-06-16
|
Indexu admin/template_delete_file.php admin_template_path Parameter Remote File Inclusion
|
| Views: 2 |
2750
Description:
X.25 contains a flaw that may allow a remote denial of service. The issue is triggered when malformed SNMP Requests are mishandled by the snmpx25d daemon, and will result in loss of availability for the X.25 service.
|
2003-10-22
|
Solaris Solstice X.25 Crafted SNMP Request DoS
|
| Views: 2 |
8449
Description:
IRIX contains a flaw that may allow a malicious user to gain access to unauthorized privileges. The issue is triggered when a malicious user can use the /usr/lib/desktop/permissions tool to modify the permissions of any file on the system. This flaw may lead to a loss of integrity.
|
1995-03-03
|
IRIX Desktop Permissions Tool File Modification Privilege Escalation
|
| Views: 2 |
11160
Description:
IRIX contains a networking flaw related to its bsd.a kernel that may allow t_unbind to change the behavior of t_bind. No further details have been provided.
|
2004-09-29
|
IRIX bsd.a Kernel t_bind t_unbind Unspecified
|
| Views: 2 |
35100
Description:
(Description Provided by CVE) : Grayscale Blog 0.8.0, and possibly earlier versions, allows remote attackers to gain privileges via direct requests with modified arguments in (1) the user_permissions parameter to add_users.php, and unspecified parameters to (2) addblog.php, (3) editblog.php, (4) editlinks.php, (5) edit_users.php, and (6) add_links.php.
|
2007-03-10
|
Grayscale Blog add_links.php Unspecified Privilege Escalation
|
| Views: 2 |
39339
Description:
Indexu contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to admin/head.php not properly sanitizing user input supplied to the 'admin_template_path' variable. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script.
|
2006-06-16
|
Indexu admin/head.php admin_template_path Parameter Remote File Inclusion
|
| Views: 2 |
39340
Description:
Indexu contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to admin/db_backup.php not properly sanitizing user input supplied to the 'admin_template_path' variable. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script.
|
2006-06-16
|
Indexu admin/db_backup.php admin_template_path Parameter Remote File Inclusion
|
| Views: 2 |
39342
Description:
Indexu contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to admin/editor_add.php not properly sanitizing user input supplied to the 'admin_template_path' variable. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script.
|
2006-06-16
|
Indexu admin/editor_add.php admin_template_path Parameter Remote File Inclusion
|
| Views: 2 |
39344
Description:
Indexu contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to admin/db_import.php not properly sanitizing user input supplied to the 'admin_template_path' variable. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script.
|
2006-06-16
|
Indexu admin/db_import.php admin_template_path Parameter Remote File Inclusion
|
| Views: 2 |
39345
Description:
Indexu contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to admin/db_export.php not properly sanitizing user input supplied to the 'admin_template_path' variable. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script.
|
2006-06-16
|
Indexu admin/db_export.php admin_template_path Parameter Remote File Inclusion
|
| Views: 2 |
39356
Description:
My Postcards Platinum contains a flaw that allows a remote attacker to read contents outside of the web path. The issue is due to the 'magiccard.cgi' not properly sanitizing user input, specifically directory traversal style attacks (../../) supplied via unspecified variables.
|
2002-06-05
|
My Postcards Platinum magiccard.cgi Directory Traversal
|
| Views: 2 |
6148
Description:
(Description Provided by CVE) : Trend Micro OfficeScan allows remote attackers to replay administrative commands and modify the configuration of OfficeScan clients.
|
2000-03-03
|
Trend Micro OfficeScan Remote Configuration Change
|
| Views: 2 |
26557
Description:
(Description Provided by CVE) : CRLF injection vulnerability in (1) index.php and (2) admin.php in myWebland MyBloggie 2.1.3 allows remote attackers to hijack sessions and conduct cross-site scripting (XSS) attacks via a cookie.
|
2006-05-17
|
myBloggie admin.php CRLF Injection
|
| Views: 2 |
29362
Description:
Unknown / Incomplete
|
2006-06-05
|
MailMarshal ACE Archive Content Filter Bypass
|
| Views: 2 |
30503
Description:
(Description Provided by CVE) : PHP remote file inclusion vulnerability in core/editor.php in phpWebThings 1.5.2 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the editor_insert_bottom parameter.
|
2006-11-18
|
phpWebThings core/editor.php Multiple Parameter Remote File Inclusion
|
| Views: 2 |
33964
Description:
(Description Provided by CVE) : Multiple PHP remote file inclusion vulnerabilities in miniBB 2.0.2 and earlier, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the pathToFiles parameter to (1) bb_func_forums.php, (2) bb_functions.php, or (3) the RSS plugin.
|
2007-03-09
|
miniBB bb_functions.php pathToFiles Parameter Remote File Inclusion
|
| Views: 2 |
38182
Description:
MailMarshal contains a flaw that may allow an attacker to modify arbitrary accounts via the Spam Quarantine interface. The issue is due to the password reset feature in the HTTP interface not properly sanitizing user supplied input. By sending a crafted string in the UserID variable with a large amount of trailing whitespace characters, an attacker can trigger an SQL buffer truncation and modify arbitrary accounts.
|
2007-07-17
|
MailMarshal Spam Quarantine Interface UserID Variable SQL Truncation Arbitrary Account Modification
|
| Views: 2 |
39251
Description:
(Description Provided by CVE) : Coppermine galleries before 1.4.6, when running on Apache with mod_mime installed, allows remote attackers to upload arbitrary files via a filename with multiple file extensions.
|
2006-05-22
|
Coppermine Photo Gallery on Apache Multiple File Extension Upload Arbitrary Code Execution
|
| Views: 2 |
19239
Description:
Unclassified NewsBoard contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the "Description" variable when posting a message. This could allow a user to inject arbitrary HTML and script code that would execute in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2005-09-07
|
Unclassified NewsBoard Description Field XSS
|
| Views: 2 |
35497
Description:
(Description Provided by CVE) : ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2007-2893. Reason: this candidate was intended for one issue, but some sources used this identifier for a separate issue, and a duplicate identifier had also been created by the time dual use was detected. Notes: All CVE users should consult CVE-2007-2893 to determine if it is appropriate. All references and descriptions in this candidate have been removed to prevent accidental usage.
|
2007-05-01
|
QEMU NE2000 Device Registers Integer Signedness Error
|
| Views: 2 |
18046
Description:
Oracle E-Business Suite contain an unspecified flaw related to the Oracle Net component that may allow an attacker connected with a valid session to compromise the confidentiality and/or integrity of a server via SQL injection or parameter manipulation. No further details have been provided.
|
2005-07-12
|
Oracle E-Business Suite SQL portal.wpg_session Unspecified Input Manipulation Issue
|
| Views: 2 |
31940
Description:
(Description Provided by CVE) : Multiple cross-site scripting (XSS) vulnerabilities in PHPOLL 0.96 allow remote attackers to inject arbitrary web script or HTML via the language parameter to (1) index.php, (2) info.php; and (3) index.php, (4) votanti.php, (5) risultati_config.php, (6) modifica_band.php, (7) band_editor.php, and (8) config_editor.php in admin/.
|
2006-11-19
|
PHPOLL index.php language Parameter XSS
|