| Blogs | OSVDB ID | Disclosure Date | Title |
| Views: 55 |
28068
Description:
Guestbook contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the 'page' form field parameter upon submission to the gbook.php script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2006-08-21
|
Doika Guestbook gbook.php page XSS
|
| Views: 54 |
94328
Description:
HAProxy contains a flaw that may allow a remote denial of service. The issue is triggered when the program does not account for wrapping with a negative number when handling an incoming header field. This may allow a remote attacker to crash the program.
|
2013-06-18
|
HAProxy Header Field Handling Remote DoS
|
| Views: 54 |
94324
Description:
WHMPHP contains a flaw that is due to the program failing to properly restrict access to the /admin/changepwd.php script. This may allow a remote unauthenticated attacker to change the administrative password.
|
2013-06-15
|
WHMPHP /admin/changepwd.php Unauthenticated Admin Password Manipulation
|
| Views: 54 |
94236
Description:
X.Org xdm contains a flaw in the crypt() function that may allow a remote denial of service. The issue is due to a NULL pointer dereference, which may allow a remote attacker to crash the program.
|
2013-06-07
|
X.Org xdm crypt() Function NULL Pointer Dereference Remote DoS
|
| Views: 54 |
94124
Description:
Microsoft Windows Kernel contains a flaw that may lead to the unauthorized disclosure of sensitive information. The issue is triggered during the handling of page fault system calls. This may allow a local attacker to gain access to potentially sensitive information related to kernel addresses.
|
2013-06-11
|
Microsoft Windows Kernel Page Fault System Call Handling Local Information Disclosure
|
| Views: 54 |
93645
Description:
Apache Struts contains a flaw that may allow an attacker to execute arbitrary commands. The issue is due to the handling of the includeParams attribute in the URL and Anchor tags. With a specially crafted request parameter, an attacker could inject arbitrary OGNL code that would be evaluated. In addition, a second evaluation of attacker supplied input can occur when the URL or Anchor tag tries to resolve arbitrary parameters, that would be evaluated as an OGNL expression.
|
2013-05-23
|
Apache Struts URL / Anchor Tag includeParams Attribute Remote Command Execution
|
| Views: 54 |
90734
Description:
By default, XEROX WorkCentre installs with default user credentials (username/password combination) for the web console. The 'admin' account has a password of '1111', which is publicly known and documented. This allows remote attackers to trivially access the program or system and gain privileged access.
|
2013-02-27
|
XEROX WorkCentre Web Console Default Administrator Password
|
| Views: 54 |
56387
Description:
Secure Sockets Layer (SSL) version 2 (v2) has been found to contain several weaknesses. Depending on the time and resources of an attacker, any communication protected by SSLv2 may be vulnerable to Man-in-The-Middle (MiTM) attacks that could allow data tampering or disclosure. SSLv2 flaws in summary: - SSL encrypted web requests traffic analysis can disclose which pages were downloaded, length of data downloaded, what web servers were accessed and more. This requires sniffing or physical access and is considered a passive attack. - Bellovin cut-and-paste attack. This requires sniffing and MiTM manipulation and is considered an active attack. - Bellovin short-block attack. This requires sniffing and MiTM manipulation and is considered an active attack. - Insecure MAC use post-encryption. This is considered a design flaw weakness. - Horton Principle failure. This requires sniffing and MiTM manipulation and is considered an active attack. - Ciphersuite rollback attack. This requires sniffing and MiTM manipulation. - Diffie-hellman Key-exchange MiTM attack. - 40-bit MAC use. This is considered a design flaw weakness.
|
1996-11-01
|
SSLv2 Protocol Multiple Weaknesses
|
| Views: 54 |
12246
Description:
Advanced Guestbook contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the entry variable upon submission to the index.php script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2004-12-02
|
Advanced Guestbook index.php entry Parameter XSS
|
| Views: 53 |
94157
Description:
PHP Ticket System contains a flaw that allows a remote Cross-site Request Forgery (CSRF / XSRF) attack. The flaw exists because the application does not require multiple steps or explicit confirmation for sensitive transactions. By using a crafted URL (e.g., a crafted GET request inside an "img" tag), an attacker may trick the victim into clicking on the image to take advantage of the trust relationship between the authenticated victim and the application. Such an attack could trick the victim into changing a user's password in the context of their session with the application, without further prompting or verification.
|
2013-06-07
|
PHP Ticket System Password Manipulation CSRF
|
| Views: 53 |
94016
Description:
IBM AIX contains a flaw that leads to unauthorized privileges being gained. The issue is triggered during the handling of the arp.ib command. This may allow a local attacker to gain elevated privileges.
|
2013-06-05
|
IBM AIX arp.ib Command Handling Local Privilege Escalation
|
| Views: 52 |
67535
Description:
Microsoft Windows Progman Group Converter (grpconv.exe) is prone to a flaw in the way it loads dynamic-link libraries (e.g., imm.dll). The program uses a fixed path to look for specific files or libraries. This path includes directories that may not be trusted or under user control. By placing a custom version of the file or library in the path, the program will load it before the legitimate version. This allows an attacker to inject custom code that will be run with the privilege of the program or user executing the program. This can be done by tricking a user into opening a .grp file from the local file system or a USB drive in some cases. This attack can be leveraged remotely in some cases by placing the malicious file or library on a network share or extracted archive downloaded from a remote source.
|
2010-08-25
|
Microsoft Windows Progman Group Converter Path Subversion Arbitrary DLL Injection Code Execution
|
| Views: 52 |
32840
Description:
Indexu contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the 'error_msg' variable upon submission to the suggest_category.php script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2007-01-16
|
Indexu suggest_category.php error_msg Parameter XSS
|
| Views: 51 |
94142
Description:
RuubikCMS contains a flaw that allows a persistent cross-site scripting (XSS) attack. This flaw exists because the application does not validate the 'name' parameter upon submission to the index.php script. This may allow an attacker to create a specially crafted request that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2013-06-07
|
RuubikCMS index.php name Parameter XSS
|
| Views: 51 |
50194
Description:
Pligg contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the 'cloud.php' script not properly sanitizing user-supplied input to the 'categoryID' parameter. This may allow an attacker to inject or manipulate SQL queries in the back-end database.
|
2008-07-30
|
Pligg cloud.php categoryID Parameter SQL Injection
|
| Views: 51 |
2946
Description:
Web Wiz Forums contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the "find" variable upon submission to the forum_members.asp script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2003-10-21
|
Web Wiz Forums forum_members.asp XSS
|
| Views: 51 |
25600
Description:
A remote overflow exists in Mac OS X Server. The Quicktime Streaming Server fails to validate RTSP requests resulting in a buffer overflow. With a specially crafted request, an attacker can cause arbitrary code execution resulting in a loss of integrity.
|
2006-05-08
|
Apple Mac OS X Server QuickTime Streaming Server RTSP Request DoS
|
| Views: 51 |
18293
Description:
By default, many Belkin 54G wireless routers using a default ssid of "belkin54g" are preconfigured with a default password. The "admin" account has a null password which is publicly known and documented. This allows attackers to trivially access the program or system as the routers come preconfigured with remote telnet access enabled.
|
2005-07-15
|
Belkin 54G Routers Admin Account Default Null Password
|
| Views: 50 |
94172
Description:
FFmpeg contains a NULL pointer dereference flaw in the jpeg2000_decode_tile function in libavcodec/jpeg2000dec.c that may allow a context-dependent attacker to cause a denial of service. No further details have been provided by the vendor.
|
2013-06-06
|
FFmpeg libavcodec/jpeg2000dec.c jpeg2000_decode_tile Function NULL Pointer Dereference DoS
|
| Views: 50 |
94126
Description:
Microsoft Windows contains a flaw in the Print Spooler that leads to unauthorized privileges being gained. The issue is triggered during the handling of memory when a printer has been deleted. This may allow a local attacker to gain elevated privileges.
|
2013-06-11
|
Microsoft Windows Print Spooler Printer Deletion Memory Handling Local Privilege Escalation
|
| Views: 49 |
94013
Description:
CTERA Portal contains a flaw that may allow a remote attacker to bypass the account lock mechanism. By using the WEBDAV authentication, the system does not count failed logins toward the lockout threshold.
|
2013-06-05
|
CTERA Portal WEBDAV Authentication Account Lockout Bypass
|
| Views: 49 |
94011
Description:
CTERA Portal contains a flaw that allows a persistent cross-site scripting (XSS) attack. This flaw exists because the application does not validate input passed via a file name before returning it to the user. This may allow an attacker to create a specially crafted request that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2013-06-05
|
CTERA Portal File Name XSS
|
| Views: 49 |
94012
Description:
CTERA Portal contains an XXE (Xml eXternal Entity) injection flaw that is triggered during the parsing of XML data. The issue is due to an incorrectly configured XML parser accepting XML external entities from an untrusted source. By sending specially crafted XML data, a remote attacker can gain access to arbitrary files.
|
2013-06-05
|
CTERA Portal XML External Entity (XXE) Data Parsing Arbitrary File Disclosure
|
| Views: 49 |
94010
Description:
JBoss Application Server contains a flaw that may lead to the unauthorized disclosure of sensitive information. The issue is due to datasources in the resources section transmitting password information as cleartext. This may allow a remote attacker that is sniffing a user's traffic to gain access to password information.
|
2013-06-03
|
JBoss Application Server Admin Console Datasource Resource Cleartext Password Disclosure
|
| Views: 49 |
93977
Description:
QNAP VioStor NVR and NAS contain a flaw that allows a remote cross-site scripting (XSS) attack. This flaw exists because the application does not validate the 'ping_ip' parameter upon submission to the /cgi-bin/pingping.cgi script. This may allow an attacker to create a specially crafted request that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2013-06-05
|
QNAP VioStor NVR / NAS /cgi-bin/pingping.cgi ping_ip Parameter XSS
|
| Views: 49 |
93972
Description:
IBM Tivoli Netcool System Service Monitor (SSM) and Application Service Monitor (ASM contain an overflow condition in the Transaction MIB agent. The issue is triggered as user-supplied input is not properly validated by certain packet decoders during the handling of a malformed SQL table name that is larger than 255 characters. This may allow a remote attacker to cause a buffer overflow, resulting in a denial of service. With a specially crafted transaction that is read by the Transaction MIB sub agent, the attacker can potentially further utilize this vulnerability to execute arbitrary code.
|
2013-05-31
|
IBM Tivoli Netcool SSM / ASM Transaction MIB Agent SQL Table Name Handling Remote Overflow
|
| Views: 49 |
93754
Description:
Synactis PDF In-The-Box contains an overflow condition in the PDF In-The-Box ActiveX control (PDF_In_The_Box.ocx). The issue is triggered as the aPageRef argument is not properly validated when passed via the ConnectToSynactis() method. With a specially crafted overly long string, a context-dependent attacker can cause a stack-based buffer overflow, resulting in a denial of service or potentially allowing the execution of arbitrary code.
|
2013-05-30
|
Synactis PDF In-The-Box ActiveX (PDF_In_The_Box.ocx) ConnectToSynactis() Method Stack Buffer Overflow
|
| Views: 49 |
49243
Description:
Microsoft Windows Server Service contains a flaw that may allow a malicious user to remotely execute arbitrary code. The issue is triggered when a crafted RPC request is handled. It is possible that the flaw may allow remote code execution resulting in a loss of integrity.
|
2008-10-23
|
Microsoft Windows Server Service Crafted RPC Request Handling Unspecified Remote Code Execution
|
| Views: 48 |
94331
Description:
TaxiMonger for Android contains a flaw that allows a persistent cross-site scripting (XSS) attack. This flaw exists because the application does not validate input passed via the 'Username' field in the registration module. This may allow an attacker to create a specially crafted request that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2013-06-15
|
TaxiMonger for Android Registration Username XSS
|
| Views: 48 |
94310
Description:
EC-CUBE contains a flaw that allows a remote cross-site scripting (XSS) attack. This flaw exists because the application does not validate the 'email' and 'tel01' fields upon submission to the LC_Page_Contact.php script. This may allow an attacker to create a specially crafted request that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2010-02-08
|
EC-CUBE LC_Page_Contact.php Multiple Field XSS
|
| Views: 48 |
94112
Description:
Microsoft Internet Explorer contains an unspecified flaw that is triggered as user-supplied input is not properly sanitized. This may allow a context-dependent attacker to corrupt memory and cause a denial of service or potentially execute arbitrary code.
|
2013-06-11
|
Microsoft IE Unspecified Memory Corruption (2013-3118)
|
| Views: 48 |
94106
Description:
Microsoft Internet Explorer contains an unspecified flaw that is triggered as user-supplied input is not properly sanitized. This may allow a context-dependent attacker to corrupt memory and cause a denial of service or potentially execute arbitrary code.
|
2013-06-11
|
Microsoft IE Unspecified Memory Corruption (2013-3111)
|
| Views: 48 |
93995
Description:
FFmpeg and Libav contain a NULL pointer dereference in the decode_frame function in libavcodec/h264.c. This issue may allow a context-dependent attacker to crash the program.
|
2013-01-11
|
FFmpeg / Libav libavcodec/h264.c decode_frame Function NULL Pointer Dereference DoS
|
| Views: 48 |
93282
Description:
nginx contains a flaw when proxy_pass is used that may lead to unauthorized disclosure of sensitive information. The issue is triggered during the handling of a specially crafted response from an upstream proxied server. This may allow a remote attacker to gain access to worker process memory or potentially cause a denial of service.
|
2013-05-13
|
nginx proxy_pass Crafted Upstream Proxied Server Response Handling Worker Process Memory Disclosure
|
| Views: 47 |
94326
Description:
SPBAS Business Automation Software contains a flaw that allows a persistent cross-site scripting (XSS) attack. This flaw exists because the application does not validate input passed via the 'first name', 'last name', and 'security question' fields in the client info section. This may allow an attacker to create a specially crafted request that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2013-06-16
|
SPBAS Business Automation Software Client Info Multiple Field XSS
|
| Views: 47 |
94175
Description:
FFmpeg contains an unspecified out-of-bounds read flaw in the tiff_unpack_strip function in libavcodec/tiff.c that may allow a context-dependent attacker to have an unspecified impact. No further detail have been provided by the vendor.
|
2013-06-07
|
FFmpeg libavcodec/tiff.c tiff_unpack_strip Function Out-of-bounds Read Access Issue
|
| Views: 47 |
94153
Description:
IBM Informix Dynamic Server contains a flaw that is triggered as user-supplied input is not properly sanitized when re-using prepared statements that contain multisets. This may allow a remote attacker to corrupt memory and cause a denial of service or potentially execute arbitrary code.
|
2013-04-18
|
IBM Informix Dynamic Server Prepared Multiset Statement Re-use Remote Memory Corruption
|
| Views: 47 |
94145
Description:
RuubikCMS contains a flaw that allows a persistent cross-site scripting (XSS) attack. This flaw exists because the application does not validate the 'firstname' and 'lastname' parameters upon submission to the users.php script. This may allow an attacker to create a specially crafted request that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2013-06-07
|
RuubikCMS users.php Multiple Parameter XSS
|
| Views: 47 |
94143
Description:
RuubikCMS contains a flaw that allows a persistent cross-site scripting (XSS) attack. This flaw exists because the application does not validate the 'name' parameter upon submission to the extranet.php script. This may allow an attacker to create a specially crafted request that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2013-06-07
|
RuubikCMS extranet.php name Parameter XSS
|
| Views: 47 |
94113
Description:
Microsoft Internet Explorer contains an unspecified flaw that is triggered as user-supplied input is not properly sanitized. This may allow a context-dependent attacker to corrupt memory and cause a denial of service or potentially execute arbitrary code.
|
2013-06-11
|
Microsoft IE Unspecified Memory Corruption (2013-3119)
|