|
65465
|
Views: 850
Description:
WMS-CMS contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the 'printpage.asp' script not properly sanitizing user-supplied input to the 'psPrice', 'pr' and 'sbr' parameters. This may allow an attacker to inject or manipulate SQL queries in the back-end database, allowing for the manipulation or disclosure of arbitrary data.
Comments: 0, Blogs: 0, References: 9
Vulnerability Classification
| Location | Attack Type | Impact | Solution | Exploit | Disclosure | OSVDB |
|---|
| - Information Disclosure
- Input Manipulation
| - Loss of Confidentiality
- Loss of Integrity
| | | | |
|
WMS-CMS printpage.asp Multiple Parameter SQL Injection
|
|
13002
|
Views: 315
Description:
AWStats contains a flaw that may allow a malicious user to issue arbitray commands under the web server privileges. The issue is triggered when using the pipe character (|) and shell metacaracters in the 'configdir' variable of the awstats.pl script. Such input is not santitized before being passed to the perl 'open()' command to be executed.
Comments: 0, Blogs: 0, References: 24
Vulnerability Classification
| Location | Attack Type | Impact | Solution | Exploit | Disclosure | OSVDB |
|---|
| | | | - Exploit Public
- Exploit Commercial
| | |
|
AWStats awstats.pl configdir Parameter Arbitrary Command Execution
|
|
76733
|
Views: 266
Description:
Digital College contains a flaw that may allow a remote attacker to execute arbitrary commands or code. The issue is due to the includes/tiny_mce/plugins/filemanager/classes/FileManager/FileManagerPlugin.php script not properly sanitizing user input supplied to the 'basepath' parameter. This may allow an attacker to include a file from a third-party remote host that contains commands or code that will be executed by the vulnerable script with the same privileges as the web server.
Comments: 0, Blogs: 0, References: 6
Vulnerability Classification
| Location | Attack Type | Impact | Solution | Exploit | Disclosure | OSVDB |
|---|
| | | | | | |
|
Digital College includes/tiny_mce/plugins/filemanager/classes/FileManager/FileManagerPlugin.php basepath Parameter Remote File Inclusion
|
|
76780
|
Views: 255
Description:
Magtrb MyNews contains a flaw that may allow a remote attacker to execute arbitrary commands or code. The issue is due to the includes/tiny_mce/plugins/filemanager/classes/FileManager/FileManagerPlugin.php script not properly sanitizing user input supplied to the 'basename' parameter. This may allow an attacker to include a file from a third-party remote host that contains commands or code that will be executed by the vulnerable script with the same privileges as the web server.
Comments: 0, Blogs: 0, References: 6
Vulnerability Classification
| Location | Attack Type | Impact | Solution | Exploit | Disclosure | OSVDB |
|---|
| | | | | | |
|
Magtrb MyNews includes/tiny_mce/plugins/filemanager/classes/FileManager/FileManagerPlugin.php basename Parameter Remote File Inclusion
|
|
18293
|
Views: 231
Description:
By default, many Belkin 54G wireless routers using a default ssid of "belkin54g" are preconfigured with a default password. The "admin" account has a null password which is publicly known and documented. This allows attackers to trivially access the program or system as the routers come preconfigured with remote telnet access enabled.
Comments: 1, Blogs: 0, References: 5
Vulnerability Classification
| Location | Attack Type | Impact | Solution | Exploit | Disclosure | OSVDB |
|---|
| - Authentication Management
| | | | | |
|
Belkin 54G Routers Admin Account Default Null Password
|
|
13834
|
Views: 227
Description:
(Description Provided by CVE) : awstats.pl in AWStats 6.3 and 6.4 allows remote attackers to obtain sensitive information by setting the debug parameter.
Comments: 0, Blogs: 0, References: 13
Vulnerability Classification
| Location | Attack Type | Impact | Solution | Exploit | Disclosure | OSVDB |
|---|
| | | | | | |
|
AWStats awstats.pl debug mode Information Disclosure
|
|
66441
|
Views: 223
Description:
By default, Siemens SIMATIC installs with a default password. The 'WinCCConnect' and 'WinCCAdmin' accounts have a password of '2WSXcder' which is publicly known and documented. This allows attackers to trivially access the program or system.
Comments: 0, Blogs: 0, References: 26
Vulnerability Classification
| Location | Attack Type | Impact | Solution | Exploit | Disclosure | OSVDB |
|---|
| - Authentication Management
| | - Solution Unknown
- Change Default Setting
| | - Discovered in the Wild
- Vendor Verified
- Uncoordinated Disclosure
| |
|
Siemens SIMATIC WinCC Default Password
|
|
62780
|
Views: 151
Description:
Bild Flirt Community contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the 'index.php' script not properly sanitizing user-supplied input to the 'id' parameter. This may allow an attacker to inject or manipulate SQL queries in the back-end database, allowing for the manipulation or disclosure of arbitrary data.
Comments: 0, Blogs: 0, References: 8
Vulnerability Classification
| Location | Attack Type | Impact | Solution | Exploit | Disclosure | OSVDB |
|---|
| - Input Manipulation
- Information Disclosure
| - Loss of Confidentiality
- Loss of Integrity
| | | - Uncoordinated Disclosure
- Third-party Verified
| |
|
Bild Flirt Community index.php id Parameter SQL Injection
|
|
62923
|
Views: 142
Description:
Domain Verkaus & Auktions Portal contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the 'index.php' script (when 'a' is set to 'd') not properly sanitizing user-supplied input to the 'id' parameter. This may allow an attacker to inject or manipulate SQL queries in the back-end database, allowing for the manipulation or disclosure of arbitrary data.
Comments: 0, Blogs: 0, References: 6
Vulnerability Classification
| Location | Attack Type | Impact | Solution | Exploit | Disclosure | OSVDB |
|---|
| - Input Manipulation
- Information Disclosure
| - Loss of Integrity
- Loss of Confidentiality
| | | | |
|
Domain Verkaus & Auktions Portal index.php id Parameter SQL Injection
|
|
78443
|
Views: 139
Description:
Oracle VM VirtualBox contains a flaw related to the Shared Folders component that may allow a local attacker to affect confidentiality and integrity. No further details have been provided.
Comments: 0, Blogs: 0, References: 6
Vulnerability Classification
| Location | Attack Type | Impact | Solution | Exploit | Disclosure | OSVDB |
|---|
| | - Loss of Confidentiality
- Loss of Integrity
| | | | |
|
Oracle VM VirtualBox Shared Folders Component Unspecified Local Issue
|