| OSVDB ID | Disclosure Date | Title |
|
75733
Description:
(Description Provided by CVE) : 111WebCalendar 1.2.3 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by footer.php and certain other files.
|
2011-01-30
|
111WebCalendar Multiple Script Direct Request Path Disclosure
|
|
2126
Description:
121 WAM! Server contains a flaw that allows malicious users to conduct unauthorized directory traversals. This is possible because the "CWD" command doesn't validate the character sequence "/../". A malicious user can use this to access information outside the FTP root.
|
2003-08-06
|
121 WAM! Server Traversal Arbitrary File/Directory Access
|
|
67267
Description:
Unknown / Incomplete
|
2010-08-16
|
123 Flash Chat Cleartext Password Transmission
|
|
67269
Description:
Unknown / Incomplete
|
2010-08-16
|
123 Flash Chat index.html URI XSS
|
|
42849
Description:
(Description Provided by CVE) : ** DISPUTED ** Multiple PHP remote file inclusion vulnerabilities in the 123 Flash Chat Module for phpBB allow remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter to (1) 123flashchat.php and (2) phpbb_login_chat.php. NOTE: CVE disputes this issue because $phpbb_root_path is explicitly set to "./" in both programs.
|
2008-02-28
|
123 Flash Chat Module for phpBB Multiple Script phpbb_root_path Parameter Remote File Inclusion
|
|
22930
Description:
(Description Provided by CVE) : Eval injection vulnerability in 123 Flash Chat Server 5.0 and 5.1 allows attackers to execute arbitrary code via a crafted username.
|
2006-01-24
|
123 Flash Chat Server Eval Injection Privilege Escalation
|
|
22440
Description:
123 Flash Chat Server contains a flaw that allows a remote attacker to write to files outside of the web path. The issue is due to the server not properly sanitizing user input when creating new users, specifically traversal style attacks (../../) supplied via the "user" variable. This flaw may allow a malicious user to gain access to unauthorized privileges and files.
|
2006-01-13
|
123 Flash Chat Server Username Traversal Arbitrary File Access
|
|
67268
Description:
Unknown / Incomplete
|
2010-08-16
|
123 Flash Chat URI Traversal Arbitrary File Access
|
|
59363
Description:
123tkShop contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the 'function_describe_item1.inc.php' script not properly sanitizing user-supplied input to the unspecified parameter. This may allow an attacker to inject or manipulate SQL queries in the back-end database, allowing for the manipulation or disclosure of arbitrary data.
|
2002-07-15
|
123tkShop function_describe_item1.inc.php Unspecified Parameter SQL Injection
|
|
59364
Description:
(Description Provided by CVE) : Directory traversal vulnerability in function_foot_1.inc.php for Thorsten Korner 123tkShop before 0.3.1 allows remote attackers to read arbitrary files via .. (dot dot) sequences terminated by a null character in the $designNo variable, which is part of an "include" function call.
|
2002-07-15
|
123tkShop function_foot_1.inc.php $designNo Parameter Traversal Arbitrary File Access
|
|
43706
Description:
(Description Provided by CVE) : SQL injection vulnerability in shop/mainfile.php in 123tkShop 0.9.1 allows remote attackers to execute arbitrary SQL commands via a base64-encoded value of the admin parameter to shop/admin.php.
|
2007-12-14
|
123tkShop shop/admin.php admin Parameter SQL Injection
|
|
50429
Description:
Unknown / Incomplete
|
2003-04-11
|
12Planet Chat Server Administrator Authentication Cleartext Credential Disclosure
|
|
50428
Description:
Unknown / Incomplete
|
2003-04-11
|
12Planet Chat Server Error Message Path Disclosure
|
|
7464
Description:
12Planet Chat Server contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate page variables upon submission to the one2planet.infolet.InfoServlet CGI applet. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2004-07-05
|
12Planet Chat Server one2planet.infolet.InfoServlet XSS
|
|
46011
Description:
(Description Provided by CVE) : Static code injection vulnerability in guestbook.php in 1Book 1.0.1 and earlier allows remote attackers to upload arbitrary PHP code via the message parameter in an HTML webform, which is written to data.php.
|
2008-06-03
|
1Book guestbook.php Multiple Variable Arbitrary PHP Code Execution
|
|
53815
Description:
A buffer overflow flaw exists in 1by1. 1by1 fails to check boundaries in the processing of m3u files resulting in a stack overflow. With a specially crafted file, a context-dependent attacker can cause execution of arbitary code resulting in a loss of integrity.
|
2009-04-20
|
1by1 M3U File Handling Overflow
|
|
77648
Description:
1pluginjquery contains a flaw that allows a remote cross-site scripting (XSS) attack. This flaw exists because the application does not validate the 'page' parameter upon submission to the wp-content/plugins/1-jquery-photo-gallery-slideshow-flash/wp-1pluginjquery.php script. This may allow a user to create a specially crafted URL that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2011-11-30
|
1pluginjquery /wp-1pluginjquery.php page Parameter XSS
|
|
5016
Description:
1st Class Mail Server contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the Mailbox variable upon submission to the advanced.tagz script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2004-04-08
|
1st Class Mail Server advanced.tagz XSS
|
|
4129
Description:
1st Class Mail Server contains a flaw that may allow a remote denial of service. The issue is triggered when a long string is sent to the second parameter of the APOP USER command, and will result in loss of availability for the service.
|
2004-02-25
|
1st Class Mail Server APOP Digest Parameter DoS
|
|
5011
Description:
1st Class Internet Solutions 1st Class Mail Server contains a flaw that allows a remote attacker to view arbitrary files outside of the web path. The issue is due to the program not properly sanitizing user input, specifically traversal style attacks (../../).
|
2004-04-08
|
1st Class Mail Server Arbitrary File Access
|
|
5015
Description:
1st Class Mail Server contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the Mailbox variable upon submission to the general.tagz script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2004-04-08
|
1st Class Mail Server general.tagz XSS
|
|
5013
Description:
1st Class Mail Server contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the Mailbox variable upon submission to the index script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2004-04-08
|
1st Class Mail Server Index XSS
|
|
5017
Description:
1st Class Mail Server contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the Mailbox variable upon submission to the list.tagz script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2004-04-08
|
1st Class Mail Server list.tagz XSS
|
|
5014
Description:
1st Class Mail Server contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the Mailbox variable upon submission to the members.tagz script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2004-04-08
|
1st Class Mail Server members.tagz XSS
|
|
5012
Description:
1st Class Mail Server contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the MessageIndex variable upon submission to the viewmail.tagz script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2004-04-08
|
1st Class Mail Server viewmail.tagz XSS
|
|
49534
Description:
1st News contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the 'products.php' script not properly sanitizing user-supplied input to the 'id' variable. This may allow an attacker to inject or manipulate SQL queries in the back-end database.
|
2008-11-02
|
1st News products.php id Parameter SQL Injection
|
|
13795
Description:
(Description Provided by CVE) : Buffer overflow in 1st Up Mail Server 4.1 allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long MAIL FROM command.
|
2000-12-26
|
1st Up Mail Server MAIL FROM Command Remote Overflow
|
|
17322
Description:
(Description Provided by CVE) : Multiple cross-site scripting (XSS) vulnerabilities in Annuaire 1Two 1.1 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the id parameter to index.php, or the (2) site_id, (3) nom, (4) email, or (5) commentaire parameters in commentaires.php.
|
2005-05-17
|
1Two Comment Multiple Field Script Insertion
|
|
17321
Description:
(Description Provided by CVE) : Multiple cross-site scripting (XSS) vulnerabilities in Annuaire 1Two 1.1 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the id parameter to index.php, or the (2) site_id, (3) nom, (4) email, or (5) commentaire parameters in commentaires.php.
|
2005-05-17
|
1Two index.php id Parameter XSS
|
|
16717
Description:
1Two Livre d'Or contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the 'livreornom', 'livreoremail', and 'livreormessage' variables upon submission to the 'guestbook.php' script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2005-05-10
|
1Two Livre dOr guestbook.php Multiple Field XSS
|