| OSVDB ID | Disclosure Date | Title |
|
74418
Description:
AChecker contains a flaw that allows a remote cross-site scripting (XSS) attack. This flaw exists because the application does not validate the 'myown_patch_id' parameter upon submission to the updater/patch_edit.php script. This may allow a user to create a specially crafted URL that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server. Additionally, the program may disclose the software's installation path. While such information is relatively low risk, it is often useful in carrying out additional, more focused attacks.
|
2011-08-06
|
AChecker updater/patch_edit.php myown_patch_id Parameter XSS
|
|
74414
Description:
AChecker contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the user/user_create_edit.php script not properly sanitizing user-supplied input to the 'id' parameter. This may allow an attacker to inject or manipulate SQL queries in the back-end database, allowing for the manipulation or disclosure of arbitrary data.
|
2011-08-06
|
AChecker user/user_create_edit.php id Parameter SQL Injection
|
|
74419
Description:
AChecker contains a flaw that allows a remote cross-site scripting (XSS) attack. This flaw exists because the application does not validate the 'id' parameter upon submission to the user/user_create_edit.php script. This may allow a user to create a specially crafted URL that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server. Additionally, the program may disclose the software's installation path. While such information is relatively low risk, it is often useful in carrying out additional, more focused attacks.
|
2011-08-06
|
AChecker user/user_create_edit.php id Parameter XSS
|
|
41527
Description:
Unknown / Incomplete
|
2006-03-14
|
Achievo ATK atkProfileAttribute Privilege Escalation
|
|
41524
Description:
Unknown / Incomplete
|
2005-10-25
|
Achievo ATK DB Authentication Unspecified SQL Injection
|
|
41526
Description:
Unknown / Incomplete
|
2005-12-02
|
Achievo ATK Demo Application sourceviewer Local File Inclusion
|
|
41528
Description:
Unknown / Incomplete
|
2007-06-12
|
Achievo ATK makeHiddenPostvars Method Multiple Page XSS
|
|
41525
Description:
Unknown / Incomplete
|
2005-10-27
|
Achievo ATK modules/lesson_utils/class.sourceviewer.inc Unspecified Arbitrary File Access
|
|
37445
Description:
Unknown / Incomplete
|
2007-08-30
|
Achievo ATK PHP_SELF XSS
|
|
41523
Description:
Unknown / Incomplete
|
2004-05-03
|
Achievo ATK Unspecified Session Hijacking
|
|
54886
Description:
Achievo contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate parameters upon submission to the makeHiddenPostvars() function in the atk/atktools.inc script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2009-05-28
|
Achievo atk/atktools.inc makeHiddenPostvars() Function XSS
|
|
14538
Description:
Achievo contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to class.atkdateattribute.js.php not properly sanitizing user input supplied to the 'config_atkroot' variable. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script.
|
2002-08-22
|
Achievo class.atkdateattribute.js.php config_atkroot Parameter Remote File Inclusion
|
|
25811
Description:
Achievo contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the class.employee.inc script not properly sanitizing user-supplied input to the 'atkselector' variable. This may allow an attacker to inject or manipulate SQL queries in the back-end database.
|
2006-05-29
|
Achievo class.employee.inc atkselector Parameter SQL Injection
|
|
59048
Description:
Achievo contains a flaw that may allow a remote attacker to execute arbitrary commands or code. The issue is due to the 'debugger.php' script not properly sanitizing user input supplied to the 'config_atkroot' parameter. This may allow an attacker to include a file from a third-party remote host that contains commands or code that will be executed by the vulnerable script with the same privileges as the web server.
|
2009-10-14
|
Achievo debugger.php config_atkroot Parameter Remote File Inclusion
|
|
88184
Description:
Achievo contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the dispatch.php script not properly sanitizing user-supplied input to the 'activityid' parameter. This may allow an attacker to inject or manipulate SQL queries in the back-end database, allowing for the manipulation or disclosure of arbitrary data.
|
2012-12-05
|
Achievo dispatch.php activityid Parameter SQL Injection
|
|
87012
Description:
Achievo contains a flaw that may allow a remote attacker to execute arbitrary commands or code. The issue is due to the dispatch.php script not properly sanitizing user input, specifically directory traversal style attacks (e.g., ../../) supplied to the 'atknodetype' parameter. This may allow an attacker to include a file from the targeted host that contains arbitrary commands or code that will be executed by the vulnerable script. Such attacks are limited due to the script only calling files already on the target host. In addition, this flaw can potentially be used to disclose the contents of any file on the system accessible by the web server.
|
2012-11-01
|
Achievo dispatch.php atknodetype Parameter Traversal Local File Inclusion
|
|
60689
Description:
Achievo contains a flaw that allows a remote cross-site scripting (XSS) attack. This flaw exists because the application does not validate the 'description' parameter upon submission to the 'dispatch.php' script. This may allow a user to create a specially crafted URL that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2009-12-03
|
Achievo dispatch.php description Parameter XSS
|
|
60690
Description:
Unknown / Incomplete
|
2009-12-03
|
Achievo dispatch.php File Upload Arbitrary Code Execution
|
|
82186
Description:
Achievo contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the dispatch.php script not properly sanitizing user-supplied input to the 'id' parameter. This may allow an attacker to inject or manipulate SQL queries in the back-end database, allowing for the manipulation or disclosure of arbitrary data.
|
2012-01-30
|
Achievo dispatch.php id Parameter SQL Injection
|
|
78883
Description:
Achievo contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the 'action_vcard()' function in modules/person/class.person.inc not properly sanitizing user-supplied input passed via the 'id' parameter to the 'dispatch.php' script. This may allow an attacker to inject or manipulate SQL queries in the back-end database, allowing for the manipulation or disclosure of arbitrary data.
|
2012-01-30
|
Achievo dispatch.php modules/person/class.person.inc action_vcard() Function id Parameter SQL Injection
|
|
75071
Description:
Achievo contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the dispatch.php script not properly sanitizing user-supplied input to the 'atkselector', 'viewuser', 'startdate' and 'enddate' parameters. This may allow an attacker to inject or manipulate SQL queries in the back-end database, allowing for the manipulation or disclosure of arbitrary data.
|
2011-03-23
|
Achievo dispatch.php Multiple Parameter SQL Injection
|
|
48485
Description:
Achievo contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate 'atkaction' and 'atknodetype' parameters upon submission to the 'dispatch.php' script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2008-09-23
|
Achievo dispatch.php Multiple Parameter XSS
|
|
80826
Description:
Achievo contains a flaw that allows a remote cross-site scripting (XSS) attack. This flaw exists because the application does not validate the 'atklevel', 'atknodetype', 'atkaction' and 'atkstackid' parameters upon submission to the dispatch.php script. This may allow a user to create a specially crafted URL that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2011-11-28
|
Achievo dispatch.php Multiple Parameter XSS
|
|
87013
Description:
Achievo contains a flaw that allows a remote cross-site scripting (XSS) attack. This flaw exists because the application does not validate the 'atkselector' and 'atkfilter' parameters upon submission to the dispatch.php script. This may allow a user to create a specially crafted URL that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2012-11-01
|
Achievo dispatch.php Multiple Parameter XSS
|
|
75065
Description:
Achievo contains a flaw that allows a remote cross-site scripting (XSS) attack. This flaw exists because the application does not validate the 'searchstring' parameter upon submission to the dispatch.php script. This may allow a user to create a specially crafted URL that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2011-03-23
|
Achievo dispatch.php searchstring Parameter XSS
|
|
58935
Description:
Achievo contains a flaw that allows a remote cross site scripting (XSS) attack. This flaw exists because the application does not validate the 'title' parameter upon submission to the dispatch.php script. This may allow a user to create a specially crafted URL that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2009-08-25
|
Achievo dispatch.php title Parameter XSS
|
|
58936
Description:
Achievo contains a flaw that may allow a remote attacker to carry out an SQL injection attack. The issue is due to the 'dispatch.php' script not properly sanitizing user-supplied input to the 'userid' parameter. This may allow a remote attacker to inject or manipulate SQL queries in the back-end database, allowing for the manipulation or disclosure of arbitrary data.
|
2009-08-20
|
Achievo dispatch.php userid Parameter SQL Injection
|
|
75070
Description:
Achievo contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the graph.php script not properly sanitizing user-supplied input to the 'viewstart' and 'viewend' parameters. This may allow an attacker to inject or manipulate SQL queries in the back-end database, allowing for the manipulation or disclosure of arbitrary data.
|
2011-03-23
|
Achievo graph.php Multiple Parameter SQL Injection
|
|
75069
Description:
Achievo contains a flaw that may allow a remote attacker to execute arbitrary commands or code. The issue is due to the graph.php script not properly sanitizing user input, specifically directory traversal style attacks (e.g., ../../) supplied to the 'plotter' parameter. This may allow an attacker to include a file from the targeted host that contains arbitrary commands or code that will be executed by the vulnerable script. Such attacks are limited due to the script only calling files already on the target host. In addition, this flaw can potentially be used to disclose the contents of any file on the system accessible by the web server.
|
2011-03-23
|
Achievo graph.php plotter Parameter Traversal Local File Inclusion
|
|
75066
Description:
Achievo contains a flaw that allows a remote cross-site scripting (XSS) attack. This flaw exists because the atk/popups/colorpicker.inc script does not validate the 'field' and 'usercol' parameters upon submission to the include.php script. This may allow a user to create a specially crafted URL that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2011-03-23
|
Achievo include.php Multiple Parameter XSS
|