| OSVDB ID | Disclosure Date | Title |
|
67161
Description:
coWiki contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the 'index.php' script not properly sanitizing user-supplied input to the 'node' parameter. This may allow an attacker to inject or manipulate SQL queries in the back-end database, allowing for the manipulation or disclosure of arbitrary data.
|
2010-07-21
|
coWiki index.php node Parameter SQL Injection
|
|
21481
Description:
coWiki contains a flaw that allows a remote cross-site scripting (XSS) attack. This flaw exists because the application does not validate the 'q' parameter upon submission to the 'index.php' script. This may allow a user to create a specially crafted URL that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2005-12-05
|
coWiki index.php q Parameter XSS
|
|
60192
Description:
(Description Provided by CVE) : JetAudio 7.5.3 COWON Media Center allows remote attackers to cause a denial of service (memory consumption and application crash) via a long string at the end of a .wav file.
|
2009-07-14
|
COWON Media Center Crafted WAV File Handling DoS
|
|
81300
Description:
Cox Web contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the shop.php script not properly sanitizing user-supplied input to the 'id' and 'maincatid' parameters. This may allow an attacker to inject or manipulate SQL queries in the back-end database, allowing for the manipulation or disclosure of arbitrary data.
|
2012-04-22
|
Cox Web shop.php Multiple Parameter SQL Injection
|
|
58259
Description:
cP Creator contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the 'index.php' script not properly sanitizing user-supplied input to the 'tickets' cookie. This may allow an attacker to inject or manipulate SQL queries in the back-end database.
|
2009-09-21
|
cP Creator index.php tickets Cookie SQL Injection
|
|
21620
Description:
(Description Provided by CVE) : Unspecified vulnerability in Positive Software Corporation CP+ (cpplus) before 2.5.5 allows attackers to has unknown impact and attack vectors, related to "a possible security flaw caused by a bug in Perl." NOTE: unless CP+ includes its own copy of Perl with CVE-2005-3962, this is a different vulnerability than CVE-2005-3962; however, there is insufficient information to be sure.
|
2005-11-30
|
CP+ Unspecified Perl Issue
|
|
18746
Description:
(Description Provided by CVE) : Eval injection vulnerability in CPAINT 1.3-SP allows remote attackers to execute arbitrary ASP code via the cpaint_argument[] parameter to (1) calculator.asp or (2) cpaintfile.asp, which is directly fed into an eval statement.
|
2005-08-16
|
CPAINT Ajax Toolkit cpaint_function String Concatenation Arbitrary Code Execution
|
|
18747
Description:
CPAINT Ajax Toolkit contains a flaw that allows a remote cross site scripting attack. This flaw exists because the "checkBlacklist" function does not sanitize calls to the "ExecuteGlobal" function and "GetRef" statement. This could allow a malicious user to execute code remotely, leading to a loss of integrity.
|
2005-08-15
|
CPAINT Ajax Toolkit ExecuteGlobal/GetRef checkBlacklist Function Bypass
|
|
18748
Description:
CPAINT Ajax ToolKit contains a flaw that allows a remote cross site scripting attack. The disclosure does not make it clear whether specific scripts or functions are prone to such attacks. This issue could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2005-08-15
|
CPAINT Ajax Toolkit Multiple Function XSS
|
|
18745
Description:
(Description Provided by CVE) : Unknown vulnerability in CPAINT Ajax Toolkit before 1.3-SP allows attackers to execute arbitrary PHP or ASP code or read files via unknown vectors.
|
2005-08-15
|
CPAINT Ajax Toolkit Unspecified Command Execution
|
|
19274
Description:
Unknown / Incomplete
|
2005-09-05
|
CPAINT ASP Incoming Arguments Unspecified Issue
|
|
22979
Description:
(Description Provided by CVE) : Cross-site scripting (XSS) vulnerability in cpaint2.inc.php in the CPAINT library before 2.0.3, as used in multiple scripts, allows remote attackers to inject arbitrary web script or HTML via the cpaint_response_type parameter, which is displayed in a resulting error message, as demonstrated using a hex-encoded IFRAME tag.
|
2006-02-09
|
CPAINT cpaint2.inc.php cpaint_response_type Function XSS
|
|
52250
Description:
cPanel contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the .contactemail local file upon submission to an unspecified script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2008-08-05
|
cPanel .contactemail Local File XSS
|
|
4530
Description:
cPanel contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the "handle" variable upon submission to the "addhandle.html" script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2004-03-24
|
cPanel addhandle.html handle Parameter XSS
|
|
82611
Description:
cPanel contains a flaw that allows a remote attacker to traverse outside of a restricted path. The issue is due to the program not properly sanitizing user input, specifically directory traversal style attacks (e.g., ../../). This directory traversal attack would allow the attacker to create arbitrary files via an error when handling log messages in the split logs binary.
|
2012-05-31
|
cPanel Apache Piped Log Configuration Log Message Formatting Traversal Arbitrary File Creation
|
|
10960
Description:
(Description Provided by CVE) : cPanel 9.4.1-RELEASE-64 follows hard links, which allows local users to (1) read arbitrary files via the backup feature or (2) chown arbitrary files via the .htaccess file when Front Page extensions are enabled or disabled.
|
2004-10-18
|
cPanel Backup Feature Hardlink Arbitrary File Access
|
|
32042
Description:
(Description Provided by CVE) : Cross-site scripting (XSS) vulnerability in mail/manage.html in BoxTrapper in cPanel 11 allows remote attackers to inject arbitrary web script or HTML via the account parameter.
|
2006-12-01
|
cPanel BoxTrapper /mail/manage.html account Parameter XSS
|
|
6944
Description:
cPanel contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate multiple variables upon submission to the bwday.html script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2004-06-12
|
cPanel bwday.html Multiple Parameter XSS
|
|
6942
Description:
cPanel contains a flaw that may lead to an unauthorized information disclosure. The issue is triggered when a specially crafted URL is sent to the "detailbw.html" page, which will disclose private information resulting in a loss of confidentiality.
|
2004-04-14
|
cPanel bwday.html View Unauthorized Domain Statistics
|
|
18661
Description:
Unknown / Incomplete
|
2005-08-08
|
cPanel Common Password Cross Domain Privilege Escalation
|
|
33234
Description:
Unknown / Incomplete
|
2006-12-01
|
cPanel cpanelpro/dohtaccess.html dir Parameter XSS
|
|
82646
Description:
cPanel contains a flaw that is triggered by cPDAVd not properly sanitizing input when parsing filenames, which may allow a remote attacker to execute arbitrary code.
|
2012-05-31
|
cPanel cPDAVd Filename Parsing Remote Code Execution
|
|
17399
Description:
cPanel contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the 'user' variable upon submission to the 'cpsrvd.pl' script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2005-06-22
|
cPanel cpsrvd.pl user Parameter XSS
|
|
4243
Description:
cPanel contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the "ip" variable upon submission to the "del.html" script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2004-03-13
|
cPanel del.html account Parameter XSS
|
|
6946
Description:
cPanel contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate multiple variables upon submission to the detailbw.html script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2004-06-13
|
cPanel detailbw.html Multiple Parameter XSS
|
|
22939
Description:
cPanel contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate 'target' variable upon submission to the detailbw.html script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2006-02-02
|
cPanel detailbw.html target Parameter XSS
|
|
6941
Description:
Unknown / Incomplete
|
2004-04-14
|
cPanel detailbw.html View Unauthorized Domain Statistics
|
|
6945
Description:
cPanel contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the "mon", "year" and "domain" variables upon submission to the detailsubbw.html script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2004-06-12
|
cPanel detailsubbw.html Multiple Parameter XSS
|
|
6943
Description:
Unknown / Incomplete
|
2004-06-12
|
cPanel detailsubbw.html View Unauthorized Domain Statistics
|
|
88820
Description:
cPanel contains a flaw that allows a remote cross-site scripting (XSS) attack. This flaw exists because the application does not validate the 'dir' parameter upon submission to the dir.html script. This may allow a user to create a specially crafted request that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2012-12-26
|
cPanel dir.html dir Parameter XSS
|