| OSVDB ID | Disclosure Date | Title |
|
84247
Description:
The Extension::MobileUI Extension for RT contains a flaw that allows a remote cross-site scripting (XSS) attack. This flaw exists because the application does not validate certain unspecified input before returning it to the user. This may allow a user to create a specially crafted request that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2012-07-25
|
Extension::MobileUI Extension for RT Unspecified XSS
|
|
420
Description:
(Description Provided by CVE) : Directory traversal vulnerability in Extent RBS ISP web server allows remote attackers to read sensitive information via a .. (dot dot) attack on the Image parameter.
|
2000-09-20
|
Extent RBS Web Server Image Parameter Traversal Arbitrary File Access
|
|
64762
Description:
External Link Page Module for Drupal contains a flaw that allows a remote cross site scripting (XSS) attack. This flaw exists because the application does not validate the input on the module's administration page before being displayed on redirect pages. This may allow a user to create a specially crafted URL that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2010-05-20
|
External Link Page Module for Drupal Content Filter Redirect XSS
|
|
90740
Description:
extlib Gem for Ruby contains a flaw that is triggered when a type casting error occurs during the parsing of parameters. This may allow a context-dependent attacker to potentially execute arbitrary code.
|
2013-01-08
|
extlib Gem for Ruby Type Casting Parameter Parsing Remote Code Execution
|
|
84687
Description:
eXtplorer contains a flaw that is triggered when the program fails to properly check for permissions in /var/lib/extplorer/ftp_tmp. This may allow a local attacker to delete or overwrite arbitrary files.
|
2012-08-02
|
eXtplorer /var/lib/extplorer/ftp_tmp Permission Weakness Local File Manipulation
|
|
71566
Description:
eXtplorer contains a flaw that allows a remote Cross-site Request Forgery (CSRF / XSRF) attack. The flaw exists because the application does not require multiple steps or explicit confirmation for sensitive transactions for the addition of an administrative user. By using a crafted URL (e.g., a crafted GET request inside an "img" tag), an attacker may trick the victim into clicking on the image to take advantage of the trust relationship between the authenticated victim and the application. Such an attack could trick the victim into executing arbitrary commands in the context of their session with the application, without further prompting or verification.
|
2011-04-06
|
eXtplorer Admin User Creation CSRF
|
|
52303
Description:
Unknown / Incomplete
|
2009-03-02
|
eXtplorer index.php lang Parameter Traversal Local File Inclusion
|
|
84050
Description:
eXtplorer contains a flaw that allows a remote cross-site scripting (XSS) attack. This flaw exists because the application does not validate the 'lang' parameter upon submission to the index.php script. This may allow a user to create a specially crafted request that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2012-07-09
|
eXtplorer index.php lang Parameter XSS
|
|
49400
Description:
(Description Provided by CVE) : Directory traversal vulnerability in the eXtplorer module (com_extplorer) 2.0.0 RC2 and earlier in Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the dir parameter in a show_error action.
|
2008-04-13
|
eXtplorer Module for Joomla! index.php dir Parameter Traversal Arbitrary File Access
|
|
88751
Description:
eXtplorer contains a flaw in the ext_find_user() function of the users.php script. This issue may allow a remote attacker to bypass authentication and login as an arbitrary user. No further details have been provided.
|
2012-12-25
|
eXtplorer users.php ext_find_user() Function Unspecified Authentication Bypass
|
|
50915
Description:
(Description Provided by CVE) : Directory traversal vulnerability in download.php in eMetrix Extract Website allows remote attackers to read arbitrary files via a .. (dot dot) in the filename parameter.
|
2008-12-19
|
Extract Website download.php filename Parameter Traversal Arbitrary File Access
|
|
52282
Description:
Extrakt Framework contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate 'plugins[file][id]' variables upon submission to the 'index.php' script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2008-10-29
|
Extrakt Framework index.php plugins[file][id] Parameter XSS
|
|
41766
Description:
(Description Provided by CVE) : Multiple buffer overflows in eXtremail 2.1.1 and earlier allow remote attackers to (1) have an unknown impact by sending multiple long strings to the IMAP port (143/tcp); (2) execute arbitrary code via a long string in an IMAP AUTHENTICATE PLAIN action, involving the ifParseAuthPlain function; (3) execute arbitrary code via a long LOGIN command to the admin interface port (4501/tcp); or (4) execute arbitrary code via a long string in an IMAP AUTHENTICATE LOGIN (aka CRAM-MD5 authentication) action, involving the ifProcImapAuth1 function.
|
2007-10-15
|
eXtremail Admin Interface LOGIN Command Remote Overflow
|
|
35583
Description:
(Description Provided by CVE) : Stack-based buffer overflow in eXtremail 2.1.1 and earlier allows remote attackers to execute arbitrary code via a long DNS response. NOTE: this might be related to CVE-2006-6926.
|
2007-04-20
|
eXtremail DNS Response Handling Overflow
|
|
35584
Description:
(Description Provided by CVE) : eXtremail 2.1.1 and earlier does not verify the ID field (aka transaction id) in DNS responses, which makes it easier for remote attackers to conduct DNS spoofing.
|
2007-04-20
|
eXtremail DNS Response ID Field Verification Weakness
|
|
41767
Description:
(Description Provided by CVE) : Multiple buffer overflows in eXtremail 2.1.1 and earlier allow remote attackers to (1) have an unknown impact by sending multiple long strings to the IMAP port (143/tcp); (2) execute arbitrary code via a long string in an IMAP AUTHENTICATE PLAIN action, involving the ifParseAuthPlain function; (3) execute arbitrary code via a long LOGIN command to the admin interface port (4501/tcp); or (4) execute arbitrary code via a long string in an IMAP AUTHENTICATE LOGIN (aka CRAM-MD5 authentication) action, involving the ifProcImapAuth1 function.
|
2007-10-15
|
eXtremail IMAP AUTHENTICATE LOGIN Action Remote Overflow
|
|
41765
Description:
(Description Provided by CVE) : Multiple buffer overflows in eXtremail 2.1.1 and earlier allow remote attackers to (1) have an unknown impact by sending multiple long strings to the IMAP port (143/tcp); (2) execute arbitrary code via a long string in an IMAP AUTHENTICATE PLAIN action, involving the ifParseAuthPlain function; (3) execute arbitrary code via a long LOGIN command to the admin interface port (4501/tcp); or (4) execute arbitrary code via a long string in an IMAP AUTHENTICATE LOGIN (aka CRAM-MD5 authentication) action, involving the ifProcImapAuth1 function.
|
2007-10-15
|
eXtremail IMAP AUTHENTICATE PLAIN Action Remote Overflow
|
|
41764
Description:
(Description Provided by CVE) : Multiple buffer overflows in eXtremail 2.1.1 and earlier allow remote attackers to (1) have an unknown impact by sending multiple long strings to the IMAP port (143/tcp); (2) execute arbitrary code via a long string in an IMAP AUTHENTICATE PLAIN action, involving the ifParseAuthPlain function; (3) execute arbitrary code via a long LOGIN command to the admin interface port (4501/tcp); or (4) execute arbitrary code via a long string in an IMAP AUTHENTICATE LOGIN (aka CRAM-MD5 authentication) action, involving the ifProcImapAuth1 function.
|
2007-10-15
|
eXtremail IMAP Port Multiple String Remote Overflow
|
|
14148
Description:
eXtremail contains multiple flaws that may allow a malicious user to execute arbitrary commands. The issue is triggered when a specially formatted string is sent to the fprintfstatement statement of the flog function due to a format string vulnerability in that function. It is possible that the flaw may allow a malicious user to execute arbitrary code as the superuser resulting in a loss of integrity.
|
2001-06-22
|
eXtremail Multiple POP3 Command flog Function Format String
|
|
14147
Description:
(Description Provided by CVE) : Format string vulnerability in flog function of eXtremail 1.1.9 and earlier allows remote attackers to gain root privileges via format specifiers in the SMTP commands (1) HELO, (2) EHLO, (3) MAIL FROM, or (4) RCPT TO, and the POP3 commands (5) USER and (6) other commands that can be executed after POP3 authentication.
|
2001-06-22
|
eXtremail Multiple SMTP Command flog Function Format String
|
|
4127
Description:
eXtremail contains a flaw that may allow a malicious user to bypass authentication. The issue is triggered when a user password consists of a single digit or begins with a digit. It is possible that the flaw may allow an attacker to log in without a password resulting in a loss of confidentiality and integrity.
|
2004-02-26
|
eXtremail Numeric Password User Authentication Bypass
|
|
41763
Description:
(Description Provided by CVE) : Integer overflow in eXtremail 2.1.1 and earlier allows remote attackers to cause a denial of service, and possibly execute arbitrary code, via a long USER command containing "%s" sequences to the pop3 port (110/tcp), which are expanded to "%%s" before being used in the memmove function, possibly due to an incomplete fix for CVE-2001-1078.
|
2007-10-15
|
eXtremail pop3 USER Command Remote Overflow
|
|
30396
Description:
(Description Provided by CVE) : Buffer overflow in eXtremail 2.1 has unknown impact and attack vectors, as demonstrated by VulnDisco Pack. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.
|
2006-11-14
|
eXtremail Unspecified Overflow
|
|
30591
Description:
(Description Provided by CVE) : Multiple cross-site scripting (XSS) vulnerabilities in admin/options.php in Extreme CMS 0.9, and possibly earlier, allow remote attackers to inject arbitrary web script or HTML via the (1) bg1, (2) bg2, (3) text, or (4) size parameters. NOTE: the provenance of this information is unknown; details are obtained from third party sources.
|
2006-11-15
|
Extreme CMS admin/options.php Multiple Parameter XSS
|
|
30592
Description:
(Description Provided by CVE) : admin/options.php in Extreme CMS 0.9, and possibly earlier, does not require authentication, which might allow remote attackers to conduct unauthorized activities. NOTE: this issue can be combined with another vulnerability to expand the scope of a cross-site scripting (XSS) attack without authentication. NOTE: the provenance of this information is unknown; details are obtained from third party sources.
|
2006-11-15
|
Extreme CMS admin/options.php Unauthenticated Access
|
|
33181
Description:
(Description Provided by CVE) : Unrestricted file upload vulnerability in eXtremePow eXtreme File Hosting allows remote attackers to upload arbitrary PHP code via a filename with a double extension such as (1) .rar.php or (2) .zip.php.
|
2007-02-09
|
eXtreme File Hosting Double Extension Unrestricted File Upload
|
|
36957
Description:
(Description Provided by CVE) : PHP remote file inclusion vulnerability in functions.php in Extreme phpBB (aka phpBB Extreme) 3.0.1 allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.
|
2007-02-24
|
Extreme phpBB functions.php phpbb_root_path Parameter Remote File Inclusion
|
|
35420
Description:
(Description Provided by CVE) : Multiple PHP remote file inclusion vulnerabilities in Extreme PHPBB2 3.0 Pre Final allow remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter to (1) functions.php or (2) functions_portal.php in includes/.
|
2007-04-18
|
Extreme PHPBB2 includes/functions.php phpbb_root_path Parameter Remote File Inclusion
|
|
35421
Description:
(Description Provided by CVE) : Multiple PHP remote file inclusion vulnerabilities in Extreme PHPBB2 3.0 Pre Final allow remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter to (1) functions.php or (2) functions_portal.php in includes/.
|
2007-04-18
|
Extreme PHPBB2 includes/functions_portal.php phpbb_root_path Parameter Remote File Inclusion
|
|
21336
Description:
Extreme Search Corporate Edition contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the 'search' variable upon submission to the 'extremesearch.php' script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2005-12-01
|
Extreme Search Corporate Edition extremesearch.php search Parameter XSS
|