| OSVDB ID | Disclosure Date | Title |
|
46172
Description:
gllcTS2 contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the 'login.php' script not properly sanitizing user-supplied input to the 'detail' variable. This may allow an attacker to inject or manipulate SQL queries in the back-end database.
|
2008-06-12
|
gllcTS2 login.php detail Parameter SQL Injection
|
|
74577
Description:
Global Content Blocks Plugin for WordPress contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the wp-content/plugins/global-content-blocks/gcb/gcb_export.php script not properly sanitizing user-supplied input to the 'gcb' parameter. This may allow an attacker to inject or manipulate SQL queries in the back-end database, allowing for the manipulation or disclosure of arbitrary data.
|
2011-08-19
|
Global Content Blocks Plugin for WordPress wp-content/plugins/global-content-blocks/gcb/gcb_export.php gcb Parameter SQL Injection
|
|
73663
Description:
Global Flash Galleries Component for Joomla! contains a flaw that allows a remote Cross-site Request Forgery (CSRF / XSRF) attack. The flaw exists because the application does not require multiple steps or explicit confirmation for sensitive transactions for the addition or deletion of galleries. By using a crafted URL (e.g., a crafted GET request inside an "img" tag), an attacker may trick the victim into clicking on the image to take advantage of the trust relationship between the authenticated victim and the application. Such an attack could trick the victim into executing arbitrary commands in the context of their session with the application, without further prompting or verification.
|
2011-07-01
|
Global Flash Galleries Component for Joomla! Gallery Manipulation CSRF
|
|
73662
Description:
Global Flash Galleries Component for Joomla! contains a flaw that allows a remote cross-site scripting (XSS) attack. This flaw exists because the application does not validate certain unspecified input before returning it to the user. This may allow a user to create a specially crafted URL that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2011-07-01
|
Global Flash Galleries Component for Joomla! Unspecified XSS
|
|
45886
Description:
(Description Provided by CVE) : Multiple heap-based buffer overflows in GlobalLink 2.7.0.8 allow remote attackers to execute arbitrary code via (1) a long eighth argument to the SetInfo method in a certain ActiveX control in glItemCom.dll or (2) a long second argument to the SetClientInfo method in a certain ActiveX control in glitemflat.dll.
|
2007-09-05
|
GlobalLink ActiveX (glItemCom.dll) SetInfo Method Overflow
|
|
45887
Description:
(Description Provided by CVE) : Multiple heap-based buffer overflows in GlobalLink 2.7.0.8 allow remote attackers to execute arbitrary code via (1) a long eighth argument to the SetInfo method in a certain ActiveX control in glItemCom.dll or (2) a long second argument to the SetClientInfo method in a certain ActiveX control in glitemflat.dll.
|
2007-09-05
|
GlobalLink ActiveX (glitemflat.dll) SetClientInfo Method Overflow
|
|
33679
Description:
GlobalMegaCorp contains a flaw that may allow a remote attacker to execute arbitrary commands or code. The issue is due to the 'dvddb inc/common.php' script not properly sanitizing user input supplied to the 'config' parameter. This may allow an attacker to include a file from a third-party remote host that contains commands or code that will be executed by the vulnerable script with the same privileges as the web server.
|
2007-02-04
|
GlobalMegaCorp dvddb inc/common.php config Parameter Remote File Inclusion
|
|
33670
Description:
(Description Provided by CVE) : ** DISPUTED ** SQL injection vulnerability in inc/common.php in GlobalMegaCorp dvddb 0.6 allows remote attackers to execute arbitrary SQL commands via the user parameter. NOTE: this issue has been disputed by a reliable third party, who states that inc/common.php only contains function definitions.
|
2007-02-04
|
GlobalMegaCorp dvddb inc/common.php user Parameter SQL Injection
|
|
17822
Description:
(Description Provided by CVE) : read.cgi in GlobalNoteScript allows remote attackers to execute arbitrary commands via shell metacharacters in the file parameters.
|
2005-07-07
|
GlobalNoteScript read.cgi file Variable Arbitrary Command Execution
|
|
24452
Description:
Unknown / Incomplete
|
2004-05-16
|
GlobalSCAPE Secure FTP Server (gsftps) Authentication Method Mismatch
|
|
16049
Description:
A remote overflow exists in GlobalSCAPE Secure FTP Server. The Secure FTP Server fails to perform adequate bounds checking of user-supplied input resulting in a buffer overflow. With a specially crafted request in the format "[3000 Bytes] \r\n" , an attacker can overwrite the EIP and SEH registers and execute arbitrary code on the system, resulting in a loss of integrity.
|
2005-05-01
|
GlobalSCAPE Secure FTP Server (gsftps) Command Parsing Remote Overflow
|
|
24451
Description:
Secure FTP Server contains a flaw that may allow a remote denial of service. The issue is triggered when an unspecified command with a lengthy parameter line is passed to the server, and will result in loss of availability for the service.
|
2006-01-10
|
GlobalSCAPE Secure FTP Server (gsftps) Custom Command Long Parameter DoS
|
|
4332
Description:
(Description Provided by CVE) : Buffer overflow in GlobalSCAPE Secure FTP Server 2.0 B03.11.2004.2 allows remote attackers to cause a denial of service (crash) via a SITE command with a long argument.
|
2004-03-18
|
GlobalSCAPE Secure FTP Server (gsftps) SITE Command Overflow
|
|
30718
Description:
Unknown / Incomplete
|
2006-04-12
|
GlobalSCAPE Secure FTP Server (gsftps) Unspecified Command Processing Overflow
|
|
43676
Description:
(Description Provided by CVE) : The Globe7 soft phone client 7.3 sends username and password information in cleartext, which allows remote attackers to obtain sensitive information by sniffing the HTTP traffic.
|
2007-05-15
|
Globe7 Soft Phone Client Cleartext Credentials Remote Disclosure
|
|
40626
Description:
(Description Provided by CVE) : The Globe7 soft phone client 7.3 uses weak cryptography (reversed sequence of binary values) for the password, which might allow local users to obtain sensitive information.
|
2007-10-24
|
Globe7 Soft Phone Client Weak Password Encryption Local Information Disclosure
|
|
42203
Description:
(Description Provided by CVE) : Directory traversal vulnerability in globsy_edit.php in Globsy 1.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter.
|
2008-02-20
|
Globsy globsy_edit.php file Parameter Traversal Arbitrary File Access
|
|
51607
Description:
(Description Provided by CVE) : globsy_edit.php in Globsy 1.0 and earlier allows remote attackers to create or overwrite arbitrary files via a filename in the file parameter and file contents in the data parameter.
|
2008-10-12
|
Globsy globsy_edit.php Multiple Parameter Arbitrary File Manipulation
|
|
28014
Description:
Unknown / Incomplete
|
2005-05-17
|
Globus Toolkit Aggregator Execution Source aggrexec Arbitrary Command Execution
|
|
36094
Description:
(Description Provided by CVE) : Unspecified vulnerability in globus-job-manager in Globus Toolkit 4.1.1 and earlier (globus_nexus-6.6 and earlier) allows remote attackers to cause a denial of service (resource exhaustion and system crash) via certain requests to temporary TCP ports for a GRAM2 job or its MPICH-G2 applications.
|
2007-05-17
|
Globus Toolkit globus-job-manager MPICH-G2 Application GRAM2 Job Unspecified DoS
|
|
28018
Description:
(Description Provided by CVE) : Globus Toolkit 3.2.x, 4.0.x, and 4.1.0 before 20060815 allow local users to obtain sensitive information (proxy certificates) and overwrite arbitrary files via a symlink attack on temporary files in the /tmp directory, as demonstrated by files created by (1) myproxy-admin-adduser, (2) grid-ca-sign, and (3) grid-security-config.
|
2006-08-15
|
Globus Toolkit grid-ca-sign Symlink Arbitrary File Disclosure
|
|
28020
Description:
(Description Provided by CVE) : Race condition in the grid-proxy-init tool in Globus Toolkit 3.2.x, 4.0.x, and 4.1.0 before 20060815 allows local users to steal credential data by replacing the proxy credentials file in between file creation and the check for exclusive file access.
|
2006-08-15
|
Globus Toolkit grid-proxy-init File I/O Race Condition Credential Disclosure
|
|
28019
Description:
(Description Provided by CVE) : Globus Toolkit 3.2.x, 4.0.x, and 4.1.0 before 20060815 allow local users to obtain sensitive information (proxy certificates) and overwrite arbitrary files via a symlink attack on temporary files in the /tmp directory, as demonstrated by files created by (1) myproxy-admin-adduser, (2) grid-ca-sign, and (3) grid-security-config.
|
2006-08-15
|
Globus Toolkit grid-security-config Symlink Arbitrary File Disclosure
|
|
28015
Description:
Unknown / Incomplete
|
2005-05-17
|
Globus Toolkit MDS3 Index Service ScriptExecutionProvider Arbitrary Command Execution
|
|
28017
Description:
(Description Provided by CVE) : Globus Toolkit 3.2.x, 4.0.x, and 4.1.0 before 20060815 allow local users to obtain sensitive information (proxy certificates) and overwrite arbitrary files via a symlink attack on temporary files in the /tmp directory, as demonstrated by files created by (1) myproxy-admin-adduser, (2) grid-ca-sign, and (3) grid-security-config.
|
2006-08-15
|
Globus Toolkit myproxy-admin-adduser Symlink Arbitrary File Disclosure
|
|
28016
Description:
Unknown / Incomplete
|
2005-09-07
|
Globus Toolkit XIO HTTP Driver Content-Length Overflow
|
|
53092
Description:
(Description Provided by CVE) : Cross-site scripting (XSS) vulnerability in glossaire.php in Glossaire 2.0 allows remote attackers to inject arbitrary web script or HTML via the letter parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
|
2008-04-04
|
Glossaire glossaire.php letter Parameter XSS
|
|
37921
Description:
(Description Provided by CVE) : SQL injection vulnerability in glossaire-p-f.php in the Glossaire 1.7 and earlier module for Xoops allows remote attackers to execute arbitrary SQL commands via the sid parameter in an ImprDef action.
|
2007-05-15
|
Glossaire Module for XOOPS glossaire-p-f.php ImprDef Action sid Parameter SQL Injection
|
|
34451
Description:
(Description Provided by CVE) : PHP remote file inclusion vulnerability in index.php in the Glossaire module 1.7 for Xoops allows remote attackers to execute arbitrary PHP code via a URL in the pa parameter.
|
2006-07-01
|
Glossaire Module for XOOPS index.php pa Remote File Inclusion
|
|
41268
Description:
(Description Provided by CVE) : SQL injection vulnerability in index.php in the Glossary (com_glossary) 2.0 component for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the catid parameter in a display action.
|
2008-01-30
|
Glossary Component for Mambo / Joomla! index.php catid Parameter SQL Injection
|