| OSVDB ID | Disclosure Date | Title |
|
28925
Description:
(Description Provided by CVE) : SQL injection vulnerability in mods.php in GNUTurk 2G and earlier allows remote attackers to execute arbitrary SQL commands via the t_id parameter when the go parameter is "Forum."
|
2006-09-16
|
Gnuturk Portal mods.php t_id Parameter SQL Injection
|
|
57413
Description:
Unknown / Incomplete
|
2009-08-26
|
Go - url redirects Module for Drupal PCRE Regex Engine Arbitrary PHP Code Execution
|
|
57415
Description:
Unknown / Incomplete
|
2009-08-26
|
Go - url redirects Module for Drupal Redirect Manipulation CSRF
|
|
57414
Description:
Unknown / Incomplete
|
2009-08-26
|
Go - url redirects Module for Drupal Unspecified XSS
|
|
20464
Description:
A remote overflow exists in GO-Global. The server and clients fail to validate the _USERSA_ fields resulting in a buffer overflow. With a specially crafted request, an attacker can cause arbitrary code execution resulting in a loss of integrity.
|
2005-11-02
|
GO-Global for Windows _USERSA_ Remote Overflow
|
|
58383
Description:
(Description Provided by CVE) : Multiple heap-based buffer overflows in cppcanvas/source/mtfrenderer/emfplus.cxx in Go-oo 2.x and 3.x before 3.0.1, previously named ooo-build and related to OpenOffice.org (OOo), allow remote attackers to execute arbitrary code via a crafted EMF+ file, a similar issue to CVE-2008-2238.
|
2009-09-10
|
Go-oo cppcanvas/source/mtfrenderer/emfplus.cxx EMF+ File Handling Multiple Overflows
|
|
57860
Description:
(Description Provided by CVE) : Heap-based buffer overflow in svtools/source/filter.vcl/wmf/enhwmf.cxx in Go-oo 2.x and 3.x before 3.0.1, previously named ooo-build and related to OpenOffice.org (OOo), allows remote attackers to execute arbitrary code via a crafted EMF file, a similar issue to CVE-2008-2238.
|
2009-09-04
|
Go-oo svtools/source/filter.vcl/wmf/enhwmf.cxx Crafted EMF File Handling Overflow
|
|
2513
Description:
Unknown / Incomplete
|
2003-09-04
|
Go2Call DoS
|
|
6664
Description:
GoAhead WebServer on Windows contains a flaw that may allow a remote denial of service. The issue is triggered when an attacker requests the /aux directory (and likely other MS-DOS reserved names) which will result in a loss of availability for the web server.
|
2001-04-17
|
GoAhead WebServer /aux Directory Request DoS
|
|
76845
Description:
GoAhead Webserver contains a flaw that allows a remote cross-site scripting (XSS) attack. This flaw exists because the application does not validate the 'group' parameter upon submission to the addgroup.asp script. This may allow a user to create a specially crafted URL that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2011-10-10
|
GoAhead Webserver addgroup.asp group Parameter XSS
|
|
76846
Description:
GoAhead Webserver contains a flaw that allows a remote cross-site scripting (XSS) attack. This flaw exists because the application does not validate the 'url' parameter upon submission to the addlimit.asp script. This may allow a user to create a specially crafted URL that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2011-10-10
|
GoAhead Webserver addlimit.asp url Parameter XSS
|
|
76847
Description:
GoAhead Webserver contains a flaw that allows a remote cross-site scripting (XSS) attack. This flaw exists because the application does not validate the 'User ID' or 'group' parameters upon submission to the adduser.asp script. This may allow a user to create a specially crafted URL that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2011-10-10
|
GoAhead Webserver adduser.asp Multiple Parameter XSS
|
|
13295
Description:
GoAhead WebServer contains a flaw that may lead to an unauthorized information disclosure. The issue is triggered when prefixing an ASP filename with specific characters (/), (\), (%20) or (%00), which will disclose the source file code resulting in a loss of confidentiality.
|
2002-12-17
|
GoAhead WebServer Crafted File Request Script Source Disclosure
|
|
56440
Description:
Unknown / Incomplete
|
2004-01-19
|
GoAhead WebServer Crafted GET Request Restricted Directory Protection Bypass
|
|
6662
Description:
GoAhead WebServer contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate input variables upon submission to the error handling script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2002-07-10
|
GoAhead WebServer Error Page XSS
|
|
56425
Description:
(Description Provided by CVE) : The security handler in GoAhead WebServer before 2.1.1 allows remote attackers to bypass authentication and obtain access to protected web content via "an extra slash in a URL," a different vulnerability than CVE-2002-1603.
|
2001-12-05
|
GoAhead WebServer Extra Slash Request Authentication Bypass
|
|
56439
Description:
(Description Provided by CVE) : Directory traversal vulnerability in GoAhead Web Server 2.1 allows remote attackers to read arbitrary files via a URL with an encoded / (%5C) in a .. (dot dot) sequence. NOTE: it is highly likely that this candidate will be REJECTED because it has been reported to be a duplicate of CVE-2001-0228.
|
2002-07-10
|
GoAhead WebServer GET Request Encoded Traversal Arbitrary File Access
|
|
3694
Description:
(Description Provided by CVE) : Directory traversal vulnerability in GoAhead web server 2.1 and earlier allows remote attackers to read arbitrary files via a .. attack in an HTTP GET request.
|
2001-02-02
|
GoAhead WebServer GET Request Traversal Arbitrary File Access
|
|
77198
Description:
GoAhead WebServer contains a flaw that allows a remote cross-site scripting (XSS) attack. This flaw exists because the application does not validate the 'name' and 'address' parameters upon submission to the goform/formTest script. This may allow a user to create a specially crafted URL that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2011-11-18
|
GoAhead WebServer goform/formTest Multiple Parameter XSS
|
|
43168
Description:
(Description Provided by CVE) : goform/QuickStart_c0 on the GoAhead Web Server on the FS4104-AW (aka rooter) VDSL device contains a password in the typepassword field, which allows remote attackers to obtain this password by reading the HTML source, a different vulnerability than CVE-2002-1603.
|
2007-12-18
|
GoAhead WebServer goform/QuickStart_c0 typepassword Field Password Disclosure
|
|
59786
Description:
(Description Provided by CVE) : Buffer overflow in GoAhead WebServer 2.1 allows remote attackers to execute arbitrary code via a long HTTP GET request with a large number of subdirectories.
|
2002-08-14
|
GoAhead WebServer HTTP GET Request Subdirectory Handling Remote Overflow
|
|
3617
Description:
GoAhead WebServer contains a flaw that may allow a remote denial of service. The issue is triggered when sending a HTTP POST request with a malformed Content-Length header, which causes the application to crash resulting in a loss of availability.
|
2003-09-23
|
GoAhead WebServer Malformed Content-Length Header Remote DoS
|
|
56424
Description:
(Description Provided by CVE) : GoAhead WebServer before 2.1.5 on Windows 95, 98, and ME allows remote attackers to cause a denial of service (daemon crash) via an HTTP request with a (1) con, (2) nul, (3) clock$, or (4) config$ device name in a path component, different vectors than CVE-2001-0385.
|
2003-03-19
|
GoAhead WebServer on Windows MS-DOS Device Name Request DoS
|
|
78079
Description:
(Description Provided by CVE) : GoAhead WebServer allows remote attackers to cause a denial of service (daemon outage) via partial HTTP requests, as demonstrated by Slowloris.
|
2009-06-17
|
GoAhead WebServer Partial HTTP Request Parsing Remote DoS
|
|
56426
Description:
(Description Provided by CVE) : GoAhead WebServer before 2.1.1 allows remote attackers to cause a denial of service (CPU consumption) by performing a socket disconnect to terminate a request before it has been fully processed by the server.
|
2001-12-05
|
GoAhead WebServer Socket Disconnect Remote DoS
|
|
56428
Description:
(Description Provided by CVE) : Unspecified vulnerability in GoAhead WebServer before 2.1.4 allows remote attackers to cause "incorrect behavior" via unknown "malicious code," related to incorrect use of the socketInputBuffered function by sockGen.c.
|
2002-10-17
|
GoAhead WebServer sockGen.c socketInputBuffered Function Unspecified Remote Issue
|
|
56427
Description:
(Description Provided by CVE) : webs.c in GoAhead WebServer before 2.1.4 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via an HTTP POST request that contains a Content-Length header but no body data.
|
2002-10-17
|
GoAhead WebServer webs.c Crafted POST Request NULL Pointer Dereference DoS
|
|
56429
Description:
(Description Provided by CVE) : GoAhead WebServer before 2.1.6 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via an invalid URL, related to the websSafeUrl function.
|
2003-03-25
|
GoAhead WebServer websSafeUrl Function Malformed URL NULL Dereference Remote DoS
|
|
50825
Description:
(Description Provided by CVE) : admin/auth.php in Gobbl CMS 1.0 allows remote attackers to bypass authentication and gain administrative access by setting the auth cookie to "ok".
|
2008-12-18
|
Gobbl CMS auth Cookie Manipulation Admin Authentication Bypass
|
|
36872
Description:
(Description Provided by CVE) : Cross-site scripting (XSS) vulnerability in Gobi as of 20070711, built on Helma, allows remote attackers to inject arbitrary web script or HTML via the q parameter to the search function.
|
2007-04-12
|
Gobi Search Function q Parameter XSS
|