| OSVDB ID | Disclosure Date | Title |
|
49439
Description:
H&H WebSoccer contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the 'liga.php' script not properly sanitizing user-supplied input to the 'id' variable. This may allow an attacker to inject or manipulate SQL queries in the back-end database.
|
2008-10-28
|
H&H WebSoccer liga.php id Parameter SQL Injection
|
|
3496
Description:
AntiVir for Linux contains a flaw that may allow a malicious user to gain access to unauthorized privileges. The issue is triggered when the program creates a temp file with a predictable filename. This flaw may lead to a loss of Confidentiality, Integrity and/or Availability.
|
2004-01-13
|
H+BEDV AntiVir Insecure Temp File Privilege Escalation
|
|
31732
Description:
(Description Provided by CVE) : The control panel for Positive Software H-Sphere before 2.5.0 RC3 creates log files in a user's directory with insecure permissions, which allows local users to append log data to arbitrary files via a symlink attack. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.
|
2006-12-05
|
H-Sphere Control Panel Symlink Arbitrary File Manipulation
|
|
16241
Description:
(Description Provided by CVE) : Cross-site scripting (XSS) vulnerability in the guestbook for SiteStudio 1.6 allows remote attackers to inject arbitrary web script or HTML via the name field to (1) psoft.guestbook.GuestBookServ in Standalone Site Studio or (2) E-Guest_sign.pl in Integrated Site Studio with H-Sphere.
|
2005-05-09
|
H-Sphere E-Guest_sign.pl name Field XSS
|
|
16242
Description:
Unknown / Incomplete
|
2005-05-09
|
H-Sphere Multiple Default Account Persistence
|
|
16239
Description:
(Description Provided by CVE) : H-Sphere Winbox 2.4.2 and 2.4.3 RC1 stores sensitive information such as username and password in plaintext in world-readable log files, which allows local users to gain privileges.
|
2005-05-09
|
H-Sphere Multiple Log File Cleartext Login Credential Disclosure
|
|
22372
Description:
H-Sphere contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the 'login' variable upon submission to the 'psoft.hsphere.CP' script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2006-01-12
|
H-Sphere psoft.hsphere.CP login Parameter XSS
|
|
26863
Description:
H-Sphere contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the 'next_template', 'start', 'curr_menu_id' and 'arid' variables upon submission to the psoft.hsphere.CP script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2006-06-27
|
H-Sphere psoft.hsphere.CP Multiple Parameter XSS
|
|
4329
Description:
P-SOFT H-Sphere contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the "template_name" variable upon submission to the "psoft.hsphere.CP" script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2003-06-09
|
H-Sphere psoft.hsphere.CP template_name Parameter XSS
|
|
35977
Description:
(Description Provided by CVE) : Directory traversal vulnerability in H-Sphere SiteStudio 1.6 allows remote attackers to read, or include and execute, arbitrary local files via a .. (dot dot) in the template parameter.
|
2007-05-10
|
H-Sphere SiteStudio template Parameter Traversal Arbitrary File Access
|
|
42945
Description:
(Description Provided by CVE) : Unspecified vulnerability in Parallels SiteStudio before 1.7.2, and 1.8.x before 1.8b, as used in Parallels H-Sphere 3.0 before Patch 9 and 2.5 before Patch 11, has unknown impact and attack vectors.
|
2008-02-26
|
H-Sphere SiteStudio Unspecified Issue
|
|
48858
Description:
(Description Provided by CVE) : Cross-site request forgery (CSRF) vulnerability in actions.php in Positive Software H-Sphere WebShell 4.3.10 allows remote attackers to perform unauthorized actions as an administrator, including file deletion and creation, via a link or IMG tag to the (1) overkill, (2) futils, or (3) edit actions.
|
2008-09-28
|
H-Sphere WebShell actions.php Multiple Parameter CSRF
|
|
48857
Description:
(Description Provided by CVE) : Cross-site scripting (XSS) vulnerability in actions.php in Positive Software H-Sphere WebShell 4.3.10 allows remote attackers to inject arbitrary web script or HTML via (1) the fn parameter during a dload action, (2) the mask parameter during a search action, and (3) the tab parameter during a sysinfo action.
|
2008-09-28
|
H-Sphere WebShell actions.php Multiple Parameter XSS
|
|
60390
Description:
(Description Provided by CVE) : Multiple buffer overflows in H-Sphere WebShell 2.3 allow remote attackers to execute arbitrary code via (1) a long URL content type in CGI::readFile, (2) a long path in diskusage, and (3) a long fname in flist.
|
2003-01-06
|
H-Sphere WebShell CGI::readFile URL Content Type Handling Remote Overflow
|
|
60391
Description:
(Description Provided by CVE) : Multiple buffer overflows in H-Sphere WebShell 2.3 allow remote attackers to execute arbitrary code via (1) a long URL content type in CGI::readFile, (2) a long path in diskusage, and (3) a long fname in flist.
|
2003-01-06
|
H-Sphere WebShell diskusage Path Handling Remote Overflow
|
|
60392
Description:
(Description Provided by CVE) : Multiple buffer overflows in H-Sphere WebShell 2.3 allow remote attackers to execute arbitrary code via (1) a long URL content type in CGI::readFile, (2) a long path in diskusage, and (3) a long fname in flist.
|
2003-01-06
|
H-Sphere WebShell flist fname Argument Handling Remote Overflow
|
|
59587
Description:
(Description Provided by CVE) : H-Sphere WebShell 2.3 allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) mode and (2) zipfile parameters in a URL request.
|
2003-01-06
|
H-Sphere WebShell Multiple Parameter Shell Metacharacter Remote Command Execution
|
|
44703
Description:
Unknown / Incomplete
|
2007-10-05
|
H-Sphere Webshell4 /webshell4/upeek.php pwf Variable Arbitrary Truncated File Access
|
|
44704
Description:
Unknown / Incomplete
|
2007-10-05
|
H-Sphere Webshell4 /webshell4/viewer.php fn Parameter Arbitrary File Access
|
|
44702
Description:
Unknown / Incomplete
|
2007-10-05
|
H-Sphere Webshell4 302 Response Manipulation Access Bypass
|
|
48232
Description:
(Description Provided by CVE) : Multiple cross-site scripting (XSS) vulnerabilities in login.php in webshell4 in Parallels H-Sphere 3.0.0 P9 and 3.1 P1 allow remote attackers to inject arbitrary web script or HTML via the (1) err, (2) errorcode, and (3) login parameters.
|
2008-09-13
|
H-Sphere webshell4 login.php Multiple Parameter XSS
|
|
48856
Description:
Unknown / Incomplete
|
2008-05-31
|
H2 Database Engine Char Array Cleartext Password Disclosure
|
|
70892
Description:
H2 Database Engine contains a flaw that may lead to an unauthorized information disclosure. The issue is triggered when the program stores plain text passwords in configuration files, which will disclose logon credentials to a local attacker.
|
2010-08-22
|
H2 Database Engine Configuration File Plaintext Password Local Disclosure
|
|
91463
Description:
H2 Database Engine contains a flaw in the TCP server. This issue is due to the application failing to properly enforce client access rights. This may allow a remote attacker to overwrite arbitrary properties.
|
2013-03-17
|
H2 Database Engine TCP Server Client Access Rights Enforcement Failure
|
|
65660
Description:
(Description Provided by CVE) : H264WebCam 3.7 allows remote attackers to cause a denial of service (crash) via a long URI in a GET request, which triggers a NULL pointer dereference. NOTE: some of these details are obtained from third party information.
|
2010-06-18
|
H264WebCam GET Request NULL Dereference Remote DoS
|
|
43053
Description:
Unknown / Incomplete
|
2008-03-01
|
h2desk Support System helpdesk/index.php Direct Request Unauthorized Database Export
|
|
43052
Description:
h2desk Support System contains a flaw that may lead to an unauthorized information disclosure. The issue is triggered when a remote attacker edits the session ID, which will disclose the software's session path resulting in a loss of confidentiality. While such information is relatively low risk, it is often useful in carrying out additional, more focused attacks.
|
2008-03-01
|
h2desk Support System Malformed Session ID Path Disclosure
|
|
49418
Description:
Unknown / Incomplete
|
2008-10-28
|
H2O-CMS Multiple Cookie Manipulation Admin Authentication Bypass
|
|
49419
Description:
Unknown / Incomplete
|
2008-10-28
|
H2O-CMS SaveConfig.php Multiple Variable Arbitrary PHP Code Execution
|
|
73228
Description:
Unknown / Incomplete
|
2011-06-17
|
H3C ER5100 Router Web Interface userLogin.asp Authentication Bypass
|