| OSVDB ID | Disclosure Date | Title |
|
51210
Description:
(Description Provided by CVE) : Unrestricted file upload vulnerability in admin/editor/images.php in K&S Shopsoftware allows remote attackers to execute arbitrary PHP code by uploading a file with an executable extension, then accessing it via a direct request to the file in images/upload/.
|
2008-12-17
|
K&S Shopsoftware admin/editor/images.php File Upload Arbitrary PHP Code Execution
|
|
49476
Description:
(Description Provided by CVE) : Cross-site scripting (XSS) vulnerability in analysis.cgi 1.44, as used in K's CGI Access Log Kaiseki (1) jcode.pl and (2) Jcode.pm, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
|
2008-07-23
|
K's CGI Access Log Kaiseki analysis.cgi XSS
|
|
40495
Description:
(Description Provided by CVE) : kb_whois.cgi in K+B-Bestellsystem (aka KB-Bestellsystem) allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) domain or (2) tld parameter in a check_owner action.
|
2007-11-22
|
K+B-Bestellsystem kb_whois.cgi check_owner Action Multiple Variable Remote Command Execution
|
|
35259
Description:
(Description Provided by CVE) : Directory traversal vulnerability in index.php in Kai Content Management System (K-CMS) 1.0 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the current_theme parameter.
|
2007-04-04
|
K-CMS index.php current_theme Parameter Traversal Local File Inclusion
|
|
52237
Description:
Unknown / Incomplete
|
2008-08-10
|
K-Links Directory Report Link Functionality SQL Injection
|
|
47609
Description:
(Description Provided by CVE) : Multiple SQL injection vulnerabilities in Qsoft K-Links allow remote attackers to execute arbitrary SQL commands via (1) the id parameter to visit.php, or the PATH_INFO to the default URI under (2) report/, (3) addreview/, or (4) refer/.
|
2008-08-02
|
K-Links Platinum addreview/ PATH_INFO SQL Injection
|
|
47606
Description:
(Description Provided by CVE) : Cross-site scripting (XSS) vulnerability in index.php in Qsoft K-Links allows remote attackers to inject arbitrary web script or HTML via the login_message parameter in a login action.
|
2008-08-02
|
K-Links Platinum index.php login_message Parameter XSS
|
|
47610
Description:
(Description Provided by CVE) : Multiple SQL injection vulnerabilities in Qsoft K-Links allow remote attackers to execute arbitrary SQL commands via (1) the id parameter to visit.php, or the PATH_INFO to the default URI under (2) report/, (3) addreview/, or (4) refer/.
|
2008-08-02
|
K-Links Platinum refer/ PATH_INFO SQL Injection
|
|
47608
Description:
(Description Provided by CVE) : Multiple SQL injection vulnerabilities in Qsoft K-Links allow remote attackers to execute arbitrary SQL commands via (1) the id parameter to visit.php, or the PATH_INFO to the default URI under (2) report/, (3) addreview/, or (4) refer/.
|
2008-08-02
|
K-Links Platinum report/ PATH_INFO SQL Injection
|
|
47607
Description:
K-Links Platinum contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the 'visit.php' script not properly sanitizing user-supplied input to the 'id' parameter. This may allow an attacker to inject or manipulate SQL queries in the back-end database.
|
2008-08-02
|
K-Links Platinum visit.php id Parameter SQL Injection
|
|
49880
Description:
(Description Provided by CVE) : vsfilter.dll in K-Lite Mega Codec Pack 3.5.7.0 allows remote attackers to cause a denial of service (application crash) via a malformed FLV file.
|
2008-09-25
|
K-Lite Mega Codec Pack vsfilter.dll Malformed FLV File Handling DoS
|
|
68784
Description:
Unknown / Incomplete
|
2010-08-04
|
K-Meleon about:neterror URL Handling Overflow DoS
|
|
55360
Description:
(Description Provided by CVE) : Mozilla Firefox 1.5.0.2 and possibly other versions before 1.5.0.4, Netscape 8.1, 8.0.4, and 7.2, and K-Meleon 0.9.13 allows user-assisted remote attackers to open local files via a web page with an IMG element containing a SRC attribute with a non-image file:// URL, then tricking the user into selecting View Image for the broken image, as demonstrated using a .wma file to launch Windows Media Player, or by referencing an "alternate web page."
|
2006-04-17
|
K-Meleon IMG Element Crafted file:// URL Arbitrary Local File Access
|
|
62402
Description:
(Description Provided by CVE) : Array index error in the (1) dtoa implementation in dtoa.c (aka pdtoa.c) and the (2) gdtoa (aka new dtoa) implementation in gdtoa/misc.c in libc, as used in multiple operating systems and products including in FreeBSD 6.4 and 7.2, NetBSD 5.0, OpenBSD 4.5, Mozilla Firefox 3.0.x before 3.0.15 and 3.5.x before 3.5.4, K-Meleon 1.5.3, SeaMonkey 1.1.8, and other products, allows context-dependent attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a large precision value in the format argument to a printf function, which triggers incorrect memory allocation and a heap-based buffer overflow during conversion to a floating-point number.
|
2009-11-19
|
K-Meleon libc dtoa Implementation Floating Point Parsing Memory Corruption
|
|
59026
Description:
K-Meleon web browser contains a flaw that may allow a remote attacker to launch a program from a known location. The issue is triggered when rendering specially-crafted web page using the "shell:" command. This requires the attacker to trick a user into visiting the web page.
|
2004-07-08
|
K-Meleon shell: URI Arbitrary Command Execution
|
|
57754
Description:
(Description Provided by CVE) : K-Meleon 1.5.3 allows context-dependent attackers to spoof the address bar, via window.open with a relative URI, to show an arbitrary file: URL after a victim has visited any file: URL, as demonstrated by a visit to a file: document written by the attacker.
|
2009-08-15
|
K-Meleon window.open() New Window URL Path Spoofing Weakness
|
|
48338
Description:
K-Rate Premium contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the 'index.php' script not properly sanitizing user-supplied input to the 'show' parameter (when 'req' is set to 'online') and 'id' and 'image' parameters (when 'act' is set to 'vote'). This may allow an attacker to inject or manipulate SQL queries in the back-end database, allowing for the manipulation or disclosure of arbitrary data.
|
2008-08-26
|
K-Rate Premium index.php Multiple Parameter SQL Injection
|
|
48342
Description:
K-Rate Premium contains a flaw that may allow an attacker to execute arbitrary PHP code. The issue is triggered due to the 'Manage Templates' script failing to sanitize template data before storing.
|
2008-08-26
|
K-Rate Premium Manage Templates Data Handling Arbitrary PHP Code Execution
|
|
48340
Description:
K-Rate Premium contains a flaw that allows a remote cross site scripting (XSS) attack. This flaw exists because the application does not validate the 'Title' and 'Text' fields upon submission to the 'Post A New Thread' script. This may allow a user to create a specially crafted URL that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2008-08-26
|
K-Rate Premium Post A New Entry Multiple Field XSS
|
|
48339
Description:
K-Rate Premium contains a flaw that allows a remote cross site scripting (XSS) attack. This flaw exists because the application does not validate the 'Your Message' field upon submission to the 'Post a New Thread' script. This may allow a user to create a specially crafted URL that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2008-08-26
|
K-Rate Premium Post A New Thread Your Message Field XSS
|
|
48341
Description:
K-Rate Premium contains a flaw that allows a remote cross site scripting (XSS) attack. This flaw exists because the application does not validate the 'Description' field upon submission to the 'Your Pictures' script. This may allow a user to create a specially crafted URL that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2008-08-26
|
K-Rate Premium Your Pictures Description Field XSS
|
|
21128
Description:
r0t has reported some vulnerabilities in K-Search, which can be exploited by malicious users to conduct SQL injection attacks. Input passed to the "id", "stat", and "source" parameters in "index.php" isn't properly sanitised before being used in a SQL query. This can be exploited to manipulate SQL queries by injecting arbitrary SQL code. 1. Input passed to the "term" parameter in "index.php" isn't properly sanitised before being used in a SQL query.This can be exploited to manipulate SQL queries by injecting arbitrary SQL code. examples: /index.php?term=%23%25%23term%23%25%23&sm =Mekl%E7t&source=1&req=search /index.php?term=%28%27r0t+checker%27%29&sm =Mekl%E7t&source=1&req=search 2. Input passed to the many parameters in "index.php" isn't properly sanitised before being used in a SQL query (Below examples).This can be exploited to manipulate SQL queries by injecting arbitrary SQL code. examples: /index.php?req=edit&id=[SQL] /index.php?req=view&act=stat_all&stat=[SQL] /index.php?req=view&act=status&id=1&stat=[SQL] /index.php?req=view&act=status&id=[SQL] /index.php?req=delsite&id=[SQL] /index.php?req=search&source=[SQL] 3. Into "/index.php?req=add" , upload image parameters isn't properly sanitised before being used in a SQL query. Attacker can get full instalisation path.
|
2005-11-28
|
K-Search Crafted Image Upload Path Disclosure
|
|
21127
Description:
K-Search contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the index.php script not properly sanitizing user-supplied input to the 'id', 'stat' and 'source' variable. This may allow an attacker to inject or manipulate SQL queries in the back-end database.
|
2005-11-28
|
K-Search index.php Multiple Parameter SQL Injection
|
|
65806
Description:
K-Search contains a flaw that allows a remote cross site scripting (XSS) attack. This flaw exists because the application does not validate the 'term' parameter upon submission to the 'index.php' script. This may allow a user to create a specially crafted URL that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2010-06-22
|
K-Search index.php term Parameter XSS
|
|
68182
Description:
Unknown / Incomplete
|
2010-09-11
|
K2 Component for Joomla! Comment Page Multiple Parameter XSS
|
|
55759
Description:
K2 Component for Joomla! contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the 'index.php' script not properly sanitizing user-supplied input to the 'category' variable. This may allow an attacker to inject or manipulate SQL queries in the back-end database.
|
2009-06-29
|
K2 Component for Joomla! index.php category Parameter SQL Injection
|
|
68699
Description:
K2Editor is prone to a flaw in the way it loads dynamic-link libraries (DLL). The program uses a fixed path to look for specific files or libraries. This path includes directories that may not be trusted or under user control. By placing a custom version of the file or library in the path, the program will load it before the legitimate version. This allows an attacker to inject custom code that will be run with the privilege of the program or user executing the program. This can be done by tricking a user into opening certain text files from the local file system or a USB drive in some cases. This attack can be leveraged remotely in some cases by placing the malicious file or library on a network share or extracted archive downloaded from a remote source.
|
2010-10-10
|
K2Editor Path Subversion Arbitrary Executable Injection Code Execution
|
|
50764
Description:
(Description Provided by CVE) : K7AntiVirus 7.10.541 and possibly 7.10.454, when Internet Explorer 6 or 7 is used, allows remote attackers to bypass detection of malware in an HTML document by placing an MZ header (aka "EXE info") at the beginning, and modifying the filename to have (1) no extension, (2) a .txt extension, or (3) a .jpg extension, as demonstrated by a document containing a CVE-2006-5745 exploit.
|
2008-12-09
|
K7AntiVirus HTML Document MZ Header Multiple Filename Modification Malware Detection Bypass
|
|
77240
Description:
Unknown / Incomplete
|
2007-01-10
|
ka-Map getcjs.php Arbitrary File Access
|
|
75823
Description:
(Description Provided by CVE) : ka-Map 1.0-20070205 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by test.php and certain other files.
|
2011-01-28
|
ka-Map Multiple Script Direct Request Path Disclosure
|