| OSVDB ID | Disclosure Date | Title |
|
17941
Description:
(Description Provided by CVE) : PHP remote file inclusion vulnerability in im.php in Laffer 0.3.2.6 and 0.3.2.7 allows remote attackers to execute arbitrary PHP code via the CFG_PATH variable.
|
2005-07-09
|
Laffer im.php CFG_PATH Parameter Remote File Inclusion
|
|
11382
Description:
(Description Provided by CVE) : LakeWeb Filemail CGI script allows remote attackers to execute arbitrary commands via shell metacharacters in the recipient email address.
|
1998-11-09
|
LakeWeb Filemail Recipient Address Command Execution
|
|
11381
Description:
(Description Provided by CVE) : LakeWeb Mail List CGI script allows remote attackers to execute arbitrary commands via shell metacharacters in the recipient email address.
|
1998-11-09
|
LakeWeb Mail List Recipient Address Command Execution
|
|
16305
Description:
(Description Provided by CVE) : The LAM runtime environment package (lam-runtime-7.0.6-2mdk) on Mandrake Linux installs the mpi user without a password, which allows local users to gain privileges.
|
2005-04-28
|
lam-runtime RPM Default Account
|
|
40446
Description:
(Description Provided by CVE) : Multiple PHP remote file inclusion vulnerabilities in Lama Software allow remote attackers to execute arbitrary PHP code via a URL in the MY_CONF[classRoot] parameter to (1) inc.steps.access_error.php, (2) inc.steps.check_login.php, or (3) inc.steps.init_system.php in admin/functions/.
|
2008-01-21
|
Lama Software inc.steps.access_error.php MY_CONF[classRoot] Parameter Remote File Inclusion
|
|
40447
Description:
(Description Provided by CVE) : Multiple PHP remote file inclusion vulnerabilities in Lama Software allow remote attackers to execute arbitrary PHP code via a URL in the MY_CONF[classRoot] parameter to (1) inc.steps.access_error.php, (2) inc.steps.check_login.php, or (3) inc.steps.init_system.php in admin/functions/.
|
2008-01-21
|
Lama Software inc.steps.check_login.php MY_CONF[classRoot] Parameter Remote File Inclusion
|
|
40448
Description:
(Description Provided by CVE) : Multiple PHP remote file inclusion vulnerabilities in Lama Software allow remote attackers to execute arbitrary PHP code via a URL in the MY_CONF[classRoot] parameter to (1) inc.steps.access_error.php, (2) inc.steps.check_login.php, or (3) inc.steps.init_system.php in admin/functions/.
|
2008-01-21
|
Lama Software inc.steps.init_system.php MY_CONF[classRoot] Parameter Remote File Inclusion
|
|
18893
Description:
Unknown / Incomplete
|
2005-08-19
|
LAN Management System (LMS) Database Backup Session Disclosure
|
|
35479
Description:
(Description Provided by CVE) : Cross-site scripting (XSS) vulnerability in LAN Management System (LMS) before 1.6.9 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, probably involving the OD parameter to contrib/formularz_przelewu_wplaty/druk.php.
|
2007-04-06
|
LAN Management System (LMS) druk.php OD Parameter XSS
|
|
36194
Description:
LAN Management System (LMS) contains a flaw that may allow a remote attacker to execute arbitrary commands or code. The issue is due to the 'lib/language.php' script not properly sanitizing user input supplied to the '_LIB_DIR' parameter. This may allow an attacker to include a file from a third-party remote host that contains commands or code that will be executed by the vulnerable script with the same privileges as the web server.
|
2007-06-20
|
LAN Management System (LMS) lib/language.php _LIB_DIR Parameter Remote File Inclusion
|
|
35480
Description:
(Description Provided by CVE) : PHP remote file inclusion vulnerability in modules/rtmessageadd.php in LAN Management System (LMS) 1.5.3, and possibly 1.5.4, allows remote attackers to execute arbitrary PHP code via a URL in the _LIB_DIR parameter, a different vector than CVE-2007-1643.
|
2007-04-22
|
LAN Management System (LMS) modules/rtmessageadd.php _LIB_DIR Parameter Remote File Inclusion
|
|
18892
Description:
Unknown / Incomplete
|
2005-08-19
|
LAN Management System (LMS) Session Cleartext Password Disclosure
|
|
34423
Description:
(Description Provided by CVE) : Multiple PHP remote file inclusion vulnerabilities in LAN Management System (LMS) 1.8.9 Vala and earlier allow remote attackers to execute arbitrary PHP code via a URL in (1) the CONFIG[directories][userpanel_dir] parameter to userpanel.php or the (2) _LIB_DIR parameter to welcome.php.
|
2007-03-22
|
LAN Management System (LMS) userpanel.php CONFIG[directories][userpanel_dir] Parameter Remote File Inclusion
|
|
34424
Description:
(Description Provided by CVE) : Multiple PHP remote file inclusion vulnerabilities in LAN Management System (LMS) 1.8.9 Vala and earlier allow remote attackers to execute arbitrary PHP code via a URL in (1) the CONFIG[directories][userpanel_dir] parameter to userpanel.php or the (2) _LIB_DIR parameter to welcome.php.
|
2007-03-22
|
LAN Management System (LMS) welcome.php _LIB_DIR Parameter Remote File Inclusion
|
|
37369
Description:
(Description Provided by CVE) : Unspecified vulnerability in the info request mechanism in LAN Messenger before 1.5.1.2 allows remote attackers to cause a denial of service (application crash) or transmit spam via unspecified vectors.
|
2007-06-16
|
LAN Messenger Info Request Mechanism Unspecified Remote DoS
|
|
37470
Description:
(Description Provided by CVE) : Multiple SQL injection vulnerabilities in module.php in LANAI (la-nai) CMS 1.2.14 allow remote attackers to execute arbitrary SQL commands via (1) the mid parameter in an faqviewgroup action in the FAQ Modules, (2) the cid parameter in the EZSHOPINGCART Modules, or (3) the gid parameter in a view action in the GALLERY Modules.
|
2007-08-03
|
LANAI CMS EZSHOPINGCART Module cid Parameter SQL Injection
|
|
36438
Description:
(Description Provided by CVE) : Multiple SQL injection vulnerabilities in module.php in LANAI (la-nai) CMS 1.2.14 allow remote attackers to execute arbitrary SQL commands via (1) the mid parameter in an faqviewgroup action in the FAQ Modules, (2) the cid parameter in the EZSHOPINGCART Modules, or (3) the gid parameter in a view action in the GALLERY Modules.
|
2007-08-03
|
LANAI CMS FAQ Module mid Parameter SQL Injection
|
|
37471
Description:
(Description Provided by CVE) : Multiple SQL injection vulnerabilities in module.php in LANAI (la-nai) CMS 1.2.14 allow remote attackers to execute arbitrary SQL commands via (1) the mid parameter in an faqviewgroup action in the FAQ Modules, (2) the cid parameter in the EZSHOPINGCART Modules, or (3) the gid parameter in a view action in the GALLERY Modules.
|
2007-08-03
|
LANAI CMS GALLERY Module gid Parameter SQL Injection
|
|
66684
Description:
(Description Provided by CVE) : Lanai Core 0.6 allows remote attackers to obtain configuration information via a direct request to info.php, which calls the phpinfo function.
|
2009-08-24
|
Lanai Core info.php Direct Request Information Disclosure
|
|
66683
Description:
(Description Provided by CVE) : Directory traversal vulnerability in modules/backup/download.php in Lanai Core 0.6 allows remote attackers to read arbitrary files via a .. (dot dot) in the f parameter.
|
2009-08-24
|
Lanai Core modules/backup/download.php f Parameter Traversal Arbitrary File Access
|
|
26812
Description:
(Description Provided by CVE) : The Lanap BotDetect APS.NET CAPTCHA component before 1.5.4.0 stores the UUID and hash for a CAPTCHA in the ViewState of a page, which makes it easier for remote attackers to conduct automated attacks by "replaying the ViewState for a known number."
|
2006-06-23
|
Lanap BotDetect ASP.NET CAPTCHA ViewState Bypass
|
|
13461
Description:
(Description Provided by CVE) : LANChat Pro Revival 1.666c allows remote attackers to cause a denial of service (application crash) via a malformed UDP packet.
|
2005-02-03
|
LANChat Malformed UDP Packet DoS
|
|
19504
Description:
Land Down Under (LDU) contains a flaw that may allow a remote attacker to carry out an SQL injection attack. The issue is due to the 'auth.php' script not properly sanitizing user-supplied input to the 'm' variable. This may allow a remote attacker to inject or manipulate SQL queries in the back-end database.
|
2005-09-13
|
Land Down Under (LDU) auth.php m Parameter SQL Injection
|
|
11301
Description:
Land Down Under contains a flaw that will allow an attacker to inject arbitrary SQL code. The problem is that the "rusername" variable in the auth.php module is not verified properly and will allow an attacker to inject or manipulate SQL queries.
|
2004-10-30
|
Land Down Under (LDU) auth.php rusername Parameter SQL Injection
|
|
2943
Description:
Land Down Under website manager contains a flaw that may lead to an unauthorized information disclosure. The issue is triggered when SQL injection attacks occur, which will disclose user information resulting in a loss of confidentiality.
|
2003-12-10
|
Land Down Under (LDU) auth.php SQL Injection
|
|
6508
Description:
Land Down Under (LDU) contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate [img] BBCode tags upon submission to various scripts. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2004-05-29
|
Land Down Under (LDU) BBCode IMG Tag XSS
|
|
25293
Description:
Unknown / Incomplete
|
2006-04-21
|
Land Down Under (LDU) calendar.php Multiple Variable Path Disclosure
|
|
11300
Description:
Land Down Under contains a flaw that will allow an attacker to inject arbitrary SQL code. The problem is that the "id" variable in the comments.php module is not verified properly and will allow an attacker to inject or manipulate SQL queries.
|
2004-10-30
|
Land Down Under (LDU) comments.php id Parameter SQL Injection
|
|
19300
Description:
Land Down Under (LDU) contains a flaw that may allow a remote attacker to carry out an SQL injection attack. The issue is due to the 'events.php' script not properly sanitizing user-supplied input to the 'c' variable. This may allow a remote attacker to inject or manipulate SQL queries in the back-end database.
|
2005-08-29
|
Land Down Under (LDU) events.php c Parameter SQL Injection
|
|
19301
Description:
Land Down Under (LDU) contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate user-supplied input to the 'Description' Field upon submission to the 'events.php' script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2005-09-05
|
Land Down Under (LDU) events.php Description Field XSS
|