| OSVDB ID | Disclosure Date | Title |
|
19296
Description:
Land Down Under (LDU) contains a flaw that may allow a remote attacker to carry out an SQL injection attack. The issue is due to the 'forums.php' script not properly sanitizing user-supplied input to the 's', 'x', 'n' and 'm' variables. This may allow a remote attacker to inject or manipulate SQL queries in the back-end database.
|
2005-08-20
|
Land Down Under (LDU) forums.php Multiple Parameter SQL Injection
|
|
19299
Description:
Land Down Under (LDU) contains a flaw that may allow a remote attacker to carry out an SQL injection attack. The issue is due to the 'index.php' script not properly sanitizing user-supplied input to the 'c' variable. This may allow a remote attacker to inject or manipulate SQL queries in the back-end database.
|
2005-08-29
|
Land Down Under (LDU) index.php c Parameter SQL Injection
|
|
19297
Description:
Land Down Under (LDU) contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate 'c', 'm' and 'w' variables upon submission to the 'index.php' script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2005-08-20
|
Land Down Under (LDU) index.php Multiple Parameter XSS
|
|
33344
Description:
(Description Provided by CVE) : SQL injection vulnerability in Journal.inc.php in Neocrome Land Down Under (LDU) 8.x and earlier allows remote attackers to execute arbitrary SQL commands via the w parameter to journal.php.
|
2006-12-29
|
Land Down Under (LDU) journal.inc.php w Parameter SQL Injection
|
|
19293
Description:
Land Down Under (LDU) contains a flaw that may allow a remote attacker to carry out an SQL injection attack. The issue is due to the 'journal.php' script not properly sanitizing user-supplied input to the 'm' variable. This may allow a remote attacker to inject or manipulate SQL queries in the back-end database.
|
2005-08-20
|
Land Down Under (LDU) journal.php m Parameter SQL Injection
|
|
19295
Description:
Land Down Under (LDU) contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the 'w' variable upon submission to the 'journal.php' script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2005-08-20
|
Land Down Under (LDU) journal.php w Parameter XSS
|
|
19292
Description:
Land Down Under (LDU) contains a flaw that may allow a remote attacker to carry out an SQL injection attack. The issue is due to the 'links.php' script not properly sanitizing user-supplied input to the 'w' variable. This may allow a remote attacker to inject or manipulate SQL queries in the back-end database.
|
2005-08-20
|
Land Down Under (LDU) links.php w Parameter SQL Injection
|
|
19294
Description:
Land Down Under (LDU) contains a flaw that may allow a remote attacker to carry out an SQL injection attack. The issue is due to the 'list.php' script not properly sanitizing user-supplied input to the 'o', 'w', 's', 'p' and 'c' variables. This may allow a remote attacker to inject or manipulate SQL queries in the back-end database.
|
2005-08-20
|
Land Down Under (LDU) list.php Multiple Parameter SQL Injection
|
|
19505
Description:
Land Down Under (LDU) contains a flaw that may allow a remote attacker to carry out an SQL injection attack. The issue is due to the 'plug.php' script not properly sanitizing user-supplied input to the 'e' variable. This may allow a remote attacker to inject or manipulate SQL queries in the back-end database.
|
2005-09-13
|
Land Down Under (LDU) plug.php e Parameter SQL Injection
|
|
11302
Description:
Land Down Under contains a flaw that will allow an attacker to inject arbitrary SQL code. The problem is that the "h" variable in the plug.php module is not verified properly and will allow an attacker to inject or manipulate SQL queries.
|
2004-10-30
|
Land Down Under (LDU) plug.php h Parameter SQL Injection
|
|
31433
Description:
(Description Provided by CVE) : plug.php in Land Down Under (LDU) 802 and earlier allows remote attackers to obtain sensitive information via an invalid (1) month or (2) year parameter, which reveals the path in an error message.
|
2006-04-27
|
Land Down Under (LDU) plug.php Multiple Variable Path Disclosure
|
|
32036
Description:
(Description Provided by CVE) : SQL injection vulnerability in polls.php in Neocrome Land Down Under (LDU) 8.x and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.
|
2006-11-30
|
Land Down Under (LDU) polls.php id Parameter SQL Injection
|
|
19585
Description:
Land Down Under contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to unspecified scripts not properly sanitizing user-supplied input to the 'Referer' HTTP header. This may allow an attacker to inject or manipulate SQL queries in the back-end database.
|
2005-09-21
|
Land Down Under (LDU) Referer HTTP Header SQL Injection
|
|
19298
Description:
Land Down Under contains a flaw that allows a remote cross-site scripting (XSS) attack. This flaw exists because the application does not validate user signatures for arbitrary web script or HTML. This may allow a user to create a specially crafted URL that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2005-08-28
|
Land Down Under (LDU) User Signature XSS
|
|
31953
Description:
(Description Provided by CVE) : SQL injection vulnerability in system/core/profile/profile.inc.php in Neocrome Land Down Under (LDU) 8.x and earlier allows remote authenticated users to execute arbitrary SQL commands via a url-encoded id parameter to users.php that begins with a valid filename, as demonstrated by "default.gif" followed by a double-encoded NULL and ' (apostrophe) (%2500%2527).
|
2006-11-21
|
Land Down Under (LDU) users.php id Parameter SQL Injection
|
|
11299
Description:
Land Down Under contains a flaw that will allow an attacker to inject arbitrary SQL code. The problem is that the "s", "w" and "d" variables in the users.php module are not verified properly and will allow an attacker to inject or manipulate SQL queries.
|
2004-10-30
|
Land Down Under (LDU) users.php Multiple Parameter SQL Injection
|
|
3222
Description:
LANDesk Software contains a flaw that may allow a malicious user to execute code on a vulnerable host. The issue is triggered when a web page containing a call to the vulnerable ActiveX control along with a malicious argument occurs. It is possible that the flaw may allow the attacker to execute arbitrary code on the vulnerable host with privileges of the browser user, resulting in a loss of confidentiality, integrity, and/or availability.
|
2003-12-27
|
LANDesk ircrboot.dll Overflow
|
|
62136
Description:
LANDesk Management Gateway contains a flaw that allows a remote Cross-site Request Forgery (CSRF / XSRF) attack. The flaw exists because the application does not require multiple steps or explicit confirmation for sensitive transactions such us inject and execute arbitrary shell commands. By using a crafted URL (e.g., a crafted GET request inside an "img" tag), an attacker may trick the victim into clicking on the image to take advantage of the trust relationship between the authenticated victim and the application. Such an attack could trick the victim into executing arbitrary commands in the context of their session with the application, without further prompting or verification.
|
2010-02-03
|
LANDesk Management Gateway Arbitrary Shell Command Execution CSRF
|
|
69251
Description:
LANDesk Management Gatewa contains a flaw that allows a remote Cross-site Request Forgery (CSRF / XSRF) attack. The flaw exists because the application does not require multiple steps or explicit confirmation for sensitive transactions in the gsp/drivers.php script's shell metacharacters in the 'DRIVES' parameter. By using a crafted URL (e.g., a crafted GET request inside an "img" tag), an attacker may trick the victim into clicking on the image to take advantage of the trust relationship between the authenticated victim and the application. Such an attack could trick the victim into executing arbitrary commands in the context of their session with the application, without further prompting or verification.
|
2010-11-10
|
LANDesk Management Gateway gsb/drivers.php DRIVES Parameter Shell Metacharacter Arbitrary Command Execution
|
|
62137
Description:
LANDesk Management Gateway contains a flaw that allows a remote cross site scripting (XSS) attack. This flaw exists because the application does not validate an unspecified parameter upon submission to an unspecified script. This may allow a user to create a specially crafted URL that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2010-02-03
|
LANDesk Management Gateway Unspecified XSS
|
|
34964
Description:
A buffer overflow exists in LANDesk Management Suite. The Alert Service fails to validate data received on UDP port 65535 resulting in a stack overflow. With a specially crafted request, a remote attacker can cause arbitrary code execution resulting in a loss of integrity.
|
2007-04-13
|
LANDesk Management Suite Alert Service (aolnsrvr.exe) Remote Overflow
|
|
54671
Description:
(Description Provided by CVE) : Directory traversal vulnerability in the PXE TFTP Service (PXEMTFTP.exe) in LANDesk Management Suite (LDMS) 8.80.1.1 and earlier allows remote attackers to read arbitrary files via a subdirectory name followed by ".." sequences, a different vulnerability than CVE-2008-1643.
|
2008-04-01
|
LANDesk Management Suite PXE TFTP Service (PXEMTFTP.exe) Traversal Arbitrary File Access
|
|
43982
Description:
(Description Provided by CVE) : Directory traversal vulnerability in the PXE TFTP Service (PXEMTFTP.exe) in LANDesk Management Suite (LDMS) 8.7 SP5 and earlier and 8.8 allows remote attackers to read arbitrary files via unspecified vectors.
|
2008-03-31
|
LANDesk Management Suite PXE TFTP Service Traversal Arbitrary File Access
|
|
58010
Description:
Unknown / Incomplete
|
2009-05-11
|
LANDesk Management Suite Unspecified Remote Pre-authentication Issue (1)
|
|
58011
Description:
Unknown / Incomplete
|
2009-05-11
|
LANDesk Management Suite Unspecified Remote Pre-authentication Issue (2)
|
|
48123
Description:
(Description Provided by CVE) : Multiple buffer overflows in the QIP Server Service (aka qipsrvr.exe) in LANDesk Management Suite, Security Suite, and Server Manager 8.8 and earlier allow remote attackers to execute arbitrary code via a crafted heal request, related to the StringToMap and StringSize arguments.
|
2008-09-12
|
LANDesk Multiple Products QIP Server Service (qipsrvr.exe) Heal Request Packet Handling Overflow
|
|
10964
Description:
Unknown / Incomplete
|
2004-10-19
|
LANDesk Remote Desktop Port idsintkm.dll DoS
|
|
21434
Description:
LandShop contains a flaw that may lead to an unauthorized information disclosure. The issue is triggered when a remote attacker inserts arbitrary data into the 'lang' variable in the 'ls.php' script, which will disclose the software's installation path resulting in a loss of confidentiality. While such information is relatively low risk, it is often useful in carrying out additional, more focused attacks.
|
2005-12-05
|
LandShop ls.php lang Variable Path Disclosure
|
|
21433
Description:
LandShop contains a flaw that may allow a remote attacker to carry out an SQL injection attack. The issue is due to the 'ls.php' script not properly sanitizing user-supplied input to the 'search_order', 'search_type', 'keyword', and 'search_area' variables. This may allow a remote attacker to inject or manipulate SQL queries in the back-end database.
|
2005-12-05
|
LandShop ls.php Multiple Parameter SQL Injection
|
|
30277
Description:
(Description Provided by CVE) : SQL injection vulnerability in ls.php in SAMEDIA LandShop allows remote attackers to execute arbitrary SQL commands via the infield parameter. NOTE: the start, search_order, search_type, and search_area parameters are already covered by CVE-2005-4018.
|
2006-11-09
|
LandShop ls.php Multiple Parameter SQL Injection
|