| OSVDB ID | Disclosure Date | Title |
|
64494
Description:
LDF contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the default.asp script not properly sanitizing user-supplied input to the 'page' parameter. This may allow an attacker to inject or manipulate SQL queries in the back-end database, allowing for the manipulation or disclosure of arbitrary data.
|
2010-02-06
|
LDF default.asp page Parameter SQL Injection
|
|
52027
Description:
LDF contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the login.asp script not properly sanitizing user-supplied input to the user parameter. This may allow an attacker to inject or manipulate SQL queries in the back-end database.
|
2009-01-23
|
LDF login.asp user Parameter SQL Injection
|
|
44681
Description:
(Description Provided by CVE) : ldm in Linux Terminal Server Project (LTSP) 0.99 and 2 passes the -ac option to the X server on each LTSP client, which allows remote attackers to connect to this server via TCP port 6006 (aka display :6).
|
2008-04-28
|
ldm X11 Forwarding LTSP Client Connection Restriction Bypass
|
|
52859
Description:
(Description Provided by CVE) : Heap-based buffer overflow in the ldns_rr_new_frm_str_internal function in ldns 1.4.x allows remote attackers to cause a denial of service (memory corruption) and possibly execute arbitrary code via a DNS resource record (RR) with a long (1) class field (clas variable) and possibly (2) TTL field.
|
2009-02-02
|
ldns rr.c ldns_rr_new_frm_str_internal Function Overflow
|
|
76795
Description:
(Description Provided by CVE) : Heap-based buffer overflow in the ldns_rr_new_frm_str_internal function in ldns before 1.6.11 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a Resource Record (RR) with an unknown type containing input that is longer than a specified length.
|
2011-08-24
|
ldns rr.c ldns_rr_new_frm_str_internal() Function DNS Resource Record Parsing Remote Overflow
|
|
46498
Description:
(Description Provided by CVE) : admin/upload.php in le.cms 1.4 and earlier allows remote attackers to bypass administrative authentication, and upload and execute arbitrary files in images/, via a nonzero value for the submit0 parameter in conjunction with filenames in the filename and upload parameters.
|
2008-06-21
|
le.cms cms/admin/upload.php submit0 Variable Arbitrary Remote File Execution
|
|
78455
Description:
Lead Capture Page System contains a flaw that allows a remote cross-site scripting (XSS) attack. This flaw exists because the application does not validate the 'message' parameter upon submission to the admin/login.php script. This may allow a user to create a specially crafted URL that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2012-01-21
|
Lead Capture Page System admin/login.php message Parameter XSS
|
|
25030
Description:
Leadhound contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the 'login' variable upon submission to the agent_affil.pl script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2006-04-18
|
Leadhound agent_affil.pl login Parameter XSS
|
|
25051
Description:
Leadhound contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the 'login' and 'logged' variables upon submission to the agent_affil_code.pl script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2006-04-18
|
Leadhound agent_affil_code.pl Multiple Parameter XSS
|
|
25052
Description:
Leadhound contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the 'logged' and 'login' variables upon submission to the agent_affil_list.pl script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2006-04-18
|
Leadhound agent_affil_list.pl Multiple Parameter XSS
|
|
25049
Description:
Leadhound contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the 'login' or 'logged' variables upon submission to the agent_camp_all.pl script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2006-04-18
|
Leadhound agent_camp_all.pl Multiple Parameter XSS
|
|
25029
Description:
Leadhound contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the agent_camp_det.pl script not properly sanitizing user-supplied input to the 'logged' or 'camp_id' variables. This may allow an attacker to inject or manipulate SQL queries in the back-end database.
|
2006-04-18
|
Leadhound agent_camp_det.pl Multiple Parameter SQL Injection
|
|
25054
Description:
Leadhound contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the 'page', 'camp_id', and 'logged' variables upon submission to the agent_camp_det.pl script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2006-04-18
|
Leadhound agent_camp_det.pl Multiple Parameter XSS
|
|
25057
Description:
Leadhound contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the 'login' and 'logged' variables upon submission to the agent_camp_expired.pl script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2006-04-18
|
Leadhound agent_camp_expired.pl Multiple Parameter XSS
|
|
25060
Description:
Leadhound contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the 'login' and 'logged' variables upon submission to the agent_camp_new.pl script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2006-04-18
|
Leadhound agent_camp_new.pl Multiple Parameter XSS
|
|
25059
Description:
Leadhound contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the 'login' and 'logged' variables upon submission to the agent_camp_notsub.pl script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2006-04-18
|
Leadhound agent_camp_notsub.pl Multiple Parameter XSS
|
|
25055
Description:
Leadhound contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the 'login' and 'logged' variables upon submission to the agent_camp_sub.pl script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2006-04-18
|
Leadhound agent_camp_sub.pl Multiple Parameter XSS
|
|
25058
Description:
Leadhound contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the 'login' and 'logged' variables upon submission to the agent_campaign.pl script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2006-04-18
|
Leadhound agent_campaign.pl Multiple Parameter XSS
|
|
25044
Description:
Leadhound contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the 'agent_id' variable upon submission to the agent_commission_statement.pl script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2006-04-18
|
Leadhound agent_commission_statement.pl agent_id Parameter XSS
|
|
25027
Description:
Leadhound contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the agent_commission_statement.pl script not properly sanitizing user-supplied input to the 'login', 'logged' or 'agent_id' variables. This may allow an attacker to inject or manipulate SQL queries in the back-end database.
|
2006-04-18
|
Leadhound agent_commission_statement.pl Multiple Parameter SQL Injection
|
|
25032
Description:
Leadhound contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the 'login' or 'logged' variables upon submission to the agent_faq.pl script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2006-04-18
|
Leadhound agent_faq.pl Multiple Parameter XSS
|
|
25031
Description:
Leadhound contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the 'login' variable upon submission to the agent_help.pl script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2006-04-18
|
Leadhound agent_help.pl login Parameter XSS
|
|
25033
Description:
Leadhound contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the 'login' or 'logged' variables upon submission to the agent_help_insert.pl script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2006-04-18
|
Leadhound agent_help_insert.pl Multiple Parameter XSS
|
|
25023
Description:
Leadhound contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the agent_links.pl script not properly sanitizing user-supplied input to the 'banner' or 'offset' variables. This may allow an attacker to inject or manipulate SQL queries in the back-end database.
|
2006-04-18
|
Leadhound agent_links.pl Multiple Parameter SQL Injection
|
|
25039
Description:
Leadhound contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the 'login', 'logged', 'camp_id', 'banner' or 'offset' variables upon submission to the agent_links.pl script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2006-04-18
|
Leadhound agent_links.pl Multiple Parameter XSS
|
|
25041
Description:
Leadhound contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the 'login' variable upon submission to the agent_logoff.pl script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2006-04-18
|
Leadhound agent_logoff.pl login Parameter XSS
|
|
25047
Description:
Leadhound contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the 'login' variables upon submission to the agent_payment_history.pl script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2006-04-18
|
Leadhound agent_payment_history.pl login Parameter XSS
|
|
25042
Description:
Leadhound contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the 'login' or 'dates' variables upon submission to the agent_rev_det.pl script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2006-04-18
|
Leadhound agent_rev_det.pl Multiple Parameter XSS
|
|
25053
Description:
Leadhound contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the 'login' and 'logged' variables upon submission to the agent_stats.pl script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2006-04-18
|
Leadhound agent_stats.pl Multiple Parameter XSS
|
|
25056
Description:
Leadhound contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the 'dates' and 'login' variables upon submission to the agent_stats_det.pl script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2006-04-18
|
Leadhound agent_stats_det.pl Multiple Parameter XSS
|