| OSVDB ID | Disclosure Date | Title |
|
39050
Description:
MWOpen contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the 'leggi_commenti.asp' script not properly sanitizing user-supplied input to the 'id' variable. This may allow an attacker to inject or manipulate SQL queries in the back-end database.
|
2007-12-06
|
MWOpen leggi_commenti.asp id Parameter SQL Injection
|
|
50992
Description:
MWP Blog System for PHP-Fusion contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the 'blog.php' script not properly sanitizing user-supplied input to the 'id' variable. This may allow an attacker to inject or manipulate SQL queries in the back-end database.
|
2008-12-28
|
MWP Blog System for PHP-Fusion blog.php id Parameter SQL Injection
|
|
37400
Description:
Mx At A Glance Module for MxBB Portal contains a flaw that may allow a remote attacker to execute arbitrary commands or code. The issue is due to the 'contrib/mx_glance_sdesc.php' script not properly sanitizing user input supplied to the 'mx_root_path' parameter. This may allow an attacker to include a file from a third-party remote host that contains commands or code that will be executed by the vulnerable script with the same privileges as the web server.
|
2007-09-29
|
Mx At A Glance Module for MxBB Portal contrib/mx_glance_sdesc.php mx_root_path Parameter Remote File Inclusion
|
|
15172
Description:
MX Kart contains a flaw that will allow an attacker to inject arbitrary SQL code. The problem is that the 'id_ctg' variable in the 'category' module is not verified properly and will allow an attacker to inject or manipulate SQL queries.
|
2005-03-31
|
MX Kart Category Module id_ctg Parameter SQL Injection
|
|
15173
Description:
MX Kart contains a flaw that will allow an attacker to inject arbitrary SQL code. The problem is that the "id_man" variable in the "index.php" module is not verified properly and will allow an attacker to inject or manipulate SQL queries.
|
2005-03-31
|
MX Kart Manufacturer Module id_man Parameter SQL Injection
|
|
15167
Description:
MX Kart contains a flaw that may allow a remote attacker to inject arbitrary SQL queries. The issue is due to the 'idp' parameter in the 'Pages' module not being properly sanitized and may allow a remote attacker to inject or manipulate SQL queries.
|
2005-03-31
|
MX Kart Pages Module idp Parameter SQL Injection
|
|
15168
Description:
MX Shop contains a flaw that may allow a remote attacker to inject arbitrary SQL queries. The issue is due to the 'id_ctg' parameter in the 'Category' module not being properly sanitized and may allow a remote attacker to inject or manipulate SQL queries.
|
2005-03-31
|
MX Shop Category Module id_ctg Parameter SQL Injection
|
|
19611
Description:
MX Shop contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the 'index.php' script in the pages module not properly sanitizing user-supplied input to the 'idp', 'id_ctg' and 'id_prd' variables. This may allow an attacker to inject or manipulate SQL queries in the back-end database.
|
2005-09-17
|
MX Shop Pages Module Multiple Parameter SQL Injection
|
|
64856
Description:
Unknown / Incomplete
|
2010-03-20
|
MX Simulator Server Unspecified Remote Overflow
|
|
33263
Description:
(Description Provided by CVE) : PHP remote file inclusion vulnerability in includes/profilcp_constants.php in the Profile Control Panel (CPanel) module for mxBB 0.91c allows remote attackers to execute arbitrary PHP code via a URL in the module_root_path parameter.
|
2006-12-09
|
mxBB Module (mx_profilecp) profilcp_constants.php module_root_path Parameter Remote File Inclusion
|
|
30536
Description:
(Description Provided by CVE) : PHP remote file inclusion vulnerability in includes/mx_common.php in the CalSnails Module for MxBB Portal 1.06 allows remote attackers to execute arbitrary PHP code via a URL in the module_root_path parameter.
|
2006-11-17
|
MxBB Portal CalSnails Module mx_common.php module_root_path Parameter Remote File Inclusion
|
|
45606
Description:
MxBB Portal contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the 'index.php' script not properly sanitizing user-supplied input to the 'page' variable. This may allow an attacker to inject or manipulate SQL queries in the back-end database.
|
2008-05-20
|
MxBB Portal index.php page Parameter SQL Injection
|
|
35760
Description:
(Description Provided by CVE) : Directory traversal vulnerability in includes/kb_constants.php in the Knowledge Base (mx_kb) 2.0.2 module for mxBB allows remote attackers to include arbitrary files via a .. (dot dot) sequence in the phpEx parameter.
|
2006-12-12
|
MxBB Portal Knowledge Base Module (mx_kb) kb_constants.php phbEx Parameter Remote File Inclusion
|
|
31235
Description:
(Description Provided by CVE) : PHP remote file inclusion vulnerability in includes/kb_constants.php in the Knowledge Base (mx_kb) 2.0.2 module for mxBB allows remote attackers to execute arbitrary PHP code via a URL in the module_root_path parameter.
|
2006-12-12
|
MxBB Portal Knowledge Base/mx_kb Module kb_constants.php module_root_path Parameter Remote File Inclusion
|
|
31233
Description:
(Description Provided by CVE) : PHP remote file inclusion vulnerability in charts_constants.php in the Charts (mx_charts) 1.0.0 and earlier module for mxBB allows remote attackers to execute arbitrary PHP code via a URL in the module_root_path parameter.
|
2006-12-16
|
MxBB Portal mx_charts Module charts_constants.php module_root_path Parameter Remote File Inclusion
|
|
31237
Description:
(Description Provided by CVE) : PHP remote file inclusion vulnerability in includes/common.php in the ErrorDocs 1.0.0 and earlier module for mxBB (mx_errordocs) allows remote attackers to execute arbitrary PHP code via a URL in the module_root_path parameter.
|
2006-12-11
|
MxBB Portal mx_errordocs Module common.php module_root_path Parameter Remote File Inclusion
|
|
31232
Description:
(Description Provided by CVE) : PHP remote file inclusion vulnerability in pages/meeting_constants.php in the Meeting (mx_meeting) 1.1.2 and earlier module for mxBB allows remote attackers to execute arbitrary PHP code via a URL in the module_root_path parameter.
|
2006-12-16
|
MxBB Portal mx_meeting Module meeting_constants.php module_root_path Parameter Remote File Inclusion
|
|
31236
Description:
(Description Provided by CVE) : PHP remote file inclusion vulnerability in includes/common.php in the mx_modsdb 1.0.0 module for MxBB (aka MX-System) Portal allows remote attackers to execute arbitrary PHP code via a URL in the module_root_path parameter.
|
2006-12-12
|
MxBB Portal mx_modsdb Module common.php module_root_path Parameter Remote File Inclusion
|
|
31234
Description:
(Description Provided by CVE) : PHP remote file inclusion vulnerability in includes/newssuite_constants.php in the NewsSuite 1.03 module for mxBB allows remote attackers to execute arbitrary PHP code via a URL in the mx_root_path parameter.
|
2006-12-12
|
MxBB Portal mx_newssuite Module newssuite_constants.php mx_root_path Parameter Remote File Inclusion
|
|
31238
Description:
mxBB mx_tinies contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to the 'includes/common.php' script not properly sanitizing user input supplied to the 'module_root_path' parameter. This may allow an attacker to include a file from an arbitrary remote host that contains commands which will be executed by the vulnerable script with the same privileges as the web server.
|
2006-12-02
|
mxBB Portal mx_tinies Module common.php module_root_path Parameter Remote File Inclusion
|
|
35752
Description:
(Description Provided by CVE) : PHP remote file inclusion vulnerability in getinfo1.php in the Shotcast 1.0 RC2 module for mxBB allows remote attackers to execute arbitrary PHP code via a URL in the mx_root_path parameter.
|
2007-04-12
|
mxBB Shotcast getinfo1.php mx_root_path Variable Remote File
|
|
31958
Description:
(Description Provided by CVE) : PHP remote file inclusion vulnerability in modules/mx_smartor/album.php in the mxBB Smartor Album module 1.02 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the module_root_path parameter.
|
2006-11-05
|
mxBB Smartor Album modules/mx_smartor/album.php module_root_path Parameter Remote File Inclusion
|
|
44396
Description:
mxbBB mx_blogs contains a flaw that may allow a remote attacker to execute arbitrary commands or code. The issue is due to the 'includes/functions_weblog.php' script not properly sanitizing user input supplied to the ' mx_root_path' parameter. This may allow an attacker to include a file from a third-party remote host that contains commands or code that will be executed by the vulnerable script with the same privileges as the web server.
|
2008-03-30
|
mxbBB mx_blogs includes/functions_weblog.php mx_root_path Parameter Remote File Inclusion
|
|
49887
Description:
(Description Provided by CVE) : Static code injection vulnerability in admin/admin.php in mxCamArchive 2.2 allows remote authenticated administrators to inject arbitrary PHP code into an unspecified program via the description parameter, which is executed by invocation of index.php. NOTE: some of these details are obtained from third party information.
|
2008-11-17
|
mxCamArchive admin/admin.php description Parameter Arbitrary PHP Code Execution
|
|
49886
Description:
(Description Provided by CVE) : mxCamArchive 2.2 stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain configuration details and passwords via a direct request for archive/config.ini.
|
2008-11-17
|
mxCamArchive archive/config.ini Direct Request Password Disclosure
|
|
21339
Description:
MXChange contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to an unspecified script not properly sanitizing user-supplied input to an unspecified variable. This may allow an attacker to inject or manipulate SQL queries in the back-end database.
|
2005-12-01
|
MXChange Unspecified SQL Injection
|
|
21338
Description:
MXChange contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate unspecified variables upon submission to an unspecified script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2005-12-01
|
MXChange Unspecified XSS
|
|
32470
Description:
(Description Provided by CVE) : SQL injection vulnerability in detail.asp in Mxmania File Upload Manager (FUM) 1.0.6 and earlier allows remote attackers to execute arbitrary SQL commands via the ID parameter.
|
2006-12-24
|
Mxmania File Upload Manager detail.asp ID Parameter SQL Injection
|
|
60193
Description:
(Description Provided by CVE) : Buffer overflow in the FTP service on the Tandberg MXP F7.0 allows remote attackers to cause a denial of service (process crash or device reboot) or possibly execute arbitrary code via a long USER command, as demonstrated by a command ending with many space characters.
|
2009-07-13
|
MXP USER Command Handling Remote Overflow
|
|
63148
Description:
Unknown / Incomplete
|
2010-03-22
|
Mxserver UDP Packet Handling Remote Overflow
|