| OSVDB ID | Disclosure Date | Title |
|
47823
Description:
(Description Provided by CVE) : javareconf in R 2.7.2 allows local users to overwrite arbitrary files via a symlink attack on temporary files.
|
2008-08-24
|
R javareconf Temporary File Symlink Arbitrary File Overwrite
|
|
54835
Description:
(Description Provided by CVE) : R2 Newsletter Lite, Pro, and Stats stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file via a direct request for admin.mdb.
|
2009-06-01
|
R2 Newsletter Stats admin.mdb Direct Request Database Disclosure
|
|
36015
Description:
(Description Provided by CVE) : Directory traversal vulnerability in galeria.php in R2K Gallery 1.7 allows remote attackers to read arbitrary files via a .. (dot dot) in the lang2 parameter.
|
2007-05-11
|
R2K Gallery galeria.php lang2 Parameter Traversal Arbitrary File Access
|
|
64895
Description:
Unknown / Incomplete
|
2010-01-31
|
RaakCms browse.asp dir Parameter Traversal Arbitrary Directory Listing
|
|
64896
Description:
Unknown / Incomplete
|
2010-01-31
|
RaakCms browseFile.asp dir Parameter Traversal Arbitrary Directory Listing
|
|
64894
Description:
Unknown / Incomplete
|
2010-01-31
|
RaakCms pic.aspx Arbitrary File Upload
|
|
18067
Description:
(Description Provided by CVE) : Format string vulnerability in Race Driver 1.20 and earlier allows remote attackers to cause a denial of service (application crash) via format string specifiers in a (1) nickname or (2) chat message.
|
2005-07-19
|
Race Driver Chat String Format String
|
|
18068
Description:
(Description Provided by CVE) : Buffer overflow in Race Driver 1.20 and earlier allows remote attackers to cause a denial of service (application crash) via a long (1) nickname or (2) chat message.
|
2005-07-19
|
Race Driver Chat String Remote Overflow
|
|
7094
Description:
Unknown / Incomplete
|
2004-06-16
|
Race Driver Malformed Packet Match Termination
|
|
7095
Description:
Unknown / Incomplete
|
2004-06-16
|
Race Driver Message Spoofing
|
|
7093
Description:
Unknown / Incomplete
|
2004-06-16
|
Race Driver Packet Length 0 DoS
|
|
25914
Description:
Unknown / Incomplete
|
2006-05-20
|
RaceEventManagement nennung.php pid Parameter SQL Injection
|
|
25913
Description:
Unknown / Incomplete
|
2006-05-20
|
RaceEventManagement nennung.php pid Parameter XSS
|
|
39601
Description:
A remote overflow exists in Racer v0.5.3beta5. The game fails to verify buffer lengths resulting in a stack overflow. With a specially crafted request, a remote attacker can execute arbitrary code resulting in a loss of integrity.
|
2007-08-13
|
Racer Client/Server UDP Packet Handling Remote Overflow
|
|
78121
Description:
Rack contains a flaw that may allow a remote denial of service. The issue is triggered when an attacker sends multiple crafted parameters which trigger hash collisions, and will result in loss of availability for the program via CPU consumption.
|
2011-12-28
|
Rack Hash Collision Form Parameter Parsing Remote DoS
|
|
51275
Description:
Unknown / Incomplete
|
2009-01-12
|
RackTables Null Password LDAP User Authentication Bypass
|
|
32066
Description:
(Description Provided by CVE) : ** DISPUTED ** PHP remote file inclusion vulnerability in upload.php in Rad Upload 3.02 allows remote attackers to execute arbitrary PHP code via a URL in the save_path parameter. NOTE: CVE disputes this vulnerability because save_path is originally defined as "" before use, and the nearby instructions say "SET THE SAVE PATH by editing the line below."
|
2006-12-12
|
Rad Upload upload.php save_path Parameter Remote File Inclusion
|
|
58195
Description:
RADactive I-Load contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate multiple unspecified parameters (parameters that begin with two underscores "__") upon submission to the 'WebcodeModule.ashx' script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2009-09-17
|
RADactive I-Load WebcodeModule.ashx Multiple Parameter XSS
|
|
58197
Description:
(Description Provided by CVE) : Unrestricted file upload vulnerability in RADactive I-Load before 2008.2.5.0 allows remote attackers to execute arbitrary code by uploading a file with an executable extension, and then sending a request for a predictable filename during a short time window.
|
2009-09-17
|
RADactive I-Load Webcontrol File Upload Arbitrary Command Execution
|
|
58194
Description:
(Description Provided by CVE) : WebCoreModule.ashx in RADactive I-Load before 2008.2.5.0 allows remote attackers to obtain sensitive information via unspecified requests that trigger responses containing the saved-image folder pathname.
|
2009-09-17
|
RADactive I-Load WebCoreModule.ashx File Upload Absolute Path Disclosure
|
|
58196
Description:
(Description Provided by CVE) : Directory traversal vulnerability in WebCoreModule.ashx in RADactive I-Load before 2008.2.5.0 allows remote attackers to read arbitrary files via unspecified vectors.
|
2009-09-17
|
RADactive I-Load WebCoreModule.ashx Traversal Arbitrary File Access
|
|
50417
Description:
Unknown / Incomplete
|
2008-12-03
|
RadAsm Crafted RAP File Handling Overflow
|
|
56731
Description:
Unknown / Incomplete
|
2009-08-03
|
RadAsm MNU File Handling Format String
|
|
15430
Description:
RadBids Gold contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the 'farea' variable upon submission to the faq.php script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2005-04-09
|
RadBids Gold faq.php farea Parameter XSS
|
|
56001
Description:
RadBids Gold contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the 'index.php' script not properly sanitizing user-supplied input to the 'fid' parameter. This may allow an attacker to inject or manipulate SQL queries in the back-end database.
|
2009-07-17
|
RadBids Gold index.php fid Parameter SQL Injection
|
|
15429
Description:
RadBids Gold contains a flaw that may allow an attacker to inject arbitrary SQL queries. The issue is due to the 'mode' variable in the index.php script not being properly sanitized and may allow an attacker to inject or manipulate SQL queries.
|
2005-04-09
|
RadBids Gold index.php mode Parameter SQL Injection
|
|
15431
Description:
RadBids Gold contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the 'cat', 'order' or 'area' variables upon submission to the index.php script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2005-04-09
|
RadBids Gold index.php Multiple Parameter XSS
|
|
15428
Description:
RadBids Gold contains a flaw that allows a remote attacker to access arbitray files outside of the web path. The issue is due to the index.phps cript not properly sanitizing user input, specifically traversal style attacks (../../) supplied via the 'read' variable.
|
2005-04-09
|
RadBids Gold index.php read Parameter Traversal Arbitrary File Access
|
|
56000
Description:
RadBids Gold contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate 'mode' parameters upon submission to the 'storefront.php' script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2009-07-17
|
RadBids Gold storefront.php mode Parameter XSS
|
|
54834
Description:
RadCLASSIFIEDS contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the 'index.php' script not properly sanitizing user-supplied input to the 'seller' parameter. This may allow an attacker to inject or manipulate SQL queries in the back-end database.
|
2009-06-01
|
RadCLASSIFIEDS index.php seller Parameter SQL Injection
|