| OSVDB ID | Disclosure Date | Title |
|
43440
Description:
(Description Provided by CVE) : RaidSonic NAS-4220-B with 2.6.0-n(2007-10-11) firmware stores a partition encryption key in an unencrypted /system/.crypt file with base64 encoding, which allows local users to obtain the key.
|
2008-03-16
|
RaidSonic ICY BOX NAS-4220-B Plaintext Encryption Key Disclosure
|
|
90219
Description:
Multiple RaidSonic products contain a flaw that allows a stored cross-site scripting (XSS) attack. This flaw exists because the application does not validate the 'ntp_name' parameter upon submission to the /cgi/time/time.cgi script. This may allow an attacker to create a specially crafted request that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2013-02-12
|
Raidsonic Multiple Product /cgi/time/time.cgi ntp_name Parameter XSS
|
|
90221
Description:
Multiple RaidSonic products contain a flaw that is due to the program failing to properly sanitized input passed via the 'ping_size' parameter to the /cgi/time/timeHandler.cgi script. This may allow a remote attacker to execute arbitrary commands.
|
2013-02-12
|
Raidsonic Multiple Product /cgi/time/timeHandler.cgi ping_size Parameter Remote Command Execution
|
|
90220
Description:
Multiple RaidSonic products contain a flaw that is triggered when input passed via the 'foldName' parameter is not properly sanitized before being used in the /nav.cgi script. This may allow a remote attacker to bypass authentication.
|
2013-02-12
|
Raidsonic Multiple Product /nav.cgi foldName Parameter Authentication Bypass
|
|
39181
Description:
(Description Provided by CVE) : Cross-site scripting (XSS) vulnerability in Rainboard before 2.10 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
|
2007-12-12
|
Rainboard Unspecified XSS
|
|
67882
Description:
Unknown / Incomplete
|
2010-09-02
|
Rainbow Portal app_support/FCK.filemanager/imagegallery.aspx Multiple Parameter XSS
|
|
67886
Description:
Rainbow Portal contains a flaw that allows a remote cross site scripting (XSS) attack. This flaw exists because the application does not validate the 'Title' parameter upon submission to the 'DesktopModules/Announcements/AnnouncementsEdit.aspx' script. This may allow a user to create a specially crafted URL that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2010-09-02
|
Rainbow Portal DesktopModules/Announcements/AnnouncementsEdit.aspx Title Parameter XSS
|
|
67883
Description:
Rainbow Portal contains a flaw that allows a remote cross site scripting (XSS) attack. This flaw exists because the application does not validate the 'Title', 'Name', and 'Comments' parameters upon submission to the 'DesktopModules/Blog/BlogView.aspx' script. This may allow a user to create a specially crafted URL that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2010-09-02
|
Rainbow Portal DesktopModules/Blog/BlogView.aspx Multiple Parameter XSS
|
|
67885
Description:
Rainbow Portal contains a flaw that allows a remote cross site scripting (XSS) attack. This flaw exists because the application does not validate the 'Name', 'Role', 'Office', 'Mobile', 'Fax', and 'Address' parameters upon submission to the 'DesktopModules/Contacts/ContactsEdit.aspx' script. This may allow a user to create a specially crafted URL that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2010-09-02
|
Rainbow Portal DesktopModules/Contacts/ContactsEdit.aspx Multiple Parameter XSS
|
|
67888
Description:
Rainbow Portal contains a flaw that allows a remote cross site scripting (XSS) attack. This flaw exists because the application does not validate the 'Filename' and 'Category' parameters upon submission to the 'DesktopModules/Documents/DocumentsEdit.aspx' script. This may allow a user to create a specially crafted URL that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2010-09-02
|
Rainbow Portal DesktopModules/Documents/DocumentsEdit.aspx Multiple Parameter XSS
|
|
67887
Description:
Rainbow Portal contains a flaw that allows a remote cross site scripting (XSS) attack. This flaw exists because the application does not validate the 'Title' and 'Description' parameters upon submission to the 'DesktopModules/EnhancedLinks/EnhancedLinksEdit.aspx' script. This may allow a user to create a specially crafted URL that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2010-09-02
|
Rainbow Portal DesktopModules/EnhancedLinks/EnhancedLinksEdit.aspx Multiple Parameter XSS
|
|
67884
Description:
Rainbow Portal contains a flaw that allows a remote cross site scripting (XSS) attack. This flaw exists because the application does not validate the 'Title' and 'Status' parameters upon submission to the 'DesktopModules/MileStones/MilestonesEdit.aspx' script. This may allow a user to create a specially crafted URL that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2010-09-02
|
Rainbow Portal DesktopModules/MileStones/MilestonesEdit.aspx Multiple Parameter XSS
|
|
8784
Description:
(Description Provided by CVE) : Buffer overflow in Rainbow Six Multiplayer allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long nickname (nick) command.
|
1999-02-11
|
Rainbow Six Multiplayer nickname Remote Overflow DoS
|
|
33683
Description:
(Description Provided by CVE) : Cross-site scripting (XSS) vulnerability in jira/secure/BrowseProject.jspa in Rainbow with the Zen (Rainbow.Zen) extension allows remote attackers to inject arbitrary web script or HTML via the id parameter.
|
2007-02-09
|
Rainbow with the Zen (Rainbow.Zen) jira/secure/BrowseProject.jspa id Parameter XSS
|
|
52534
Description:
Unknown / Incomplete
|
2009-03-10
|
RainbowPlayer RPL File Handling Overflow
|
|
31650
Description:
(Description Provided by CVE) : Cross-site scripting (XSS) vulnerability in the "failed" functionality in Raindance Web Conferencing Pro allows remote attackers to inject arbitrary web script or HTML via the browser parameter.
|
2006-03-24
|
Raindance Web Conferencing Pro failed browser XSS
|
|
88593
Description:
Rake contains a flaw that is due to insecure permissions on the FileUtils method. This may allow a context-dependent attacker to write files to other projects.
|
2005-04-09
|
Rake FileUtils Methods Cross-method File Manipulation Weakness
|
|
50325
Description:
(Description Provided by CVE) : RakhiSoftware Price Comparison Script (aka Shopping Cart) allows remote attackers to obtain sensitive information via an invalid PHPSESSID cookie, which reveals the installation path in an error message.
|
2008-11-27
|
RakhiSoftware Shopping Cart PHPSESSID Cookie Manipulation Path Disclosure
|
|
50313
Description:
RakhiSoftware Shopping Cart contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the product.php script not properly sanitizing user-supplied input to the subcategory_id variable. This may allow an attacker to inject or manipulate SQL queries in the back-end database.
|
2008-11-27
|
RakhiSoftware Shopping Cart product.php Multiple Parameter SQL Injection
|
|
50326
Description:
(Description Provided by CVE) : Multiple cross-site scripting (XSS) vulnerabilities in product.php in RakhiSoftware Price Comparison Script (aka Shopping Cart) allow remote attackers to inject arbitrary web script or HTML via the (1) category_id and (2) subcategory_id parameters.
|
2008-11-27
|
RakhiSoftware Shopping Cart product.php Multiple Parameter XSS
|
|
45034
Description:
(Description Provided by CVE) : SQL injection vulnerability in the Autopatcher server plugin in RakNet before 3.23 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
|
2008-05-12
|
RakNet Autopatcher Unspecified SQL Injection
|
|
17125
Description:
Raknet contains a flaw that may allow a remote denial of service. The issue is triggered when an empty UDP datagram is received by the server, and will result in loss of availability for the service.
|
2005-06-05
|
RakNet Empty UDP Datagram Remote DoS
|
|
63240
Description:
Unknown / Incomplete
|
2010-03-25
|
RakNet RakPeer.cpp ProcessOfflineNetworkPacket() Function NULL Dereference Remote Underflow DoS
|
|
46973
Description:
Ralf Image Gallery (RIG) contains a flaw that may allow a remote attacker to execute arbitrary commands or code. The issue is due to the 'check_entry.php' script not properly sanitizing user input supplied to the 'dir_abs_src' parameter. This may allow an attacker to include a file from a third-party remote host that contains commands or code that will be executed by the vulnerable script with the same privileges as the web server.
|
2007-07-30
|
Ralf Image Gallery (RIG) check_entry.php dir_abs_src Parameter Remote File Inclusion
|
|
26754
Description:
Ralf Image Gallery (R.I.G.) contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to the admin_album.php script not properly sanitizing user input supplied to the 'dir_abs_src' or 'dir_abs_admin_src' variables. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script. Additionally, this can be used to access arbitrary files via directory traversal style attacks (../../), or conduct cross-site scripting (XSS) attacks allowing for the execution of arbitrary code in a user's browser within the trust relationship between the browser and the server.
|
2006-06-20
|
Ralf Image Gallery admin_album.php Multiple Parameter Remote File Inclusion
|
|
26755
Description:
Ralf Image Gallery (R.I.G.) contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to the admin_image.php script not properly sanitizing user input supplied to the 'dir_abs_src' or 'dir_abs_admin_src' variables. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script. Additionally, this can be used to access arbitrary files via directory traversal style attacks (../../), or conduct cross-site scripting (XSS) attacks allowing for the execution of arbitrary code in a user's browser within the trust relationship between the browser and the server.
|
2006-06-20
|
Ralf Image Gallery admin_image.php Multiple Parameter Remote File Inclusion
|
|
26756
Description:
Ralf Image Gallery (R.I.G.) contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to the admin_util.php script not properly sanitizing user input supplied to the 'dir_abs_src' variable. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script. Additionally, this can be used to access arbitrary files via directory traversal style attacks (../../), or conduct cross-site scripting (XSS) attacks allowing for the execution of arbitrary code in a user's browser within the trust relationship between the browser and the server.
|
2006-06-20
|
Ralf Image Gallery admin_util.php dir_abs_src Parameter Remote File Inclusion
|
|
26753
Description:
Ralf Image Gallery (R.I.G.) contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to the check_entry.php script not properly sanitizing user input supplied to the 'dir_abs_src' variable. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script. Additionally, this can be used to access arbitrary files via directory traversal style attacks (../../), or conduct cross-site scripting (XSS) attacks allowing for the execution of arbitrary code in a user's browser within the trust relationship between the browser and the server.
|
2006-06-20
|
Ralf Image Gallery check_entry.php dir_abs_src Parameter Remote File Inclusion
|
|
53551
Description:
(Description Provided by CVE) : Integer overflow in Ralink Technology USB wireless adapter (RT73) 3.08 for Windows, and other wireless card drivers including rt2400, rt2500, rt2570, and rt61, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a Probe Request packet with a long SSID, possibly related to an integer signedness error.
|
2009-01-18
|
Ralink Technology USB Wireless Adapter (RT73) Probe Request Packet SSID Handling Remote Overflow
|
|
30315
Description:
(Description Provided by CVE) : Directory traversal vulnerability in lang.php in Rama CMS 0.68 and earlier, when register_globals is enabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the lang cookie, as demonstrated by injecting PHP sequences into an Apache HTTP Server log file, which is then included by lang.php.
|
2006-11-13
|
Rama CMS lang File Inclusion
|