| OSVDB ID | Disclosure Date | Title |
|
84248
Description:
The RTFM Extension for RT contains a flaw that allows a remote cross-site scripting (XSS) attack. This flaw exists because the application does not validate certain unspecified input passed via the topic administration page before returning it to the user. This may allow a user to create a specially crafted request that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2012-07-25
|
RTFM Extension for RT Topic Administration Page Unspecified XSS
|
|
83983
Description:
RTG and RTG2 contain a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the 95.php script not properly sanitizing user-supplied input before using it in SQL queries. This may allow an attacker to inject or manipulate SQL queries in the back-end database, allowing for the manipulation or disclosure of arbitrary data.
|
2012-07-09
|
RTG / RTG2 95.php Unspecified SQL Injection
|
|
83982
Description:
RTG and RTG2 contain a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the rtg.php script not properly sanitizing user-supplied input before using it in SQL queries. This may allow an attacker to inject or manipulate SQL queries in the back-end database, allowing for the manipulation or disclosure of arbitrary data.
|
2012-07-09
|
RTG / RTG2 rtg.php Unspecified SQL Injection
|
|
83981
Description:
RTG and RTG2 contain a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the view.php script not properly sanitizing user-supplied input before using it in SQL queries. This may allow an attacker to inject or manipulate SQL queries in the back-end database, allowing for the manipulation or disclosure of arbitrary data.
|
2012-07-09
|
RTG / RTG2 view.php Unspecified SQL Injection
|
|
75789
Description:
RTG Files Extension for TYPO3 contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to certain unspecified input not being properly sanitized before use in SQL queries. This may allow an attacker to inject or manipulate SQL queries in the back-end database, allowing for the manipulation or disclosure of arbitrary data.
|
2011-09-28
|
RTG Files Extension for TYPO3 Unspecified SQL Injection
|
|
47567
Description:
Unknown / Incomplete
|
2008-08-08
|
RTH download.php upload_filename Parameter Arbitrary File Access
|
|
47568
Description:
RTH contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the 'login.php' script not properly sanitizing user-supplied input to the 'uname' parameter. This may allow an attacker to inject or manipulate SQL queries in the back-end database.
|
2008-08-08
|
RTH login.php uname Array Parameter SQL Injection
|
|
20327
Description:
WebAdmin contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the login script not properly sanitizing user-supplied input to the 'username' and 'password' variables. This may allow an attacker to inject or manipulate SQL queries in the back-end database.
|
2005-10-14
|
RTIS WebAdmin Login Multiple Field SQL Injection
|
|
40616
Description:
(Description Provided by CVE) : Stack-based buffer overflow in the PTZCamPanelCtrl ActiveX control (CamPanel.dll) in RTS Sentry 2.1.0.2 allows remote attackers to execute arbitrary code via a long second argument to the ConnectServer method.
|
2008-01-16
|
RTS Sentry PTZCamPanelCtrl ActiveX (CamPanel.dll) ConnectServer() Method Overflow
|
|
69959
Description:
RTShop contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the 'productDetail.asp' script not properly sanitizing user-supplied input to the 'id' parameter. This may allow an attacker to inject or manipulate SQL queries in the back-end database, allowing for the manipulation or disclosure of arbitrary data.
|
2010-12-20
|
RTShop productDetail.asp id Parameter SQL Injection
|
|
42378
Description:
Unknown / Incomplete
|
2008-02-26
|
RTSP MPEG4 SP Control RtspVaPgCtrl ActiveX (RtspVapgDecoderNew.dll) Url Property Overflow Arbitrary Code Execution
|
|
40892
Description:
(Description Provided by CVE) : Buffer overflow in the Digital Data Communications RtspVaPgCtrl ActiveX control (RtspVapgDecoder.dll 1.1.0.29) allows remote attackers to execute arbitrary code via a long MP4Prefix property.
|
2008-01-17
|
RTSP MPEG4 SP Control RtspVaPgDecoder.RtspVaPgCtrl ActiveX (RtspVapgDecoder.dll) MP4Prefix Property Overflow Arbitrary Code Execution
|
|
90548
Description:
RTTucson Quotations Database contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the /quotations/admin/include/login.php script not properly sanitizing user-supplied input to the 'Username' field. This may allow an attacker to manipulate an SQL query that will result in bypassing authentication. Once authenticated, the attacker will have access to the application with the same privileges as the ADMIN | USER account used during the authentication bypass.
|
2013-02-21
|
RTTucson Quotations Database /quotations/admin/include/login.php Username Field SQL Injection Authentication Bypass
|
|
90499
Description:
RTTucson Quotations Database contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the author.php script not properly sanitizing user-supplied input to the 'ID' parameter. This may allow an attacker to inject or manipulate SQL queries in the back-end database, allowing for the manipulation or disclosure of arbitrary data.
|
2013-02-19
|
RTTucson Quotations Database author.php ID Parameter SQL Injection
|
|
90498
Description:
RTTucson Quotations Database contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the category_quotes.php script not properly sanitizing user-supplied input to the 'ID' parameter. This may allow an attacker to inject or manipulate SQL queries in the back-end database, allowing for the manipulation or disclosure of arbitrary data.
|
2013-02-19
|
RTTucson Quotations Database category_quotes.php ID Parameter SQL Injection
|
|
90500
Description:
RTTucson Quotations Database contains a flaw that allows a remote cross-site scripting (XSS) attack. This flaw exists because the application does not validate the 'keywords' parameter upon submission to the quote_search.php script. This may allow an attacker to create a specially crafted request that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2013-02-19
|
RTTucson Quotations Database quote_search.php keywords Parameter XSS
|
|
54367
Description:
RTWebalbum contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the 'index.php' script not properly sanitizing user-supplied input to the 'AlbumId' variable. This may allow an attacker to inject or manipulate SQL queries in the back-end database.
|
2009-05-08
|
RTWebalbum index.php AlbumId Parameter SQL Injection
|
|
78119
Description:
Rubinius contains a flaw that may allow a remote denial of service. The issue is triggered when an attacker sends multiple crafted parameters which trigger hash collisions, and will result in loss of availability for the program via CPU consumption.
|
2011-12-28
|
Rubinius Hash Collision Form Parameter Parsing Remote DoS
|
|
87861
Description:
Rubinius contains a flaw related to the MurmurHash3 implementation that may allow a remote denial of service. The issue is triggered when hash values are computed without having the ability to cause hash collisions restricted. When sending specially crafted input to an application maintaining a hash table, a context-dependent attacker can cause a consumption of CPU resources. This will result in a loss of availability for the program.
|
2012-11-23
|
Rubinius MurmurHash3 Implementation Hash Collision Remote DoS
|
|
62600
Description:
rubrique contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the 'rubrique.php' script not properly sanitizing user-supplied input to the 'id' parameter. This may allow an attacker to inject or manipulate SQL queries in the back-end database, allowing for the manipulation or disclosure of arbitrary data.
|
2009-09-19
|
rubrique rubrique.php id Parameter SQL Injection
|
|
27144
Description:
Ruby contains a flaw that may allow a malicious user to gain access to unauthorized privileges. The issue is triggered due to an unspecified error in the handling of the "alias" functionality. No further details have been provided.
|
2006-07-11
|
Ruby alias Function Safe Level Security Bypass
|
|
55031
Description:
(Description Provided by CVE) : The BigDecimal library in Ruby 1.8.6 before p369 and 1.8.7 before p173 allows context-dependent attackers to cause a denial of service (application crash) via a string argument that represents a large number, as demonstrated by an attempted conversion to the Float data type.
|
2009-06-10
|
Ruby BigDecimal Library Float Data Type Conversion String Argument Handling DoS
|
|
8845
Description:
Ruby contains a flaw that may lead to an unauthorized information disclosure. The issue is triggered because the cgi::session's filestore stores session information in temporary files created without any regard to permissions. Permissions are set only using the umask value, which may disclose the CGI session variable data resulting in a loss of confidentiality
|
2004-08-16
|
Ruby CGI Session Management Insecure File Creation
|
|
34237
Description:
(Description Provided by CVE) : The cgi.rb CGI library for Ruby 1.8 allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via an HTTP request with a multipart MIME body that contains an invalid boundary specifier, as demonstrated using a specifier that begins with a "-" instead of "--" and contains an inconsistent ID.
|
2006-10-25
|
Ruby cgi.rb Crafted HTTP Request DoS
|
|
11534
Description:
(Description Provided by CVE) : The CGI module in Ruby 1.6 before 1.6.8, and 1.8 before 1.8.2, allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a certain HTTP request.
|
2004-11-08
|
Ruby cgi.rb Malformed HTTP Request CPU Utilization DoS
|
|
34238
Description:
(Description Provided by CVE) : The read_multipart function in cgi.rb in Ruby before 1.8.5-p2 does not properly detect boundaries in MIME multipart content, which allows remote attackers to cause a denial of service (infinite loop) via crafted HTTP requests, a different issue than CVE-2006-5467.
|
2006-12-04
|
Ruby cgi.rb read_multipart Function Crafted HTTP Request DoS
|
|
27145
Description:
Ruby contains a flaw that may allow a malicious user to bypass Safe Level restrictions. The issue is triggered when improper validation of the 'alias' function occurs. It is possible that the flaw may allow malicious code execution resulting in a loss of confidentiality, integrity.
|
2006-07-11
|
Ruby Directory Operations Safe Level Security Bypass
|
|
47472
Description:
(Description Provided by CVE) : The dl module in Ruby 1.8.5 and earlier, 1.8.6 through 1.8.6-p286, 1.8.7 through 1.8.7-p71, and 1.9 through r18423 does not check "taintness" of inputs, which allows context-dependent attackers to bypass safe levels and execute dangerous functions by accessing a library using DL.dlopen.
|
2008-08-08
|
Ruby dl Module DL.dlopen Arbitrary Library Access
|
|
19610
Description:
(Description Provided by CVE) : Ruby 1.6.x up to 1.6.8, 1.8.x up to 1.8.2, and 1.9.0 development up to 2005-09-01 allows attackers to bypass safe level and taint flag protections and execute disallowed code when Ruby processes a program through standard input (stdin).
|
2005-09-22
|
Ruby eval.c safe_level Restriction Bypass
|
|
70957
Description:
Ruby contains a flaw related to the safe-level feature. The issue is triggered when a context-dependent attacker exploits a flaw within the exception '#to_s' handling. This may allow an attacker to bypass safe-level protection and modify strings via the 'Exception#to_s' method.
|
2011-02-18
|
Ruby Exception#to_s Method Safe Level Security Bypass
|