| OSVDB ID | Disclosure Date | Title |
|
30540
Description:
Rapid Classified contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate 'id' variable upon submission to the view_print.asp script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2006-11-19
|
Rapid Classified view_print.asp id Parameter XSS
|
|
30538
Description:
(Description Provided by CVE) : SQL injection vulnerability in viewad.asp in Rapid Classified 3.1 allows remote attackers to execute arbitrary SQL commands via the id parameter.
|
2006-11-19
|
Rapid Classified viewad.asp id Parameter SQL Injection
|
|
75886
Description:
Rapid Leech contains a flaw that may lead to an unauthorized information disclosure. The issue is triggered when a remote attacker sends a direct request to multiple scripts, which discloses the software's installation path resulting in a loss of confidentiality. While such information is relatively low risk, it is often useful in carrying out additional, more focused attacks.
|
2011-02-14
|
Rapid Leech Multiple Script Direct Request Path Disclosure
|
|
41481
Description:
(Description Provided by CVE) : Multiple SQL injection vulnerabilities in index.php in the Rapid Recipe (com_rapidrecipe) 1.6.5 component for Joomla! allow remote attackers to execute arbitrary SQL commands via (1) the user_id parameter in a showuser action or (2) the category_id parameter in a viewcategorysrecipes action.
|
2008-02-12
|
Rapid Recipe Component for Joomla! index.php Multiple Parameter SQL Injection
|
|
66248
Description:
Rapid Recipe Component for Joomla! contains a flaw that allows a remote cross site scripting (XSS) attack. This flaw exists because the application does not validate the 'introtext', 'ingredients', 'steps', and 'recipecomment' parameters upon submission to the 'index.php' script. This may allow a user to create a specially crafted URL that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2010-07-12
|
Rapid Recipe Component for Joomla! index.php Multiple Parameter XSS
|
|
46032
Description:
Rapid Recipe for Joomla! contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the index.php script not properly sanitizing user-supplied input to the "recipe_id" variable. This may allow an attacker to inject or manipulate SQL queries in the back-end database.
|
2008-06-08
|
Rapid Recipe Component for Joomla! index.php recipe_id Parameter SQL Injection
|
|
3553
Description:
RapidCache contains a flaw that may allow a remote denial of service. The issue is triggered when an overly long "Host:" header is supplied, and will result in loss of availability for the service.
|
2004-01-15
|
RapidCache Host Header Overflow DoS
|
|
3554
Description:
RapidCache contains a flaw that allows a remote attacker to read arbitrary files outside of the web path. The issue is due to the server not properly sanitizing user input, specifically traversal style attacks (../../) supplied via the URI.
|
2004-01-15
|
RapidCache Server Arbitrary File Access
|
|
78097
Description:
Rapidleech contains a flaw that allows a remote cross-site scripting (XSS) attack. This flaw exists because the application does not validate the 'links' parameter upon submission to the audl.php script. This may allow a user to create a specially crafted URL that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2011-12-20
|
Rapidleech audl.php links Parameter XSS
|
|
78098
Description:
Rapidleech contains a flaw that allows a remote cross-site scripting (XSS) attack. This flaw exists because the application does not validate the 'notes' parmaeter upon submission to the notes.php script. This may allow a user to create a specially crafted URL that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2011-12-21
|
Rapidleech notes.php notes Parameter XSS
|
|
53078
Description:
(Description Provided by CVE) : Absolute path traversal vulnerability in upload.php in Rapidleech rev.36 and earlier allows remote attackers to read arbitrary files via a base64-encoded absolute path in the filename parameter.
|
2009-03-14
|
Rapidleech upload.php filename Parameter Traversal Arbitrary File Access
|
|
52753
Description:
(Description Provided by CVE) : Directory traversal vulnerability in upload.php in Rapidleech rev.36 and earlier allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the uploaded parameter.
|
2009-03-14
|
Rapidleech upload.php uploaded Parameter Traversal Local File Inclusion
|
|
52754
Description:
Rapidleech contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate 'uploaded' parameters upon submission to the 'upload.php' script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2009-03-14
|
Rapidleech upload.php uploaded Parameter XSS
|
|
39981
Description:
(Description Provided by CVE) : Cross-site scripting (XSS) vulnerability in Default.asp in RapidShare Database allows remote attackers to inject arbitrary web script or HTML via the Arayalim parameter.
|
2008-01-07
|
RapidShare Database Default.asp Arayalim Parameter XSS
|
|
8037
Description:
(Description Provided by CVE) : sshd program in the Rapidstream 2.1 Beta VPN appliance has a hard-coded "rsadmin" account with a null password, which allows remote attackers to execute arbitrary commands via ssh.
|
2000-08-14
|
Rapidstream VPN sshd Default Hardcoded Admin Account
|
|
1501
Description:
Raptor GFX contains a flaw that may allow a local attacker to gain root privileges. The issue is due to the a flaw in the "pgxconfig" utility that allows an attacker to specify an arbitrary path to the "cp" program. If an attacker uses a specially crafted program in its place, it will be called allowing execution of arbitrary commands with root privileges.
|
2000-08-02
|
Raptor GFX pgxconfig Path Subversion Local Privilege Escalation
|
|
5740
Description:
Raptor GFX contains a flaw in the pgxconfig utility that may allow a malicious user to gain root privileges. The issue results from the combination of two issues: 1) pgxconfig is suid root and 2) pgxconfig uses a predictable temporary file name. It is possible that the flaw may allow a malicious user to over write any file on the system, resulting in a loss of integrity, and/or availability.
|
2000-08-02
|
Raptor GFX pgxconfig Symlink Arbitrary File Overwrite
|
|
80307
Description:
Raptor contains a flaw that may lead to an unauthorized information disclosure. The issue is triggered when processing XML external entities in certain XML components within an RDF document, which will disclose contents of arbitrary files to a context-dependent attacker.
|
2012-03-22
|
Raptor XML Eternal Entity RDF Document Handling Information Disclosure
|
|
8975
Description:
(Description Provided by CVE) : Directory traversal vulnerability in rar 2.02 and earlier allows attackers to overwrite arbitrary files during archive extraction via a .. (dot dot) attack on archived filenames.
|
2001-07-02
|
rar Archive Extraction Double Dot Arbitrary File Overwrite
|
|
19914
Description:
(Description Provided by CVE) : Format string vulnerability in RARLAB WinRAR 2.90 through 3.50 allows remote attackers to execute arbitrary code via format string specifiers in a UUE/XXE file, which are not properly handled when WinRAR displays diagnostic errors related to an invalid filename.
|
2005-10-11
|
RAR/WinRAR UUE/XXE Invalid Filename Error Message Format String
|
|
33124
Description:
(Description Provided by CVE) : Stack-based buffer overflow in RARLabs Unrar, as packaged in WinRAR and possibly other products, allows user-assisted remote attackers to execute arbitrary code via a crafted, password-protected archive.
|
2007-02-07
|
RARLabs UnRAR Password Protected Archive Handling Overflow
|
|
71453
Description:
Rash CMS contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the module/contact/contact-config.php script not properly sanitizing user-supplied input passed via the 'reciver' parameter to 'index.php'. This may allow an attacker to inject or manipulate SQL queries in the back-end database, allowing for the manipulation or disclosure of arbitrary data.
|
2011-04-03
|
Rash CMS index.php reciver Parameter SQL Injection
|
|
57468
Description:
RASH Quote Management System contains a flaw that may allow a remote attacker to carry out an SQL injection attack. The issue is due to the 'Admin Login' page not properly sanitizing user-supplied input to the 'user' parameter. This may allow an a remote attacker to inject or manipulate SQL queries in the back-end database.
|
2009-08-26
|
RASH Quote Management System Admin Login user Parameter SQL Injection Authentication Bypass
|
|
57469
Description:
RASH Quote Management System contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the Quote Addition not properly sanitizing user-supplied input to the 'quote' variable. This may allow an attacker to inject or manipulate SQL queries in the back-end database.
|
2009-08-26
|
RASH Quote Management System Quote Addition quote Parameter SQL Injection
|
|
57467
Description:
RASH Quote Management System contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the Search Functionality not properly sanitizing user-supplied input to the 'search' parameter. This may allow an attacker to inject or manipulate SQL queries in the back-end database.
|
2009-08-26
|
RASH Quote Management System Search Functionality search Parameter SQL Injection
|
|
57470
Description:
RASH Quote Management System contains a flaw that may allow a remote attacker to carry out an SQL injection attack. The issue is due to the 'Admin Login' page not properly sanitizing user-supplied input to the 'user' parameter. This may allow an a remote attacker to inject or manipulate SQL queries in the back-end database.
|
2009-08-26
|
RASH Quote Management System User_Name Cookie SQL Injection
|
|
22198
Description:
raSMP contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate user-supplied input to the "User-Agent" HTTP header before submission to the record_hit() function of the index.php script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2006-01-04
|
raSMP index.php User-Agent Field XSS
|
|
90817
Description:
Raspberry Pi Firmware Updater (rpi-update) contains a flaw as rpi-update creates temporary files insecurely. It is possible for a local attacker to use a symlink attack against the updateScript.sh file to cause the program to unexpectedly overwrite an arbitrary file when an administrator runs the updater.
|
2013-02-28
|
Raspberry Pi Firmware Updater (rpi-update) updateScript.sh Symlink Arbitrary File Overwrite
|
|
55070
Description:
(Description Provided by CVE) : Directory traversal vulnerability in src/torrent_info.cpp in Rasterbar libtorrent before 0.14.4, as used in firetorrent, qBittorrent, deluge Torrent, and other applications, allows remote attackers to create or overwrite arbitrary files via a .. (dot dot) and partial relative pathname in a Multiple File Mode list element in a .torrent file.
|
2009-06-08
|
Rasterbar libtorrent src/torrent_info.cpp Multiple File Mode List Element Traversal Arbitrary File Overwrite
|
|
6618
Description:
(Description Provided by CVE) : Ratbag game engine, as used in products such as Dirt Track Racing, Leadfoot, and World of Outlaws Spring Cars, allows remote attackers to cause a denial of service (CPU consumption) via a TCP packet that specifies the length of data to read and then sends a second TCP packet that contains less data than specified, which causes Ratbag to repeatedly check the socket for more data.
|
2004-02-11
|
Ratbag Game Engine TCP Socket Read DoS
|