| OSVDB ID | Disclosure Date | Title |
|
72661
Description:
Unknown / Incomplete
|
2010-12-03
|
S-Banking / S-Finanzstatus Certificate Verification Failure MiTM Weakness
|
|
61663
Description:
S-CMS contains a flaw that may allow a remote attacker to execute arbitrary commands or code. The issue is due to the 'admin.php' script not properly sanitizing user input, specifically directory traversal style attacks (e.g., ../../) supplied to the 'plug' parameter. This may allow an attacker to include a file from the targeted host that contains arbitrary commands or code that will be executed by the vulnerable script. Such attacks are limited due to the script only calling files already on the target host. In addition, this flaw can potentially be used to disclose the contents of any file on the system accessible by the web server.
|
2009-06-09
|
S-CMS admin.php plug Parameter Traversal Local File Inclusion
|
|
52571
Description:
S-Cms contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the 'admin/delete_page.php' script not properly sanitizing user-supplied input to the 'id' parameter. This may allow an attacker to inject or manipulate SQL queries in the back-end database.
|
2009-02-17
|
S-Cms admin/delete_page.php id Parameter SQL Injection
|
|
61662
Description:
Unknown / Incomplete
|
2009-06-09
|
S-CMS index.php lang Parameter Traversal Local File Inclusion
|
|
52570
Description:
(Description Provided by CVE) : S-Cms 1.1 Stable allows remote attackers to bypass authentication and obtain administrative access via an OK value for the login cookie.
|
2009-02-17
|
S-Cms Login Cookie OK Value Admin Authentication Bypass
|
|
61661
Description:
S-CMS contains a flaw that may allow a remote attacker to execute arbitrary commands or code. The issue is due to the 'plugin.php' script not properly sanitizing user input, specifically directory traversal style attacks (e.g., ../../) supplied to the 'file' parameter. This may allow an attacker to include a file from the targeted host that contains arbitrary commands or code that will be executed by the vulnerable script. Such attacks are limited due to the script only calling files already on the target host. In addition, this flaw can potentially be used to disclose the contents of any file on the system accessible by the web server.
|
2009-06-09
|
S-CMS plugin.php file Parameter Traversal Local File Inclusion
|
|
61664
Description:
S-CMS contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the 'plugin.php' script not properly sanitizing user-supplied input to the 'username' parameter and the 'username' cookie. This may allow an attacker to inject or manipulate SQL queries in the back-end database, allowing for the manipulation or disclosure of arbitrary data.
|
2009-06-09
|
S-CMS plugin.php Multiple Parameter SQL Injection
|
|
54155
Description:
(Description Provided by CVE) : Directory traversal vulnerability in plugin.php in S-Cms 1.1 Stable and 1.5.2 allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the page parameter.
|
2009-04-29
|
S-CMS plugin.php page Parameter Traversal Local File Inclusion
|
|
69417
Description:
S-CMS contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the 'viewforum.php' script not properly sanitizing user-supplied input to the 'id' parameter. This may allow an attacker to inject or manipulate SQL queries in the back-end database, allowing for the manipulation or disclosure of arbitrary data.
|
2010-11-22
|
S-CMS viewforum.php id Parameter SQL Injection
|
|
73219
Description:
S-CMS contains a flaw that allows a remote cross-site scripting (XSS) attack. This flaw exists because the application does not validate the 'id' parameter upon submission to the 'viewforum.php' script. This may allow a user to create a specially crafted URL that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2010-11-20
|
S-CMS viewforum.php id Parameter XSS
|
|
60374
Description:
(Description Provided by CVE) : S-PLUS 6.0 allows local users to overwrite arbitrary files and possibly elevate privileges via a symlink attack on (1) /tmp/__F8499 by Sqpe, (2) /tmp/PRINT.$$.out by PRINT, (3) /tmp/SUBST$PID.TXT and /tmp/ed.cmds$PID by mustfix.hlinks, (4) /tmp/file.1 and /tmp/file.2 by sas_get, (5) /tmp/file.1 by sas_vars, and (6) /tmp/sgml2html$$tmp /tmp/sgml2html$$tmp1 /tmp/sgml2html$$tmp2 by sglm2html.
|
2003-01-05
|
S-PLUS Multiple Temporary File Symlink Arbitrary File Overwrite
|
|
64368
Description:
S.O.M.P.L. Player is prone to an overflow condition. The program fails to properly sanitize user-supplied input resulting in a stack overflow. With a specially crafted M3U file, a remote attacker can potentially cause arbitrary code execution.
|
2010-01-19
|
S.O.M.P.L. Player M3U Playlist File Handling Overflow
|
|
56191
Description:
Unknown / Incomplete
|
2009-07-22
|
S.T.A.L.K.E.R.: Clear Sky Nickname UDP Packet Handling DoS
|
|
46626
Description:
(Description Provided by CVE) : Stack-based buffer overflow in the IPureServer::_Recieve function in S.T.A.L.K.E.R.: Shadow of Chernobyl 1.0006 and earlier allows remote attackers to execute arbitrary code via a compressed 0x39 packet, which is decompressed by the NET_Compressor::Decompress function.
|
2008-06-28
|
S.T.A.L.K.E.R.: Shadow of Chernobyl IPureServer::_Recieve Function Remote Overflow
|
|
46628
Description:
(Description Provided by CVE) : The MultipacketReciever::RecievePacket function in S.T.A.L.K.E.R.: Shadow of Chernobyl 1.0006 and earlier allows remote attackers to cause a denial of service (server termination) via a crafted packet without an expected 0xe0 or 0xe1 value, which triggers the INT3 instruction.
|
2008-06-28
|
S.T.A.L.K.E.R.: Shadow of Chernobyl MultipacketReciever::RecievePacket Function Remote DoS
|
|
46627
Description:
(Description Provided by CVE) : Integer overflow in the NET_Compressor::Decompress function in S.T.A.L.K.E.R.: Shadow of Chernobyl 1.0006 and earlier allows remote attackers to cause a denial of service (server crash) via a crafted packet with a 0xc1 value that contains no compressed data, which triggers a copy of a large amount of memory.
|
2008-06-28
|
S.T.A.L.K.E.R.: Shadow of Chernobyl NET_Compressor::Decompress Function Remote Overflow DoS
|
|
46432
Description:
(Description Provided by CVE) : S.T.A.L.K.E.R.: Shadow of Chernobyl 1.0006 and earlier allows remote attackers to cause a denial of service (crash) via a long nickname, which triggers an exception.
|
2008-06-15
|
S.T.A.L.K.E.R.: Shadow of Chernobyl Nickname Handling Remote DoS
|
|
14175
Description:
(Description Provided by CVE) : keyinit in S/Key does not require authentication to initialize a one-time password sequence, which allows an attacker who has gained privileges to a user account to create new one-time passwords for use in other activities that may use S/Key authentication, such as sudo.
|
1999-09-23
|
S/Key keyinit One-time Password Sequence Initialization Authentication Weakness
|
|
3271
Description:
S/Key implementations contained a flaw that allowed a remote attacker to gain enough information to launch a trivial brute force attack against a login. The flaw was due to S/Key sending both the user/iteration and seed. By sending the seed along with the user/iteration, it greatly reduces the security provided by the S/Key protocol and allows an attacker relatively trivial effort to compromise the login information.
|
1996-05-01
|
S/Key Weak Password Implementation
|
|
65757
Description:
(Description Provided by CVE) : The S2 Security NetBox 2.5, 3.3, and 4.0, as used in the Linear eMerge 50 and 5000 and the Sonitrol eAccess, stores sensitive information under the web root with insufficient access control, which allows remote attackers to download node logs, photographs of persons, and backup files via unspecified HTTP requests.
|
2010-06-24
|
S2 NetBox Unspecified HTTP Request Directory Access Restriction Bypass
|
|
65929
Description:
(Description Provided by CVE) : The S2 Security NetBox 2.x and 3.x, as used in the Linear eMerge 50 and 5000 and the Sonitrol eAccess, uses a weak hash algorithm for storing the Administrator password, which makes it easier for context-dependent attackers to obtain privileged access by recovering the cleartext of this password.
|
2010-03-29
|
S2 Security NetBox Admin Password Hash Weakness
|
|
65928
Description:
(Description Provided by CVE) : The S2 Security NetBox, possibly 2.x and 3.x, as used in the Linear eMerge 50 and 5000 and the Sonitrol eAccess, does not require setting a password for the FTP server that stores database backups, which makes it easier for remote attackers to download backup files via unspecified FTP requests.
|
2010-03-29
|
S2 Security NetBox FTP Server Password Weakness Backup File Disclosure
|
|
65927
Description:
(Description Provided by CVE) : The S2 Security NetBox, possibly 2.x and 3.x, as used in the Linear eMerge 50 and 5000 and the Sonitrol eAccess, does not properly prevent downloading of database backups, which allows remote attackers to obtain sensitive information via requests for full_*.dar files with predictable filenames.
|
2010-03-29
|
S2 Security NetBox full_*.dar Predictable Filename Database Disclosure
|
|
77555
Description:
Unknown / Incomplete
|
2011-09-20
|
s2Member Plugin for WordPress Payment URL s2_invoice Parameter Access Restriction Bypass
|
|
75460
Description:
Unknown / Incomplete
|
2011-09-14
|
s2Member Plugin for WordPress Unspecified Traversal Arbitrary File Access
|
|
63805
Description:
S5 Clan Roster Component for Joomla! contains a flaw that may allow a remote attacker to execute arbitrary commands or code. The issue is due to the 'index.php' script not properly sanitizing user input, specifically directory traversal style attacks (e.g., ../../) supplied to the 'controller' parameter. This may allow an attacker to include a file from the targeted host that contains arbitrary commands or code that will be executed by the vulnerable script. Such attacks are limited due to the script only calling files already on the target host. In addition, this flaw can potentially be used to disclose the contents of any file on the system accessible by the web server.
|
2010-04-14
|
S5 Clan Roster Component for Joomla! index.php controller Parameter Directory Traversal Local File Inclusion
|
|
63804
Description:
S5 Clan Roster Component for Joomla! contains a flaw that may allow a remote attacker to execute arbitrary commands or code. The issue is due to the 'index.php' script not properly sanitizing user input, specifically directory traversal style attacks (e.g., ../../), supplied to the 'view' parameter. This may allow an attacker to include a file from the targeted host that contains arbitrary commands or code that will be executed by the vulnerable script. Such attacks are limited due to the script only calling files already on the target host. In addition, this flaw can potentially be used to disclose the contents of any file on the system accessible by the web server.
|
2010-04-14
|
S5 Clan Roster Component for Joomla! index.php view Parameter Directory Traversal Local File Inclusion
|
|
59678
Description:
(Description Provided by CVE) : Cross-site scripting (XSS) vulnerability in the S5 Presentation Player module 6.x-1.x before 6.x-1.1 for Drupal allows remote attackers to inject arbitrary web script or HTML via an unspecified field that is copied to the HTML HEAD element.
|
2009-11-04
|
S5 Presentation Player Module for Drupal Unspecified XSS
|
|
10858
Description:
S8Forum contains a flaw that will allow a remote attacker to execute arbitrary commands. The problem is that user-supplied input upon submission to the 'register.php' script is not verified properly. It is possible for a remote attacker to pass arbitrary commands to the server in the name, email, or password field to be executed on the system resulting in a loss of integrity.
|
2003-06-05
|
S8Forum register.php Arbitrary Command Execution
|
|
23849
Description:
(Description Provided by CVE) : Argument injection vulnerability in greylistclean.cron in sa-exim 4.2 allows remote attackers to delete arbitrary files via an email with a To field that contains a filename separated by whitespace, which is not quoted when greylistclean.cron provides the argument to the rm command.
|
2006-01-19
|
sa-exim greylistclean.cron Arbitrary File Deletion
|