| OSVDB ID | Disclosure Date | Title |
|
77183
Description:
V-CMS contains a flaw that allows a remote user to execute arbitrary PHP code. This flaw exists because the inline_image_upload.php script does not properly verify or sanitize user-uploaded files. By uploading a .php file, the remote system will place the file in a user-accessible path. Making a direct request to the uploaded file will allow the user to execute the script with the privileges of the web server.
|
2011-11-13
|
V-CMS includes/inline_image_upload.php File Upload Arbitrary PHP Code Execution
|
|
77181
Description:
V-CMS contains a flaw that allows a remote cross-site scripting (XSS) attack. This flaw exists because the includes/TrueColorPicker/class.TrueColorPicker.php script does not validate the 'box' parameter upon submission to the includes/TrueColorPicker/index.php script. This may allow a user to create a specially crafted URL that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2011-11-13
|
V-CMS includes/TrueColorPicker/index.php box Parameter XSS
|
|
77182
Description:
V-CMS contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the process.php script not properly sanitizing user-supplied input to the 'user' parameter. This may allow an attacker to inject or manipulate SQL queries in the back-end database, allowing for the manipulation or disclosure of arbitrary data.
|
2011-11-13
|
V-CMS process.php user Parameter SQL Injection
|
|
77180
Description:
V-CMS contains a flaw that allows a remote cross-site scripting (XSS) attack. This flaw exists because the application does not validate the 'p' parameter upon submission to the redirect.php script. This may allow a user to create a specially crafted URL that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2011-11-13
|
V-CMS redirect.php p Parameter XSS
|
|
87384
Description:
V-CMS contains a flaw that allows a remote user to execute arbitrary PHP code. This flaw exists because the uploadify.php script does not properly verify or sanitize user-uploaded files. By uploading a .php file, the remote system will place the file in a user-accessible path. Making a direct request to the uploaded file will allow the user to execute the script, and therefore their own code.
|
2012-06-03
|
V-CMS uploadify.php File Upload Arbitrary Code Execution
|
|
24304
Description:
v-creator contains a flaw that may allow a malicious user to execute arbitrary shell commands. The issue is triggered due to an input validation error in the 'enrypt()' and 'decrypt()' functions in VCEngine.php. It is possible that the flaw may allow arbitrary command execution resulting in a loss of integrity.
|
2006-03-30
|
v-creator VCEngine.php OPENSSL Command Injection
|
|
74279
Description:
(Description Provided by CVE) : Passlogix v-GO Self-Service Password Reset (SSPR) and OEM before 7.0A allows physically proximate attackers to execute arbitrary programs without authentication by triggering use of an invalid SSL certificate and using the Internet Explorer interface to navigate through the filesystem via a "Save As" dialog that is reachable from the "Certificate Export" wizard.
|
2010-12-10
|
v-GO Self-Service Password Reset (SSPR) Invalid SSL Certificate Export Save As Dialog Arbitrary Program Execution
|
|
55495
Description:
V-SpacePal contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the login.asp script not properly sanitizing user-supplied input to the password parameter. This may allow an attacker to bypass authentication
|
2009-06-30
|
V-SpacePal login.asp Password Parameter SQL Injection
|
|
26085
Description:
V-webmail contains a flaw that may allow a remote attacker to execute arbitrary commands or code. The issue is due to the 'core.php' script not properly sanitizing user input supplied to the 'CONFIG[pear_dir]' parameter. This may allow an attacker to include a file from a third-party remote host that contains commands or code that will be executed by the vulnerable script with the same privileges as the web server.
|
2006-05-25
|
V-webmail core.php CONFIG[pear_dir] Parameter Remote File Inclusion
|
|
23261
Description:
V-webmail contains a flaw that may allow a remote attacker to execute arbitrary commands in the target's web browser. The issue is due to 'frameset.php' not properly sanitizing user input supplied to the 'rframe' variable. This may allow an attacker to include a file from a remote host that contains arbitrary scripting commands which will be executed by the browser.
|
2006-02-17
|
V-webmail frameset.php rframe Variable Arbitrary Remote HTML Inclusion
|
|
23262
Description:
V-webmail contains a flaw that may lead to an unauthorized information disclosure. The issue is triggered when invalid parameters are passed to the 'help.php' script, which will disclose file system path information resulting in a loss of confidentiality.
|
2006-02-17
|
V-webmail help.php Direct Request Path Disclosure
|
|
55581
Description:
V-webmail contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to the 'includes/cachedConfig.php' script not properly sanitizing user input supplied to the 'CONFIG[pear_dir]' parameter. This may allow an attacker to include a file from an arbitrary remote host that contains commands which will be executed by the vulnerable script with the same privileges as the web server.
|
2008-07-10
|
V-webmail includes/cachedConfig.php CONFIG[pear_dir] Parameter Remote File Inclusion
|
|
55583
Description:
V-webmail contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to the 'includes/email.list.search.php' script not properly sanitizing user input supplied to the 'CONFIG[includes]' parameter. This may allow an attacker to include a file from an arbitrary remote host that contains commands which will be executed by the vulnerable script with the same privileges as the web server.
|
2008-07-10
|
V-webmail includes/email.list.search.php CONFIG[includes] Parameter Remote File Inclusion
|
|
55573
Description:
V-webmail contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to the 'includes/pear/Console/Getopt.php' script not properly sanitizing user input supplied to the 'CONFIG[pear_dir]' parameter. This may allow an attacker to include a file from an arbitrary remote host that contains commands which will be executed by the vulnerable script with the same privileges as the web server.
|
2008-07-10
|
V-webmail includes/pear/Console/Getopt.php CONFIG[pear_dir] Parameter Remote File Inclusion
|
|
55578
Description:
V-webmail contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to the 'includes/pear/File.php' script not properly sanitizing user input supplied to the 'CONFIG[pear_dir]' parameter. This may allow an attacker to include a file from an arbitrary remote host that contains commands which will be executed by the vulnerable script with the same privileges as the web server.
|
2008-07-10
|
V-webmail includes/pear/File.php CONFIG[pear_dir] Parameter Remote File Inclusion
|
|
55576
Description:
V-webmail contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to the 'includes/pear/Log.php' script not properly sanitizing user input supplied to the 'CONFIG[pear_dir]' parameter. This may allow an attacker to include a file from an arbitrary remote host that contains commands which will be executed by the vulnerable script with the same privileges as the web server.
|
2008-07-10
|
V-webmail includes/pear/Log.php CONFIG[pear_dir] Parameter Remote File Inclusion
|
|
55572
Description:
V-webmail contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to the 'includes/pear/Mail/mimeDecode.php' script not properly sanitizing user input supplied to the 'CONFIG[pear_dir]' parameter. This may allow an attacker to include a file from an arbitrary remote host that contains commands which will be executed by the vulnerable script with the same privileges as the web server.
|
2008-07-10
|
V-webmail includes/pear/Mail/mimeDecode.php CONFIG[pear_dir] Parameter Remote File Inclusion
|
|
55568
Description:
V-webmail contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to the 'includes/pear/Mail/RFC822.php' script not properly sanitizing user input supplied to the 'CONFIG[pear_dir]' parameter. This may allow an attacker to include a file from an arbitrary remote host that contains commands which will be executed by the vulnerable script with the same privileges as the web server.
|
2008-07-10
|
V-webmail includes/pear/Mail/RFC822.php CONFIG[pear_dir] Parameter Remote File Inclusion
|
|
55569
Description:
V-webmail contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to the 'includes/pear/Net/Socket.php' script not properly sanitizing user input supplied to the 'CONFIG[pear_dir]' parameter. This may allow an attacker to include a file from an arbitrary remote host that contains commands which will be executed by the vulnerable script with the same privileges as the web server.
|
2008-07-10
|
V-webmail includes/pear/Net/Socket.php CONFIG[pear_dir] Parameter Remote File Inclusion
|
|
55574
Description:
V-webmail contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to the 'includes/pear/System.php' script not properly sanitizing user input supplied to the 'CONFIG[pear_dir]' parameter. This may allow an attacker to include a file from an arbitrary remote host that contains commands which will be executed by the vulnerable script with the same privileges as the web server.
|
2008-07-10
|
V-webmail includes/pear/System.php CONFIG[pear_dir] Parameter Remote File Inclusion
|
|
55570
Description:
V-webmail contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to the 'includes/pear/XML/Parser.php' script not properly sanitizing user input supplied to the 'CONFIG[pear_dir]' parameter. This may allow an attacker to include a file from an arbitrary remote host that contains commands which will be executed by the vulnerable script with the same privileges as the web server.
|
2008-07-10
|
V-webmail includes/pear/XML/Parser.php CONFIG[pear_dir] Parameter Remote File Inclusion
|
|
55571
Description:
V-webmail contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to the 'includes/pear/XML/Tree.php' script not properly sanitizing user input supplied to the 'CONFIG[pear_dir]' parameter. This may allow an attacker to include a file from an arbitrary remote host that contains commands which will be executed by the vulnerable script with the same privileges as the web server.
|
2008-07-10
|
V-webmail includes/pear/XML/Tree.php CONFIG[pear_dir] Parameter Remote File Inclusion
|
|
55582
Description:
V-webmail contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to the 'includes/prepend.php' script not properly sanitizing user input supplied to the 'CONFIG[includes]' parameter. This may allow an attacker to include a file from an arbitrary remote host that contains commands which will be executed by the vulnerable script with the same privileges as the web server.
|
2008-07-10
|
V-webmail includes/prepend.php CONFIG[includes] Parameter Remote File Inclusion
|
|
55579
Description:
V-webmail contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to the 'includes/prepend.php' script not properly sanitizing user input supplied to the 'CONFIG[pear_dir]' parameter. This may allow an attacker to include a file from an arbitrary remote host that contains commands which will be executed by the vulnerable script with the same privileges as the web server.
|
2008-07-10
|
V-webmail includes/prepend.php CONFIG[pear_dir] Parameter Remote File Inclusion
|
|
48793
Description:
V-webmail contains a flaw that may lead to an unauthorized information disclosure. The issue is triggered when a remote attacker provides unexpected input to the login page, which will disclose the software's installation path resulting in a loss of confidentiality. While such information is relatively low risk, it is often useful in carrying out additional, more focused attacks.
|
2008-10-05
|
V-webmail Login Page imap_open() Function Path Disclosure
|
|
48795
Description:
V-webmail contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the login.php script not properly sanitizing user-supplied input to the 'username' field. This may allow an attacker to inject or manipulate SQL queries in the back-end database.
|
2008-10-05
|
V-webmail login.php username Field SQL Injection
|
|
48794
Description:
V-webmail contains a flaw that may lead to an unauthorized information disclosure. The issue is triggered when a remote attacker provides malformed session data, which will disclose the software's configured temporary directory resulting in a loss of confidentiality. While such information is relatively low risk, it is often useful in carrying out additional, more focused attacks.
|
2008-10-05
|
V-webmail Malformed Session Data Temporary Directory Disclosure
|
|
26086
Description:
V-webmail contains a flaw that may allow a remote attacker to execute arbitrary commands or code. The issue is due to the 'pop3.php' script not properly sanitizing user input supplied to the 'CONFIG[pear_dir]' parameter. This may allow an attacker to include a file from a third-party remote host that contains commands or code that will be executed by the vulnerable script with the same privileges as the web server.
|
2006-05-25
|
V-webmail pop3.php CONFIG[pear_dir] Parameter Remote File Inclusion
|
|
23260
Description:
V-webmail contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the 'newid' variable upon submission to the 'preferences.personal.php' script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2006-02-17
|
V-webmail preferences.personal.php newid Parameter XSS
|
|
48796
Description:
V-webmail contains a flaw that allows a remote cross site redirection attack. This flaw exists because the application does not validate the "to" variable upon submission to the redirect.php script. This could allow a user to create a specially crafted URL that would allow malicious redirection in a user's browser to an arbitrary web site, without user interaction.
|
2008-10-05
|
V-webmail redirect.php to Variable Arbitrary Site Redirect
|