| OSVDB ID | Disclosure Date | Title |
|
51584
Description:
WB News contains a flaw that may allow a remote attacker to execute arbitrary commands or code. The issue is due to the 'comments.php' script not properly sanitizing user input supplied to the 'config[insalldir]' parameter. This may allow an attacker to include a file from a third-party remote host that contains commands or code that will be executed by the vulnerable script with the same privileges as the web server.
|
2009-01-25
|
WB News comments.php config[installdir] Parameter Remote File Inclusion
|
|
22523
Description:
(Description Provided by CVE) : Cross-site scripting vulnerability in WBNews 1.1.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the Name field.
|
2006-01-17
|
WB News Name Field XSS
|
|
51585
Description:
WB News contains a flaw that may allow a remote attacker to execute arbitrary commands or code. The issue is due to the 'news.php' script not properly sanitizing user input supplied to the 'config[installdir]' parameter. This may allow an attacker to include a file from a third-party remote host that contains commands or code that will be executed by the vulnerable script with the same privileges as the web server.
|
2009-01-25
|
WB News news.php config[installdir] Parameter Remote File Inclusion
|
|
51591
Description:
WB News contains a flaw that may allow a remote attacker to execute arbitrary commands or code. The issue is due to the 'search.php' script not properly sanitizing user input supplied to the 'config[installdir]' parameter. This may allow an attacker to include a file from a third-party remote host that contains commands or code that will be executed by the vulnerable script with the same privileges as the web server.
|
2009-01-25
|
WB News search.php config[installdir] Parameter Remote File Inclusion
|
|
63973
Description:
WB News contains a flaw that allows a remote cross site scripting (XSS) attack. This flaw exists because the application does not validate the 'message' and 'name' parameters upon submission to the comments.php script. This may allow a user to create a specially crafted URL that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2010-04-17
|
WB News Unspecified Multiple Parameter XSS
|
|
53822
Description:
(Description Provided by CVE) : WB News 2.1.2 allows remote attackers to bypass authentication and gain administrative access via a modified WBNEWS cookie, as demonstrated by setting this cookie to 1.
|
2009-04-20
|
WB News WBNEWS Cookie Manipulation Admin Authentication Bypass
|
|
38304
Description:
(Description Provided by CVE) : SQL injection vulnerability in acrotxt.php in WBB2-Addon: Acrotxt 1 allows remote attackers to execute arbitrary SQL commands via the show parameter.
|
2007-08-27
|
WBB2-Addon for Acrotxt acrotxt.php show Parameter SQL Injection
|
|
34182
Description:
WBBlog contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the 'index.php' script not properly sanitizing user-supplied input to the 'e_id' parameter. This may allow an attacker to inject or manipulate SQL queries in the back-end database, allowing for the manipulation or disclosure of arbitrary data.
|
2007-03-15
|
WBBlog index.php e_id Parameter SQL Injection
|
|
34183
Description:
WBBlog contains a flaw that allows a remote cross site scripting (XSS) attack. This flaw exists because the application does not validate the 'e_id' parameter upon submission to the 'index.php' script. This may allow a user to create a specially crafted URL that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2007-03-15
|
WBBlog index.php e_id Parameter XSS
|
|
38886
Description:
(Description Provided by CVE) : Multiple cross-site scripting (XSS) vulnerabilities in cgi-bin/ddns in the web management panel for the WBR3404TX broadband router with firmware R1.94p0vTIG allow remote attackers to inject arbitrary web script or HTML via the (1) DD or (2) DU parameter.
|
2007-09-19
|
WBR3404TX Broadband Router Web Management Panel cgi-bin/ddns Multiple Parameter XSS
|
|
51579
Description:
(Description Provided by CVE) : Wbstreet (aka PHPSTREET Webboard) 1.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain database credentials via a direct request to connect.inc.
|
2008-12-04
|
Wbstreet connect.inc Direct Request Database Credentials Disclosure
|
|
51575
Description:
Wbstreet contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the 'show.php' script not properly sanitizing user-supplied input to the 'id' parameter. This may allow an attacker to inject or manipulate SQL queries in the back-end database.
|
2008-12-04
|
Wbstreet show.php id Parameter SQL Injection
|
|
12105
Description:
Unknown / Incomplete
|
2004-11-20
|
WCI TC-IDE Embedded Linux Net Tools Dialog Privilege Escalation
|
|
12107
Description:
Unknown / Incomplete
|
2004-11-20
|
WCI TC-IDE Embedded Linux Opera Preferences Privilege Escalation
|
|
12106
Description:
Unknown / Incomplete
|
2004-11-20
|
WCI TC-IDE Embedded Linux PPPoE Dialer Privilege Escalation
|
|
33539
Description:
(Description Provided by CVE) : wcSimple Poll stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain password hashes via a direct request for password.txt.
|
2007-01-14
|
wcSimple Poll password.txt Direct Request Password Disclosure
|
|
15103
Description:
(Description Provided by CVE) : Webmasters-Debutants WD Guestbook 2.8 allows remote attackers to bypass authentication and perform certain administrator actions via a direct HTTP POST request to (1) ajout_admin2.php or (2) suppr.php.
|
2005-03-24
|
WD Guestbook ajout_admin2.php Arbitrary Admin Account Creation
|
|
15104
Description:
(Description Provided by CVE) : Webmasters-Debutants WD Guestbook 2.8 allows remote attackers to bypass authentication and perform certain administrator actions via a direct HTTP POST request to (1) ajout_admin2.php or (2) suppr.php.
|
2005-03-24
|
WD Guestbook suppr.php Arbitrary Message Suppression
|
|
34661
Description:
(Description Provided by CVE) : ** DISPUTED ** WDaemon 9.5.4 allows remote attackers to access the /WorldClient.dll URI on TCP port 3000, which has unknown impact. NOTE: The researcher reports that the vendor response was "this is not a security bug."
|
2007-01-18
|
WDaemon /WorldClient.dll URI TCP Port 3000 Unspecified DoS
|
|
72771
Description:
Unknown / Incomplete
|
2011-03-01
|
we20090202 Multiple Applications for Android Trojaned Distribution
|
|
38136
Description:
(Description Provided by CVE) : Directory traversal vulnerability in index.php in InstaGuide Weather (aka Weather for PHP) 1.0, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the PageName parameter.
|
2007-10-22
|
Weather Free index.php PageName Parameter Traversal Local File Inclusion
|
|
34807
Description:
(Description Provided by CVE) : PHP remote file inclusion vulnerability in index.php in Weatimages 1.7.1 and earlier, when weatimages.ini is missing, allows remote attackers to execute arbitrary PHP code via a URL in the ini[langpack] parameter.
|
2007-04-10
|
Weatimages index.php ini[langpack] Parameter Remote File Inclusion
|
|
61445
Description:
Unknown / Incomplete
|
2009-12-31
|
Weatimages index.php path Parameter Traversal Arbitrary Directory Access
|
|
65440
Description:
(Description Provided by CVE) : Web Application Finger Printer (WAFP) 0.01-26c3 uses fixed pathnames under /tmp for temporary files and directories, which (1) allows local users to cause a denial of service (application outage) by creating a file with a pathname that the product expects is available for its own internal use, (2) allows local users to overwrite arbitrary files via symlink attacks on certain files in /tmp, (3) might allow local users to delete arbitrary files and directories via a symlink attack on a directory under /tmp, and (4) might make it easier for local users to obtain sensitive information by reading files in a directory under /tmp, related to (a) lib/wafp_pidify.rb, (b) utils/generate_wafp_fingerprint.sh, (c) utils/online_update.sh, and (d) utils/extract_from_db.sh.
|
2010-04-28
|
Web Application Finger Printer (WAFP) Multiple Script Insecure /tmp Handling Issue
|
|
3088
Description:
WebArtFactory CMS contains a flaw that may allow a malicious user unauthorized access to all management webpages. The issue is due to an undisclosed vulnerability in the authentication mechanism for the management subsystem.
|
2003-12-16
|
Web Art Factory CMS Unspecified User Authentication
|
|
23387
Description:
(Description Provided by CVE) : SQL injection vulnerability in dropbase.php in MitriDAT Web Calendar Pro allows remote attackers to modify internal SQL queries and cause a denial of service (inaccessible database) via the tabls parameter.
|
2006-01-12
|
Web Calendar Pro dropbase.php tabls Parameter SQL Injection DoS
|
|
44536
Description:
(Description Provided by CVE) : SQL injection vulnerability in one_day.php in Web Calendar Pro 4.1 and earlier allows remote attackers to execute arbitrary SQL commands via the user_id parameter.
|
2008-04-22
|
Web Calendar Pro one_day.php user_id Parameter SQL Injection
|
|
36950
Description:
(Description Provided by CVE) : PHP remote file inclusion vulnerability in CliServ Web Community 0.65 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the cl_headers parameter to (1) menu.php3 and (2) login.php3.
|
2006-08-25
|
Web Community login.php3 cl_headers Parameter Remote File Inclusion
|
|
36949
Description:
(Description Provided by CVE) : PHP remote file inclusion vulnerability in CliServ Web Community 0.65 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the cl_headers parameter to (1) menu.php3 and (2) login.php3.
|
2006-08-25
|
Web Community menu.php3 cl_headers Parameter Remote File Inclusion
|
|
54635
Description:
Web Conference Room Free contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate unspecified variables upon submission to an unspecified script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2009-05-22
|
Web Conference Room Free Unspecified XSS
|