| OSVDB ID | Disclosure Date | Title |
|
16555
Description:
yappa-ng contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to the index_overview.inc.php script not properly sanitizing user input supplied to the 'config' variable. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script.
|
2005-05-11
|
yappa-ng index_overview.inc.php config Parameter Remote File Inclusion
|
|
16556
Description:
yappa-ng contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to the index_leftnavbar.inc.php script not properly sanitizing user input supplied to the 'config' variable. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script.
|
2005-05-11
|
yappa-ng index_leftnavbar.inc.php config Parameter Remote File Inclusion
|
|
16557
Description:
yappa-ng contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to the index_image.inc.php script not properly sanitizing user input supplied to the 'config' variable. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script.
|
2005-05-11
|
yappa-ng index_image.inc.php config Parameter Remote File Inclusion
|
|
16558
Description:
yappa-ng contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to the image-gd.class.php script not properly sanitizing user input supplied to the 'config' variable. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script.
|
2005-05-11
|
yappa-ng image-gd.class.php config Parameter Remote File Inclusion
|
|
16559
Description:
yappa-ng contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to the image.class.php script not properly sanitizing user input supplied to the 'config' variable. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script.
|
2005-05-11
|
yappa-ng image.class.php config Parameter Remote File Inclusion
|
|
16560
Description:
yappa-ng contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to the album.class.php script not properly sanitizing user input supplied to the 'config' variable. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script.
|
2005-05-11
|
yappa-ng album.class.php config Parameter Remote File Inclusion
|
|
16561
Description:
yappa-ng contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to the show_random.inc.php script not properly sanitizing user input supplied to the 'config' variable. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script.
|
2005-05-11
|
yappa-ng show_random.inc.php config Parameter Remote File Inclusion
|
|
16562
Description:
yappa-ng contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to the main.inc.php script not properly sanitizing user input supplied to the 'config' variable. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script.
|
2005-05-11
|
yappa-ng main.inc.php config Parameter Remote File Inclusion
|
|
16563
Description:
yappa-ng contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to the index_passwd-admin.inc.php script not properly sanitizing user input supplied to the 'config' variable. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script.
|
2005-05-11
|
yappa-ng index_passwd-admin.inc.php config Parameter Remote File Inclusion
|
|
16297
Description:
Invision Power Board contains a flaw that may allow a remote attacker to inject arbitrary SQL queries. This flaw exists because the 'login.php' script does not validate user-supplied input in certain login methods and may allow a remote attacker to inject or manipulate SQL queries.
|
2005-05-05
|
Invision Power Board login.php SQL Injection
|
|
16298
Description:
Invision Power Board contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the 'highlite' variable upon submission to the 'topics.php' script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2005-05-05
|
Invision Power Board topics.php highlite Parameter XSS
|
|
16270
Description:
osTicket contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the 't' variable upon submission to the view.php script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2005-05-02
|
osTicket view.php t Parameter XSS
|
|
16271
Description:
osTicket contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the 'osticket_title' variable upon submission to the header.php script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2005-05-02
|
osTicket header.php osticket_title Parameter XSS
|
|
16272
Description:
osTicket contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the 'em' variable upon submission to the admin_login.php script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2005-05-02
|
osTicket admin_login.php em Parameter XSS
|
|
16273
Description:
osTicket contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the 'e' variable upon submission to the user_login.php script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2005-05-02
|
osTicket user_login.php e Parameter XSS
|
|
16274
Description:
osTicket contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the 'err' variable upon submission to the open_submit.php script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2005-05-02
|
osTicket open_submit.php err Parameter XSS
|
|
16275
Description:
osTicket contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the 'Name' or 'Subject' fields upon submission to the add ticket routine. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2005-05-02
|
osTicket Ticket Creation Multiple Field Script Injection
|
|
16276
Description:
osTicket contains a flaw that may allow an attacker to inject arbitrary SQL queries. The issue is due to the 'id' variable in the admin.php script not being properly sanitized and may allow an attacker to inject or manipulate SQL queries.
|
2005-05-02
|
osTicket admin.php id Parameter SQL Injection
|
|
16277
Description:
osTicket contains a flaw that may allow an attacker to inject arbitrary SQL queries. The issue is due to the 'cat' variable in the view.php script not being properly sanitized and may allow an attacker to inject or manipulate SQL queries.
|
2005-05-02
|
osTicket view.php cat Parameter SQL Injection
|
|
16278
Description:
osTicket contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to the main.php script not properly sanitizing user input supplied to the 'include_dir' variable. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script.
|
2005-05-02
|
osTicket main.php include_dir Parameter Remote File Inclusion
|
|
16279
Description:
osTicket contains a flaw that allows a remote attacker to view arbitrary files outside of the web path. The issue is due to the attachments.php script not properly sanitizing user input, specifically traversal style attacks (../../) supplied via the 'file' variable.
|
2005-05-02
|
osTicket attachments.php file Parameter Traversal Arbitrary File Access
|
|
16262
Description:
SitePanel2 contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the 'v', 'show' or 'sec_name' variables upon submission to the main.php script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2005-05-02
|
SitePanel2 main.php Multiple Parameter XSS
|
|
16263
Description:
SitePanel2 contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the 'inadmin', 'newsev' or 'postid' variables upon submission to the 5.php script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2005-05-02
|
SitePanel2 5.php Multiple Parameter XSS
|
|
16264
Description:
SitePanel2 contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the 'id' variable upon submission to the 0.php script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2005-05-02
|
SitePanel2 0.php id Parameter XSS
|
|
16265
Description:
SitePanel2 contains a flaw that may allow a remote attacker to delete arbitrary files. The issue is due to the 5.php script not properly sanitizing input passed to the 'id' variable. By specifying arbitrary files to this script, the system will delete the file without proper authentication. Even if the server runs as user 'nobody', this can be used to delete arbitrary attachments.
|
2005-05-02
|
SitePanel2 5.php id Variable Traversal Arbitrary File Deletion
|
|
16266
Description:
SitePanel2 contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to index.php not properly sanitizing user input supplied to the 'lang' variable. This may allow an attacker to include a file from the local host that contains arbitrary commands which will be executed by the vulnerable script. An attacker could also specify an arbitrary file on the local host which would be disclosed in full.
|
2005-05-02
|
SitePanel2 index.php lang Parameter Traversal Local File Inclusion
|
|
16267
Description:
SitePanel2 contains a flaw that may allow an attacker to execute arbitrary files. The issue is due to the system allowing users to upload any file as an attachment to a trouble ticket. Once uploaded, the file can be executed with the same privileges as the web server.
|
2005-05-02
|
SitePanel2 Arbitrary File Upload
|
|
16268
Description:
SitePanel2 contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to main.php not properly sanitizing user input supplied to the 'p' variable. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script.
|
2005-05-02
|
SitePanel2 main.php p Parameter Remote File Inclusion
|
|
15899
Description:
phpBB contains a flaw that may allow an attacker to inject arbitrary SQL queries. The issue is due to the 'p' variable in the posting_notes.php script not being properly sanitized and may allow an attacker to inject or manipulate SQL queries.
|
2005-04-27
|
phpBB Personal Notes Module posting_notes.php p Parameter SQL Injection
|
|
15700
Description:
AZ Bulletin Board contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to main_index.php not properly sanitizing user input supplied to the dir_src and abs_layer parameters. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script.
|
2005-04-19
|
AZ Bulletin Board main_index.php Arbitrary File Inclusion
|
|
15701
Description:
AZ Bulletin Board contains a flaw that may allow a malicious admin to delete arbitrary files. The issue is triggered when an input validation error occurs in admin_avatar.php. It is possible that the flaw may allow arbitrary file deletion resulting in a loss of availability.
|
2005-04-19
|
AZ Bulletin Board admin_avatar.php Arbitrary File Deletion
|
|
15702
Description:
AZ Bulletin Board contains a flaw that may allow a malicious admin to delete arbitrary files. The issue is triggered when an input validation error occurs in admin_attachment.php. It is possible that the flaw may allow arbitrary file deletion resulting in a loss of availability.
|
2005-04-19
|
AZ Bulletin Board admin_attachment.php Arbitrary File Deletion
|
|
15703
Description:
AZ Bulletin Board contains a flaw related to the input validation errors in "admin_avatar.php" and "admin_attachment.php" that may allow an attacker to exploited to delete arbitrary files.Input passed to the "dir_src" and "abs_layer" parameters in "main_index.php" isn't properly verified, before it is used to include files. This may be exploited to include arbitrary files from external and local resources.An input validation error in "attachment.php" can be exploited to enumerate local files via the "attachment" parameter.
|
2005-04-19
|
AZ Bulletin Board attachment.php File Existence Enumeration
|
|
15649
Description:
eGroupWare contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the 'ab_id', 'page', 'lang' or 'type' parameters upon submission to the index.php script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2005-04-15
|
eGroupWare index.php Multiple Parameter XSS
|
|
15750
Description:
eGroupWare contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the 'page' or 'lang' variables upon submission to the wiki/index.php script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2005-04-15
|
eGroupWare wiki/index.php Multiple Parameter XSS
|
|
15751
Description:
eGropuWare contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the category_id variable upon submission to the sitemgr-site/index.php script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2005-04-15
|
eGroupWare sitemgr-site/index.php category_id Parameter XSS
|
|
15752
Description:
eGroupWare contains a flaw that may allow an attacker to inject arbitrary SQL queries. The issue is due to the 'filter' variable in the tts/index.php script not being properly sanitized and may allow an attacker to inject or manipulate SQL queries.
|
2005-04-15
|
eGroupWare tts/index.php filter Parameter SQL Injection
|
|
15753
Description:
eGroupWare contains a flaw that may allow an attacker to inject arbitrary SQL queries. The issue is due to the 'cats_app' variable in the index.php script not being properly sanitized and may allow an attacker to inject or manipulate SQL queries.
|
2005-04-15
|
eGroupWare index.php cats_app Parameter SQL Injection
|
|
15426
Description:
ModernBill contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the 'c_code' or 'aid' variables upon submission to the orderwiz.php script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2005-04-10
|
ModernBill orderwiz.php Multiple Parameter XSS
|
|
15427
Description:
ModernBill contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to news.php not properly sanitizing user input supplied to the 'DIR' variable. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script.
|
2005-04-10
|
ModernBill news.php DIR Parameter Remote File Inclusion
|