| OSVDB ID | Disclosure Date | Title |
|
15701
Description:
AZ Bulletin Board contains a flaw that may allow a malicious admin to delete arbitrary files. The issue is triggered when an input validation error occurs in admin_avatar.php. It is possible that the flaw may allow arbitrary file deletion resulting in a loss of availability.
|
2005-04-19
|
AZ Bulletin Board admin_avatar.php Arbitrary File Deletion
|
|
15702
Description:
AZ Bulletin Board contains a flaw that may allow a malicious admin to delete arbitrary files. The issue is triggered when an input validation error occurs in admin_attachment.php. It is possible that the flaw may allow arbitrary file deletion resulting in a loss of availability.
|
2005-04-19
|
AZ Bulletin Board admin_attachment.php Arbitrary File Deletion
|
|
15703
Description:
AZ Bulletin Board contains a flaw related to the input validation errors in "admin_avatar.php" and "admin_attachment.php" that may allow an attacker to exploited to delete arbitrary files.Input passed to the "dir_src" and "abs_layer" parameters in "main_index.php" isn't properly verified, before it is used to include files. This may be exploited to include arbitrary files from external and local resources.An input validation error in "attachment.php" can be exploited to enumerate local files via the "attachment" parameter.
|
2005-04-19
|
AZ Bulletin Board attachment.php File Existence Enumeration
|
|
15649
Description:
eGroupWare contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the 'ab_id', 'page', 'lang' or 'type' parameters upon submission to the index.php script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2005-04-15
|
eGroupWare index.php Multiple Parameter XSS
|
|
15750
Description:
eGroupWare contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the 'page' or 'lang' variables upon submission to the wiki/index.php script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2005-04-15
|
eGroupWare wiki/index.php Multiple Parameter XSS
|
|
15751
Description:
eGropuWare contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the category_id variable upon submission to the sitemgr-site/index.php script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2005-04-15
|
eGroupWare sitemgr-site/index.php category_id Parameter XSS
|
|
15752
Description:
eGroupWare contains a flaw that may allow an attacker to inject arbitrary SQL queries. The issue is due to the 'filter' variable in the tts/index.php script not being properly sanitized and may allow an attacker to inject or manipulate SQL queries.
|
2005-04-15
|
eGroupWare tts/index.php filter Parameter SQL Injection
|
|
15753
Description:
eGroupWare contains a flaw that may allow an attacker to inject arbitrary SQL queries. The issue is due to the 'cats_app' variable in the index.php script not being properly sanitized and may allow an attacker to inject or manipulate SQL queries.
|
2005-04-15
|
eGroupWare index.php cats_app Parameter SQL Injection
|
|
15426
Description:
ModernBill contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the 'c_code' or 'aid' variables upon submission to the orderwiz.php script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2005-04-10
|
ModernBill orderwiz.php Multiple Parameter XSS
|
|
15427
Description:
ModernBill contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to news.php not properly sanitizing user input supplied to the 'DIR' variable. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script.
|
2005-04-10
|
ModernBill news.php DIR Parameter Remote File Inclusion
|
|
15160
Description:
phpCOIN contains a flaw that will allow a remote attacker to inject arbitrary SQL code. The problem is that user-supplied input in the 'Search For' field is not verified properly and will allow a remote attacker to inject or manipulate SQL queries.
|
2005-03-29
|
phpCOIN Search Engine SQL Injection
|
|
15161
Description:
phpCOIN contains a flaw that will allow a remote attacker to inject arbitrary SQL code. The problem is that user-supplied input in the 'Domain Name' field when ordering a product is not verified properly and will allow a remote attacker to inject or manipulate SQL queries.
|
2005-03-29
|
phpCOIN Product Order SQL Injection
|
|
15162
Description:
phpCOIN contains a flaw that will allow a remote attacker to inject arbitrary SQL code. The problem is that user-supplied input in the 'username' and 'email' fields when requesting a forgotten password are not verified properly and will allow a remote attacker to inject or manipulate SQL queries.
|
2005-03-29
|
phpCOIN Forgotten Password Request SQL Injection
|
|
15163
Description:
phpCOIN contains a flaw that allows a remote attacker to arbitrary access files outside of the web path. The issue is due to the 'auxpage.php' script not properly sanitizing user input, specifically traversal style attacks (../../) supplied via the 'page' variable.
|
2005-03-29
|
phpCOIN auxpage.php page Parameter Traversal Arbitrary File Access
|
|
12703
Description:
ReviewPost PHP Pro contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate 'si' variables upon submission to the 'showcat.php' script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2005-01-03
|
ReviewPost PHP Pro showcat.php si Parameter XSS
|
|
12704
Description:
ReviewPost PHP Pro contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate multiple variables upon submission to the 'showproduct.php' script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2005-01-03
|
ReviewPost PHP Pro showproduct.php Multiple Parameter XSS
|
|
12705
Description:
ReviewPost PHP Pro contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate 'report' variables upon submission to the 'reportproduct.php' script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2005-01-03
|
ReviewPost PHP Pro reportproduct.php report Parameter XSS
|
|
12706
Description:
ReviewPost PHP Pro contains a flaw that will allow a remote attacker to inject arbitrary SQL code. The problem is that the 'cat' parameter in the 'showcat.php' script is not verified properly and will allow an attacker to inject or manipulate SQL queries.
|
2005-01-03
|
ReviewPost PHP Pro showcat.php cat Parameter SQL Injection
|
|
12707
Description:
ReviewPost PHP Pro contains a flaw that will allow a remote attacker to inject arbitrary SQL code. The problem is that the 'product' parameter in the 'addfav.php' script is not verified properly and will allow an attacker to inject or manipulate SQL queries.
|
2005-01-03
|
ReviewPost PHP Pro addfav.php product Parameter SQL Injection
|
|
12708
Description:
(Description Provided by CVE) : ReviewPost PHP Pro before 2.84 allows remote attackers to upload and execute arbitrary PHP files by posting a review file with multiple extensions, which bypasses the intended restrictions.
|
2005-01-03
|
ReviewPost PHP Pro Arbitrary File Upload
|
|
12741
Description:
PhotoPost PHP Pro contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate multiple variables upon submission to the 'showgallery.php' script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2005-01-03
|
PhotoPost PHP Pro showgallery.php Multiple Parameter XSS
|
|
12742
Description:
PhotoPost PHP Pro contains a flaw that will allow a remote attacker to inject arbitrary SQL code. The problem is that multiple parameters in the 'showgallery.php' script are not verified properly and will allow an attacker to inject or manipulate SQL queries.
|
2005-01-03
|
PhotoPost PHP Pro showgallery.php Multiple Parameter SQL Injection
|
|
12737
Description:
PhotoPost Classifieds contains a flaw that may allow a remote attacker to upload arbitrary files. The issue is triggered due to the improper handling of file names with multiple extensions. It is possible that the flaw may allow a remote attacker to upload arbitrary PHP files, which could execute arbitrary code resulting in a loss of integrity.
|
2005-01-01
|
PhotoPost Classifieds Multiple File Extension Upload Arbitrary Code Execution
|
|
12728
Description:
PhotoPost Classified contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate 'si' variables upon submission to the 'showcat.php' script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2005-01-01
|
PhotoPost Classifieds showcat.php si Parameter XSS
|
|
12729
Description:
PhotoPost Classified contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate 'report' variables upon submission to the 'reportproduct.php' script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2005-01-01
|
PhotoPost Classifieds reportproduct.php report Parameter XSS
|
|
12730
Description:
PhotoPost Classified contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate 'productid' variables upon submission to the 'contact.php' script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2005-01-01
|
PhotoPost Classifieds contact.php productid Parameter XSS
|
|
12731
Description:
PhotoPost Classifieds contains a flaw that will allow a remote attacker to inject arbitrary SQL code. The problem is that multiple parameters in the 'showproduct.php' script are not verified properly and will allow an attacker to inject or manipulate SQL queries.
|
2005-01-01
|
PhotoPost Classifieds showproduct.php Multiple Parameter SQL Injection
|
|
12732
Description:
PhotoPost Classifieds contains a flaw that will allow a remote attacker to inject arbitrary SQL code. The problem is that the 'productid' parameter in the 'contact.php' script is not verified properly and will allow an attacker to inject or manipulate SQL queries.
|
2005-01-01
|
PhotoPost Classifieds contact.php productid Parameter SQL Injection
|
|
12733
Description:
PhotoPost Classifieds contains a flaw that will allow a remote attacker to inject arbitrary SQL code. The problem is that the 'product' parameter in the 'addfav.php' script is not verified properly and will allow an attacker to inject or manipulate SQL queries.
|
2005-01-01
|
PhotoPost Classifieds addfav.php product Parameter SQL Injection
|
|
12734
Description:
PhotoPost Classifieds contains a flaw that will allow a remote attacker to inject arbitrary SQL code. The problem is that the 'cat' parameter in the 'showcat.php' script is not verified properly and will allow an attacker to inject or manipulate SQL queries.
|
2005-01-01
|
PhotoPost Classifieds showcat.php cat Parameter SQL Injection
|
|
12735
Description:
PhotoPost Classifieds contains a flaw that will allow a remote attacker to inject arbitrary SQL code. The problem is that the 'cat' parameter in the 'index.php' script is not verified properly and will allow an attacker to inject or manipulate SQL queries.
|
2005-01-01
|
PhotoPost Classifieds index.php cat Parameter SQL Injection
|
|
12736
Description:
PhotoPost Classifieds contains a flaw that will allow a remote attacker to inject arbitrary SQL code. The problem is that the 'cedit' parameter in the 'comments.php' script is not verified properly and will allow an attacker to inject or manipulate SQL queries.
|
2005-01-01
|
PhotoPost Classifieds comments.php cedit Parameter SQL Injection
|
|
12597
Description:
Help Center Live contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the find variable upon submission to the index.php script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2004-12-24
|
Help Center Live index.php find Parameter XSS
|
|
12598
Description:
Help Center Live contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to pipe.php not properly sanitizing user input supplied to the HCL_path variable. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script.
|
2004-12-24
|
Help Center Live pipe.php Arbitrary Command Execution
|
|
12631
Description:
Help Center Live contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to skin.php not properly sanitizing user input. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script.
|
2004-12-24
|
Help Center Live skin.php Arbitrary Command Execution
|
|
12390
Description:
phpGroupware contains a flaw that may lead to an unauthorized information disclosure. The issue is triggered when sending a specially crafted URL request to the 'preferences.php' script, which will disclose the installation path resulting in a loss of confidentiality.
|
2004-12-14
|
phpGroupWare preferences.php Path Disclosure
|
|
12391
Description:
phpGroupware contains a flaw that may lead to an unauthorized information disclosure. The issue is triggered when sending a specially crafted URL request to the 'index.php' script, which will disclose the installation path resulting in a loss of confidentiality.
|
2004-12-14
|
phpGroupWare index.php Path Disclosure
|
|
12392
Description:
phpGroupWare contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate 'kp3' variables upon submission to the 'index.php' script ('wiki' directory). This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2004-12-14
|
phpGroupWare wiki/index.php kp3 Parameter XSS
|
|
12393
Description:
phpGroupWare contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate multiple variables upon submission to the 'index.php' script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2004-12-14
|
phpGroupWare index.php Multiple Parameter XSS
|
|
12394
Description:
phpGroupWare contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate 'ticket_id' variables upon submission to the 'viewticket_details.php' script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2004-12-14
|
phpGroupWare viewticket_details.php ticket_id Parameter XSS
|