| OSVDB ID | Disclosure Date | Title |
|
12735
Description:
PhotoPost Classifieds contains a flaw that will allow a remote attacker to inject arbitrary SQL code. The problem is that the 'cat' parameter in the 'index.php' script is not verified properly and will allow an attacker to inject or manipulate SQL queries.
|
2005-01-01
|
PhotoPost Classifieds index.php cat Parameter SQL Injection
|
|
12736
Description:
PhotoPost Classifieds contains a flaw that will allow a remote attacker to inject arbitrary SQL code. The problem is that the 'cedit' parameter in the 'comments.php' script is not verified properly and will allow an attacker to inject or manipulate SQL queries.
|
2005-01-01
|
PhotoPost Classifieds comments.php cedit Parameter SQL Injection
|
|
12597
Description:
Help Center Live contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the find variable upon submission to the index.php script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2004-12-24
|
Help Center Live index.php find Parameter XSS
|
|
12598
Description:
Help Center Live contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to pipe.php not properly sanitizing user input supplied to the HCL_path variable. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script.
|
2004-12-24
|
Help Center Live pipe.php Arbitrary Command Execution
|
|
12631
Description:
Help Center Live contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to skin.php not properly sanitizing user input. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script.
|
2004-12-24
|
Help Center Live skin.php Arbitrary Command Execution
|
|
12390
Description:
phpGroupware contains a flaw that may lead to an unauthorized information disclosure. The issue is triggered when sending a specially crafted URL request to the 'preferences.php' script, which will disclose the installation path resulting in a loss of confidentiality.
|
2004-12-14
|
phpGroupWare preferences.php Path Disclosure
|
|
12391
Description:
phpGroupware contains a flaw that may lead to an unauthorized information disclosure. The issue is triggered when sending a specially crafted URL request to the 'index.php' script, which will disclose the installation path resulting in a loss of confidentiality.
|
2004-12-14
|
phpGroupWare index.php Path Disclosure
|
|
12392
Description:
phpGroupWare contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate 'kp3' variables upon submission to the 'index.php' script ('wiki' directory). This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2004-12-14
|
phpGroupWare wiki/index.php kp3 Parameter XSS
|
|
12393
Description:
phpGroupWare contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate multiple variables upon submission to the 'index.php' script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2004-12-14
|
phpGroupWare index.php Multiple Parameter XSS
|
|
12394
Description:
phpGroupWare contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate 'ticket_id' variables upon submission to the 'viewticket_details.php' script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2004-12-14
|
phpGroupWare viewticket_details.php ticket_id Parameter XSS
|
|
12395
Description:
phpGroupWare contains a flaw that will allow a remote attacker to inject arbitrary SQL code. The problem is that the 'ticket_id' parameter in the 'viewticket_details.php' script is not verified properly and will allow an attacker to inject or manipulate SQL queries.
|
2004-12-14
|
phpGroupWare viewticket_details.php ticket_id Parameter SQL Injection
|
|
12396
Description:
phpGroupWare contains a flaw that will allow a remote attacker to inject arbitrary SQL code. The problem is that multiple parameters in the 'index.php' script are not verified properly and will allow an attacker to inject or manipulate SQL queries.
|
2004-12-14
|
phpGroupWare index.php Multiple Parameter SQL Injection
|
|
12120
Description:
SugarCRM contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate user-supplied input upon submission to multiple modules. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2004-12-01
|
SugarCRM Multiple Module XSS
|
|
12228
Description:
SugarCRM contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate user-supplied input when calling certain scripts directly. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2004-12-01
|
SugarCRM Direct Script Call XSS
|
|
12229
Description:
SugarCRM contains a flaw that will allow a remote attacker to inject arbitrary SQL code. The problem is that the 'record' parameter in multiple modules is not verified properly and will allow a remote attacker to inject or manipulate SQL queries.
|
2004-12-01
|
SugarCRM Multiple Module record Parameter SQL Injection
|
|
12230
Description:
SugarCRM contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to multiple modules not properly sanitizing user-supplied input. This may allow a remote attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script.
|
2004-12-01
|
SugarCRM Multiple Module Traversal Arbitrary File Access
|
|
13269
Description:
SugarCRM contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate user-supplied input upon submission to multiple modules. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2004-12-01
|
SugarCRM Module Path Disclosure
|
|
10380
Description:
A remote overflow exists in dBpowerAMP Music Converter and Audio Player. The application fails to perform proper bounds checking resulting in a buffer overflow. With a specially crafted playlist file (*.pls or *.m3u), a remote attacker can cause arbitrary code execution or cause the applications to crash resulting in a loss of integrity and/or availability.
|
2004-09-27
|
dBpowerAMP Multiple Products Playlist File Overflow
|
|
11126
Description:
A remote overflow exists in dBpowerAMP Music Converter and Audio Player. The application fails to perform proper bounds checking resulting in a buffer overflow. With a specially crafted *.mcc file, a remote attacker can cause arbitrary code execution or cause the applications to crash resulting in a loss of integrity and/or availability.
|
2004-09-27
|
dBpowerAMP Multiple Products .mcc File Overflow
|
|
11127
Description:
A remote overflow exists in dBpowerAMP Music Converter and Audio Player. The application fails to perform proper bounds checking resulting in a buffer overflow. With a specially crafted mp3 file containing malformed ID3 tags, a remote attacker can cause arbitrary code execution or cause the applications to crash resulting in a loss of integrity and/or availability.
|
2004-09-27
|
dBpowerAMP Multiple Products ID3 Tags Overflow
|
|
10176
Description:
EmuLive Server4 contains a flaw that may lead to an unauthorized information disclosure. The issue is triggered when a specially crafted URL is used, which will disclose Administrator information resulting in a loss of confidentiality.
|
2004-09-20
|
EmuLive Server4 Double Slash Admin Access Restriction Bypass
|
|
10177
Description:
EmuLive Server4 contains a flaw that may allow a a remote denial of service. The issue is triggered by sending a malicious TCP packet to a specific port, and will result in loss of availability for the platform.
|
2004-09-20
|
EmuLive Server4 Multiple Carriage Return DoS
|
|
10038
Description:
DNS4Me contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate HTTP GET requests. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2004-09-16
|
DNS4Me GET Request XSS
|
|
10039
Description:
DNS4Me contains a flaw that may allow a remote denial of service. The issue is triggered when sending a large amount of data to port 80, which causes the service to consume all available CPU resources and eventually crash resulting in a loss of availability.
|
2004-09-16
|
DNS4Me Web Server GET Request Overflow DoS
|
|
9444
Description:
phpWebSite contains a flaw that will allow an attacker to inject arbitrary SQL code. The problem is that the "cal_template" variable in the Calendar Module is not verified properly and will allow an attacker to inject or manipulate SQL queries.
|
2004-08-31
|
phpWebSite Calendar Module cal_template Parameter SQL Injection
|
|
9445
Description:
phpWebSite contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the "CM_pis" variable upon submission to the Comment Module. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2004-08-31
|
phpWebSite Comment Module CM_pid XSS
|
|
9446
Description:
phpWebSite contains a flaw that may allow a malicious user to execute arbitrary scripts within a user's browser. The issue is triggered when a malicious user sends specially crafted scripts via the 'subject' and 'message' fields within the notes module. It is possible that the flaw may allow the execution of the script within the users browser in the context of the affected phpWebSite while accessing the notes module, resulting in a loss of integrity.
|
2004-08-31
|
phpWebSite Notes Module Multiple Field Script Injection
|
|
9447
Description:
phpWebSite contains a flaw that may allow a malicious user to force an administrator to execute malicious code. The issue is triggered when a malicious user sends specially crafted code to an administrator which forces commands to be executed via POST requests instead of GET requests, bypassing some authentication checks. It is possible that the flaw may allow a remote attacker to create an adminsitrative account and/or take over the system resulting in a loss of confidentiality and/or integrity.
|
2004-08-31
|
phpWebSite Administrator Forced Command Execution
|
|
9387
Description:
Xedus Webserver contains a flaw that may allow a remote denial of service. The issue is triggered when establishing multiple connections from the same host, which causes the Web server to stop accepting requests from other users resulting in a loss of availability for the server.
|
2004-08-30
|
Xedus Webserver Connection Saturation DoS
|
|
9388
Description:
Xedus Webserver contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate 'username' variable upon submission to the 'test.x' script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2004-08-30
|
Xedus Webserver test.x username Parameter XSS
|
|
9389
Description:
Xedus Webserver contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the "username" variable upon submission to the "TestServer.x" script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2004-08-30
|
Xedus Webserver TestServer.x username Parameter XSS
|
|
9390
Description:
Xedus Webserver contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate 'username' variable upon submission to the 'testgetrequest.x' script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2004-08-30
|
Xedus Webserver testgetrequest.x username Parameter XSS
|
|
9391
Description:
Xedus Webserver contains a flaw that may allow a malicious user to access files outside the web root via directory traversal resulting in a loss of confidentiality. The issue is triggered when a user supplies a specially crafted link containing directory traversal characters.
|
2004-08-30
|
Xedus Webserver Traversal Arbitrary File Access
|
|
9174
Description:
Easy File Sharing Web Server contains a flaw that may allow a malicious user to bypass username checks. The issue is triggered when an attacker makes a request directly to the virtual folder disk_c. It is possible that the flaw may allow read access to the entire filesystem resulting in a loss of confidentiality.
|
2004-08-24
|
Easy File Sharing Web Server disk_c Virtual Folder Request Arbitrary File Access
|
|
9175
Description:
Easy File Sharing Web Server contains a flaw that may allow a remote denial of service. The issue is triggered when a number of large HTTP requests are sent, and will result in loss of availability for the service and possibly the platform by using all available CPU resources.
|
2004-08-24
|
Easy File Sharing Web Server HTTP Request Saturation DoS
|
|
9180
Description:
Multiple products of LiveWorld, such as LiveForum, LiveQ&A, LiveChat and Focus Groups contains flaws that allows a remote cross site scripting attack. These flaws exists because the application does not validate certain variables upon submission to some scripts. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2004-08-23
|
LiveWorld Multiple Products Multiple XSS
|
|
8592
Description:
Keene Digital Media Server contains a flaw that allows a remote attacker to view arbitrary files. The issue is due to the server not sanitizing URL requests. With a specially crafted URL request containing %2E and %5C characters, a remote attacker could view arbitrary files outside of the web root.
|
2004-08-11
|
Keene Digital Media Server Encoded Request Arbitrary File Access
|
|
4771
Description:
PhotoPost contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the 'addfav.php' script not properly sanitizing user-supplied input to the 'photo' parameter. This may allow an attacker to inject or manipulate SQL queries in the back-end database, allowing for the manipulation or disclosure of arbitrary data.
|
2004-03-28
|
PhotoPost addfav.php photo Parameter SQL Injection
|
|
10261
Description:
PhotoPost PHP Pro contains a flaw that will allow a remote attacker to inject arbitrary SQL code. The problem is that multiple variables in the 'comments.php' script are not verified properly and will allow an attacker to inject or manipulate SQL queries.
|
2004-03-28
|
PhotoPost PHP Pro comments.php Multiple Parameter SQL Injection
|
|
10262
Description:
PhotoPost PHP Pro contains a flaw that will allow a remote attacker to inject arbitrary SQL code. The problem is that the 'cat' variable in the 'index.php' script are not verified properly and will allow an attacker to inject or manipulate SQL queries.
|
2004-03-28
|
PhotoPost PHP Pro index.php cat Parameter SQL Injection
|