| OSVDB ID | Disclosure Date | Title |
|
19940
Description:
Utopia News Pro contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the 'sitetitle' variable upon submission to the 'header.php' script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2005-10-06
|
Utopia News Pro header.php sitetitle Parameter XSS
|
|
19941
Description:
Utopia News Pro contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate 'version' and 'query_count' variables upon submission to the 'footer.php' script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2005-10-06
|
Utopia News Pro footer.php Multiple Parameter XSS
|
|
19942
Description:
Utopia News Pro contains a flaw that may allow a remote attacker to carry out an SQL injection attack. The issue is due to the 'news.php' script not properly sanitizing user-supplied input to the 'newsid' variable. This may allow a remote attacker to inject or manipulate SQL queries in the back-end database.
|
2005-10-06
|
Utopia News Pro news.php newsid Parameter SQL Injection
|
|
19935
Description:
myBloggie contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the login.php script not properly sanitizing user-supplied input beginning with a null character to the 'username' variable. This may allow an attacker to inject or manipulate SQL queries in the back-end database.
|
2005-10-01
|
myBloggie login.php username Variable Null Character SQL Injection
|
|
19885
Description:
Lucid CMS contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the login form script not properly sanitizing user-supplied input to the 'login' field. This may allow an attacker to inject or manipulate SQL queries in the back-end database.
|
2005-09-29
|
lucidCMS Login Form login: Field SQL Injection
|
|
19718
Description:
PHP-Fusion contains a flaw that may allow a remote attacker to carry out an SQL injection attack. The issue is due to the 'messages.php' script not properly sanitizing user-supplied input to the 'msg_send' variable. This may allow a remote attacker to inject or manipulate SQL queries in the back-end database.
|
2005-09-28
|
PHP-Fusion messages.php msg_send Parameter SQL Injection
|
|
19679
Description:
Mailgust contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the password reminder page not properly sanitizing user-supplied input to the email field. This may allow an attacker to inject or manipulate SQL queries in the back-end database.
|
2005-09-24
|
Mailgust Password Reminder email Field SQL Injection
|
|
19650
Description:
My Little Forum contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the search.php script not properly sanitizing user-supplied input to the 'search' parameter. This may allow an attacker to inject or manipulate SQL queries in the back-end database.
|
2005-09-22
|
my little forum search.php search Field SQL Injection
|
|
19666
Description:
phpMyFAQ contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the password.php script not properly sanitizing user-supplied input to the user: field. This may allow an attacker to inject or manipulate SQL queries in the back-end database.
|
2005-09-22
|
phpMyFAQ password.php user Field SQL Injection
|
|
19667
Description:
phpMyFAQ contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the 'PMF_CONF[version]' variable upon submission to the footer.php script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2005-09-22
|
phpMyFAQ footer.php PMF_CONF[version] Parameter XSS
|
|
19668
Description:
phpMyFAQ contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the 'PMF_LANG[metaLanguage]' variable upon submission to the header.php script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2005-09-22
|
phpMyFAQ header.php PMF_LANG[metaLanguage] Parameter XSS
|
|
19669
Description:
phpMyFAQ contains a flaw that allows a remote attacker to access arbitrary files outside of the web path. The issue is due to the index.php script not properly sanitizing user input, specifically traversal style attacks (../../) supplied via the 'LANGCODE' variable.
|
2005-09-22
|
phpMyFAQ index.php LANGCODE Parameter Traversal Arbitrary File Access
|
|
19670
Description:
phpMyFAQ contains a flaw that may lead to an unauthorized information disclosure. The issue is triggered when a remote attacker directly requests a log file from the /data/ directory occurs, which will disclose user information and other log entries resulting in a loss of confidentiality. This attack requires the attacker to supply a file name based on the date.
|
2005-09-22
|
phpMyFAQ Remote Log Access Information Disclosure
|
|
19671
Description:
phpMyFAQ contains a flaw that may lead to an unauthorized information disclosure. The issue is triggered when a remote attacker provides an invalid file to the LANGCODE variable of index.php, which will disclose the software's installation path resulting in a loss of confidentiality. While such information is relatively low risk, it is often useful in carrying out additional, more focused attacks.
|
2005-09-22
|
phpMyFAQ index.php Malformed LANGCODE Variable Path Disclosure
|
|
19672
Description:
phpMyFAQ contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is triggered when an attacker sends a crafted User Agent field with PHP code. Once injected, subsequent commands to a script such as index.php can be called to execute arbitrary commands.
|
2005-09-22
|
phpMyFAQ User Agent Field Arbitrary PHP Code Execution
|
|
19673
Description:
phpMyFAQ contains a flaw that allows a remote attacker to execute arbitrary PHP scripts outside of the web path. The issue is due to the index.php script not properly sanitizing user input, specifically traversal style attacks (../../) supplied via the 'LANGCODE' variable. Note: Script requests must be made without a file extension, as the system will append ".php" by default.
|
2005-09-22
|
phpMyFAQ index.php LANGCODE Variable Traversal Arbitrary PHP Script Execution
|
|
19523
Description:
PHP Advanced Transfer Manager contains a flaw that allows a remote attacker to access arbitrary files outside of the web path. The issue is due to the txt.php script not properly sanitizing user input, specifically traversal style attacks (../../) supplied via the 'current_dir' variable.
|
2005-09-20
|
PHP Advanced Transfer Manager (phpATM) txt.php currentdir Parameter Traversal Arbitrary File Access
|
|
19524
Description:
PHP Advanced Transfer Manager contains a flaw that allows a remote attacker to access arbitrary files outside of the web path. The issue is due to the htm.php script not properly sanitizing user input, specifically traversal style attacks (../../) supplied via the 'current_dir' variable.
|
2005-09-20
|
PHP Advanced Transfer Manager (phpATM) htm.php current_dir Parameter Traversal Arbitrary File Access
|
|
19525
Description:
PHP Advanced Transfer Manager contains a flaw that allows a remote attacker to access arbitrary files outside of the web path. The issue is due to the html.php script not properly sanitizing user input, specifically traversal style attacks (../../) supplied via the 'current_dir' variable.
|
2005-09-20
|
PHP Advanced Transfer Manager (phpATM) html.php current_dir Parameter Traversal Arbitrary File Access
|
|
19526
Description:
PHP Advanced Transfer Manager contains a flaw that allows a remote attacker to access arbitrary zip files outside of the web path. The issue is due to the zip.php script not properly sanitizing user input, specifically traversal style attacks (../../) supplied via the 'current_dir' variable.
|
2005-09-20
|
PHP Advanced Transfer Manager (phpATM) zip.php current_dir Parameter Traversal Arbitrary File Access
|
|
19527
Description:
PHP Advanced Transfer Manager contains a flaw that may allow a malicious user to include arbitrary HTML content from remote sites. The issue is triggered when an attacker requests the htm.php script but supplies remote HTML content to the 'current_dir' variable. It is possible that the flaw may allow a remote user to manipulate site content.
|
2005-09-20
|
PHP Advanced Transfer Manager (phpATM) htm.php Remote HTML Content Inclusion
|
|
19528
Description:
PHP Advanced Transfer Manager contains a flaw that may allow a malicious user to include arbitrary HTML content from remote sites. The issue is triggered when an attacker requests the html.php script but supplies remote HTML content to the 'current_dir' variable. It is possible that the flaw may allow a remote user to manipulate site content.
|
2005-09-20
|
PHP Advanced Transfer Manager (phpATM) html.php Remote HTML Content Inclusion
|
|
19529
Description:
PHP Advanced Transfer Manager contains a flaw that may lead to an unauthorized information disclosure. The issue is triggered when an attacker directly requests a user file (/users/[name]), which will disclose the encrypted password hash for that user resulting in a loss of confidentiality.
|
2005-09-20
|
PHP Advanced Transfer Manager (phpATM) /users/ Direct Request Password Hash Disclosure
|
|
19530
Description:
PHP Advanced Transfer Manager contains a flaw that may allow a malicious authenticated user to execute arbitrary commands. The issue is triggered by uploading a file with a .inc extension, which is not blocked or sanitized by the system. After uploading, it is possible to directly call the script which will be executed under the privileges as the web server.
|
2005-09-20
|
PHP Advanced Transfer Manager (phpATM) File Upload Arbitrary Command Execution
|
|
19531
Description:
By default, PHP Advanced Transfer Manager installs with a default password. The 'admin' account has a password of 'test' which is publicly known and documented. This allows attackers to trivially access the program or system.
|
2005-09-20
|
PHP Advanced Transfer Manager (phpATM) Default Admin Account
|
|
19532
Description:
PHP Advanced Transfer Manager contains a flaw that may lead to an unauthorized information disclosure. The issue is triggered when an attacker directly requests the test.php script, which will disclose various configuration settings and system information resulting in a loss of confidentiality.
|
2005-09-20
|
PHP Advanced Transfer Manager (phpATM) test.php Remote Information Disclosure
|
|
19533
Description:
PHP Advanced Transfer Manager contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the 'font', 'normalfontcolor' or 'mess' variables upon submission to the txt.php script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2005-09-20
|
PHP Advanced Transfer Manager (phpATM) txt.php Multiple Parameter XSS
|
|
19478
Description:
CuteNews contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to the flood protection code in /inc/shows.inc.php not properly sanitizing user input supplied to the HTTP_CLIENT_IP variable. This may allow an attacker to supply a specially crafted header value and inject arbitrary strings into the /data/flood.db.php file from a remote host that contains arbitrary commands which will be executed by the vulnerable script.
|
2005-09-17
|
CuteNews flood.db.php Client-IP HTTP Header Arbitrary Code Injection
|
|
19460
Description:
Digital Scribe contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the login script not properly sanitizing user-supplied input to the 'username' variable. This may allow an attacker to inject or manipulate SQL queries in the back-end database.
|
2005-09-15
|
Digital Scribe login Field SQL Injection
|
|
19411
Description:
ATutor contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the password_reminder.php script not properly sanitizing user-supplied input to the 'email' field. This may allow an attacker to inject or manipulate SQL queries in the back-end database.
|
2005-09-14
|
ATutor password_reminder.php Email Field SQL Injection
|
|
19239
Description:
Unclassified NewsBoard contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the "Description" variable when posting a message. This could allow a user to inject arbitrary HTML and script code that would execute in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2005-09-07
|
Unclassified NewsBoard Description Field XSS
|
|
19353
Description:
phpCommunityCalendar contains a flaw that may allow a remote attacker to carry out an SQL injection attack. The issue is due to the 'login.php' script not properly sanitizing user-supplied input to the 'login' variable. This may allow a remote attacker to inject or manipulate SQL queries in the back-end database.
|
2005-09-05
|
phpCommunityCalendar login.php login Parameter SQL Injection
|
|
19354
Description:
phpCommunityCalendar contains a flaw that may allow a remote attacker to carry out an SQL injection attack. The issue is due to the 'week.php' script not properly sanitizing user-supplied input to the 'LocationID' variable. This may allow a remote attacker to inject or manipulate SQL queries in the back-end database.
|
2005-09-05
|
phpCommunityCalendar week.php LocationID Parameter SQL Injection
|
|
19356
Description:
phpCommunityCalendar contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate user-supplied input in multiple fields when adding an event. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2005-09-05
|
phpCommunityCalendar Add Event Multiple Field XSS
|
|
19357
Description:
phpCommunityCalendar contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the 'LocationID' variable upon submission to the 'thankyou.php' script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2005-09-05
|
phpCommunityCalendar thankyou.php LocationID Parameter XSS
|
|
19358
Description:
phpCommunityCalendar contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate 'font' and 'LocationID' variables upon submission to the 'day.php' script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2005-09-05
|
phpCommunityCalendar day.php Multiple Parameter XSS
|
|
19359
Description:
phpCommunityCalendar contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate 'font', 'CeTi', 'Contact', 'Description' and 'ShowAddress' variables upon submission to the 'event.php' script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2005-09-05
|
phpCommunityCalendar event.php Multiple Parameter XSS
|
|
19360
Description:
phpCommunityCalendar contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the 'font' variable upon submission to the 'week.php' script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2005-09-05
|
phpCommunityCalendar week.php font Parameter XSS
|
|
19361
Description:
phpCommunityCalendar contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the 'font' variable upon submission to the 'calDaily.php' script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2005-09-05
|
phpCommunityCalendar calDaily.php font Parameter XSS
|
|
19362
Description:
phpCommunityCalendar contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the 'font' variable upon submission to the 'calWeekly.php' script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2005-09-05
|
phpCommunityCalendar calWeekly.php font Parameter XSS
|