| OSVDB ID | Disclosure Date | Title |
|
18634
Description:
Gravity Board X contains a flaw that may lead to an unauthorized information disclosure. The issue is triggered when a remote attacker makes a direct request to the 'adminforum.php' script, which will disclose the software's installation path resulting in a loss of confidentiality. While such information is relatively low risk, it is often useful in carrying out additional, more focused attacks.
|
2005-08-07
|
Gravity Board X adminform.php Direct Request Path Disclosure
|
|
18635
Description:
Gravity Board X contains a flaw that may lead to an unauthorized information disclosure. The issue is triggered when a remote attacker makes direct requests to multiple scripts in the 'forms' directory, which will disclose the software's installation path resulting in a loss of confidentiality. While such information is relatively low risk, it is often useful in carrying out additional, more focused attacks.
|
2005-08-07
|
Gravity Board X /forms/ Directory Multiple Script Path Disclosure
|
|
18549
Description:
FlatNuke contains a flaw that may lead to an unauthorized information disclosure. The issue is triggered when a remote attacker makes a direct request to the 'structure.php' script, which will disclose the software's installation path resulting in a loss of confidentiality. While such information is relatively low risk, it is often useful in carrying out additional, more focused attacks.
|
2005-08-04
|
FlatNuke structure.php Direct Request Path Disclosure
|
|
18550
Description:
FlatNuke contains a flaw that may lead to an unauthorized information disclosure. The issue is triggered when a remote attacker provides malformed input to the 'mod' variable in the 'index.php' script, which will disclose the software's installation path resulting in a loss of confidentiality. While such information is relatively low risk, it is often useful in carrying out additional, more focused attacks.
|
2005-08-04
|
FlatNuke index.php mod Variable Path Disclosure
|
|
18551
Description:
FlatNuke contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate 'bodycolor', 'backimage', 'theme' and 'logo' variables upon submission to the 'structure.php' script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2005-08-04
|
FlatNuke structure.php Multiple Parameter XSS
|
|
18552
Description:
FlatNuke contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate 'admin', 'admin_mail' and 'back' variables upon submission to the 'footer.php' script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2005-08-04
|
FlatNuke footer.php Multiple Parameter XSS
|
|
18553
Description:
FlatNuke contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the content of news items upon submission to a moderator. This could allow a user to create a specially crafted new item that would execute arbitrary code in a moderator's browser within the trust relationship between the browser and the server, possibly allowing an attacker to steal authentication cookies or other information of a privileged account, leading to a loss of integrity.
|
2005-08-04
|
FlatNuke News Submission Body XSS
|
|
18554
Description:
Flatnuke contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to the program not properly sanitizing user input supplied to the user registration function. This may allow an attacker to include an arbitrary command in the user registration file [username].php which can be executed by the attacker.
|
2005-08-04
|
FlatNuke User Signature Arbitrary Command Execution
|
|
18517
Description:
SilverNews contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the "login.php" script not properly sanitizing user-supplied input to the username field. This may allow an attacker to inject or manipulate SQL queries in the back-end database.
|
2005-08-03
|
SilverNews login.php username Field SQL Injection
|
|
18524
Description:
web content management contains a flaw that may allow a malicious user to gain access to unauthorized privileges. The issue is triggered when a regular user accesses AddModifyInput.php and is granted permission to create a privileged administrator account.
|
2005-07-29
|
web content management AddModifyInput.php Remote Privilege Escalation
|
|
18451
Description:
PHPFreeNews contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the 'ScriptVersion' variable upon submission to the Footer.php script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2005-07-29
|
PHPFreeNews Footer.php ScriptVersion Parameter XSS
|
|
18452
Description:
PHPFreeNews contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the 'NewsDir', 'PopupWidth', or 'PopupHeight' variables upon submission to the ScriptFunctions.php script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2005-07-29
|
PHPFreeNews ScriptFunctions.php Multiple Parameter XSS
|
|
18453
Description:
PHPFreeNews contains a flaw that may allow a remote attacker to trick a user into visiting an arbitrary site under the apparent trust of a legitimate site. The issue is due to the Logout.php script providing a site redirect to an arbitrary web site. This may give an attacker a way to trick a user into clicking what appears to be a legitimate URL of a valid site, but really leads them to an arbitrary site with malicious content.
|
2005-07-29
|
PHPFreeNews Logout.php Arbitrary Site Redirect
|
|
18454
Description:
PHPFreeNews contains a flaw that may lead to an unauthorized information disclosure. The issue is triggered when a remote attacker directly requests any number of scripts in the /inc/ directory, which will disclose the software's installation path resulting in a loss of confidentiality. While such information is relatively low risk, it is often useful in carrying out additional, more focused attacks.
|
2005-07-29
|
PHPFreeNews /inc/ Multiple Script Direct Request Path Disclosure
|
|
18455
Description:
PHPFreeNews contains a flaw that may lead to an unauthorized information disclosure. The issue is triggered when an attacker visits the admin.php script, which will disclose the PHP and MySQL versions resulting in a loss of confidentiality. While such information is relatively low risk, it is often useful in carrying out additional, more focused attacks.
|
2005-07-29
|
PHPFreeNews admin.php Information Disclosure
|
|
18456
Description:
By default, PHPFreeNews installs with a default password. The 'Admin' account has a password of 'Admin' which is publicly known and documented. This allows attackers to trivially access the program or system.
|
2005-07-29
|
PHPFreeNews Default Admin Account Password
|
|
18457
Description:
PHPFreeNews contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the Login routine not properly sanitizing user-supplied input to the 'password' field. This may allow an attacker to inject or manipulate SQL queries in the back-end database.
|
2005-07-29
|
PHPFreeNews Login password Field SQL Injection
|
|
18277
Description:
Netquery contains a flaw that may lead to an unauthorized information disclosure. The issue is that the nqlog.txt file is publicly available, which will disclose user activity information resulting in a loss of confidentiality.
|
2005-07-25
|
Netquery nq_log.txt User Activity Remote Disclosure
|
|
18278
Description:
Netquery contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the 'portnum' variable upon submission to the 'submit.php' script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2005-07-25
|
Netquery submit.php portnum Parameter XSS
|
|
18279
Description:
Netquery contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the 'step' and 'body' variables upon submission to the 'nqgeoip2.php' script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2005-07-25
|
Netquery nqgeoip2.php Multiple Parameter XSS
|
|
18280
Description:
Netquery contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the 'step' variable upon submission to the 'nqgeoip.php' script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2005-07-25
|
Netquery nqgeoip.php step Parameter XSS
|
|
18281
Description:
Netquery contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the 'step' variable upon submission to the 'nqports.php' script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2005-07-25
|
Netquery nqports.php step Parameter XSS
|
|
18282
Description:
Netquery contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the 'step' and 'body' variables upon submission to the 'nqports2.php' script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2005-07-25
|
Netquery nqports2.php Multiple Parameter XSS
|
|
18283
Description:
Netquery contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the 'portnum' variable upon submission to the 'portlist.php' script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2005-07-25
|
Netquery portlist.php portnum Parameter XSS
|
|
18486
Description:
FlexPHPNews contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate 'front_indextitle', 'front_searchsubmit', and 'front_latestnews' variables upon submission to the 'index.php' script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2005-07-24
|
FlexPHPNews index.php Multiple Parameter XSS
|
|
18487
Description:
FlexPHPNews contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate 'newsid', 'front_rating', 'salt', 'front_letmerateit', 'front_ratebest', 'front_ratesubmit', and 'front_searchsubmit' variables upon submission to the 'news.php' script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2005-07-24
|
FlexPHPNews news.php Multiple Parameter XSS
|
|
18488
Description:
FlexPHPNews contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate 'front_searchresult' and 'front_searchsubmit' variables upon submission to the 'search.php' script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2005-07-24
|
FlexPHPNews search.php Multiple Parameter XSS
|
|
18489
Description:
FlexPHPNews contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate 'front_searchsubmit', 'front_latestnews' and 'catalogid' variables upon submission to the 'catalog.php' script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2005-07-24
|
FlexPHPNews catalog.php Multiple Parameter XSS
|
|
18490
Description:
FlexPHPNews contains a flaw that may lead to an unauthorized information disclosure. The issue is triggered when a remote attacker provides malformed input to the 'logincheck' variable in the 'usercheck.php' script, which will disclose the software's installation path resulting in a loss of confidentiality. While such information is relatively low risk, it is often useful in carrying out additional, more focused attacks.
|
2005-07-24
|
FlexPHPNews usercheck.php logincheck Variable Path Disclosure
|
|
18491
Description:
FlexPHPNews contains a flaw that may allow a remote denial of service. The issue is triggered when a remote attacker provides an overly long value to the 'prenumber' and/or 'nextnumber' variables in the 'news.php' script, which causes the application to consume all available CPU resources resulting in a loss of availability.
|
2005-07-24
|
FlexPHPNews news.php Large Value DoS
|
|
18492
Description:
FlexPHPNews contains a flaw that may allow a remote attacker to carry out an SQL injection attack. The issue is due to the 'usercheck.php' script not properly sanitizing user-supplied input to the 'username' and 'password' fields. This may allow a remote attacker to inject or manipulate SQL queries in the back-end database.
|
2005-07-24
|
FlexPHPNews usercheck.php Admin Login Multiple Field SQL Injection
|
|
18295
Description:
phpBook contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the 'admin' variable upon submission to the 'guestbook.php' script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2005-07-22
|
phpBook guestbook.php admin Parameter XSS
|
|
18142
Description:
PHPSiteSearch contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the 'query' variable upon submission to the search.php script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2005-07-21
|
PHPSiteSearch search.php query Parameter XSS
|
|
18143
Description:
Ultimate PHP Board (UPB) Gold contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the 'css' variable upon submission to the send.php script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2005-07-21
|
Ultimate PHP Board (UPB) send.php css Parameter XSS
|
|
18144
Description:
Ultimate PHP Board (UPB) Gold contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the 'css' variable upon submission to the users.php script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2005-07-21
|
Ultimate PHP Board (UPB) users.php css Parameter XSS
|
|
18145
Description:
Ultimate PHP Board (UPB) Gold contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the 'css' variable upon submission to the top.php script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2005-07-21
|
Ultimate PHP Board (UPB) top.php css Parameter XSS
|
|
18146
Description:
Ultimate PHP Board (UPB) Gold contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the 'css' variable upon submission to the main.php script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2005-07-21
|
Ultimate PHP Board (UPB) main.php css Parameter XSS
|
|
18147
Description:
Ultimate PHP Board (UPB) Gold contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the 'title' variable upon submission to the header.php script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2005-07-21
|
Ultimate PHP Board (UPB) header.php title Parameter XSS
|
|
18227
Description:
Asn Guestbook contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the 'version' variable upon submission to the 'header.php' script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2005-07-20
|
Asn Guestbook header.php version Parameter XSS
|
|
18228
Description:
Asn Guestbook contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the 'version' variable upon submission to the 'footer.php' script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2005-07-20
|
Asn Guestbook footer.php version Parameter XSS
|