| OSVDB ID | Disclosure Date | Title |
|
26277
Description:
KAPhotoservice contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the 'New Category' field and the 'apage' variable upon submission to the edtalbum.asp script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2006-06-09
|
KAPhotoservice edtalbum.asp Multiple Parameter XSS
|
|
26416
Description:
(Description Provided by CVE) : Multiple cross-site scripting (XSS) vulnerabilities in ClickGallery 5.0 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) gallery_id parameter in gallery.asp and (2) parentcurrentpage parameter in view_gallery.asp.
|
2006-06-09
|
ClickGallery gallery.asp gallery_id Parameter XSS
|
|
26417
Description:
(Description Provided by CVE) : Multiple cross-site scripting (XSS) vulnerabilities in ClickGallery 5.0 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) gallery_id parameter in gallery.asp and (2) parentcurrentpage parameter in view_gallery.asp.
|
2006-06-09
|
ClickGallery view_gallery.asp parentcurrentpage Parameter XSS
|
|
26411
Description:
(Description Provided by CVE) : Multiple cross-site scripting (XSS) vulnerabilities in BlueCollar i-Gallery 4.1 PLUS and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) n and (2) d parameters in (a) login.asp and the d parameter in (b) igallery.asp.
|
2006-06-09
|
i-Gallery login.asp Multiple Parameter XSS
|
|
26412
Description:
(Description Provided by CVE) : Multiple cross-site scripting (XSS) vulnerabilities in BlueCollar i-Gallery 4.1 PLUS and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) n and (2) d parameters in (a) login.asp and the d parameter in (b) igallery.asp.
|
2006-06-09
|
i-Gallery igallery.asp d Parameter XSS
|
|
26365
Description:
ePhotos contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the subphotos.asp script not properly sanitizing user-supplied input to the 'CAT_ID' variable. This may allow an attacker to inject or manipulate SQL queries in the back-end database.
|
2006-06-09
|
ePhotos subphotos.asp CAT_ID Parameter SQL Injection
|
|
26366
Description:
ePhotos contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the photos.asp script not properly sanitizing user-supplied input to the 'AL_ID' variable. This may allow an attacker to inject or manipulate SQL queries in the back-end database.
|
2006-06-09
|
ePhotos photo.asp AL_ID Parameter SQL Injection
|
|
26367
Description:
ePhotos contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the subLevel2.asp script not properly sanitizing user-supplied input to the "CAT_ID" and "SUB_ID" variables. This may allow an attacker to inject or manipulate SQL queries in the back-end database.
|
2006-06-09
|
ePhotos subLevel2.asp Multiple Parameter SQL Injection
|
|
26198
Description:
Open Business Management (OBM) contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the 'tf_lang' variable upon submission to the publication_index.php script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2006-06-06
|
Open Business Management (OBM) publication_index.php tf_lang Parameter XSS
|
|
26199
Description:
Open Business Management (OBM) contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the 'tf_name' or 'tf_user' variables upon submission to the group_index.php script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2006-06-06
|
Open Business Management (OBM) group_index.php Multiple Parameter XSS
|
|
26200
Description:
Open Business Management (OBM) contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the 'tf_lastname' variable upon submission to the user_index.php script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2006-06-06
|
Open Business Management (OBM) user_index.php tf_lastname Parameter XSS
|
|
26201
Description:
Open Business Management (OBM) contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the 'tf_name' or 'tf_contact' variables upon submission to the list_index.php script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2006-06-06
|
Open Business Management (OBM) list_index.php Multiple Parameter XSS
|
|
26202
Description:
Open Business Management (OBM) contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the 'tf_datebefore' or 'tf_dateafter' variables upon submission to the company_index.php script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2006-06-06
|
Open Business Management (OBM) company_index.php Multiple Parameter XSS
|
|
26203
Description:
Open Business Management (OBM) contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the an unspecified script (likely index.php) not properly sanitizing user-supplied input to the 'new_order' variable. This may allow an attacker to inject or manipulate SQL queries in the back-end database.
|
2006-06-06
|
Open Business Management (OBM) index.php new_order Parameter SQL Injection
|
|
26204
Description:
Open Business Management (OBM) contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the group_index.php script not properly sanitizing user-supplied input to the 'new_order', 'tf_user' and 'order_dir' variables. This may allow an attacker to inject or manipulate SQL queries in the back-end database.
|
2006-06-06
|
Open Business Management (OBM) group_index.php Multiple Parameter SQL Injection
|
|
26205
Description:
Open Business Management (OBM) contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the user_index.php script not properly sanitizing user-supplied input to the 'order_dir' variable. This may allow an attacker to inject or manipulate SQL queries in the back-end database.
|
2006-06-06
|
Open Business Management (OBM) user_index.php order_dir Parameter SQL Injection
|
|
26206
Description:
Open Business Management (OBM) contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the list_index.php script not properly sanitizing user-supplied input to the 'order_dir' and 'new_order' variables. This may allow an attacker to inject or manipulate SQL queries in the back-end database.
|
2006-06-06
|
Open Business Management (OBM) list_index.php Multiple Parameter SQL Injection
|
|
26207
Description:
Open Business Management (OBM) contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the company_index.php script not properly sanitizing user-supplied input to the 'entity', 'order_dir', 'new_order' and 'tf_dateafter' variables. This may allow an attacker to inject or manipulate SQL queries in the back-end database.
|
2006-06-06
|
Open Business Management (OBM) company_index.php Multiple Parameter SQL Injection
|
|
26179
Description:
KnowledgeTree Open Source contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the 'fDocumentId' variable upon submission to the view.php script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2006-06-06
|
KnowledgeTree Open Source view.php fDocumentId Parameter XSS
|
|
26180
Description:
KnowledgeTree Open Source contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the 'fSearchableText' variable upon submission to the search/simpleSearch.php script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2006-06-06
|
KnowledgeTree Open Source search/simpleSearch.php fSearchableText Parameter XSS
|
|
26297
Description:
KnowledgeTree Open Source contains a flaw that may lead to an unauthorized information disclosure. The issue is triggered when a remote attacker provides a crafted 'fDocumentId' variable to the view.php script, which will disclose the software's installation path resulting in a loss of confidentiality. While such information is relatively low risk, it is often useful in carrying out additional, more focused attacks.
|
2006-06-06
|
KnowledgeTree Open Source view.php fDocumentId Variable Path Disclosure
|
|
25976
Description:
Particle Wiki contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the index.php script not properly sanitizing user-supplied input to the 'version' variable. This may allow an attacker to inject or manipulate SQL queries in the back-end database.
|
2006-06-05
|
Particle Wiki index.php version Parameter SQL Injection
|
|
25953
Description:
Particle gallery contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the viewimage.php script not properly sanitizing user-supplied input to the imageid variable. This may allow an attacker to inject or manipulate SQL queries in the back-end database.
|
2006-06-05
|
Particle Gallery viewimage.php imageid Parameter SQL Injection
|
|
25963
Description:
LabWiki contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate 'help' variable upon submission to the recentchanges.php script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2006-06-05
|
LabWiki recentchanges.php help Parameter XSS
|
|
26009
Description:
(Description Provided by CVE) : Multiple cross-site scripting (XSS) vulnerabilities in EVA-Web 2.1.2 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) debut_image parameter in (a) article-album.php3, (2) date parameter in (b) rubrique.php3, and the (3) perso and (4) aide parameters to (c) an unknown script, probably index.php.
|
2006-05-27
|
EVA-Web article-album.php3 debut_image Parameter XSS
|
|
26010
Description:
(Description Provided by CVE) : Multiple cross-site scripting (XSS) vulnerabilities in EVA-Web 2.1.2 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) debut_image parameter in (a) article-album.php3, (2) date parameter in (b) rubrique.php3, and the (3) perso and (4) aide parameters to (c) an unknown script, probably index.php.
|
2006-05-27
|
EVA-Web rubrique.php3 date Parameter XSS
|
|
26011
Description:
(Description Provided by CVE) : Multiple cross-site scripting (XSS) vulnerabilities in EVA-Web 2.1.2 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) debut_image parameter in (a) article-album.php3, (2) date parameter in (b) rubrique.php3, and the (3) perso and (4) aide parameters to (c) an unknown script, probably index.php.
|
2006-05-27
|
EVA-Web index.php Multiple Parameter XSS
|
|
26012
Description:
(Description Provided by CVE) : An unspecified script in EVA-Web 2.1.2 and earlier, probably index.php, allows remote attackers to obtain the full path of the web server via invalid (1) perso or (2) aide parameters.
|
2006-05-27
|
EVA-Web index.php Multiple Variable Path Disclosure
|
|
25504
Description:
FlexChat contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the 'username' and 'CFTOKEN' variables upon submission to the index.cfm script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2006-05-13
|
FlexChat index.cfm Multiple Parameter XSS
|
|
25505
Description:
FlexChat contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the "CFTOKEN" and "CFID" variables upon submission to the chat.cfm script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2006-05-13
|
FlexChat chat.cfm Multiple Parameter XSS
|
|
25307
Description:
Creative Community Portal contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the ArticleView.php script not properly sanitizing user-supplied input to the 'article_id' variable. This may allow an attacker to inject or manipulate SQL queries in the back-end database.
|
2006-05-08
|
Creative Community Portal ArticleView.php article_id Parameter SQL Injection
|
|
25308
Description:
Creative Community Portal contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the DiscView.php script not properly sanitizing user-supplied input to the 'forum_id' variable. This may allow an attacker to inject or manipulate SQL queries in the back-end database.
|
2006-05-08
|
Creative Community Portal DiscView.php forum_id Parameter SQL Injection
|
|
25309
Description:
Creative Community Portal contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the Discussion.php script not properly sanitizing user-supplied input to the 'forum_id' variable. This may allow an attacker to inject or manipulate SQL queries in the back-end database.
|
2006-05-08
|
Creative Community Portal Discussions.php forum_id Parameter SQL Injection
|
|
25310
Description:
Creative Community Portal contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the EventView.php script not properly sanitizing user-supplied input to the 'event_id' variable. This may allow an attacker to inject or manipulate SQL queries in the back-end database.
|
2006-05-08
|
Creative Community Portal EventView.php event_id Parameter SQL Injection
|
|
25311
Description:
Creative Community Portal contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the PollResults.php script not properly sanitizing user-supplied input to the 'AddVote' or 'answer_id' variables. This may allow an attacker to inject or manipulate SQL queries in the back-end database.
|
2006-05-08
|
Creative Community Portal PollResults.php Multiple Parameter SQL Injection
|
|
25312
Description:
Creative Community Portal contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the DiscReply.php script not properly sanitizing user-supplied input to the 'mid' variable. This may allow an attacker to inject or manipulate SQL queries in the back-end database.
|
2006-05-08
|
Creative Community Portal DiscReply.php mid Parameter SQL Injection
|
|
25239
Description:
Albinator contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to the 'eday.php' not properly sanitizing user input supplied to the 'Config_rootdir' variable. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script.
|
2006-05-03
|
Albinator eday.php Config_rootdir Parameter Remote File Inclusion
|
|
25240
Description:
Albinator contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to the 'eshow.php' script not properly sanitizing user input supplied to the 'Config_rootdir' variable. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script.
|
2006-05-03
|
Albinator eshow.php Config_rootdir Parameter Remote File Inclusion
|
|
25241
Description:
Albinator contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to the 'forgot.php' script not properly sanitizing user input supplied to the 'Config_rootdir' variable. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script.
|
2006-05-03
|
Albinator forgot.php Config_rootdir Parameter Remote File Inclusion
|
|
25242
Description:
Albinator contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the 'cid' variable upon submission to the 'dlisting.php' script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2006-05-03
|
Albinator dlisting.php cid Parameter XSS
|