| OSVDB ID | Disclosure Date | Title |
|
36442
Description:
Php Blue Dragon CMS contains a flaw that may allow a remote attacker to execute arbitrary commands or code. The issue is due to the 'activecontent.php' script not properly sanitizing user input supplied to the 'vsDragonRootPath' parameter. This may allow an attacker to include a file from a third-party remote host that contains commands or code that will be executed by the vulnerable script with the same privileges as the web server.
|
2007-08-10
|
Php Blue Dragon CMS activecontent.php vsDragonRootPath Parameter Remote File Inclusion
|
|
36293
Description:
(Description Provided by CVE) : SQL injection vulnerability in index.php in Simple Invoices 2007 05 25 allows remote attackers to execute arbitrary SQL commands via the submit parameter in an email action.
|
2007-06-24
|
Simple Invoices index.php email Action submit Parameter SQL Injection
|
|
36315
Description:
(Description Provided by CVE) : SQL injection vulnerability in category.php in cpCommerce 1.1.0 and earlier allows remote attackers to execute arbitrary SQL commands via the id_category parameter.
|
2007-05-24
|
cpCommerce category.php id_category Parameter SQL Injection
|
|
30144
Description:
Free File Hosting contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to login.php not properly sanitizing user input supplied to the 'AD_BODY_TEMP' variable. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script.
|
2006-10-31
|
Free File Hosting login.php AD_BODY_TEMP Parameter Remote File Inclusion
|
|
30145
Description:
Free File Hosting contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to register.php not properly sanitizing user input supplied to the 'AD_BODY_TEMP' variable. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script.
|
2006-10-31
|
Free File Hosting register.php AD_BODY_TEMP Parameter Remote File Inclusion
|
|
30146
Description:
Free File Hosting contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to send.php not properly sanitizing user input supplied to the 'AD_BODY_TEMP' variable. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script.
|
2006-10-31
|
Free File Hosting send.php AD_BODY_TEMP Parameter Remote File Inclusion
|
|
30160
Description:
Spider Friendly for phpBB contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to admin/modules_data.php not properly sanitizing user input supplied to the 'phpbb_root_path' variable. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script.
|
2006-10-30
|
Spider Friendly for phpBB admin/modules_data.php phpbb_root_path Parameter Remote File Inclusion
|
|
30127
Description:
Free Image Hosting contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to forgot_pass.php not properly sanitizing user input supplied to the 'AD_BODY_TEMP' variable. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script.
|
2006-10-28
|
Free Image Hosting forgot_pass.php AD_BODY_TEMP Parameter Remote File Inclusion
|
|
30143
Description:
Free File Hosting contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to forgot_pass.php not properly sanitizing user input supplied to the 'AD_BODY_TEMP' variable. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script.
|
2006-10-28
|
Free File Hosting forgot_pass.php AD_BODY_TEMP Parameter Remote File Inclusion
|
|
29971
Description:
MiniBB contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to bb_func_txt.php not properly sanitizing user input supplied to the 'pathToFiles' variable. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script.
|
2006-10-26
|
miniBB bb_func_txt.php pathToFiles Parameter Remote File Inclusion
|
|
29899
Description:
PH Pexplorer contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to explorer_load_lang.php not properly sanitizing user input supplied to the 'Language' cookie variable. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script.
|
2006-10-19
|
PH Pexplorer explorer_load_lang.php Language Parameter Remote File Inclusion
|
|
36290
Description:
(Description Provided by CVE) : PHP remote file inclusion vulnerability in modules/forum/include/config.php in Ciamos Content Management System (CMS) 0.9.6b and earlier allows remote attackers to execute arbitrary PHP code via a URL in the module_cache_path parameter.
|
2006-10-08
|
Ciamos CMS modules/forum/include/config.php module_cache_path Parameter Remote File Inclusion
|
|
29403
Description:
BasiliX contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to settings.php3 not properly sanitizing user input supplied to the 'BSX_LIBDIR' variable. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script.
|
2006-10-01
|
BasiliX settings.php3 BSX_LIBDIR Parameter Remote File Inclusion
|
|
31097
Description:
SolidState contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to DeleteProductPage.class.php not properly sanitizing user input supplied to the 'base_path' variable. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script.
|
2006-09-21
|
SolidState DeleteProductPage.class.php base_path Parameter Remote File Inclusion
|
|
31098
Description:
SolidState contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to DeleteServerPage.class.php not properly sanitizing user input supplied to the 'base_path' variable. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script.
|
2006-09-21
|
SolidState DeleteServerPage.class.php base_path Parameter Remote File Inclusion
|
|
31099
Description:
SolidState contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to DomainServicesPage.class.php not properly sanitizing user input supplied to the 'base_path' variable. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script.
|
2006-09-21
|
SolidState DomainServicesPage.class.php base_path Parameter Remote File Inclusion
|
|
31100
Description:
SolidState contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to DomainsPage.class.php not properly sanitizing user input supplied to the 'base_path' variable. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script.
|
2006-09-21
|
SolidState DomainsPage.class.php base_path Parameter Remote File Inclusion
|
|
31101
Description:
SolidState contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to EditProductPage.class.php not properly sanitizing user input supplied to the 'base_path' variable. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script.
|
2006-09-21
|
SolidState EditProductPage.class.php base_path Parameter Remote File Inclusion
|
|
31102
Description:
SolidState contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to EditHostingServicePage.class.php not properly sanitizing user input supplied to the 'base_path' variable. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script.
|
2006-09-21
|
SolidState EditHostingServicePage.class.php base_path Parameter Remote File Inclusion
|
|
31103
Description:
SolidState contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to EditPaymentPage.class.php not properly sanitizing user input supplied to the 'base_path' variable. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script.
|
2006-09-21
|
SolidState EditPaymentPage.class.php base_path Parameter Remote File Inclusion
|
|
31104
Description:
SolidState contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to EditAccountPage.class.php not properly sanitizing user input supplied to the 'base_path' variable. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script.
|
2006-09-21
|
SolidState EditAccountPage.class.php base_path Parameter Remote File Inclusion
|
|
31105
Description:
SolidState contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to EditDomainPage.class.php not properly sanitizing user input supplied to the 'base_path' variable. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script.
|
2006-09-21
|
SolidState EditDomainPage.class.php base_path Parameter Remote File Inclusion
|
|
31106
Description:
SolidState contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to EditDomainServicePage.class.php not properly sanitizing user input supplied to the 'base_path' variable. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script.
|
2006-09-21
|
SolidState EditDomainServicePage.class.php base_path Parameter Remote File Inclusion
|
|
31107
Description:
SolidState contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to LoginPage.class.php not properly sanitizing user input supplied to the 'base_path' variable. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script.
|
2006-09-21
|
SolidState LoginPage.class.php base_path Parameter Remote File Inclusion
|
|
31108
Description:
SolidState contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to IPManagerPage.class.php not properly sanitizing user input supplied to the 'base_path' variable. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script.
|
2006-09-21
|
SolidState IPManagerPage.class.php base_path Parameter Remote File Inclusion
|
|
31109
Description:
SolidState contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to InactiveAccountsPage.class.php not properly sanitizing user input supplied to the 'base_path' variable. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script.
|
2006-09-21
|
SolidState InactiveAccountsPage.class.php base_path Parameter Remote File Inclusion
|
|
31110
Description:
SolidState contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to GenerateInvoicesPage.class.php not properly sanitizing user input supplied to the 'base_path' variable. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script.
|
2006-09-21
|
SolidState GenerateInvoicesPage.class.php base_path Parameter Remote File Inclusion
|
|
31111
Description:
SolidState contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to HomePage.class.php not properly sanitizing user input supplied to the 'base_path' variable. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script.
|
2006-09-21
|
SolidState HomePage.class.php base_path Parameter Remote File Inclusion
|
|
31112
Description:
SolidState contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to FulfilledOrdersPage.class.php not properly sanitizing user input supplied to the 'base_path' variable. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script.
|
2006-09-21
|
SolidState FulfilledOrdersPage.class.php base_path Parameter Remote File Inclusion
|
|
31113
Description:
SolidState contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to ExpiredDomainsPage.class.php not properly sanitizing user input supplied to the 'base_path' variable. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script.
|
2006-09-21
|
SolidState ExpiredDomainsPage.class.php base_path Parameter Remote File Inclusion
|
|
31114
Description:
SolidState contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to ExecuteOrderPage.class.php not properly sanitizing user input supplied to the 'base_path' variable. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script.
|
2006-09-21
|
SolidState ExecuteOrderPage.class.php base_path Parameter Remote File Inclusion
|
|
31115
Description:
SolidState contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to EmailInvoicePage.class.php not properly sanitizing user input supplied to the 'base_path' variable. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script.
|
2006-09-21
|
SolidState EmailInvoicePage.class.php base_path Parameter Remote File Inclusion
|
|
31116
Description:
SolidState contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to EditServerPage.class.php not properly sanitizing user input supplied to the 'base_path' variable. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script.
|
2006-09-21
|
SolidState EditServerPage.class.php base_path Parameter Remote File Inclusion
|
|
31117
Description:
SolidState contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to LogPage.class.php not properly sanitizing user input supplied to the 'base_path' variable. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script.
|
2006-09-21
|
SolidState LogPage.class.php base_path Parameter Remote File Inclusion
|
|
31118
Description:
SolidState contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to ModulesPage.class.php not properly sanitizing user input supplied to the 'base_path' variable. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script.
|
2006-09-21
|
SolidState ModulesPage.class.php base_path Parameter Remote File Inclusion
|
|
31119
Description:
SolidState contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to NewAccountPage.class.php not properly sanitizing user input supplied to the 'base_path' variable. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script.
|
2006-09-21
|
SolidState NewAccountPage.class.php base_path Parameter Remote File Inclusion
|
|
31120
Description:
SolidState contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to NewDomainServicePage.class.php not properly sanitizing user input supplied to the 'base_path' variable. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script.
|
2006-09-21
|
SolidState NewDomainServicePage.class.php base_path Parameter Remote File Inclusion
|
|
31121
Description:
SolidState contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to NewProductPage.class.php not properly sanitizing user input supplied to the 'base_path' variable. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script.
|
2006-09-21
|
SolidState NewProductPage.class.php base_path Parameter Remote File Inclusion
|
|
31122
Description:
SolidState contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to OutstandingInvoicesPage.class.php not properly sanitizing user input supplied to the 'base_path' variable. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script.
|
2006-09-21
|
SolidState OutstandingInvoicesPage.class.php base_path Parameter Remote File Inclusion
|
|
31123
Description:
SolidState contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to PendingAccountsPage.class.php not properly sanitizing user input supplied to the 'base_path' variable. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script.
|
2006-09-21
|
SolidState PendingAccountsPage.class.php base_path Parameter Remote File Inclusion
|