| OSVDB ID | Disclosure Date | Title |
|
31144
Description:
SolidState contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to ViewServerPage.class.php not properly sanitizing user input supplied to the 'base_path' variable. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script.
|
2006-09-21
|
SolidState ViewServerPage.class.php base_path Parameter Remote File Inclusion
|
|
31145
Description:
SolidState contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to WelcomeEmailPage.class.php not properly sanitizing user input supplied to the 'base_path' variable. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script.
|
2006-09-21
|
SolidState WelcomeEmailPage.class.php base_path Parameter Remote File Inclusion
|
|
31146
Description:
SolidState contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to RegistrarModule.class.php not properly sanitizing user input supplied to the 'base_path' variable. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script.
|
2006-09-21
|
SolidState RegistrarModule.class.php base_path Parameter Remote File Inclusion
|
|
31147
Description:
SolidState contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to SolidStateModule.class.php not properly sanitizing user input supplied to the 'base_path' variable. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script.
|
2006-09-21
|
SolidState SolidStateModule.class.php base_path Parameter Remote File Inclusion
|
|
31148
Description:
SolidState contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to authorizeaim.class.php not properly sanitizing user input supplied to the 'base_path' variable. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script.
|
2006-09-21
|
SolidState authorizeaim.class.php base_path Parameter Remote File Inclusion
|
|
31149
Description:
SolidState contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to AAIMConfigPage.class.php not properly sanitizing user input supplied to the 'base_path' variable. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script.
|
2006-09-21
|
SolidState AAIMConfigPage.class.php base_path Parameter Remote File Inclusion
|
|
31184
Description:
SolidState contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to the AccountsPage.class.php script not properly sanitizing user input supplied to the 'base_path' variable. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script.
|
2006-09-21
|
SolidState AccountsPage.class.php base_path Parameter Remote File Inclusion
|
|
31185
Description:
SolidState contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to the AddInvoicePage.class.php script not properly sanitizing user input supplied to the 'base_path' variable. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script.
|
2006-09-21
|
SolidState AddInvoicePage.class.php base_path Parameter Remote File Inclusion
|
|
31186
Description:
SolidState contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to the AddIPAddressPage.class.php script not properly sanitizing user input supplied to the 'base_path' variable. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script.
|
2006-09-21
|
SolidState AddIPAddressPage.class.php base_path Parameter Remote File Inclusion
|
|
31187
Description:
SolidState contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to the AddPaymentPage.class.php script not properly sanitizing user input supplied to the 'base_path' variable. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script.
|
2006-09-21
|
SolidState AddPaymentPage.class.php base_path Parameter Remote File Inclusion
|
|
31188
Description:
SolidState contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to the AddTaxRulePage.class.php script not properly sanitizing user input supplied to the 'base_path' variable. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script.
|
2006-09-21
|
SolidState AddTaxRulePage.class.php base_path Parameter Remote File Inclusion
|
|
31189
Description:
SolidState contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to the AssignDomainPage.class.php script not properly sanitizing user input supplied to the 'base_path' variable. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script.
|
2006-09-21
|
SolidState AssignDomainPage.class.php base_path Parameter Remote File Inclusion
|
|
31190
Description:
SolidState contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to the AssignHostingPage.class.php script not properly sanitizing user input supplied to the 'base_path' variable. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script.
|
2006-09-21
|
SolidState AssignHostingPage.class.php base_path Parameter Remote File Inclusion
|
|
31191
Description:
SolidState contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to the AssignProductPage.class.php script not properly sanitizing user input supplied to the 'base_path' variable. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script.
|
2006-09-21
|
SolidState AssignProductPage.class.php base_path Parameter Remote File Inclusion
|
|
31192
Description:
SolidState contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to the BillingPage.class.php script not properly sanitizing user input supplied to the 'base_path' variable. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script.
|
2006-09-21
|
SolidState BillingPage.class.php base_path Parameter Remote File Inclusion
|
|
31193
Description:
SolidState contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to the BillingPaymentPage.class.php script not properly sanitizing user input supplied to the 'base_path' variable. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script.
|
2006-09-21
|
SolidState BillingPaymentPage.class.php base_path Parameter Remote File Inclusion
|
|
31194
Description:
SolidState contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to the BrowseAccountsPage.class.php script not properly sanitizing user input supplied to the 'base_path' variable. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script.
|
2006-09-21
|
SolidState BrowseAccountsPage.class.php base_path Parameter Remote File Inclusion
|
|
31195
Description:
SolidState contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to the BrowseInvoicesPage.class.php script not properly sanitizing user input supplied to the 'base_path' variable. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script.
|
2006-09-21
|
SolidState BrowseInvoicesPage.class.php base_path Parameter Remote File Inclusion
|
|
31196
Description:
SolidState contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to the ConfigureEditUserPage.class.php script not properly sanitizing user input supplied to the 'base_path' variable. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script.
|
2006-09-21
|
SolidState ConfigureEditUserPage.class.php base_path Parameter Remote File Inclusion
|
|
31197
Description:
SolidState contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to the ConfigureNewUserPage.class.php script not properly sanitizing user input supplied to the 'base_path' variable. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script.
|
2006-09-21
|
SolidState ConfigureNewUserPage.class.php base_path Parameter Remote File Inclusion
|
|
31198
Description:
SolidState contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to the ConfigureNewUserReceiptPage.class.php script not properly sanitizing user input supplied to the 'base_path' variable. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script.
|
2006-09-21
|
SolidState ConfigureNewUserReceiptPage.class.php base_path Parameter Remote File Inclusion
|
|
31199
Description:
SolidState contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to the ConfigureUsersPage.class.php script not properly sanitizing user input supplied to the 'base_path' variable. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script.
|
2006-09-21
|
SolidState ConfigureUsersPage.class.php base_path Parameter Remote File Inclusion
|
|
31200
Description:
SolidState contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to the DeleteAccountPage.class.php script not properly sanitizing user input supplied to the 'base_path' variable. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script.
|
2006-09-21
|
SolidState DeleteAccountPage.class.php base_path Parameter Remote File Inclusion
|
|
31201
Description:
SolidState contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to the DeleteDomainServicePage.class.php script not properly sanitizing user input supplied to the 'base_path' variable. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script.
|
2006-09-21
|
SolidState DeleteDomainServicePage.class.php base_path Parameter Remote File Inclusion
|
|
31202
Description:
SolidState contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to the DeleteHostingServicePage.class.php script not properly sanitizing user input supplied to the 'base_path' variable. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script.
|
2006-09-21
|
SolidState DeleteHostingServicePage.class.php base_path Parameter Remote File Inclusion
|
|
31203
Description:
SolidState contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to the DeleteInvoicePage.class.php script not properly sanitizing user input supplied to the 'base_path' variable. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script.
|
2006-09-21
|
SolidState DeleteInvoicePage.class.php base_path Parameter Remote File Inclusion
|
|
28038
Description:
SportsPHool contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to 'includes/layout/plain.footer.php' not properly sanitizing user input supplied to the 'mainnav' variable. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script.
|
2006-08-20
|
SportsPHool plain.footer.php mainnav Parameter Remote File Inclusion
|
|
28044
Description:
NES Game & NES System contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to includes.php not properly sanitizing user input supplied to the 'phphtmllib' variable. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script.
|
2006-08-20
|
NES Game & NES System includes.php phphtmllib Parameter Remote File Inclusion
|
|
28045
Description:
NES Game & NES System contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to tag_utils/divtag_utils.php not properly sanitizing user input supplied to the 'phphtmllib' variable. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script.
|
2006-08-20
|
NES Game & NES System divtag_utils.php phphtmllib Parameter Remote File Inclusion
|
|
28046
Description:
NES Game & NES System contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to tag_utils/form_utils.php not properly sanitizing user input supplied to the 'phphtmllib' variable. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script.
|
2006-08-20
|
NES Game & NES System form_utils.php phphtmllib Parameter Remote File Inclusion
|
|
28047
Description:
NES Game & NES System contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to tag_utils/html_utils.php not properly sanitizing user input supplied to the 'phphtmllib' variable. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script.
|
2006-08-20
|
NES Game & NES System html_utils.php phphtmllib Parameter Remote File Inclusion
|
|
28048
Description:
NES Game & NES System contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to tag_utils/localinc.php not properly sanitizing user input supplied to the 'phphtmllib' variable. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script.
|
2006-08-20
|
NES Game & NES System tag_utils/localinc.php phphtmllib Parameter Remote File Inclusion
|
|
28049
Description:
NES Game & NES System contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to widgets/FooterNav.php not properly sanitizing user input supplied to the 'phphtmllib' variable. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script.
|
2006-08-20
|
NES Game & NES System FooterNav.php phphtmllib Parameter Remote File Inclusion
|
|
28050
Description:
NES Game & NES System contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to HTMLPageClass.php not properly sanitizing user input supplied to the 'phphtmllib' variable. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script.
|
2006-08-20
|
NES Game & NES System HTMLPageClass.php phphtmllib Parameter Remote File Inclusion
|
|
28051
Description:
NES Game & NES System contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to widgets/InfoTable.php not properly sanitizing user input supplied to the 'phphtmllib' variable. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script.
|
2006-08-20
|
NES Game & NES System InfoTable.php phphtmllib Parameter Remote File Inclusion
|
|
28052
Description:
NES Game & NES System contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to widgets/localinc.php not properly sanitizing user input supplied to the 'phphtmllib' variable. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script.
|
2006-08-20
|
NES Game & NES System widgets/localinc.php phphtmllib Parameter Remote File Inclusion
|
|
28053
Description:
NES Game & NES System contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to NavTable.php not properly sanitizing user input supplied to the 'phphtmllib' variable. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script.
|
2006-08-20
|
NES Game & NES System NavTable.php phphtmllib Parameter Remote File Inclusion
|
|
28054
Description:
NES Game & NES System contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to TextNav.php not properly sanitizing user input supplied to the 'phphtmllib' variable. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script.
|
2006-08-20
|
NES Game & NES System TextNav.php phphtmllib Parameter Remote File Inclusion
|
|
28282
Description:
Shadows Rising RPG contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to '/core/includes/smarty.inc.php', '/qcms/includes/smarty.inc.php' and '/qlib/smarty.inc.php' scripts not properly sanitizing user input supplied to the 'CONFIG[gameroot]' variable. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script.
|
2006-08-20
|
Shadows Rising RPG smarty.inc.php CONFIG[gameroot] Parameter Remote File Inclusion
|
|
28283
Description:
Shadows Rising contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to '/core/includes/security.inc.php' not properly sanitizing user input supplied to the 'CONFIG[gameroot]' variable. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script.
|
2006-08-20
|
Shadows Rising RPG security.inc.php CONFIG[gameroot] Parameter Remote File Inclusion
|