| OSVDB ID | Disclosure Date | Title |
|
7243
Description:
php-exec-dir contains a flaw that may allow a malicious user to bypass restrictions and execute commands. The issue is triggered when a user places a ";" before the command they wish to execute. It is possible that the flaw may allow remote command execution resulting in a loss of confidentiality, integrity, and/or availability.
|
2004-06-24
|
php-exec-dir Command Execution Bypass
|
|
7268
Description:
Lotus Domino contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not properly validate input upon submission to an unmentioned script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2004-06-24
|
IBM Lotus Domino Unspecified XSS
|
|
7251
Description:
PHP Gift Registry contains a flaw related to the approval feature in the shop.php script. This may allow an attacker to 'shop' and manipulate data without approval. No further details have been provided.
|
2004-06-24
|
PHP Gift Registry shop.php Unspecified Shopping Authentication
|
|
7248
Description:
BT Voyager 2000 Wireless ADSL Router contains a flaw that may lead to an unauthorized information disclosure. The issue is triggered when a remote attacker grabs the SNMP strings from the router using a default public/private community name, which will disclose the account password in plaintext resulting in a loss of confidentiality.
|
2004-06-24
|
BT Voyager 2000 Router Cleartext Password SNMP Disclosure
|
|
7266
Description:
giFT-FastTrack contains a flaw that may allow a remote denial of service. The issue is triggered when a NULL pointer involving HTTP header parsing gets dereferenced, and will result in loss of availability for the service.
|
2004-06-24
|
giFT-FastTrack HTTP Header Parsing DoS
|
|
7429
Description:
Acrobat Reader contains a flaw related to malformed uuencoded PDF files that may allow an attacker to crash the application. No further details have been provided.
|
2004-06-23
|
Adobe Acrobat Reader Unspecified Malformed UUencoded PDF File
|
|
7239
Description:
rssh contains a flaw that may lead to an unauthorized information disclosure. The issue is triggered when path expansion occurs before entering the chroot jail, which will disclose file existence information resulting in a loss of confidentiality.
|
2004-06-23
|
rssh File Existence Information Disclosure
|
|
23724
Description:
(Description Provided by CVE) : Buffer overflow in the PostScript file interpreter code for Xerox CopyCentre and Xerox WorkCentre Pro, running software 1.001.02.073 or earlier, or 1.001.02.074 before 1.001.02.715, allows attackers to cause a denial of service via unknown vectors.
|
2004-06-23
|
XEROX CopyCentre/WorkCentre PostScript File Interpreter Overflow Remote DoS
|
|
7237
Description:
A remote overflow exists in ISC DHCP server. The DHCP server fails to check the boundary length from a DHCP request with multiple hostname query options set. The logging function uses a temporary 1024 byte buffer for storage and this can result in a buffer overflow. With a specially crafted DHCP request, an attacker can cause supplied code to execute resulting in a loss of integrity.
|
2004-06-23
|
ISC DHCP Daemon Hostname Logging Remote Overflow
|
|
7222
Description:
cplay contains a flaw that may allow a malicious user to gain access to unauthorized privileges. The issue is triggered when the "/var/tmp/cplay_control" temporary file is opened for reading and writing without verifying if it exists first. This flaw may lead to a loss of integrity.
|
2004-06-23
|
cplay Symlink Arbitrary File Overwrite
|
|
7267
Description:
(Description Provided by CVE) : Argument injection vulnerability in IBM Lotus Notes 6.0.3 and 6.5 allows remote attackers to execute arbitrary code via a notes: URI that uses a UNC network share pathname to provide an alternate notes.ini configuration file to notes.exe.
|
2004-06-23
|
IBM Lotus Notes URI Handler Argument Injection
|
|
7223
Description:
PHP-Nuke contains a flaw that may lead to an unauthorized information disclosure. The issue is triggered when a remote attacker requests an invalid parameter of the voteinclude.php file in the Web Links module, which will disclose the physical path of the web server resulting in a loss of confidentiality.
|
2004-06-23
|
PHP-Nuke Web_Links Module voteinclude.php Path Disclosure
|
|
7224
Description:
PHP-Nuke contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the "jid" variable upon submission to the "delete.php" script in the Journal module. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2004-06-23
|
PHP-Nuke Journal Module delete.php jid Parameter XSS
|
|
7225
Description:
PHP-Nuke contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the "onwhat" variable upon submission to the "comment.php" script in the Journal module. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2004-06-23
|
PHP-Nuke Journal Module comment.php onwhat Parameter XSS
|
|
7226
Description:
PHP-Nuke contains a flaw that may lead to an unauthorized information disclosure. The issue is triggered when a remote attacker requests an invalid parameter of the convert_month() function of the Statistics module, which will disclose the physical path of the web server resulting in a loss of confidentiality.
|
2004-06-23
|
PHP-Nuke Statistics Module convert_month() Function Path Disclosure
|
|
7227
Description:
PHP-Nuke contains a flaw that may lead to an unauthorized information disclosure. The issue is triggered when a remote attacker requests an invalid parameter of the add.php file in the Journal module, which will disclose the physical path of the web server resulting in a loss of confidentiality.
|
2004-06-23
|
PHP-Nuke Journal Module add.php Path Disclosure
|
|
7228
Description:
PHP-Nuke contains a flaw that may lead to an unauthorized information disclosure. The issue is triggered when a remote attacker requests an invalid parameter of the modify.php file in the Journal module, which will disclose the physical path of the web server resulting in a loss of confidentiality.
|
2004-06-23
|
PHP-Nuke Journal Module modify.php Path Disclosure
|
|
7229
Description:
PHP-Nuke contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the "yun" or "ye" variables upon submission to the "friend.php" script in the Journal module. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2004-06-23
|
PHP-Nuke Journal Module friend.php Multiple Parameter XSS
|
|
7230
Description:
PHP-Nuke contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the "filelist" variable upon submission to the "add.php" script in the Journal module. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2004-06-23
|
PHP-Nuke Journal Module add.php filelist Parameter XSS
|
|
7231
Description:
PHP-Nuke contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the "filelist" variable upon submission to the "modify.php" script in the Journal module. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2004-06-23
|
PHP-Nuke Journal Module modify.php filelist Parameter XSS
|
|
7232
Description:
PHP-Nuke contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the "rid" variable upon submission to the "commentsave.php" script in the Journal module. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2004-06-23
|
PHP-Nuke Journal Module commentsave.php rid Parameter XSS
|
|
7233
Description:
PHP-Nuke contains a flaw that will allow an attacker to inject arbitrary SQL code. The problem is that the "forwhat" variable in the Journal module search.php script is not verified properly and will allow an attacker to inject or manipulate SQL queries.
|
2004-06-23
|
PHP-Nuke Journal Module search.php SQL Injection
|
|
7234
Description:
PHP-Nuke contains a flaw that may allow a remote attacker to inject arbitrary javascript in a journal entry. The flaw is due to the Journal module not properly sanitize journal entry input. By creating a new journal entry with malicious java script, an attacker can have it executed under arbitrary privileges when another user attempts to list or read the journal entry.
|
2004-06-23
|
PHP-Nuke Journal Module Java Script Injection
|
|
7235
Description:
PHP-Nuke contains a flaw that may allow a remote attacker to delete arbitrary journal entries. The flaw is due to the Journal module not properly checking for authentication credentials during a request to the commentkill.php script. If an attacker directly requests the script via a GET request, he can delete any journal entry.
|
2004-06-23
|
PHP-Nuke Journal Module commentkill.php Arbitrary Comment Deletion
|
|
7236
Description:
PHP-Nuke contains a flaw that may allow a remote attacker to insert arbitrary journal entries. The flaw is due to the Journal module not properly checking for authentication credentials during a request to the savenew.php script. If an attacker directly requests the script via a GET request, he can insert a new journal entry without authenticating.
|
2004-06-23
|
PHP-Nuke Journal Module savenew.php Arbitrary Entry Insertion
|
|
16007
Description:
FreeBSD contains a flaw that may allow a local denial of service. The issue is triggered when a malicious user specially crafts an execve() system call with an unaligned memory address as the second or third argument, causing the kernel to crash resulting in loss of availability for the platform.
|
2004-06-23
|
FreeBSD for Alpha Malformed execve System Call Local DoS
|
|
60297
Description:
(Description Provided by CVE) : gzexe in gzip 1.3.3 and earlier will execute an argument when the creation of a temp file fails instead of exiting the program, which could allow remote attackers or local users to execute arbitrary commands, a different vulnerability than CVE-1999-1332.
|
2004-06-23
|
gzip gzexe Temp File Failure Argument Handling Arbitrary Command Execution
|
|
7253
Description:
A local overflow exists in Linux kernel. The IEEE1394 kernel driver fails to perform bounds checking on a user data structure when being copied to a kernel buffer. This flaw in the alloc_hpsb_packet() function results in a buffer overflow. With a specially crafted request, an attacker can cause DOS and possible code execution resulting in a loss of availability.
|
2004-06-22
|
Linux Kernel IEEE 1394 (Firewire) Driver Integer Overflow DoS
|
|
9166
Description:
Unknown / Incomplete
|
2004-06-22
|
ignitionServer SERVER Command Spoofed Server Saturation DoS
|
|
7238
Description:
A remote overflow exists in ISC DHCP 3.0.1. The DHCP server uses the vsprintf()call instead of the vsnprintf()function resulting in a buffer overflow. With a specially crafted DHCP request, an attacker can cause supplied code to execute resulting in a loss of integrity.
|
2004-06-22
|
ISC DHCP Daemon vsnprintf Function Multiple Overflows
|
|
7241
Description:
The e1000 driver in linux Kernel versions 2.4 through 2.4.26 does not properly reset memory or restrict the maximum length of a data structure, which can allow a local user to read portions of kernel memory and potentially corrupt user memory space. This may disclose sensitive information or cause a loss of availability for the system.
|
2004-06-22
|
Linux Kernel e1000 Driver Memory Disclosure
|
|
7250
Description:
gnubiff contains a flaw related to the tables used for password encryption that may allow an attacker to gain access to passwords. No further details have been provided.
|
2004-06-22
|
gnubiff Unspecified Password Table Weakness
|
|
7215
Description:
nCipher netHSM contains a flaw that may lead to an unauthorized password exposure. It is possible to gain access to plaintext passwords when pass phrases entered by means of the nCipher netHSM front panel, either using the built in thumbwheel or using a directly attached keyboard, are stored in the netHSM system log, which may lead to a loss of confidentiality.
|
2004-06-22
|
nCipher netHSM Logfile Pass Phrase Disclosure
|
|
7240
Description:
Sun Microsystems Solaris contains a flaw that may allow a local denial of service. The issue is triggered when its Basic Security Module (BSM) has been configured to audit the Administrative audit class "ad" or the System-Wide Administration audit class "as", and will result in loss of availability for the platform.
|
2004-06-22
|
Solaris Basic Security Module (BSM) Local DoS
|
|
14799
Description:
(Description Provided by CVE) : Cross-site scripting (XSS) vulnerability in ArbitroWeb 0.6 allows remote attackers to inject arbitrary script or HTML via the rawURL parameter.
|
2004-06-22
|
ArbitroWeb rawurl Parameter XSS
|
|
15691
Description:
(Description Provided by CVE) : osTicket trusts a hidden form field in the submit form to limit the upload size of a document, which could allow remote attackers to upload a file of any size.
|
2004-06-21
|
osTicket Form Field Modification File Upload Size Restriction Bypass
|
|
15692
Description:
(Description Provided by CVE) : osTicket allows remote attackers to view sensitive uploaded files and possibly execute arbitrary code via an HTTP request that uploads a PHP file to the ticket attachments directory.
|
2004-06-21
|
osTicket Attachment Handling File Upload Arbitrary Code Execution
|
|
15693
Description:
(Description Provided by CVE) : osTicket allows remote attackers to view sensitive uploaded files and possibly execute arbitrary code via an HTTP request that uploads a PHP file to the ticket attachments directory.
|
2004-06-21
|
osTicket Arbitrary Attachment Disclosure
|
|
11682
Description:
Unknown / Incomplete
|
2004-06-21
|
Roxen Web Server Show Internal Errors Port Bind Arbitrary File Access
|
|
7192
Description:
A local overflow exists in WWW-SQL. The WWW-SQL parser fails to check the length of the file include command resulting in a stack overflow. With a specially crafted request, an attacker can cause arbitrary code execution resulting in a loss of integrity.
|
2004-06-21
|
WWW-SQL File Include Overflow
|