| OSVDB ID | Disclosure Date | Title |
|
21189
Description:
drzes HMS contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the /customers/pass_dirs.php script not properly sanitizing user-supplied input to the 'plan_id' or 'domain' variables. This may allow an attacker to inject or manipulate SQL queries in the back-end database.
|
2005-11-25
|
DRZES HMS /customers/pass_dirs.php Multiple Parameter SQL Injection
|
|
21190
Description:
drzes HMS contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the /customers/zone_files.php script not properly sanitizing user-supplied input to the 'plan_id' or 'domain' variables. This may allow an attacker to inject or manipulate SQL queries in the back-end database.
|
2005-11-25
|
DRZES HMS /customers/zone_files.php Multiple Parameter SQL Injection
|
|
21191
Description:
drzes HMS contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the /customers/htaccess.php script not properly sanitizing user-supplied input to the 'plan_id' or 'domain' variables. This may allow an attacker to inject or manipulate SQL queries in the back-end database.
|
2005-11-25
|
DRZES HMS /customers/htaccess.php Multiple Parameter SQL Injection
|
|
21192
Description:
drzes HMS contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the /customers/software.php script not properly sanitizing user-supplied input to the 'plan_id' or 'domain' variables. This may allow an attacker to inject or manipulate SQL queries in the back-end database.
|
2005-11-25
|
DRZES HMS /customers/software.php Multiple Parameter SQL Injection
|
|
21193
Description:
drzes HMS contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the 'Domain Availability' field upon submission to the /customers/register_domain.php script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2005-11-25
|
DRZES HMS /customers/register_domain.php Domain Availability Field XSS
|
|
21165
Description:
DMANews contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the index.php script not properly sanitizing user-supplied input to the 'id', 'sortorder' and 'display_num' variables. This may allow an attacker to inject or manipulate SQL queries in the back-end database.
|
2005-11-25
|
DMANews index.php Multiple Parameter SQL Injection
|
|
21163
Description:
Clientexec contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the 'index.php' script not properly sanitizing user-supplied input to the 'billshowid', 'billdetailid', 'fuse' and 'frmClientID' variables. This may allow an attacker to inject or manipulate SQL queries in the back-end database.
|
2005-11-25
|
ClientExec index.php Multiple Parameter SQL Injection
|
|
21162
Description:
Fantastic News contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the 'news.php' script not properly sanitizing user-supplied input to the 'category' variable. This may allow an attacker to inject or manipulate SQL queries in the back-end database.
|
2005-11-25
|
Fantastic News news.php category Parameter SQL Injection
|
|
48707
Description:
(Description Provided by CVE) : eFiction 1.0, 1.1, and 2.0, in unspecified environments, might allow remote attackers to conduct unauthorized operations by directly accessing (1) install.php or (2) upgrade.php. NOTE: it is unclear whether this is a vulnerability in eFiction itself or the result of incorrect system administration practices, e.g. by not removing utility scripts once they have been used.
|
2005-11-25
|
eFiction on Unspecified Environment install.php / upgrade.php Unauthorized Operations
|
|
22830
Description:
(Description Provided by CVE) : Cross-site scripting (XSS) vulnerability in the Unicode version of msearch (unicode-msearch) 1.51(U1)-beta1, 1.51(U1), and 1.52(U1) allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
|
2005-11-25
|
unicode-msearch Unspecified XSS
|
|
21313
Description:
Unknown / Incomplete
|
2005-11-25
|
Kayako SupportSuite index.php Path Disclosure
|
|
21314
Description:
SMBCMS contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the search feature not properly sanitizing user-supplied input to an unspecified variable(s). This may allow an attacker to inject or manipulate SQL queries in the back-end database.
|
2005-11-25
|
SMBCMS Search Query SQL Injection
|
|
21320
Description:
Systems Panel contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the /knowledgebase/index.php script not properly sanitizing user-supplied input to the 'cid' variable. This may allow an attacker to inject or manipulate SQL queries in the back-end database.
|
2005-11-25
|
Systems Panel /knowledgebase/index.php cid Parameter SQL Injection
|
|
21321
Description:
Systems Panel contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the /knowledgebase/view.php script not properly sanitizing user-supplied input to the 'aid' variable. This may allow an attacker to inject or manipulate SQL queries in the back-end database.
|
2005-11-25
|
Systems Panel /knowledgebase/view.php aid Parameter SQL Injection
|
|
21322
Description:
Sysbotz contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the /contact/update.php script not properly sanitizing user-supplied input to the 'cid' variable. This may allow an attacker to inject or manipulate SQL queries in the back-end database.
|
2005-11-25
|
Systems Panel /contact/update.php cid Parameter SQL Injection
|
|
21323
Description:
Systems Panel contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the /links/index.php script not properly sanitizing user-supplied input to the 'letter' variable. This may allow an attacker to inject or manipulate SQL queries in the back-end database.
|
2005-11-25
|
Systems Panel /links/index.php letter Parameter SQL Injection
|
|
21324
Description:
Systems Panel contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the /messageboard/view.php script not properly sanitizing user-supplied input to the 'mid' variable. This may allow an attacker to inject or manipulate SQL queries in the back-end database.
|
2005-11-25
|
Systems Panel /messageboard/view.php mid Parameter SQL Injection
|
|
21325
Description:
Systems Panel contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the /tickets/view.php script not properly sanitizing user-supplied input to the 'tid' variable. This may allow an attacker to inject or manipulate SQL queries in the back-end database.
|
2005-11-25
|
Systems Panel /tickets/view.php tid Parameter SQL Injection
|
|
21315
Description:
DapperDesk contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the 'news.php' script not properly sanitizing user-supplied input to the 'page' variable. This may allow an attacker to inject or manipulate SQL queries in the back-end database.
|
2005-11-25
|
DapperDesk news.php page Parameter SQL Injection
|
|
21316
Description:
cSupport contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the 'tickets.php' script not properly sanitizing user-supplied input to the 'pg' variable. This may allow an attacker to inject or manipulate SQL queries in the back-end database.
|
2005-11-25
|
cSupport tickets.php pg Parameter SQL Injection
|
|
21317
Description:
iSupport contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the 'index.php' script not properly sanitizing user-supplied input to the 'include_file' variable. This may allow an attacker to inject or manipulate SQL queries in the back-end database.
|
2005-11-25
|
iSupport index.php include_file Parameter SQL Injection
|
|
21368
Description:
LogicBill contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the 'helpdesk.php' script not properly sanitizing user-supplied input to the '__mode' and '__id' variables. This may allow an attacker to inject or manipulate SQL queries in the back-end database.
|
2005-11-25
|
LogicBill helpdesk.php Multiple Parameter SQL Injection
|
|
21369
Description:
EZI contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the 'invoices.php' script not properly sanitizing user-supplied input to the 'i' variable. This may allow an attacker to inject or manipulate SQL queries in the back-end database.
|
2005-11-25
|
EZ Invoice Inc invoices.php i Parameter SQL Injection
|
|
21370
Description:
CS-Cart contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the 'index.php' script not properly sanitizing user-supplied input to the 'sort_by' and 'sort_order' variables. This may allow an attacker to inject or manipulate SQL queries in the back-end database.
|
2005-11-25
|
CS-Cart index.php Multiple Parameter SQL Injection
|
|
24606
Description:
(Description Provided by CVE) : PHP remote file include vulnerability in functions_admin.php in Virtual War (VWar) 1.5.0 R10 allows remote attackers to include and execute arbitrary PHP code via unspecified attack vectors. NOTE: this issue has been referred to as XSS, but it is clear from the vendor description that it is a file inclusion problem.
|
2005-11-25
|
Virtual War (Vwar) functions_admin.php Remote File Inclusion
|
|
21100
Description:
(Description Provided by CVE) : PHP remote file inclusion vulnerability in support/index.php in DeskLance 2.3 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the main parameter.
|
2005-11-24
|
DeskLance index.php main Parameter Remote File Inclusion
|
|
24118
Description:
(Description Provided by CVE) : SQL injection vulnerability in DeskLance 2.3 and earlier allows remote attackers to execute arbitrary SQL commands via the announce parameter.
|
2005-11-24
|
DeskLance index.php announce Parameter SQL Injection
|
|
21096
Description:
KnowledgeBuilder contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the 'index.php' script not properly sanitizing user-supplied input to the 'article' variable. This may allow an attacker to inject or manipulate SQL queries in the back-end database.
|
2005-11-24
|
ActiveCampaign KnowledgeBuilder index.php article Parameter SQL Injection
|
|
21097
Description:
KnowledgeBuilder contains a flaw that may lead to an unauthorized information disclosure. The issue is triggered when a remote attacker passes input to the 'category' parameter in the 'index.php' script, which will disclose the software's installation path resulting in a loss of confidentiality. While such information is relatively low risk, it is often useful in carrying out additional, more focused attacks.
|
2005-11-24
|
ActiveCampaign KnowledgeBuilder index.php category Variable Path Disclosure
|
|
21098
Description:
KnowledgeBuilder contains a flaw that may allow a remote denial of service. The issue is triggered when a large amount of SQL queries are sent to the 'category' parameter in 'index.php' script, and will result in loss of availability for the service.
|
2005-11-24
|
ActiveCampaign KnowledgeBuilder index.php category Variable DoS
|
|
21094
Description:
OKBSYS Lite contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the 'q' variable upon submission to the 'search.asp' script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2005-11-24
|
OKBSYS Lite search.asp q Parameter XSS
|
|
21102
Description:
Support Center contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the search.php script not properly sanitizing user-supplied input to the "lorder", "Priority", "Status", "Category", "searchvalue", and "field" variables. This may allow an attacker to inject or manipulate SQL queries in the back-end database.
|
2005-11-24
|
IsolSoft Support Center search.php Multiple Parameter SQL Injection
|
|
21117
Description:
iDesk contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the faq.php script not properly sanitizing user-supplied input to the 'cat_id' variable. This may allow an attacker to inject or manipulate SQL queries in the back-end database.
|
2005-11-24
|
Nicecoder iDesk faq.php cat_id Parameter SQL Injection
|
|
21085
Description:
Orca Forum contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the 'forum.php' script not properly sanitizing user-supplied input to the 'msg' variable. This may allow an attacker to inject or manipulate SQL queries in the back-end database.
|
2005-11-24
|
Orca Forum forum.php msg Parameter SQL Injection
|
|
21073
Description:
A local overflow exists in SpeedCommander, Squeez, and ZipStar. The products fail to safely use the "lstrcat()" function in the "CxZIP60.dll", "CxZIP60u.dll", "CxUux60.dll", "CxUux60u.dll" modules while processing filename pathnames resulting in a stack-based overflow. With a specially crafted archive, an attacker can cause the execution of arbitrary code resulting in a loss of integrity.
|
2005-11-24
|
SpeedProject Multiple Products ZIP/UUE Archive File Pathname Overflow
|
|
21223
Description:
Unknown / Incomplete
|
2005-11-24
|
vtiger CRM Logging Function Arbitrary PHP Code Injection
|
|
21224
Description:
(Description Provided by CVE) : Multiple directory traversal vulnerabilities in index.php in vTiger CRM 4.2 and earlier allow remote attackers to read or include arbitrary files, an ultimately execute arbitrary PHP code, via .. (dot dot) and null byte ("%00") sequences in the (1) module parameter and (2) action parameter in the Leads module, as also demonstrated by injecting PHP code into log messages and accessing the log file.
|
2005-11-24
|
vtiger CRM Multiple Parameter Traversal Local File Inclusion
|
|
21225
Description:
vTiger CRM contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the 'index.php' script not properly sanitizing user-supplied input to the 'date' or 'user_name' variables. This may allow a logged-in attacker to inject or manipulate SQL queries in the back-end database.
|
2005-11-24
|
vtiger CRM HelpDesk Module index.php Multiple Parameter SQL Injection
|
|
21226
Description:
vTiger CRM contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the login script not properly sanitizing user-supplied input to the username variable. This may allow an attacker to inject or manipulate SQL queries in the back-end database.
|
2005-11-24
|
vtiger CRM Login username Field SQL Injection
|
|
21227
Description:
vTiger CRM contains a flaw that allows a remote cross site scripting attack. This flaw exists because the program does not validate RSS feeds upon submission to the RSS aggregation module script. This could allow a malicious blog or news site to create a specially crafted feed that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2005-11-24
|
vtiger CRM RSS Aggregation Module Feed XSS
|