| OSVDB ID | Disclosure Date | Title |
|
28562
Description:
Unknown / Incomplete
|
2005-05-31
|
MySource Unspecified Restricted Page Authentication Bypass
|
|
16977
Description:
(Description Provided by CVE) : Symantec Brightmail AntiSpam before 6.0.2 has a hard-coded database administrator password, which allows remote attackers to gain privileges.
|
2005-05-31
|
Symantec Brightmail AntiSpam Hardcoded Database Password
|
|
45596
Description:
(Description Provided by CVE) : The admin interface in eZ publish 3.5 before 3.5.7, 3.6 before 3.6.5, 3.7 before 3.7.3, and 3.8 before 20051110 does not properly handle authorization errors, which allows remote attackers to obtain sensitive information and see the admin pagelayout and associated templates via a request with (1) "anything after the url" or (2) a "wrong url".
|
2005-05-31
|
eZ publish Administrator Interface Information Disclosure
|
|
17094
Description:
Internet Explorer contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue occurs when the browser does not properly handle requests to the window() object. A remote attacker could create a malicious website that uses an onload event to initialize a window() object, which may cause Internet Explorer to crash or execute arbitrary code with the privileges of the person running it.
|
2005-05-31
|
Microsoft IE window() Function Arbitrary Code Execution
|
|
16954
Description:
A remote overflow exists in TFTP Server 2000. The application fails to perform proper bounds checking resulting in a buffer overflow. With a specially crafted request containing an overly long filename or transfer-mode string, a remote attacker can cause arbitrary code execution resulting in a loss of integrity.
|
2005-05-31
|
FutureSoft TFTP Server 2000 Multiple Remote Overflows
|
|
16955
Description:
(Description Provided by CVE) : Directory traversal vulnerability in FutureSoft TFTP Server Evaluation Version 1.0.0.1 allows remote attackers to read arbitrary files via a TFTP GET request containing (1) "../" (dot dot slash) or (2) "..\" (dot dot backslash) sequences.
|
2005-05-31
|
FutureSoft TFTP Server 2000 GET Traversal Arbitrary File Access
|
|
17008
Description:
MyBulletinBoard (MyBB) contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate user-supplied input to multiple variables upon submission to the misc.php script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2005-05-31
|
MyBulletinBoard (MyBB) misc.php Multiple Parameter XSS
|
|
17009
Description:
MyBulletinBoard (MyBB) contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the 'datecut' or 'page' variables upon submission to the forumdisplay.php script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2005-05-31
|
MyBulletinBoard (MyBB) forumdisplay.php Multiple Parameter XSS
|
|
17010
Description:
MyBulletinBoard (MyBB) contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the 'username', 'email' or 'email2' variables upon submission to the member.php script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2005-05-31
|
MyBulletinBoard (MyBB) member.php Multiple Parameter XSS
|
|
17011
Description:
MyBulletinBoard (MyBB) contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the 'page' or 'usersearch' variables upon submission to the memberlist.php script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2005-05-31
|
MyBulletinBoard (MyBB) memberlist.php Multiple Parameter XSS
|
|
17012
Description:
MyBulletinBoard (MyBB) contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the 'pid' or 'tid' variables upon submission to the showthread.php script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2005-05-31
|
MyBulletinBoard (MyBB) showthread.php Multiple Parameter XSS
|
|
17013
Description:
MyBulletinBoard (MyBB) contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the 'tid' variable upon submission to the printthread.php script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2005-05-31
|
MyBulletinBoard (MyBB) printthread.php tid Parameter XSS
|
|
17014
Description:
MyBulletinBoard (MyBB) contains a flaw that may allow an attacker to inject arbitrary SQL queries. The issue is due to the 'eid' variable in the calendar.php script not being properly sanitized and may allow an attacker to inject or manipulate SQL queries.
|
2005-05-31
|
MyBulletinBoard (MyBB) calendar.php eid Parameter SQL Injection
|
|
17015
Description:
MyBulletinBoard (MyBB) contains a flaw that may allow an attacker to inject arbitrary SQL queries. The issue is due to the 'pidsql' variable in the online.php script not being properly sanitized and may allow an attacker to inject or manipulate SQL queries.
|
2005-05-31
|
MyBulletinBoard (MyBB) online.php pidsql Parameter SQL Injection
|
|
17016
Description:
MyBulletinBoard (MyBB) contains a flaw that may allow an attacker to inject arbitrary SQL queries. The issue is due to the 'usersearch' variable in the memberlist.php script not being properly sanitized and may allow an attacker to inject or manipulate SQL queries.
|
2005-05-31
|
MyBulletinBoard (MyBB) memberlist.php usersearch Parameter SQL Injection
|
|
17017
Description:
MyBulletinBoard (MyBB) contains a flaw that may allow an attacker to inject arbitrary SQL queries. The issue is due to the 'pid' variable in the editpost.php script not being properly sanitized and may allow an attacker to inject or manipulate SQL queries.
|
2005-05-31
|
MyBulletinBoard (MyBB) editpost.php pid Parameter SQL Injection
|
|
17018
Description:
MyBulletinBoard (MyBB) contains a flaw that may allow an attacker to inject arbitrary SQL queries. The issue is due to the 'fid' variable in the forumdisplay.php script not being properly sanitized and may allow an attacker to inject or manipulate SQL queries.
|
2005-05-31
|
MyBulletinBoard (MyBB) forumdisplay.php fid Parameter SQL Injection
|
|
17019
Description:
MyBulletinBoard (MyBB) contains a flaw that may allow an attacker to inject arbitrary SQL queries. The issue is due to the 'tid' variable in the newreply.php script not being properly sanitized and may allow an attacker to inject or manipulate SQL queries.
|
2005-05-31
|
MyBulletinBoard (MyBB) newreply.php tid Parameter SQL Injection
|
|
17020
Description:
MyBulletinBoard (MyBB) contains a flaw that may allow an attacker to inject arbitrary SQL queries. The issue is due to the 'sid' variable in the search.php script not being properly sanitized and may allow an attacker to inject or manipulate SQL queries.
|
2005-05-31
|
MyBulletinBoard (MyBB) search.php sid Parameter SQL Injection
|
|
17021
Description:
MyBulletinBoard (MyBB) contains a flaw that may allow an attacker to inject arbitrary SQL queries. The issue is due to the 'tid' and 'pid' variables in the showthread.php script not being properly sanitized and may allow an attacker to inject or manipulate SQL queries.
|
2005-05-31
|
MyBulletinBoard (MyBB) showthread.php Multiple Parameter SQL Injection
|
|
17022
Description:
MyBulletinBoard (MyBB) contains a flaw that may allow an attacker to inject arbitrary SQL queries. The issue is due to the 'tid' variable in the usercp2.php script not being properly sanitized and may allow an attacker to inject or manipulate SQL queries.
|
2005-05-31
|
MyBulletinBoard (MyBB) usercp2.php tid Parameter SQL Injection
|
|
17023
Description:
MyBulletinBoard (MyBB) contains a flaw that may allow an attacker to inject arbitrary SQL queries. The issue is due to the 'tid' variable in the printthread.php script not being properly sanitized and may allow an attacker to inject or manipulate SQL queries.
|
2005-05-31
|
MyBulletinBoard (MyBB) printthread.php tid Parameter SQL Injection
|
|
17024
Description:
MyBulletinBoard (MyBB) contains a flaw that may allow an attacker to inject arbitrary SQL queries. The issue is due to the 'pid' variable in the reputation.php script not being properly sanitized and may allow an attacker to inject or manipulate SQL queries.
|
2005-05-31
|
MyBulletinBoard (MyBB) reputation.php pid Parameter SQL Injection
|
|
17025
Description:
MyBulletinBoard (MyBB) contains a flaw that may allow an attacker to inject arbitrary SQL queries. The issue is due to the 'username' variable in the portal.php script not being properly sanitized and may allow an attacker to inject or manipulate SQL queries.
|
2005-05-31
|
MyBulletinBoard (MyBB) portal.php username Parameter SQL Injection
|
|
17026
Description:
MyBulletinBoard (MyBB) contains a flaw that may allow an attacker to inject arbitrary SQL queries. The issue is due to the 'tid' variable in the polls.php script not being properly sanitized and may allow an attacker to inject or manipulate SQL queries.
|
2005-05-31
|
MyBulletinBoard (MyBB) polls.php tid Parameter SQL Injection
|
|
17027
Description:
MyBulletinBoard (MyBB) contains a flaw that may allow an attacker to inject arbitrary SQL queries. The issue is due to the 'tid' variable in the ratethread.php script not being properly sanitized and may allow an attacker to inject or manipulate SQL queries.
|
2005-05-31
|
MyBulletinBoard (MyBB) ratethread.php tid Parameter SQL Injection
|
|
16953
Description:
(Description Provided by CVE) : Hosting Controller 6.1 HotFix 2.0 and earlier allows remote attackers to steal passwords and gain privileges via a modified emailaddress parameter in an updateprofile action for UserProfile.asp.
|
2005-05-31
|
Hosting Controller UserProfile.asp Authentication Bypass
|
|
16968
Description:
(Description Provided by CVE) : I-Man 0.9, and possibly earlier versions, allows remote attackers to execute arbitrary PHP code by uploading a file attachment with a .php extension.
|
2005-05-31
|
I-Man Upload File Attachment Issue
|
|
22838
Description:
(Description Provided by CVE) : The send_pinentry_environment function in asshelp.c in gpg2 on SUSE Linux 9.3 does not properly handle certain options, which can prevent pinentry from being found and causes S/MIME signing to fail.
|
2005-05-31
|
gpg2 on SuSE Linux asshelp.c send_pinentry_environment Function S/MIME Signature Failure
|
|
16992
Description:
Unknown / Incomplete
|
2005-05-30
|
Yahoo! Messenger Launchcast Skip Song Restriction Bypass
|
|
16913
Description:
NewLife Blogger contains a flaw that may allow an attacker to inject arbitrary SQL queries. The issue is due to an unspecified variable not being properly sanitized and may allow an attacker to inject or manipulate SQL queries.
|
2005-05-30
|
NewLife Blogger Unspecified SQL Injection
|
|
16933
Description:
StrongHold 2 contains a flaw that may allow a remote denial of service. The issue is triggered when an attacker sends a specially crafted Nickname which is padded with a large number of bytes to the server. The STLport Library on the server fails to properly allocate memory, and will result in loss of availability for the application.
|
2005-05-30
|
Stronghold 2 Malformed Nickname Join DoS
|
|
16936
Description:
X-Cart Gold contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the 'cat' or 'printable' variables upon submission to the home.php script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2005-05-30
|
X-Cart Gold home.php Multiple Parameter XSS
|
|
16937
Description:
X-Cart Gold contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the 'productid' or 'mode' variables upon submission to the product.php script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2005-05-30
|
X-Cart Gold product.php Multiple Parameter XSS
|
|
16938
Description:
X-Cart Gold contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the 'id' variable upon submission to the error_message.php script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2005-05-30
|
X-Cart Gold error_message.php id Parameter XSS
|
|
16939
Description:
X-Cart Gold contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the 'section' variable upon submission to the help.php script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2005-05-30
|
X-Cart Gold help.php section Parameter XSS
|
|
16940
Description:
X-Cart Gold contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the 'mode' variable upon submission to the orders.php script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2005-05-30
|
X-Cart Gold orders.php mode Parameter XSS
|
|
16941
Description:
X-Cart Gold contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the 'mode' variable upon submission to the register.php script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2005-05-30
|
X-Cart Gold register.php mode Parameter XSS
|
|
16942
Description:
X-Cart Gold contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the 'mode' variable upon submission to the search.php script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2005-05-30
|
X-Cart Gold search.php mode Parameter XSS
|
|
16943
Description:
X-Cart Gold contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the 'gcid' or 'gcindex' variables upon submission to the giftcert.php script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2005-05-30
|
X-Cart Gold giftcert.php Multiple Parameter XSS
|