| OSVDB ID | Disclosure Date | Title |
|
54106
Description:
Unknown / Incomplete
|
2006-11-21
|
CuteNews rss.php rss_title Parameter XSS
|
|
31982
Description:
Unknown / Incomplete
|
2006-11-21
|
Grandora /admin/default.asp Multiple Parameter SQL Injection
|
|
31983
Description:
Unknown / Incomplete
|
2006-11-21
|
Grandora listfull.asp ID Parameter SQL Injection
|
|
31984
Description:
Unknown / Incomplete
|
2006-11-21
|
Grandora listmain.asp cat Parameter SQL Injection
|
|
31985
Description:
Unknown / Incomplete
|
2006-11-21
|
Grandora printmain.asp ID Parameter SQL Injection
|
|
31986
Description:
Unknown / Incomplete
|
2006-11-21
|
Grandora searchmain.asp Multiple Parameter SQL Injection
|
|
31987
Description:
Unknown / Incomplete
|
2006-11-21
|
Grandora searchkey.asp Multiple Parameter SQL Injection
|
|
31988
Description:
Unknown / Incomplete
|
2006-11-21
|
Grandora searchoption.asp Multiple Parameter SQL Injection
|
|
31989
Description:
Unknown / Incomplete
|
2006-11-21
|
Grandora listmain.asp cat Parameter XSS
|
|
31990
Description:
Unknown / Incomplete
|
2006-11-21
|
Grandora searchkey.asp Keyword Parameter XSS
|
|
31991
Description:
Unknown / Incomplete
|
2006-11-21
|
Grandora searchmain.asp cat Parameter XSS
|
|
31992
Description:
Unknown / Incomplete
|
2006-11-21
|
Grandora forminfo.asp refno Parameter XSS
|
|
31953
Description:
(Description Provided by CVE) : SQL injection vulnerability in system/core/profile/profile.inc.php in Neocrome Land Down Under (LDU) 8.x and earlier allows remote authenticated users to execute arbitrary SQL commands via a url-encoded id parameter to users.php that begins with a valid filename, as demonstrated by "default.gif" followed by a double-encoded NULL and ' (apostrophe) (%2500%2527).
|
2006-11-21
|
Land Down Under (LDU) users.php id Parameter SQL Injection
|
|
33212
Description:
osCommerce contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate 'gID' variable upon submission to the 'configuration.php' script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2006-11-21
|
osCommerce admin/configuration.php gID Parameter XSS
|
|
33213
Description:
osCommerce contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate 'set' and 'module' variables upon submission to the 'modules.php' script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2006-11-21
|
osCommerce admin/modules.php Multiple Parameter XSS
|
|
33214
Description:
osCommerce contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate 'option_order_by' , 'option_page' and 'value_page' variables upon submission to the 'products_attributes.php' script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2006-11-21
|
osCommerce admin/products_attributes.php Multiple Parameter XSS
|
|
33216
Description:
osCommerce contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate 'lID' variable upon submission to the 'languages.php' script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2006-11-21
|
osCommerce admin/languages.php lID Parameter XSS
|
|
33217
Description:
osCommerce contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate 'cID' and 'selected_box' variables upon submission to the 'customers.php' script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2006-11-21
|
osCommerce admin/customers.php Multiple Parameter XSS
|
|
33218
Description:
osCommerce contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the 'spage', 'zID' and 'sID' variables upon submission to the 'geo_zones.php' script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2006-11-21
|
osCommerce admin/geo_zones.php Multiple Parameter XSS
|
|
30641
Description:
(Description Provided by CVE) : The (1) Password Manager in Mozilla Firefox 2.0, and 1.5.0.8 and earlier; and the (2) Passcard Manager in Netscape 8.1.2 and possibly other versions, do not properly verify that an ACTION URL in a FORM element containing a password INPUT element matches the web site for which the user stored a password, which allows remote attackers to obtain passwords via a password INPUT element on a different web page located on the web site intended for this password.
|
2006-11-21
|
Netscape Navigator Password Manager Crafted Form Cross-Site Password Disclosure
|
|
30658
Description:
CuteNews contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the 'mod', 'image', 'area', and 'source' variables upon submission to the index.php script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2006-11-21
|
CuteNews index.php Multiple Parameter XSS
|
|
30659
Description:
CuteNews contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate variables upon submission to the search.php script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2006-11-21
|
CuteNews search.php XSS
|
|
30657
Description:
(Description Provided by CVE) : SQL injection vulnerability in system/core/users/users.profile.inc.php in Neocrome Seditio 1.10 and earlier allows remote authenticated users to execute arbitrary SQL commands via a double-url-encoded id parameter to users.php that begins with a valid filename, as demonstrated by "default.gif" followed by an encoded NULL and ' (apostrophe) (%2500%2527).
|
2006-11-21
|
Seditio users.php id Parameter SQL Injection
|
|
31712
Description:
(Description Provided by CVE) : SQL injection vulnerability in polls.php in Neocrome Seditio 1.10 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.
|
2006-11-21
|
Seditio polls.php id Parameter SQL Injection
|
|
30656
Description:
(Description Provided by CVE) : SQL injection vulnerability in index.php in ContentNow 1.39 and earlier allows remote attackers to execute arbitrary SQL commands via the pageid parameter. NOTE: this issue can be leveraged for path disclosure with an invalid pageid parameter.
|
2006-11-21
|
ContentNow index.php pageid Parameter SQL Injection
|
|
30655
Description:
(Description Provided by CVE) : Cross-site scripting (XSS) vulnerability in Grim Pirate GrimBB before 2006_11_21 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
|
2006-11-21
|
GrimBB Unspecified XSS
|
|
30564
Description:
(Description Provided by CVE) : My Firewall Plus 5.0 Build 1119 does not verify if explorer.exe is running before launching iexplore.exe from the "Test Your Firewall" feature, which allows local users to gain SYSTEM privileges.
|
2006-11-21
|
My Firewall Plus Application Window Local Privilege Escalation
|
|
30721
Description:
(Description Provided by CVE) : GNU tar 1.16 and 1.15.1, and possibly other versions, allows user-assisted attackers to overwrite arbitrary files via a tar file that contains a GNUTYPE_NAMES record with a symbolic link, which is not properly handled by the extract_archive function in extract.c and extract_mangle function in mangle.c, a variant of CVE-2002-1216.
|
2006-11-21
|
GNU tar GNUTYPES_NAMES Record Type Traversal Arbitrary File Overwrite
|
|
30652
Description:
(Description Provided by CVE) : SQL injection vulnerability in search.asp in CreaScripts Creadirectory allows remote attackers to execute arbitrary SQL commands via the category parameter.
|
2006-11-21
|
CreaDirectory search.asp category Parameter SQL Injection
|
|
30653
Description:
(Description Provided by CVE) : Multiple cross-site scripting (XSS) vulnerabilities in CreaScripts Creadirectory allow remote attackers to inject arbitrary web script or HTML via the (1) cat parameter to addlisting.asp or the (2) search parameter to search.asp.
|
2006-11-21
|
CreaDirectory addlisting.asp cat Parameter XSS
|
|
30654
Description:
(Description Provided by CVE) : Multiple cross-site scripting (XSS) vulnerabilities in CreaScripts Creadirectory allow remote attackers to inject arbitrary web script or HTML via the (1) cat parameter to addlisting.asp or the (2) search parameter to search.asp.
|
2006-11-21
|
CreaDirectory search.asp search Parameter XSS
|
|
30651
Description:
(Description Provided by CVE) : PHP remote file inclusion vulnerability in src/ark_inc.php in e-Ark 1.0 allows remote attackers to execute arbitrary PHP code via a URL in the cfg_pear_path parameter.
|
2006-11-21
|
e-Ark ark_inc.php cfg_pear_path Parameter Remote File Inclusion
|
|
30650
Description:
(Description Provided by CVE) : Multiple PHP remote file inclusion vulnerabilities in adminprint.php in PicturesPro Photo Cart 3.9 allow remote attackers to execute arbitrary PHP code via a URL in the (1) admin_folder and (2) path parameters.
|
2006-11-21
|
Photo Cart adminprint.php Multiple Parameter Remote File Inclusion
|
|
30560
Description:
(Description Provided by CVE) : Multiple buffer overflows in the Message Parsing Interpreter (MPI) in Fuzzball MUCK before 6.07 allow remote attackers to execute arbitrary code via crafted messages.
|
2006-11-21
|
Fuzzball MUCK MPI Overflow
|
|
30510
Description:
Mac OS X contains a flaw that may allow a local denial of service. The issue is triggered when mounting a corrupt UDTO HFS+ disk image file, and will result in loss of availability for the platform.
|
2006-11-21
|
Apple Mac OS X UDTO HFS+ Image Handling DoS
|
|
30647
Description:
(Description Provided by CVE) : Multiple SQL injection vulnerabilities in JiRos Links Manager allow remote attackers to execute arbitrary SQL commands via the (1) LinkID parameter to openlink.asp or the (2) CategoryID parameter to viewlinks.asp.
|
2006-11-21
|
JiRos Link Manager openlink.asp LinkID Parameter SQL Injection
|
|
30648
Description:
(Description Provided by CVE) : Multiple SQL injection vulnerabilities in JiRos Links Manager allow remote attackers to execute arbitrary SQL commands via the (1) LinkID parameter to openlink.asp or the (2) CategoryID parameter to viewlinks.asp.
|
2006-11-21
|
JiRos Link Manager viewlinks.asp CategoryID Parameter SQL Injection
|
|
30649
Description:
(Description Provided by CVE) : Multiple cross-site scripting (XSS) vulnerabilities in submitlink.asp in JiRos Links Manager allow remote attackers to inject arbitrary web script or HTML via the (1) lName, (2) lURL, (3) lImage, and (4) lDescription parameters. NOTE: some of these details are obtained from third party information.
|
2006-11-21
|
JiRos Link Manager submitlink.asp Multiple Field XSS
|
|
79165
Description:
(Description Provided by CVE) : The (1) Password Manager in Mozilla Firefox 2.0, and 1.5.0.8 and earlier; and the (2) Passcard Manager in Netscape 8.1.2 and possibly other versions, do not properly verify that an ACTION URL in a FORM element containing a password INPUT element matches the web site for which the user stored a password, which allows remote attackers to obtain passwords via a password INPUT element on a different web page located on the web site intended for this password.
|
2006-11-21
|
Mozilla Firefox Password Manager Crafted Form Cross-Site Password Disclosure
|
|
30637
Description:
A remote overflow exists in BrightStor ARCserve Backup Tape Engine. The BrightStor ARCserve Backup Tape Engine uses insufficient bounds checking resulting in a stack overflow. With a specially crafted request, an attacker can cause arbitrary code execution resulting in a loss of integrity.
|
2006-11-21
|
CA BrightStor ARCserve Backup Tape Engine (tapeeng.exe) RPC Overflow
|