| OSVDB ID | Disclosure Date | Title |
|
32541
Description:
(Description Provided by CVE) : Multiple PHP remote file inclusion vulnerabilities in process.php in Vladimir Menshakov buratinable templator (aka bubla) 1.0.0rc2 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the (1) bu_dir or (2) bu_config[dir] parameter.
|
2006-12-27
|
bubla (buratinable templator) process.php Multiple Parameter Remote File Inclusion
|
|
33330
Description:
(Description Provided by CVE) : Multiple cross-site scripting (XSS) vulnerabilities in DMXReady Secure Login Manager 1.0 allow remote authenticated administrators to inject arbitrary web script or HTML via unspecified parameters to (1) set_preferences.asp, (2) send_password_preferences.asp, and (3) SecureLoginManager/list.asp in the Local-Admin Panel.
|
2006-12-27
|
Secure Login Manager set_preferences.asp XSS
|
|
33331
Description:
(Description Provided by CVE) : Multiple cross-site scripting (XSS) vulnerabilities in DMXReady Secure Login Manager 1.0 allow remote authenticated administrators to inject arbitrary web script or HTML via unspecified parameters to (1) set_preferences.asp, (2) send_password_preferences.asp, and (3) SecureLoginManager/list.asp in the Local-Admin Panel.
|
2006-12-27
|
Secure Login Manager send_password_preferences.asp XSS
|
|
33332
Description:
(Description Provided by CVE) : Multiple cross-site scripting (XSS) vulnerabilities in DMXReady Secure Login Manager 1.0 allow remote authenticated administrators to inject arbitrary web script or HTML via unspecified parameters to (1) set_preferences.asp, (2) send_password_preferences.asp, and (3) SecureLoginManager/list.asp in the Local-Admin Panel.
|
2006-12-27
|
Secure Login Manager SecureLoginManager/list.asp XSS
|
|
33333
Description:
Secure Login Manager contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the set_preferences.asp script not properly sanitizing user-supplied input to an unknown variable. This may allow an attacker to inject or manipulate SQL queries in the back-end database.
|
2006-12-27
|
Secure Login Manager set_preferences.asp SQL Injection
|
|
33334
Description:
Secure Login Manager contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the send_password_preferences.asp script not properly sanitizing user-supplied input to an unspecified variable. This may allow an attacker to inject or manipulate SQL queries in the back-end database.
|
2006-12-27
|
Secure Login Manager send_password_preferences.asp SQL Injection
|
|
33335
Description:
Secure Login Manager contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the SecureLoginManager/list.asp script not properly sanitizing user-supplied input to an unspecified variable. This may allow an attacker to inject or manipulate SQL queries in the back-end database.
|
2006-12-27
|
Secure Login Manager SecureLoginManager/list.asp SQL Injection
|
|
33336
Description:
Secure Login Manager contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the login.asp script not properly sanitizing user-supplied input to the 'sent' variable. This may allow an attacker to inject or manipulate SQL queries in the back-end database.
|
2006-12-27
|
Secure Login Manager login.asp sent Parameter SQL Injection
|
|
33337
Description:
Secure Login Manager contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the content.asp script not properly sanitizing user-supplied input to the 'sent' variable. This may allow an attacker to inject or manipulate SQL queries in the back-end database.
|
2006-12-27
|
Secure Login Manager content.asp sent Parameter SQL Injection
|
|
33338
Description:
Secure Login Manager contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the members.asp script not properly sanitizing user-supplied input to the 'sent' variable. This may allow an attacker to inject or manipulate SQL queries in the back-end database.
|
2006-12-27
|
Secure Login Manager members.asp sent Parameter SQL Injection
|
|
33339
Description:
(Description Provided by CVE) : Multiple SQL injection vulnerabilities in DMXReady Secure Login Manager 1.0 allow remote attackers to execute arbitrary SQL commands via unspecified parameters to (1) set_preferences.asp, (2) send_password_preferences.asp, and (3) SecureLoginManager/list.asp in the Local-Admin Panel; (4) the sent parameter to (a) login.asp, (b) content.asp, and (c) members.asp in the Remote-WebSite; and (5) the sent parameter to applications/SecureLoginManager/inc_secureloginmanager.asp in the Live Demo.
|
2006-12-27
|
Secure Login Manager applications/SecureLoginManager/inc_secureloginmanager.asp sent Parameter SQL Injection
|
|
31519
Description:
(Description Provided by CVE) : AlstraSoft Web Host Directory allows remote attackers to obtain sensitive information by requesting any invalid URI, which reveals the path in an error message, a different vulnerability than CVE-2006-2617.
|
2006-12-27
|
AlstraSoft Web Host Directory Invalid URI Path Disclosure
|
|
31520
Description:
(Description Provided by CVE) : AlstraSoft Web Host Directory allows remote attackers to bypass authentication and change the admin password via a direct request to admin/config.
|
2006-12-27
|
AlstraSoft Web Host Directory Admin Passwod Modification
|
|
31521
Description:
(Description Provided by CVE) : AlstraSoft Web Host Directory stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a backup database via a direct request for admin/backup/db.
|
2006-12-27
|
AlstraSoft Web Host Directory Database Download
|
|
31578
Description:
WordPress contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the 'file' variable upon submission to the 'templates.php' script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2006-12-27
|
WordPress templates.php file Parameter XSS
|
|
35713
Description:
(Description Provided by CVE) : PHP remote file inclusion vulnerability in plugins/metasearch/plug.inc.php in Yrch! 1.0 allows remote attackers to execute arbitrary PHP code via a URL in the path parameter.
|
2006-12-27
|
Yrch plug.inc.php path Parameter Remote File Inclusion
|
|
33326
Description:
(Description Provided by CVE) : Multiple PHP remote file inclusion vulnerabilities in LuckyBot 3 allow remote attackers to execute arbitrary PHP code via a URL in the dir parameter to (1) run.php or (2) ircbot.class.php.
|
2006-12-26
|
LuckyBot Multiple Script dir Parameter Remote File Inclusion
|
|
34756
Description:
(Description Provided by CVE) : PHP remote file inclusion vulnerability in the BE IT EasyPartner 0.0.9 beta component for Joomla! allows remote attackers to execute arbitrary PHP code via unspecified vectors. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.
|
2006-12-26
|
EasyPartner for Joomla! Multiple Unspecified Remote File Inclusion
|
|
36176
Description:
(Description Provided by CVE) : Direct static code injection vulnerability in chat/login.php in Ultimate PHP Board (UPB) 2.0b1 and earlier allows remote attackers to inject arbitrary PHP code via the username parameter, which is injected into chat/text.php.
|
2006-12-26
|
Ultimate PHP Board (UPB) chat/login.php username Variable Arbitrary Code Injection
|
|
36649
Description:
(Description Provided by CVE) : Efkan Forum 1.0 and earlier store sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for forum.mdb. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.
|
2006-12-26
|
Efkan Forum forum.mdb Direct Request Information Disclosure
|
|
30893
Description:
(Description Provided by CVE) : ** DISPUTED ** PHP remote file inclusion vulnerability in lib/php/phphtmllib-2.5.4/examples/example6.php for maintain 3.0.0-RC2 allows remote attackers to execute arbitrary PHP code via a URL in the phphtmllib parameter. NOTE: this issue might be in phpHtmlLib. NOTE: CVE disputes this issue for proper installations of maintain, since $phphtmllib is set in includes.inc before being used in example6.php.
|
2006-12-26
|
phpHtmlLib example6.php phphtmllib Parameter Remote File Inclusion
|
|
30964
Description:
Unknown / Incomplete
|
2006-12-26
|
Parabuild Security Subsystem Unspecified Issue
|
|
32504
Description:
(Description Provided by CVE) : Unrestricted file upload vulnerability in admin/uploads.php in PHP-Update 2.7 and earlier allows remote authenticated users to upload arbitrary PHP scripts to the gfx/ and files/ directories via the userfile parameter.
|
2006-12-26
|
PHP-Update admin/uploads.php Unrestricted File Upload
|
|
32505
Description:
(Description Provided by CVE) : Multiple SQL injection vulnerabilities in code/guestadd.php in PHP-Update 2.7 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) newmessage, (2) newname, (3) newwebsite, or (4) newemail parameter.
|
2006-12-26
|
PHP-Update code/guestadd.php Multiple Parameter SQL Injection
|
|
31587
Description:
(Description Provided by CVE) : Multiple PHP file inclusion vulnerabilities in src/admin/pt_upload.php in Pagetool 1.07 allow remote attackers to execute arbitrary PHP code via (1) a local filename or FTP/share URI in the config_file parameter or (2) a URL in the ptconf[src] parameter.
|
2006-12-26
|
Pagetool pt_upload.php ptconf[src] Remote File Inclusion
|
|
32453
Description:
(Description Provided by CVE) : Cross-site scripting (XSS) vulnerability in pnamazu 2006.02.28 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
|
2006-12-26
|
pnamazu Unspecified XSS
|
|
31515
Description:
(Description Provided by CVE) : myprofile.asp in Enthrallweb eCoupons does not properly validate the MM_recordId parameter during profile updates, which allows remote authenticated users to modify certain profile fields of another account by specifying that account's username in a modified MM_recordId parameter.
|
2006-12-26
|
Enthrallweb eCoupons myprofile.asp MM_recordId Account Modification
|
|
32442
Description:
KISGB contains a flaw that may allow a remote attacker to execute arbitrary commands or code. The issue is due to the 'admin.php' script not properly sanitizing user input supplied to the 'default_path_for_themes' parameter. This may allow an attacker to include a file from a third-party remote host that contains commands or code that will be executed by the vulnerable script with the same privileges as the web server.
|
2006-12-26
|
KISGB admin.php default_path_for_themes Parameter Remote File Inclusion
|
|
32443
Description:
KISGB contains a flaw that may allow a remote attacker to execute arbitrary commands or code. The issue is due to the 'upconfig.php' script not properly sanitizing user input supplied to the 'default_path_for_themes' parameter. This may allow an attacker to include a file from a third-party remote host that contains commands or code that will be executed by the vulnerable script with the same privileges as the web server.
|
2006-12-26
|
KISGB upconfig.php default_path_for_themes Parameter Remote File Inclusion
|
|
32550
Description:
(Description Provided by CVE) : Directory traversal vulnerability in FolderManager/FolderManager.aspx in Hosting Controller 7c allows remote authenticated users to read and modify arbitrary files, and list arbitrary directories via ..\ (dot dot backslash) sequences in the BrowsePath parameter.
|
2006-12-26
|
Hosting Controller FolderManager/FolderManager.aspx BrowsePath Parameter Traversal Arbitrary File Access
|
|
37371
Description:
(Description Provided by CVE) : phpProfiles before 2.1.1 does not have an index.php or other index file in the (1) image_data, (2) graphics/comm, or (3) users read/write directories, which might allow remote attackers to list directory contents or have other unknown impacts.
|
2006-12-26
|
phpProfiles Multiple Directory Open Browsing
|
|
31528
Description:
(Description Provided by CVE) : SQL injection vulnerability in calendar_detail.asp in Calendar MX BASIC 1.0.2 and earlier allows remote attackers to execute arbitrary SQL commands via the ID parameter. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.
|
2006-12-26
|
Calendar MX BASIC ID calendar_detail.asp ID SQL Injection
|
|
31683
Description:
(Description Provided by CVE) : SQL injection vulnerability in bus_details.asp in Dragon Business Directory - Pro (aka Dragon Internet Business Search Directory - Pro) 3.01.12 and earlier allows remote attackers to execute arbitrary SQL commands via the ID parameter.
|
2006-12-26
|
Dragon Business Directory Pro bus_details.asp ID SQL Injection
|
|
31684
Description:
(Description Provided by CVE) : SQL injection vulnerability in admin/admin_mail_adressee.asp in Newsletter MX 1.0.2 and earlier allows remote attackers to execute arbitrary SQL commands via the ID parameter.
|
2006-12-26
|
Newsletter MX admin_mail_adressee.asp ID SQL Injection
|
|
31685
Description:
(Description Provided by CVE) : Multiple PHP remote file inclusion vulnerabilities in Jinzora Media Jukebox 2.7 and earlier, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the include_path parameter in (1) popup.php, (2) rss.php, (3) ajax_request.php, and (4) mediabroadcast.php.
|
2006-12-26
|
Jinzora popup.php include_path File Inclusion
|
|
31686
Description:
(Description Provided by CVE) : Multiple PHP remote file inclusion vulnerabilities in Jinzora Media Jukebox 2.7 and earlier, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the include_path parameter in (1) popup.php, (2) rss.php, (3) ajax_request.php, and (4) mediabroadcast.php.
|
2006-12-26
|
Jinzora rss.php include_path File Inclusion
|
|
31687
Description:
(Description Provided by CVE) : Multiple PHP remote file inclusion vulnerabilities in Jinzora Media Jukebox 2.7 and earlier, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the include_path parameter in (1) popup.php, (2) rss.php, (3) ajax_request.php, and (4) mediabroadcast.php.
|
2006-12-26
|
Jinzora ajax_request.php include_path File Inclusion
|
|
31688
Description:
(Description Provided by CVE) : Multiple PHP remote file inclusion vulnerabilities in Jinzora Media Jukebox 2.7 and earlier, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the include_path parameter in (1) popup.php, (2) rss.php, (3) ajax_request.php, and (4) mediabroadcast.php.
|
2006-12-26
|
Jinzora mediabroadcast.php include_path File Inclusion
|
|
35838
Description:
(Description Provided by CVE) : Multiple SQL injection vulnerabilities in Efkan Forum 1.0 and earlier allow remote attackers to execute arbitrary SQL commands via (1) the grup parameter in admin.asp, or the id parameter in (2) default.asp or (3) admin.asp. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information. The default.asp/grup vector is already covered by CVE-2006-6794.
|
2006-12-26
|
Efkan Forum admin.asp grup Parameter SQL Injection
|
|
35839
Description:
(Description Provided by CVE) : Multiple SQL injection vulnerabilities in Efkan Forum 1.0 and earlier allow remote attackers to execute arbitrary SQL commands via (1) the grup parameter in admin.asp, or the id parameter in (2) default.asp or (3) admin.asp. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information. The default.asp/grup vector is already covered by CVE-2006-6794.
|
2006-12-26
|
Efkan Forum default.asp id Parameter SQL Injection
|