| OSVDB ID | Disclosure Date | Title |
|
25851
Description:
FreeBSD contains a flaw that allows a remote attacker to escape a chroot environment when the chroot is implemented over a Server Message Block File System (SMBFS). The issue is due to the SMBFS not properly sanitizing user input, specifically directory traversal style attacks (..\). This flaw may lead to a loss of integrity.
|
2006-05-31
|
FreeBSD SMBFS Traversal chroot Bypass
|
|
25852
Description:
FreeBSD contains a flaw that may allow "securenets" access restrictions to be inadvertantly disabled. The issue is triggered when a change in the build process caused ypserv to fail to load or process the networks and hosts specified in the /var/yp/securenets file. It is possible that the flaw may allow access to NIS maps resulting in a loss of integrity.
|
2006-05-31
|
FreeBSD ypserv securenets Access Control Failure
|
|
31648
Description:
(Description Provided by CVE) : SQL injection vulnerability in VBulletin 3.0.10 allows remote attackers to execute arbitrary SQL commands via the featureid parameter.
|
2006-05-31
|
VBulletin portal.php featureid SQL Injection
|
|
31649
Description:
(Description Provided by CVE) : The default configuration of syslogd in the Linux sysklogd package does not enable the -x (disable name lookups) option, which allows remote attackers to cause a denial of service (traffic amplification) via messages with spoofed source IP addresses.
|
2006-05-31
|
sysklogd Name Lookups Remote DoS
|
|
37032
Description:
(Description Provided by CVE) : SQL injection vulnerability in view_album.php in SelectaPix 1.4 allows remote attackers to execute arbitrary SQL commands via unknown vectors. NOTE: the provenance of this information is unknown; the details are obtained solely from third party sources.
|
2006-05-31
|
SelectaPix view_album.php Unspecified SQL Injection
|
|
39401
Description:
METAjour contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to 'uptodate.class.php' not properly sanitizing user input supplied to the 'system_path' variable. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script.
|
2006-05-31
|
METAjour uptodate.class.php system_path Variable Remote File Inclusion
|
|
39402
Description:
METAjour contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to 'slide.class.php' not properly sanitizing user input supplied to the 'system_path' variable. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script.
|
2006-05-31
|
METAjour slide.class.php system_path Variable Remote File Inclusion
|
|
39403
Description:
METAjour contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to 'sitemap.datatype.php' not properly sanitizing user input supplied to the 'GLOBALS[system_path]' variable. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script.
|
2006-05-31
|
METAjour sitemap.datatype.php GLOBALS[system_path] Variable Remote File Inclusion
|
|
39404
Description:
METAjour contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to 'sitemap.class.php' not properly sanitizing user input supplied to the 'system_path' variable. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script.
|
2006-05-31
|
METAjour sitemap.class.php system_path Variable Remote File Inclusion
|
|
39405
Description:
METAjour contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to 'shop.class.php' not properly sanitizing user input supplied to the 'system_path' variable. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script.
|
2006-05-31
|
METAjour shop.class.php system_path Variable Remote File Inclusion
|
|
39406
Description:
METAjour contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to 'search.datatype.php' not properly sanitizing user input supplied to the 'system_path' variable. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script.
|
2006-05-31
|
METAjour search.datatype.php system_path Variable Remote File Inclusion
|
|
39407
Description:
METAjour contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to 'search.class.php' not properly sanitizing user input supplied to the 'system_path' variable. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script.
|
2006-05-31
|
METAjour search.class.php system_path Variable Remote File Inclusion
|
|
39408
Description:
METAjour contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to 'related.class.php' not properly sanitizing user input supplied to the 'system_path' variable. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script.
|
2006-05-31
|
METAjour related.class.php system_path Variable Remote File Inclusion
|
|
39409
Description:
METAjour contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to 'register.class.php' not properly sanitizing user input supplied to the 'system_path' variable. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script.
|
2006-05-31
|
METAjour register.class.php system_path Variable Remote File Inclusion
|
|
39410
Description:
METAjour contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to 'online.class.php' not properly sanitizing user input supplied to the 'system_path' variable. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script.
|
2006-05-31
|
METAjour online.class.php system_path Variable Remote File Inclusion
|
|
39411
Description:
METAjour contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to 'menu.class.php' not properly sanitizing user input supplied to the 'system_path' variable. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script.
|
2006-05-31
|
METAjour menu.class.php system_path Variable Remote File Inclusion
|
|
39412
Description:
METAjour contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to 'login.class.php' not properly sanitizing user input supplied to the 'system_path' variable. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script.
|
2006-05-31
|
METAjour login.class.php system_path Variable Remote File Inclusion
|
|
39413
Description:
METAjour contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to 'listpopulardoc.class.php' not properly sanitizing user input supplied to the 'system_path' variable. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script.
|
2006-05-31
|
METAjour listpopulardoc.class.php system_path Variable Remote File Inclusion
|
|
39414
Description:
METAjour contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to 'listlatestdoc.class.php' not properly sanitizing user input supplied to the 'system_path' variable. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script.
|
2006-05-31
|
METAjour listlatestdoc.class.php system_path Variable Remote File Inclusion
|
|
39415
Description:
METAjour contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to 'listing_view_combidialog.php' not properly sanitizing user input supplied to the 'system_path' variable. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script.
|
2006-05-31
|
METAjour listing_view_combidialog.php system_path Variable Remote File Inclusion
|
|
39416
Description:
METAjour contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to 'listing.datatype.php' not properly sanitizing user input supplied to the 'system_path' variable. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script.
|
2006-05-31
|
METAjour listing.datatype.php system_path Variable Remote File Inclusion
|
|
39417
Description:
METAjour contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to 'listing.class.php' not properly sanitizing user input supplied to the 'system_path' variable. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script.
|
2006-05-31
|
METAjour listing.class.php system_path Variable Remote File Inclusion
|
|
39418
Description:
METAjour contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to 'listcomment.class.php' not properly sanitizing user input supplied to the 'system_path' variable. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script.
|
2006-05-31
|
METAjour listcomment.class.php system_path Variable Remote File Inclusion
|
|
39419
Description:
METAjour contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to 'indexadv.class.php' not properly sanitizing user input supplied to the 'system_path' variable. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script.
|
2006-05-31
|
METAjour indexadv.class.php system_path Variable Remote File Inclusion
|
|
39420
Description:
METAjour contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to 'index.class.php' not properly sanitizing user input supplied to the 'system_path' variable. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script.
|
2006-05-31
|
METAjour index.class.php system_path Variable Remote File Inclusion
|
|
39421
Description:
METAjour contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to 'gallery.class.php' not properly sanitizing user input supplied to the 'system_path' variable. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script.
|
2006-05-31
|
METAjour gallery.class.php system_path Variable Remote File Inclusion
|
|
39422
Description:
METAjour contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to 'gallery.datatype.php' not properly sanitizing user input supplied to the 'system_path' variable. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script.
|
2006-05-31
|
METAjour gallery.datatype.php system_path Variable Remote File Inclusion
|
|
39423
Description:
METAjour contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to 'forumdata.datatype.php' not properly sanitizing user input supplied to the 'system_path' variable. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script.
|
2006-05-31
|
METAjour forumdata.datatype.php system_path Variable Remote File Inclusion
|
|
39424
Description:
METAjour contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to 'forum.datatype.php' not properly sanitizing user input supplied to the 'system_path' variable. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script.
|
2006-05-31
|
METAjour forum.datatype.php system_path Variable Remote File Inclusion
|
|
39425
Description:
METAjour contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to 'forum.class.php' not properly sanitizing user input supplied to the 'system_path' variable. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script.
|
2006-05-31
|
METAjour forum.class.php system_path Variable Remote File Inclusion
|
|
39426
Description:
METAjour contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to 'forgottenpassword.class.php' not properly sanitizing user input supplied to the 'system_path' variable. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script.
|
2006-05-31
|
METAjour forgottenpassword.class.php system_path Variable Remote File Inclusion
|
|
39427
Description:
METAjour contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to <SCRIPT> not properly sanitizing user input supplied to the 'system_path' variable. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script.
|
2006-05-31
|
METAjour filelist.class.php system_path Variable Remote File Inclusion
|
|
39428
Description:
METAjour contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to 'filelist.datatype.php' not properly sanitizing user input supplied to the 'system_path' variable. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script.
|
2006-05-31
|
METAjour filelist.datatype.php system_path Variable Remote File Inclusion
|
|
39429
Description:
METAjour contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to 'changepassword.class.php' not properly sanitizing user input supplied to the 'system_path' variable. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script.
|
2006-05-31
|
METAjour changepassword.class.php system_path Variable Remote File Inclusion
|
|
39430
Description:
METAjour contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to 'cform.datatype.php' not properly sanitizing user input supplied to the 'system_path' variable. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script.
|
2006-05-31
|
METAjour cform.datatype.php system_path Variable Remote File Inclusion
|
|
39431
Description:
METAjour contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to 'cform.class.php' not properly sanitizing user input supplied to the 'system_path' variable. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script.
|
2006-05-31
|
METAjour cform.class.php system_path Variable Remote File Inclusion
|
|
39432
Description:
METAjour contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to 'bulletinboard.class.php' not properly sanitizing user input supplied to the 'system_path' variable. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script.
|
2006-05-31
|
METAjour bulletinboard.class.php system_path Variable Remote File Inclusion
|
|
39433
Description:
METAjour contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to 'breadcrumb.class.php' not properly sanitizing user input supplied to the 'system_path' variable. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script.
|
2006-05-31
|
METAjour breadcrumb.class.php system_path Variable Remote File Inclusion
|
|
39434
Description:
METAjour contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to 'article.datatype.php' not properly sanitizing user input supplied to the 'system_path' variable. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script.
|
2006-05-31
|
METAjour article.datatype.php system_path Variable Remote File Inclusion
|
|
39435
Description:
METAjour contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to 'article.class.php' not properly sanitizing user input supplied to the 'system_path' variable. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script.
|
2006-05-31
|
METAjour article.class.php system_path Variable Remote File Inclusion
|