| OSVDB ID | Disclosure Date | Title |
|
26598
Description:
Bible Portal Project contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to Admin/rtf_parser.php not properly sanitizing user input supplied to the 'destination' variable. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script.
|
2006-06-14
|
Bible Portal Project Admin/rtf_parser.php destination Parameter Remote File Inclusion
|
|
26511
Description:
KDM contains a flaw that may allow a malicious local user to read any files on the system. The issue is due to the 'ReadDmrc()' function reading temporary files insecurely. It is possible for a user to use a symlink style attack to read arbitrary files, resulting in a loss of confidentiality.
|
2006-06-14
|
KDE KDM Login Sesson Type Symlink Arbitrary File Read
|
|
26622
Description:
HP-UX Support Tools Manager contains a flaw that may allow a local denial of service. The issue is triggered when an unspecified error occurs, and will result in loss of availability for the system.
|
2006-06-14
|
HP-UX Support Tools Manager Unspecified Local DoS
|
|
64340
Description:
Windows contains a flaw that may allow a remote denial of service. The issue is triggered by a NULL dereference in svchost.exe, and will result in loss of availability for the service.
|
2006-06-14
|
Microsoft Windows RRAS InterfaceAdjustVLSPointers Null Dereference Remote DoS
|
|
26447
Description:
A remote overflow exists in PicoZip. The 'zipinfo.dll' fails to get info of ACE, RAR, or ZIP archives containing a file with a long filename resulting in a stack-based overflow. With a specially crafted request, an attacker can execute arbitrary code resulting in a loss of integrity.
|
2006-06-14
|
PicoZip zipinfo.dll Multiple Archive Filename Processing Overflow
|
|
27054
Description:
(Description Provided by CVE) : mysqld in MySQL 4.1.x before 4.1.18, 5.0.x before 5.0.19, and 5.1.x before 5.1.6 allows remote authorized users to cause a denial of service (crash) via a NULL second argument to the str_to_date function.
|
2006-06-14
|
MySQL mysqld str_to_date Function NULL Argument DoS
|
|
26432
Description:
A local overflow exists in Microsoft Windows. The jgdw400.dll library fails to perform correct boundary checking on .ART files which can result in a buffer overflow. With a specially crafted request, an attacker can perform arbitrary code execution resulting in a loss of integrity.
|
2006-06-14
|
Microsoft Windows jgdw400.dll ART Image Rendering Overflow
|
|
35999
Description:
(Description Provided by CVE) : PHP remote file inclusion vulnerability in admin/index.php in Fusion Polls allows remote attackers to execute arbitrary PHP code via a URL in the xtrphome parameter.
|
2006-06-14
|
Fusion Polls admin/index.php xtrphome Parameter Remote File Inclusion
|
|
77218
Description:
Unknown / Incomplete
|
2006-06-14
|
Atlassian Confluence HTTP Request Parsing Remote Permission Manipulation
|
|
26444
Description:
Microsoft IE contains a flaw that may allow a malicious user to execute arbitrary code. The issue is triggered due to an error in the parameter validation in the DXImageTransform.Microsoft.Light ActiveX control. It is possible that the flaw may allow arbitrary code execution when a user e.g. visits a malicious web site resulting in a loss of integrity.
|
2006-06-13
|
Microsoft IE DXImageTransform.Microsoft.Light ActiveX Arbitrary Code Execution
|
|
26445
Description:
Microsoft Internet Explorer contains a flaw that may allow a malicious user to spoof the information in the address bar in a way that preserves the original address bar and trusted UI of a trusted site even after the browser has been navigated to a malicious site. It is possible that the flaw may allow phishing attacks or loss of integrity.
|
2006-06-13
|
Microsoft IE Modal Browser Window Address Bar Spoofing
|
|
26446
Description:
Microsoft Internet Explorer contains a flaw that allows remote code execution via a crafted web page that triggers memory corruption when it is saved as a multipart HTML (.mht) file.
|
2006-06-13
|
Microsoft IE Multipart HTML File Save Memory Corruption
|
|
26441
Description:
Exchange Server contains an unspcified Cross Site Scripting flaw in Outlook Web Access that may allow an attacker to execute arbitrary code as a target user with a specially crafted email. No further details have been provided.
|
2006-06-13
|
Microsoft Exchange Server Outlook Web Access HTML Parsing Unspecified XSS
|
|
26437
Description:
An unspecified remote overflow exists in Windows. The RASMAN component of RRAS fails to validate unspecified network traffic resulting in a buffer overflow. With a specially crafted request, an attacker can cause arbitrary code execution resulting in a loss of integrity.
|
2006-06-13
|
Microsoft Windows RRAS RASMAN Remote Overflow
|
|
27452
Description:
Ltwcalendar has been reported to contain a flaw that may allow a remote attacker to execute arbitrary commands. The issue is supposedly due to the calendar.php script not properly sanitizing user input supplied to the 'ltw_config[include_dir]' variable. However, subsequent testing by CVE staff have determined that "the $ltw_config[include_dir] variable is defined as a static value in an include file before it is referenced in an include() statement."
|
2006-06-13
|
ltwCalendar calendar.php ltw_config[include_dir] Parameter Remote File Inclusion
|
|
27453
Description:
(Description Provided by CVE) : include.php in Shoutpro 1.0 might allow remote attackers to bypass IP ban restrictions via a URL in the path parameter that points to an alternate bannedips.php file. NOTE: this issue was originally reported as remote file inclusion, but CVE analysis suggests that this cannot be used for code execution.
|
2006-06-13
|
Shoutpro include.php path Variable IP Ban Bypass
|
|
27455
Description:
Amr Talkbox has been reported to contain a flaw that may allow a remote attacker to execute arbitrary commands. The issue is supposedly due to the talkbox.php script not properly sanitizing user input supplied to the 'direct' variable. However, subsequent testing by CVE staff has determined that "since the $direct variable is set to a static value just before the include statement", this can not be exploited.
|
2006-06-13
|
Amr Talkbox talkbox.php direct Parameter Remote File Inclusion
|
|
27454
Description:
(Description Provided by CVE) : ** DISPUTED ** PHP remote file inclusion vulnerability in admin.jobline.php in Jobline 1.1.1 allows remote attackers to execute arbitrary code via a URL in the mosConfig_absolute_path parameter. NOTE: CVE disputes this issue because the script is protected against direct requests.
|
2006-06-13
|
Jobline for Mambo admin.jobline.php mosConfig_absolute_path Parameter Remote File Inclusion
|
|
27456
Description:
Unknown / Incomplete
|
2006-06-13
|
PHP MESSENGER (Phpmsg10) php_messenger.php path_to_php_conv_script Parameter Remote File Inclusion
|
|
26434
Description:
Windows contains a flaw that may allow a malicious user to execute arbitary code. The issue is triggered when JScript releases objects early, leading to memory corruption and may allow an attacker to run arbitary code. It is possible that the flaw may allow arbitary code executiomn resulting in a loss of integrity.
|
2006-06-13
|
Microsoft JScript Object Release Memory Corruption
|
|
48933
Description:
Unknown / Incomplete
|
2006-06-13
|
PhpGedView GEDCOM Death Record Disclosure
|
|
26433
Description:
A remote overflow exists in Windows. The TCP/IP protocol driver fails to validate packets with an unspecified Source Routing flag resulting in a buffer overflow. With a specially crafted request, an attacker can cause arbitrary code execution resulting in a loss of integrity.
|
2006-06-13
|
Microsoft Windows TCP/IP Protocol Driver Source Routing Overflow
|
|
31441
Description:
(Description Provided by CVE) : Multiple cross-site scripting (XSS) vulnerabilities in addwords.php in MyScrapbook 3.1 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) name and (2) comment parameters. NOTE: the provenance of this information is unknown; the details are obtained from third party information.
|
2006-06-13
|
MyScrapbook addwords.php Multiple Parameter XSS
|
|
27472
Description:
bbrss for phpBB has been reported to contain a flaw that may allow a remote attacker to execute arbitrary commands. The issue is supposedly due to the bbrss.php script not properly sanitizing user input supplied to the 'phpbb_root_path' variable. However, subsequent evaluation by George A. Theall at Tenable Security has revealed the variable can not be manipulated by an attacker.
|
2006-06-13
|
bbrss for phpBB bbrss.php phpbb_root_path Parameter Remote File Inclusion
|
|
27465
Description:
Unknown / Incomplete
|
2006-06-13
|
G-Shout shoutbox.php language Parameter Remote File Inclusion
|
|
26442
Description:
Windows contains an unspecified flaw in Internet Explorer related to the handling of ActiveX controls by the Wmm2fxa.ddl component that may allow an attacker to execute arbitrary code. No further details have been provided.
|
2006-06-13
|
Microsoft IE Wmm2fxa.dll DXImageTransform COM Object Memory Corruption
|
|
26443
Description:
A remote overflow exists in Microsoft IE. Internet Explorer fails to translate UTF-8 characters to Unicode resulting in an encoded HTML overflow. With a specially crafted request, an attacker can cause remote code execution resulting in a loss of integrity.
|
2006-06-13
|
Microsoft IE UTF-8 Encoded HTML Overflow
|
|
26439
Description:
Windows contains a flaw that may allow a remote denial of service. The issue is triggered when the MrxSmbCsIoctlCloseForCopyChunk function of SMB is passed the file handle for a shadow device, which will create a deadlock and result in loss of availability for the service.
|
2006-06-13
|
Microsoft Windows SMB MRXSMB.SYS MrxSmbCscIoctlCloseForCopyChunk Remote DoS
|
|
26440
Description:
A local overflow exists in Microsoft SMB. The function 'MrxSmbCscIoctlOpenForCopyChunk' fails to validate input when handling certain DeviceIoControl requests resulting in an overflow. With a specially crafted request, an attacker can execute arbitrary code with escalated privileges resulting in a loss of integrity.
|
2006-06-13
|
Microsoft Windows SMB MrxSmbCscIoctlOpenForCopyChunk Function Overflow
|
|
26438
Description:
Windows contains a flaw that may allow a malicious user to spoof a valid server. The issue is triggered when using RPC over SSL, and the client does not validate the RPC server. It is possible that the flaw may allow impersonation of a server resulting in a loss of integrity.
|
2006-06-13
|
Microsoft Windows RPC Mutual Authentication Server Spoofing
|
|
27460
Description:
mcGuestbook contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to admin.php not properly sanitizing user input supplied to the 'lang' variable. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script.
|
2006-06-13
|
mcGuestbook admin.php lang Parameter Remote File Inclusion
|
|
27461
Description:
mcGuestbook contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to ecrire.php not properly sanitizing user input supplied to the 'lang' variable. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script.
|
2006-06-13
|
mcGuestbook ecrire.php lang Parameter Remote File Inclusion
|
|
27462
Description:
mcGuestbook contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to lire.php not properly sanitizing user input supplied to the 'lang' variable. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script.
|
2006-06-13
|
mcGuestbook lire.php lang Parameter Remote File Inclusion
|
|
26436
Description:
Windows contains a flaw that may allow a malicious user to execute arbitrary code. The issue is triggered when a sequence of specially crafted packets are sent to one of the RPC interfaces provided by the RASMAN service, which leads to memory corruption. It is possible that the flaw may allow arbitrary code execution resulting in a loss of integrity.
|
2006-06-13
|
Microsoft Windows RASMAN RPC Request Remote Overflow
|
|
27596
Description:
Wheatblog has been reported to contain a flaw that may allow a remote attacker to execute arbitrary commands. The issue is supposedly due to the view_links.php script not properly sanitizing user input supplied to the 'wb_inc_dir' variable. However, subsequent evaluation by multiple researchers indicate that a user does not have the ability to manipulate input to the variable as reported.
|
2006-06-13
|
Wheatblog (wB) view_links.php wb_inc_dir Parameter Remote File Inclusion
|
|
27663
Description:
Unknown / Incomplete
|
2006-06-13
|
Mamblog admin.mamblog.php cfgfile Parameter Remote File Inclusion
|
|
27675
Description:
Flog has been reported to contain a flaw that may allow a remote attacker to execute arbitrary commands. The issue is supposedly due to the config.php script not properly sanitizing user input supplied to the 'FLog_dir_include' variable. However, subsequent evaluation indicates the variable is set to a static value in the core.inc.php file and can not be manipulated by an attacker.
|
2006-06-13
|
Flog config.php FLog_dir_include Parameter Remote File Inclusion
|
|
27674
Description:
boastMachine has been reported to contain a flaw that may allow a remote attacker to execute arbitrary commands. The issue is supposedly due to the vote.php script not properly sanitizing user input supplied to the 'bmc_dir' variable. However, subsequent evaluation indicates the variable is set to a static value in the config.php script and can not be manipulated by an attacker.
|
2006-06-13
|
boastMachine vote.php bmc_dir Parameter Remote File Inclusion
|
|
27673
Description:
phphg Guestbook has been reported to contain a flaw that may allow a remote attacker to execute arbitrary commands. The issue is supposedly due to the signed.php script not properly sanitizing user input supplied to the 'phphg_real_path' variable. However, subsequent examination by CVE staff indicates the variable is set to a static value by common.php and can not be manipulated by an attacker.
|
2006-06-13
|
phphg Guestbook signed.php phphg_real_path Parameter Remote File Inclusion
|
|
27662
Description:
(Description Provided by CVE) : ** DISPUTED ** PHP remote file inclusion vulnerability in upload/admin/team.php in Robin de Graff Somery 0.4.4 allows remote attackers to execute arbitrary PHP code via a URL in the checkauth parameter. NOTE: CVE disputes this vulnerability because the checkauth parameter is only used in conditionals.
|
2006-06-13
|
Somery team.php checkauth Parameter Remote File Inclusion
|