| OSVDB ID | Disclosure Date | Title |
|
26467
Description:
PhpMyFactures contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the /pays/modifier_pays.php script not properly sanitizing user-supplied input to the 'id_pays' variable. This may allow an attacker to inject or manipulate SQL queries in the back-end database.
|
2006-06-10
|
PhpMyFactures pays/modifier_pays.php id_pays Parameter SQL Injection
|
|
26468
Description:
PhpMyFactures contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the produits/ajouter_cat.php script not properly sanitizing user-supplied input to the 'titre' variable. This may allow an attacker to inject or manipulate SQL queries in the back-end database.
|
2006-06-10
|
PhpMyFactures produits/ajouter_cat.php titre Parameter SQL Injection
|
|
26469
Description:
PhpMyFactures contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the stocks/ajouter.php script not properly sanitizing user-supplied input to the 'id_produit', 'quantite', 'prix_ht' and 'date' variables. This may allow an attacker to inject or manipulate SQL queries in the back-end database.
|
2006-06-10
|
PhpMyFactures stocks/ajouter.php Multiple Parameter SQL Injection
|
|
26470
Description:
PhpMyFactures contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the produits/modifier_cat.php script not properly sanitizing user-supplied input to the 'id_cat' variable. This may allow an attacker to inject or manipulate SQL queries in the back-end database.
|
2006-06-10
|
PhpMyFactures produits/modifier_cat.php id_cat Parameter SQL Injection
|
|
26471
Description:
PhpMyFactures contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the clients/modifier_client.php script not properly sanitizing user-supplied input to the 'id_client' variable. This may allow an attacker to inject or manipulate SQL queries in the back-end database.
|
2006-06-10
|
PhpMyFactures clients/modifier_client.php id_client Parameter SQL Injection
|
|
26472
Description:
PhpMyFactures contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the remises/index.php script not properly sanitizing user-supplied input to the 'id_remise' variable. This may allow an attacker to inject or manipulate SQL queries in the back-end database.
|
2006-06-10
|
PhpMyFactures remises/index.php id_remise Parameter SQL Injection
|
|
26473
Description:
PhpMyFactures contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the tva/index.php script not properly sanitizing user-supplied input to the 'id_taux' variable. This may allow an attacker to inject or manipulate SQL queries in the back-end database.
|
2006-06-10
|
PhpMyFactures tva/index.php id_taux Parameter SQL Injection
|
|
26474
Description:
PhpMyFactures contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the stocks/index.php script not properly sanitizing user-supplied input to the 'ref_produit', 'id_stock' or 'ref_produit' variables. This may allow an attacker to inject or manipulate SQL queries in the back-end database.
|
2006-06-10
|
PhpMyFactures stocks/index.php Multiple Parameter SQL Injection
|
|
26475
Description:
PhpMyFactures contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the pays/index.php script not properly sanitizing user-supplied input to the 'id_pays' variable. This may allow an attacker to inject or manipulate SQL queries in the back-end database.
|
2006-06-10
|
PhpMyFactures pays/index.php id_pays Parameter SQL Injection
|
|
26476
Description:
PhpMyFactures contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the produits/index.php script not properly sanitizing user-supplied input to the 'id_cat' variable. This may allow an attacker to inject or manipulate SQL queries in the back-end database.
|
2006-06-10
|
PhpMyFactures produits/index.php id_cat Parameter SQL Injection
|
|
26477
Description:
PhpMyFactures contains a flaw that may allow a remote attacker to manipulate data. The issue is due to the system not properly authenticating for access to several pages. A remote unauthenticated attacker could use this manipulate a wide variety of data in the back-end database.
|
2006-06-10
|
PhpMyFactures Unauthenticated Data Manipulation
|
|
26478
Description:
PhpMyFactures contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the 'prefixe_dossier' variable upon submission to the /inc/header.php script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2006-06-10
|
PhpMyFactures inc/header.php prefixe_dossier Parameter XSS
|
|
26479
Description:
PhpMyFactures contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the 'msg' or 'tire' variables upon submission to the ajouter_remise.php script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2006-06-10
|
PhpMyFactures ajouter_remise.php Multiple Parameter XSS
|
|
26480
Description:
PhpMyFactures contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the 'msg' variable upon submission to the ajouter_produit.php script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2006-06-10
|
PhpMyFactures ajouter_produit.php msg Parameter XSS
|
|
26481
Description:
PhpMyFactures contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the 'msg' variable upon submission to the ajouter_tva.php script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2006-06-10
|
PhpMyFactures ajouter_tva.php msg Parameter XSS
|
|
26482
Description:
PhpMyFactures contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the 'msg', 'quantite', 'taux' or 'date' variables upon submission to the /stocks/ajouter.php script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2006-06-10
|
PhpMyFactures ajouter.php Multiple Parameter XSS
|
|
26483
Description:
PhpMyFactures contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the 'msg', 'pays' or 'prefixe' variables upon submission to the ajouter_pays.php script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2006-06-10
|
PhpMyFactures ajouter_pays.php Multiple Parameter XSS
|
|
26484
Description:
PhpMyFactures contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the 'msg' variable upon submission to the ajouter_cat.php script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2006-06-10
|
PhpMyFactures ajouter_cat.php msg Parameter XSS
|
|
26485
Description:
PhpMyFactures contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the 'msg' variable upon submission to the modifier_cat.php script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2006-06-10
|
PhpMyFactures modifier_cat.php msg Parameter XSS
|
|
26486
Description:
PhpMyFactures contains a flaw that may lead to an unauthorized information disclosure. The issue is triggered when a remote attacker makes a direct request to the verif.php script, which will disclose the software's installation path resulting in a loss of confidentiality. While such information is relatively low risk, it is often useful in carrying out additional, more focused attacks.
|
2006-06-10
|
PhpMyFactures verif.php Direct Request Path Disclosure
|
|
26487
Description:
PhpMyFactures contains a flaw that may lead to an unauthorized information disclosure. The issue is triggered when a remote attacker makes a direct request to the inc/footer.php script, which will disclose the software's installation path resulting in a loss of confidentiality. While such information is relatively low risk, it is often useful in carrying out additional, more focused attacks.
|
2006-06-10
|
PhpMyFactures inc/footer.php Direct Request Path Disclosure
|
|
26488
Description:
PhpMyFactures contains a flaw that may lead to an unauthorized information disclosure. The issue is triggered when a remote attacker makes a direct request to the ajouter_remise.php script, which will disclose the software's installation path resulting in a loss of confidentiality. While such information is relatively low risk, it is often useful in carrying out additional, more focused attacks.
|
2006-06-10
|
PhpMyFactures ajouter_remise.php Direct Request Path Disclosure
|
|
26401
Description:
DqZone Shopping Cart contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the 'ToCategory' and 'FromCategory' variables upon submission to the ProductDetailsForm.asp script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2006-06-10
|
DwZone Shopping Cart ProductDetailsForm.asp Multiple Parameter XSS
|
|
26402
Description:
DwZone contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the 'UserName' and 'Password' variables upon submission to the LogIn/VerifyUserLog.asp script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2006-06-10
|
DwZone Shopping Cart LogIn/VerifyUserLog.asp Multiple Parameter XSS
|
|
26400
Description:
(Description Provided by CVE) : Multiple cross-site scripting (XSS) vulnerabilities in thumbnails.asp in Uapplication Uphotogallery 1.1 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) s and (2) block parameters.
|
2006-06-10
|
Uphotogallery thumbnails.asp Multiple Parameter XSS
|
|
26398
Description:
Xtreme ASP Photo Gallery contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the 'catname' and 'total' variables upon submission to the displaypic.asp script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2006-06-10
|
Xtreme ASP Photo Gallery displaypic.asp Multiple Parameter XSS
|
|
26399
Description:
Xtreme ASP PhotoGallery contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the 'catname' variable upon submission to the displaythumbs.asp script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2006-06-10
|
Xtreme ASP Photo Gallery displaythumbs.asp catname Parameter XSS
|
|
26218
Description:
(Description Provided by CVE) : SQL injection vulnerability in vs_search.php in Arantius Vice Stats before 1.0.1 allows remote attackers to execute arbitrary SQL commands via unknown vectors, a different issue than CVE-2006-2972.
|
2006-06-10
|
Vice Stats vs_search.php SQL Injection
|
|
26515
Description:
(Description Provided by CVE) : Multiple buffer overflows in MERCUR Messaging 2005 before Service Pack 4 allow remote attackers to cause a denial of service (crash) via (1) "long command lines at port 32000" and (2) certain name service queries that are not properly handled by the SMTP service.
|
2006-06-10
|
MERCUR Messaging Port 32000 Command Overflow
|
|
26516
Description:
(Description Provided by CVE) : The IMAP4 service in MERCUR Messaging 2005 before Service Pack 4 allows remote attackers to cause a denial of service (crash) via a message with a long subject field.
|
2006-06-10
|
MERCUR Messaging IMAP Service Subject Field Overflow DoS
|
|
26517
Description:
Unknown / Incomplete
|
2006-06-10
|
MERCUR Messaging Remote Mail Account Virus/Attachment Filtering Failure
|
|
26518
Description:
Unknown / Incomplete
|
2006-06-10
|
MERCUR Messaging Firewall Denied Address Handling Failure
|
|
26519
Description:
(Description Provided by CVE) : The SMTP service in MERCUR Messaging 2005 before Service Pack 4 allows remote attackers to cause a denial of service (infinite loop) via a message in which neither the originator nor recipient address is known.
|
2006-06-10
|
MERCUR Messaging SMTP Service Crafted Address DoS
|
|
26520
Description:
(Description Provided by CVE) : Multiple buffer overflows in MERCUR Messaging 2005 before Service Pack 4 allow remote attackers to cause a denial of service (crash) via (1) "long command lines at port 32000" and (2) certain name service queries that are not properly handled by the SMTP service.
|
2006-06-10
|
MERCUR Messaging SMTP Service Malformed Name Server Query DoS
|
|
26521
Description:
(Description Provided by CVE) : Unspecified vulnerability in MERCUR Messaging 2005 before Service Pack 4 allows remote attackers to cause a denial of service (crash) via a TOP command to the POP3 service.
|
2006-06-10
|
MERCUR Messaging POP3 TOP Command DoS
|
|
26656
Description:
Unknown / Incomplete
|
2006-06-10
|
GD Graphics Library (libgd) gd_gif_in.c Infinite Loop DoS
|
|
41776
Description:
(Description Provided by CVE) : Multiple cross-site scripting (XSS) vulnerabilities in fx-APP 0.0.8.1 allow remote attackers to inject arbitrary HTML or web script via (1) the search box, and the (2) url, (3) website, (4) comment, and (5) signature fields in the profile, and possibly (6) a menu item.
|
2006-06-10
|
fx-APP Search Box XSS
|
|
41777
Description:
(Description Provided by CVE) : Multiple cross-site scripting (XSS) vulnerabilities in fx-APP 0.0.8.1 allow remote attackers to inject arbitrary HTML or web script via (1) the search box, and the (2) url, (3) website, (4) comment, and (5) signature fields in the profile, and possibly (6) a menu item.
|
2006-06-10
|
fx-APP Profile Multiple Field XSS
|
|
31601
Description:
(Description Provided by CVE) : PHP remote file inclusion vulnerability in sql_fcnsOLD.php in Emergenices Personnel Information System (Empris) 20020923 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the phormationdir parameter.
|
2006-06-10
|
Empris sql_fcnsOLD.php phormationdir Remote File Inclusion
|
|
58820
Description:
(Description Provided by CVE) : The Tools module in fx-APP 0.0.8.1 allows remote attackers to misrepresent the contents of a web page via an arbitrary URL in the url parameter to a showhtml action for index.php, which causes the URL to be displayed within an iframe.
|
2006-06-10
|
fx-APP Tools Module index.php showhtml Action url Parameter Arbitrary Content Injection
|