| OSVDB ID | Disclosure Date | Title |
|
27627
Description:
(Description Provided by CVE) : Multiple SQL injection vulnerabilities in HSPcomplete 3.2.2 and 3.3 Beta and earlier allow remote attackers to execute arbitrary SQL commands via the (1) type parameter in report.php and (2) level parameter in custom_buttons.php.
|
2006-06-27
|
HSPcomplete report.php type Parameter SQL Injection
|
|
27628
Description:
(Description Provided by CVE) : Multiple SQL injection vulnerabilities in HSPcomplete 3.2.2 and 3.3 Beta and earlier allow remote attackers to execute arbitrary SQL commands via the (1) type parameter in report.php and (2) level parameter in custom_buttons.php.
|
2006-06-27
|
HSPcomplete custom_buttons.php level Parameter SQL Injection
|
|
28137
Description:
(Description Provided by CVE) : spread uses a temporary file with a static filename based on the port number, which allows local users to cause a denial of service by creating the file during a race condition between unlink and bind function calls. NOTE: spread deletes this temporary file before use, which could cause conflicts with other programs that use the same filename, but this is not a distinct issue.
|
2006-06-27
|
spread Tmp File Local Race Condition DoS
|
|
43500
Description:
(Description Provided by CVE) : Cross-domain vulnerability in MYweb4net Browser 3.8.8.0 allows remote attackers to access restricted information from other domains via an object tag with a data parameter that references a link on the attacker's originating site that specifies a Location HTTP header that references the target site, which then makes that content available through the outerHTML attribute of the object, a similar vulnerability to CVE-2006-3280.
|
2006-06-27
|
MYweb4net Browser Object Tag outerHTML Attribute Cross-domain Information Disclosure
|
|
43501
Description:
(Description Provided by CVE) : Cross-domain vulnerability in GreenBrowser 3.4.0622 allows remote attackers to access restricted information from other domains via an object tag with a data parameter that references a link on the attacker's originating site that specifies a Location HTTP header that references the target site, which then makes that content available through the outerHTML attribute of the object, a similar vulnerability to CVE-2006-3280.
|
2006-06-27
|
GreenBrowser Object Tag outerHTML Attribute Cross-domain Information Disclosure
|
|
43502
Description:
(Description Provided by CVE) : Cross-domain vulnerability in Maxthon 1.5.6 build 42 allows remote attackers to access restricted information from other domains via an object tag with a data parameter that references a link on the attacker's originating site that specifies a Location HTTP header that references the target site, which then makes that content available through the outerHTML attribute of the object, a similar vulnerability to CVE-2006-3280.
|
2006-06-27
|
Maxthon Object Tag outerHTML Attribute Cross-domain Information Disclosure
|
|
43503
Description:
(Description Provided by CVE) : Cross-domain vulnerability in PhaseOut 5.4.4 allows remote attackers to access restricted information from other domains via an object tag with a data parameter that references a link on the attacker's originating site that specifies a Location HTTP header that references the target site, which then makes that content available through the outerHTML attribute of the object, a similar vulnerability to CVE-2006-3280.
|
2006-06-27
|
PhaseOut Object Tag outerHTML Attribute Cross-domain Information Disclosure
|
|
43504
Description:
(Description Provided by CVE) : Cross-domain vulnerability in FineBrowser Freeware 3.2.2 allows remote attackers to access restricted information from other domains via an object tag with a data parameter that references a link on the attacker's originating site that specifies a Location HTTP header that references the target site, which then makes that content available through the outerHTML attribute of the object, a similar vulnerability to CVE-2006-3280.
|
2006-06-27
|
FineBrowser Object Tag outerHTML Attribute Cross-domain Information Disclosure
|
|
43505
Description:
(Description Provided by CVE) : Cross-domain vulnerability in Slim Browser 4.07 build 100 allows remote attackers to access restricted information from other domains via an object tag with a data parameter that references a link on the attacker's originating site that specifies a Location HTTP header that references the target site, which then makes that content available through the outerHTML attribute of the object, a similar vulnerability to CVE-2006-3280.
|
2006-06-27
|
Slim Browser Object Tag outerHTML Attribute Cross-domain Information Disclosure
|
|
43506
Description:
(Description Provided by CVE) : Cross-domain vulnerability in NetCaptor 4.5.7 Personal Edition allows remote attackers to access restricted information from other domains via an object tag with a data parameter that references a link on the attacker's originating site that specifies a Location HTTP header that references the target site, which then makes that content available through the outerHTML attribute of the object, a similar vulnerability to CVE-2006-3280.
|
2006-06-27
|
NetCaptor Object Tag outerHTML Attribute Cross-domain Information Disclosure
|
|
43507
Description:
(Description Provided by CVE) : Cross-domain vulnerability in Enigma Browser 3.8.8 allows remote attackers to access restricted information from other domains via an object tag with a data parameter that references a link on the attacker's originating site that specifies a Location HTTP header that references the target site, which then makes that content available through the outerHTML attribute of the object, a similar vulnerability to CVE-2006-3280.
|
2006-06-27
|
Enigma Browser Object Tag outerHTML Attribute Cross-domain Information Disclosure
|
|
43508
Description:
(Description Provided by CVE) : Cross-domain vulnerability in Fast Browser Pro 8.1 allows remote attackers to access restricted information from other domains via an object tag with a data parameter that references a link on the attacker's originating site that specifies a Location HTTP header that references the target site, which then makes that content available through the outerHTML attribute of the object, a similar vulnerability to CVE-2006-3280.
|
2006-06-27
|
Fast Browser Pro Object Tag outerHTML Attribute Cross-domain Information Disclosure
|
|
43509
Description:
(Description Provided by CVE) : Cross-domain vulnerability in GoSuRF Browser 2.62 allows remote attackers to access restricted information from other domains via an object tag with a data parameter that references a link on the attacker's originating site that specifies a Location HTTP header that references the target site, which then makes that content available through the outerHTML attribute of the object, a similar vulnerability to CVE-2006-3280.
|
2006-06-27
|
GoSuRF Browser Object Tag outerHTML Attribute Cross-domain Information Disclosure
|
|
26654
Description:
CA Integrated Threat Management, eTrust Antivirus and eTrust PestPatrol Anti-Spyware Corporate Edition contain a flaw that may allow a remote denial of service. The issue is triggered when a format string error occurs when handling the description field of a scan job, and will result in loss of availability for the platform.
|
2006-06-27
|
CA Multiple Products Scan Job Description Field Format String
|
|
26829
Description:
Emilia Pinball contains a flaw that may allow a local denial of service. The issue is triggered when an unspecified error occurs when loading compiled plugins, and will result in loss of availability for the system.
|
2006-06-26
|
Emilia Pinball Arbitrary Plugin Privilege Escalation
|
|
26828
Description:
Qdig contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the 'pre_gallery' and 'post_gallery' variables upon submission to the index.php script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2006-06-26
|
Qdig index.php Multiple Parameter XSS
|
|
26862
Description:
CBSMS Mambo module contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to mod_cbsms_messages.php not properly sanitizing user input supplied to the 'mosConfig_absolute_path' variable. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script.
|
2006-06-26
|
CBSMS Mambo Module mod_cbsms_messages.php mosConfig_absolute_path Parameter Remote File Inclusion
|
|
26861
Description:
A buffer overflow exists in PrivateWire. The registration functionality fails to validate GET requests resulting in a buffer overflow. With a specially crafted request, a remote attacker can cause arbitrary code execution resulting in a loss of integrity.
|
2006-06-26
|
PrivateWire Registration Functionality GET Request Overflow
|
|
26930
Description:
Mac OS X contains a flaw that may lead to an unauthorized information disclosure. The issue is triggered when a user performs a search in an AFP share, which will disclose filenames for which the user has no permission resulting in a loss of confidentiality.
|
2006-06-26
|
Apple Mac OS X Apple File Protocol (AFP) Server Search Result Information Disclosure
|
|
26931
Description:
A local overflow exists in Mac OS X. The ImageIO library fails to validate TIFF image files resulting in a stack overflow. With a specially crafted file, an attacker can cause arbitrary code execution resulting in a loss of integrity.
|
2006-06-26
|
Apple Mac OS X ImageIO TIFF Processing Overflow
|
|
26932
Description:
Mac OS X contains a flaw that may allow a remote denial of service. The issue is triggered when an attacker sends a specially crafted request to the OpenLDAP server, and will result in loss of availability for the service.
|
2006-06-26
|
Apple Mac OS X OpenLDAP Server Malformed Request Remote DoS
|
|
26933
Description:
Mac OS X contains a flaw that may allow a malicious user to execute arbitrary code. The issue is triggered when the CF_syslog() function passes unchecked data to syslog(), allowing for a possible format string exploit. It is possible that the flaw may allow arbitrary code execution resulting in a loss of integrity.
|
2006-06-26
|
Apple Mac OS X CF_syslog Function Format String
|
|
26924
Description:
(Description Provided by CVE) : Multiple unspecified vulnerabilities in IBM Lotus Notes and Domino Server before 6.5.5 have unknown impact and attack vectors, due to "potential security issues" as identified by SPR numbers (1) GPKS6C9J67 in Agents, (2) JGAN6B6TZ3 and (3) KSPR699NBP in the Router, (4) GPKS5YQGPT in Security, or (5) HSAO6BNL6Y in the Web Server. NOTE: vector 3 is related to an issue in NROUTER in IBM Lotus Notes and Domino Server before 6.5.4 FP1, 6.5.5, and 7.0, which allows remote attackers to cause a denial of service (CPU consumption) via a crafted vCal meeting request sent via SMTP (aka SPR# KSPR699NBP).
|
2006-06-26
|
IBM Lotus Domino SMTP Server Malformed Meeting Request (vCal) DoS
|
|
26858
Description:
(Description Provided by CVE) : Multiple cross-site scripting (XSS) vulnerabilities in Claroline 1.7.7 allow remote attackers to inject arbitrary HTML or web script via unspecified attack vectors, possibly including (1) calendar/myagenda.php, (2) document/document.php, (3) phpbb/newtopic.php, (4) tracking/userLog.php, and (5) wiki/page.php.
|
2006-06-26
|
Claroline Multiple Unspecified XSS
|
|
26910
Description:
Joomla! contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the application not properly sanitizing user-supplied input to the 'Remember Me' functionality. This may allow an attacker to inject or manipulate SQL queries in the back-end database.
|
2006-06-26
|
Joomla! Remember Me Function SQL Injection
|
|
26911
Description:
Joomla! contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the application not properly sanitizing user-supplied input to the 'Related Items' module. This may allow an attacker to inject or manipulate SQL queries in the back-end database.
|
2006-06-26
|
Joomla! Related Items Module SQL Injection
|
|
26912
Description:
Joomla! contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the application not properly sanitizing user-supplied input to the 'Weblinks' functionality. This may allow an attacker to inject or manipulate SQL queries in the back-end database.
|
2006-06-26
|
Joomla! Weblinks Feature SQL Injection
|
|
26913
Description:
Joomla! contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate input upon submission to the 'SEF' functionality. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2006-06-26
|
Joomla! SEF Feature Unspecified XSS
|
|
26914
Description:
Joomla! contains a flaw related that enables an unspecified spoofing attack on the 'frontend submission forms'. No further details have been provided.
|
2006-06-26
|
Joomla! Front End Submission Form Unspecified Spoofing Weakness
|
|
26915
Description:
Joomla! contains an unspecified flaw related to the 'mosmsg' variable. No further details have been provided.
|
2006-06-26
|
Joomla! mosmsg Unspecified Issue
|
|
26916
Description:
Joomla! contains an unspecified input validation flaw related to the 'mosgetparam' parameter. No further details have been provided.
|
2006-06-26
|
Joomla! mosgetparam Input Sanitization Unspecified Weakness
|
|
26917
Description:
Joomla! contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the 'com_messages' variables upon submission to an unspecified script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2006-06-26
|
Joomla! com_messages Unspecified XSS
|
|
26918
Description:
Joomla! contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate input upon submission to scripts that make use of the 'getUserStateFromRequest()' function. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2006-06-26
|
Joomla! getUserStateFromRequest() Function XSS
|
|
26855
Description:
(Description Provided by CVE) : SQL injection vulnerability in the Search gadget in Jaws 0.6.2 allows remote attackers to execute arbitrary SQL commands via queries with the "LIKE" keyword in the searchdata parameter (search field).
|
2006-06-26
|
Jaws Search Function searchdata Field SQL Injection
|
|
27625
Description:
(Description Provided by CVE) : SQL injection vulnerability in index.php in Zorum Forum 3.5 allows remote attackers to execute arbitrary SQL commands via the (1) offset, (2) tid, (3) fromid, (4) sortby, (5) fromfrommethod, and (6) fromfromlist parameters.
|
2006-06-26
|
Zorum index.php Multiple Parameter SQL Injection
|
|
27626
Description:
(Description Provided by CVE) : Cross-site scripting (XSS) vulnerability in index.php in Zorum Forum 3.5 allows remote attackers to inject web script or HTML via the multiple unspecified parameters, including the (1) frommethod, (2) list, and (3) method, which are reflected in an error message. NOTE: some of these vectors might be resultant from SQL injection.
|
2006-06-26
|
Zorum index.php Multiple Parameter XSS
|
|
27624
Description:
(Description Provided by CVE) : PlaNet Concept planetNews allows remote attackers to bypass authentication and execute arbitrary code via a direct request to news/admin/planetnews.php.
|
2006-06-26
|
PlaNet Concept planetNews news/admin/planetnews.php Authentication Bypass
|
|
27660
Description:
Unknown / Incomplete
|
2006-06-26
|
MyMail admin/login.php error Parameter XSS
|
|
28189
Description:
(Description Provided by CVE) : SQL injection vulnerability in cms_admin.php in THoRCMS 1.3.1 allows remote attackers to execute arbitrary SQL commands via multiple unspecified parameters, such as the add_link_mid parameter. NOTE: the provenance of this information is unknown; portions of the details are obtained from third party information.
|
2006-06-26
|
THoRCMS for phpBB cms_admin.php add_link_mid Parameter SQL Injection
|
|
31742
Description:
(Description Provided by CVE) : PHP remote file inclusion vulnerability in mod_cbsms.php in CBSMS Mambo Module 1.0 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the mosC_a_path parameter. NOTE: the provenance of this information is unknown; portions of the details are obtained from third party information.
|
2006-06-26
|
CBSMS Mambo Module mod_cbsms.php mosC_a_path Variable Remote File
|