| OSVDB ID | Disclosure Date | Title |
|
28693
Description:
Mosets Tree contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to the Savant2_Plugin_ahrefreport.php script not properly sanitizing user input supplied to the 'mosConfig_absolute_path' variable. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script.
|
2006-07-21
|
Mosets Tree Savant2_Plugin_ahrefreport.php mosConfig_absolute_path Parameter Remote File Inclusion
|
|
28694
Description:
Mosets Tree contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to the Savant2_Plugin_ahrefreview.php script not properly sanitizing user input supplied to the 'mosConfig_absolute_path' variable. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script.
|
2006-07-21
|
Mosets Tree Savant2_Plugin_ahrefreview.php mosConfig_absolute_path Parameter Remote File Inclusion
|
|
28695
Description:
Mosets Tree contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to the Savant2_Plugin_ahrefvisit.php script not properly sanitizing user input supplied to the 'mosConfig_absolute_path' variable. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script.
|
2006-07-21
|
Mosets Tree Savant2_Plugin_ahrefvisit.php mosConfig_absolute_path Parameter Remote File Inclusion
|
|
28696
Description:
Mosets Tree contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to the Savant2_Plugin_checkbox.php script not properly sanitizing user input supplied to the 'mosConfig_absolute_path' variable. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script.
|
2006-07-21
|
Mosets Tree Savant2_Plugin_checkbox.php mosConfig_absolute_path Parameter Remote File Inclusion
|
|
28697
Description:
Mosets Tree contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to the Savant2_Plugin_cycle.php script not properly sanitizing user input supplied to the 'mosConfig_absolute_path' variable. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script.
|
2006-07-21
|
Mosets Tree Savant2_Plugin_cycle.php mosConfig_absolute_path Parameter Remote File Inclusion
|
|
28698
Description:
Mosets Tree contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to the Savant2_Plugin_dateformat.php script not properly sanitizing user input supplied to the 'mosConfig_absolute_path' variable. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script.
|
2006-07-21
|
Mosets Tree Savant2_Plugin_dateformat.php mosConfig_absolute_path Parameter Remote File Inclusion
|
|
28699
Description:
Mosets Tree contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to the Savant2_Plugin_editor.php script not properly sanitizing user input supplied to the 'mosConfig_absolute_path' variable. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script.
|
2006-07-21
|
Mosets Tree Savant2_Plugin_editor.php mosConfig_absolute_path Parameter Remote File Inclusion
|
|
28700
Description:
Mosets Tree contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to the Savant2_Plugin_form.php script not properly sanitizing user input supplied to the 'mosConfig_absolute_path' variable. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script.
|
2006-07-21
|
Mosets Tree Savant2_Plugin_form.php mosConfig_absolute_path Parameter Remote File Inclusion
|
|
28701
Description:
Mosets Tree contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to the Savant2_Plugin_image.php script not properly sanitizing user input supplied to the 'mosConfig_absolute_path' variable. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script.
|
2006-07-21
|
Mosets Tree Savant2_Plugin_image.php mosConfig_absolute_path Parameter Remote File Inclusion
|
|
28702
Description:
Mosets Tree contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to the Savant2_Plugin_input.php script not properly sanitizing user input supplied to the 'mosConfig_absolute_path' variable. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script.
|
2006-07-21
|
Mosets Tree Savant2_Plugin_input.php mosConfig_absolute_path Parameter Remote File Inclusion
|
|
28703
Description:
Mosets Tree contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to the Savant2_Plugin_javascript.php script not properly sanitizing user input supplied to the 'mosConfig_absolute_path' variable. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script.
|
2006-07-21
|
Mosets Tree Savant2_Plugin_javascript.php mosConfig_absolute_path Parameter Remote File Inclusion
|
|
28704
Description:
Mosets Tree contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to the Savant2_Plugin_listalpha.php script not properly sanitizing user input supplied to the 'mosConfig_absolute_path' variable. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script.
|
2006-07-21
|
Mosets Tree Savant2_Plugin_listalpha.php mosConfig_absolute_path Parameter Remote File Inclusion
|
|
28705
Description:
Mosets Tree contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to the Savant2_Plugin_listingname.php script not properly sanitizing user input supplied to the 'mosConfig_absolute_path' variable. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script.
|
2006-07-21
|
Mosets Tree Savant2_Plugin_listingname.php mosConfig_absolute_path Parameter Remote File Inclusion
|
|
28706
Description:
Mosets Tree contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to the Savant2_Plugin_modify.php script not properly sanitizing user input supplied to the 'mosConfig_absolute_path' variable. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script.
|
2006-07-21
|
Mosets Tree Savant2_Plugin_modify.php mosConfig_absolute_path Parameter Remote File Inclusion
|
|
28707
Description:
Mosets Tree contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to the Savant2_Plugin_mtpath.php script not properly sanitizing user input supplied to the 'mosConfig_absolute_path' variable. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script.
|
2006-07-21
|
Mosets Tree Savant2_Plugin_mtpath.php mosConfig_absolute_path Parameter Remote File Inclusion
|
|
28708
Description:
Mosets Tree contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to the Savant2_Plugin_options.php script not properly sanitizing user input supplied to the 'mosConfig_absolute_path' variable. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script.
|
2006-07-21
|
Mosets Tree Savant2_Plugin_options.php mosConfig_absolute_path Parameter Remote File Inclusion
|
|
28709
Description:
Mosets Tree contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to the Savant2_Plugin_radios.php script not properly sanitizing user input supplied to the 'mosConfig_absolute_path' variable. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script.
|
2006-07-21
|
Mosets Tree Savant2_Plugin_radios.php mosConfig_absolute_path Parameter Remote File Inclusion
|
|
28710
Description:
Mosets Tree contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to the Savant2_Plugin_rating.php script not properly sanitizing user input supplied to the 'mosConfig_absolute_path' variable. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script.
|
2006-07-21
|
Mosets Tree Savant2_Plugin_rating.php mosConfig_absolute_path Parameter Remote File Inclusion
|
|
28711
Description:
Mosets Tree contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to the Savant2_Plugin_stylesheet.php script not properly sanitizing user input supplied to the 'mosConfig_absolute_path' variable. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script.
|
2006-07-21
|
Mosets Tree Savant2_Plugin_stylesheet.php mosConfig_absolute_path Parameter Remote File Inclusion
|
|
28712
Description:
Mosets Tree contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to the Savant2_Plugin_textarea.php script not properly sanitizing user input supplied to the 'mosConfig_absolute_path' variable. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script.
|
2006-07-21
|
Mosets Tree Savant2_Plugin_textarea.php mosConfig_absolute_path Parameter Remote File Inclusion
|
|
32723
Description:
Apache Tomcat contains a flaw that may lead to an unauthorized information disclosure. The issue is triggered when an attacker makes a crafted file request containing a semicolon (;) before the file name, which will result in the server displaying the contents of the directory. This may disclose sensitive files, unpublished content or back up files.
|
2006-07-21
|
Apache Tomcat semicolon Crafted Filename Request Forced Directory Listing
|
|
27551
Description:
(Description Provided by CVE) : Absolute path traversal vulnerability in downloadTrigger.jsp in Alkacon OpenCms before 6.2.2 allows remote authenticated users to download arbitrary files via an absolute pathname in the filePath parameter.
|
2006-07-21
|
Alkacon OpenCms downloadTrigger.jsp filePath Parameter Arbitrary File Access
|
|
27552
Description:
(Description Provided by CVE) : system/workplace/editors/editor.jsp in Alkacon OpenCms before 6.2.2 allows remote authenticated users to read the source code of arbitrary JSP files by specifying the file in the resource parameter, as demonstrated using index.jsp.
|
2006-07-21
|
Alkacon OpenCms editor.jsp Arbitrary JSP File Source Disclosure
|
|
27553
Description:
(Description Provided by CVE) : Cross-site scripting (XSS) vulnerability in Alkacon OpenCms before 6.2.2 allows remote authenticated users to inject arbitrary web script or HTML via the message body.
|
2006-07-21
|
Alkacon OpenCms Message Body XSS
|
|
27554
Description:
(Description Provided by CVE) : system/workplace/views/admin/admin-main.jsp in Alkacon OpenCms before 6.2.2 does not restrict access to administrator functions, which allows remote authenticated users to (1) send broadcast messages to all users (/workplace/broadcast), (2) list all users (/accounts/users), (3) add webusers (/accounts/webusers/new), (4) upload database import and export files (/database/importhttp), (5) upload arbitrary program modules (/modules/modules_import), and (6) read the log file (/workplace/logfileview) by setting the appropriate value for the path parameter in a direct request to admin-main.jsp.
|
2006-07-21
|
Alkacon OpenCms Direct Request Admin Authentication Bypass
|
|
27493
Description:
Unknown / Incomplete
|
2006-07-21
|
SuSE Linux CASA Secret Special Character Handling Weakness
|
|
27494
Description:
Unknown / Incomplete
|
2006-07-21
|
SuSE Linux CASA Unspecified Salt Generation Weakness
|
|
27664
Description:
(Description Provided by CVE) : Integer overflow in parse_comment in GnuPG (gpg) 1.4.4 allows remote attackers to cause a denial of service (segmentation fault) via a crafted message.
|
2006-07-21
|
GnuPG parse_comment Function Crafted Message Overflow DoS
|
|
27447
Description:
Unknown / Incomplete
|
2006-07-21
|
Novell Client Firewall Open File Local Privilege Escalation
|
|
27231
Description:
Internet Explorer contains a flaw that may allow a remote denial of service. The issue is triggered when calling the "Click()" method of the Internet.HHCtrl.1 ActiveX object. This triggers a NULL dereference and will result in loss of availability for the browser.
|
2006-07-21
|
Microsoft IE HTML Help COM Object Click Method NULL Dereference
|
|
27439
Description:
(Description Provided by CVE) : The IPv4 implementation in Sun Solaris 10 before 20060721 allows local users to select routes that differ from the routing table, possibly facilitating firewall bypass or unauthorized network communication.
|
2006-07-21
|
Solaris IP Routing Table Local User Bypass
|
|
28615
Description:
(Description Provided by CVE) : Cross-site scripting (XSS) vulnerability in Blackboard Academic Suite 6.2.3.23 allows remote authenticated users to inject arbitrary HTML or web script by bypassing client-side validation through disabling JavaScript when submitting an essay response, which has no server-side validation before being viewed via "View Attempt Details" in the Gradebook.
|
2006-07-21
|
Blackboard Academic Suite Gradebook View Attempt Details XSS
|
|
29060
Description:
(Description Provided by CVE) : Password Safe 2.11, 2.16 and 3.0BETA1 does not respect the configuration settings for locking the password database when certain dialogue windows are open, which might allow attackers with physical access to obtain the database contents.
|
2006-07-21
|
Password Safe Database Locking Mechanism Weakness
|
|
29812
Description:
DotClear contains a flaw that may lead to an unauthorized information disclosure. The issue is triggered when a remote attacker makes a direct request to the /ecrire/tools/blogroll/edit_cat.php script, which will disclose the software's installation path resulting in a loss of confidentiality. While such information is relatively low risk, it is often useful in carrying out additional, more focused attacks.
|
2006-07-21
|
DotClear /ecrire/tools/blogroll/edit_cat.php Direct Request Path Disclosure
|
|
29813
Description:
DotClear contains a flaw that may lead to an unauthorized information disclosure. The issue is triggered when a remote attacker makes a direct request to the /ecrire/tools/blogroll/index.php script, which will disclose the software's installation path resulting in a loss of confidentiality. While such information is relatively low risk, it is often useful in carrying out additional, more focused attacks.
|
2006-07-21
|
DotClear /ecrire/tools/blogroll/index.php Direct Request Path Disclosure
|
|
29814
Description:
DotClear contains a flaw that may lead to an unauthorized information disclosure. The issue is triggered when a remote attacker makes a direct request to the /ecrire/tools/blogroll/edit_link.php script, which will disclose the software's installation path resulting in a loss of confidentiality. While such information is relatively low risk, it is often useful in carrying out additional, more focused attacks.
|
2006-07-21
|
DotClear /ecrire/tools/blogroll/edit_link.php Direct Request Path Disclosure
|
|
29815
Description:
DotClear contains a flaw that may lead to an unauthorized information disclosure. The issue is triggered when a remote attacker makes a direct request to the /ecrire/tools/syslog/index.php script, which will disclose the software's installation path resulting in a loss of confidentiality. While such information is relatively low risk, it is often useful in carrying out additional, more focused attacks.
|
2006-07-21
|
DotClear /ecrire/tools/syslog/index.php Direct Request Path Disclosure
|
|
29816
Description:
DotClear contains a flaw that may lead to an unauthorized information disclosure. The issue is triggered when a remote attacker makes a direct request to the /ecrire/tools/thememng/index.php script, which will disclose the software's installation path resulting in a loss of confidentiality. While such information is relatively low risk, it is often useful in carrying out additional, more focused attacks.
|
2006-07-21
|
DotClear /ecrire/tools/thememng/index.php Direct Request Path Disclosure
|
|
29817
Description:
DotClear contains a flaw that may lead to an unauthorized information disclosure. The issue is triggered when a remote attacker makes a direct request to the /ecrire/tools/toolsmng/index.php script, which will disclose the software's installation path resulting in a loss of confidentiality. While such information is relatively low risk, it is often useful in carrying out additional, more focused attacks.
|
2006-07-21
|
DotClear /ecrire/tools/toolsmng/index.php Direct Request Path Disclosure
|
|
29818
Description:
DotClear contains a flaw that may lead to an unauthorized information disclosure. The issue is triggered when a remote attacker makes a direct request to the /ecrire/tools/utf8convert/index.php script, which will disclose the software's installation path resulting in a loss of confidentiality. While such information is relatively low risk, it is often useful in carrying out additional, more focused attacks.
|
2006-07-21
|
DotClear /ecrire/tools/utf8convert/index.php Direct Request Path Disclosure
|