| OSVDB ID | Disclosure Date | Title |
|
29819
Description:
DotClear contains a flaw that may lead to an unauthorized information disclosure. The issue is triggered when a remote attacker makes a direct request to the /ecrire/inc/connexion.php script, which will disclose the software's installation path resulting in a loss of confidentiality. While such information is relatively low risk, it is often useful in carrying out additional, more focused attacks.
|
2006-07-21
|
DotClear /ecrire/inc/connexion.php Direct Request Path Disclosure
|
|
29820
Description:
DotClear contains a flaw that may lead to an unauthorized information disclosure. The issue is triggered when a remote attacker makes a direct request to the /inc/session.php script, which will disclose the software's installation path resulting in a loss of confidentiality. While such information is relatively low risk, it is often useful in carrying out additional, more focused attacks.
|
2006-07-21
|
DotClear /inc/session.php Direct Request Path Disclosure
|
|
29821
Description:
DotClear contains a flaw that may lead to an unauthorized information disclosure. The issue is triggered when a remote attacker makes a direct request to the /inc/classes/class.blog.php script, which will disclose the software's installation path resulting in a loss of confidentiality. While such information is relatively low risk, it is often useful in carrying out additional, more focused attacks.
|
2006-07-21
|
DotClear /inc/classes/class.blog.php Direct Request Path Disclosure
|
|
29822
Description:
DotClear contains a flaw that may lead to an unauthorized information disclosure. The issue is triggered when a remote attacker makes a direct request to the /inc/classes/class.blogcomment.php script, which will disclose the software's installation path resulting in a loss of confidentiality. While such information is relatively low risk, it is often useful in carrying out additional, more focused attacks.
|
2006-07-21
|
DotClear /inc/classes/class.blogcomment.php Direct Request Path Disclosure
|
|
29823
Description:
DotClear contains a flaw that may lead to an unauthorized information disclosure. The issue is triggered when a remote attacker makes a direct request to the /inc/classes/class.blogpost.php script, which will disclose the software's installation path resulting in a loss of confidentiality. While such information is relatively low risk, it is often useful in carrying out additional, more focused attacks.
|
2006-07-21
|
DotClear /inc/classes/class.blogpost.php Direct Request Path Disclosure
|
|
29824
Description:
DotClear contains a flaw that may lead to an unauthorized information disclosure. The issue is triggered when a remote attacker makes a direct request to the /layout/append.php script, which will disclose the software's installation path resulting in a loss of confidentiality. While such information is relatively low risk, it is often useful in carrying out additional, more focused attacks.
|
2006-07-21
|
DotClear /layout/append.php Direct Request Path Disclosure
|
|
29825
Description:
DotClear contains a flaw that may lead to an unauthorized information disclosure. The issue is triggered when a remote attacker makes a direct request to the /layout/class.xblog.php script, which will disclose the software's installation path resulting in a loss of confidentiality. While such information is relatively low risk, it is often useful in carrying out additional, more focused attacks.
|
2006-07-21
|
DotClear /layout/class.xblog.php Direct Request Path Disclosure
|
|
29826
Description:
DotClear contains a flaw that may lead to an unauthorized information disclosure. The issue is triggered when a remote attacker makes a direct request to the /layout/class.xblogcomment.php script, which will disclose the software's installation path resulting in a loss of confidentiality. While such information is relatively low risk, it is often useful in carrying out additional, more focused attacks.
|
2006-07-21
|
DotClear /layout/class.xblogcomment.php Direct Request Path Disclosure
|
|
29827
Description:
DotClear contains a flaw that may lead to an unauthorized information disclosure. The issue is triggered when a remote attacker makes a direct request to the /layout/class.xblogpost.php script, which will disclose the software's installation path resulting in a loss of confidentiality. While such information is relatively low risk, it is often useful in carrying out additional, more focused attacks.
|
2006-07-21
|
DotClear /layout/class.xblogpost.php Direct Request Path Disclosure
|
|
29828
Description:
DotClear contains a flaw that may lead to an unauthorized information disclosure. The issue is triggered when a remote attacker makes a direct request to the /themes/default/form.php script, which will disclose the software's installation path resulting in a loss of confidentiality. While such information is relatively low risk, it is often useful in carrying out additional, more focused attacks.
|
2006-07-21
|
DotClear /themes/default/form.php Direct Request Path Disclosure
|
|
29829
Description:
DotClear contains a flaw that may lead to an unauthorized information disclosure. The issue is triggered when a remote attacker makes a direct request to the /themes/default/list.php script, which will disclose the software's installation path resulting in a loss of confidentiality. While such information is relatively low risk, it is often useful in carrying out additional, more focused attacks.
|
2006-07-21
|
DotClear /themes/default/list.php Direct Request Path Disclosure
|
|
29830
Description:
DotClear contains a flaw that may lead to an unauthorized information disclosure. The issue is triggered when a remote attacker makes a direct request to the /themes/default/post.php script, which will disclose the software's installation path resulting in a loss of confidentiality. While such information is relatively low risk, it is often useful in carrying out additional, more focused attacks.
|
2006-07-21
|
DotClear /themes/default/post.php Direct Request Path Disclosure
|
|
29831
Description:
DotClear contains a flaw that may lead to an unauthorized information disclosure. The issue is triggered when a remote attacker makes a direct request to the /themes/default/template.php script, which will disclose the software's installation path resulting in a loss of confidentiality. While such information is relatively low risk, it is often useful in carrying out additional, more focused attacks.
|
2006-07-21
|
DotClear /themes/default/template.php Direct Request Path Disclosure
|
|
29783
Description:
Unknown / Incomplete
|
2006-07-21
|
BLOG:CMS globalfunctions.php id Parameter XSS
|
|
29784
Description:
Unknown / Incomplete
|
2006-07-21
|
BLOG:CMS blog.php id Parameter XSS
|
|
45907
Description:
(Description Provided by CVE) : The NFS client implementation in the kernel in Red Hat Enterprise Linux (RHEL) 3, when a filesystem is mounted with the noacl option, checks permissions for the open system call via vfs_permission (mode bits) data rather than an NFS ACCESS call to the server, which allows local client processes to obtain a false success status from open calls that the server would deny, and possibly obtain sensitive information about file permissions on the server, as demonstrated in a root_squash environment. NOTE: it is uncertain whether any scenarios involving this issue cross privilege boundaries.
|
2006-07-21
|
Red Hat Linux Kernel NFS Client File Permission Information Disclosure
|
|
28678
Description:
MosCom for Joomla contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to 'tradetop.php' script not properly sanitizing user input supplied to the 'mosConfig_absolute_path' variable. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script.
|
2006-07-21
|
MosCom for Joomla tradetop.php mosConfig_absolute_path Parameter Remote File Inclusion
|
|
28677
Description:
MicroGuestBook contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the 'name' and 'comment' variables upon submission to the 'index.php' script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2006-07-21
|
MicroGuestBook index.php Multiple Field XSS
|
|
29866
Description:
(Description Provided by CVE) : Cross-site scripting (XSS) vulnerability in index.php in phpFaber TopSites 2.0.9 allows remote attackers to inject arbitrary web script or HTML via the i_cat parameter. NOTE: the provenance of this information is unknown; the details are obtained from third party information.
|
2006-07-20
|
phpFaber TopSites index.php i_cat Parameter XSS
|
|
27441
Description:
(Description Provided by CVE) : PHP remote file inclusion vulnerability in extadminmenus.class.php in the MultiBanners 1.0.1 for Mambo allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.
|
2006-07-20
|
MultiBanners for Mambo (com_multibanners) extadminmenus.class.php mosConfig_absolute_path Parameter Remote File Inclusion
|
|
27417
Description:
PlaNet concept planetGallery contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to admin/gallery.php not properly sanitizing user input supplied to the _FILES['grafik']['name'][$i] variable. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script.
|
2006-07-20
|
planetGallery admin/gallery_admin.php Multiple File Extension Upload Arbitrary Code Execution
|
|
27411
Description:
IDevSpot PhpHostBot contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to order/index.php not properly sanitizing user input supplied to the 'page' variable. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script.
|
2006-07-20
|
PhpHostBot order/index.php page Parameter Remote File Inclusion
|
|
27410
Description:
PhpLinkExchange contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to index.php script not properly sanitizing user input supplied to the 'page' variable. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script.
|
2006-07-20
|
PhpLinkExchange index.php page Parameter Remote File Inclusion
|
|
27450
Description:
(Description Provided by CVE) : Directory traversal vulnerability in index.php in UNIDOmedia Chameleon LE 1.203 and earlier, and possibly Chameleon PRO, allows remote attackers to read arbitrary files via the rmid parameter.
|
2006-07-20
|
Unidomedia Chameleon index.php rmid Parameter Traversal Arbitrary File Access
|
|
27413
Description:
Top XL contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the 'pass' and 'pass2' variables upon submission to the add.php script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2006-07-20
|
Top XL add.php Multiple Parameter XSS
|
|
27414
Description:
Top XL contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the 'id' variable upon submission to the /members/index.php script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2006-07-20
|
Top XL /members/index.php id Parameter XSS
|
|
28791
Description:
Unknown / Incomplete
|
2006-07-20
|
Moodle Crafted ZIP File Decompression Unspecified Issue
|
|
27442
Description:
Loudblog contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the 'index.php' script not properly sanitizing user-supplied input to the 'id' variable. This may allow an attacker to inject or manipulate SQL queries in the back-end database.
|
2006-07-20
|
Loudblog index.php id Parameter SQL Injection
|
|
27415
Description:
phpFaber TopSites contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the index.php script not properly sanitizing user-supplied input to the 'i_cat' and 'method' variables. This may allow an attacker to inject or manipulate SQL queries in the back-end database. Additionally, some parts of user input is echoed during SQL error output which may allow an attacker to conduct a cross-site scripting attack. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2006-07-20
|
phpFaber TopSites index.php Multiple Parameter SQL Injection
|
|
27230
Description:
Internet Explorer contains a flaw that may allow a local denial of service. The issue is triggered when a long parameter in the CEnroll.CEnroll.2 ActiveX object's stringToBinary method is used, and will result in loss of availability for the Internet Explorer software.
|
2006-07-20
|
Microsoft IE CEnroll SysAllocStringLen Invalid Length
|
|
27438
Description:
(Description Provided by CVE) : systeminfo.c for Sun Solaris allows local users to read kernel memory via a 0 variable count argument to the sysinfo system call, which causes a -1 argument to be used by the copyout function. NOTE: this issue has been referred to as an integer overflow, but it is probably more like a signedness error or integer underflow.
|
2006-07-20
|
Solaris sysinfo() Overflow Kernel Memory Disclosure
|
|
28647
Description:
iManage CMS contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to the themes/default.php script not properly sanitizing user input supplied to the 'absolute_path' variable. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script.
|
2006-07-20
|
iManage CMS themes/default.php absolute_path Parameter Remote File Inclusion
|
|
28648
Description:
iManage CMS contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to the articles.php script not properly sanitizing user input supplied to the 'absolute_path' variable. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script.
|
2006-07-20
|
iManage CMS articles.php absolute_path Parameter Remote File Inclusion
|
|
28649
Description:
iManage CMS contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to the contact.php script not properly sanitizing user input supplied to the 'absolute_path' variable. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script.
|
2006-07-20
|
iManage CMS contact.php absolute_path Parameter Remote File Inclusion
|
|
28650
Description:
iManage CMS contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to the displaypage.php script not properly sanitizing user input supplied to the 'absolute_path' variable. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script.
|
2006-07-20
|
iManage CMS displaypage.php absolute_path Parameter Remote File Inclusion
|
|
28651
Description:
iManage CMS contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to the faq.php script not properly sanitizing user input supplied to the 'absolute_path' variable. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script.
|
2006-07-20
|
iManage CMS faq.php absolute_path Parameter Remote File Inclusion
|
|
28652
Description:
iManage CMS contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to the mainbody.php script not properly sanitizing user input supplied to the 'absolute_path' variable. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script.
|
2006-07-20
|
iManage CMS mainbody.php absolute_path Parameter Remote File Inclusion
|
|
28653
Description:
iManage CMS contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to the news.php script not properly sanitizing user input supplied to the 'absolute_path' variable. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script.
|
2006-07-20
|
iManage CMS news.php absolute_path Parameter Remote File Inclusion
|
|
28654
Description:
iManage CMS contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to the registration.php script not properly sanitizing user input supplied to the 'asolute_path' variable. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script.
|
2006-07-20
|
iManage CMS registration.php absolute_path Parameter Remote File Inclusion
|
|
28655
Description:
iManage CMS contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to the whosOnline.php script not properly sanitizing user input supplied to the 'asolute_path' variable. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script.
|
2006-07-20
|
iManage CMS whosOnline.php absolute_path Parameter Remote File Inclusion
|