| OSVDB ID | Disclosure Date | Title |
|
28461
Description:
vtiger CRM contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the 'solution' variables upon submission to the 'HelpDesk' module. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2006-08-29
|
vtiger CRM HelpDesk Module solution Parameter XSS
|
|
28462
Description:
vtiger CRM contains a flaw that may allow a malicious user to gain access to unauthorized privileges. The issue is triggered because access controls are not applied when files are requested directly, enabling users without administrative privileges to access modules which are restricted to administrators. This flaw may lead to a loss of integrity.
|
2006-08-29
|
vtiger CRM Admin Modules Direct Request Authentication Bypass
|
|
30714
Description:
(Description Provided by CVE) : Gonafish.com LinksCaffe 2.0 and 3.0 do not properly restrict access to administrator functions, which allows remote attackers to gain full administration rights via a direct request to Admin/admin1953.php.
|
2006-08-29
|
LinksCaffe admin1953.php Direct Request Admin Authentication Bypass
|
|
30804
Description:
Unknown / Incomplete
|
2006-08-29
|
Bluetrait Admin File Upload Unspecified Issue
|
|
30712
Description:
(Description Provided by CVE) : PHP remote file inclusion vulnerability in index.php in phpECard 2.1.4 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the include_path parameter. NOTE: the provenance of this information is unknown; the details are obtained from third party information.
|
2006-08-29
|
phpECard index.php include_path Parameter Remote File Inclusion
|
|
58789
Description:
Unknown / Incomplete
|
2006-08-29
|
Apache WSS4J SOAP Header Malformed UsernameToken Authentication Bypass
|
|
31297
Description:
(Description Provided by CVE) : The KDE PAM configuration shipped with Fedora Core 5 causes KDM passwords to be cached, which allows attackers to login without a password by attempting to log in multiple times.
|
2006-08-28
|
KDE PAM on Fedora Core KDM Password Cache Login Bypass
|
|
28319
Description:
ezContents contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the 'subgroupname' variable upon submission to the loginreq2.php script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2006-08-28
|
ezContents loginreq2.php subgroupname Parameter XSS
|
|
28320
Description:
ezContents contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the headeruserdata.php script not properly sanitizing user-supplied input to the 'groupname' variable. This may allow an attacker to inject or manipulate SQL queries in the back-end database.
|
2006-08-28
|
ezContents headeruserdata.php groupname Parameter SQL Injection
|
|
28321
Description:
ezContents contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to the event_list.php script not properly sanitizing user input supplied to the 'GLOBALS[admin_home]' variable. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script.
|
2006-08-28
|
ezContents event_list.php GLOBALS[admin_home] Parameter Remote File Inclusion
|
|
28322
Description:
ezContents contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to the calendar.php script not properly sanitizing user input supplied to the 'GLOBALS[language_home]' variable. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script.
|
2006-08-28
|
ezContents calendar.php GLOBALS[language_home] Parameter Remote File Inclusion
|
|
28323
Description:
ezContents contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to the gallery_summary.php script not properly sanitizing user input supplied to the 'GLOBALS[admin_home]' variable. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script.
|
2006-08-28
|
ezContents gallery_summary.php GLOBALS[admin_home] Parameter Remote File Inclusion
|
|
28324
Description:
ezContents contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to the showguestbook.php script not properly sanitizing user input supplied to the 'GLOBALS[admin_home]' variable. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script.
|
2006-08-28
|
ezContents showguestbook.php GLOBALS[admin_home] Parameter Remote File Inclusion
|
|
28325
Description:
ezContents contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to the showlinks.php script not properly sanitizing user input supplied to the 'GLOBALS[admin_home]' variable. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script.
|
2006-08-28
|
ezContents showlinks.php GLOBALS[admin_home] Parameter Remote File Inclusion
|
|
28326
Description:
ezContents contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to the shownews.php script not properly sanitizing user input supplied to the 'GLOBALS[language_home]' variable. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script.
|
2006-08-28
|
ezContents shownews.php GLOBALS[admin_home] Parameter Remote File Inclusion
|
|
28327
Description:
ezContents contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to the showpoll.php script not properly sanitizing user input supplied to the 'GLOBALS[language_home]' variable. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script.
|
2006-08-28
|
ezContents showpoll.php GLOBALS[admin_home] Parameter Remote File Inclusion
|
|
28328
Description:
ezContents contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to the review_summary.php script not properly sanitizing user input supplied to the 'GLOBALS[admin_home]' variable. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script.
|
2006-08-28
|
ezContents review_summary.php GLOBALS[admin_home] Parameter Remote File Inclusion
|
|
28329
Description:
ezContents contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to the search.php script not properly sanitizing user input supplied to the 'GLOBALS[language_home]' variable. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script.
|
2006-08-28
|
ezContents search.php GLOBALS[language_home] Parameter Remote File Inclusion
|
|
28330
Description:
ezContents contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to the toprated.php script not properly sanitizing user input supplied to the 'GLOBALS[language_home]' variable. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script.
|
2006-08-28
|
ezContents toprated.php GLOBALS[language_home] Parameter Remote File Inclusion
|
|
28331
Description:
ezContents contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to the whatsnew.php script not properly sanitizing user input supplied to the 'GLOBALS[language_home]' variable. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script.
|
2006-08-28
|
ezContents whatsnew.php GLOBALS[language_home] Parameter Remote File Inclusion
|
|
28359
Description:
Unknown / Incomplete
|
2006-08-28
|
Mambo Content Editing id Parameter SQL Injection
|
|
28360
Description:
Unknown / Incomplete
|
2006-08-28
|
Mambo Admin Section Multiple Unspecified SQL Injection
|
|
28248
Description:
Web3news contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to _class.security.php not properly sanitizing user input supplied to the 'PHPSECURITYADMIN_PATH' variable. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script.
|
2006-08-28
|
Web3news _class.security.php PHPSECURITYADMIN_PATH Parameter Remote File Inclusion
|
|
28339
Description:
(Description Provided by CVE) : Multiple unspecified vulnerabilities in Joomla! before 1.0.11, related to unvalidated input, allow attackers to have an unknown impact via unspecified vectors involving the (1) mosMail, (2) JosIsValidEmail, and (3) josSpoofValue functions; (4) the lack of inclusion of globals.php in administrator/index.php; (5) the Admin User Manager; and (6) the poll module.
|
2006-08-28
|
Joomla! mosMail() Unspecified Input Sanitization Weakness
|
|
28340
Description:
(Description Provided by CVE) : Multiple unspecified vulnerabilities in Joomla! before 1.0.11, related to unvalidated input, allow attackers to have an unknown impact via unspecified vectors involving the (1) mosMail, (2) JosIsValidEmail, and (3) josSpoofValue functions; (4) the lack of inclusion of globals.php in administrator/index.php; (5) the Admin User Manager; and (6) the poll module.
|
2006-08-28
|
Joomla! JosIsValidEmail() Unspecified Sanitization Weakness
|
|
28341
Description:
(Description Provided by CVE) : Unspecified vulnerability in PEAR.php in Joomla! before 1.0.11 allows remote attackers to perform "remote execution," related to "Injection Flaws."
|
2006-08-28
|
Joomla! PEAR.php Unspecified Remote Code Execution
|
|
28342
Description:
Unknown / Incomplete
|
2006-08-28
|
Joomla! Zend Hash Del Key Unspecified Issue
|
|
28343
Description:
(Description Provided by CVE) : Multiple unspecified vulnerabilities in Joomla! before 1.0.11, related to unvalidated input, allow attackers to have an unknown impact via unspecified vectors involving the (1) mosMail, (2) JosIsValidEmail, and (3) josSpoofValue functions; (4) the lack of inclusion of globals.php in administrator/index.php; (5) the Admin User Manager; and (6) the poll module.
|
2006-08-28
|
Joomla! administrator/index.php Unspecified globals.php Input Weakness
|
|
28344
Description:
(Description Provided by CVE) : Joomla! before 1.0.11 omits some checks for whether _VALID_MOS is defined, which allows attackers to have an unknown impact, possibly resulting in PHP remote file inclusion.
|
2006-08-28
|
Joomla! Missing _VALID_MOS Check Unspecified Authentication Bypass
|
|
28345
Description:
Unknown / Incomplete
|
2006-08-28
|
Joomla! Admin Upload Image Unauthorized Code Execution
|
|
28346
Description:
(Description Provided by CVE) : Multiple unspecified vulnerabilities in Joomla! before 1.0.11 allow attackers to bypass user authentication via unknown vectors involving the (1) do_pdf command and the (2) emailform com_content task.
|
2006-08-28
|
Joomla! do_pdf Command Authentication Bypass
|
|
28347
Description:
(Description Provided by CVE) : Multiple unspecified vulnerabilities in Joomla! before 1.0.11 allow attackers to bypass user authentication via unknown vectors involving the (1) do_pdf command and the (2) emailform com_content task.
|
2006-08-28
|
Joomla! emailform com_content Task Unspecified Authentication Bypass
|
|
28348
Description:
(Description Provided by CVE) : Multiple cross-site scripting (XSS) vulnerabilities in Joomla! before 1.0.11 allow remote attackers to inject arbitrary web script or HTML via unspecified parameters in (1) Admin Module Manager, (2) Admin Help, and (3) Search.
|
2006-08-28
|
Joomla! Admin Module Manager XSS
|
|
28349
Description:
(Description Provided by CVE) : Multiple cross-site scripting (XSS) vulnerabilities in Joomla! before 1.0.11 allow remote attackers to inject arbitrary web script or HTML via unspecified parameters in (1) Admin Module Manager, (2) Admin Help, and (3) Search.
|
2006-08-28
|
Joomla! Admin Help XSS
|
|
28350
Description:
(Description Provided by CVE) : Multiple cross-site scripting (XSS) vulnerabilities in Joomla! before 1.0.11 allow remote attackers to inject arbitrary web script or HTML via unspecified parameters in (1) Admin Module Manager, (2) Admin Help, and (3) Search.
|
2006-08-28
|
Joomla! Search Function XSS
|
|
28351
Description:
Unknown / Incomplete
|
2006-08-28
|
Joomla! globals.php Loading Weakness
|
|
28352
Description:
(Description Provided by CVE) : Multiple unspecified vulnerabilities in Joomla! before 1.0.11, related to "Injection Flaws," allow attackers to have an unknown impact via (1) globals.php, which uses include_once() instead of require(); (2) the $options variable; (3) Admin Upload Image; (4) ->load(); (5) content submissions when frontpage is selected; (6) the mosPageNav constructor; (7) saveOrder functions; (8) the absence of "exploit blocking rules" in htaccess; and (9) the ACL.
|
2006-08-28
|
Joomla! $option Variable Unspecified Issue
|
|
28353
Description:
(Description Provided by CVE) : The Admin Upload Image functionality in Joomla! before 1.0.11 allows remote authenticated users to upload files outside of the /images/stories/ directory via unspecified vectors.
|
2006-08-28
|
Joomla! Admin Upload Image Unspecified Injection
|
|
28354
Description:
(Description Provided by CVE) : Multiple unspecified vulnerabilities in Joomla! before 1.0.11, related to "Injection Flaws," allow attackers to have an unknown impact via (1) globals.php, which uses include_once() instead of require(); (2) the $options variable; (3) Admin Upload Image; (4) ->load(); (5) content submissions when frontpage is selected; (6) the mosPageNav constructor; (7) saveOrder functions; (8) the absence of "exploit blocking rules" in htaccess; and (9) the ACL.
|
2006-08-28
|
Joomla! ->load() Content Editor SQL Injection
|
|
28355
Description:
(Description Provided by CVE) : Multiple unspecified vulnerabilities in Joomla! before 1.0.11, related to "Injection Flaws," allow attackers to have an unknown impact via (1) globals.php, which uses include_once() instead of require(); (2) the $options variable; (3) Admin Upload Image; (4) ->load(); (5) content submissions when frontpage is selected; (6) the mosPageNav constructor; (7) saveOrder functions; (8) the absence of "exploit blocking rules" in htaccess; and (9) the ACL.
|
2006-08-28
|
Joomla! Frontpage Content Submission Unspecified Injection
|