| OSVDB ID | Disclosure Date | Title |
|
33316
Description:
(Description Provided by CVE) : SQL injection vulnerability in index.php in Francisco Burzi PHP-Nuke 8.0 Final and earlier, when the "HTTP Referers" block is enabled, allows remote attackers to execute arbitrary SQL commands via the HTTP Referer header (HTTP_REFERER variable).
|
2007-02-20
|
PHP-Nuke index.php HTTP referer Header SQL Injection
|
|
36843
Description:
(Description Provided by CVE) : SQL injection vulnerability in page.asp in Design4Online UserPages2 2.0 allows remote attackers to execute arbitrary SQL commands via the art_id parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
|
2007-02-20
|
UserPages2 page.asp art_id Parameter SQL Injection
|
|
42001
Description:
(Description Provided by CVE) : Unspecified vulnerability in Peanut Knowledge Base (PeanutKB) 0.0.3 and earlier has unknown impact and attack vectors.
|
2007-02-20
|
PeanutKB Unspecified Security Issue
|
|
45244
Description:
(Description Provided by CVE) : VMware Workstation 5.5.3 build 34685 does not provide per-user restrictions on certain privileged actions, which allows local users to perform restricted operations such as changing system time, accessing hardware components, and stopping the "VMware tools service" service. NOTE: exploitation is simplified via (1) weak file permisssions (Users = Read & Execute) for %PROGRAMFILES%\VMware; and weak registry key permissions (access by Users) for (2) vmmouse, (3) vmscsi, (4) VMTools, (5) vmx_svga, and (6) vmxnet in HKLM\SYSTEM\CurrentControlSet\Services\; which allows local users to perform various privileged actions outside of the guest OS by executing certain files under %PROGRAMFILES%\VMware\VMware Tools, as demonstrated by (a) VMControlPanel.cpl and (b) vmwareservice.exe.
|
2007-02-19
|
VMWare Workstation Per-user Restriction Weakness Local Privilege Escalation
|
|
32083
Description:
(Description Provided by CVE) : Format string vulnerability in GnomeMeeting 1.0.2 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via format strings in the name, which is not properly handled in a call to the gnomemeeting_log_insert function.
|
2007-02-19
|
GnomeMeeting gnomemeeting_log_insert name Variable Format String
|
|
33245
Description:
(Description Provided by CVE) : SQL injection vulnerability in h_goster.asp in Turuncu Portal 1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
|
2007-02-19
|
Turuncu Portal h_goster.asp id Parameter SQL Injection
|
|
33248
Description:
(Description Provided by CVE) : PHP remote file inclusion vulnerability in tpl/header.php in VirtualSystem VS-News-System 1.2.1 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the newsordner parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
|
2007-02-19
|
VS-News-System tpl/header.php newsordner Parameter Remote File Inclusion
|
|
33535
Description:
(Description Provided by CVE) : Multiple cross-site scripting (XSS) vulnerabilities in Kayako SupportSuite - ESupport 3.00.13 and 3.04.10 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors related to a (1) lostpassword or (2) register action in index.php, (3) unspecified vectors in the Submit form in a submit action in index.php, and (4) the user's name in index.php; and (5) allow remote authenticated users to inject arbitrary web script or HTML via unspecified vectors related to the Admin and Staff Control Panel. NOTE: this might issue overlap CVE-2004-1412, CVE-2005-0487, or CVE-2005-0842.
|
2007-02-19
|
Kayako eSupport index.php Multiple Parameter XSS
|
|
33536
Description:
(Description Provided by CVE) : Multiple cross-site scripting (XSS) vulnerabilities in Kayako SupportSuite - ESupport 3.00.13 and 3.04.10 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors related to a (1) lostpassword or (2) register action in index.php, (3) unspecified vectors in the Submit form in a submit action in index.php, and (4) the user's name in index.php; and (5) allow remote authenticated users to inject arbitrary web script or HTML via unspecified vectors related to the Admin and Staff Control Panel. NOTE: this might issue overlap CVE-2004-1412, CVE-2005-0487, or CVE-2005-0842.
|
2007-02-19
|
Kayako eSupport Admin/Staff Control Panel Unspecified Local XSS
|
|
33251
Description:
(Description Provided by CVE) : Unspecified vulnerability in Distributed Checksum Clearinghouse (DCC) before 1.3.51 allows remote attackers to delete or add hosts in /var/dcc/maps.
|
2007-02-19
|
Distributed Checksum Clearinghouse (DCC) Unauthorized /var/dcc/maps Manipulation
|
|
34854
Description:
A remote overflow exists in Mac OS X. The gifGetBandProc function in the ImageIO library fails to validate GIF image files resulting in an integer overflow. With a specially crafted file, a context-dependent attacker can cause arbitrary code execution resulting in a loss of integrity.
|
2007-02-19
|
Apple Mac OS X ImageIO gifGetBandProc Function GIF Decompression Overflow
|
|
33317
Description:
(Description Provided by CVE) : Multiple cross-site scripting (XSS) vulnerabilities in index.php in AbleDesign MyCalendar allow remote attackers to inject arbitrary web script or HTML via (1) the go parameter, (2) the keyword parameter in the search menu (go=search), or (3) the username or (4) the password in a go=Login action.
|
2007-02-19
|
MyCalendar index.php go Parameter XSS
|
|
33318
Description:
(Description Provided by CVE) : Multiple cross-site scripting (XSS) vulnerabilities in index.php in AbleDesign MyCalendar allow remote attackers to inject arbitrary web script or HTML via (1) the go parameter, (2) the keyword parameter in the search menu (go=search), or (3) the username or (4) the password in a go=Login action.
|
2007-02-19
|
MyCalendar Search Menu keyword Parameter XSS
|
|
33319
Description:
(Description Provided by CVE) : Multiple cross-site scripting (XSS) vulnerabilities in index.php in AbleDesign MyCalendar allow remote attackers to inject arbitrary web script or HTML via (1) the go parameter, (2) the keyword parameter in the search menu (go=search), or (3) the username or (4) the password in a go=Login action.
|
2007-02-19
|
MyCalendar Login Action Multiple Parameter XSS
|
|
32078
Description:
(Description Provided by CVE) : Cross-site scripting (XSS) vulnerability in the AJAX features in index.php in MediaWiki 1.6.x through 1.9.2, when $wgUseAjax is enabled, allows remote attackers to inject arbitrary web script or HTML via a UTF-7 encoded value of the rs parameter, which is processed by Internet Explorer.
|
2007-02-19
|
MediaWiki AJAX Support Module UTF-7 XSS
|
|
33228
Description:
(Description Provided by CVE) : Niels Provos libevent 1.2 and 1.2a allows remote attackers to cause a denial of service (infinite loop) via a DNS response containing a label pointer that references its own offset.
|
2007-02-19
|
libevent Malformed DNS Response DoS
|
|
33226
Description:
(Description Provided by CVE) : Directory traversal vulnerability in news.php in Xpression News (X-News) 1.0.1, when magic_quotes_gpc is disabled, allows remote attackers to include arbitrary files or obtain sensitive information via a .. (dot dot) in the xnews-template parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
|
2007-02-19
|
Xpression News news.php xnews-template Parameter Traversal Arbitrary File Access
|
|
33022
Description:
(Description Provided by CVE) : The Linux kernel 2.6.13 and other versions before 2.6.20.1 allows remote attackers to cause a denial of service (oops) via a crafted NFSACL 2 ACCESS request that triggers a free of an incorrect pointer.
|
2007-02-19
|
Linux Kernel Crafted NFSACL 2 ACCESS Request Remote DoS
|
|
33902
Description:
(Description Provided by CVE) : Integer overflow in Apple QuickTime before 7.1.5 allows remote user-assisted attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted QuickTime movie with a User Data Atom (UDTA) with an Atom size field with a large value.
|
2007-02-19
|
Apple QuickTime Movie User Data Atom (UDTA) Field Overflow
|
|
33905
Description:
(Description Provided by CVE) : Integer overflow in Apple QuickTime before 7.1.5, when installed on Windows operating systems, allows remote user-assisted attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted 3GP video file.
|
2007-02-19
|
Apple QuickTime Crafted 3GP Video File Unspecified Overflow
|
|
33743
Description:
(Description Provided by CVE) : SQL injection vulnerability in view.php in XLAtunes 0.1 and earlier allows remote attackers to execute arbitrary SQL commands via the album parameter in view mode. NOTE: some of these details are obtained from third party information.
|
2007-02-19
|
XLAtunes view.php View Mode album Parameter SQL Injection
|
|
33742
Description:
(Description Provided by CVE) : Apple iTunes 7.0.2 allows user-assisted remote attackers to cause a denial of service (application crash) via a crafted XML list of radio stations, which results in memory corruption. NOTE: iTunes retrieves the XML document from a static URL, which requires an attacker to perform DNS spoofing or man-in-the-middle attacks for exploitation.
|
2007-02-19
|
Apple iTunes Crafted Radio Station XML List DoS
|
|
33741
Description:
(Description Provided by CVE) : Pearson Education PowerSchool 4.3.6 allows remote attackers to list the contents of the admin folder via a URI composed of the admin/ directory name and an arbitrary filename ending in ".js." NOTE: it was later reported that this issue had been addressed by 5.1.2.
|
2007-02-19
|
Powerschool admin/ Crafted Request Forced Directory Listing
|
|
35981
Description:
(Description Provided by CVE) : SQL injection vulnerability in the category file in modules.php in the Emporium 2.3.0 and earlier module for PHP-Nuke allows remote attackers to execute arbitrary SQL commands via the category_id parameter.
|
2007-02-19
|
PHP-Nuke Emporium modules.php category_id SQL Injection
|
|
37343
Description:
(Description Provided by CVE) : Cross-site scripting (XSS) vulnerability in the AJAX features in index.php in MediaWiki 1.9.x before 1.9.0rc2, and 1.8.2 and earlier allows remote attackers to inject arbitrary web script or HTML via the rs parameter. NOTE: this issue might be a duplicate of CVE-2007-0177.
|
2007-02-19
|
MediaWiki AJAX Features index.php rs Parameter XSS
|
|
38906
Description:
(Description Provided by CVE) : Shemes.com Grabit 1.5.3, and possibly earlier, allows remote attackers to cause a denial of service (application crash) via a .nzb file with a subject field containing ';' (semicolon) characters. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
|
2007-02-19
|
Grabit Crafted NZB File Subject Field Remote Application Crash DoS
|
|
53618
Description:
(Description Provided by CVE) : The CCITTFax decoding filter in Ghostscript 8.60, 8.61, and possibly other versions, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted PDF file that triggers a buffer underflow in the cf_decode_2d function.
|
2007-02-19
|
Ghostscript CCITTFax Decoding Filter cf_decode_2d Function PDF File Handling Underflow
|
|
32603
Description:
(Description Provided by CVE) : Unspecified vulnerability in phpMyFAQ 1.6.9 and earlier, when register_globals is enabled, allows remote attackers to "gain the privilege for uploading files on the server."
|
2007-02-18
|
phpMyFAQ admin/attachment.php Arbitrary File Upload
|
|
50180
Description:
(Description Provided by CVE) : Unspecified vulnerability in phpMyFAQ 1.6.9 and earlier, when register_globals is enabled, allows remote attackers to "gain the privilege for uploading files on the server."
|
2007-02-18
|
phpMyFAQ admin/editor/plugins/ImageManager/images.php Arbitrary File Upload
|
|
34241
Description:
Unknown / Incomplete
|
2007-02-18
|
qwik-smtpd main() Function Remote Format String
|
|
33227
Description:
(Description Provided by CVE) : Stack-based buffer overflow in VicFTPS before 5.0 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a long CWD command.
|
2007-02-18
|
VicFTPS CWD Command Handling Overflow
|
|
33225
Description:
(Description Provided by CVE) : Directory traversal vulnerability in archives.php in Xpression News (X-News) 1.0.1 allows remote attackers to include arbitrary files or obtain sensitive information via a .. (dot dot) in the xnews-template parameter.
|
2007-02-18
|
Xpression News archives.php xnews-template Parameter Traversal Arbitrary File Access
|
|
33477
Description:
Unknown / Incomplete
|
2007-02-18
|
PHP HTML Form Generation and Validation Class Unspecified XSS
|
|
33223
Description:
(Description Provided by CVE) : PHP remote file inclusion vulnerability in functions_inc.php in VS-Gastebuch 1.5.3 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the gb_pfad parameter.
|
2007-02-18
|
VS-Gästebuch functions_inc.php gb_pfad Parameter Remote File Inclusion
|
|
33166
Description:
Unknown / Incomplete
|
2007-02-18
|
AXIGEN POP3 Remote Format String
|
|
32094
Description:
A remote overflow exists in Snort. The DCE/RPC Pre-Processor fails to check if traffic is part of a valid TCP session, and multiple "Write AndX" requests can be chained in the same TCP segment resulting in a stack overflow. With a specially crafted SMB packet, an attacker can cause arbitrary code execution resulting in a loss of integrity.
|
2007-02-17
|
Snort DCE/RPC Pre-Processor Packet Reassembly Remote Overflow
|
|
34742
Description:
(Description Provided by CVE) : Buffer overflow in the bufprint function in capiutil.c in libcapi, as used in Linux kernel 2.6.9 to 2.6.20 and isdn4k-utils, allows local users to cause a denial of service (crash) and possibly gain privileges via a crafted CAPI packet.
|
2007-02-17
|
Linux Kernel libcapi capiutil.c bufprint Function CAPI Packet Local DoS
|
|
33478
Description:
Unknown / Incomplete
|
2007-02-17
|
dotProject Multiple Unspecified XSS
|
|
33740
Description:
(Description Provided by CVE) : mAlbum 0.3 has default accounts (1) "login"/"pass" for its administrative account and (2) "dqsfg"/"sdfg", which allows remote attackers to gain privileges.
|
2007-02-17
|
mAlbum Default Administrator Credentials
|
|
33739
Description:
Unknown / Incomplete
|
2007-02-17
|
DotClear index.php blog_dc_path Parameter Remote File Inclusion
|