| OSVDB ID | Disclosure Date | Title |
|
43594
Description:
(Description Provided by CVE) : Directory traversal vulnerability in wp-db-backup.php in WordPress 2.0.3 and earlier allows remote attackers to read arbitrary files, delete arbitrary files, and cause a denial of service via a .. (dot dot) in the backup parameter in a wp-db-backup.php action to wp-admin/edit.php. NOTE: this might be the same as CVE-2006-5705.1.
|
2008-01-03
|
Wordpress wp-admin/edit.php wp-db-backup.php Action backup Variable Arbitrary File Manipulation
|
|
43549
Description:
(Description Provided by CVE) : WordPress 2.0.11 and earlier allows remote attackers to obtain sensitive information via an empty value of the page parameter to certain PHP scripts under wp-admin/, which reveals the path in various error messages.
|
2008-01-03
|
WordPress wp-admin/ Multiple Script page Variable Error Message Path Disclosure
|
|
43564
Description:
WordPress contains a flaw that allows a remote attacker to access arbitrary files outside of the web path. The issue is due to the /wp-admin/admin.php script not properly sanitizing user input, specifically directory traversal style attacks (../../) supplied via the 'page' or 'import' variables.
|
2008-01-03
|
WordPress /wp-admin/admin.php Multiple Parameter Traversal Arbitrary File Access
|
|
43560
Description:
WordPress contains a flaw that allows a remote attacker to access arbitrary files outside of the web path. The issue is due to the /wp-admin/themes.php script not properly sanitizing user input, specifically directory traversal style attacks (../../) supplied via the 'page' variable.
|
2008-01-03
|
WordPress /wp-admin/themes.php page Parameter Traversal Arbitrary File Access
|
|
43586
Description:
WordPress contains a flaw that allows a remote attacker to access arbitrary files outside of the web path. The issue is due to the /wp-admin/edit.php script not properly sanitizing user input, specifically directory traversal style attacks (../../) supplied via the 'page' variable.
|
2008-01-03
|
WordPress /wp-admin/edit.php page Parameter Traversal Arbitrary File Access
|
|
43572
Description:
WordPress contains a flaw that allows a remote attacker to access arbitrary files outside of the web path. The issue is due to the /wp-admin/templates.php script not properly sanitizing user input, specifically directory traversal style attacks (../../) supplied via the 'page' variable.
|
2008-01-03
|
WordPress /wp-admin/templates.php page Parameter Traversal Arbitrary File Access
|
|
43571
Description:
WordPress contains a flaw that allows a remote attacker to access arbitrary files outside of the web path. The issue is due to the /wp-admin/edit-pages.php script not properly sanitizing user input, specifically directory traversal style attacks (../../) supplied via the 'page' variable.
|
2008-01-03
|
WordPress /wp-admin/edit-pages.php page Parameter Traversal Arbitrary File Access
|
|
43570
Description:
WordPress contains a flaw that allows a remote attacker to access arbitrary files outside of the web path. The issue is due to the /wp-admin/categories.php script not properly sanitizing user input, specifically directory traversal style attacks (../../) supplied via the 'page' variable.
|
2008-01-03
|
WordPress /wp-admin/categories.php page Parameter Traversal Arbitrary File Access
|
|
43565
Description:
WordPress contains a flaw that allows a remote attacker to access arbitrary files outside of the web path. The issue is due to the /wp-admin/edit-comments.php script not properly sanitizing user input, specifically directory traversal style attacks (../../) supplied via the 'page' variable.
|
2008-01-03
|
WordPress /wp-admin/edit-comments.php page Parameter Traversal Arbitrary File Access
|
|
43569
Description:
WordPress contains a flaw that allows a remote attacker to access arbitrary files outside of the web path. The issue is due to the /wp-admin/moderation.php script not properly sanitizing user input, specifically directory traversal style attacks (../../) supplied via the 'page' variable.
|
2008-01-03
|
WordPress /wp-admin/moderation.php page Parameter Traversal Arbitrary File Access
|
|
43568
Description:
WordPress contains a flaw that allows a remote attacker to access arbitrary files outside of the web path. The issue is due to the /wp-admin/post.php script not properly sanitizing user input, specifically directory traversal style attacks (../../) supplied via the 'page' variable.
|
2008-01-03
|
WordPress /wp-admin/post.php page Parameter Traversal Arbitrary File Access
|
|
43577
Description:
WordPress contains a flaw that allows a remote attacker to access arbitrary files outside of the web path. The issue is due to the /wp-admin/page-new.php script not properly sanitizing user input, specifically directory traversal style attacks (../../) supplied via the 'page' variable.
|
2008-01-03
|
WordPress /wp-admin/page-new.php page Parameter Traversal Arbitrary File Access
|
|
43576
Description:
WordPress contains a flaw that allows a remote attacker to access arbitrary files outside of the web path. The issue is due to the /wp-admin/index.php script not properly sanitizing user input, specifically directory traversal style attacks (../../) supplied via the 'page' variable.
|
2008-01-03
|
WordPress /wp-admin/index.php page Parameter Traversal Arbitrary File Access
|
|
43561
Description:
WordPress contains a flaw that allows a remote attacker to access arbitrary files outside of the web path. The issue is due to the /wp-admin/link-manager.php script not properly sanitizing user input, specifically directory traversal style attacks (../../) supplied via the 'page' variable.
|
2008-01-03
|
WordPress /wp-admin/link-manager.php page Parameter Traversal Arbitrary File Access
|
|
43593
Description:
WordPress contains a flaw that allows a remote attacker to access arbitrary files outside of the web path. The issue is due to the /wp-admin/link-add.php script not properly sanitizing user input, specifically directory traversal style attacks (../../) supplied via the 'page' variable.
|
2008-01-03
|
WordPress /wp-admin/link-add.php page Parameter Traversal Arbitrary File Access
|
|
43575
Description:
WordPress contains a flaw that allows a remote attacker to access arbitrary files outside of the web path. The issue is due to the /wp-admin/link-categories.php script not properly sanitizing user input, specifically directory traversal style attacks (../../) supplied via the 'page' variable.
|
2008-01-03
|
WordPress /wp-admin/link-categories.php page Parameter Traversal Arbitrary File Access
|
|
43574
Description:
WordPress contains a flaw that allows a remote attacker to access arbitrary files outside of the web path. The issue is due to the /wp-admin/link-import.php script not properly sanitizing user input, specifically directory traversal style attacks (../../) supplied via the 'page' variable.
|
2008-01-03
|
WordPress /wp-admin/link-import.php page Parameter Traversal Arbitrary File Access
|
|
43573
Description:
WordPress contains a flaw that allows a remote attacker to access arbitrary files outside of the web path. The issue is due to the /wp-admin/theme-editor.php script not properly sanitizing user input, specifically directory traversal style attacks (../../) supplied via the 'page' variable.
|
2008-01-03
|
WordPress /wp-admin/theme-editor.php page Parameter Traversal Arbitrary File Access
|
|
43582
Description:
WordPress contains a flaw that allows a remote attacker to access arbitrary files outside of the web path. The issue is due to the /wp-admin/plugin-editor.php script not properly sanitizing user input, specifically directory traversal style attacks (../../) supplied via the 'page' variable.
|
2008-01-03
|
WordPress /wp-admin/plugin-editor.php page Parameter Traversal Arbitrary File Access
|
|
43566
Description:
WordPress contains a flaw that allows a remote attacker to access arbitrary files outside of the web path. The issue is due to the /wp-admin/profile.php script not properly sanitizing user input, specifically directory traversal style attacks (../../) supplied via the 'page' variable.
|
2008-01-03
|
WordPress /wp-admin/profile.php page Parameter Traversal Arbitrary File Access
|
|
43581
Description:
WordPress contains a flaw that allows a remote attacker to access arbitrary files outside of the web path. The issue is due to the /wp-admin/users.php script not properly sanitizing user input, specifically directory traversal style attacks (../../) supplied via the 'page' variable.
|
2008-01-03
|
WordPress /wp-admin/users.php page Parameter Traversal Arbitrary File Access
|
|
43580
Description:
WordPress contains a flaw that allows a remote attacker to access arbitrary files outside of the web path. The issue is due to the /wp-admin/options-general.php script not properly sanitizing user input, specifically directory traversal style attacks (../../) supplied via the 'page' variable.
|
2008-01-03
|
WordPress /wp-admin/options-general.php page Parameter Traversal Arbitrary File Access
|
|
43578
Description:
WordPress contains a flaw that allows a remote attacker to access arbitrary files outside of the web path. The issue is due to the /wp-admin/options-writing.php script not properly sanitizing user input, specifically directory traversal style attacks (../../) supplied via the 'page' variable.
|
2008-01-03
|
WordPress /wp-admin/options-writing.php page Parameter Traversal Arbitrary File Access
|
|
43585
Description:
WordPress contains a flaw that allows a remote attacker to access arbitrary files outside of the web path. The issue is due to the /wp-admin/options-reading.php script not properly sanitizing user input, specifically directory traversal style attacks (../../) supplied via the 'page' variable.
|
2008-01-03
|
WordPress /wp-admin/options-reading.php page Parameter Traversal Arbitrary File Access
|
|
43562
Description:
WordPress contains a flaw that allows a remote attacker to access arbitrary files outside of the web path. The issue is due to the /wp-admin/options-discussion.php script not properly sanitizing user input, specifically directory traversal style attacks (../../) supplied via the 'page' variable.
|
2008-01-03
|
WordPress /wp-admin/options-discussion.php page Parameter Traversal Arbitrary File Access
|
|
43592
Description:
WordPress contains a flaw that allows a remote attacker to access arbitrary files outside of the web path. The issue is due to the /wp-admin/options-permalink.php script not properly sanitizing user input, specifically directory traversal style attacks (../../) supplied via the 'page' variable.
|
2008-01-03
|
WordPress /wp-admin/options-permalink.php page Parameter Traversal Arbitrary File Access
|
|
43584
Description:
WordPress contains a flaw that allows a remote attacker to access arbitrary files outside of the web path. The issue is due to the /wp-admin/options-misc.php script not properly sanitizing user input, specifically directory traversal style attacks (../../) supplied via the 'page' variable.
|
2008-01-03
|
WordPress /wp-admin/options-misc.php page Parameter Traversal Arbitrary File Access
|
|
43583
Description:
WordPress contains a flaw that allows a remote attacker to access arbitrary files outside of the web path. The issue is due to the /wp-admin/import.php script not properly sanitizing user input, specifically directory traversal style attacks (../../) supplied via the 'page' variable.
|
2008-01-03
|
WordPress /wp-admin/import.php page Parameter Traversal Arbitrary File Access
|
|
43591
Description:
WordPress contains a flaw that allows a remote attacker to access arbitrary files outside of the web path. The issue is due to the /wp-admin/admin.php script not properly sanitizing user input, specifically directory traversal style attacks (../../) supplied via the 'page' variable.
|
2008-01-03
|
WordPress /wp-admin/admin.php page Parameter Traversal Arbitrary File Access
|
|
43590
Description:
WordPress contains a flaw that allows a remote attacker to access arbitrary files outside of the web path. The issue is due to the /wp-admin/bookmarklet.php script not properly sanitizing user input, specifically directory traversal style attacks (../../) supplied via the 'page' variable.
|
2008-01-03
|
WordPress /wp-admin/bookmarklet.php page Parameter Traversal Arbitrary File Access
|
|
43567
Description:
WordPress contains a flaw that allows a remote attacker to access arbitrary files outside of the web path. The issue is due to the /wp-admin/cat-js.php script not properly sanitizing user input, specifically directory traversal style attacks (../../) supplied via the 'page' variable.
|
2008-01-03
|
WordPress /wp-admin/cat-js.php page Parameter Traversal Arbitrary File Access
|
|
43589
Description:
WordPress contains a flaw that allows a remote attacker to access arbitrary files outside of the web path. The issue is due to the /wp-admin/inline-uploading.php script not properly sanitizing user input, specifically directory traversal style attacks (../../) supplied via the 'page' variable.
|
2008-01-03
|
WordPress /wp-admin/inline-uploading.php page Parameter Traversal Arbitrary File Access
|
|
43588
Description:
WordPress contains a flaw that allows a remote attacker to access arbitrary files outside of the web path. The issue is due to the /wp-admin/options.php script not properly sanitizing user input, specifically directory traversal style attacks (../../) supplied via the 'page' variable.
|
2008-01-03
|
WordPress /wp-admin/options.php page Parameter Traversal Arbitrary File Access
|
|
43579
Description:
WordPress contains a flaw that allows a remote attacker to access arbitrary files outside of the web path. The issue is due to the /wp-admin/profile-update.php script not properly sanitizing user input, specifically directory traversal style attacks (../../) supplied via the 'page' variable.
|
2008-01-03
|
WordPress /wp-admin/profile-update.php page Parameter Traversal Arbitrary File Access
|
|
43587
Description:
WordPress contains a flaw that allows a remote attacker to access arbitrary files outside of the web path. The issue is due to the /wp-admin/sidebar.php script not properly sanitizing user input, specifically directory traversal style attacks (../../) supplied via the 'page' variable.
|
2008-01-03
|
WordPress /wp-admin/sidebar.php page Parameter Traversal Arbitrary File Access
|
|
43563
Description:
WordPress contains a flaw that allows a remote attacker to access arbitrary files outside of the web path. The issue is due to the /wp-admin/user-edit.php script not properly sanitizing user input, specifically directory traversal style attacks (../../) supplied via the 'page' variable.
|
2008-01-03
|
WordPress /wp-admin/user-edit.php page Parameter Traversal Arbitrary File Access
|
|
51235
Description:
Unknown / Incomplete
|
2008-01-03
|
w3-msql URI Error Page XSS
|
|
57224
Description:
Unknown / Incomplete
|
2008-01-02
|
FTP Voyager Connection Saver Unspecified Privileged Command Execution
|
|
42765
Description:
(Description Provided by CVE) : Multiple buffer overflows in Georgia SoftWorks SSH2 Server (GSW_SSHD) 7.01.0003 and earlier allow remote attackers to execute arbitrary code via a (1) a long username, which triggers an overflow in the log function; or (2) a long password.
|
2008-01-02
|
Georgia SoftWorks SSH2 Server (GSW_SSHD) Multiple Authentication Fields Remote Overflow
|
|
42766
Description:
(Description Provided by CVE) : Format string vulnerability in the log function in Georgia SoftWorks SSH2 Server (GSW_SSHD) 7.01.0003 and earlier allows remote attackers to execute arbitrary code via format string specifiers in the username field, as demonstrated by a certain LoginPassword message.
|
2008-01-02
|
Georgia SoftWorks SSH2 Server (GSW_SSHD) username Field Remote Format String
|