| OSVDB ID | Disclosure Date | Title |
|
56353
Description:
(Description Provided by CVE) : Cross-site request forgery (CSRF) vulnerability in index.php in WoltLab Burning Board (wBB) 3.0.1, and possibly other 3.x versions, allows remote attackers to hijack the authentication of users for requests that delete private messages via the pmID parameter in a delete action in a PM page, a different vulnerability than CVE-2008-0472.
|
2008-01-26
|
WoltLab Burning Board index.php Private Message Deletion CSRF
|
|
40692
Description:
(Description Provided by CVE) : Cross-site scripting (XSS) vulnerability in dms/policy/rep_request.php in F5 BIG-IP Application Security Manager (ASM) 9.4.3 allows remote attackers to inject arbitrary web script or HTML via the report_type parameter.
|
2008-01-26
|
F5 BIG-IP Application Security Manager rep_request.php report_type Parameter XSS
|
|
40818
Description:
(Description Provided by CVE) : Multiple cross-site scripting (XSS) vulnerabilities in forum.php in Gerd Tentler Simple Forum 3.2 allow remote attackers to inject arbitrary web script or HTML via the (1) open and (2) date_show parameters.
|
2008-01-26
|
Simple Forum forum.php Multiple Parameter XSS
|
|
40768
Description:
ASPired2Protect contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the login.asp script not properly sanitizing user-supplied input to the 'username' or 'password' variables. This may allow an attacker to inject or manipulate SQL queries in the back-end database.
|
2008-01-26
|
ASPired2Protect login.asp Multiple Parameter SQL Injection
|
|
40819
Description:
(Description Provided by CVE) : Directory traversal vulnerability in thumbnail.php in Gerd Tentler Simple Forum 3.2 allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter.
|
2008-01-26
|
Simple Forum thumbnail.php file Parameter Traversal Arbitrary File Access
|
|
41180
Description:
(Description Provided by CVE) : Multiple directory traversal vulnerabilities in Bubbling Library 1.32 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the (1) uri parameter to (a) yui-menu.tpl.php, (b) simple.tpl.php, and (c) advanced.tpl.php in dispatcher/framework/; and the (2) page parameter to (d) yui-menu.php, (e) simple.php, and (f) advanced.php in dispatcher/framework/, different vectors than CVE-2008-0521.
|
2008-01-26
|
Bubbling Library yui-menu.tpl.php uri Parameter Traversal Local File Inclusion
|
|
41181
Description:
(Description Provided by CVE) : Multiple directory traversal vulnerabilities in Bubbling Library 1.32 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the (1) uri parameter to (a) yui-menu.tpl.php, (b) simple.tpl.php, and (c) advanced.tpl.php in dispatcher/framework/; and the (2) page parameter to (d) yui-menu.php, (e) simple.php, and (f) advanced.php in dispatcher/framework/, different vectors than CVE-2008-0521.
|
2008-01-26
|
Bubbling Library simple.tpl.php uri Parameter Traversal Local File Inclusion
|
|
41182
Description:
(Description Provided by CVE) : Multiple directory traversal vulnerabilities in Bubbling Library 1.32 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the (1) uri parameter to (a) yui-menu.tpl.php, (b) simple.tpl.php, and (c) advanced.tpl.php in dispatcher/framework/; and the (2) page parameter to (d) yui-menu.php, (e) simple.php, and (f) advanced.php in dispatcher/framework/, different vectors than CVE-2008-0521.
|
2008-01-26
|
Bubbling Library advanced.tpl.php uri Parameter Traversal Local File Inclusion
|
|
41183
Description:
(Description Provided by CVE) : Multiple directory traversal vulnerabilities in Bubbling Library 1.32 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the (1) uri parameter to (a) yui-menu.tpl.php, (b) simple.tpl.php, and (c) advanced.tpl.php in dispatcher/framework/; and the (2) page parameter to (d) yui-menu.php, (e) simple.php, and (f) advanced.php in dispatcher/framework/, different vectors than CVE-2008-0521.
|
2008-01-26
|
Bubbling Library yui-menu.php page Parameter Traversal Local File Inclusion
|
|
41184
Description:
(Description Provided by CVE) : Multiple directory traversal vulnerabilities in Bubbling Library 1.32 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the (1) uri parameter to (a) yui-menu.tpl.php, (b) simple.tpl.php, and (c) advanced.tpl.php in dispatcher/framework/; and the (2) page parameter to (d) yui-menu.php, (e) simple.php, and (f) advanced.php in dispatcher/framework/, different vectors than CVE-2008-0521.
|
2008-01-26
|
Bubbling Library simple.php page Parameter Traversal Local File Inclusion
|
|
41185
Description:
(Description Provided by CVE) : Multiple directory traversal vulnerabilities in Bubbling Library 1.32 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the (1) uri parameter to (a) yui-menu.tpl.php, (b) simple.tpl.php, and (c) advanced.tpl.php in dispatcher/framework/; and the (2) page parameter to (d) yui-menu.php, (e) simple.php, and (f) advanced.php in dispatcher/framework/, different vectors than CVE-2008-0521.
|
2008-01-26
|
Bubbling Library advanced.php page Parameter Traversal Local File Inclusion
|
|
50969
Description:
Unknown / Incomplete
|
2008-01-26
|
PhPress sql_phpress.php User Database Disclosure
|
|
42840
Description:
(Description Provided by CVE) : Stack-based buffer overflow in the ClientConnection::NegotiateProtocolVersion function in vncviewer/ClientConnection.cpp in vncviewer for UltraVNC 1.0.2 and 1.0.4 before 01252008, when in LISTENING mode or when using the DSM plugin, allows remote attackers to execute arbitrary code or cause a denial of service (crash) via a modified size value.
|
2008-01-25
|
UltraVNC vncviewer/ClientConnection.cpp ClientConnection::NegotiateProtocolVersion() vncviewer Remote Overflow
|
|
41153
Description:
Patchlink contains a flaw that may allow a malicious local user to overwrite arbitrary files on the system. The issue is due to the script creating temporary files insecurely. It is possible for a local attacker to use a symlink attack to cause the program to unexpectedly write to, or overwrite an attacker specified file.
|
2008-01-25
|
PatchLink Update Client for Unix rebootTask /tmp/plshutdown Symlink Arbitrary File Truncation
|
|
42838
Description:
(Description Provided by CVE) : Xdg-utils 1.0.2 and earlier allows user-assisted remote attackers to execute arbitrary commands via shell metacharacters in a URL argument to (1) xdg-open or (2) xdg-email.
|
2008-01-25
|
Xdg-utils xdg-open URL Argument Arbitrary Command Execution
|
|
42839
Description:
(Description Provided by CVE) : Xdg-utils 1.0.2 and earlier allows user-assisted remote attackers to execute arbitrary commands via shell metacharacters in a URL argument to (1) xdg-open or (2) xdg-email.
|
2008-01-25
|
Xdg-utils xdg-email URL Argument Arbitrary Command Execution
|
|
42536
Description:
(Description Provided by CVE) : SQL injection vulnerability in Mambo LaiThai 4.5.5 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
|
2008-01-25
|
Mambo LaiThai Unspecified SQL Injection
|
|
43227
Description:
General Electric (GE) Proficy Real-Time Information Portal contains a flaw that may lead to an unauthorized password exposure. It is possible for a remote attacker to gain access to base64 encoded passwords when the Web servers are configured to use the Base64 encoded authentication scheme resulting in a loss of confidentiality.
|
2008-01-25
|
General Electric (GE) Proficy Real-Time Information Portal Base64-Encoded Password Disclosure
|
|
40573
Description:
(Description Provided by CVE) : Unspecified vulnerability in metashell before 0.03 has unknown impact and attack vectors related to a "PATH execution security flaw," possibly an untrusted search path vulnerability.
|
2008-01-25
|
metashell PATH Execution Unspecified Issue
|
|
40581
Description:
(Description Provided by CVE) : Multiple cross-site scripting (XSS) vulnerabilities in OpenWebMail before 2.53 (Stable) allow remote attackers to inject arbitrary web script or HTML via unknown vectors.
|
2008-01-25
|
Open WebMail (OWM) Multiple Unspecified XSS
|
|
40697
Description:
CandyPress Store contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the ajax/ajax_getTiers.asp script not properly sanitizing user-supplied input to the 'idcust' parameter. This may allow an attacker to inject or manipulate SQL queries in the back-end database.
|
2008-01-25
|
CandyPress Store ajax/ajax_getTiers.asp idcust Parameter SQL Injection
|
|
40698
Description:
CandyPress Store contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the ajax/ajax_getCust.asp script not properly sanitizing user-supplied input to the 'idcust' parameter. This may allow an attacker to inject or manipulate SQL queries in the back-end database.
|
2008-01-25
|
CandyPress Store ajax/ajax_getCust.asp idcust Parameter SQL Injection
|
|
40699
Description:
CandyPress Store contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the ajax/ajax_getBrands.asp script not properly sanitizing user-supplied input to the 'recid' parameter. This may allow an attacker to inject or manipulate SQL queries in the back-end database.
|
2008-01-25
|
CandyPress Store ajax/ajax_getBrands.asp recid Parameter SQL Injection
|
|
40700
Description:
CandyPress Store contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the ajax/ajax_tableFields.asp script not properly sanitizing user-supplied input to the 'tableName' parameter. This may allow an attacker to inject or manipulate SQL queries in the back-end database.
|
2008-01-25
|
CandyPress Store ajax/ajax_tableFields.asp tableName Parameter SQL Injection
|
|
40701
Description:
CandyPress Store contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the admin/utilities_ConfigHelp.asp script not properly sanitizing user-supplied input to the 'helpfield' parameter. This may allow an attacker to inject or manipulate SQL queries in the back-end database.
|
2008-01-25
|
CandyPress Store admin/utilities_ConfigHelp.asp helpfield Parameter SQL Injection
|
|
40702
Description:
CandyPress Store contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the admin/SA_shipFedExMeter.asp script not properly sanitizing user-supplied input to the 'FedExAccount' parameter. This may allow an attacker to inject or manipulate SQL queries in the back-end database.
|
2008-01-25
|
CandyPress Store admin/SA_shipFedExMeter.asp FedExAccount Parameter SQL Injection
|
|
40703
Description:
CandyPress Store contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the ajax/ajax_optInventory.asp script not properly sanitizing user-supplied input to the 'idProduct' and 'options' parameters. This may allow an attacker to inject or manipulate SQL queries in the back-end database.
|
2008-01-25
|
CandyPress Store ajax/ajax_optInventory.asp Multiple Parameter SQL Injection
|
|
40704
Description:
CandyPress Store contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate 'helpfield' variables upon submission to the admin/utilities_ConfigHelp.asp script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2008-01-25
|
CandyPress Store admin/utilities_ConfigHelp.asp helpfield Parameter XSS
|
|
40762
Description:
(Description Provided by CVE) : Stack-based buffer overflow in the Persits.XUpload.2 ActiveX control in XUpload.ocx 3.0.0.4 and earlier in Persits XUpload 3.0 allows remote attackers to execute arbitrary code via a long argument to the AddFile method. NOTE: some of these details are obtained from third party information.
|
2008-01-25
|
Persits Software XUpload Persits.XUpload.2 ActiveX (XUpload.ocx) AddFile() Method Overflow
|
|
41152
Description:
Patchlink contains a flaw that may allow a malicious local user to overwrite arbitrary files on the system. The issue is due to the script creating temporary files insecurely. It is possible for a local attacker to use a symlink attack to cause the program to unexpectedly write to, or overwrite an attacker specified file.
|
2008-01-25
|
PatchLink Update Client for Unix logtrimmer /tmp/patchlink.tmp Symlink Arbitrary File Truncation
|
|
40923
Description:
(Description Provided by CVE) : SQL injection vulnerability in category.php in Flinx 1.3 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.
|
2008-01-25
|
Flinx category.php id Parameter SQL Injection
|
|
41168
Description:
(Description Provided by CVE) : The NamoInstaller.NamoInstall.1 ActiveX control in NamoInstaller.dll 3.0.0.1 and earlier in Namo Web Editor in Sejoong Namo ActiveSquare 6 allows remote attackers to execute arbitrary code via a URL in the argument to the Install method. NOTE: some of these details are obtained from third party information.
|
2008-01-25
|
Sejoong Namo ActiveSquare6 Namo Web Editor NamoInstaller.NamoInstall ActiveX (NamoInstaller.dll) Install Method Arbitrary Code Execution
|
|
41559
Description:
CandyPress contains a flaw that may lead to an unauthorized information disclosure. The issue is triggered when a malicious user supplies an invalid 'FedExAccount' variable to the admin/SA_shipFedExMeter.asp, which will disclose installation path information resulting in a loss of confidentiality.
|
2008-01-25
|
CandyPress admin/SA_shipFedExMeter.asp FedExAccount Variable Remote Path Disclosure
|
|
74525
Description:
(Description Provided by CVE) : Bugzilla 2.20.x before 2.20.5, 2.22.x before 2.22.3, and 3.0.x before 3.0.3 on Windows does not delete the temporary files associated with uploaded attachments, which allows local users to obtain sensitive information by reading these files, a different vulnerability than CVE-2011-2977.
|
2008-01-25
|
Bugzilla on Windows Uploaded Attachment Temporary File Local Information Disclosure
|
|
53477
Description:
Unknown / Incomplete
|
2008-01-24
|
Movable Type Dynamic Error Template MTErrorMessage Tag XSS
|
|
42039
Description:
(Description Provided by CVE) : Multiple cross-site scripting (XSS) vulnerabilities in ManageEngine Applications Manager 8.1 build 8100 allow remote attackers to inject arbitrary web script or HTML via the (1) showlink parameter to jsp/DiscoveryProfiles.jsp; the (2) attributeIDs, (3) attributeToSelect, (4) redirectto, and (5) resourceid parameters to (a) jsp/ThresholdActionConfiguration.jsp; the (6) page and (7) redirect parameters to (b) jsp/UpdateGlobalSettings.jsp; and the (8) haid and (9) returnpath parameters to (c) showTile.do. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
|
2008-01-24
|
ManageEngine Applications Manager jsp/ThresholdActionConfiguration.jsp Multiple Parameter XSS
|
|
42845
Description:
(Description Provided by CVE) : ActivationHandler in Magnolia CE 3.5.x before 3.5.4 does not check permissions during importing, which allows remote attackers to have an unknown impact via activation of a new item, possibly involving addition of arbitrary new content.
|
2008-01-24
|
Magnolia CE ActivationHandler Importing Permission Weakness Unspecified Issue
|
|
41333
Description:
(Description Provided by CVE) : Unrestricted file upload vulnerability in GE Fanuc Proficy Real-Time Information Portal 2.6 and earlier allows remote attackers to execute arbitrary code by uploading a file with an executable extension to the main virtual directory.
|
2008-01-24
|
General Electric (GE) Fanuc Proficy Real-Time Information Portal Unrestricted File Upload Arbitrary Code Execution
|
|
53183
Description:
Unknown / Incomplete
|
2008-01-24
|
Cisco PIX enable Special Character Handling Privilege Escalation
|
|
42041
Description:
(Description Provided by CVE) : Multiple cross-site scripting (XSS) vulnerabilities in ManageEngine Applications Manager 8.1 build 8100 allow remote attackers to inject arbitrary web script or HTML via the (1) showlink parameter to jsp/DiscoveryProfiles.jsp; the (2) attributeIDs, (3) attributeToSelect, (4) redirectto, and (5) resourceid parameters to (a) jsp/ThresholdActionConfiguration.jsp; the (6) page and (7) redirect parameters to (b) jsp/UpdateGlobalSettings.jsp; and the (8) haid and (9) returnpath parameters to (c) showTile.do. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
|
2008-01-24
|
ManageEngine Applications Manager jsp/DiscoveryProfiles.jsp showlink Parameter XSS
|