| OSVDB ID | Disclosure Date | Title |
|
52781
Description:
(Description Provided by CVE) : SQL injection vulnerability in the Tasklist module 5.x-1.x before 5.x-1.3 and 5.x-2.x before 5.x-2.0-alpha1, a module for Drupal, allows remote attackers to execute arbitrary SQL commands via values in the URI.
|
2009-03-18
|
Tasklist Module for Drupal Unspecified SQL Injection
|
|
52813
Description:
Advanced Image Hosting contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the 'gallery_list.php' script not properly sanitizing user-supplied input to the 'gal' parameter. This may allow an attacker to inject or manipulate SQL queries in the back-end database.
|
2009-03-18
|
Advanced Image Hosting gallery_list.php gal Parameter SQL Injection
|
|
52783
Description:
(Description Provided by CVE) : Multiple cross-site scripting (XSS) vulnerabilities in the node edit form feature in Drupal Content Construction Kit (CCK) 6.x before 6.x-2.2, a module for Drupal, allow remote attackers to inject arbitrary web script or HTML via the (1) titles of candidate referenced nodes in the Node reference sub-module and the (2) names of candidate referenced users in the User reference sub-module.
|
2009-03-18
|
Drupal Content Construction Kit (CCK) Node Reference Sub-module Candidate Title XSS
|
|
52782
Description:
(Description Provided by CVE) : Cross-site scripting (XSS) vulnerability in the Tasklist module 5.x-1.x before 5.x-1.3 and 5.x-2.x before 5.x-2.0-alpha1, a module for Drupal, allows remote authenticated users to inject arbitrary web script or HTML via Cascading Style Sheets (CSS).
|
2009-03-18
|
Tasklist Module for Drupal CSS Pages XSS
|
|
52786
Description:
(Description Provided by CVE) : Cross-site request forgery (CSRF) vulnerability in the Plus 1 module before 6.x-2.6, a module for Drupal, allows remote attackers to cast votes for content via unspecified aspects of the URI.
|
2009-03-18
|
Plus 1 Module for Drupal Unspecified CSRF
|
|
52784
Description:
(Description Provided by CVE) : Multiple cross-site scripting (XSS) vulnerabilities in the node edit form feature in Drupal Content Construction Kit (CCK) 6.x before 6.x-2.2, a module for Drupal, allow remote attackers to inject arbitrary web script or HTML via the (1) titles of candidate referenced nodes in the Node reference sub-module and the (2) names of candidate referenced users in the User reference sub-module.
|
2009-03-18
|
Drupal Content Construction Kit (CCK) User Reference Sub-module Candidate Name XSS
|
|
52846
Description:
Unknown / Incomplete
|
2009-03-18
|
Chasys Media Player Multiple Playlist File Handling Overflow
|
|
52852
Description:
(Description Provided by CVE) : Cross-site scripting (XSS) vulnerability in the Send by e-mail module in the "Printer, e-mail and PDF versions" module 5.x before 5.x-4.4 and 6.x before 6.x-1.4, a module for Drupal, allows remote attackers to inject arbitrary web script or HTML via vectors involving outbound HTML e-mail.
|
2009-03-18
|
Send By E-mail Module for Drupal Outbound HTML E-Mail XSS
|
|
52888
Description:
An attacker can execute arbitrary code (possibly gaining control over the machine) by having an end-user click on a malicious URL.
|
2009-03-18
|
Apple Safari on Mac OS X Link Click Unspecified Arbitrary Code Execution (PWN2OWN)
|
|
52892
Description:
(Description Provided by CVE) : Unspecified vulnerability in Microsoft Internet Explorer 8 on Windows 7 allows remote attackers to execute arbitrary code via unknown vectors triggered by clicking on a link, as demonstrated by Nils during a PWN2OWN competition at CanSecWest 2009.
|
2009-03-18
|
Microsoft IE on Windows Link Click Unspecified Arbitrary Code Execution (PWN2OWN)
|
|
52896
Description:
(Description Provided by CVE) : Mozilla Firefox 3.0.7 on Windows 7 allows remote attackers to execute arbitrary code via unknown vectors related to the _moveToEdgeShift XUL tree method, which triggers garbage collection on objects that are still in use, as demonstrated by Nils during a PWN2OWN competition at CanSecWest 2009.
|
2009-03-18
|
Mozilla Firefox on Windows _moveToEdgeShift() XUL Tree Method Garbage Collection Arbitrary Code Execution (PWN2OWN)
|
|
53065
Description:
(Description Provided by CVE) : SQL injection vulnerability in auth2db 0.2.5, and possibly other versions before 0.2.7, uses the addslashes function instead of the mysql_real_escape_string function, which allows remote attackers to conduct SQL injection attacks using multibyte character encodings.
|
2009-03-18
|
auth2db addslashes Function Multibyte Character Encoding SQL Injection
|
|
53479
Description:
(Description Provided by CVE) : The IMAP task in the server in IBM Lotus Domino 8.0.2 before FP1 IF1 and 8.5 before IF3 allows remote attackers to cause a denial of service (daemon crash) via a MIME e-mail message with RFC822 attachments (aka blobs) containing malformed root entities.
|
2009-03-18
|
IBM Lotus Domino IMAP Server RFC822 Attachment Handling DoS
|
|
91911
Description:
Juniper IVE OS Secure Access (SA) contains an unspecified flaw in multiple parameters in the Secure Meeting client that may allow an attacker to have an unspecified impact. No further details have been provided by the vendor.
|
2009-03-18
|
Juniper IVE OS Secure Access (SA) Secure Meeting Client Multiple Parameter Unspecified Issue
|
|
91910
Description:
Juniper IVE OS Secure Access (SA) contains an unspecified flaw in the sign-in page in the Secure Meeting Outlook plugin that may allow an attacker to have an unspecified impact. No further details have been provided by the vendor.
|
2009-03-18
|
Juniper IVE OS Secure Access (SA) Secure Meeting Outlook Plugin Sign-in Page Unspecified Issue
|
|
52713
Description:
(Description Provided by CVE) : Stack-based buffer overflow in wp6sr.dll in the Autonomy KeyView SDK 10.4 and earlier, as used in IBM Lotus Notes, Symantec Mail Security (SMS) products, Symantec BrightMail Appliance products, and Symantec Data Loss Prevention (DLP) products, allows remote attackers to execute arbitrary code via a crafted Word Perfect Document (WPD) file.
|
2009-03-17
|
Autonomy KeyView SDK wp6sr.dll Word Perfect Document Handling Overflow
|
|
52750
Description:
PHP Pro Bid contains a flaw that may allow a remote attacker to execute arbitrary commands or code. The issue is due to the 'includes/class_image.php' script not properly sanitizing user input supplied to the 'fileExtension' parameter. This may allow an attacker to include a file from a third-party remote host that contains commands or code that will be executed by the vulnerable script with the same privileges as the web server.
|
2009-03-17
|
PHP Pro Bid includes/class_image.php fileExtension Parameter Remote File Inclusion
|
|
52770
Description:
phpFoX contains a flaw that allows a remote Cross-Site Request Forgery (CSRF / XSRF) attack. The flaw exists because the application does not require multiple steps and/or confirmation for sensitive transactions for the manipulation of user accounts. By using a crafted URL (e.g. a crafted GET request inside an "img" tag), an attacker may trick the victim into clicking on the image to take advantage of the trust relationship between the authenticated victim and the application. Such an attack could trick the victim into executing arbitrary commands in the context of their session with the application, without further prompting or verification.
|
2009-03-17
|
phpFoX account/settings/account/ Admin Email Address Manipulation CSRF
|
|
52798
Description:
PHPRunner contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the 'UserView_list.php' script not properly sanitizing user-supplied input to the 'SearchField' variable. This may allow an attacker to inject or manipulate SQL queries in the back-end database.
|
2009-03-17
|
PHPRunner UserView_list.php SearchField Parameter SQL Injection
|
|
52789
Description:
YABSoft Mega File Hosting Script contains a flaw that may allow a remote attacker to execute arbitrary commands or code. The issue is due to the 'cross.php' script not properly sanitizing user input supplied to the 'url' parameter. This may allow an attacker to include a file from a third-party remote host that contains commands or code that will be executed by the vulnerable script with the same privileges as the web server.
|
2009-03-17
|
YABSoft Mega File Hosting Script cross.php url Parameter Remote File Inclusion
|
|
52836
Description:
fMoblog Plugin for Wordpress contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the 'index.php' script not properly sanitizing user-supplied input to the 'id' variable. This may allow an attacker to inject or manipulate SQL queries in the back-end database.
|
2009-03-17
|
fMoblog Plugin for Wordpress index.php id Parameter SQL Injection
|
|
52764
Description:
(Description Provided by CVE) : IBM Rational AppScan Enterprise before 5.5 FP1 allows remote attackers to read arbitrary exported reports by "forcefully browsing."
|
2009-03-17
|
IBM Rational AppScan Exported Report Unspecified Information Disclosure
|
|
52797
Description:
(Description Provided by CVE) : Format string vulnerability in Symantec pcAnywhere before 12.5 SP1 allows local users to read and modify arbitrary memory locations, and cause a denial of service (application crash) or possibly have unspecified other impact, via format string specifiers in the pathname of a remote control file (aka .CHF file).
|
2009-03-17
|
Symantec pcAnywhere CHF File Pathname Handling Format String
|
|
52847
Description:
(Description Provided by CVE) : Multiple cross-site request forgery (CSRF) vulnerabilities in the HP Embedded Web Server (EWS) on HP LaserJet Printers, Edgeline Printers, and Digital Senders allow remote attackers to hijack the intranet connectivity of arbitrary users for requests that (1) print documents via unknown vectors, (2) modify the network configuration via a NetIPChange request to hp/device/config_result_YesNo.html/config, or (3) change the password via the Password and ConfirmPassword parameters to hp/device/set_config_password.html/config.
|
2009-03-17
|
HP Embedded Web Server (EWS) Print Documents Unspecified CSRF
|
|
52799
Description:
PHPRunner contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the 'orders_list.php' script not properly sanitizing user-supplied input to the 'SearchField' variable. This may allow an attacker to inject or manipulate SQL queries in the back-end database.
|
2009-03-17
|
PHPRunner orders_list.php SearchField Parameter SQL Injection
|
|
52800
Description:
PHPRunner contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the 'users_list.php' script not properly sanitizing user-supplied input to the 'SearchField' variable. This may allow an attacker to inject or manipulate SQL queries in the back-end database.
|
2009-03-17
|
PHPRunner users_list.php SearchField Parameter SQL Injection
|
|
52801
Description:
PHPRunner contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the 'Administrator_list.php' script not properly sanitizing user-supplied input to the 'SearchField' variable. This may allow an attacker to inject or manipulate SQL queries in the back-end database.
|
2009-03-17
|
PHPRunner Administrator_list.php SearchField Parameter SQL Injection
|
|
52803
Description:
Ganesha Digital Library (GDL) contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the 'gdl.php' script not properly sanitizing user-supplied input to the 'node' parameter. This may allow an attacker to inject or manipulate SQL queries in the back-end database.
|
2009-03-17
|
Ganesha Digital Library (GDL) gdl.php node Parameter SQL Injection
|
|
52804
Description:
(Description Provided by CVE) : UserView_list.php in PHPRunner 4.2, and possibly earlier, stores passwords in cleartext in the database, which allows attackers to gain privileges. NOTE: this can be leveraged with a separate SQL injection vulnerability to obtain passwords remotely without authentication.
|
2009-03-17
|
PHPRunner UserView_list.php Database Cleartext Password Disclosure
|
|
52812
Description:
(Description Provided by CVE) : Buffer overflow in CDex 1.70b2 allows remote attackers to execute arbitrary code via a crafted Info header in an Ogg Vorbis (.ogg) file.
|
2009-03-17
|
CDex Crafted OGG File Info Header Overflow
|
|
52848
Description:
(Description Provided by CVE) : Multiple cross-site request forgery (CSRF) vulnerabilities in the HP Embedded Web Server (EWS) on HP LaserJet Printers, Edgeline Printers, and Digital Senders allow remote attackers to hijack the intranet connectivity of arbitrary users for requests that (1) print documents via unknown vectors, (2) modify the network configuration via a NetIPChange request to hp/device/config_result_YesNo.html/config, or (3) change the password via the Password and ConfirmPassword parameters to hp/device/set_config_password.html/config.
|
2009-03-17
|
HP Embedded Web Server (EWS) hp/device/config_result_YesNo.html/config NetIPChange Request CSRF
|
|
52849
Description:
(Description Provided by CVE) : Multiple cross-site request forgery (CSRF) vulnerabilities in the HP Embedded Web Server (EWS) on HP LaserJet Printers, Edgeline Printers, and Digital Senders allow remote attackers to hijack the intranet connectivity of arbitrary users for requests that (1) print documents via unknown vectors, (2) modify the network configuration via a NetIPChange request to hp/device/config_result_YesNo.html/config, or (3) change the password via the Password and ConfirmPassword parameters to hp/device/set_config_password.html/config.
|
2009-03-17
|
HP Embedded Web Server (EWS) hp/device/set_config_password.html/config Multiple Parameter CSRF
|
|
53263
Description:
Unknown / Incomplete
|
2009-03-17
|
cPanel Standard File Manager Filename XSS
|
|
53264
Description:
Unknown / Incomplete
|
2009-03-17
|
cPanel Legacy File Manager Filename XSS
|
|
64582
Description:
Talkative IRC 0.4.4.16 suffers from a stack based buffer overflow vulnerability that enables us to gain full control over the application and execute arbitrary commands. ECX and EIP registers gets overwriten, so does the SEH. An attacker can exploit this issue by enticing an unsuspecting user into connecting to a malicious IRC server.
|
2009-03-17
|
Talkative IRC Response String Handling Overflow
|
|
89520
Description:
Vino contains a flaw in vino-preferences that is due to the program notifying users that their desktop is only reachable over a local network, which has been reported to be incorrect. This may cause a user to assume their system is more secure than it actually is.
|
2009-03-17
|
Vino vino-preferences Local Network Notification Weakness
|
|
52974
Description:
(Description Provided by CVE) : Unspecified vulnerability in Sun OpenSolaris snv_39 through snv_45, when running in 64-bit mode on x86 architectures, allows local users to cause a denial of service (hang of UFS filesystem write) via unknown vectors related to the (1) ufs_getpage and (2) ufs_putapage routines, aka CR 6442712.
|
2009-03-16
|
OpenSolaris 64-bit UFS Filesystem Functionality ufs_getpage / ufs_putapage Routines Unspecified Local DoS (6442712)
|
|
52973
Description:
(Description Provided by CVE) : Unspecified vulnerability in Sun Solaris 10 on SPARC sun4v systems, and OpenSolaris snv_47 through snv_85, allows local users to cause a denial of service (hang of UFS filesystem write) via unknown vectors related to the (1) ufs_getpage and (2) ufs_putapage routines, aka CR 6425723.
|
2009-03-16
|
Solaris UFS Filesystem Functionality ufs_getpage / ufs_putapage Routines Unspecified Local DoS (6425723)
|
|
52972
Description:
(Description Provided by CVE) : Unspecified vulnerability in the UFS filesystem functionality in Sun OpenSolaris snv_86 through snv_91, when running in 32-bit mode on x86 systems, allows local users to cause a denial of service (panic) via unknown vectors related to the (1) ufs_getpage and (2) ufs_putapage routines, aka CR 6679732.
|
2009-03-16
|
OpenSolaris 32-bit UFS Filesystem Functionality ufs_getpage / ufs_putapage Routines Unspecified Local DoS (6679732)
|
|
52971
Description:
(Description Provided by CVE) : Unspecified vulnerability in Kerberos Incremental Propagation in Solaris 10 and OpenSolaris snv_01 through snv_110 allows remote attackers to cause a denial of service (loss of incremental propagation requests to slave KDC servers) via unknown vectors related to the master Key Distribution Center (KDC) server.
|
2009-03-16
|
Solaris Kerberos Incremental Propagation Master Key Distribution Center (KDC) kpropd.c Full Resynchronization Request Remote DoS
|