| OSVDB ID | Disclosure Date | Title |
|
57458
Description:
(Description Provided by CVE) : Symantec Altiris Deployment Solution 6.9.x before 6.9 SP3 Build 430 does not properly restrict access to the listening port for the DBManager service, which allows remote attackers to bypass authentication and modify tasks or the Altiris Database via a connection to this service.
|
2009-08-27
|
Symantec Altiris Deployment Solution DBManager Unspecified Authentication Bypass
|
|
57459
Description:
(Description Provided by CVE) : The Aclient GUI in Symantec Altiris Deployment Solution 6.9.x before 6.9 SP3 Build 430 installs a client executable with insecure permissions (Everyone:Full Control), which allows local users to gain privileges by replacing the executable with a Trojan horse program.
|
2009-08-27
|
Symantec Altiris Deployment Solution Aclient GUI Permission Weakness Local Privilege Escalation
|
|
57460
Description:
(Description Provided by CVE) : Unspecified vulnerability in the AClient agent in Symantec Altiris Deployment Solution 6.9.x before 6.9 SP3 Build 430, when key-based authentication is being used between a deployment server and a client, allows remote attackers to bypass authentication and execute arbitrary commands as SYSTEM by spoofing the deployment server and sending "alternate commands" before the handshake is completed.
|
2009-08-27
|
Symantec Altiris Deployment Solution AClient Agent Handshake Race Condition Remote Authentication Bypass
|
|
57461
Description:
(Description Provided by CVE) : Race condition in the file transfer functionality in Symantec Altiris Deployment Solution 6.9.x before 6.9 SP3 Build 430 allows remote attackers to read sensitive files and prevent client updates by connecting to the file transfer port before the expected client does.
|
2009-08-27
|
Symantec Altiris Deployment Solution File Transfer Authentication Bypass
|
|
57425
Description:
(Description Provided by CVE) : Cross-site request forgery (CSRF) vulnerability in bingo!CMS 1.2 and earlier allows remote attackers to hijack the authentication of other users for requests that modify configuration or change content via unspecified vectors.
|
2009-08-27
|
bingo!CMS Configuration Manipulation CSRF
|
|
57426
Description:
(Description Provided by CVE) : Directory traversal vulnerability in gallery/gallery.php in Wap-Motor before 18.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the image parameter.
|
2009-08-27
|
Wap-motor gallery/gallery.php image Parameter Traversal Arbitrary File Access
|
|
57448
Description:
PHP Calendars contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate 'search' parameters upon submission to the 'search.php' script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2009-08-27
|
PHP Calendars search.php search Parameter XSS
|
|
57437
Description:
Stand Alone Arcade contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate 'cat' parameters upon submission to the 'gamelist.php' script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2009-08-27
|
Stand Alone Arcade gamelist.php cat Parameter XSS
|
|
57444
Description:
DigiOz Guestbook contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate 'search_term' parameters upon submission to the 'search.php' script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2009-08-27
|
DigiOz Guestbook search.php search_term Parameter XSS
|
|
57449
Description:
SearchFeed Script contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate 'search' parameters upon submission to the 'index.php' script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2009-08-27
|
SearchFeed Script index.php search Parameter XSS
|
|
57438
Description:
VideoGirls contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate 't' parameters upon submission to the 'forum.php' script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2009-08-27
|
VideoGirls forum.php t Parameter XSS
|
|
57445
Description:
LinkorCMS contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate 'searchstr' parameters upon submission to the 'index.php' script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2009-08-27
|
LinkorCMS index.php Multiple Parameter XSS
|
|
57450
Description:
Auction RSS Content Script contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate 'id' parameters upon submission to the 'rss.php' script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2009-08-27
|
Auction RSS Content Script rss.php id Parameter XSS
|
|
57441
Description:
PHP Video Script contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate 'key' parameters upon submission to the 'index.php' script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2009-08-27
|
PHP Video Script index.php key Parameter XSS
|
|
57446
Description:
Affiliate Master contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate 'search' parameters upon submission to the 'search.php' script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2009-08-27
|
Affiliate Master Datafeed Parser Script search.php search Parameter XSS
|
|
57439
Description:
VideoGirls contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate 'profile_name' parameters upon submission to the 'profile.php' script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2009-08-27
|
VideoGirls profile.php profile_name Parameter XSS
|
|
57440
Description:
VideoGirls contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate 'p' parameters upon submission to the 'view.php' script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2009-08-27
|
VideoGirls view.php p Parameter XSS
|
|
57447
Description:
DigiFolio Component for Joomla contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the 'index.php' script not properly sanitizing user-supplied input to the 'id' parameter. This may allow an attacker to inject or manipulate SQL queries in the back-end database.
|
2009-08-27
|
DigiFolio Component for Joomla! index.php id Parameter SQL Injection
|
|
57464
Description:
Uiga Church Portal contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the index.php script not properly sanitizing user-supplied input to the 'year', 'month', 'name_from', 'email_from', 'telephone', and 'message' parameters. This may allow an attacker to inject or manipulate SQL queries in the back-end database, allowing for the manipulation or disclosure of arbitrary data.
|
2009-08-27
|
Uiga Church Portal index.php Multiple Parameter SQL Injection
|
|
57463
Description:
Pirates of The Caribbean contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the 'index.php' script not properly sanitizing user-supplied input to the 'x' and 'y' parameters. This may allow an attacker to inject or manipulate SQL queries in the back-end database.
|
2009-08-27
|
Pirates of The Caribbean index.php Multiple Parameter SQL Injection
|
|
57451
Description:
Auction RSS Content Script contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate 'id' parameters upon submission to the 'search.php' script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2009-08-27
|
Auction RSS Content Script search.php id Parameter XSS
|
|
57895
Description:
(Description Provided by CVE) : xscreensaver (aka Gnome-XScreenSaver) in Sun Solaris 9 and 10, OpenSolaris snv_109 through snv_122, and X11 6.4.1 on Solaris 8 does not properly handle Accessibility support, which allows local users to cause a denial of service (system hang) by locking the screen and then attempting to launch an Accessibility pop-up window, related to a regression in certain Solaris and OpenSolaris patches.
|
2009-08-27
|
Solaris Gnome-XScreenSaver (xscreensaver) Multiple Method Local Screen Lock DoS
|
|
58111
Description:
Freetag Plugin for Serendipity contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the viewing meta keywords for a blog entry not properly sanitizing user-supplied input to the unspecified parameter. This may allow an attacker to inject or manipulate SQL queries in the back-end database.
|
2009-08-27
|
Freetag Plugin for Serendipity Blog Entry Meta Keywords SQL Injection
|
|
60946
Description:
Unknown / Incomplete
|
2009-08-27
|
MetaForum Ajax Handling Private Thread Post Access
|
|
57467
Description:
RASH Quote Management System contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the Search Functionality not properly sanitizing user-supplied input to the 'search' parameter. This may allow an attacker to inject or manipulate SQL queries in the back-end database.
|
2009-08-26
|
RASH Quote Management System Search Functionality search Parameter SQL Injection
|
|
57468
Description:
RASH Quote Management System contains a flaw that may allow a remote attacker to carry out an SQL injection attack. The issue is due to the 'Admin Login' page not properly sanitizing user-supplied input to the 'user' parameter. This may allow an a remote attacker to inject or manipulate SQL queries in the back-end database.
|
2009-08-26
|
RASH Quote Management System Admin Login user Parameter SQL Injection Authentication Bypass
|
|
57469
Description:
RASH Quote Management System contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the Quote Addition not properly sanitizing user-supplied input to the 'quote' variable. This may allow an attacker to inject or manipulate SQL queries in the back-end database.
|
2009-08-26
|
RASH Quote Management System Quote Addition quote Parameter SQL Injection
|
|
57470
Description:
RASH Quote Management System contains a flaw that may allow a remote attacker to carry out an SQL injection attack. The issue is due to the 'Admin Login' page not properly sanitizing user-supplied input to the 'user' parameter. This may allow an a remote attacker to inject or manipulate SQL queries in the back-end database.
|
2009-08-26
|
RASH Quote Management System User_Name Cookie SQL Injection
|
|
57842
Description:
(Description Provided by CVE) : Cross-site scripting (XSS) vulnerability in the Self Service UI (SSUI) in IBM Tivoli Identity Manager (ITIM) 5.0.0.5 allows remote authenticated users to inject arbitrary web script or HTML via the last name field in a profile.
|
2009-08-26
|
IBM Tivoli Identity Manager Self Service UI Console Profile Change Last Name Field XSS
|
|
57421
Description:
(Description Provided by CVE) : Google V8, as used in Google Chrome before 2.0.172.43, allows remote attackers to bypass intended restrictions on reading memory, and possibly obtain sensitive information or execute arbitrary code in the Chrome sandbox, via crafted JavaScript.
|
2009-08-26
|
Google Chrome V8 Javascript Engine Unspecified Memory Corruption
|
|
57422
Description:
(Description Provided by CVE) : Google Chrome before 2.0.172.43 does not prevent SSL connections to a site with an X.509 certificate signed with the (1) MD2 or (2) MD4 algorithm, which makes it easier for man-in-the-middle attackers to spoof arbitrary HTTPS servers via a crafted certificate, a related issue to CVE-2009-2409.
|
2009-08-26
|
Google Chrome MD2 / MD4 Signed SSL Certificate Spoofing Weakness
|
|
57457
Description:
(Description Provided by CVE) : The sockfs module in the kernel in Sun Solaris 10 and OpenSolaris snv_41 through snv_122, when Network Cache Accelerator (NCA) logging is enabled, allows remote attackers to cause a denial of service (panic) via unspecified web-server traffic that triggers a NULL pointer dereference in the nl7c_http_log function, related to "improper http response handling."
|
2009-08-26
|
Solaris sockfs Kernel Module Unspecified HTTP Requests Remote DoS
|
|
57474
Description:
Unknown / Incomplete
|
2009-08-26
|
TFTPUtil GET Request NULL Dereference Remote DoS
|
|
57489
Description:
Unknown / Incomplete
|
2009-08-26
|
SmartyPaginate Addon for Smarty SmartyPaginate.class.php next Parameter XSS
|
|
57496
Description:
Unknown / Incomplete
|
2009-08-26
|
OpenAutoClassifieds useredit.php Crafted File Upload Arbitrary Code Execution
|
|
57494
Description:
OpenAutoClassifieds contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the 'listings.php' script not properly sanitizing user-supplied input to the 'start_zip' parameter. This may allow an attacker to inject or manipulate SQL queries in the back-end database.
|
2009-08-26
|
OpenAutoClassifieds listings.php start_zip Parameter SQL Injection
|
|
57497
Description:
Open Auto Classifieds contains a flaw that may lead to an unauthorized information disclosure. The issue is triggered when a remote attacker sets interest to 0 in the paycalc form, which will disclose the software's installation path resulting in a loss of confidentiality. While such information is relatively low risk, it is often useful in carrying out additional, more focused attacks.
|
2009-08-26
|
OpenAutoClassifieds paycalc.php interest Parameter Path Disclosure
|
|
57498
Description:
OpenAutoClassifieds contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the 'xml_zone_data.php' script not properly sanitizing user-supplied input to the 'filter' parameter. This may allow an attacker to inject or manipulate SQL queries in the back-end database.
|
2009-08-26
|
OpenAutoClassifieds xml_zone_data.php filter Parameter SQL Injection
|
|
57434
Description:
phpSANE contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to the 'save.php' script not properly sanitizing user input supplied to the 'file_save' parameter. This may allow an attacker to include a file from an arbitrary remote host that contains commands which will be executed by the vulnerable script with the same privileges as the web server.
|
2009-08-26
|
phpSANE save.php file_save Parameter Remote File Inclusion
|
|
57495
Description:
OpenAutoClassifieds contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the 'search.php' script not properly sanitizing user-supplied input to the 'start_zip' parameter. This may allow an attacker to inject or manipulate SQL queries in the back-end database.
|
2009-08-26
|
OpenAutoClassifieds search.php start_zip Parameter SQL Injection
|