| OSVDB ID | Disclosure Date | Title |
|
62613
Description:
The Foursquare mobile application contains a flaw that may lead to an unauthorized information disclosure. The issue is due to the device using HTTP Basic authentication for users to authenticate to the device. When this authentication method is used without the protection of SSL/TLS, the credentials are sent over the network in cleartext. An attacker with access to traffic between the device and user could intercept this information.
|
2010-02-28
|
Foursquare Mobile Application Basic Authentication Weakness
|
|
68279
Description:
webSPELL contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the 'asearch.php' script not properly sanitizing user-supplied input to the 'search' parameter. This may allow an attacker to inject or manipulate SQL queries in the back-end database, allowing for the manipulation or disclosure of arbitrary data.
|
2010-02-28
|
webSPELL asearch.php search Parameter SQL Injection
|
|
62629
Description:
Uiga FanClub contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the 'index.php' script not properly sanitizing user-supplied input to the 'id' parameter. This may allow an attacker to inject or manipulate SQL queries in the back-end database, allowing for the manipulation or disclosure of arbitrary data.
|
2010-02-28
|
Uiga FanClub index.php id Parameter SQL Injection
|
|
62628
Description:
Uiga Personal Portal contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the 'index.php' script not properly sanitizing user-supplied input to the 'id' parameter. This may allow an attacker to inject or manipulate SQL queries in the back-end database, allowing for the manipulation or disclosure of arbitrary data.
|
2010-02-28
|
Uiga Personal Portal index.php id Parameter SQL Injection
|
|
62630
Description:
Uiga FanClub contains a flaw that allows a remote cross site scripting (XSS) attack. This flaw exists because the application does not validate the "admin_name" and "admin_password" parameters upon submission to the 'admin/admin_login.php' script. This may allow a user to create a specially crafted URL that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2010-02-28
|
Uiga FanClub admin/admin_login.php Multiple Parameter XSS
|
|
62667
Description:
Oracle Siebel CRM contains a flaw that allows a remote cross site scripting (XSS) attack. This flaw exists because the application does not validate input passed via the URI upon submission to the 'htim_enu/start.swe' script. This may allow a user to create a specially crafted URL that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2010-02-28
|
Oracle Siebel CRM htim_enu/start.swe URI XSS
|
|
62710
Description:
Comptel Provisioning and Activation contains a flaw that allows a remote cross site scripting (XSS) attack. This flaw exists because the application does not validate the 'error_msg_parameter' parameter upon submission to the 'index.jsp' script. This may allow a user to create a specially crafted URL that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2010-02-28
|
Comptel Provisioning and Activation index.jsp error_msg_parameter Parameter XSS
|
|
62751
Description:
(Description Provided by CVE) : cfnetwork.dll 1.450.5.0 in CFNetwork, as used by safari.exe 531.21.10 in Apple Safari 4.0.3 and 4.0.4 on Windows, allows remote attackers to cause a denial of service (application crash) via a long string in the BACKGROUND attribute of a BODY element.
|
2010-02-28
|
Apple Safari on Windows CFNetwork cfnetwork.dll Multiple Element Remote DoS
|
|
63632
Description:
(Description Provided by CVE) : The ULE decapsulation functionality in drivers/media/dvb/dvb-core/dvb_net.c in dvb-core in Linux kernel 2.6.33 and earlier allows attackers to cause a denial of service (infinite loop) via a crafted MPEG2-TS frame, related to an invalid Payload Pointer ULE.
|
2010-02-28
|
Linux Kernel dvb-core drivers/media/dvb/dvb-core/dvb_net.c ULE Decapsulation Crafted MPEG2-TS Frame DoS
|
|
65129
Description:
(Description Provided by CVE) : Multiple SQL injection vulnerabilities in login.php in HazelPress Lite 0.0.4 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) Username and (2) password fields.
|
2010-02-28
|
HazelPress Lite login.php Multiple Parameter SQL Injection Authentication Bypass
|
|
65132
Description:
Open Education System (OES) contains a flaw that may allow a remote attacker to execute arbitrary commands or code. The issue is due to the 'forum/admin.php' script not properly sanitizing user input supplied to the 'CONF_INCLUDE_PATH' parameter. This may allow an attacker to include a file from a third-party remote host that contains commands or code that will be executed by the vulnerable script with the same privileges as the web server.
|
2010-02-28
|
Open Education System (OES) forum/admin.php CONF_INCLUDE_PATH Parameter Remote File Inclusion
|
|
65133
Description:
Open Education System (OES) contains a flaw that may allow a remote attacker to execute arbitrary commands or code. The issue is due to the 'plotgraph/index.php' script not properly sanitizing user input supplied to the 'CONF_INCLUDE_PATH' parameter. This may allow an attacker to include a file from a third-party remote host that contains commands or code that will be executed by the vulnerable script with the same privileges as the web server.
|
2010-02-28
|
Open Education System (OES) plotgraph/index.php CONF_INCLUDE_PATH Parameter Remote File Inclusion
|
|
65134
Description:
Open Education System (OES) contains a flaw that may allow a remote attacker to execute arbitrary commands or code. The issue is due to the 'admin_user/mod_admuser.php' script not properly sanitizing user input supplied to the 'CONF_INCLUDE_PATH' parameter. This may allow an attacker to include a file from a third-party remote host that contains commands or code that will be executed by the vulnerable script with the same privileges as the web server.
|
2010-02-28
|
Open Education System (OES) admin_user/mod_admuser.php CONF_INCLUDE_PATH Parameter Remote File Inclusion
|
|
65135
Description:
Open Education System (OES) contains a flaw that may allow a remote attacker to execute arbitrary commands or code. The issue is due to the 'ogroup/mod_group.php' script not properly sanitizing user input supplied to the 'CONF_INCLUDE_PATH' parameter. This may allow an attacker to include a file from a third-party remote host that contains commands or code that will be executed by the vulnerable script with the same privileges as the web server.
|
2010-02-28
|
Open Education System (OES) ogroup/mod_group.php CONF_INCLUDE_PATH Parameter Remote File Inclusion
|
|
68280
Description:
webSPELL contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the 'clanwars_details.php' script not properly sanitizing user-supplied input to the 'cwID' parameter. This may allow an attacker to inject or manipulate SQL queries in the back-end database, allowing for the manipulation or disclosure of arbitrary data.
|
2010-02-28
|
webSPELL clanwars_details.php cwID Parameter SQL Injection
|
|
68281
Description:
Unknown / Incomplete
|
2010-02-28
|
webSPELL contact.php Unspecified Parameter Arbitrary Email Address Injection
|
|
68282
Description:
Unknown / Incomplete
|
2010-02-28
|
webSPELL shoutbox_content.php Unspecified Parameter SQL Injection
|
|
62622
Description:
(Description Provided by CVE) : include/userlogin.class.php in DeDeCMS 5.5 GBK, when session.auto_start is enabled, allows remote attackers to bypass authentication and gain administrative access via a value of 1 for the _SESSION[dede_admin_id] parameter, as demonstrated by a request to uploads/include/dialog/select_soft_post.php.
|
2010-02-27
|
DedeCMS include/userlogin.class.php _SESSION[dede_admin_id] Parameter Manipulation Authentication Bypass
|
|
62670
Description:
libpng contains a flaw in the decompression of PNG files that may allow a remote denial of service. The issue is triggered when the 'png_decompress_chunk()' function in pngrutil.c fails to properly decompress certain highly compressed ancillary-chunk data. With a specially crafted PNG file, a context-dependent attacker can cause the system to exhaust the CPU and memory.
|
2010-02-27
|
libpng pngrutil.c png_decompress_chunk Function Ancillary Chunks PNG File Decompression DoS
|
|
62664
Description:
Unknown / Incomplete
|
2010-02-27
|
msn-pecan Multiple Unspecified Issues
|
|
62626
Description:
ScriptsFeed Business Directory Software contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the 'login.php' script not properly sanitizing user-supplied input to the 'us' and 'ps' parameters. This may allow an attacker to inject or manipulate SQL queries in the back-end database, allowing for the manipulation or disclosure of arbitrary data.
|
2010-02-27
|
ScriptsFeed Business Directory Software login.php Multiple Parameter SQL Injection
|
|
63199
Description:
phpMySite contains a flaw that allows a remote cross-site scripting (XSS) attack. This flaw exists because the application does not validate the 'name', 'city', 'email', 'state' and 'message' parameters upon submission to the 'contact.php' script. This may allow a user to create a specially crafted URL that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2010-02-27
|
phpMySite contact.php Multiple Parameter XSS
|
|
63200
Description:
phpMySite contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the 'index.php' script not properly sanitizing user-supplied input to the 'action' parameter. This may allow an attacker to inject or manipulate SQL queries in the back-end database, allowing for the manipulation or disclosure of arbitrary data.
|
2010-02-27
|
phpMySite index.php action Parameter SQL Injection
|
|
63734
Description:
Uiga FanClub contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the admin/admin_login.php script not properly sanitizing user-supplied input to the 'admin_name' and 'admin_password' parameters. This may allow an attacker to inject or manipulate SQL queries in the back-end database, allowing for the manipulation or disclosure of arbitrary data.
|
2010-02-27
|
Uiga FanClub admin/admin_login.php Multiple Parameter SQL Injection
|
|
64105
Description:
phpCDB contains a flaw that may allow a remote attacker to execute arbitrary commands or code. The issue is due to the 'firstvisit.php' script not properly sanitizing user input, specifically directory traversal style attacks (e.g., ../../) supplied to the 'lang_global' parameter. This may allow an attacker to include a file from the targeted host that contains arbitrary commands or code that will be executed by the vulnerable script. Such attacks are limited due to the script only calling files already on the target host. In addition, this flaw can potentially be used to disclose the contents of any file on the system accessible by the web server.
|
2010-02-27
|
phpCDB firstvisit.php lang_global Parameter Traversal Local File Inclusion
|
|
64106
Description:
phpCDB contains a flaw that may allow a remote attacker to execute arbitrary commands or code. The issue is due to the 'newfolder.php' script not properly sanitizing user input, specifically directory traversal style attacks (e.g., ../../) supplied to the 'lang_global' parameter. This may allow an attacker to include a file from the targeted host that contains arbitrary commands or code that will be executed by the vulnerable script. Such attacks are limited due to the script only calling files already on the target host. In addition, this flaw can potentially be used to disclose the contents of any file on the system accessible by the web server.
|
2010-02-27
|
phpCDB newfolder.php lang_global Parameter Traversal Local File Inclusion
|
|
64107
Description:
phpCDB contains a flaw that may allow a remote attacker to execute arbitrary commands or code. The issue is due to the 'showfolders.php' script not properly sanitizing user input, specifically directory traversal style attacks (e.g., ../../) supplied to the 'lang_global' parameter. This may allow an attacker to include a file from the targeted host that contains arbitrary commands or code that will be executed by the vulnerable script. Such attacks are limited due to the script only calling files already on the target host. In addition, this flaw can potentially be used to disclose the contents of any file on the system accessible by the web server.
|
2010-02-27
|
phpCDB showfolders.php lang_global Parameter Traversal Local File Inclusion
|
|
64108
Description:
phpCDB contains a flaw that may allow a remote attacker to execute arbitrary commands or code. The issue is due to the 'newlang.php' script not properly sanitizing user input, specifically directory traversal style attacks (e.g., ../../) supplied to the 'lang_global' parameter. This may allow an attacker to include a file from the targeted host that contains arbitrary commands or code that will be executed by the vulnerable script. Such attacks are limited due to the script only calling files already on the target host. In addition, this flaw can potentially be used to disclose the contents of any file on the system accessible by the web server.
|
2010-02-27
|
phpCDB newlang.php lang_global Parameter Traversal Local File Inclusion
|
|
64109
Description:
phpCDB contains a flaw that may allow a remote attacker to execute arbitrary commands or code. The issue is due to the 'showinnerfolder.php' script not properly sanitizing user input, specifically directory traversal style attacks (e.g., ../../) supplied to the 'lang_global' parameter. This may allow an attacker to include a file from the targeted host that contains arbitrary commands or code that will be executed by the vulnerable script. Such attacks are limited due to the script only calling files already on the target host. In addition, this flaw can potentially be used to disclose the contents of any file on the system accessible by the web server.
|
2010-02-27
|
phpCDB showinnerfolder.php lang_global Parameter Traversal Local File Inclusion
|
|
64110
Description:
phpCDB contains a flaw that may allow a remote attacker to execute arbitrary commands or code. The issue is due to the 'writecode.php' script not properly sanitizing user input, specifically directory traversal style attacks (e.g., ../../) supplied to the 'lang_global' parameter. This may allow an attacker to include a file from the targeted host that contains arbitrary commands or code that will be executed by the vulnerable script. Such attacks are limited due to the script only calling files already on the target host. In addition, this flaw can potentially be used to disclose the contents of any file on the system accessible by the web server.
|
2010-02-27
|
phpCDB writecode.php lang_global Parameter Traversal Local File Inclusion
|
|
64111
Description:
phpCDB contains a flaw that may allow a remote attacker to execute arbitrary commands or code. The issue is due to the 'showcode.php' script not properly sanitizing user input, specifically directory traversal style attacks (e.g., ../../) supplied to the 'lang_global' parameter. This may allow an attacker to include a file from the targeted host that contains arbitrary commands or code that will be executed by the vulnerable script. Such attacks are limited due to the script only calling files already on the target host. In addition, this flaw can potentially be used to disclose the contents of any file on the system accessible by the web server.
|
2010-02-27
|
phpCDB showcode.php lang_global Parameter Traversal Local File Inclusion
|
|
64112
Description:
phpRAINCHECK contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the 'print_raincheck.php' script not properly sanitizing user-supplied input to the 'id' parameter. This may allow an attacker to inject or manipulate SQL queries in the back-end database, allowing for the manipulation or disclosure of arbitrary data.
|
2010-02-27
|
phpRAINCHECK print_raincheck.php id Parameter SQL Injection
|
|
64783
Description:
(Description Provided by CVE) : Unspecified vulnerability in Dovecot 1.2.x before 1.2.11 allows remote attackers to cause a denial of service (CPU consumption) via long headers in an e-mail message.
|
2010-02-27
|
Dovecot E-mail Message Header Unspecified DoS
|
|
65121
Description:
ProMan contains a flaw that may allow a remote attacker to execute arbitrary commands or code. The issue is due to the 'elisttasks.php' script not properly sanitizing user input, specifically directory traversal style attacks (e.g., ../../) supplied to the '_SESSION[userLang]' parameter. This may allow an attacker to include a file from the targeted host that contains arbitrary commands or code that will be executed by the vulnerable script. Such attacks are limited due to the script only calling files already on the target host. In addition, this flaw can potentially be used to disclose the contents of any file on the system accessible by the web server.
|
2010-02-27
|
ProMan elisttasks.php _SESSION[userLang] Parameter Traversal Local File Inclusion
|
|
65122
Description:
ProMan contains a flaw that may allow a remote attacker to execute arbitrary commands or code. The issue is due to the 'managepmanagers.php' script not properly sanitizing user input, specifically directory traversal style attacks (e.g., ../../) supplied to the '_SESSION[userLang]' parameter. This may allow an attacker to include a file from the targeted host that contains arbitrary commands or code that will be executed by the vulnerable script. Such attacks are limited due to the script only calling files already on the target host. In addition, this flaw can potentially be used to disclose the contents of any file on the system accessible by the web server.
|
2010-02-27
|
ProMan managepmanagers.php _SESSION[userLang] Parameter Traversal Local File Inclusion
|
|
65123
Description:
ProMan contains a flaw that may allow a remote attacker to execute arbitrary commands or code. The issue is due to the 'manageusers.php' script not properly sanitizing user input, specifically directory traversal style attacks (e.g., ../../) supplied to the '_SESSION[userLang]' parameter. This may allow an attacker to include a file from the targeted host that contains arbitrary commands or code that will be executed by the vulnerable script. Such attacks are limited due to the script only calling files already on the target host. In addition, this flaw can potentially be used to disclose the contents of any file on the system accessible by the web server.
|
2010-02-27
|
ProMan manageusers.php _SESSION[userLang] Parameter Traversal Local File Inclusion
|
|
65124
Description:
ProMan contains a flaw that may allow a remote attacker to execute arbitrary commands or code. The issue is due to the 'helpfunc.php' script not properly sanitizing user input, specifically directory traversal style attacks (e.g., ../../) supplied to the '_SESSION[userLang]' parameter. This may allow an attacker to include a file from the targeted host that contains arbitrary commands or code that will be executed by the vulnerable script. Such attacks are limited due to the script only calling files already on the target host. In addition, this flaw can potentially be used to disclose the contents of any file on the system accessible by the web server.
|
2010-02-27
|
ProMan helpfunc.php _SESSION[userLang] Parameter Traversal Local File Inclusion
|
|
65125
Description:
ProMan contains a flaw that may allow a remote attacker to execute arbitrary commands or code. The issue is due to the 'managegroups.php' script not properly sanitizing user input, specifically directory traversal style attacks (e.g., ../../) supplied to the '_SESSION[userLang]' parameter. This may allow an attacker to include a file from the targeted host that contains arbitrary commands or code that will be executed by the vulnerable script. Such attacks are limited due to the script only calling files already on the target host. In addition, this flaw can potentially be used to disclose the contents of any file on the system accessible by the web server.
|
2010-02-27
|
ProMan managegroups.php _SESSION[userLang] Parameter Traversal Local File Inclusion
|
|
65126
Description:
ProMan contains a flaw that may allow a remote attacker to execute arbitrary commands or code. The issue is due to the 'manageprocess.php' script not properly sanitizing user input, specifically directory traversal style attacks (e.g., ../../) supplied to the '_SESSION[userLang]' parameter. This may allow an attacker to include a file from the targeted host that contains arbitrary commands or code that will be executed by the vulnerable script. Such attacks are limited due to the script only calling files already on the target host. In addition, this flaw can potentially be used to disclose the contents of any file on the system accessible by the web server.
|
2010-02-27
|
ProMan manageprocess.php _SESSION[userLang] Parameter Traversal Local File Inclusion
|
|
65127
Description:
ProMan contains a flaw that may allow a remote attacker to execute arbitrary commands or code. The issue is due to the 'manageusersgroups.php' script not properly sanitizing user input, specifically directory traversal style attacks (e.g., ../../) supplied to the '_SESSION[userLang]' parameter. This may allow an attacker to include a file from the targeted host that contains arbitrary commands or code that will be executed by the vulnerable script. Such attacks are limited due to the script only calling files already on the target host. In addition, this flaw can potentially be used to disclose the contents of any file on the system accessible by the web server.
|
2010-02-27
|
ProMan manageusersgroups.php _SESSION[userLang] Parameter Traversal Local File Inclusion
|