| OSVDB ID | Disclosure Date | Title |
|
65001
Description:
BF Quiz Component for Joomla! contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the 'index.php' script not properly sanitizing user-supplied input to the 'catid' parameter. This may allow an attacker to inject or manipulate SQL queries in the back-end database, allowing for the manipulation or disclosure of arbitrary data.
|
2010-05-29
|
BF Quiz Component for Joomla! index.php catid Parameter SQL Injection
|
|
65004
Description:
NP_Gallery Plugin for Nucleu contains a flaw that may allow a remote attacker to execute arbitrary commands or code. The issue is due to the 'nucleus/plugins/NP_gallery.php' script not properly sanitizing user input supplied to the 'DIR_NUCLEUS' parameter. This may allow an attacker to include a file from a third-party remote host that contains commands or code that will be executed by the vulnerable script with the same privileges as the web server.
|
2010-05-29
|
NP_Gallery Plugin for Nucleus nucleus/plugins/NP_gallery.php DIR_NUCLEUS Parameter Remote File Inclusion
|
|
65005
Description:
NP_Gallery Plugin for Nucleus contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the 'index.php' script not properly sanitizing user-supplied input to the 'id' parameter. This may allow an attacker to inject or manipulate SQL queries in the back-end database, allowing for the manipulation or disclosure of arbitrary data.
|
2010-05-29
|
NP_Gallery Plugin for Nucleus index.php id Parameter SQL Injection
|
|
65007
Description:
NP_Twitter Plugin for Nucleus contains a flaw that may allow a remote attacker to execute arbitrary commands or code. The issue is due to the 'nucleus/plugins/NP_Twitter.php' script not properly sanitizing user input supplied to the 'DIR_PLUGINS' parameter. This may allow an attacker to include a file from a third-party remote host that contains commands or code that will be executed by the vulnerable script with the same privileges as the web server.
|
2010-05-29
|
NP_Twitter Plugin for Nucleus nucleus/plugins/NP_Twitter.php DIR_PLUGINS Parameter Remote File Inclusion
|
|
65295
Description:
GR Board contains a flaw that may allow a remote attacker to execute arbitrary commands or code. The issue is due to the 'page.php' script not properly sanitizing user input supplied to the 'theme' parameter. This may allow an attacker to include a file from a third-party remote host that contains commands or code that will be executed by the vulnerable script with the same privileges as the web server.
|
2010-05-29
|
GR Board page.php theme Parameter Remote File Inclusion
|
|
65208
Description:
Unknown / Incomplete
|
2010-05-28
|
Heimdal kdc Missing Message Value NULL Dereference DoS
|
|
64994
Description:
ImpressPages CMS contains a flaw that may allow an attacker to carry out SQL injection attacks. The issue is due to the 'admin.php' script not properly sanitizing user-supplied input to the 'page_size[]','sort_field[]' and 'road[]' parameters. This may allow an attacker to inject or manipulate SQL queries in the back-end database, allowing for the manipulation or disclosure of arbitrary data.
|
2010-05-28
|
ImpressPages CMS admin.php Multiple Parameter SQL Injection
|
|
65148
Description:
(Description Provided by CVE) : IBM DB2 9.7 before FP2, when AUTO_REVAL is IMMEDIATE, allows remote authenticated users to cause a denial of service (loss of privileges) to a view owner by defining a dependent view.
|
2010-05-28
|
IBM DB2 Base Object Recreation AUTO_REVAL Configuration System Privilege Regrant Weakness
|
|
65149
Description:
(Description Provided by CVE) : IBM DB2 9.7 before FP2 does not perform the expected access control on the monitor administrative views in the SYSIBMADM schema, which allows remote attackers to obtain sensitive information via unspecified vectors.
|
2010-05-28
|
IBM DB2 SYSIBMADM SCHEMA Monitor Administrative Views Information Disclosure
|
|
76877
Description:
Groone's Simple Contact Form contains a flaw that may allow a remote attacker to execute arbitrary commands or code. The issue is due to the contact/contact.php script not properly sanitizing user input supplied to the 'abspath' parameter. This may allow an attacker to include a file from a third-party remote host that contains commands or code that will be executed by the vulnerable script with the same privileges as the web server.
|
2010-05-28
|
Groone's Simple Contact Form contact/contact.php abspath Parameter Remote File Inclusion
|
|
64982
Description:
MediaWiki contains a flaw that allows a remote cross site scripting (XSS) attack. This flaw exists because the application does not validate the CSS input. This may allow a user to create a specially crafted URL that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2010-05-28
|
MediaWiki CSS Handling XSS
|
|
64983
Description:
MediaWiki contains a flaw that allows a remote Cross-site Request Forgery (CSRF / XSRF) attack. The flaw exists because the application does not require multiple steps or explicit confirmation for sensitive transactions such as create arbitrary users. By using a crafted URL (e.g., a crafted GET request inside an "img" tag), an attacker may trick the victim into clicking on the image to take advantage of the trust relationship between the authenticated victim and the application. Such an attack could trick the victim into executing arbitrary commands in the context of their session with the application, without further prompting or verification.
|
2010-05-28
|
MediaWiki Arbitrary User Creation CSRF
|
|
65000
Description:
My Car Component for Joomla! contains a flaw that allows a remote cross site scripting (XSS) attack. This flaw exists because the application does not validate the 'modveh' parameter upon submission to the 'index.php' script. This may allow a user to create a specially crafted URL that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2010-05-28
|
My Car Component for Joomla! index.php modveh Parameter XSS
|
|
65039
Description:
Visitor Web Stats Module for osCommerce contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the 'index.php' script not properly sanitizing input passed via the 'Accept-Language' HTTP header. This may allow an attacker to inject or manipulate SQL queries in the back-end database, allowing for the manipulation or disclosure of arbitrary data.
|
2010-05-28
|
Visitor Web Stats Module for osCommerce index.php Accept-Language HTTP Header SQL Injection
|
|
65011
Description:
Joomla! contains a flaw that allows a remote cross site scripting (XSS) attack. This flaw exists because the application does not validate the 'search' parameter upon submission to the 'administrator/index.php' script. This may allow a user to create a specially crafted URL that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2010-05-28
|
Joomla! administrator/index.php search Parameter XSS
|
|
64999
Description:
My Car Component for Joomla! contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the 'index.php' script not properly sanitizing user-supplied input to the 'pagina' parameter. This may allow an attacker to inject or manipulate SQL queries in the back-end database, allowing for the manipulation or disclosure of arbitrary data.
|
2010-05-28
|
My Car Component for Joomla! index.php pagina Parameter SQL Injection
|
|
65271
Description:
Unknown / Incomplete
|
2010-05-28
|
Core SFTP Server Multiple Command Long Filename Overflow
|
|
65348
Description:
Groones Simple Contact Form contains a flaw that may allow a remote attacker to execute arbitrary commands or code. The issue is due to the 'contact.php' script not properly sanitizing user input supplied to the 'abspath' parameter. This may allow an attacker to include a file from a third-party remote host that contains commands or code that will be executed by the vulnerable script with the same privileges as the web server.
|
2010-05-28
|
Groones Simple Contact Form contact.php abspath Parameter Remote File Inclusion
|
|
65351
Description:
ArtDesign CMS contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the news.php script not properly sanitizing user-supplied input to the 'id' parameter. This may allow an attacker to inject or manipulate SQL queries in the back-end database, allowing for the manipulation or disclosure of arbitrary data.
|
2010-05-28
|
ArtDesign CMS news.php id Parameter SQL Injection
|
|
64949
Description:
(Description Provided by CVE) : Off-by-one error in the __opiereadrec function in readrec.c in libopie in OPIE 2.4.1-test1 and earlier, as used on FreeBSD 6.4 through 8.1-PRERELEASE and other platforms, allows remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code via a long username, as demonstrated by a long USER command to the FreeBSD 8.0 ftpd.
|
2010-05-27
|
OPIE readrec.c __opiereadrec() Off-by-One Remote Code Execution
|
|
65279
Description:
Cisco Network Building Mediator contains an unspecified flaw that may allow a remote attacker to use a XML RPC or XML RPC over HTTPS request to arbitrarily read and modify device configuration settings, allowing them to escalate their privileges.
|
2010-05-27
|
Cisco Network Building Mediator XML RPC Protocol Unspecified Privilege Escalation
|
|
64936
Description:
MultiShop CMS contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the 'pages.php' script not properly sanitizing user-supplied input to the 'id' parameter. This may allow an attacker to inject or manipulate SQL queries in the back-end database, allowing for the manipulation or disclosure of arbitrary data.
|
2010-05-27
|
MultiShop CMS pages.php id Parameter SQL Injection
|
|
65042
Description:
Unknown / Incomplete
|
2010-05-27
|
Mozilla Firefox window.onerror Error Handling URL Destination Information Disclosure
|
|
64937
Description:
MultiShop CMS contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the 'itemdetail.php' script not properly sanitizing user-supplied input to the 'itemid' parameter. This may allow an attacker to inject or manipulate SQL queries in the back-end database, allowing for the manipulation or disclosure of arbitrary data.
|
2010-05-27
|
MultiShop CMS itemdetail.php itemid Parameter SQL Injection
|
|
64969
Description:
Medi-QnA Component for Joomla! contains a flaw that may allow a remote attacker to execute arbitrary commands or code. The issue is due to the 'index.php' script not properly sanitizing user input, specifically directory traversal style attacks (e.g., ../../) supplied to the 'controller' parameter. This may allow an attacker to include a file from the targeted host that contains arbitrary commands or code that will be executed by the vulnerable script. Such attacks are limited due to the script only calling files already on the target host. In addition, this flaw can potentially be used to disclose the contents of any file on the system accessible by the web server.
|
2010-05-27
|
Medi-QnA Component for Joomla! index.php controller Parameter Traversal Local File Inclusion
|
|
64985
Description:
Core FTP Server contains a flaw that allows a remote attacker to traverse outside of a restricted path. The issue is due to the program not properly sanitizing user input, specifically directory traversal style attacks (e.g., .../) supplied via the CWD command. This directory traversal attack would allow the attacker to access arbitrary files on the file system.
|
2010-05-27
|
Core FTP Server / SFTP Server FTP Command Traversal Arbitrary Directory Access
|
|
64987
Description:
Unknown / Incomplete
|
2010-05-27
|
KCFinder Unspecified Issue
|
|
65152
Description:
(Description Provided by CVE) : jail.c in jail in FreeBSD 8.0 and 8.1-PRERELEASE, when the "-l -U root" options are omitted, does not properly restrict access to the current working directory, which might allow local users to read, modify, or create arbitrary files via standard filesystem operations.
|
2010-05-27
|
FreeBSD jail(8) Descendant Process CWD Escape Arbitrary File Access
|
|
65036
Description:
(Description Provided by CVE) : sys/nfsclient/nfs_vfsops.c in the NFS client in the kernel in FreeBSD 7.2 through 8.1-PRERELEASE, when vfs.usermount is enabled, does not validate the length of a certain fhsize parameter, which allows local users to gain privileges via a crafted mount request.
|
2010-05-27
|
FreeBSD nfsclient nfs_vfsops.c nfs_mount() Function File Handle Buffer Mounting Local Overflow
|
|
65112
Description:
Chrome contains a flaw that may allow a remote denial of service. The issue is triggered when processing a web page containing a large number of invalid NNTP elements, and will result in loss of availability for the application.
|
2010-05-27
|
Google Chrome Invalid news URI IFRAME Element Handling Remote DoS
|
|
65109
Description:
Firefox contains a flaw that may allow a remote denial of service. The issue is triggered when processing a web page containing a large number of invalid NNTP elements, and will result in loss of availability for the application.
|
2010-05-27
|
Mozilla Firefox Invalid news / nntp URI IFRAME Element Handling Remote DoS
|
|
65110
Description:
Internet Explorer contains a flaw that may allow a remote denial of service. The issue is triggered when processing a web page with a large number of invalid NNTP elements, and will result in loss of availability for the application.
|
2010-05-27
|
Microsoft IE Invalid news / nntp URI IFRAME Element Handling Remote DoS
|
|
65111
Description:
Opera contains a flaw that may allow a remote denial of service. The issue is triggered when processing a web page with a large number of invalid NNTP elements, and will result in loss of availability for the application.
|
2010-05-27
|
Opera Invalid news / nntp URI IFRAME Element Handling Remote DoS
|
|
65116
Description:
ClearSite contains a flaw that may allow a remote attacker to execute arbitrary commands or code. The issue is due to the 'docs.php' script not properly sanitizing user input supplied to the 'cs_base_path' parameter. This may allow an attacker to include a file from a third-party remote host that contains commands or code that will be executed by the vulnerable script with the same privileges as the web server.
|
2010-05-27
|
ClearSite docs.php cs_base_path Parameter Remote File Inclusion
|
|
65117
Description:
ClearSite contains a flaw that may allow a remote attacker to execute arbitrary commands or code. The issue is due to the 'include/admin/device_admin.php' script not properly sanitizing user input supplied to the 'cs_base_path' parameter. This may allow an attacker to include a file from a third-party remote host that contains commands or code that will be executed by the vulnerable script with the same privileges as the web server.
|
2010-05-27
|
ClearSite include/admin/device_admin.php cs_base_path Parameter Remote File Inclusion
|
|
73981
Description:
(Description Provided by CVE) : dexdump in Android SDK before 2.3 does not properly perform structural verification, which allows user-assisted remote attackers to cause a denial of service (dexdump crash) and possibly execute arbitrary code via a malformed APK or dex file that calls a method using more arguments than the number of register that have been declared for that method.
|
2010-05-27
|
Android SDK dexdump Structural Verification Method Argument Saturation DoS
|
|
89818
Description:
By default, Dataprobe iBoot-G2 Power Switch installs with default user credentials (username/password combination) for the web interface. The 'admin' account has a password of 'admin' and the 'user' account has a password of 'user', which are publicly known and documented. These allows remote attackers to trivially access the program or system and gain privileged access.
|
2010-05-27
|
Dataprobe iBoot-G2 Power Switch Web Interface Default Admin Credentials
|
|
65280
Description:
(Description Provided by CVE) : Cisco Mediator Framework 1.5.1 before 1.5.1.build.14-eng, 2.2 before 2.2.1.dev.1, and 3.0 before 3.0.9.release.1 on the Cisco Network Building Mediator NBM-2400 and NBM-4800 and the Richards-Zeta Mediator 2500 does not encrypt HTTP sessions from operator workstations, which allows remote attackers to discover Administrator credentials by sniffing the network, aka Bug ID CSCtb83631.
|
2010-05-26
|
Cisco Network Building Mediator HTTP Cleartext Admin Credential Remote Disclosure
|
|
65281
Description:
(Description Provided by CVE) : Cisco Mediator Framework 1.5.1 before 1.5.1.build.14-eng, 2.2 before 2.2.1.dev.1, and 3.0 before 3.0.9.release.1 on the Cisco Network Building Mediator NBM-2400 and NBM-4800 and the Richards-Zeta Mediator 2500 does not encrypt XML RPC sessions from operator workstations, which allows remote attackers to discover Administrator credentials by sniffing the network, aka Bug ID CSCtb83505.
|
2010-05-26
|
Cisco Network Building Mediator XML RPC Cleartext Admin Credential Remote Disclosure
|
|
65282
Description:
(Description Provided by CVE) : Cisco Mediator Framework 1.5.1 before 1.5.1.build.14-eng, 2.2 before 2.2.1.dev.1, and 3.0 before 3.0.9.release.1 on the Cisco Network Building Mediator NBM-2400 and NBM-4800 and the Richards-Zeta Mediator 2500 does not properly restrict network access to an unspecified configuration file, which allows remote attackers to read passwords and unspecified other account details via a (1) XML RPC or (2) XML RPC over HTTPS session, aka Bug ID CSCtb83512.
|
2010-05-26
|
Cisco Network Building Mediator Remote Configuration File Disclosure
|