| OSVDB ID | Disclosure Date | Title |
|
68408
Description:
(Description Provided by CVE) : The Security component in IBM DB2 UDB 9.5 before FP6a logs AUDIT events by using a USERID and an AUTHID value corresponding to the instance owner, instead of a USERID and an AUTHID value corresponding to the logged-in user account, which makes it easier for remote authenticated users to execute Audit administration commands without discovery.
|
2010-05-25
|
IBM DB2 UDB Security Component AUDIT Event Logging User Account Value Weakness Audit Admin Command Execution
|
|
76027
Description:
WebAsyst Shop-Script contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the 'index.php' script not properly sanitizing user-supplied input to the 'blog_id' parameter. This may allow an attacker to inject or manipulate SQL queries in the back-end database, allowing for the manipulation or disclosure of arbitrary data.
|
2010-05-25
|
WebAsyst Shop-Script index.php blog_id Parameter SQL Injection
|
|
64963
Description:
(Description Provided by CVE) : Buffer overflow in Webby Webserver 1.01 allows remote attackers to execute arbitrary code via a long HTTP GET request.
|
2010-05-25
|
Webby Webserver GET Request Remote Overflow
|
|
65066
Description:
(Description Provided by CVE) : The do_gfs2_set_flags function in fs/gfs2/file.c in the Linux kernel before 2.6.34-git10 does not verify the ownership of a file, which allows local users to bypass intended access restrictions via a SETFLAGS ioctl request.
|
2010-05-25
|
Linux Kernel fs/gfs2/file.c do_gfs2_set_flags Function SETFLAGS IOCTL Request Local Access Restriction Bypass
|
|
65120
Description:
NITRO Web Gallery contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the 'index.php' script not properly sanitizing user-supplied input to the 'PictureId' parameter. This may allow an attacker to inject or manipulate SQL queries in the back-end database, allowing for the manipulation or disclosure of arbitrary data.
|
2010-05-25
|
NITRO Web Gallery index.php PictureId Parameter SQL Injection
|
|
65286
Description:
RuubikCMS contains a flaw that allows a remote cross site scripting (XSS) attack. This flaw exists because the application does not validate the 'description' parameter upon submission to the 'index.php' script. This may allow a user to create a specially crafted URL that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2010-05-25
|
RuubikCMS index.php description Parameter XSS
|
|
65355
Description:
360 Web Manager contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the webpages-form-led-edit.php script not properly sanitizing user-supplied input to the 'IDFM' parameter. This may allow an attacker to inject or manipulate SQL queries in the back-end database, allowing for the manipulation or disclosure of arbitrary data.
|
2010-05-25
|
360 Web Manager webpages-form-led-edit.php IDFM Parameter SQL Injection
|
|
65354
Description:
Unknown / Incomplete
|
2010-05-25
|
360 Web Manager /menu/sub-menu-led-01.php IDM Parameter XSS
|
|
65350
Description:
Unknown / Incomplete
|
2010-05-25
|
Flock Browser Memory Corruption Remote DoS
|
|
69922
Description:
IBM Lotus Notes Traveler contains a flaw that may allow a remote denial of service. The issue is triggered when a context-dependent attacker uses a malformed document to cause a denial of service via a sync failure.
|
2010-05-25
|
IBM Lotus Notes Traveler Malformed Document Sync Failure Remote DoS
|
|
64849
Description:
(Description Provided by CVE) : Multiple integer overflows in src/image.c in Ziproxy before 3.0.1 allow remote attackers to execute arbitrary code via (1) a large JPG image, related to the jpg2bitmap function or (2) a large PNG image, related to the png2bitmap function, leading to heap-based buffer overflows.
|
2010-05-24
|
Ziproxy src/image.c jpg2bitmap() Function Overflow
|
|
64850
Description:
(Description Provided by CVE) : Multiple integer overflows in src/image.c in Ziproxy before 3.0.1 allow remote attackers to execute arbitrary code via (1) a large JPG image, related to the jpg2bitmap function or (2) a large PNG image, related to the png2bitmap function, leading to heap-based buffer overflows.
|
2010-05-24
|
Ziproxy src/image.c png2bitmap() Function Overflow
|
|
64919
Description:
razorCMS contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the 'admin/index.php' script not properly sanitizing user-supplied input to the 'content' parameter. This may allow an attacker to inject or manipulate SQL queries in the back-end database, allowing for the manipulation or disclosure of arbitrary data.
|
2010-05-24
|
razorCMS admin/index.php content Parameter XSS
|
|
64832
Description:
McAfee Email Gateway contains a flaw that may allow an attacker to gain access to unauthorized privileges. The issue is triggered by direct access to admin/systemWebAdminConfig.do, allowing a remote attacker to gain administrative privileges.
|
2010-05-24
|
McAfee Email Gateway Web Access admin/systemWebAdminConfig.do Direct Request Authentication Bypass
|
|
64854
Description:
ECShop contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the 'search.php' script not properly sanitizing user-supplied input to the 'encode' parameter. This may allow an attacker to inject or manipulate SQL queries in the back-end database, allowing for the manipulation or disclosure of arbitrary data.
|
2010-05-24
|
ECShop search.php encode Parameter SQL Injection
|
|
64941
Description:
(Description Provided by CVE) : Multiple cross-site request forgery (CSRF) vulnerabilities in the web interface on the Cisco Scientific Atlanta WebSTAR DPC2100R2 cable modem with firmware 2.0.2r1256-060303 allow remote attackers to hijack the authentication of administrators for requests that (1) reset the modem, (2) erase the firmware, (3) change the administrative password, (4) install modified firmware, or (5) change the access level, as demonstrated by a request to goform/_aslvl.
|
2010-05-24
|
Cisco Scientific Atlanta WebSTAR DPC2100R2 goform/_aslvl Multiple CSRF
|
|
64942
Description:
(Description Provided by CVE) : The web interface on the Cisco Scientific Atlanta WebSTAR DPC2100R2 cable modem with firmware 2.0.2r1256-060303 allows remote attackers to bypass authentication, and reset the modem or replace the firmware, via a direct request to an unspecified page.
|
2010-05-24
|
Cisco Scientific Atlanta WebSTAR DPC2100R2 Web Interface Unspecified Page Direct Request Authentication Bypass
|
|
64943
Description:
(Description Provided by CVE) : The web interface on the Cisco Scientific Atlanta WebSTAR DPC2100R2 cable modem with firmware 2.0.2r1256-060303 has a default administrative password (aka SAPassword) of W2402, which makes it easier for remote attackers to obtain privileged access.
|
2010-05-24
|
Cisco Scientific Atlanta WebSTAR DPC2100R2 Web Interface Admin Account Default Password
|
|
65343
Description:
Microsoft Internet Explorer contains a flaw related to ICMFilter. in the CSS filter property. This may allow a remote attacker to access arbitrary UNC files and disclose local passwords.
|
2010-05-24
|
Microsoft IE ICMFilter Arbitrary UNC File Access
|
|
65276
Description:
Zabbix contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the events.php script not properly sanitizing user-supplied input to the 'nav_time' parameter. This may allow an attacker to inject or manipulate SQL queries in the back-end database, allowing for the manipulation or disclosure of arbitrary data.
|
2010-05-24
|
Zabbix events.php nav_time Parameter SQL Injection
|
|
90276
Description:
Apache Axis2 contains a flaw that may lead to unauthorized disclosure of potentially sensitive information. The issue is due to the program storing password information in plaintext in the axis2.xml file, which may allow a local attacker to gain access to such information.
|
2010-05-24
|
Apache Axis2 axis2.xml Plaintext Password Local Disclosure
|
|
64833
Description:
KAVSafe.sys 2010.4.14.609 and earlier, as used in Kingsoft Webshield 3.5.1.2 and earlier contains a flaw that may allow an attacker to gain access to unauthorized privileges. The issue is triggered when an error in the KAVSafe.sys driver occurs, allowing a local attacker to corrupt kernel memory and allow the attacker to gain system privileges in order to execute arbitrary code via a specially crafted 830020D4h IOCTL.
|
2010-05-23
|
Kingsoft WebShield KAVSafe.sys IOCTL Handling Memory Corruption
|
|
65258
Description:
odCMS contains a flaw that allows a remote cross site scripting (XSS) attack. This flaw exists because the application does not validate the 'Page' parameter upon submission to the '_main/index.php' script. This may allow a user to create a specially crafted URL that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2010-05-23
|
odCMS _main/index.php Page Parameter XSS
|
|
65259
Description:
odCMS contains a flaw that allows a remote cross site scripting (XSS) attack. This flaw exists because the application does not validate the 'Page' parameter upon submission to the '_members/index.php' script. This may allow a user to create a specially crafted URL that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2010-05-23
|
odCMS _members/index.php Page Parameter XSS
|
|
65260
Description:
odCMS contains a flaw that allows a remote cross site scripting (XSS) attack. This flaw exists because the application does not validate the 'Page' parameter upon submission to the '_forum/index.php' script. This may allow a user to create a specially crafted URL that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2010-05-23
|
odCMS _forum/index.php Page Parameter XSS
|
|
65261
Description:
odCMS contains a flaw that allows a remote cross site scripting (XSS) attack. This flaw exists because the application does not validate the 'Page' parameter upon submission to the '_docs/index.php' script. This may allow a user to create a specially crafted URL that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2010-05-23
|
odCMS _docs/index.php Page Parameter XSS
|
|
65262
Description:
odCMS contains a flaw that allows a remote cross site scripting (XSS) attack. This flaw exists because the application does not validate the 'Page' parameter upon submission to the '_announcements/index.php' script. This may allow a user to create a specially crafted URL that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2010-05-23
|
odCMS _announcements/index.php Page Parameter XSS
|
|
65263
Description:
odCMS contains a flaw that allows a remote Cross-site Request Forgery (CSRF / XSRF) attack. The flaw exists because the application does not require multiple steps or explicit confirmation for sensitive transactions for the admin password manipulation. By using a crafted URL (e.g., a crafted GET request inside an "img" tag), an attacker may trick the victim into clicking on the image to take advantage of the trust relationship between the authenticated victim and the application. Such an attack could trick the victim into executing arbitrary commands in the context of their session with the application, without further prompting or verification.
|
2010-05-23
|
odCMS Admin Password Manipulation CSRF
|
|
65292
Description:
Unknown / Incomplete
|
2010-05-23
|
CompleteFTP Server PORT Command Remote DoS
|
|
65359
Description:
Unknown / Incomplete
|
2010-05-23
|
JV2 Folder Gallery popup_slideshow.php Multiple Parameter Local File Inclusion
|
|
91751
Description:
Wicd contains a flaw that is due to wicd-daemon.py resetting /etc/resolv.conf to insecure permissions when the program is restarted. This may allow a local attacker to change the content of the file, allowing them to control the server used for DNS resolution. This can greatly assist attacks that require DNS tampering.
|
2010-05-23
|
Wicd wicd-daemon.py /etc/resolv.conf Permission Manipulation Weakness
|
|
64841
Description:
ScriptsFeed Recipes contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the 'control/admin_login.php' script not properly sanitizing user-supplied input to the 'loginid' parameter. This may allow an attacker to inject or manipulate SQL queries in the back-end database, allowing for the manipulation or disclosure of arbitrary data.
|
2010-05-22
|
ScriptsFeed Recipes Listing Portal control/admin_login.php loginid Parameter SQL Injection
|
|
65119
Description:
Cyberhost contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the 'default.asp' script not properly sanitizing user-supplied input to the 'id' parameter. This may allow an attacker to inject or manipulate SQL queries in the back-end database, allowing for the manipulation or disclosure of arbitrary data.
|
2010-05-22
|
Cyberhost default.asp id Parameter SQL Injection
|
|
65384
Description:
BigAce contains a flaw that allows a remote cross site scripting (XSS) attack. This flaw exists because the application does not validate the user-defined input upon submission to the create category module URI. This may allow a user to create a specially crafted URL that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2010-05-22
|
BigAce Create Category Module URI XSS
|
|
65353
Description:
Unknown / Incomplete
|
2010-05-22
|
Ghostscript Startup Sequence CWD Arbitrary Code Execution
|
|
65360
Description:
Unknown / Incomplete
|
2010-05-22
|
Hustoj fckeditor Connector Arbitrary File Upload
|
|
65358
Description:
Unknown / Incomplete
|
2010-05-22
|
DS-Syndicate for Joomla! feed_id Parameter Path Disclosure
|
|
65357
Description:
Unknown / Incomplete
|
2010-05-22
|
DS-Syndicate for Joomla! feed_id Parameter SQL Injection
|
|
65356
Description:
Unknown / Incomplete
|
2010-05-22
|
DS-Syndicate for Joomla! feed_id Parameter Traversal Arbitrary File Overwrite
|
|
65385
Description:
BigAce contains a flaw that allows a remote cross site scripting (XSS) attack. This flaw exists because the application does not validate the user-defined input upon submission to the create style sheet module URI. This may allow a user to create a specially crafted URL that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2010-05-22
|
BigAce Create Style Sheet Module URI XSS
|