| OSVDB ID | Disclosure Date | Title |
|
74993
Description:
HP Insight Diagnostics Online Edition on Linux contains a flaw that allows a remote cross-site scripting (XSS) attack. This flaw exists because the application does not validate the 'testmode' parameter upon submission to the custom.php script. This may allow a user to create a specially crafted URL that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2010-08-30
|
HP Insight Diagnostics Online Edition on Linux custom.php testmode Parameter XSS
|
|
67694
Description:
Maxthon Browser is prone to a flaw in the way it loads dynamic-link libraries (e.g., dwmapi.dll). The program uses a fixed path to look for specific files or libraries. This path includes directories that may not be trusted or under user control. By placing a custom version of the file or library in the path, the program will load it before the legitimate version. This allows an attacker to inject custom code that will be run with the privilege of the program or user executing the program. This can be done by tricking a user into opening a htm, html or mhtml file from the local file system or a USB drive in some cases. This attack can be leveraged remotely in some cases by placing the malicious file or library on a network share or extracted archive downloaded from a remote source.
|
2010-08-29
|
Maxthon Browser Path Subversion Arbitrary DLL Injection Code Execution
|
|
67700
Description:
SnackAmp Music Player is prone to an overflow condition. The program fails to properly sanitize user-supplied input resulting in a stack overflow. With a specially crafted 'SMP' file, a remote attacker can potentially cause arbitrary code excution.
|
2010-08-29
|
SnackAmp Music Player SMP File Handling Overflow
|
|
67689
Description:
Seagull PHP Framework contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the 'index.php/user/password' script not properly sanitizing user-supplied input to the 'frmQuestion' parameter. This may allow an attacker to inject or manipulate SQL queries in the back-end database, allowing for the manipulation or disclosure of arbitrary data.
|
2010-08-29
|
Seagull PHP Framework index.php/user/password frmQuestion Parameter SQL Injection
|
|
67701
Description:
SnackAmp Music Player is prone to an overflow condition. The program fails to properly sanitize user-supplied input resulting in a heap overflow. With a specially crafted 'WAV' file, a remote attacker can potentially cause arbitrary code excution.
|
2010-08-29
|
SnackAmp Music Player WAV File Handling Overflow
|
|
67808
Description:
Multi-lingual E-Commerce System contains a flaw that may allow a remote attacker to execute arbitrary commands or code. The issue is due to the 'inc/checkout2-CYM.php' script not properly sanitizing user input supplied to the 'include_path' parameter. This may allow an attacker to include a file from a third-party remote host that contains commands or code that will be executed by the vulnerable script with the same privileges as the web server.
|
2010-08-29
|
Multi-lingual E-Commerce System inc/checkout2-CYM.php include_path Parameter Remote File Inclusion
|
|
67809
Description:
Multi-lingual E-Commerce System contains a flaw that may allow a remote attacker to execute arbitrary commands or code. The issue is due to the 'inc/checkout2-EN.php' script not properly sanitizing user input supplied to the 'include_path' parameter. This may allow an attacker to include a file from a third-party remote host that contains commands or code that will be executed by the vulnerable script with the same privileges as the web server.
|
2010-08-29
|
Multi-lingual E-Commerce System inc/checkout2-EN.php include_path Parameter Remote File Inclusion
|
|
67810
Description:
Multi-lingual E-Commerce System contains a flaw that may allow a remote attacker to execute arbitrary commands or code. The issue is due to the 'inc/checkout2-FR.php' script not properly sanitizing user input supplied to the 'include_path' parameter. This may allow an attacker to include a file from a third-party remote host that contains commands or code that will be executed by the vulnerable script with the same privileges as the web server.
|
2010-08-29
|
Multi-lingual E-Commerce System inc/checkout2-FR.php include_path Parameter Remote File Inclusion
|
|
67811
Description:
Multi-lingual E-Commerce System contains a flaw that may allow a remote attacker to execute arbitrary commands or code. The issue is due to the 'inc/cat-FR.php' script not properly sanitizing user input supplied to the 'include_path' parameter. This may allow an attacker to include a file from a third-party remote host that contains commands or code that will be executed by the vulnerable script with the same privileges as the web server.
|
2010-08-29
|
Multi-lingual E-Commerce System inc/cat-FR.php include_path Parameter Remote File Inclusion
|
|
67812
Description:
Multi-lingual E-Commerce System contains a flaw that may allow a remote attacker to execute arbitrary commands or code. The issue is due to the 'inc/cat-EN.php' script not properly sanitizing user input supplied to the 'include_path' parameter. This may allow an attacker to include a file from a third-party remote host that contains commands or code that will be executed by the vulnerable script with the same privileges as the web server.
|
2010-08-29
|
Multi-lingual E-Commerce System inc/cat-EN.php include_path Parameter Remote File Inclusion
|
|
67813
Description:
Multi-lingual E-Commerce System contains a flaw that may allow a remote attacker to execute arbitrary commands or code. The issue is due to the 'inc/cat-CYM.php' script not properly sanitizing user input supplied to the 'include_path' parameter. This may allow an attacker to include a file from a third-party remote host that contains commands or code that will be executed by the vulnerable script with the same privileges as the web server.
|
2010-08-29
|
Multi-lingual E-Commerce System inc/cat-CYM.php include_path Parameter Remote File Inclusion
|
|
67814
Description:
Multi-lingual E-Commerce System contains a flaw that may allow a remote attacker to execute arbitrary commands or code. The issue is due to the 'inc/checkout1-CYM.php' script not properly sanitizing user input supplied to the 'include_path' parameter. This may allow an attacker to include a file from a third-party remote host that contains commands or code that will be executed by the vulnerable script with the same privileges as the web server.
|
2010-08-29
|
Multi-lingual E-Commerce System inc/checkout1-CYM.php include_path Parameter Remote File Inclusion
|
|
67815
Description:
Multi-lingual E-Commerce System contains a flaw that may allow a remote attacker to execute arbitrary commands or code. The issue is due to the 'inc/checkout1-EN.php' script not properly sanitizing user input supplied to the 'include_path' parameter. This may allow an attacker to include a file from a third-party remote host that contains commands or code that will be executed by the vulnerable script with the same privileges as the web server.
|
2010-08-29
|
Multi-lingual E-Commerce System inc/checkout1-EN.php include_path Parameter Remote File Inclusion
|
|
67816
Description:
Multi-lingual E-Commerce System contains a flaw that may allow a remote attacker to execute arbitrary commands or code. The issue is due to the 'inc/checkout1-FR.php' script not properly sanitizing user input supplied to the 'include_path' parameter. This may allow an attacker to include a file from a third-party remote host that contains commands or code that will be executed by the vulnerable script with the same privileges as the web server.
|
2010-08-29
|
Multi-lingual E-Commerce System inc/checkout1-FR.php include_path Parameter Remote File Inclusion
|
|
67817
Description:
Multi-lingual E-Commerce System contains a flaw that may allow a remote attacker to execute arbitrary commands or code. The issue is due to the 'inc/prod-CYM.php' script not properly sanitizing user input supplied to the 'include_path' parameter. This may allow an attacker to include a file from a third-party remote host that contains commands or code that will be executed by the vulnerable script with the same privileges as the web server.
|
2010-08-29
|
Multi-lingual E-Commerce System inc/prod-CYM.php include_path Parameter Remote File Inclusion
|
|
67818
Description:
Multi-lingual E-Commerce System contains a flaw that may allow a remote attacker to execute arbitrary commands or code. The issue is due to the 'inc/prod-EN.php' script not properly sanitizing user input supplied to the 'include_path' parameter. This may allow an attacker to include a file from a third-party remote host that contains commands or code that will be executed by the vulnerable script with the same privileges as the web server.
|
2010-08-29
|
Multi-lingual E-Commerce System inc/prod-EN.php include_path Parameter Remote File Inclusion
|
|
67819
Description:
Multi-lingual E-Commerce System contains a flaw that may allow a remote attacker to execute arbitrary commands or code. The issue is due to the 'inc/prod-FR.php' script not properly sanitizing user input supplied to the 'include_path' parameter. This may allow an attacker to include a file from a third-party remote host that contains commands or code that will be executed by the vulnerable script with the same privileges as the web server.
|
2010-08-29
|
Multi-lingual E-Commerce System inc/prod-FR.php include_path Parameter Remote File Inclusion
|
|
68119
Description:
(Description Provided by CVE) : rss.php in UseBB before 1.0.11 does not properly handle forum configurations in which a user has the view permission but not the read permission, which allows remote attackers to bypass intended access restrictions by reading a forum feed in combination with a topic feed.
|
2010-08-29
|
UseBB rss.php Forum / Topic Feed Access Restriction Bypass
|
|
71529
Description:
WebKit contains a flaw that is triggered when handling the 'selectedStylesheetSet' property. With a specially crafted web page, a context-dependent attacker can corrupt memory to cause a denial of service or potentially execute arbitrary code.
|
2010-08-29
|
WebKit selectedStylesheetSet Property Handling Memory Corruption
|
|
67725
Description:
QtWeb Browser is prone to a flaw in the way it loads dynamic-link libraries (e.g. wintab32.dll). The program uses a fixed path to look for specific files or libraries. This path includes directories that may not be trusted or under user control. By placing a custom version of the file or library in the path, the program will load it before the legitimate version. This allows an attacker to inject custom code that will be run with the privilege of the program or user executing the program. This can be done by tricking a user into opening a HTML file from the local file system or a USB drive in some cases. This attack can be leveraged remotely in some cases by placing the malicious file or library on a network share or extracted archive downloaded from a remote source.
|
2010-08-28
|
QtWeb Browser Path Subversion Arbitrary DLL Injection Code Execution
|
|
68079
Description:
(Description Provided by CVE) : Mozilla Firefox before 3.5.14 and 3.6.x before 3.6.11, Thunderbird before 3.0.9 and 3.1.x before 3.1.5, and SeaMonkey before 2.0.9 recognize a wildcard IP address in the subject's Common Name field of an X.509 certificate, which might allow man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority.
|
2010-08-28
|
Mozilla Multiple Products SSL Certificate IP Address Wildcard Matching Weakness
|
|
67585
Description:
DivX Plus Player is prone to a flaw in the way it loads dynamic-link libraries (e.g. VersionCheckDLL.dll in version 7, import\Qt\win32vs05\all\bin\ssleay32.dll in version 8). The program uses a fixed path to look for specific files or libraries. This path includes directories that may not be trusted or under user control. By placing a custom version of the file or library in the path, the program will load it before the legitimate version. This allows an attacker to inject custom code that will be run with the privilege of the program or user executing the program. This can be done by tricking a user into opening an AVI file from the local file system or a USB drive in some cases. This attack can be leveraged remotely in some cases by placing the malicious file or library on a network share or extracted archive downloaded from a remote source.
|
2010-08-28
|
DivX Plus Player Path Subversion Arbitrary DLL Injection Code Execution
|
|
67692
Description:
The vulnerability is caused due to a boundary error in LtocxTwainu.dll when handling the value assigned to the "AppName" property and can be exploited to cause a heap-based buffer overflow via an overly long string. Successful exploitation allows execution of arbitrary code.
|
2010-08-28
|
LEADTOOLS LEAD RasterTwain LtocxTwainu.dll ActiveX AppName Property Overflow
|
|
67690
Description:
GaleriaSHQIP contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the 'index.php' script not properly sanitizing user-supplied input to the 'album_id' parameter. This may allow an attacker to inject or manipulate SQL queries in the back-end database, allowing for the manipulation or disclosure of arbitrary data.
|
2010-08-28
|
GaleriaSHQIP index.php album_id Parameter SQL Injection
|
|
67770
Description:
Unknown / Incomplete
|
2010-08-28
|
TANDBERG MXP Series Endpoint Crafted SNMP Packet Remote DoS
|
|
67800
Description:
Textpattern CMS contains a flaw that may allow a remote attacker to execute arbitrary commands or code. The issue is due to the 'index.php' script not properly sanitizing user input supplied to the 'inc' parameter. This may allow an attacker to include a file from a third-party remote host that contains commands or code that will be executed by the vulnerable script with the same privileges as the web server.
|
2010-08-28
|
Textpattern CMS index.php inc Parameter Remote File Inclusion
|
|
67801
Description:
DiY-CMS contains a flaw that may allow a remote attacker to execute arbitrary commands or code. The issue is due to the 'modules/guestbook/blocks/control.block.php' script not properly sanitizing user input supplied to the 'lang' parameter. This may allow an attacker to include a file from a third-party remote host that contains commands or code that will be executed by the vulnerable script with the same privileges as the web server.
|
2010-08-28
|
DiY-CMS modules/guestbook/blocks/control.block.php lang Parameter Remote File Inclusion
|
|
67802
Description:
DiY-CMS contains a flaw that may allow a remote attacker to execute arbitrary commands or code. The issue is due to the 'index.php' script not properly sanitizing user input supplied to the 'main_module' parameter. This may allow an attacker to include a file from a third-party remote host that contains commands or code that will be executed by the vulnerable script with the same privileges as the web server.
|
2010-08-28
|
DiY-CMS index.php main_module Parameter Remote File Inclusion
|
|
67803
Description:
DiY-CMS contains a flaw that may allow a remote attacker to execute arbitrary commands or code. The issue is due to the 'includes/general.functions.php' script not properly sanitizing user input supplied to the 'getFile' parameter. This may allow an attacker to include a file from a third-party remote host that contains commands or code that will be executed by the vulnerable script with the same privileges as the web server.
|
2010-08-28
|
DiY-CMS includes/general.functions.php getFile Parameter Remote File Inclusion
|
|
68858
Description:
Notepad++ is prone to a flaw in the way it loads dynamic-link libraries (DLL). The program uses a fixed path to look for specific files or libraries. This path includes directories that may not be trusted or under user control. By placing a custom version of the file or library in the path, the program will load it before the legitimate version. This allows an attacker to inject custom code that will be run with the privilege of the program or user executing the program. This can be done by tricking a user into opening a CSS, INC, INF, INI, LOG, SCP, WTX, or SHTML file from the local file system or a USB drive in some cases. This attack can be leveraged remotely in some cases by placing the malicious file or library on a network share or extracted archive downloaded from a remote source.
|
2010-08-28
|
Notepad++ Path Subversion Arbitrary DLL Injection Code Execution
|
|
67580
Description:
PHP Gästebuch Script contains a flaw that may allow a remote attacker to execute arbitrary commands or code. The issue is due to the 'guestbook/gbook.php' script not properly sanitizing user input, specifically directory traversal style attacks (e.g., ../../) supplied to the 'script_pfad' parameter. This may allow an attacker to include a file from the targeted host that contains arbitrary commands or code that will be executed by the vulnerable script. Such attacks are limited due to the script only calling files already on the target host. In addition, this flaw can potentially be used to disclose the contents of any file on the system accessible by the web server.
|
2010-08-27
|
PHP Gästebuch Script guestbook/gbook.php script_pfad Parameter Local File Inclusion
|
|
67776
Description:
Unknown / Incomplete
|
2010-08-27
|
Network Security Services (NSS) Certificate IP Address Wildcard Matching Weakness
|
|
81845
Description:
Cisco Adaptive Security Appliances contains a flaw that allows an attacker to conduct an HTTP response splitting attack. This flaw exists because the application does not validate certain input upon submission to the /+CSCOE+/logon.html script. This could allow a remote attacker to insert arbitrary HTTP headers, which are included in a response sent to the server. If an application does not properly filter such a request, it could be used to inject additional headers that manipulate cookies, authentication status, or more.
|
2010-08-27
|
Cisco Adaptive Security Appliances (ASA) /+CSCOE+/logon.html CRLF Injection HTTP Response Splitting
|
|
67576
Description:
Hycus CMS contains a flaw that allows a remote Cross-site Request Forgery (CSRF / XSRF) attack. The flaw exists because the application does not require multiple steps or explicit confirmation for sensitive transactions such as add an administrative user. By using a crafted URL (e.g., a crafted GET request inside an "img" tag), an attacker may trick the victim into clicking on the image to take advantage of the trust relationship between the authenticated victim and the application. Such an attack could trick the victim into executing arbitrary commands in the context of their session with the application, without further prompting or verification.
|
2010-08-27
|
Hycus CMS Admin User Creation CSRF
|
|
68737
Description:
Adobe Flash Player is prone to a flaw in the way it loads dynamic-link libraries (DLL). The program uses a fixed path to look for specific files or libraries. This path includes directories that may not be trusted or under user control. By placing a custom version of the file or library in the path, the program will load it before the legitimate version. This allows a local attacker to inject custom code that will be run with the privilege of the program or user executing the program. This attack can be leveraged remotely in some cases by placing the malicious file or library on a network share or extracted archive downloaded from a remote source. This can be done by tricking a user into opening a DLL file from the local file system or a USB drive in some cases. This attack scenario is certainly possible, but rare.
|
2010-08-27
|
Adobe Flash Player Path Subversion Arbitrary DLL Injection Code Execution
|
|
70659
Description:
Linux Kernel contains a flaw that may allow a local denial of service. The issue is triggered when fs/exec.c fails to enable the OOM Killer to assess memory use representing the arguments and environment, allowing a local attacker to use a crafted exec system call to cause an 'OOM dodging issue' denial of service.
|
2010-08-27
|
Linux Kernel fs/exec.c Crafted Exec System Call OOM Dodging Local DoS
|
|
67556
Description:
Prometeo CMS contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the 'categoria.php' script not properly sanitizing user-supplied input to the 'ID' parameter. This may allow an attacker to inject or manipulate SQL queries in the back-end database, allowing for the manipulation or disclosure of arbitrary data.
|
2010-08-27
|
Prometeo CMS categoria.php ID Parameter SQL Injection
|
|
67557
Description:
Unknown / Incomplete
|
2010-08-27
|
Remository Component for Mambo / Joomla! Thumbnail Arbitrary File Upload
|
|
67555
Description:
Kontakt Formular contains a flaw that may allow a remote attacker to execute arbitrary commands or code. The issue is due to the 'kontaktformular/formmailer.php' script not properly sanitizing user input, specifically directory traversal style attacks (e.g., ../../) supplied to the 'script_pfad' parameter. This may allow an attacker to include a file from the targeted host that contains arbitrary commands or code that will be executed by the vulnerable script. Such attacks are limited due to the script only calling files already on the target host. In addition, this flaw can potentially be used to disclose the contents of any file on the system accessible by the web server.
|
2010-08-27
|
Kontakt Formular kontaktformular/formmailer.php script_pfad Parameter Traversal Local File Inclusion
|
|
67569
Description:
CMS & News Script light contains a flaw that may allow a remote attacker to execute arbitrary commands or code. The issue is due to the 'news_system/news_base.php' script not properly sanitizing user input supplied to the 'script_pfad' parameter. This may allow an attacker to include a file from a third-party remote host that contains commands or code that will be executed by the vulnerable script with the same privileges as the web server.
|
2010-08-27
|
CMS & News Script light news_system/news_base.php script_pfad Parameter Remote File Inclusion
|