| OSVDB ID | Disclosure Date | Title |
|
91925
Description:
Instructure Canvas contains a flaw that allows a remote Cross-site Request Forgery (CSRF / XSRF) attack. The flaw exists because the application does not require multiple steps or explicit confirmation for sensitive transactions for AJAX request calls. By using a crafted URL (e.g., a crafted GET request inside an "img" tag), an attacker may trick the victim into clicking on the image to take advantage of the trust relationship between the authenticated victim and the application. Such an attack could trick the victim into gain access to sensitive information in the context of their session with the application, without further prompting or verification.
|
2011-12-13
|
Instructure Canvas AJAX Request Call Multiple Action CSRF
|
|
77991
Description:
SafeNet Sentinel HASP Run-time Environment contains a flaw that allows a remote cross-site scripting (XSS) attack. This flaw exists because the application does not validate unspecified parameters upon submission to the Sentinel HASP Admin Control Center. This may allow an attacker to create a specially crafted request that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2011-12-12
|
SafeNet Sentinel HASP Admin Control Center Unspecified XSS
|
|
78027
Description:
(Description Provided by CVE) : The ComputePassword function in the Schneider Electric Quantum Ethernet Module on the NOE 771 device (aka the Quantum 140NOE771* module) generates the password for the fwupgrade account by performing a calculation on the MAC address, which makes it easier for remote attackers to obtain access via a (1) ARP request message or (2) Neighbor Solicitation message.
|
2011-12-12
|
Schneider Electric PowerLogic ION / Quantum Ethernet Module fwupgrade Account Insecure Password Generation Multiple Message Parsing Remote Authentication Bypass
|
|
77741
Description:
RSA SecurID Software Token is prone to a flaw in the way it loads dynamic-link libraries (DLL), such as wintab32.dll. The program uses a fixed path to look for specific files or libraries. This path includes directories that may not be trusted or under user control. By placing a custom version of the file or library in the path, the program will load it before the legitimate version. This allows an attacker to inject custom code that will be run with the privilege of the program or user executing the program. This can be done by tricking a user into opening a .sdtid file from the local file system or a USB drive in some cases. This attack can be leveraged remotely in some cases by placing the malicious file or library on a network share or extracted archive downloaded from a remote source.
|
2011-12-12
|
RSA SecurID Software Token Path Subversion Arbitrary DLL Injection Code Execution
|
|
78028
Description:
Schneider Electric Quantum Ethernet Module on the NOE 771 device contains a flaw in the 'modbus_125_handler' function. The issue is triggered when parsing incoming MODBUS requests with a function code of 125. With a specially crafted request, a remote attacker can install an arbitrary firmware update.
|
2011-12-12
|
Schneider Electric Quantum Ethernet Module MODBUS 125 Function Code Parsing Remote Firmware Update Installation
|
|
77638
Description:
(Description Provided by CVE) : Heap-based buffer overflow in the in_mod.dll plugin in Winamp before 5.623 allows remote attackers to execute arbitrary code via crafted song message data in an Impulse Tracker (IT) file. NOTE: some of these details are obtained from third party information.
|
2011-12-12
|
Winamp in_mod.dll Plugin Song Message Data Impulse Tracker (IT) File Handling Remote Overflow
|
|
77690
Description:
(Description Provided by CVE) : EMC RSA Adaptive Authentication On-Premise (AAOP) 6.0.2.1 SP1 Patch 2, SP1 Patch 3, SP2, SP2 Patch 1, and SP3 does not properly implement Device Recovery and Device Identification, which might allow remote attackers to bypass intended security restrictions on a (1) previously non-registered device or (2) registered device by sending unspecified "data elements."
|
2011-12-12
|
RSA Adaptive Authentication On-Premise Data Element Validation Unauthorized Device Recovery
|
|
77691
Description:
(Description Provided by CVE) : EMC RSA Adaptive Authentication On-Premise (AAOP) 6.0.2.1 SP1 Patch 2, SP1 Patch 3, SP2, SP2 Patch 1, and SP3 does not properly perform forensic evaluation upon receipt of device tokens from mobile apps, which might allow remote attackers to bypass intended application restrictions via a mobile device.
|
2011-12-12
|
RSA Adaptive Authentication On-Premise Mobile Device Token Validation Authentication Bypass
|
|
77695
Description:
(Description Provided by CVE) : mappy.py in Splunk Web in Splunk 4.2.x before 4.2.5 does not properly restrict use of the mappy command to access Python classes, which allows remote authenticated administrators to execute arbitrary code by leveraging the sys module in a request to the search application, as demonstrated by a cross-site request forgery (CSRF) attack, aka SPL-45172.
|
2011-12-12
|
Splunk Remote Code Execution CSRF
|
|
78035
Description:
(Description Provided by CVE) : Multiple directory traversal vulnerabilities in Splunk 4.x before 4.2.5 allow remote authenticated users to read arbitrary files via a .. (dot dot) in a URI to (1) Splunk Web or (2) the Splunkd HTTP Server, aka SPL-45243.
|
2011-12-12
|
Splunk Web API Traversal Arbitrary File Access
|
|
77636
Description:
(Description Provided by CVE) : Multiple integer overflows in the in_avi.dll plugin in Winamp before 5.623 allow remote attackers to execute arbitrary code via an AVI file with a crafted value for (1) the number of streams or (2) the size of the RIFF INFO chunk, leading to a heap-based buffer overflow.
|
2011-12-12
|
Winamp in_avi.dll Plugin Stream Header Value Memory Allocation AVI File Handling Remote Overflow
|
|
77637
Description:
(Description Provided by CVE) : Multiple integer overflows in the in_avi.dll plugin in Winamp before 5.623 allow remote attackers to execute arbitrary code via an AVI file with a crafted value for (1) the number of streams or (2) the size of the RIFF INFO chunk, leading to a heap-based buffer overflow.
|
2011-12-12
|
Winamp in_avi.dll Plugin RIFF INFO Chunk Size Memory Allocation AVI File Handling Remote Overflow
|
|
77694
Description:
Splunk contains a flaw that allows a remote cross-site scripting (XSS) attack. This flaw exists because the application does not validate certain unspecified input before returning it to the user. This may allow a user to create a specially crafted URL that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2011-12-12
|
Splunk Unspecified XSS
|
|
77704
Description:
Unknown / Incomplete
|
2011-12-12
|
Squiz Matrix a Parameter Remote Username Enumeration
|
|
88047
Description:
IBM WebSphere Operational Decision Management contains a flaw that allows a remote cross-site scripting (XSS) attack. This flaw exists because the application does not validate input passed via cause messages in the 'RTS Error' page. This may allow a user to create a specially crafted request that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2011-12-12
|
IBM WebSphere Operational Decision Management RTS Error Page Cause Message XSS
|
|
77635
Description:
Family Connections contains a flaw that allows a remote Cross-site Request Forgery (CSRF / XSRF) attack. The flaw exists because the application does not require multiple steps or explicit confirmation for sensitive transactions for the manipulation of the administrator's password. By using a crafted URL (e.g., a crafted GET request inside an "img" tag), an attacker may trick the victim into clicking on the image to take advantage of the trust relationship between the authenticated victim and the application. Such an attack could trick the victim into adding news, "praying for", or changing the administrator password in the context of their session with the application, without further prompting or verification.
|
2011-12-11
|
Family Connections CMS (FCMS) Multiple Function CSRF
|
|
77633
Description:
UPM Polls Plugin for WordPress contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the wp-admin/admin-ajax.php script not properly sanitizing user-supplied input to the 'PID' parameter. This may allow an attacker to inject or manipulate SQL queries in the back-end database, allowing for the manipulation or disclosure of arbitrary data.
|
2011-12-11
|
UPM Polls Plugin for WordPress wp-admin/admin-ajax.php PID Parameter SQL Injection
|
|
83188
Description:
Pixie CMS contains a flaw that allows a remote Cross-site Request Forgery (CSRF / XSRF) attack. The flaw exists because the application does not require multiple steps or explicit confirmation for sensitive transactions. By using a crafted URL (e.g., a crafted GET request inside an "img" tag), an attacker may trick the victim into clicking on the image to take advantage of the trust relationship between the authenticated victim and the application. Such an attack could trick the victim into creating a blog post in the context of their session with the application, without further prompting or verification.
|
2011-12-11
|
Pixie CMS Blog Post CSRF
|
|
83158
Description:
XOOPS contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the admin.php script not properly sanitizing user-supplied input to the 'selgroups' parameter. This may allow an attacker to inject or manipulate SQL queries in the back-end database, allowing for the manipulation or disclosure of arbitrary data.
|
2011-12-11
|
XOOPS admin.php selgroups Parameter SQL Injection
|
|
82593
Description:
PuTTY contains a flaw that may lead to an unauthorized information disclosure. The issue is triggered when session passwords that were stored in the memory during the keyboard-interactive authentication are not properly dumped. This will store passwords within the memory in cleartext until the program stops running, which may disclose password information to a local attacker.
|
2011-12-10
|
PuTTY Session Password Memory Dump Cleartext Local Disclosure
|
|
83196
Description:
Family Connections CMS (FCMS) contains a flaw that allows a remote cross-site scripting (XSS) attack. This flaw exists because the application does not validate input passed via the 'Text Area' field upon submission to the familynews.php script. This may allow a user to create a specially crafted request that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2011-12-10
|
Family Connections CMS (FCMS) familynews.php Text Area Field XSS
|
|
83197
Description:
Family Connections CMS (FCMS) contains a flaw that allows a remote cross-site scripting (XSS) attack. This flaw exists because the application does not validate input passed via the 'Event' field upon submission to the calendar.php script. This may allow a user to create a specially crafted request that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2011-12-10
|
Family Connections CMS (FCMS) calendar.php Event Field XSS
|
|
77600
Description:
Power2Go 8, and possibly prior versions, fails to perform adequate boundary checks on user-supplied input when parsing malformed project (.p2g) files causing a stack-based buffer overflow leading to possible remote code execution.
|
2011-12-10
|
CyberLink Power2Go Project Editor Filename Field P2G File Handling Overflow
|
|
77639
Description:
RocksnDiamonds contains a flaw that may allow a malicious local user to overwrite arbitrary files on the system. The issue is due to the program creating the ~/.rocksndiamonds/ directory as world writable. It is possible for a local attacker to use a symlink attack to cause the program to unexpectedly write to, or overwrite an attacker specified file.
|
2011-12-10
|
RocksnDiamonds ~/.rocksndiamonds/ Directory Symlink Arbitrary File Overwrite
|
|
77780
Description:
(Description Provided by CVE) : ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.
|
2011-12-10
|
Linux Kernel B.A.T.M.A.N. net/batman/icmp_socket.c bat_socket_read() Packet Parsing Remote Overflow
|
|
83198
Description:
Family Connections CMS (FCMS) contains a flaw that allows a remote cross-site scripting (XSS) attack. This flaw exists because the application does not validate input passed via the 'Name' field upon submission to the recipes.php script. This may allow a user to create a specially crafted request that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2011-12-10
|
Family Connections CMS (FCMS) recipes.php Name Field XSS
|
|
83189
Description:
Linux Kernel on MIPS contains a flaw that may allow a denial of service. The issue is triggered when an unspecified error occurs, and will result in loss of availability for the system. No further details have been provided.
|
2011-12-10
|
Linux Kernel on MIPS Unspecified Reboot Local DoS
|
|
77580
Description:
HitAppoint contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the index.php script not properly sanitizing user-supplied input to the 'username' parameter. This may allow an attacker to inject or manipulate SQL queries in the back-end database, allowing for the manipulation or disclosure of arbitrary data.
|
2011-12-09
|
HitAppoint index.php username Parameter SQL Injection
|
|
81844
Description:
Cisco Carrier Routing System contains a flaw that may allow a remote denial of service. The issue is triggered when parsing GRE packets, and will result in loss of availability for the product.
|
2011-12-09
|
Cisco Carrier Routing System GRE Packet Parsing Remote DoS
|
|
77594
Description:
FFFTP is prone to a flaw in the way it loads dynamic-link libraries (DLL). The program uses a fixed path to look for specific files or libraries. This path includes directories that may not be trusted or under user control. By placing a custom version of the file or library in the path, the program will load it before the legitimate version. This allows an attacker to inject custom code that will be run with the privilege of the program or user executing the program. This can be done by tricking a user into opening a file from the local file system or a USB drive in some cases. This attack can be leveraged remotely in some cases by placing the malicious file or library on a network share or extracted archive downloaded from a remote source.
|
2011-12-09
|
FFFTP readme.exe Path Subversion Executable File Injection Code Execution
|
|
77940
Description:
HTML::Template::Pro contains a flaw that allows a remote cross-site scripting (XSS) attack. This flaw exists because the application does not validate input passed via template parameters before returning it to the user. This may allow a user to create a specially crafted URL that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2011-12-09
|
HTML::Template::Pro Template Parameters XSS
|
|
83190
Description:
Free Opener contains a flaw that may allow for a denial of service. The issue is triggered when a user opens a malformed JPG file, resulting in a loss of availability for the program. This can be exploited remotely by tricking a user into opening the crafted file (e.g., via email), or locally by placing it in a location that may seem safe (e.g., a network share).
|
2011-12-09
|
Free Opener Malformed JPG Handling DoS
|
|
77591
Description:
Unknown / Incomplete
|
2011-12-09
|
SePortal redirect.php goto Parameter SQL Injection
|
|
77601
Description:
WaveEditor 2, and possibly prior versions, fails to perform adequate boundary checks on user-supplied input when parsing malformed project (.wve) files causing a stack-based buffer overflow leading to possible remote code execution. WaveEditor will also included on Power2Go and PowerDirector installation.
|
2011-12-09
|
CyberLink WaveEditor Project Editor Filename Field WVE File Handling Overflow
|
|
77632
Description:
Unknown / Incomplete
|
2011-12-09
|
DoceboLMS index.php message[attach] Parameter File Upload Remote PHP Code Execution
|
|
77643
Description:
ClassifiedsGeek Pet Listing contains a flaw that allows a remote cross-site scripting (XSS) attack. This flaw exists because the application does not validate the 'bedroom_from' parameter upon submission to the preview.php script. This may allow a user to create a specially crafted URL that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2011-12-09
|
ClassifiedsGeek Pet Listing preview.php bedroom_from Parameter XSS
|
|
78088
Description:
(Description Provided by CVE) : Stack-based buffer overflow in CFS.c in ConfigServer Security & Firewall (CSF) before 5.43, when running on a DirectAdmin server, allows local users to cause a denial of service (crash) via a long string in an admin.list file.
|
2011-12-09
|
ConfigServer Security & Firewall CFS.c admin.list File Handling Remote Overflow
|
|
78286
Description:
Siemens Tecnomatix FactoryLink contains a flaw in the ActBar.ocx ActiveX control. The issue is triggered when user-supplied input is passed as argument to the 'Save' method. With a specially crafted web page, a context-dependent attacker can write arbitrary file content to an arbitrary location on the system.
|
2011-12-09
|
Siemens Tecnomatix FactoryLink ActBar.ocx Save Method Remote Arbitrary File Write
|
|
78287
Description:
Siemens Tecnomatix FactoryLink contains an overflow condition in the WebClient ActiveX Control. The issue is triggered as user-supplied input is not properly validated when passed to a parameter related to the Location URL. With a specially crafted web page, a context-dependent attacker can cause a buffer overflow, allowing execution of arbitrary code.
|
2011-12-09
|
Siemens Tecnomatix FactoryLink WebClient ActiveX Control Location URL Parameter Parsing Remote Code Execution
|
|
85228
Description:
DoceboLMS contains a flaw related to the iotask module that may allow an attacker to carry out an SQL injection attack. The issue is due to the save_connection function in the lib/lib.iotask.php script not properly sanitizing user-supplied input to the 'coursereportuiconfig[name]' and 'coursereportuiconfig[description]' parameters. This may allow an attacker to inject or manipulate SQL queries in the back-end database, allowing for the manipulation or disclosure of arbitrary data.
|
2011-12-09
|
DoceboLMS iotask Module lib/lib.iotask.php save_connection Function Multiple Parameter SQL Injection
|