| OSVDB ID | Disclosure Date | Title |
|
85230
Description:
tForum contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the viewboard.php script not properly sanitizing user-supplied input to the 'BoardID' parameter. This may allow an attacker to inject or manipulate SQL queries in the back-end database, allowing for the manipulation or disclosure of arbitrary data.
|
2011-12-27
|
tForum viewboard.php BoardID Parameter SQL Injection
|
|
78070
Description:
Winn Guestbook contains a flaw that allows a remote cross-site scripting (XSS) attack. This flaw exists because the addPost() function in the data/functions.php script does not validate the 'name' parameter upon submission to the index.php script. This may allow a user to create a specially crafted URL that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2011-12-27
|
Winn Guestbook index.php name Parameter XSS
|
|
84878
Description:
FFmpeg is prone to an overflow condition. The avfilter_filter_samples function of libavfilter/avfilter.c fails to properly sanitize user-supplied input resulting in a heap-based buffer overflow. With a specially crafted media file, a context-dependent attacker can potentially execute arbitrary code or cause a denial of service.
|
2011-12-27
|
FFmpeg libavfilter/avfilter.c avfilter_filter_samples Function Media File Handling Overflow
|
|
85229
Description:
tForum contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the viewtopic.php script not properly sanitizing user-supplied input to the 'TopicID' parameter. This may allow an attacker to inject or manipulate SQL queries in the back-end database, allowing for the manipulation or disclosure of arbitrary data.
|
2011-12-27
|
tForum viewtopic.php TopicID Parameter SQL Injection
|
|
85231
Description:
tForum contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the viewcat.php script not properly sanitizing user-supplied input to the 'CatID' parameter. This may allow an attacker to inject or manipulate SQL queries in the back-end database, allowing for the manipulation or disclosure of arbitrary data.
|
2011-12-27
|
tForum viewcat.php CatID Parameter SQL Injection
|
|
78043
Description:
(Description Provided by CVE) : Stack-based buffer overflow in CoCSoft Stream Down 6.8.0 allows remote web servers to execute arbitrary code via a long response to a download request.
|
2011-12-27
|
CoCSoft Stream Down Download Request Response String Parsing Remote Overflow
|
|
85232
Description:
tForum contains a flaw that allows a remote cross-site scripting (XSS) attack. This flaw exists because the application does not validate the 'username' parameter upon submission to the member.php script. This may allow a user to create a specially crafted request that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2011-12-27
|
tForum member.php username Parameter XSS
|
|
78282
Description:
(Description Provided by CVE) : The Wi-Fi Protected Setup (WPS) protocol, when the "external registrar" authentication method is used, does not properly inform clients about failed PIN authentication, which makes it easier for remote attackers to discover the PIN value, and consequently discover the Wi-Fi network password or reconfigure an access point, by reading EAP-NACK messages.
|
2011-12-26
|
Multiple Router Wi-Fi Protected Setup (WPS) Protocol External Registrar Authentication EAP-NACK Message Remote PIN Disclosure
|
|
78023
Description:
Unknown / Incomplete
|
2011-12-26
|
vtiger CRM graph.php Database Backup Information Disclosure
|
|
78122
Description:
The Simple File Upload Module for Joomla! contains a flaw that allows a remote user to execute arbitrary PHP code. This flaw exists because the modules/mod_simplefileuploadv1.3/helper.php script does not properly verify or sanitize user-uploaded files. By uploading a .php file, the remote system will place the file in a user-accessible path. Making a direct request to the uploaded file will allow the user to execute the script.
|
2011-12-26
|
Simple File Upload Module for Joomla! modules/mod_simplefileuploadv1.3/helper.php File Upload Arbitrary Code Execution
|
|
79998
Description:
Unknown / Incomplete
|
2011-12-26
|
OllyDBG Sym File Handling Remote Overflow
|
|
82590
Description:
Nagios Plugins is prone to an overflow condition. Check_ups fails to properly sanitize user-supplied input resulting in a buffer overflow. With a specially crafted request, a local attacker can potentially execute arbitrary code.
|
2011-12-26
|
Nagios Plugins check_ups Local Overflow
|
|
82591
Description:
Free Image Hosting Script contains a flaw that allows a remote user to execute arbitrary PHP code. This flaw exists because the program does not properly verify or sanitize user-uploaded files. By uploading a .php file, the remote system will place the file in a user-accessible path. Making a direct request to the uploaded file will allow the user to execute the script.
|
2011-12-26
|
Free Image Hosting Script File Upload Arbitrary Code Execution
|
|
82592
Description:
OpenEMR contains a flaw that allows a remote user to execute arbitrary code. This flaw exists because the program does not properly verify or sanitize user-uploaded files. By uploading a PHP file as a patient photograph, the remote system will place the file in a user-accessible path. Making a direct request to the uploaded file will allow the user to execute the script.
|
2011-12-25
|
OpenEMR Patient Photograph Upload Remote Code Execution
|
|
78025
Description:
Mailing List Plugin for WordPress contains a flaw that allows a remote attacker to traverse outside of a restricted path. The issue is due to the wp-content/plugins/mailz/lists/config/config.php script not properly sanitizing user input, specifically directory traversal style attacks (e.g., ../../) supplied via the 'wph', 'wpdb', 'wpu' and "wpp' parameters to the wp-content/plugins/mailz/lists/dl.php script. This directory traversal attack would allow the attacker to access arbitrary files.
|
2011-12-25
|
Mailing List Plugin for WordPress wp-content/plugins/mailz/lists/dl.php Multiple Parameter Traversal Arbitrary File Access
|
|
78107
Description:
GraphicsClone Script contains a flaw that allows a remote cross-site scripting (XSS) attack. This flaw exists because the application does not validate the 'term' parameter upon submission to search/. This may allow a user to create a specially crafted URL that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2011-12-25
|
GraphicsClone Script search/ term Parameter XSS
|
|
86240
Description:
WP Live.php Module for WordPress contains a flaw that allows a remote cross-site scripting (XSS) attack. This flaw exists because the application does not validate the 's' parameter upon submission to the wp-live.php script. This may allow a user to create a specially crafted request that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2011-12-25
|
WP Live.php Module for WordPress wp-live.php s Parameter XSS
|
|
78020
Description:
(Description Provided by CVE) : Buffer overflow in libtelnet/encrypt.c in telnetd in FreeBSD 7.3 through 9.0, MIT Kerberos Version 5 Applications (aka krb5-appl) 1.0.2 and earlier, Heimdal 1.5.1 and earlier, GNU inetutils, and possibly other products allows remote attackers to execute arbitrary code via a long encryption key, as exploited in the wild in December 2011.
|
2011-12-24
|
FreeBSD telnetd Multiple telnet/libtelnet/encrypt.c encrypt_keyid() Function Command Parsing Remote Overflow
|
|
78283
Description:
(Description Provided by CVE) : MySQL 5.5.8, when running on Windows, allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted packet to TCP port 3306.
|
2011-12-24
|
Oracle MySQL NULL Pointer Dereference Packet Parsing Remote DoS
|
|
82595
Description:
freeSSHd contains a flaw that may allow a remote denial of service. The issue is triggered by an error in the SSH server when handling a malformed packet. This will result in a loss of availability for the service.
|
2011-12-24
|
freeSSHd Malformed Packet Handling Remote DoS
|
|
85331
Description:
FFmpeg is prone to an overflow condition. The get_sot function of j2k.c fails to properly check the curtileno variable, which may result in an overflow. No further details have been provided.
|
2011-12-24
|
FFmpeg j2k.c get_sot Function curtileno Variable Remote Overflow
|
|
82605
Description:
Microsoft Windows contains a flaw that may allow a denial of service. The issue is triggered when a local attacker creates a specially crafted subdirectory that will allow for the deletion of a parent directory. This will result in loss of availability for the explorer.exe application.
|
2011-12-24
|
Microsoft Windows Explorer Crafted Subdirectory Parent Directory Deletion Local DoS
|
|
82604
Description:
Microsoft Windows Media Player is prone to an overflow condition. The program fails to properly sanitize user-supplied input resulting in a buffer overflow. With a specially crafted streamed broadcast, a context-dependent attacker can potentially execute arbitrary code.
|
2011-12-24
|
Microsoft Windows Media Player Streamed Broadcast Handling Remote Overflow
|
|
77994
Description:
(Description Provided by CVE) : The Blueberry FlashBack ActiveX control in BB FlashBack Recorder.dll in Blueberry BB FlashBack, as used in IBM Rational Rhapsody before 7.6.1 and other products, does not properly implement the TestCompatibilityRecordMode method, which allows remote attackers to execute arbitrary code via unspecified vectors.
|
2011-12-23
|
Blueberry (BB) FlashBack SDK ActiveX (BBFlashBack.Recorder.dll) Multiple Method Remote Code Execution
|
|
77995
Description:
Multiple Public Knowledge Project products contain a flaw that allows a remote Cross-site Request Forgery (CSRF / XSRF) attack. The flaw exists because the application does not require multiple steps or explicit confirmation for sensitive transactions for the uploading of PHP files. By using a crafted URL (e.g., a crafted GET request inside an "img" tag), an attacker may trick the victim into clicking on the image to take advantage of the trust relationship between the authenticated victim and the application. Such an attack could trick the victim into executing arbitrary commands in the context of their session with the application, without further prompting or verification.
|
2011-12-23
|
Public Knowledge Project Multiple Product PHP File Upload CSRF
|
|
78021
Description:
Unknown / Incomplete
|
2011-12-23
|
FreeBSD pam_ssh Module Unencrypted SSH Private Keys Passphrase Authentication Bypass
|
|
78235
Description:
KnowledgeTree contains a flaw that allows a remote cross-site scripting (XSS) attack. This flaw exists because the config/dmsDefaults.php script does not validate input passed via the URL upon submission to the login.php, admin.php and preferences.php scripts. This may allow a user to create a specially crafted URL that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2011-12-23
|
KnowledgeTree config/dmsDefaults.php URI XSS
|
|
78313
Description:
(Description Provided by CVE) : Integer signedness error in Apple QuickTime before 7.7.1 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted font table in a QuickTime movie file.
|
2011-12-23
|
Apple QuickTime RLE BGRA Decoding Video File Handling Remote Overflow
|
|
78127
Description:
tinyguestbook contains a flaw that allows a remote cross-site scripting (XSS) attack. This flaw exists because the application does not validate the 'msg' parameter upon submission to the sign.php script. This may allow a user to create a specially crafted URL that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2011-12-23
|
tinyguestbook sign.php msg Parameter XSS
|
|
81871
Description:
Cisco Unified IP Phones contains a flaw that may allow an attacker to gain access to unauthorized privileges. The issue is triggered by an error when downloading configuration information to an RT phone, which may allow a local attacker to gain escalated privileges.
|
2011-12-23
|
Cisco Unified IP Phones RT Phone Configuration Information Download Local Privilege Escalation
|
|
78312
Description:
Siemens WinCC contains a flaw in the web server as generated authentication tokens (cookie values) are predictable. This allows a remote attacker to bypass authentication to gain unauthorized access to the HMI.
|
2011-12-23
|
Siemens SIMATIC WinCC HMI Authentication Token Generation Weakness Authentication Bypass
|
|
84149
Description:
WebKit contains a use-after-free error in the 'AccessibilityRenderObject::childrenChanged' function in WebCore/accessibility/AccessibilityRenderObject.cpp when content is changed for an element with 'contenteditable' set and a textbox role. With a specially crafted web page, a context-dependent attacker can dereference already freed memory and potentially execute arbitrary code.
|
2011-12-23
|
WebKit 'AccessibilityRenderObject::childrenChanged' Function Use-after-free Issue
|
|
77982
Description:
(Description Provided by CVE) : etc/inc/certs.inc in the PKI implementation in pfSense before 2.0.1 creates each X.509 certificate with a true value for the CA basic constraint, which allows remote attackers to create sub-certificates for arbitrary subjects by leveraging the private key.
|
2011-12-22
|
pfSense CA x.509 Certificate TRUE Arbitrary Sub-Certificate Issuing Weakness
|
|
78013
Description:
Tiki Wiki CMS/Groupware contains a flaw that allows a remote Cross-site Request Forgery (CSRF / XSRF) attack. The flaw exists because the application does not require multiple steps or explicit confirmation for sensitive transactions for the execution of PHP code. By using a crafted URL (e.g., a crafted GET request inside an "img" tag), an attacker may trick the victim into clicking on the image to take advantage of the trust relationship between the authenticated victim and the application. Such an attack could trick the victim into executing arbitrary commands in the context of their session with the application, without further prompting or verification.
|
2011-12-22
|
Tiki Wiki CMS/Groupware snarf_ajax.php PHP Code Execution CSRF
|
|
78014
Description:
(Description Provided by CVE) : The Linux kernel before 3.2.2 does not properly restrict SG_IO ioctl calls, which allows local users to bypass intended restrictions on disk read and write operations by sending a SCSI command to (1) a partition block device or (2) an LVM volume.
|
2011-12-22
|
Linux Kernel SG_IO SCSI IOCTL Command Parsing Local Privilege Escalation
|
|
78019
Description:
Whois.Cart() contains a flaw that allows a remote cross-site scripting (XSS) attack. This flaw exists because the application does not validate the 'domainname' parameter upon submission to the ordernow.php script. This may allow a user to create a specially crafted URL that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2011-12-22
|
Whois.Cart() ordernow.php domainname Parameter XSS
|
|
78044
Description:
HP Database Archiving Software is prone to an overflow condition. The program fails to properly sanitize user-supplied input resulting in a buffer overflow. With a specially crafted GIOP Opcode 0x0E packet, a remote attacker can potentially execute arbitrary code.
|
2011-12-22
|
HP Database Archiving Software Packet Field Parsing Overflow
|
|
78045
Description:
HP Database Archiving Software is prone to an overflow condition. The program fails to properly sanitize user-supplied input resulting in a buffer overflow. With a specially crafted GIOP packet, a remote attacker can potentially execute arbitrary code.
|
2011-12-22
|
HP Database Archiving Software GIOP Packet Parsing Overflow
|
|
78046
Description:
(Description Provided by CVE) : Unspecified vulnerability in HP Database Archiving Software 6.31 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-1263.
|
2011-12-22
|
DataDirect SequeLink oaagent.exe GIOP Packet Parsing Remote Overflow
|
|
78233
Description:
Cogent DataHub contains a flaw that allows a remote cross-site scripting (XSS) attack. This flaw exists because the application does not validate certain unspecified input before returning it to the user. This may allow a user to create a specially crafted URL that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2011-12-21
|
Cogent DataHub Unspecified XSS
|