| OSVDB ID | Disclosure Date | Title |
|
71658
Description:
Unknown / Incomplete
|
2011-03-20
|
Linux Kernel ROSE FAC_NATIONAL_DIGIS Facilities Field Processing Remote Heap Corruption
|
|
71659
Description:
Unknown / Incomplete
|
2011-03-20
|
Linux Kernel ROSE FAC_CCITT_*_NSAP Facilities Field Processing Multiple Remote Overflows
|
|
71415
Description:
Doctrine contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the Doctrine/Connection/Pgsql.php script not properly sanitizing user-supplied input to the 'modifyLimitQuery()' method. This may allow an attacker to inject or manipulate SQL queries in the back-end database, allowing for the manipulation or disclosure of arbitrary data.
|
2011-03-20
|
Doctrine Doctrine/Connection/Pgsql.php modifyLimitQuery() Method SQL Injection
|
|
71416
Description:
Doctrine contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the Doctrine/Connection/Db2.php script not properly sanitizing user-supplied input to the 'modifyLimitQuery()' method. This may allow an attacker to inject or manipulate SQL queries in the back-end database, allowing for the manipulation or disclosure of arbitrary data.
|
2011-03-20
|
Doctrine Doctrine/Connection/Db2.php modifyLimitQuery() Method SQL Injection
|
|
74262
Description:
(Description Provided by CVE) : The configuration merger in itk.c in the Steinar H. Gunderson mpm-itk Multi-Processing Module 2.2.11-01 and 2.2.11-02 for the Apache HTTP Server does not properly handle certain configuration sections that specify NiceValue but not AssignUserID, which might allow remote attackers to gain privileges by leveraging the root uid and root gid of an mpm-itk process.
|
2011-03-20
|
Apache HTTP Server Multi-Processing Module itk.c Configuration Merger mpm-itk root UID / GID Remote Privilege Escalation
|
|
75762
Description:
(Description Provided by CVE) : DoceboLMS 4.0.4 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by views/dummy/show.php and certain other files.
|
2011-03-20
|
DoceboLMS Multiple Script Direct Request Path Disclosure
|
|
77468
Description:
(Description Provided by CVE) : Multiple use-after-free vulnerabilities in libarchive 2.8.4 and 2.8.5 allow remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted (1) TAR archive or (2) ISO9660 image.
|
2011-03-20
|
libarchive Multiple Unspecified Use-after-free Issues
|
|
78622
Description:
Linux Kernel contains a flaw in the ROSE protocol. The issue is due to the FAC_CCITT_DEST_NSAP and FAC_CCITT_SRC_NSAP fields not properly sanitizing user-supplied input. With a specially crafted request, a remote attacker can corrupt memory to cause a denial of service or potentially execute arbitrary code.
|
2011-03-20
|
Linux Kernel ROSE Protocol Multiple Field Memory Corruption
|
|
85713
Description:
SilverStripe contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the Folder::findOrMake method not properly sanitizing user-supplied input before using it in SQL queries. This may allow an attacker to inject or manipulate SQL queries in the back-end database, allowing for the manipulation or disclosure of arbitrary data.
|
2011-03-20
|
SilverStripe Folder::findOrMake Method Unspecified SQL Injection
|
|
90443
Description:
Libiqxmlrpc contains a flaw that may allow a remote denial of service. The issue is triggered when parsing XML tags in struct members. This may allow a remote attacker to crash the program.
|
2011-03-20
|
Libiqxmlrpc Struct Member XML Tag Parsing Remote DoS
|
|
71245
Description:
Kleophatra CMS contains a flaw related to the 'do_avatar()' function in the modules/users/controllers/users.php script failing to properly validate uploaded file types. This may allow a remote attacker to upload arbitrary PHP files and execute arbitrary PHP code.
|
2011-03-19
|
Kleophatra CMS modules/users/controllers/users.php do_avatar() Function Arbitrary File Upload
|
|
72533
Description:
(Description Provided by CVE) : The _zip_name_locate function in zip_name_locate.c in the Zip extension in PHP before 5.3.6 does not properly handle a ZIPARCHIVE::FL_UNCHANGED argument, which might allow context-dependent attackers to cause a denial of service (NULL pointer dereference) via an empty ZIP archive that is processed with a (1) locateName or (2) statName operation.
|
2011-03-19
|
PHP ZIP Extension zip_name_locate.c _zip_name_locate Function Malformed ZIP Archive Handling DoS
|
|
75340
Description:
Unknown / Incomplete
|
2011-03-19
|
Web Poll Pro poll/submit.php error Parameter XSS
|
|
72293
Description:
Juniper IVE contains an unspecified flaw related to the credential provider. This may allow an attacker to bypass authentication.
|
2011-03-18
|
Juniper IVE Network Connect Credential Provider Authentication Bypass
|
|
71251
Description:
Novell NetWare is prone to an overflow condition. NWFTPD.NLM fails to properly sanitize user-supplied input resulting in a stack-based buffer overflow. With a specially crafted DELE command, a remote attacker can potentially execute arbitrary code.
|
2011-03-18
|
Novell NetWare NWFTPD.NLM DELE Command Remote Overflow
|
|
72287
Description:
CORE Multimedia Suite is prone to an overflow condition. CORE Player fails to properly sanitize user-supplied input resulting in a stack buffer overflow. With a specially crafted m3u file, a context-dependent attacker can potentially cause arbitrary code execution.
|
2011-03-18
|
CORE Multimedia Suite CORE Player m3u Playlist File Handling Overflow
|
|
74914
Description:
Unknown / Incomplete
|
2011-03-18
|
ACTi Multiple Products Web Configurator cgi-bin/test iperf Parameter Remote Command Injection
|
|
71225
Description:
ChekView contains a flaw that allows a local attacker to traverse outside of a restricted path. The issue is due to the WIFI file transfer functionality not properly sanitizing user input, specifically directory traversal style attacks (e.g., ../../) supplied via the URL. This directory traversal attack would allow the attacker to access arbitrary files, such as the iPhone address book.
|
2011-03-18
|
ChekView WIFI File Transfer Functionality Traversal Arbitrary File Access
|
|
74889
Description:
(Description Provided by CVE) : Format string vulnerability in ECTrace.dll in the iMailGateway service in the Internet Mail Gateway in OneBridge Server and DMZ Proxy in Sybase OneBridge Mobile Data Suite 5.5 and 5.6 allows remote attackers to execute arbitrary code via format string specifiers in unspecified string fields, related to authentication logging.
|
2011-03-18
|
OneBridge Multiple Products iMailGateway Service ECTrace.dll Authentication Logging Remote Format String
|
|
71216
Description:
Pennyauctionsoft contains a flaw that allows a remote cross-site scripting (XSS) attack. This flaw exists because the application does not validate input passed via the URL upon submission to the index.php script. This may allow a user to create a specially crafted URL that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2011-03-18
|
Pennyauctionsoft index.php XSS
|
|
71217
Description:
Pennyauctionsoft contains a flaw that allows a remote cross-site scripting (XSS) attack. This flaw exists because the application does not validate input passed via the URL upon submission to the jobs.php script. This may allow a user to create a specially crafted URL that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2011-03-18
|
Pennyauctionsoft jobs.php XSS
|
|
71218
Description:
Pennyauctionsoft contains a flaw that allows a remote cross-site scripting (XSS) attack. This flaw exists because the application does not validate input passed via the URL upon submission to the contact.php script. This may allow a user to create a specially crafted URL that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2011-03-18
|
Pennyauctionsoft contact.php XSS
|
|
71219
Description:
Pennyauctionsoft contains a flaw that allows a remote cross-site scripting (XSS) attack. This flaw exists because the application does not validate input passed via the URL upon submission to the forum/index.php script. This may allow a user to create a specially crafted URL that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2011-03-18
|
Pennyauctionsoft forum/index.php XSS
|
|
71220
Description:
Pennyauctionsoft contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the allauctions.php script not properly sanitizing user-supplied input to the 'client-ip' HTTP header. This may allow an attacker to inject or manipulate SQL queries in the back-end database, allowing for the manipulation or disclosure of arbitrary data.
|
2011-03-18
|
Pennyauctionsoft allauctions.php client-ip HTTP Header SQL Injection
|
|
71221
Description:
Pennyauctionsoft contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the registration.php script not properly sanitizing user-supplied input to the 'client-ip' HTTP header. This may allow an attacker to inject or manipulate SQL queries in the back-end database, allowing for the manipulation or disclosure of arbitrary data.
|
2011-03-18
|
Pennyauctionsoft registration.php client-ip HTTP Header SQL Injection
|
|
71222
Description:
Pennyauctionsoft contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the forum/forum_detail.php script not properly sanitizing user-supplied input to the 'client-ip' HTTP header. This may allow an attacker to inject or manipulate SQL queries in the back-end database, allowing for the manipulation or disclosure of arbitrary data.
|
2011-03-18
|
Pennyauctionsoft forum/forum_detail.php client-ip HTTP Header SQL Injection
|
|
71228
Description:
XOOPS contains a flaw that allows a remote cross-site scripting (XSS) attack. This flaw exists because the application does not validate the 'module', 'module[]', 'memberslist_id[]', 'newname[]' and 'oldname[]' parameters upon submission to the /modules/system/admin.php script. This may allow a user to create a specially crafted URL that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2011-03-18
|
XOOPS /modules/system/admin.php Multiple Parameter XSS
|
|
75336
Description:
W-Agora contains a flaw that allows a remote cross-site scripting (XSS) attack. This flaw exists because the application does not validate the 'bn' parameter upon submission to the 'register.php' script. This may allow a user to create a specially crafted URL that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2011-03-18
|
W-Agora register.php bn Parameter XSS
|
|
75337
Description:
W-Agora contains a flaw that may allow a remote attacker to execute arbitrary commands or code. The issue is due to the 'register.php' script not properly sanitizing user-supplied input to the 'bn' parameter. This may allow an attacker to include a file from the targeted host that contains arbitrary commands that will be executed by the vulnerable script. Such attacks are limited due to the script only calling files already on the target host. In addition, this flaw can potentially be used to disclose the contents of any file on the system accessible by the web server.
|
2011-03-18
|
W-Agora register.php bn Parameter Local File Inclusion
|
|
75338
Description:
W-Agora contains a flaw that allows a remote cross-site scripting (XSS) attack. This flaw exists because the application does not validate the 'site' parameter upon submission to the 'rss.php3' script. This may allow a user to create a specially crafted URL that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2011-03-18
|
W-Agora rss.php3 site Parameter XSS
|
|
75339
Description:
W-Agora contains a flaw that may allow a remote attacker to execute arbitrary commands or code. The issue is due to the 'rss.php3' script not properly sanitizing user-supplied input to the 'site' parameter. This may allow an attacker to include a file from the targeted host that contains arbitrary commands that will be executed by the vulnerable script. Such attacks are limited due to the script only calling files already on the target host. In addition, this flaw can potentially be used to disclose the contents of any file on the system accessible by the web server.
|
2011-03-18
|
W-Agora rss.php3 site Parameter Local File Inclusion
|
|
74892
Description:
(Description Provided by CVE) : Multiple cross-site request forgery (CSRF) vulnerabilities in the configuration screen in wp-relatedposts.php in the WP Related Posts plugin 1.0 for WordPress allow remote attackers to hijack the authentication of administrators for requests that insert cross-site scripting (XSS) sequences via the (1) wp_relatedposts_title, (2) wp_relatedposts_num, or (3) wp_relatedposts_type parameter.
|
2011-03-17
|
WP Related Posts Plugin for WordPress Multiple Parameter CSRF
|
|
71244
Description:
BookLibrary Component for Joomla! contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the index.php script not properly sanitizing user-supplied input to the 'searchtext' parameter. This may allow an attacker to inject or manipulate SQL queries in the back-end database, allowing for the manipulation or disclosure of arbitrary data.
|
2011-03-17
|
BookLibrary Component for Joomla! index.php searchtext Parameter SQL Injection
|
|
74891
Description:
(Description Provided by CVE) : Multiple cross-site request forgery (CSRF) vulnerabilities in the configuration page in the Recaptcha (aka WP-reCAPTCHA) plugin 2.9.8.2 for WordPress allow remote attackers to hijack the authentication of administrators for requests that disable the CAPTCHA requirement or insert cross-site scripting (XSS) sequences via the (1) recaptcha_opt_pubkey, (2) recaptcha_opt_privkey, (3) re_tabindex, (4) error_blank, (5) error_incorrect, (6) mailhide_pub, (7) mailhide_priv, (8) mh_replace_link, or (9) mh_replace_title parameter.
|
2011-03-17
|
Recaptcha Plugin for WordPress (WP-reCAPTCHA) Multiple Parameter CSRF
|
|
71187
Description:
Rating-Widget Plugin for WordPress contains a flaw that allows a remote cross-site scripting (XSS) attack. This flaw exists because the application does not validate the 'selected_key' parameter upon submission to the wp-content/plugins/rating-widget/view/availability_options.php script. This may allow a user to create a specially crafted URL that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2011-03-17
|
Rating-Widget Plugin for WordPress wp-content/plugins/rating-widget/view/availability_options.php selected_key Parameter XSS
|
|
71188
Description:
Rating-Widget Plugin for WordPress contains a flaw that allows a remote cross-site scripting (XSS) attack. This flaw exists because the application does not validate the 'vars[type]' parameter upon submission to the wp-content/plugins/rating-widget/view/rating.php script. This may allow a user to create a specially crafted URL that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2011-03-17
|
Rating-Widget Plugin for WordPress wp-content/plugins/rating-widget/view/rating.php vars[type] Parameter XSS
|
|
71189
Description:
Rating-Widget Plugin for WordPress contains a flaw that allows a remote cross-site scripting (XSS) attack. This flaw exists because the application does not validate the 'rw_form_hidden_field_name' parameter upon submission to the wp-content/plugins/rating-widget/view/save.php script. This may allow a user to create a specially crafted URL that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2011-03-17
|
Rating-Widget Plugin for WordPress wp-content/plugins/rating-widget/view/save.php rw_form_hidden_field_name Parameter XSS
|
|
71185
Description:
SodaHead Polls Plugin for WordPress contains a flaw that allows a remote cross-site scripting (XSS) attack. This flaw exists because the application does not validate the [PARAMETER | FIELD] [parameter | field] upon submission to the [SCRIPT] script. This may allow a user to create a specially crafted URL that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2011-03-17
|
SodaHead Polls Plugin for WordPress wp-content/plugins/sodahead-polls/poll.php customize Parameter XSS
|
|
71186
Description:
SodaHead Polls Plugin for WordPress contains a flaw that allows a remote cross-site scripting (XSS) attack. This flaw exists because the application does not validate the [PARAMETER | FIELD] [parameter | field] upon submission to the [SCRIPT] script. This may allow a user to create a specially crafted URL that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2011-03-17
|
SodaHead Polls Plugin for WordPress wp-content/plugins/sodahead-polls/customizer.php poll_id Parameter XSS
|
|
73622
Description:
(Description Provided by CVE) : Integer signedness error in zip_stream.c in the Zip extension in PHP before 5.3.6 allows context-dependent attackers to cause a denial of service (CPU consumption) via a malformed archive file that triggers errors in zip_fread function calls.
|
2011-03-17
|
PHP Zip Extension zip_stream.c zip_fread Function Call Integer Signedness Error DoS
|