| OSVDB ID | Disclosure Date | Title |
|
79636
Description:
idev-BusinessDirectory contains a flaw that allows a remote cross-site scripting (XSS) attack. This flaw exists because the application does not validate the 'SEARCH' parameter upon submission to the 'index.php' script. This may allow a user to create a specially crafted URL that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2012-02-25
|
idev-BusinessDirectory index.php SEARCH Parameter XSS
|
|
80348
Description:
Tiny Server contains a flaw that may allow a remote denial of service. The issue is triggered when sending an overly long GET request which causes the service to crash resulting in a loss of availability.
|
2012-02-25
|
Tiny Server GET Request Remote Overflow DoS
|
|
80751
Description:
Collaborative Passwords Manager contains a flaw that allows a remote user to execute arbitrary PHP code. This flaw exists because the uploadify.php script does not properly verify or sanitize user-uploaded files. By uploading a .php file, the remote system will place the file in a user-accessible path. Making a direct request to the uploaded file will allow the user to execute the script.
|
2012-02-25
|
Collaborative Passwords Manager (cPassMan) uploadify.php Arbitrary File Upload
|
|
79631
Description:
IBM AIX contains a flaw that may allow a remote denial of service. The issue is triggered when sending a specially crafted ICMP packet which causes a kernel panic resulting in a loss of availability.
|
2012-02-25
|
IBM AIX ICMP Packet Parsing Remote DoS
|
|
79662
Description:
LibreSource contains a flaw that allows a remote cross-site scripting (XSS) attack. This flaw exists because the application does not validate the 'action' parameter upon submission to the 'home/development/bug' script. This may allow a user to create a specially crafted URL that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2012-02-25
|
LibreSource home/development/bug action Parameter XSS
|
|
79664
Description:
TeamPass contains a flaw that may allow a remote attacker to execute arbitrary commands or code. The issue is due to the index.php script not properly sanitizing user input, specifically directory traversal style attacks (e.g., ../../) supplied to the 'user_language' cookie. This may allow an attacker to include a file from the targeted host that contains arbitrary commands or code that will be executed by the vulnerable script. Such attacks are limited due to the script only calling files already on the target host. In addition, this flaw can potentially be used to disclose the contents of any file on the system accessible by the web server.
|
2012-02-25
|
TeamPass user_language Cookie Local File Inclusion
|
|
79728
Description:
TeamPass contains a flaw that allows a remote user to execute arbitrary PHP code. This flaw exists because the includes/libraries/uploadify/uploadify.php script does not properly verify or sanitize user-uploaded files. By uploading a .php file, the remote system will place the file in a user-accessible path. Making a direct request to the uploaded file will allow the user to execute the script.
|
2012-02-25
|
TeamPass includes/libraries/uploadify/uploadify.php File Upload Arbitrary PHP Code Execution
|
|
80752
Description:
Collaborative Passwords Manager contains a flaw that may allow a remote attacker to execute arbitrary commands or code. The issue is due to the program not properly sanitizing user input, specifically directory traversal style attacks (e.g., ../../) supplied to the 'user_language' cookie. This may allow an attacker to include a file from the targeted host that contains arbitrary commands or code that will be executed by the vulnerable script. Such attacks are limited due to the script only calling files already on the target host. In addition, this flaw can potentially be used to disclose the contents of any file on the system accessible by the web server.
|
2012-02-25
|
Collaborative Passwords Manager (cPassMan) user_language Cookie Traversal Local File Inclusion
|
|
79496
Description:
Puppet contains a flaw that may allow a malicious local user to overwrite arbitrary files on the system. The issue is due to the application creating temporary files insecurely. It is possible for a local attacker to use a symlink attack against the '.k5login' file to cause the program to unexpectedly write to, or overwrite an attacker specified file.
|
2012-02-25
|
Puppet k5login File Symlink File Overwrite Local Privilege Escalation
|
|
79590
Description:
Dropbear contains a flaw related to the management of channel concurrencies. The issue is triggered due to an 'use-after-free' condition within a specially crafted request that may allow a remote attacker to potentially execute arbitrary code with root privileges.
|
2012-02-25
|
Dropbear SSH Server Channel Concurrency Use-after-free Remote Code Execution
|
|
79637
Description:
MyJobList contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the 'index.php' script not properly sanitizing user-supplied input to the 'eid' parameter. This may allow an attacker to inject or manipulate SQL queries in the back-end database, allowing for the manipulation or disclosure of arbitrary data.
|
2012-02-25
|
MyJobList index.php eid Parameter SQL Injection
|
|
79651
Description:
NetDecision is prone to an overflow condition. The HTTP service fails to properly sanitize user-supplied input resulting in a stack-based buffer overflow. With a specially crafted GET request containing an overly long URI, a remote attacker can potentially cause arbitrary code execution.
|
2012-02-25
|
NetDecision HTTP Server Web Request Parsing Remote Overflow
|
|
79789
Description:
Google Chrome on multiple Chromebook platforms contains multiple unspecified issues that may allow an attacker to conduct an attack with an unknown impact. No further details have been provided.
|
2012-02-24
|
Google Chrome Multiple Chromebook Platforms Multiple Unspecified Issues (2012-1418)
|
|
79652
Description:
NetDecision Traffic Grapher Server contains a flaw that may lead to an unauthorized information disclosure. The issue is triggered when sending a specially crafted HTTP GET request containing an invalid HTTP version number followed by multiple CRLFs to the 'default.nd' file, which will disclose the source code to a remote attacker.
|
2012-02-24
|
NetDecision Traffic Grapher Server Web Request GET Header Parsing NetDecision Script File Source Code Disclosure
|
|
79653
Description:
NetDecision Dashboard Server contains a flaw that may lead to an unauthorized information disclosure. The issue is triggered when requesting a non-existent resource, which will disclose the absolute path of the web directory to a remote attacker.
|
2012-02-24
|
NetDecision Dashboard Server Non-Existent Resource Web Request Parsing Web Directory Path Disclosure
|
|
79494
Description:
PHP Live! contains multiple unspecified issues that may allow an attacker to conduct an attack with an unknown impact. No further details have been provided.
|
2012-02-24
|
PHP Live! Multiple Unspecified Issues
|
|
79495
Description:
Puppet contains a flaw that may allow an attacker to gain access to unauthorized privileges. The issue is due to the application not dropping its own group permissions when spawning child processes, which may allows a local attacker to gain access to root privileges.
|
2012-02-24
|
Puppet Forked Process Group Permission Dropping Weakness Local Group Privilege Escalation
|
|
79613
Description:
CJWSoft ASPGuest GuestBook contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the 'edit.asp' script not properly sanitizing user-supplied input to the 'ID' parameter. This may allow an attacker to inject or manipulate SQL queries in the back-end database, allowing for the manipulation or disclosure of arbitrary data.
|
2012-02-24
|
CJWSoft ASPGuest GuestBook edit.asp ID Parameter SQL Injection
|
|
79618
Description:
Snom VoIP Phone contains a flaw that allows a remote Cross-site Request Forgery (CSRF / XSRF) attack. The flaw exists because the application does not require multiple steps or explicit confirmation for sensitive transactions for the manipulation of the administrator's password. By using a crafted URL (e.g., a crafted GET request inside an "img" tag), an attacker may trick the victim into clicking on the image to take advantage of the trust relationship between the authenticated victim and the application. Such an attack could trick the victim into executing arbitrary commands in the context of their session with the application, without further prompting or verification.
|
2012-02-24
|
Snom VoIP Phone Admin Password Manipulation CSRF
|
|
79687
Description:
LimeSurvey contains a flaw that allows a remote cross-site scripting (XSS) attack. This flaw exists because the admin/userrighthandling.php script does not validate the 'full_name' parameter upon submission to the 'admin.php' script. This may allow a user to create a specially crafted URL that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2012-02-24
|
LimeSurvey admin/admin.php full_name Parameter XSS
|
|
79688
Description:
LimeSurvey contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the admin/browse.php script not properly sanitizing user-supplied input passed via the 'id' parameter to the 'admin.php' script. This may allow an attacker to inject or manipulate SQL queries in the back-end database, allowing for the manipulation or disclosure of arbitrary data.
|
2012-02-24
|
LimeSurvey admin/admin.php id Parameter SQL Injection
|
|
80179
Description:
GnuTLS contains a flaw that may allow a remote denial of service. The issue is triggered due to a logical error within the libgnutls library when calling to free memory twice ('double-free') during the parsing of a malformed certificate list, which causes the application to crash resulting in a loss of availability.
|
2012-02-24
|
GnuTLS libgnutls Double-free Certificate List Parsing Remote DoS
|
|
80268
Description:
HostBill contains a flaw related to the administrative area. The issue is triggered when parsing security rules, and the software processes 'Allow' rules before 'Deny' rules. This may create a condition where traffic is passed that should be blocked.
|
2012-02-24
|
HostBill Admin Security Rules Parsing Weakness
|
|
79612
Description:
PHP Gift Registry contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the 'users.php' script not properly sanitizing user-supplied input to the 'userid' parameter. This may allow an attacker to inject or manipulate SQL queries in the back-end database, allowing for the manipulation or disclosure of arbitrary data.
|
2012-02-24
|
PHP Gift Registry users.php userid Parameter SQL Injection
|
|
79633
Description:
phpFox contains a flaw that allows a remote cross-site scripting (XSS) attack. This flaw exists because the application does not validate the 'val[description]' parameter upon submission to the 'marketplace/add/id_195' script. This may allow a user to create a specially crafted URL that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2012-02-24
|
phpFox marketplace/add/id_195 val[description] Parameter XSS
|
|
79667
Description:
Bontq contains a flaw that allows a remote cross-site scripting (XSS) attack. This flaw exists because the application does not validate input passed via the URL upon submission to the user/ script. This may allow a user to create a specially crafted URL that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2012-02-24
|
Bontq user/ URI XSS
|
|
80107
Description:
yaSSL contains a flaw that may allow a remote denial of service. The issue is triggered due to an error within the CyaSSL library when parsing malformed X.509 certificates which causes the application to crash resulting in a loss of availability.
|
2012-02-24
|
yaSSL CyaSSL X.509 Certificate Parsing Remote DoS
|
|
79491
Description:
Csound is prone to an overflow condition. The getnum() function in util/heti_main.c fails to properly sanitize user-supplied input resulting in a stack-based buffer overflow. With a specially crafted hetro file, a context-dependent attacker can potentially execute arbitrary code.
|
2012-02-24
|
Csound util/heti_main.c getnum() Function hetro File Handling Remote Overflow
|
|
79660
Description:
Kongreg8 contains a flaw that allows a remote cross-site scripting (XSS) attack. This flaw exists because the application does not validate the 'groupname', 'groupdescription', 'firstname' and 'surname' parameters upon submission to the 'index.php' script. This may allow a user to create a specially crafted URL that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2012-02-24
|
Kongreg8 index.php Multiple Parameter XSS
|
|
80329
Description:
CreateVision CMS contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the 'artykul_print.php' script not properly sanitizing user-supplied input to the 'id' parameter. This may allow an attacker to inject or manipulate SQL queries in the back-end database, allowing for the manipulation or disclosure of arbitrary data.
|
2012-02-24
|
CreateVision CMS artykul_print.php id Parameter SQL Injection
|
|
91173
Description:
Apache Wicket contains a flaw that may allow a remote attacker to bypass the WebApplicationPath constructor. This will allow the attacker to gain access to any file in the /WEB-INF/ directory.
|
2012-02-24
|
Apache Wicket WebApplicationPath Constructor Bypass /WEB-INF/ Directory File Access
|
|
79477
Description:
YVS Image Gallery contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the 'view_album.php' script not properly sanitizing user-supplied input to the 'album_id' parameter. This may allow an attacker to inject or manipulate SQL queries in the back-end database, allowing for the manipulation or disclosure of arbitrary data.
|
2012-02-23
|
YVS Image Gallery view_album.php album_id Parameter SQL Injection
|
|
79508
Description:
The Uploader contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the login.php script not properly sanitizing user-supplied input to the 'username' parameter. This may allow an attacker to inject or manipulate SQL queries in the back-end database, allowing for the manipulation or disclosure of arbitrary data. Additionally, this SQLi can be used to inject a PHP payload which can then be called and executed, allowing for arbitrary code execution.
|
2012-02-23
|
The Uploader login.php username Parameter SQL Injection Remote Code Execution
|
|
79655
Description:
The firmware in Snom VoIP phones contains a flaw that may allow an attacker to gain access to unauthorized privileges. The issue is triggered due to the handling of the advanced_network.htm form, allowing a remote attacker to reset the administrator password and gain access to full administrator privileges.
|
2012-02-23
|
Snom VoIP Phone advanced_network.htm Password Reset Admin Password Manipulation
|
|
79478
Description:
Apache Solr Extension for TYPO3 contains a flaw that allows a remote cross-site scripting (XSS) attack. This flaw exists because the application does not validate certain unspecified input before returning it to the user. This may allow a user to create a specially crafted URL that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2012-02-23
|
Apache Solr Extension for TYPO3 Unspecified XSS
|
|
79507
Description:
The Cisco Small Business SRP520 / SRP540 series contain a flaw that allows a remote attacker to traverse outside of a restricted path. The issue is due to the TFTP application not properly sanitizing user input, specifically directory traversal style attacks (e.g., ../../) when handling file upload requests. This directory traversal attack would allow the attacker to upload arbitrary files.
|
2012-02-23
|
Cisco Small Business SRP520 / SRP540 Series Local TFTP Application File Upload Request Parsing Traversal Arbitrary File Upload
|
|
79770
Description:
Multiple D-Link DCS products contain a flaw that allows a remote Cross-site Request Forgery (CSRF / XSRF) attack. The flaw exists because the security.cgi script does not require multiple steps or explicit confirmation for sensitive transactions for the manipulation of the administrator's password. By using a crafted URL (e.g., a crafted GET request inside an "img" tag), an attacker may trick the victim into clicking on the image to take advantage of the trust relationship between the authenticated victim and the application. Such an attack could trick the victim into executing arbitrary commands in the context of their session with the application, without further prompting or verification.
|
2012-02-23
|
D-Link Multiple DCS Products security.cgi Admin Password Manipulation CSRF
|
|
79617
Description:
D-Link DSL-2640B is prone to an authentication-bypass vulnerability. Attackers can exploit this issue to connect with administrator permissions without make authentication.
|
2012-02-23
|
D-Link DSL-2640B MAC Address Parsing Authentication Bypass
|
|
79872
Description:
FreeType contains an overflow condition in src/bdf/bdflib.c. The issue is triggered as user-supplied input is not properly validated when adding properties. With a specially crafted Bitmap Distribution Format (BDF) font file, a context-dependent attacker can cause a heap-based buffer overflow, resulting in a denial of service or potentially execution of arbitrary code.
|
2012-02-23
|
FreeType src/bdf/bdflib.c Adding Properties BDF Font File Handling Overflow
|
|
79875
Description:
FreeType contains an overflow condition in src/type42/t42parse.c. The issue is triggered as user-supplied input is not properly validated. With a specially crafted SFNT string in a Type 42 font, a context-dependent attacker can cause a heap-based buffer overflow, resulting in a denial of service or potentially execution of arbitrary code.
|
2012-02-23
|
FreeType src/type42/t42parse.c Type42 Font Parser SFNT String Handling Overflow
|