| OSVDB ID | Disclosure Date | Title |
|
82216
Description:
FlirtPortal Script contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the rub2.php script not properly sanitizing user-supplied input to the 'rub' parameter. This may allow an attacker to inject or manipulate SQL queries in the back-end database, allowing for the manipulation or disclosure of arbitrary data.
|
2012-04-27
|
FlirtPortal Script rub2.php rub Parameter SQL Injection
|
|
82218
Description:
FlirtPortal Script contains a flaw that allows a remote cross-site scripting (XSS) attack. This flaw exists because the application does not validate the 'ctitle' parameter upon submission to the index_kartensuche.php script. This may allow a user to create a specially crafted URL that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2012-04-27
|
FlirtPortal Script index_kartensuche.php ctitle Parameter XSS
|
|
84719
Description:
MySQLDumper contains a flaw that allows a remote cross-site scripting (XSS) attack. This flaw exists because the application does not validate the 'page' parameter upon submission to the index.php script. This may allow a user to create a specially crafted URL that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2012-04-27
|
MySQLDumper index.php page Parameter XSS
|
|
84890
Description:
McAfee Application Control and Change Control contain a flaw that is triggered by an error that may allow a local attacker to change file permissions on the solidcore\passwd file to read-only. This will cause the program to no longer prompt a user for a password when executing commands, which will allow the attacker to execute arbitrary commands.
|
2012-04-27
|
McAfee Application Control / Change Control solidcore\passwd File Permission Manipulation Local Command Execution
|
|
93541
Description:
Apache Solr contains a flaw that allows a reflected cross-site scripting (XSS) attack. This flaw exists because the application does not validate input passed via a callback upon submission to json.wrf. This may allow an attacker to create a specially crafted request that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2012-04-27
|
Apache Solr json.wrf Callback XSS
|
|
81560
Description:
DiY-CMS contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the mod.php script not properly sanitizing user-supplied input to the 'start' parameter. This may allow an attacker to inject or manipulate SQL queries in the back-end database, allowing for the manipulation or disclosure of arbitrary data.
|
2012-04-26
|
DiY-CMS mod.php start Parameter SQL Injection
|
|
81561
Description:
DiY-CMS contains a flaw that allows a remote cross-site scripting (XSS) attack. This flaw exists because the application does not validate input passed via the url upon submission to the poll/add.php script. This may allow a user to create a specially crafted URL that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2012-04-26
|
DiY-CMS poll/add.php URI XSS
|
|
81568
Description:
Twonky and TwonkyManager contain a flaw related to the secure server settings, that allows a remote attacker to traverse outside of a restricted path. The issue is due to the program not properly sanitizing user input, specifically directory traversal style attacks (e.g., ../../). This directory traversal attack would allow the attacker to read arbitrary files.
|
2012-04-26
|
PacketVideo Multiple Product Secured Server Settings Traversal Arbitrary File Access
|
|
81629
Description:
sp-mode Mail for Android contains a flaw related to the validation of SSL certificates when accessing certain services. This may allow a man-in-the-middle attacker to spoof a valid server.
|
2012-04-26
|
sp-mode Mail for Android SSL Certificate Validation MitM Spoofing Weakness
|
|
81558
Description:
KMPlayer is prone to a flaw related to ehtrace.dll, in the way it loads dynamic-link libraries (DLL). The program uses a fixed path to look for specific files or libraries. This path includes directories that may not be trusted or under user control. By placing a custom version of the file or library in the path, the program will load it before the legitimate version. This allows an attacker to inject custom code that will be run with the privilege of the program or user executing the program. This can be done by tricking a user into opening a DLL file from the local file system or a USB drive in some cases. This attack can be leveraged remotely in some cases by placing the malicious file or library on a network share or extracted archive downloaded from a remote source.
|
2012-04-26
|
KMPlayer ehtrace.dll Path Subversion Arbitrary DLL Injection Code Execution
|
|
81569
Description:
ACTi Web Configurator contains a flaw related to the cgi-bin directory, that allows a remote attacker to traverse outside of a restricted path. The issue is due to the program not properly sanitizing user input, specifically directory traversal style attacks (e.g., ../../). This directory traversal attack would allow the attacker to read arbitrary files.
|
2012-04-26
|
ACTi Web Configurator cgi-bin Traversal Arbitrary File Access
|
|
81630
Description:
NinjaXplorer Component for Joomla! contains a flaw that may allow a remote attacker to have an unspecified impact. No further details have been provided.
|
2012-04-26
|
NinjaXplorer Component for Joomla! Unspecified Remote Issue
|
|
81491
Description:
Parallels Plesk Panel contains a flaw that may lead to an unauthorized information disclosure. This issue may allow an attacker to view the contents of psadump.log, which will disclose admin passwords to a remote attacker.
|
2012-04-26
|
Parallels Plesk Panel psadump.log Admin Password Disclosure
|
|
81492
Description:
Zingiri Web Shop Plugin for Wordpress contains a flaw that allows a remote cross-site scripting (XSS) attack. This flaw exists because the application does not validate the 'page' parameter upon submission to the plugins/zingiri-web-shop/zing.inc.php script. This may allow a user to create a specially crafted URL that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2012-04-26
|
Zingiri Web Shop Plugin for WordPress plugins/zingiri-web-shop/zing.inc.php page Parameter XSS
|
|
81493
Description:
Zingiri Web Shop Plugin for Wordpress contains a flaw that allows a remote cross-site scripting (XSS) attack. This flaw exists because the application does not validate the 'notes' parameter upon submission to the fws/pages-front/onecheckout.php script. This may allow a user to create a specially crafted URL that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2012-04-26
|
Zingiri Web Shop Plugin for WordPress fws/pages-front/onecheckout.php notes Parameter XSS
|
|
83206
Description:
Opera contains a flaw that may allow a denial of service. The issue is triggered when reloading a specially crafted page during a multiple origin camera test. This will result in loss of availability for the program.
|
2012-04-26
|
Opera Multiple Origin Page Reload DoS
|
|
83211
Description:
Opera contains a flaw that may allow a denial of service. The issue is triggered when the program fails to properly handle invalid character encodings, which will result in loss of availability for the program.
|
2012-04-26
|
Opera Invalid Character Encoding Handling DoS
|
|
83207
Description:
Opera contains a flaw that may allow a denial of service. The issue is triggered when the program fails to properly handle absolute positioned wrap=off TEXTAREA elements which are adjacent to overflow: auto block elements. This will result in a loss of availability for the program.
|
2012-04-26
|
Opera Adjacent wrap=off TEXTAREA / overflow: auto Block Elements Handling DoS
|
|
83208
Description:
Opera contains a flaw that may allow a denial of service. The issue is triggered when the program fails to properly handle malformed domain names, which will result in loss of availability for the program.
|
2012-04-26
|
Opera Malformed Domain Name Handling DoS
|
|
83209
Description:
Opera contains a flaw that may allow a denial of service. The issue is triggered when an attacker uses JavaScript code to manipulate a form in an unspecified fashion before it is submitted. This will result in loss of availability for the program. No further details have been provided.
|
2012-04-26
|
Opera JavaScript Manipulated Form Submission DoS
|
|
83212
Description:
Opera contains a flaw that may allow a denial of service. The issue is triggered when an an attacker embeds a parent document into an IFRAME element via the src="#" syntax, which will result in a loss of availability for the program.
|
2012-04-26
|
Opera Crafted IFRAME Element Handling DoS
|
|
83210
Description:
Opera contains a flaw that may allow a denial of service. The issue is triggered when an attacker supplies malformed WebGL content, which will result in loss of availability for the program.
|
2012-04-26
|
Opera Malformed WebGL Content Handling DoS
|
|
84390
Description:
OpenSSL contains a flaw related to the SSL_OP_ALL option. This issue is triggered when the TLS 1.1 protocol is disabled, which will result in the protocol being rolled back to 1.0 which may not be secure.
|
2012-04-26
|
OpenSSL SSL_OP_ALL Option TLS Protocol Rollback Weakness
|
|
81837
Description:
Open Source Q&A System contains a flaw that allows a remote cross-site scripting (XSS) attack. This flaw exists because the application does not validate input passed via the URL upon submission to the cleanup_urls function in the forum/utils/html.py script. This may allow a user to create a specially crafted URL that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2012-04-26
|
Open Source Q&A System (OSQA) forum/utils/html.py cleanup_urls Function URI XSS
|
|
83243
Description:
WebKit contains an out-of-bounds read flaw in the SVG filter when handling invalid feConvolveMatrix property values. The issue is triggered when handling SVG filters. With a specially crafted SVG document, a context-dependent attacker can cause a crash or potentially disclose memory contents.
|
2012-04-26
|
WebKit SVG Filter feConvolveMatrix Invalid Property Value Handling Out-of-bounds Read Issue
|
|
84162
Description:
WebKit contains a typecasting flaw in the 'HTMLCollection::isAcceptableElement' function in WebCore/html/HTMLCollection.cpp. With a specially crafted SVG document, a context-dependent attacker can corrupt memory to cause a denial of service or potentially execute arbitrary code.
|
2012-04-26
|
WebKit 'HTMLCollection::isAcceptableElement' Function Bad Cast Memory Corruption
|
|
84178
Description:
WebKit contains a use-after-free error that is triggered when removing a line break object after layout. With a specially crafted web page, a context-dependent attacker can dereference already freed memory and potentially execute arbitrary code.
|
2012-04-26
|
WebKit Line Break Object Removal After Layout Use-after-free Issue
|
|
85823
Description:
OpenStack Keystone contains a flaw that is triggered when an account associated with a disabled tenant still authenticates as if the tenant is active. This may allow a user to authenticate in some circumstances where it should not be allowed.
|
2012-04-26
|
OpenStack Keystone Disabled Tenant Authentication Persistance
|
|
81551
Description:
Creative Commons Module for Drupal contains a flaw that allows a remote cross-site scripting (XSS) attack. This flaw exists because the application does not validate input used in describing licenses (creativecommons_site_license_additional_text parameter) before returning it to the user. This may allow a user to create a specially crafted URL that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2012-04-25
|
Creative Commons Module for Drupal creativecommons_site_license_additional_text Parameter XSS
|
|
81554
Description:
Ubercart Module for Drupal contains a flaw that may allow a remote attacker to execute arbitray PHP code.
|
2012-04-25
|
Ubercart Module for Drupal Remote PHP Code Execution
|
|
81406
Description:
By default, RuggedCom Rugged Operating System (ROS) installs with a default, unchangeable password. The 'factory' account has a password based off the ROS device's MAC address. This allows attackers to remotely access the system and gain full administrative control.
|
2012-04-25
|
RuggedCom Rugged Operating System (ROS) Hardcoded Credentials
|
|
81553
Description:
Ubercart Module for Drupal contains a flaw that allows a remote cross-site scripting (XSS) attack. This flaw exists because the application does not properly sanitize input passed via the product classes feature before returning it to the user. This may allow a user to create a specially crafted URL that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2012-04-25
|
Ubercart Module for Drupal Product Classes XSS
|
|
81488
Description:
Piwigo contains a flaw that may allow a remote attacker to execute arbitrary commands or code. The issue is due to the upgrade.php script not properly sanitizing user input, specifically directory traversal style attacks (e.g., ../../) supplied to the 'language' parameter. This may allow an attacker to include a file from the targeted host that contains arbitrary commands or code that will be executed by the vulnerable script. Such attacks are limited due to the script only calling files already on the target host. In addition, this flaw can potentially be used to disclose the contents of any file on the system accessible by the web server.
|
2012-04-25
|
Piwigo upgrade.php language Parameter Traversal Local File Inclusion
|
|
81489
Description:
Piwigo contains a flaw that allows a remote cross-site scripting (XSS) attack. This flaw exists because the application does not validate the 'installstatus', 'theme' and 'section' parameters upon submission to the admin.php script. This may allow a user to create a specially crafted URL that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2012-04-25
|
Piwigo admin.php Multiple Parameter XSS
|
|
81556
Description:
Spaces Module for Drupal contains a flaw where the spaces and spaces_og modules in the spaces packages don't always apply the proper restrictions, which may allow an attacker to bypass certain restrictions and possibly gain access to sensitive information.
|
2012-04-25
|
Spaces Module for Drupal Access Restriction Bypass
|
|
81635
Description:
RealName Module for Drupal contains a flaw related to the User Real Name field that allows a remote cross-site scripting (XSS) attack. This flaw exists because the application does not validate certain unspecified input before returning it to the user. This may allow a user to create a specially crafted URL that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2012-04-25
|
RealName Module for Drupal User Real Name Unspecified XSS
|
|
81547
Description:
By default, MoroccoTel Telnet Server installs with a default password. The admin account has a password of admin or 123456 which is publicly known and documented. This allows attackers to trivially access the program or system and gain privileged access.
|
2012-04-25
|
MoroccoTel Telnet Server Default Password
|
|
81552
Description:
Ubercart Module for Drupal contains a flaw that may lead to an unauthorized information disclosure. The issue is triggered when passwords created by new customers are stored as plain text until a purchase is confirmed, which may allow a remote attacker to easily gain access to passwords.
|
2012-04-25
|
Ubercart Module for Drupal New Customer Password Local Information Disclosure
|
|
81555
Description:
Site Documentation Module for Drupal contains a flaw that may lead to an unauthorized information disclosure. The issue is triggered when the file system doesn't properly verify the saved file is protected by the private file system, which will disclose structure information to an attacker.
|
2012-04-25
|
Site Documentation (Sitedoc) Module for Drupal Site Structure Information Disclosure
|
|
81557
Description:
Linkit Module for Drupal contains a flaw when using the search function that may allow an attacker to bypass certain restrictions and view content otherwise restricted.
|
2012-04-25
|
Linkit Module for Drupal Access Restriction Bypass
|