| OSVDB ID | Disclosure Date | Title |
|
93421
Description:
Newsletter Plugin for WordPress contains a flaw that allows a reflected cross-site scripting (XSS) attack. This flaw exists because the application does not validate the 'alert' parmaeter upon submission to the /wp-content/plugins/newsletter/subscription/page.php script. This may allow an attacker to create a specially crafted request that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2013-05-14
|
Newsletter Plugin for WordPress /wp-content/plugins/newsletter/subscription/page.php alert Parameter XSS
|
|
93259
Description:
Securimage-WP Plugin for WordPress contains a flaw that allows a remote cross-site scripting (XSS) attack. This flaw exists because the application does not validate input passed via the URL upon submission to the siwp_test.php script. This may allow an attacker to create a specially crafted request that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2013-05-11
|
Securimage-WP Plugin for WordPress siwp_test.php URI XSS
|
|
93439
Description:
Securimage contains a flaw that allows a remote cross-site scripting (XSS) attack. This flaw exists because the application does not validate input passed via the URL upon submission to the example_form.php script. This may allow an attacker to create a specially crafted request that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2013-05-10
|
Securimage example_form.php URI XSS
|
|
93143
Description:
Symantec Brightmail Gateway contains a flaw that allows multiple persistent cross-site scripting (XSS) attacks in administrative-interface pages in the management console. This flaw exists because the application does not validate certain unspecified input before returning it to the user. This may allow an attacker to create a specially crafted request that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2013-05-08
|
Symantec Brightmail Gateway Management Console Multiple Unspecified XSS
|
|
93185
Description:
isco Unified Presence (CUP) contains a flaw in the Web Framework that may allow a remote denial of service. The issue is due to the program failing to properly handle memory allocation during the handling of a saturation of malformed TCP packets. This may allow a remote attacker to consume memory resources indefinitely, even after the attack has ceased. The memory will not release until the system has been rebooted.
|
2013-05-07
|
Cisco Unified Presence (CUP) Web Framework Malformed TCP Packet Handling Memory Exhaustion Remote DoS
|
|
93234
Description:
MoinMoin WikiSandbox contains a flaw that allows an attacker to traverse outside of a restricted path. The issue is due to the program not properly sanitizing user input, specifically directory traversal style attacks (e.g., ../../) supplied via the 'target' parameter. This directory traversal attack would allow a remote attacker to overwrite an arbitrary file.
|
2013-05-07
|
MoinMoin WikiSandbox target Parameter Traversal Arbitrary File Overwrite
|
|
92988
Description:
EMC NetWorker contains a flaw that leads to unauthorized privileges being gained. The issue is triggered when the nsprush process sets weak permissions on certain unspecified files. This may allow a local attacker to to gain elevated privileges.
|
2013-05-02
|
EMC NetWorker Insecure File Permission Local Privilege Escalation
|
|
92989
Description:
EMC Avamar Server contains a flaw in the web based file restore interface that is triggered during the handling of a specially crafted URL. This may allow a remote attacker to gain access to arbitrary files.
|
2013-05-02
|
EMC Avamar Server Web Based File Restore Interface Crafted URL Handling Arbitrary File Access
|
|
92990
Description:
EMC Avamar Client contains a flaw related to certificate validation. The issue is due to the server hostname not being verified to match a domain name in the Subject's Common Name (CN) or SubjectAltName field of the X.509 certificate. This may allow a man-in-the-middle attacker to spoof SSL servers via an arbitrary certificate that appears valid. Such an attack would allow for the interception of sensitive traffic, and potentially allow for the injection of content into the SSL stream.
|
2013-05-02
|
EMC Avamar Client X.509 Certificate Multiple Field Domain Name Matching MiTM Weakness
|
|
92844
Description:
IBM SPSS SamplePower contains an unspecified flaw in the Vsflex8l ActiveX control that may allow a context-dependent attacker to potentially execute arbitrary code. No further details have been provided by the vendor.
|
2013-04-26
|
IBM SPSS SamplePower ActiveX (Vsflex8l) Unspecified Arbitrary Code Execution
|
|
92845
Description:
IBM SPSS SamplePower contains an unspecified flaw in the c1sizer ActiveX control that may allow a context-dependent attacker to potentially execute arbitrary code. No further details have been provided by the vendor.
|
2013-04-26
|
IBM SPSS SamplePower ActiveX (c1sizer) Unspecified Arbitrary Code Execution
|
|
92846
Description:
IBM SPSS SamplePower contains an unspecified flaw in the vsflex7l ActiveX control that may allow a context-dependent attacker to potentially execute arbitrary code. No further details have been provided by the vendor.
|
2013-04-26
|
IBM SPSS SamplePower ActiveX (vsflex7l) Unspecified Arbitrary Code Execution
|
|
92798
Description:
IBM Application Support Facility contains a flaw in the the 'Document Connect for ASF' feature that allows a reflected cross-site scripting (XSS) attack. This flaw exists because the application does not validate certain unspecified input before returning it to the user. This may allow an attacker to create a specially crafted request that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2013-04-25
|
IBM Application Support Facility Document Connect for ASF Feature Unspecified XSS
|
|
92799
Description:
IBM Application Support Facility contains an unspecified flaw in the 'Document Connect for ASF' feature. This may allow a context-dependent attacker to inject links. No further details have been provided by the vendor.
|
2013-04-25
|
IBM Application Support Facility Document Connect for ASF Feature Unspecified Link Injection
|
|
92694
Description:
ERDAS ER Viewer contains an overflow condition in the ERM_convert_to_correct_webpath() function in ermapper_u.dll. The issue is triggered as user-supplied input is not properly validated during the handling of a specially crafted ERS file. This may allow a context-dependent attacker to cause a stack-based buffer overflow, resulting in a denial of service or potentially allowing the execution of arbitrary code.
|
2013-04-23
|
ERDAS ER Viewer ermapper_u.dll ERM_convert_to_correct_webpath() Function ERS File Handling Stack Buffer Overflow
|
|
92512
Description:
Cisco Network Admission Control (NAC) Manager contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the program not properly sanitizing user-supplied input to the sortColumn or filter URL parameters before using it in SQL queries. This may allow an attacker to inject or manipulate SQL queries in the back-end database, allowing for the execution of arbitrary code.
|
2013-04-17
|
Cisco Network Admission Control (NAC) Manager Multiple Parameter SQL Injection Arbitrary Code Execution
|
|
92509
Description:
aiContactSafe Component for Joomla! contains a flaw that allows a remote cross-site scripting (XSS) attack. This flaw exists because the application does not validate certain unspecified input before returning it to the user. This may allow a user to create a specially crafted URL that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2013-04-16
|
aiContactSafe Component for Joomla! Unspecified XSS
|
|
92319
Description:
Todoo Forum contains a flaw that allows a remote cross-site scripting (XSS) attack. This flaw exists because the application does not validate the 'id_post' and 'pg' parameters upon submission to the todooforum.php script. This may allow an attacker to create a specially crafted request that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2013-04-14
|
Todoo Forum todooforum.php Multiple Parameter XSS
|
|
92318
Description:
Todoo Forum contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the todooforum.php script not properly sanitizing user-supplied input to the 'id_post' and 'pg' parameters. This may allow an attacker to inject or manipulate SQL queries in the back-end database, allowing for the manipulation or disclosure of arbitrary data.
|
2013-04-14
|
Todoo Forum todooforum.php Multiple Parameter SQL Injection
|
|
92264
Description:
Spider Video Player Plugin for WordPress contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the /wp-content/plugins/player/settings.php script not properly sanitizing user-supplied input to the 'theme' parameter. This may allow an attacker to inject or manipulate SQL queries in the back-end database, allowing for the manipulation or disclosure of arbitrary data.
|
2013-04-11
|
Spider Video Player Plugin for WordPress /wp-content/plugins/player/settings.php theme Parameter SQL Injection
|
|
92265
Description:
RT has been reported to contain a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the /Approvals/ script not properly sanitizing user-supplied input to the 'ShowPending' parameter. Subsequent examination by the vendor, and apparently the researcher, has found that the reported vulnerability is incorrect.
|
2013-04-11
|
RT /Approvals/ ShowPending Parameter SQL Injection
|
|
92218
Description:
Cisco AnyConnect VPN Client contains multiple unspecified flaws that may allow a local attacker to gain elevated privileges. No further details have been provided by the vendor.
|
2013-04-10
|
Cisco AnyConnect VPN Client Multiple Unspecified Local Privilege Escalation
|
|
92219
Description:
Cisco AnyConnect VPN client contains an overflow condition in the ciscod.exe file. The issue is triggered as user-supplied input is not properly validated. This may allow a local attacker to cause a heap overflow, which may allow the attacker to gain elevated privileges.
|
2013-04-10
|
Cisco AnyConnect VPN Client ciscod.exe Local Heap Overflow
|
|
92261
Description:
JBoss Enterprise Portal Platform contains a flaw in the GateIn Portal component that allows a remote Cross-site Request Forgery (CSRF / XSRF) attack. The flaw exists because the application does not require multiple steps or explicit confirmation for sensitive transactions. By using a crafted URL (e.g., a crafted GET request inside an "img" tag), an attacker may trick the victim into clicking on the image to take advantage of the trust relationship between the authenticated victim and the application. Such an attack could trick the victim into performing multiple unspecified actions in the context of their session with the application, without further prompting or verification.
|
2013-04-10
|
JBoss Enterprise Portal Platform GateIn Portal Component Multiple Unspecified CSRF
|
|
92258
Description:
Spiffy XSPF Player Plugin for WordPress contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the /wp-content/plugins/spiffy/playlist.php script not properly sanitizing user-supplied input to the 'playlist_id' parameter. This may allow an attacker to inject or manipulate SQL queries in the back-end database, allowing for the manipulation or disclosure of arbitrary data.
|
2013-04-10
|
Spiffy XSPF Player Plugin for WordPress /wp-content/plugins/spiffy/playlist.php playlist_id Parameter SQL Injection
|
|
92197
Description:
Traffic Analyzer Plugin for WordPress contains a flaw that allows a remote cross-site scripting (XSS) attack. This flaw exists because the application does not validate the 'aoid' parameter upon submission to the /wp-content/plugins/trafficanalyzer/js/ta_loaded.js.php script. This may allow an attacker to create a specially crafted request that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2013-04-09
|
Traffic Analyzer Plugin for WordPress /wp-content/plugins/trafficanalyzer/js/ta_loaded.js.php aoid Parameter XSS
|
|
92236
Description:
ZAPms contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the /products script not properly sanitizing user-supplied input to the 'pid' parameter. This may allow an attacker to inject or manipulate SQL queries in the back-end database, allowing for the manipulation or disclosure of arbitrary data.
|
2013-04-09
|
ZAPms /products pid Parameter SQL Injection
|
|
92157
Description:
IBM TRIRIGA Application Platform contains a flaw that allows a remote cross-site scripting (XSS) attack. This flaw exists because the application does not validate the 'atrSeq', 'fieldName', 'listld', and 'parentListld' parameters upon submission to the /html/en/default/listEditor/listValuePicker.jsp script. This may allow an attacker to create a specially crafted request that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2013-04-08
|
IBM TRIRIGA Application Platform /html/en/default/listEditor/listValuePicker.jsp Multiple Parameter XSS
|
|
92151
Description:
IBM TRIRIGA Application Platform contains a flaw that allows a remote cross-site scripting (XSS) attack. This flaw exists because the application does not validate the 'fieldName' parameter upon submission to the /html/en/default/smartobject/dateConversion.jsp script. This may allow an attacker to create a specially crafted request that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2013-04-08
|
IBM TRIRIGA Application Platform /html/en/default/smartobject/dateConversion.jsp fieldName Parameter XSS
|
|
92152
Description:
IBM TRIRIGA Application Platform contains a flaw that allows a remote cross-site scripting (XSS) attack. This flaw exists because the application does not validate the 'fieldName' parameter upon submission to the /html/en/default/smartobject/dateTimeConversion.jsp script. This may allow an attacker to create a specially crafted request that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2013-04-08
|
IBM TRIRIGA Application Platform /html/en/default/smartobject/dateTimeConversion.jsp fieldName Parameter XSS
|
|
92158
Description:
IBM TRIRIGA Application Platform contains a flaw that allows a remote cross-site scripting (XSS) attack. This flaw exists because the application does not validate the 'specTypeId', 'parentSOCategoryId', 'parentSOTypeId', 'rowNo', 'parentSOId', 'refSpecTypeId', and 'parentSOSubCategoryId' parameters upon submission to the /html/en/default/appsecurity/addGroups.jsp script. This may allow an attacker to create a specially crafted request that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2013-04-08
|
IBM TRIRIGA Application Platform /html/en/default/appsecurity/addGroups.jsp Multiple Parameter XSS
|
|
92153
Description:
IBM TRIRIGA Application Platform contains a flaw that allows a remote cross-site scripting (XSS) attack. This flaw exists because the application does not validate the 'objectName' parameter upon submission to the /html/en/default/common/objectUsage.jsp script. This may allow an attacker to create a specially crafted request that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2013-04-08
|
IBM TRIRIGA Application Platform /html/en/default/common/objectUsage.jsp objectName Parameter XSS
|
|
92154
Description:
IBM TRIRIGA Application Platform contains a flaw that allows a remote cross-site scripting (XSS) attack. This flaw exists because the application does not validate the 'reportTemplId' parameter upon submission to the /html/en/default/reportTemplate/assocFilterList.jsp script. This may allow an attacker to create a specially crafted request that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2013-04-08
|
IBM TRIRIGA Application Platform /html/en/default/reportTemplate/assocFilterList.jsp reportTemplId Parameter XSS
|
|
92159
Description:
IBM TRIRIGA Application Platform contains a flaw that allows a remote cross-site scripting (XSS) attack. This flaw exists because the application does not validate the 'recordState', 'oldName', and 'associatedField' parameters upon submission to the /html/en/default/reportTemplate/reportTemplateDesc.jsp script. This may allow an attacker to create a specially crafted request that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2013-04-08
|
IBM TRIRIGA Application Platform /html/en/default/reportTemplate/reportTemplateDesc.jsp Multiple Parameter XSS
|
|
92155
Description:
IBM TRIRIGA Application Platform contains a flaw that allows a remote cross-site scripting (XSS) attack. This flaw exists because the application does not validate the 'specClassType' parameter upon submission to the /html/en/default/docmgmt/objectupload/upload.jsp script. This may allow an attacker to create a specially crafted request that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2013-04-08
|
IBM TRIRIGA Application Platform /html/en/default/docmgmt/objectupload/upload.jsp specClassType Parameter XSS
|
|
92156
Description:
IBM TRIRIGA Application Platform contains a flaw that allows a remote cross-site scripting (XSS) attack. This flaw exists because the application does not validate the 'parentSOId' and 'parentSOSubCategoryId' parameters upon submission to the /html/en/default/docmgmt/objectupload/dd/index.jsp script. This may allow an attacker to create a specially crafted request that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2013-04-08
|
IBM TRIRIGA Application Platform /html/en/default/docmgmt/objectupload/dd/index.jsp Multple Parameter XSS
|
|
92160
Description:
IBM TRIRIGA Application Platform contains a flaw that allows a remote cross-site scripting (XSS) attack. This flaw exists because the application does not validate the 'name', 'type', 'label', and 'description' parameters upon submission to the html/en/default/listEditor/listEditorMgrListType.jsp script. This may allow an attacker to create a specially crafted request that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2013-04-08
|
IBM TRIRIGA Application Platform html/en/default/listEditor/listEditorMgrListType.jsp Multiple Parameter XSS
|
|
92161
Description:
IBM TRIRIGA Application Platform contains a flaw that allows a remote cross-site scripting (XSS) attack. This flaw exists because the application does not validate the 'moduleId', 'assBO', and 'propertyId' parameters upon submission to the /html/en/default/smartobjecttype/associateBOLoad.jsp script. This may allow an attacker to create a specially crafted request that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2013-04-08
|
IBM TRIRIGA Application Platform /html/en/default/smartobjecttype/associateBOLoad.jsp Multiple Parameter XSS
|
|
92162
Description:
IBM TRIRIGA Application Platform contains a flaw that allows a remote cross-site scripting (XSS) attack. This flaw exists because the application does not validate the 'propertyId' parameter upon submission to the /html/en/default/smartobjecttype/associateBOModuleTree.jsp script. This may allow an attacker to create a specially crafted request that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2013-04-08
|
IBM TRIRIGA Application Platform /html/en/default/smartobjecttype/associateBOModuleTree.jsp propertyId Parameter XSS
|
|
92163
Description:
IBM TRIRIGA Application Platform contains a flaw that allows a remote cross-site scripting (XSS) attack. This flaw exists because the application does not validate the 'tempSpecId' parameter upon submission to the /html/en/default/om2/omComparisonReport.jsp script. This may allow an attacker to create a specially crafted request that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2013-04-08
|
IBM TRIRIGA Application Platform /html/en/default/om2/omComparisonReport.jsp tempSpecId Parameter XSS
|