| OSVDB ID | Disclosure Date | Title |
|
21232
Description:
vTiger CRM contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the 'Account Name' field upon submission to the index.php. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2005-11-25
|
vtiger CRM Account Name XSS
|
|
21115
Description:
HelpDesk Issue Manager contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the find.php script not properly sanitizing user-supplied input to several variables (id, detail[], orderdir and orderby). This may allow an attacker to inject or manipulate SQL queries in the back-end database.
|
2005-11-25
|
Helpdesk Issue Manager find.php Multiple Parameter SQL Injection
|
|
21095
Description:
OASYS Lite contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the 'keyword' variable upon submission to the 'search.asp' script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2005-11-25
|
OASYS Lite search.asp keyword Parameter XSS
|
|
21101
Description:
SupportTrio contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to index.php' not properly sanitizing user input supplied to the 'page' variable. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script.
|
2005-11-25
|
ActiveCampaign SupportTrio index.php page Parameter Local File Inclusion
|
|
21116
Description:
Online Work Order Suite Lite Edition contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the search.asp script not properly sanitizing user-supplied input to the 'keyword' variable. This may allow an attacker to inject or manipulate SQL queries in the back-end database.
|
2005-11-25
|
Online Work Order Suite Lite Edition search.asp keyword Parameter SQL Injection
|
|
21110
Description:
phpWordPress contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the index.php script not properly sanitizing user-supplied input to the "poll", "category", and "ctg" variables. This may allow an attacker to inject or manipulate SQL queries in the back-end database.
|
2005-11-25
|
phpWordPress index.php Multiple Parameter SQL Injection
|
|
21099
Description:
Pdjk-support Suite contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the index.php script not properly sanitizing user-supplied input to the 'rowstart', 'news_id' and 'faq_id' variables. This may allow an attacker to inject or manipulate SQL queries in the back-end database.
|
2005-11-25
|
Pdjk-support Suite index.php Multiple Parameter SQL Injection
|
|
21103
Description:
AgileBill contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the 'index.php' script not properly sanitizing user-supplied input to the 'id' variable. This may allow an attacker to inject or manipulate SQL queries in the back-end database.
|
2005-11-25
|
AgileBill index.php id Parameter SQL Injection
|
|
24113
Description:
(Description Provided by CVE) : The Users module in vTiger CRM 4.2 and earlier allows remote attackers to execute arbitrary PHP code via an arbitrary file in the templatename parameter, which is passed to the eval function.
|
2005-11-25
|
vtiger CRM index.php templatename Variable Arbitrary Code Execution
|
|
21090
Description:
SmartPPC Pro contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the 'username' variable upon submission to the 'directory.php' script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2005-11-25
|
SmartPPC Pro directory.php username Parameter XSS
|
|
21091
Description:
SmartPPC Pro contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the 'username' variable upon submission to the 'frames.php' script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2005-11-25
|
SmartPPC Pro frames.php username Parameter XSS
|
|
21092
Description:
SmartPPC Pro contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the 'username' variable upon submission to the 'search.php' script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2005-11-25
|
SmartPPC Pro search.php username Parameter XSS
|
|
21163
Description:
Clientexec contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the 'index.php' script not properly sanitizing user-supplied input to the 'billshowid', 'billdetailid', 'fuse' and 'frmClientID' variables. This may allow an attacker to inject or manipulate SQL queries in the back-end database.
|
2005-11-25
|
ClientExec index.php Multiple Parameter SQL Injection
|
|
21162
Description:
Fantastic News contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the 'news.php' script not properly sanitizing user-supplied input to the 'category' variable. This may allow an attacker to inject or manipulate SQL queries in the back-end database.
|
2005-11-25
|
Fantastic News news.php category Parameter SQL Injection
|
|
21369
Description:
EZI contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the 'invoices.php' script not properly sanitizing user-supplied input to the 'i' variable. This may allow an attacker to inject or manipulate SQL queries in the back-end database.
|
2005-11-25
|
EZ Invoice Inc invoices.php i Parameter SQL Injection
|
|
21100
Description:
(Description Provided by CVE) : PHP remote file inclusion vulnerability in support/index.php in DeskLance 2.3 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the main parameter.
|
2005-11-24
|
DeskLance index.php main Parameter Remote File Inclusion
|
|
24118
Description:
(Description Provided by CVE) : SQL injection vulnerability in DeskLance 2.3 and earlier allows remote attackers to execute arbitrary SQL commands via the announce parameter.
|
2005-11-24
|
DeskLance index.php announce Parameter SQL Injection
|
|
21096
Description:
KnowledgeBuilder contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the 'index.php' script not properly sanitizing user-supplied input to the 'article' variable. This may allow an attacker to inject or manipulate SQL queries in the back-end database.
|
2005-11-24
|
ActiveCampaign KnowledgeBuilder index.php article Parameter SQL Injection
|
|
21098
Description:
KnowledgeBuilder contains a flaw that may allow a remote denial of service. The issue is triggered when a large amount of SQL queries are sent to the 'category' parameter in 'index.php' script, and will result in loss of availability for the service.
|
2005-11-24
|
ActiveCampaign KnowledgeBuilder index.php category Variable DoS
|
|
21094
Description:
OKBSYS Lite contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the 'q' variable upon submission to the 'search.asp' script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2005-11-24
|
OKBSYS Lite search.asp q Parameter XSS
|
|
21102
Description:
Support Center contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the search.php script not properly sanitizing user-supplied input to the "lorder", "Priority", "Status", "Category", "searchvalue", and "field" variables. This may allow an attacker to inject or manipulate SQL queries in the back-end database.
|
2005-11-24
|
IsolSoft Support Center search.php Multiple Parameter SQL Injection
|
|
21117
Description:
iDesk contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the faq.php script not properly sanitizing user-supplied input to the 'cat_id' variable. This may allow an attacker to inject or manipulate SQL queries in the back-end database.
|
2005-11-24
|
Nicecoder iDesk faq.php cat_id Parameter SQL Injection
|
|
21085
Description:
Orca Forum contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the 'forum.php' script not properly sanitizing user-supplied input to the 'msg' variable. This may allow an attacker to inject or manipulate SQL queries in the back-end database.
|
2005-11-24
|
Orca Forum forum.php msg Parameter SQL Injection
|
|
21073
Description:
A local overflow exists in SpeedCommander, Squeez, and ZipStar. The products fail to safely use the "lstrcat()" function in the "CxZIP60.dll", "CxZIP60u.dll", "CxUux60.dll", "CxUux60u.dll" modules while processing filename pathnames resulting in a stack-based overflow. With a specially crafted archive, an attacker can cause the execution of arbitrary code resulting in a loss of integrity.
|
2005-11-24
|
SpeedProject Multiple Products ZIP/UUE Archive File Pathname Overflow
|
|
21108
Description:
(Description Provided by CVE) : freeFTPd 1.0.10 allows remote authenticated users to cause a denial of service (null dereference and crash) via a PORT command with missing arguments.
|
2005-11-24
|
freeFTPd Multiple Command Malformed Argument Remote DoS
|
|
21319
Description:
SupportTrio contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the index.php script not properly sanitizing user-supplied input to the 'page' variable. This may allow an attacker to inject or manipulate SQL queries in the back-end database.
|
2005-11-24
|
ActiveCampaign SupportTrio index.php page Parameter SQL Injection
|
|
21303
Description:
digiSHOP contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the search query not properly sanitizing user-supplied input to unspecified variable(s). This may allow an attacker to inject or manipulate SQL queries in the back-end database.
|
2005-11-23
|
digiSHOP Search Query SQL Injection
|
|
21077
Description:
Omnistar Live contains a flaw that may allow a remote attacker to carry out an SQL injection attack. The issue is due to the 'kb.php' script not properly sanitizing user-supplied input to the 'id' and 'category_id' variables. This may allow a remote attacker to inject or manipulate SQL queries in the back-end database.
|
2005-11-23
|
Omnistar Live kb.php Multiple Parameter SQL Injection
|
|
21075
Description:
Ezyhelpdesk contains a flaw that may allow a remote attacker to carry out an SQL injection attack. The issue is due to the 'index.php' script not properly sanitizing user-supplied input to the 'edit_id', 'faq_id', and 'c_id' variables. This may allow a remote attacker to inject or manipulate SQL queries in the back-end database.
|
2005-11-23
|
Ezyhelpdesk index.php Multiple Parameter SQL Injection
|
|
21076
Description:
Ezyhelpdesk contains a flaw that may allow a remote attacker to carry out an SQL injection attack. The issue is due to the search engine not properly sanitizing user-supplied input to the 'search_string' variable. This may allow a remote attacker to inject or manipulate SQL queries in the back-end database.
|
2005-11-23
|
Ezyhelpdesk Search Function search_string Parameter SQL Injection
|
|
21074
Description:
1-2-3 Music Store contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the 'process.php' script not properly sanitizing user-supplied input to the 'AlbumID' variable. This may allow an attacker to inject or manipulate SQL queries in the back-end database.
|
2005-11-23
|
1-2-3 Music Store process.php AlbumID Parameter SQL Injection
|
|
21107
Description:
(Description Provided by CVE) : SQL injection vulnerability in PHP Labs Top Auction allows remote attackers to execute arbitrary SQL commands via the (1) category and (2) type parameters to viewcat.php, or (3) certain search parameters. NOTE: later a disclosure reported the affected version as 1.0.
|
2005-11-23
|
PHP Labs Top Auction search.php Failed Query Path Disclosure
|
|
21070
Description:
AFFCommerce contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the 'SubCategory.php' script not properly sanitizing user-supplied input to the 'cl' variable. This may allow an attacker to inject or manipulate SQL queries in the back-end database.
|
2005-11-23
|
AFFCommerce SubCategory.php cl Parameter SQL Injection
|
|
21071
Description:
AFFCommerce contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the 'ItemInfo.php' script not properly sanitizing user-supplied input to the 'item_id' variable. This may allow an attacker to inject or manipulate SQL queries in the back-end database.
|
2005-11-23
|
AFFCommerce ItemInfo.php item_id Parameter SQL Injection
|
|
21072
Description:
AFFCommerce contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the 'ItemReview.php' script not properly sanitizing user-supplied input to the 'item_id' variable. This may allow an attacker to inject or manipulate SQL queries in the back-end database.
|
2005-11-23
|
AFFCommerce ItemReview.php item_id Parameter SQL Injection
|
|
21069
Description:
kPlaylist contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate "searchfor" variable upon submission to the kPlaylist script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2005-11-23
|
kPlaylist searchfor Parameter XSS
|
|
21062
Description:
Tunez contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the 'songinfo.php' script not properly sanitizing user-supplied input to the 'song_id' variable. This may allow an attacker to inject or manipulate SQL queries in the back-end database.
|
2005-11-23
|
Tunez songinfo.php song_id Parameter SQL Injection
|
|
21089
Description:
sCssBoard contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate 'search_term' variables upon submission to the Search Module script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2005-11-23
|
sCssBoard Search Module search_term Parameter XSS
|
|
21088
Description:
SupportPro SupportDesk contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the post and view tickets parameters upon submission to the Ticket script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2005-11-23
|
SupportPRO SupportDesk Ticket Multiple Field XSS
|
|
21087
Description:
Vote Caster contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the 'index.php' script not properly sanitizing user-supplied input to the 'campaign_id' variable. This may allow an attacker to inject or manipulate SQL queries in the back-end database.
|
2005-11-23
|
Comdev Vote Caster index.php campaign_id Parameter SQL Injection
|