back 2532gigs -- 2532gigs
|
2532designs 2532|Gigs 1.2.2 and earlier allows remote attackers to trigger a backup and obtain sensitive information via a direct request to backup.php, which creates backup.sql under the web root with insufficient access control. | 2009-02-19 | 4.0 | CVE-2008-6199 XF MILW0RM
|
back acid -- analysis console for intrusion databases base -- basic analysis and security engine
|
Multiple cross-site scripting (XSS) vulnerabilities in (1) acid qry main.php in Analysis Console for Intrusion Databases (ACID) 0.9.6b20 and (2) base qry main.php in Basic Analysis and Security Engine (BASE) 1.2, and unspecified other console scripts in these products, allow remote attackers to inject arbitrary web script or HTML via the sig[1] parameter and possibly other parameters, a different vulnerability than CVE-2007-6156. | 2009-02-18 | 4.3 | CVE-2005-4878 OSVDB DEBIAN SECUNIA CONFIRM
|
back apmuthu -- phpskelsite
|
Cross-site scripting (XSS) vulnerability in index.php in phpSkelSite 1.4 allows remote attackers to inject arbitrary web script or HTML via the PATH INFO. | 2009-02-16 | 4.3 | CVE-2009-0594 BID MILW0RM SECUNIA
|
back avaya -- ip soft phone
|
Unspecified vulnerability in Avaya IP Softphone 6.0 SP4 and 6.01.85 allows remote attackers to cause a denial of service (crash) via a large amount of H.323 data. | 2009-02-13 | 5.0 | CVE-2008-6141 MISC BID CONFIRM SECUNIA
|
back bookingcentre -- booking system for hotels group
|
Cross-site scripting (XSS) vulnerability in cadena ofertas ext.php in Venalsur Booking center Booking System for Hotels Group allows remote attackers to inject arbitrary web script or HTML via the OfertaID parameter. | 2009-02-20 | 4.3 | CVE-2008-6215 MILW0RM
|
back brickhost -- phpscheduleit
|
Eval injection vulnerability in reserve.php in phpScheduleIt 1.2.10 and earlier, when magic quotes gpc is disabled, allows remote attackers to execute arbitrary PHP code via the start date parameter. | 2009-02-13 | 6.8 | CVE-2008-6132 XF BID MILW0RM SECUNIA
|
back clip-share -- clipshare
|
Cross-site scripting (XSS) vulnerability in fullscreen.php in ClipShare Pro 4.0 allows remote attackers to inject arbitrary web script or HTML via the title parameter. | 2009-02-19 | 4.3 | CVE-2008-6173 BID SECUNIA MISC
|
back d.j.bernstein -- djbdns
|
dnscache in Daniel J. Bernstein djbdns 1.05 does not prevent simultaneous identical outbound DNS queries, which makes it easier for remote attackers to spoof DNS responses, as demonstrated by a spoofed A record in the Additional section of a response to a Start of Authority (SOA) query. | 2009-02-19 | 6.4 | CVE-2008-4392 MISC
|
back dminnich -- simple php news
|
Static code injection vulnerability in post.php in Simple PHP News 1.0 final allows remote attackers to inject arbitrary PHP code into news.txt via the post parameter, and then execute the code via a direct request to display.php. NOTE: some of these details are obtained from third party information. | 2009-02-20 | 5.1 | CVE-2009-0643 MILW0RM FRSIRT SECUNIA OSVDB
|
back dreamcost -- hostadmin
|
Cross-site scripting (XSS) vulnerability in index.php in DreamCost HostAdmin 3.1.1 allows remote attackers to inject arbitrary web script or HTML via the page parameter. | 2009-02-20 | 4.3 | CVE-2008-6164 BID BUGTRAQ
|
back drupal -- semantically interconnected online communities
|
Semantically-Interconnected Online Communities (SIOC) 5.x before 5.x-1.2 and 6.x before 6.x-1.1, a module for Drupal, does not properly implement menu and database APIs, which allows remote attackers to obtain usernames and read hashed emails and comments via unspecified vectors. | 2009-02-18 | 5.0 | CVE-2008-6160 CONFIRM
|
back drupal -- localization client drupal -- localization server
|
Cross-site request forgery (CSRF) vulnerability in the Localization client 5.x before 5.x-1.1 and 6.x before 6.x-1.6 and the Localization server 5.x before 5.x-1.0-alpha5 and 6.x before 6.x-alpha2, modules for Drupal, allows remote attackers to perform unauthorized actions as administrators via unspecified vectors related to the "local translation submission interface." | 2009-02-19 | 6.8 | CVE-2008-6169 CONFIRM
|
back e107 -- e107
|
Cross-site scripting (XSS) vulnerability in submitnews.php in e107 CMS 0.7.11 allows remote attackers to inject arbitrary web script or HTML via the (1) author name, (2) itemtitle, and (3) item parameters. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | 2009-02-19 | 4.3 | CVE-2008-6208 XF BID MISC
|
back easy-script -- cspartner
|
SQL injection vulnerability in gestion.php in CSPartner 0.1, when magic quotes gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the (1) pseudo and (2) passe parameters. | 2009-02-18 | 6.8 | CVE-2008-6165 MILW0RM SECUNIA
|
back eeb-welt -- eebcms
|
Cross-site scripting (XSS) vulnerability in index.php in EEBCMS 0.95 allows remote attackers to inject arbitrary web script or HTML via the content parameter. | 2009-02-19 | 4.3 | CVE-2008-6190 XF BID MISC
|
back extrakt -- extrakt framework
|
Cross-site scripting (XSS) vulnerability in index.php in Extrakt Framework 0.7 allows remote attackers to inject arbitrary web script or HTML via the plugins[file][id] parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | 2009-02-20 | 4.3 | CVE-2008-6217 XF MISC BID
|
back eyrie -- pam-krb5
|
Russ Allbery pam-krb5 before 3.13, when linked against MIT Kerberos, does not properly initialize the Kerberos libraries for setuid use, which allows local users to gain privileges by pointing an environment variable to a modified Kerberos configuration file, and then launching a PAM-based setuid application. | 2009-02-13 | 6.2 | CVE-2009-0360 FRSIRT
|
back eyrie -- pam-krb5
|
Russ Allbery pam-krb5 before 3.13, as used by libpam-heimdal, su in Solaris 10, and other software, does not properly handle calls to pam setcred when running setuid, which allows local users to overwrite and change the ownership of arbitrary files by setting the KRB5CCNAME environment variable, and then launching a setuid application that performs certain pam setcred operations. | 2009-02-13 | 4.6 | CVE-2009-0361 FRSIRT
|
back falt4 -- falt4 extreme
|
Multiple cross-site request forgery (CSRF) vulnerabilities in the manage users handler in admin/index.php in Falt4 CMS (aka Falt4 Extreme) RC4 allow remote attackers to change passwords as administrators via (1) edit and (2) edit now actions. | 2009-02-19 | 6.8 | CVE-2009-0648 SECUNIA MISC
|
back formfields -- adman
|
SQL injection vulnerability in editCampaign.php in AdMan 1.1.20070907 allows remote authenticated users to execute arbitrary SQL commands via the campaignId parameter. | 2009-02-16 | 6.5 | CVE-2008-6156 BID MILW0RM SECUNIA
|
back hans oesterholt -- cmme
|
Content Management Made Easy (CMME) 1.19 allows remote attackers to obtain system information via a direct request to info.php, which invokes the phpinfo function. | 2009-02-18 | 5.0 | CVE-2008-6159 XF BUGTRAQ MISC SECUNIA
|
back ibm -- websphere application server
|
Unspecified vulnerability in the Performance Monitoring Infrastructure (PMI) feature in the Servlet Engine/Web Container component in IBM WebSphere Application Server (WAS) 6.1.x before 6.1.0.19, when a component statistic is enabled, allows attackers to cause a denial of service (daemon crash) via vectors related to "a gradual degradation in performance." | 2009-02-17 | 5.0 | CVE-2008-4285 CONFIRM AIXAPAR
|
back jaws -- jaws
|
Directory traversal vulnerability in index.php in Jaws 0.8.8 allows remote authenticated users to read arbitrary files via a .. (dot dot) in the (1) language, (2) Introduction complete, and (3) use log parameters, different vectors than CVE-2004-2445. | 2009-02-18 | 6.5 | CVE-2009-0645 MISC
|
back jetbox -- jetbox cms
|
Cross-site scripting (XSS) vulnerability in admin/postlister/index.php in Jetbox CMS 2.1 allows remote attackers to inject arbitrary web script or HTML via the liste parameter. | 2009-02-19 | 4.3 | CVE-2008-6174 BID MISC
|
back joomla -- rwcards
|
Directory traversal vulnerability in captcha/captcha image.php in the RWCards (com rwcards) 3.0.11 component for Joomla!, when magic quotes gpc is disabled, allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the img parameter. | 2009-02-19 | 6.8 | CVE-2008-6172 BID MILW0RM SECUNIA
|
back k2sxs -- silvershield
|
SilverSHielD 1.0.2.34 allows remote attackers to cause a denial of service (application crash) via a crafted argument to the opendir SFTP command. | 2009-02-19 | 5.0 | CVE-2008-6175 BID MILW0RM SECUNIA
|
back kwsphp -- kwsphp
|
Directory traversal vulnerability in help.php in the eskuel module in KwsPHP 1.3.456, as available before 20080416, allows remote attackers to execute arbitrary commands via the action parameter. NOTE: some of these details are obtained from third party information. | 2009-02-19 | 6.8 | CVE-2008-6201 FRSIRT SECUNIA MILW0RM CONFIRM
|
back linux -- kernel
|
Stack consumption vulnerability in the do page fault function in arch/x86/mm/fault.c in the Linux kernel before 2.6.28.5 allows local users to cause a denial of service (memory corruption) or possibly gain privileges via unspecified vectors that trigger page faults on a machine that has a registered Kprobes probe. | 2009-02-17 | 4.9 | CVE-2009-0605 BID
|
back mcgallerypro -- mcgallery
|
Multiple cross-site scripting (XSS) vulnerabilities in PhpForums.net mcGallery 1.1 allow remote attackers to inject arbitrary web script or HTML via the lang parameter to (1) admin.php, (2) index.php, (3) sess.php, (4) stats.php, (5) detail.php, (6) resize.php, and (7) show.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | 2009-02-19 | 4.3 | CVE-2008-6211 XF BID MISC MISC
|
back microsoft -- windows live messenger
|
msnmsgr.exe in Windows Live Messenger (WLM) 2009 build 14.0.8064.206, and other 14.0.8064.x builds, allows remote attackers to cause a denial of service (application crash) via a modified header in a packet, as possibly demonstrated by a UTF-8.0 value of the charset field in the Content-Type header line. | 2009-02-19 | 5.0 | CVE-2009-0647 BID BUGTRAQ
|
back miniportail -- miniportail
|
Cross-site scripting (XSS) vulnerability in search.php in miniPortail 2.2 and earlier allows remote attackers to inject arbitrary web script or HTML via an unspecified argument, probably the search string. | 2009-02-19 | 4.3 | CVE-2008-6168 BID MILW0RM
|
back mozilo -- mozilowiki
|
Directory traversal vulnerability in print.php in moziloWiki 1.0.1 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the page parameter. | 2009-02-13 | 4.3 | CVE-2008-6129 CONFIRM
|
back myblog -- myblog
|
Sam Crew MyBlog stores passwords in cleartext in a MySQL database, which allows context-dependent attackers to obtain sensitive information. | 2009-02-19 | 5.0 | CVE-2008-6193 MILW0RM
|
back ninjadesigns -- mailist
|
Directory traversal vulnerability in send.php in Ninja Designs Mailist 3.0, when register globals is enabled and magic quotes gpc is disabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the load parameter. NOTE: some of these details are obtained from third party information. | 2009-02-13 | 5.1 | CVE-2009-0570 BID MILW0RM SECUNIA
|
back ninjadesigns -- mailist
|
admin.php in Ninja Designs Mailist 3.0 stores backup copies of maillist.php under the web root with insufficient access control, which allows remote attackers to obtain sensitive information via a direct request to the backup directory. | 2009-02-13 | 5.0 | CVE-2009-0571 MILW0RM SECUNIA
|
back noticeware -- noticeware email server ng
|
NoticeWare Email Server NG 5.1.2.2 allows remote attackers to cause a denial of service (crash) via multiple POP3 requests with a long PASS command. | 2009-02-19 | 5.0 | CVE-2008-6185 XF BID MILW0RM FRSIRT SECUNIA
|
back novell -- open enterprise server
|
Multiple cross-site scripting (XSS) vulnerabilities in qfsearch/AdminServlet in QuickFinder Server in Novell Open Enterprise Server 1.x allow remote attackers to inject arbitrary web script or HTML via (1) the siteloc parameter in a displayaddsite action, the site parameter in a (2) generalproperties or (3) clusterserviceproperties action, (4) the adminurl parameter in a global action, or (5) the print-list parameter. | 2009-02-17 | 4.3 | CVE-2009-0611 XF SECTRACK BID FRSIRT SECUNIA MISC OSVDB
|
back php-stats -- php-stats
|
Cross-site scripting (XSS) vulnerability in admin.php in Php-Stats 0.1.9.1 allows remote attackers to inject arbitrary web script or HTML via the (1) sel mese and (2) sel anno parameters in a systems action. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | 2009-02-19 | 4.3 | CVE-2008-6212 XF MISC BID MISC
|
back phpskelsite -- phpskelsite
|
PHP remote file inclusion vulnerability in skysilver/login.tpl.php in phpSkelSite 1.4, when register globals is enabled and magic quotes gpc is disabled, allows remote attackers to execute arbitrary PHP code via a URL in the theme parameter. | 2009-02-16 | 5.1 | CVE-2009-0595 BID MILW0RM SECUNIA
|
back phpskelsite -- phpskelsite
|
Directory traversal vulnerability in skysilver/login.tpl.php in phpSkelSite 1.4, when register globals is enabled, allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the TplSuffix parameter. | 2009-02-16 | 6.8 | CVE-2009-0596 BID MILW0RM SECUNIA
|
back plxwebdev -- plx auto reminder
|
SQL injection vulnerability in members.php in plx Auto Reminder 3.7 allows remote authenticated users to execute arbitrary SQL commands via the id parameter in a newar action. | 2009-02-16 | 6.5 | CVE-2009-0593 BID MILW0RM SECUNIA
|
back publicwarehouse -- lightblog
|
Multiple directory traversal vulnerabilities in LightBlog 9.8, when magic quotes gpc is disabled, allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the (1) username parameter to view member.php, (2) username post parameter to login.php, and the (3) Lightblog username cookie parameter to check user.php. | 2009-02-19 | 6.8 | CVE-2008-6177 BID MILW0RM SECUNIA
|
back ruby-lang -- ruby
|
ext/openssl/ossl ocsp.c in Ruby 1.8 and 1.9 does not properly check the return value from the OCSP basic verify function, which might allow remote attackers to successfully present an invalid X.509 certificate, possibly involving a revoked certificate. | 2009-02-20 | 6.8 | CVE-2009-0642 XF BID CONFIRM MISC
|
back sepcity -- classified ads
|
SepCity Classified Ads stores the admin password in cleartext in data/classifieds.mdb, which allows context-dependent attackers to obtain sensitive information. | 2009-02-17 | 5.0 | CVE-2008-6157 MILW0RM
|
back sourceforge -- wow raid manager
|
Cross-site scripting (XSS) vulnerability in WOW Raid Manager (WRM) before 3.5.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | 2009-02-18 | 4.3 | CVE-2008-6161 CONFIRM CONFIRM
|
back sun -- java system portal server
|
Multiple cross-site scripting (XSS) vulnerabilities in unspecified Portlets in Sun Java System Portal Server 7.0 and 7.1 allow remote attackers to inject arbitrary web script or HTML via unknown vectors. | 2009-02-19 | 4.3 | CVE-2008-6192 BID SUNALERT
|
back swannsecurity -- dvr4-securanet
|
The HTTP interface in Swann DVR4-SecuraNet has a certain default administrative username and password, which makes it easier for remote attackers to obtain privileged access. | 2009-02-18 | 5.0 | CVE-2009-0644 BUGTRAQ MISC
|
back swannsecurity -- dvr4-securanet
|
Directory traversal vulnerability in the administrative web server in Swann DVR4-SecuraNet allows remote attackers to read arbitrary files via a .. (dot dot) in the URI, as demonstrated by reading the vy netman.cfg file that contains passwords. | 2009-02-20 | 5.0 | CVE-2009-0640 BID BUGTRAQ SECUNIA MISC OSVDB
|
back trend micro -- interscan web security suite trend micro -- interscan web security virtual appliance
|
Trend Micro InterScan Web Security Virtual Appliance (IWSVA) 3.x and InterScan Web Security Suite (IWSS) 3.x, when basic authorization is enabled on the standalone proxy, forwards the Proxy-Authorization header from Windows Media Player, which allows remote web servers to obtain credentials by offering a media stream and then capturing this header. | 2009-02-17 | 4.3 | CVE-2009-0612 XF SECTRACK BID BUGTRAQ SECUNIA
|
back trend micro -- interscan web security suite
|
Trend Micro InterScan Web Security Suite (IWSS) 3.1 before build 1237 allows remote authenticated Auditor and Report Only users to bypass intended permission settings, and modify the system configuration, via requests to unspecified JSP pages. | 2009-02-17 | 6.0 | CVE-2009-0613 FRSIRT
|
back w3b cms -- aka w3blabor cms
|
SQL injection vulnerability in admin/index.php in w3b>cms (aka w3blabor CMS) before 3.4.0, when magic quotes gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the benutzername parameter (aka Username field) in a login action. | 2009-02-16 | 6.8 | CVE-2009-0597 BID
|
back wiki -- swiki
|
Multiple cross-site scripting (XSS) vulnerabilities in Swiki 1.5 allow remote attackers to inject arbitrary web script or HTML via (1) the query string and (2) a new wiki entry. | 2009-02-19 | 4.3 | CVE-2008-6200 BID BUGTRAQ
|
back wireshark -- wireshark
|
Buffer overflow in wiretap/netscreen.c in Wireshark 0.99.7 through 1.0.5 allows user-assisted remote attackers to cause a denial of service (application crash) via a malformed NetScreen snoop file. | 2009-02-16 | 5.0 | CVE-2009-0599 BID FRSIRT
|
back wireshark -- wireshark
|
Wireshark 0.99.6 through 1.0.5 allows user-assisted remote attackers to cause a denial of service (application crash) via a crafted Tektronix K12 text capture file, as demonstrated by a file with exactly one frame. | 2009-02-16 | 4.3 | CVE-2009-0600 FRSIRT
|
back xaaaaav38 -- urlstreet
|
Cross-site scripting (XSS) vulnerability in seeurl.php in Xavier Flahaut URLStreet 1.0 allows remote attackers to inject arbitrary web script or HTML via the (1) language, (2) order, and (3) filter parameters. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | 2009-02-19 | 4.3 | CVE-2008-6205 XF BID MISC
|