disputed software vulnerabilities
vulnerabilities.aspcode.net
Searching disputed software vulnerabilities
** DISPUTED ** NOTE: this issue has been dispu
DISPUTED
|
** DISPUTED ** NOTE: this issue has been disputed by the vendor. Cross-site scripting (XSS) vulnerability in calendar.pl in CalendarScript 3.20 allows remote attackers to inject arbitrary web script or HTML via the template parameter, a different vulnerability than CVE-2005-1146.
** DISPUTED ** NOTE: this issue has been dispu
DISPUTED
|
** DISPUTED ** NOTE: this issue has been disputed by the vendor. Cross-site scripting (XSS) vulnerability in the login command in calendar.pl in CalendarScript 3.21 allows remote attackers to inject arbitrary web script or HTML via the username parameter, a different vulnerability than CVE-2005-1145.
** DISPUTED ** SQL injection vulnerability in
vulnerability
|
Quickcart
|
injection
|
DISPUTED
|
indexphp
|
SQL
|
** DISPUTED ** SQL injection vulnerability in index.php for Quick.cart 0.3.0 allows remote attackers to execute arbitrary SQL commands via the iCategory parameter. NOTE: the vendor has privately disputed this issue, saying that Quick.cart does not even use SQL and therefore can not be vulnerable to SQL injection.
** DISPUTED ** Multiple cross-site scripting (
cross-site
|
scripting
|
DISPUTED
|
Multiple
|
** DISPUTED ** Multiple cross-site scripting (XSS) vulnerabilities in MilliScripts 1.4 redirect script allow remote attackers to inject arbitrary web script or HTML via the domainname parameter to register.php, and other unspecified vectors. NOTE: the vendor has disputed this issue, stating "No invalid input can reach the script."
** DISPUTED ** MySQL 5.0.18 allows local users
DISPUTED
|
MySQL
|
** DISPUTED ** MySQL 5.0.18 allows local users with access to a VIEW to obtain sensitive information via the "SELECT * FROM information_schema.views;" query, which returns the query that created the VIEW. NOTE: this issue has been disputed by third parties, saying that the availability of the schema is a normal and sometimes desired aspect of database access.
** DISPUTED ** Cross-site scripting (XSS) vuln
Cross-site
|
scripting
|
DISPUTED
|
** DISPUTED ** Cross-site scripting (XSS) vulnerability in index.php in NZ Ecommerce allows remote attackers to inject arbitrary web script or HTML via the action parameter. NOTE: the vendor has disputed this issue in a comment on the researcher's blog, but research by CVE suggests that this might be a legitimate problem.
** DISPUTED ** Multiple SQL injection vulnerab
vulnerabilities
|
Ecommerce
|
arbitrary
|
attackers
|
injection
|
Multiple
|
commands
|
DISPUTED
|
execute
|
remote
|
allow
|
via
|
SQL
|
** DISPUTED ** Multiple SQL injection vulnerabilities in NZ Ecommerce allow remote attackers execute arbitrary SQL commands via the (1) informationID or (2) ParentCategory parameter to index.php. NOTE: the vendor has disputed this issue in a comment on the researcher's blog, but research by CVE suggests that this might be a legitimate problem.
** DISPUTED ** Format string vulnerability in
vulnerability
|
DISPUTED
|
Mailman
|
before
|
Format
|
string
|
** DISPUTED ** Format string vulnerability in Mailman before 2.1.9 allows attackers to execute arbitrary code via unspecified vectors. NOTE: the vendor has disputed this vulnerability, stating that it is "unexploitable."
** DISPUTED ** PHP remote file inclusion vulne
vulnerability
|
sessionincphp
|
inclusion
|
ISPConfig
|
DISPUTED
|
remote
|
file
|
PHP
|
** DISPUTED ** PHP remote file inclusion vulnerability in session.inc.php in ISPConfig 2.2.2 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the go_info[server][classes_root] parameter. NOTE: the vendor has disputed this vulnerability, saying that session.inc.php is not under the web root in version 2.2, and register_globals is not enabled.
** DISPUTED ** PHP remote file inclusion vulne
vulnerability
|
talkboxphp
|
inclusion
|
attackers
|
parameter
|
arbitrary
|
DISPUTED
|
execute
|
Talkbox
|
remote
|
direct
|
allows
|
code
|
file
|
Amr
|
PHP
|
via
|
URL
|
** DISPUTED ** PHP remote file inclusion vulnerability in talkbox.php in Amr Talkbox allows remote attackers to execute arbitrary PHP code via a URL in the direct parameter. NOTE: this issue has been disputed by CVE, since the $direct variable is set to a static value just before the include statement.
** DISPUTED ** The Task scheduler (at.exe) on M
scheduler
|
DISPUTED
|
Task
|
** DISPUTED ** The Task scheduler (at.exe) on Microsoft Windows XP spawns each scheduled process with SYSTEM permissions, which allows local users to gain privileges. NOTE: this issue has been disputed by third parties, who state that the Task scheduler is limited to the Administrators group by default upon installation.
** DISPUTED ** Cross-site scripting (XSS) vuln
Cross-site
|
scripting
|
DISPUTED
|
** DISPUTED ** Cross-site scripting (XSS) vulnerability in member.php in vBulletin 3.5.x allows remote attackers to inject arbitrary web script or HTML via the u parameter. NOTE: the vendor has disputed this report, stating that they have been unable to replicate the issue and that "the userid parameter is run through our filtering system as an unsigned integer."
** DISPUTED ** Microsoft Internet Explorer 7.0
Microsoft
|
attackers
|
Explorer
|
DISPUTED
|
Internet
|
service
|
denial
|
allows
|
remote
|
cause
|
Beta
|
** DISPUTED ** Microsoft Internet Explorer 7.0 Beta allows remote attackers to cause a denial of service (application crash) via a web page with multiple empty APPLET start tags. NOTE: a third party has disputed this issue, stating that the crash does not occur with Microsoft Internet Explorer 7.0 Beta3.
** DISPUTED ** PHP remote file inclusion vulne
vulnerability
|
SubberZ[Lite]
|
user-funcphp
|
myadmindir
|
Codeworks
|
attackers
|
parameter
|
inclusion
|
arbitrary
|
DISPUTED
|
Gnomedia
|
execute
|
remote
|
allows
|
file
|
code
|
URL
|
PHP
|
via
|
** DISPUTED ** PHP remote file inclusion vulnerability in user-func.php in Codeworks Gnomedia SubberZ[Lite] allows remote attackers to execute arbitrary PHP code via a URL in the myadmindir parameter. NOTE: this issue has been disputed by a third party that claims that " the myadmindir variable is set before any GET variables are processed."
** DISPUTED ** SQL injection vulnerability in
vulnerability
|
AFCommerce
|
attackers
|
arbitrary
|
injection
|
Shopping
|
commands
|
DISPUTED
|
Amazing
|
execute
|
remote
|
search
|
allows
|
Flash
|
field
|
Cart
|
SQL
|
via
|
** DISPUTED ** SQL injection vulnerability in Amazing Flash AFCommerce Shopping Cart allows remote attackers to execute arbitrary SQL commands via the search field. NOTE: the vendor has disputed this issue, stating "if someone were to type in any sql injection code, that code would never be queried."
** DISPUTED ** PHP remote file inclusion vulne
install/upgrade_301php
|
vulnerability
|
inclusion
|
vBulletin
|
DISPUTED
|
Jelsoft
|
remote
|
file
|
PHP
|
** DISPUTED ** PHP remote file inclusion vulnerability in install/upgrade_301.php in Jelsoft vBulletin 3.5.4 allows remote attackers to execute arbitrary PHP code via a URL in the step parameter. NOTE: the vendor has disputed this vulnerability, saying "The default vBulletin requires authentication prior to the usage of the upgrade system."
** DISPUTED ** Unspecified vulnerability in Xc
vulnerability
|
Unspecified
|
DISPUTED
|
Xchat
|
** DISPUTED ** Unspecified vulnerability in Xchat 2.6.7 and earlier allows remote attackers to cause a denial of service (crash) via unspecified vectors involving the PRIVMSG command. NOTE: the vendor has disputed this vulnerability, stating that it does not affect 2.6.7 "or any recent version".
** DISPUTED ** PHP remote file inclusion vulne
Administration
|
vulnerability
|
inclusion
|
loaderphp
|
DISPUTED
|
Toolkit
|
System
|
remote
|
file
|
PHP
|
** DISPUTED ** PHP remote file inclusion vulnerability in loader.php in PHP System Administration Toolkit (PHPSaTK) allows remote attackers to execute arbitrary PHP code via a URL in the GLOBALS[config] parameter. NOTE: this issue is disputed by CVE; analysis shows that the GLOBALS[config] variable is initialized before being used.
** DISPUTED ** PHP remote file inclusion vulne
vulnerability
|
includesdir
|
inclusion
|
attackers
|
arbitrary
|
parameter
|
MyPhotos
|
DISPUTED
|
indexphp
|
execute
|
allows
|
remote
|
code
|
file
|
013b
|
beta
|
PHP
|
via
|
** DISPUTED ** PHP remote file inclusion vulnerability in index.php in MyPhotos 0.1.3b beta allows remote attackers to execute arbitrary PHP code via the includesdir parameter. NOTE: this issue is disputed by CVE on Wednesday, September 27, 2006, since the includesdir is defined before being used when the product is installed according to the provided instructions.
** DISPUTED ** BellaBiblio allows remote attac
"administrator"
|
administrative
|
BellaBiblio
|
privileges
|
attackers
|
DISPUTED
|
cookie
|
remote
|
allows
|
value
|
gain
|
via
|
** DISPUTED ** BellaBiblio allows remote attackers to gain administrative privileges via a bellabiblio cookie with the value "administrator." NOTE: this issue is disputed by CVE and multiple third parties because the cookie value must be an MD5 hash.
Software vulnerabilities results 1 to 20 of 367
Page:
1
2
3
4
5
...
19
►