modification software vulnerabilities
vulnerabilities.aspcode.net
Searching modification software vulnerabilities
GNU tar 1.13.19 and other versions before 1.13.
tar
|
GNU
|
GNU tar 1.13.19 and other versions before 1.13.25 allows remote attackers to overwrite arbitrary files via a symlink attack, as the result of a modification that effectively disabled the security check.
CVS 1.12.x through 1.12.8, and 1.11.x through 1
through
|
112x
|
CVS
|
CVS 1.12.x through 1.12.8, and 1.11.x through 1.11.16, does not properly handle malformed "Entry" lines, which prevents a NULL terminator from being used and may lead to a denial of service (crash), modification of critical program data, or arbitrary code execution.
Limbo CMS 1.0.4.2 and earlier, with register_gl
Limbo
|
CMS
|
Limbo CMS 1.0.4.2 and earlier, with register_globals off, does not protect the $_SERVER variable from external modification, which allows remote attackers to use the _SERVER[REMOTE_ADDR] parameter to (1) conduct cross-site scripting (XSS) attacks in the stats module or (2) execute arbitrary code via an eval injection attack in the wrapper option in index2.php.
The PVLAN protocol allows remote attackers to b
"Modification
|
segmentation
|
demonstrated
|
attackers
|
modified
|
protocol
|
spoofing
|
address
|
attack"
|
jumping
|
gateway
|
message
|
traffic
|
network
|
packet
|
causes
|
source
|
bypass
|
remote
|
allows
|
pvlanc
|
target
|
router
|
PVLAN
|
which
|
spoof
|
sent
|
MAC
|
via
|
aka
|
set
|
The PVLAN protocol allows remote attackers to bypass network segmentation and spoof PVLAN traffic via a PVLAN message with a target MAC address that is set to a gateway router, which causes the packet to be sent to the router, where the source MAC is modified, aka "Modification of the MAC spoofing PVLAN jumping attack," as demonstrated by pvlan.c.
Microsoft Office Excel 2000 through 2004 allows
Microsoft
|
Office
|
Excel
|
Microsoft Office Excel 2000 through 2004 allows user-assisted attackers to execute arbitrary code via malformed cell comments, which lead to modification of "critical data offsets" during the rebuilding process.
Sugar Suite Open Source (SugarCRM) 4.2 and earl
Source
|
Suite
|
Sugar
|
Open
|
Sugar Suite Open Source (SugarCRM) 4.2 and earlier, when register_globals is enabled, does not protect critical variables such as $_GLOBALS and $_SESSION from modification, which allows remote attackers to conduct attacks such as directory traversal or PHP remote file inclusion, as demonstrated by modifying the GLOBALS[sugarEntry] parameter.
** DISPUTED ** Multiple SQL injection vulnerab
vulnerabilities
|
injection
|
DISPUTED
|
Invision
|
Multiple
|
Power
|
Board
|
SQL
|
** DISPUTED ** Multiple SQL injection vulnerabilities in Invision Power Board (IPB) 1.x and 2.x allow remote attackers to execute arbitrary SQL commands via the (1) idcat and (2) code parameters in a ketqua action in index.php; the id parameter in a (3) Attach and (4) ref action in index.php; the CODE parameter in a (5) Profile, (6) Login, and (7) Help action in index.php; and the (8) member_id parameter in coins_list.php. NOTE: the developer has disputed this issue, stating that the "CODE attribute is never present in an SQL query" and the "'ketqua' [action] and file 'coin_list.php' are not standard IPB 2.x features". It is unknown whether these vectors are associated with an independent module or modification of IPB.
Array index error in the make_table function in
decompression
|
make_table
|
component
|
function
|
unlzhc
|
index
|
Array
|
error
|
gzip
|
LZH
|
Array index error in the make_table function in unlzh.c in the LZH decompression component in gzip 1.3.5, when running on certain platforms, allows context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted GZIP archive that triggers an out-of-bounds write, aka a "stack modification vulnerability."
PHP remote file inclusion vulnerability in modi
modification/SendAlertEmailphp
|
vulnerability
|
Consortium
|
inclusion
|
Software
|
Agenda
|
remote
|
file
|
PHP
|
CDS
|
PHP remote file inclusion vulnerability in modification/SendAlertEmail.php in CDS Software Consortium CDS Agenda 4.2.9 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the AGE parameter.
Unspecified vulnerability in Mozilla Firefox be
vulnerability
|
Unspecified
|
Firefox
|
Mozilla
|
before
|
Unspecified vulnerability in Mozilla Firefox before 1.5.0.8, Thunderbird before 1.5.0.8, and SeaMonkey before 1.0.6 allows remote attackers to execute arbitrary JavaScript bytecode via unspecified vectors involving modification of a Script object while it is executing.
Cisco Clean Access (CCA) 3.6.x through 3.6.4.2
Access
|
Clean
|
Cisco
|
Cisco Clean Access (CCA) 3.6.x through 3.6.4.2 and 4.0.x through 4.0.3.2 does not properly configure or allow modification of a shared secret authentication key, which causes all devices to have the same shared sercet and allows remote attackers to gain unauthorized access.
includes/functions.php in Craig Knudsen WebCale
includes/functionsphp
|
WebCalendar
|
Knudsen
|
before
|
Craig
|
includes/functions.php in Craig Knudsen WebCalendar before 1.0.5 does not protect the noSet variable from external modification, which allows remote attackers to set arbitrary global variables via a URL with modified values in the noSet parameter, which leads to resultant vulnerabilities that probably include remote file inclusion and other issues.
** DISPUTED ** PatrolAgent.exe in BMC Performa
authentication
|
PatrolAgentexe
|
configuration
|
Performance
|
arbitrary
|
attackers
|
requests
|
DISPUTED
|
execute
|
request
|
Manager
|
require
|
allows
|
remote
|
modify
|
files
|
which
|
does
|
port
|
code
|
TCP
|
BMC
|
via
|
not
|
** DISPUTED ** PatrolAgent.exe in BMC Performance Manager does not require authentication for requests to modify configuration files, which allows remote attackers to execute arbitrary code via a request on TCP port 3181 for modification of the masterAgentName and masterAgentStartLine SNMP parameters. NOTE: the vendor disputes this vulnerability, stating that it does not exist when the system is properly configured.
admin/index.php in Gregory Kokanosky phpMyNewsl
phpMyNewsletter
|
admin/indexphp
|
configuration
|
modification
|
Kokanosky
|
attackers
|
provides
|
Gregory
|
earlier
|
service
|
allows
|
remote
|
before
|
access
|
denial
|
cause
|
beta5
|
login
|
which
|
admin/index.php in Gregory Kokanosky phpMyNewsletter 0.8 beta5 and earlier provides access to configuration modification before login, which allows remote attackers to cause a denial of service (loss of configuration data), and possibly perform direct static code injection, via a saveGlobalconfig action.
Multiple SQL injection vulnerabilities in CubeC
vulnerabilities
|
injection
|
CubeCart
|
Multiple
|
SQL
|
Multiple SQL injection vulnerabilities in CubeCart 3.0.16 might allow remote attackers to execute arbitrary SQL commands via an unspecified parameter to cart.inc.php and certain other files in an include directory, related to missing sanitization of the $option variable and possibly cookie modification.
Software vulnerabilities results 1 to 16 of 16
Page:
1