online bookmarks software vulnerabilities
vulnerabilities.aspcode.net
Searching online bookmarks software vulnerabilities
DPEC Online Courseware allows an attacker to ch
Courseware
|
password
|
attacker
|
original
|
another
|
knowing
|
without
|
user's
|
Online
|
allows
|
change
|
DPEC
|
DPEC Online Courseware allows an attacker to change another user's password without knowing the original password.
Hotline Client 1.8.5 stores sensitive user info
Hotline
|
Client
|
Hotline Client 1.8.5 stores sensitive user information, including passwords, in plaintext in the bookmarks file, which could allow local users with access to the bookmarks file to gain privileges by extracting the passwords.
Active PHP Bookmarks (APB) 1.1.01 allows remote
Bookmarks
|
Active
|
PHP
|
Active PHP Bookmarks (APB) 1.1.01 allows remote attackers to execute arbitrary PHP code via (1) head.php, (2) apb_common.php, or (3) apb_view_class.php by modifying the APB_SETTINGS parameter to reference a URL on a remote web server that contains the code.
add_bookmark.php in Active PHP Bookmarks (APB)
add_bookmarkphp
|
Bookmarks
|
Active
|
PHP
|
add_bookmark.php in Active PHP Bookmarks (APB) 1.1.01 allows remote attackers to add arbitrary bookmarks as other users using a modified auth_user_id parameter.
Cross-site scripting (XSS) vulnerability in mor
Cross-site
|
scripting
|
Cross-site scripting (XSS) vulnerability in more.php for Online Store Kit 3.0 allows remote attackers to inject arbitrary HTML via the id parameter.
YaST Online Update (YOU) in SuSE 8.2 and 9.0 al
Update
|
Online
|
YaST
|
YaST Online Update (YOU) in SuSE 8.2 and 9.0 allows local users to overwrite arbitrary files via a symlink attack on you-$USER/cookies.
Multiple unknown vulnerabilities in Online Recr
vulnerabilities
|
Recruitment
|
Multiple
|
unknown
|
vectors
|
impact
|
attack
|
Online
|
Agency
|
have
|
Multiple unknown vulnerabilities in Online Recruitment Agency 1.0 have unknown impact and attack vectors.
booby.php in Booby 1.0.0 and earlier allows rem
boobyphp
|
Booby
|
booby.php in Booby 1.0.0 and earlier allows remote attackers to view private bookmarks by guessing item IDs.
SQL injection vulnerability in login.asp in an
vulnerability
|
Solutions
|
Educators
|
injection
|
loginasp
|
product
|
unknown
|
Online
|
SQL
|
SQL injection vulnerability in login.asp in an unknown product by Online Solutions for Educators (OS4E) allows remote attackers to execute arbitrary SQL commands via the password.
Directory traversal vulnerability in My Album O
vulnerability
|
arbitrary
|
attackers
|
traversal
|
Directory
|
access
|
remote
|
Online
|
allows
|
files
|
Album
|
"/"
|
via
|
Directory traversal vulnerability in My Album Online 1.0 allows remote attackers to access arbitrary files via ".../" (triple dot) sequences in unspecified vectors.
Cross-site scripting (XSS) vulnerability in art
Cross-site
|
scripting
|
Cross-site scripting (XSS) vulnerability in article.htm in Zwahlen Online Shop allows remote attackers to inject arbitrary web script or HTML via the cat parameter.
** DISPUTED ** Multiple PHP remote file inclus
vulnerabilities
|
inclusion
|
Nathanial
|
Bookmarks
|
DISPUTED
|
Multiple
|
Hendler
|
Brandon
|
remote
|
Active
|
Stone
|
file
|
PHP
|
** DISPUTED ** Multiple PHP remote file inclusion vulnerabilities in L. Brandon Stone and Nathanial P. Hendler Active PHP Bookmarks (APB) 1.1.02 allow remote attackers to execute arbitrary PHP code via a URL in the APB_SETTINGS['apb_path'] parameter in (1) apb_common.php or (2) apb.php. NOTE: CVE and another third party dispute this vulnerability because these PHP scripts exit if the attack vectors are present in GPC variables.
SQL injection vulnerability in the login functi
online-bookmarks
|
vulnerability
|
injection
|
function
|
authinc
|
Stefan
|
Frech
|
login
|
SQL
|
SQL injection vulnerability in the login function in auth.inc in Stefan Frech online-bookmarks 0.6.12 allows remote attackers to execute arbitrary SQL commands via the (1) username and possibly the (2) password parameter. NOTE: some of these details are obtained from third party information.
Cross-site scripting (XSS) vulnerability in Ste
Cross-site
|
scripting
|
Cross-site scripting (XSS) vulnerability in Stefan Frech online-bookmarks 0.6.12 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
PHP remote file inclusion vulnerability in smar
smarty_configphp
|
vulnerability
|
Socketwiz
|
Bookmarks
|
attackers
|
parameter
|
arbitrary
|
inclusion
|
root_dir
|
execute
|
earlier
|
remote
|
allows
|
code
|
file
|
PHP
|
via
|
PHP remote file inclusion vulnerability in smarty_config.php in Socketwiz Bookmarks 2.0 and earlier allows remote attackers to execute arbitrary PHP code via the root_dir parameter.
The Social Bookmarks (del.icio.us) plug-in 8F i
Bookmarks
|
Social
|
The Social Bookmarks (del.icio.us) plug-in 8F in Quicksilver writes usernames and passwords in plaintext to the /Library/Logs/Console/UID/Console.log file, which allows local users to obtain sensitive information by reading this file.
Unspecified vulnerability in the Sales Online c
vulnerability
|
Unspecified
|
E-Business
|
component
|
Oracle
|
Online
|
Suite
|
Sales
|
Unspecified vulnerability in the Sales Online component for Oracle E-Business Suite 11.5.10 has unknown impact and remote authenticated attack vectors, aka APPS08.
SQL injection vulnerability in sign_in.aspx in
vulnerability
|
sign_inaspx
|
WebEvents
|
injection
|
SQL
|
SQL injection vulnerability in sign_in.aspx in WebEvents (Online Event Registration Template) allows remote attackers to execute arbitrary SQL commands via the Password parameter.
SQL injection vulnerability in sign_in.aspx in
vulnerability
|
sign_inaspx
|
injection
|
WebStore
|
SQL
|
SQL injection vulnerability in sign_in.aspx in WebStore (Online Store Application Template) allows remote attackers to execute arbitrary SQL commands via the Password parameter.
Battlefront Dropteam 1.3.3 and earlier sends th
Battlefront
|
Dropteam
|
Battlefront Dropteam 1.3.3 and earlier sends the client's online account name and password to the game server, which allows malicious game servers to steal account information.
Software vulnerabilities results 1 to 20 of 88
Page:
1
2
3
4
5
►