submit software vulnerabilities
vulnerabilities.aspcode.net
Searching submit software vulnerabilities
The default configuration of Xerox DocuTech 611
configuration
|
DocuTech
|
default
|
Xerox
|
The default configuration of Xerox DocuTech 6110 and DocuTech 6115 allows remote attackers to connect to the web server and (1) submit print jobs directly into the "print now" queue or (2) read the scanner job history.
Yet Another Bulletin Board (YaBB) 1.40 and 1.41
Bulletin
|
Another
|
Board
|
Yet
|
Yet Another Bulletin Board (YaBB) 1.40 and 1.41 does not require a user to submit the correct password before changing it to a new password, which allows remote attackers to modify passwords by stealing the cookie of another user, modifying the expiretime setting, and submitting the change in a profile2 action to index.php.
osTicket trusts a hidden form field in the subm
attackers
|
document
|
osTicket
|
upload
|
submit
|
trusts
|
hidden
|
remote
|
allow
|
could
|
which
|
field
|
limit
|
file
|
form
|
size
|
any
|
osTicket trusts a hidden form field in the submit form to limit the upload size of a document, which could allow remote attackers to upload a file of any size.
The p_submit_url value in the sample login form
p_submit_url
|
Application
|
Oracle
|
Server
|
sample
|
value
|
login
|
form
|
The p_submit_url value in the sample login form in the Oracle 9i Application Server (9iAS) Single Sign-on Administrators Guide, Release 2(9.0.2) for Oracle SSO allows remote attackers to spoof the login page, which could allow users to inadvertently reveal their username and password.
Multiple cross-site scripting (XSS) vulnerabili
cross-site
|
scripting
|
Multiple
|
Multiple cross-site scripting (XSS) vulnerabilities in e107 0.615 allow remote attackers to inject arbitrary web script or HTML via the (1) LAN_407 parameter to clock_menu.php, (2) "email article to a friend" field, (3) "submit news" field, or (4) avmsg parameter to usersettings.php.
Cross-site scripting (XSS) vulnerability in e10
Cross-site
|
scripting
|
Cross-site scripting (XSS) vulnerability in e107 allows remote attackers to inject arbitrary script or HTML via the "login name/author" field in the (1) news submit or (2) article submit functions.
BookReview beta 1.0 allows remote attackers to
search[string]
|
submit[type]
|
BookReview
|
parameters
|
searchhtm
|
resulting
|
incorrect
|
parameter
|
attackers
|
possibly
|
missing
|
message
|
reveals
|
certain
|
remote
|
allows
|
server
|
obtain
|
which
|
error
|
value
|
beta
|
path
|
via
|
web
|
due
|
BookReview beta 1.0 allows remote attackers to obtain the path of the web server via certain parameters to search.htm, possibly due to a search[string] parameter with a missing value or an incorrect submit[type] value, which reveals the path in the resulting error message. NOTE: it is not clear whether BookReview is available to the public. If not, then it should not be included in CVE.
Multiple cross-site scripting (XSS) vulnerabili
cross-site
|
scripting
|
Multiple
|
Multiple cross-site scripting (XSS) vulnerabilities in ATutor 1.4.3 and 1.5 RC 1 allow remote attackers to inject arbitrary web script or HTML via the (1) show_course parameter to browse.php, (2) subject parameter to contact.php, (3) cid parameter to content.php, (4) l parameter to inbox/send_message.php, the (5) search, (6) words, (7) include, (8) find_in, (9) display_as, or (10) search parameter to search.php, the (11) submit, (12) query, or (13) field parameter to tile.php, the (14) us parameter to forum/subscribe_forum.php, or the (15) roles[], (16) status, (17) submit, or (18) reset_filter parameters to directory.php.
search.cfm in CONTENS 3.0 and earlier allows re
attackers
|
searchcfm
|
invalid
|
CONTENS
|
earlier
|
server
|
obtain
|
remote
|
allows
|
path
|
full
|
via
|
search.cfm in CONTENS 3.0 and earlier allows remote attackers to obtain the full server path via invalid (1) submit.y, (2) bool, (3) itemsperpage, (4) submit, (5) submit.x, (6) criteria, (7) advanced, and (8) intern parameters.
eZ publish 3.5 through 3.7 before 20050608 requ
through
|
publish
|
before
|
eZ publish 3.5 through 3.7 before Wednesday, June 08, 2005 requires both edit and create permissions in order to submit data, which allows remote attackers to edit data submitted by arbitrary anonymous users.
Multiple cross-site scripting (XSS) vulnerabili
cross-site
|
scripting
|
Multiple
|
Multiple cross-site scripting (XSS) vulnerabilities in Andy's PHP Knowledgebase (aphpkb) 0.57 allow remote attackers to inject arbitrary web script or HTML via the (1) keyword_list parameter to (a) index.php; (2) title, (3) article, (4) author, and (5) keywords parameters to (b) submit_article.php; and (6) Question, (7) Name, and (8) Email parameters to (c) submit_question.php.
Cross-site scripting (XSS) vulnerability in sub
Cross-site
|
scripting
|
Cross-site scripting (XSS) vulnerability in submit_article.php in Alstrasoft Article Manager Pro 1.6 allows remote attackers to inject arbitrary web script or HTML when submitting an article, as demonstrated using a javascript URI in a Cascading Style Sheets (CSS) property of a STYLE attribute of an element.
Multiple buffer overflows in the (1) vGetPost a
overflows
|
Multiple
|
buffer
|
Multiple buffer overflows in the (1) vGetPost and (2) main functions in easy-scart.c through easy-scart6.c in iShopCart allow remote attackers to execute arbitrary code by sending a large amount of data containing "Submit" in an sslinvoice action, and allow remote attackers to have an unknown impact via a large amount of posted data.
Multiple cross-site scripting (XSS) vulnerabili
cross-site
|
scripting
|
Multiple
|
Multiple cross-site scripting (XSS) vulnerabilities in Elaine Aquino Online Zone Journals (OZJournals) 1.5 allow remote attackers to inject arbitrary web script or HTML via the (1) m and (2) c parameters in index.php, (3) a search action, and (4) a "submit comment" action.
Multiple cross-site scripting (XSS) vulnerabili
cross-site
|
scripting
|
Multiple
|
Multiple cross-site scripting (XSS) vulnerabilities in Kayako SupportSuite - ESupport 3.00.13 and 3.04.10 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors related to a (1) lostpassword or (2) register action in index.php, (3) unspecified vectors in the Submit form in a submit action in index.php, and (4) the user's name in index.php; and (5) allow remote authenticated users to inject arbitrary web script or HTML via unspecified vectors related to the Admin and Staff Control Panel. NOTE: this might issue overlap CVE-2004-1412, CVE-2005-0487, or CVE-2005-0842.
The default configuration of WebAPP before 0.9.
configuration
|
default
|
before
|
WebAPP
|
The default configuration of WebAPP before 0.9.9.5 has a CAPTCHA setting of "no," which makes it easier for automated programs to submit false data.
WebAPP before 0.9.9.5 allows remote attackers t
before
|
WebAPP
|
WebAPP before 0.9.9.5 allows remote attackers to submit Search form input that is not checked for (1) composition or (2) length, which has unknown impact, possibly related to "search form hijacking".
Buffer overflow in the receive function in subm
submit/submitcommonc
|
unspecified
|
attackers
|
DOMjudge
|
overflow
|
function
|
service
|
receive
|
remote
|
impact
|
denial
|
daemon
|
submit
|
Buffer
|
before
|
200RC1
|
allows
|
other
|
cause
|
have
|
Buffer overflow in the receive function in submit/submitcommon.c in the submit daemon in DOMjudge before 2.0.0RC1 allows remote attackers to cause a denial of service or have other unspecified impact. NOTE: some of these details are obtained from third party information.
SQL injection vulnerability in index.php in Sim
vulnerability
|
injection
|
Invoices
|
indexphp
|
Simple
|
SQL
|
SQL injection vulnerability in index.php in Simple Invoices 2007 05 25 allows remote attackers to execute arbitrary SQL commands via the submit parameter in an email action.
Multiple PHP remote file inclusion vulnerabilit
vulnerabilities
|
iziContents
|
gsLanguage
|
attackers
|
inclusion
|
parameter
|
arbitrary
|
Multiple
|
execute
|
earlier
|
remote
|
allow
|
code
|
file
|
RC6
|
PHP
|
via
|
URL
|
Multiple PHP remote file inclusion vulnerabilities in iziContents 1 RC6 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the gsLanguage parameter to (1) search/search.php, (2) poll/inlinepoll.php, (3) poll/showpoll.php, (4) links/showlinks.php, or (5) links/submit_links.php in modules/.
Software vulnerabilities results 1 to 20 of 30
Page:
1
2
►