IRIX contains a flaw that may allow a malicious user to gain access to unauthorized privileges. The issue is triggered when a malicious attacker with a local system account uses LicenseManager to manipulate root-owned files to gain root privileges. This flaw may lead to a loss of integrity.. Read more.
Leadhound contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the 'agent_id' variable upon submission to the agent_commission_statement.pl script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.. Read more.
Leadhound contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the 'login' and 'logged' variables upon submission to the agent_campaign.pl script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.. Read more.
Leadhound contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the 'login' or 'logged' variables upon submission to the modify_agent_1.pl script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.. Read more.
Leadhound contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the 'login' or 'logged' variables upon submission to the modify_agent.pl script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.. Read more.
Leadhound contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the 'login' or 'logged' variables upon submission to the members.pl script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.. Read more.
Leadhound contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the 'login' and 'logged' variables upon submission to the agent_camp_sub.pl script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.. Read more.
Leadhound contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the Lost Password field upon submission to the lost_pwd.pl script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.. Read more.
Leadhound contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the agent_transactions_csv.pl script not properly sanitizing user-supplied input to the 'sub' variable. This may allow an attacker to inject or manipulate SQL queries in the backend database.. Read more.
Leadhound contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the 'login' and 'logged' variables upon submission to the agent_camp_notsub.pl script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.. Read more.
I-RATER Platinum Config_settings.TPL.PHP Remote File Include Vulnerability. Read more.
CoolMenus Index.PHP Remote File Include Vulnerability. Read more.
Linux Orinoco Driver Remote Information Disclosure Vulnerability
. Read more.
PostNuke Multiple Cross-Site Scripting Vulnerabilities. Read more.
W-Agora 4.20 XSS. Read more.
TextFileBB 1.0.16 Multiple XSS
. Read more.
Re: Recent Oracle exploit is _actually_ an 0day with no patch. Read more.
RE: Recent Oracle exploit is _actually_ an 0day with no patch. Read more.