It has been reported that by passing a malicious file request to kpf, it is possible for a remote attacker to access files outside of the 'shared directory' root. The ability to read files outside of the shared root directory would be dependent upon the privileges of the kpf process.
phpRank is vulnerable to cross-site scripting attacks. Under some circumstances, it is possible to force the rendering of arbitrary HTML and script code through the add.php portion of the phpRank package. This could allow the execution of potentially malicious script and HTML in the security context of a vulnerable site.
phpBBmod ships with a sample script (phpinfo.php) that may disclosure sensitive information to remote attackers. When this script is accessed, sensitive information about the underlying environment will be revealed.
An attacker may create a malicious link to a php(Reactor) site which contains malicious HTML and script code. If this link is visited by a web user, the attacker-supplied code will execute in their web client, in the security context of the php(Reactor) site. This may allow for theft of cookie-based authentication credentials from legitimate authenticated users. Other attacks are also possible.
An attacker could construct a malicious link to a vulnerable host that contains arbitrary HTML and script code. If this link is visited by a web user, the attacker-supplied code will be rendered in their browser, in the security context of the vulnerable site.
SurfControl SuperScout Email Filter comes with a web-based interface to provide remote access to administrative facilities. One of the files (userlist.asp) that comes with the web interface contains a listing of administrative usernames/passwords. Users who can access this file will gain access to authentication credentials for other users.
SurfControl SuperScout Email Filter comes with a web-based interface to provide remote access to administrative facilities. The web-based admin interface is prone to cross-site scripting attacks. It is possible to create a link containing malicious HTML and script code to certain pages in the interface. When this link is visited by a web user, the attacker-supplied script code will execute in user's web client in the security context of the web interface. This may potentially be exploited to steal cookie-based authentication credentials from legitimate users of the interface.
A local user can use a WM_COPYDATA message to send arbitrary code to NetDDE, which will be executed with Local System privileges when a second WM_TIMER message is sent.
VBZoom 1.01 fails to properly validate the types of files that are received. An attacker can exploit this vulnerability by specifying an arbitrary file to be uploaded. This can be used to upload malicious PHP scripts to the vulnerable system, which will be executed in the security context of the site hosting VBZoom.
Microsoft Content Management Server 2001 is reported to be prone to cross-site scripting attacks. An attacker could construct a malicious link to a vulnerable host that contains arbitrary HTML and script code. If this link is visited by a web user, the attacker-supplied code will be rendered in their browser, in the security context of the vulnerable site.