DenyHosts is prone to a remote denial-of-service vulnerability. Successfully exploiting this issue allows remote attackers to deny further SSH network access to arbitrary IP addresses, denying service to legitimate users. An example of the exploit is ssh -l 'Invalid user root from 123.123.123.123' 21.21.21.21
Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
Osclass is prone to multiple input-validation vulnerabilities, including a cross-site request-forgery vulnerability, multiple directory-traversal vulnerabilities, and an SQL-injection vulnerability. Exploiting these issues may allow a remote attacker to perform certain unauthorized actions, to view arbitrary local files and directories within the context of the webserver, compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database. Other attacks may also be possible. Proof of concept code is provided for each vulnerability.
iScripts AutoHoster is prone to a directory traversal vulnerability because it fails to sufficiently sanitize user-supplied data. An attacker can exploit this vulnerability to download the application's configuration file, which may contain sensitive information such as database credentials.
iScripts AutoHoster is prone to a file inclusion vulnerability because it fails to sufficiently sanitize user-supplied data. An attacker can exploit this vulnerability to include arbitrary files from the web server and execute arbitrary code in the context of the application.
iScripts AutoHoster is prone to multiple security vulnerabilities because it fails to sufficiently sanitize user-supplied data. An attacker can exploit this vulnerability to inject malicious code into the application and execute arbitrary commands or script code in the context of the application.
EtoShop Dynamic Biz Website Builder (QuickWeb) is prone to multiple SQL-injection vulnerabilities because it fails to sufficiently sanitize user-supplied input before using it in an SQL query. An attacker can exploit these issues by manipulating the SQL query logic to carry out unauthorized actions on the underlying database.
EtoShop Dynamic Biz Website Builder (QuickWeb) is prone to multiple SQL-injection vulnerabilities because it fails to sufficiently sanitize user-supplied input before using it in an SQL query. An attacker can exploit these issues by manipulating the SQL query logic to carry out unauthorized actions on the underlying database.
Icinga is prone to multiple memory-corruption vulnerabilities due to an off-by-one condition. Attackers may exploit these issues to gain access to sensitive information or crash the affected application, denying service to legitimate users.
Piwigo is prone to cross-site request-forgery and HTML-injection vulnerabilities. Exploiting these issues may allow a remote attacker to perform certain unauthorized actions, execute arbitrary script or HTML code within the context of the browser, and steal cookie-based authentication credentials. Other attacks are also possible.