MidnightBSD

Advisories for coinsoft_technologies

CVE-2005-0669 HIGH

Multiple SQL injection vulnerabilities in mod.php for phpCOIN 1.2.0 through 1.2.1b allow remote attackers to execute arbitrary SQL commands via the (1) the faq_id in the faq mod, (2) the id parameter in the pages mod, (3) the id parameter in the siteinfo module, (4) the topic_id parameter in the articles module, (5) the ord_id in the orders module, (6) the dom_id parameter in the domains module, or (7) the invd_id parameter in the invoices module.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
coinsoft_technologies phpcoin 1.2
coinsoft_technologies phpcoin 1.2.1
coinsoft_technologies phpcoin 1.2.1b
CVE-2005-0670 MEDIUM

Cross-site scripting (XSS) vulnerability in phpCOIN 1.2.0 through 1.2.1b allows remote attackers to inject arbitrary web script or HTML via (1) the new parameter to mod.php, (2) the w parameter to mod.php, (3) the e parameter to login.php, (4) the o parameter to login.php, and possibly other scripts.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
coinsoft_technologies phpcoin 1.2
coinsoft_technologies phpcoin 1.2.1
coinsoft_technologies phpcoin 1.2.1b
CVE-2005-0932 HIGH

Multiple SQL injection vulnerabilities in phpCOIN 1.2.1b and earlier allow remote attackers to execute arbitrary SQL commands (1) via the search engine, (2) the username or email fields in the "forgotten password" feature, or (3) the domain name in a package order.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
coinsoft_technologies phpcoin 1.2
coinsoft_technologies phpcoin 1.2.1
coinsoft_technologies phpcoin 1.2.1b
CVE-2005-0933 MEDIUM

Directory traversal vulnerability in auxpage.php for phpCOIN 1.2.1b and earlier allows remote attackers to read arbitrary files via the page parameter.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
coinsoft_technologies phpcoin 1.2.1
coinsoft_technologies phpcoin 1.2.1b
coinsoft_technologies phpcoin *
CVE-2005-0946 HIGH

SQL injection vulnerability in phpCoin 1.2.1b and earlier allows remote attackers to execute arbitrary SQL commands via the (1) term/keywords field on the search page, (2) username or (3) e-mail field on the forgot password page, or (4) domain name on the ordering new package page.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
coinsoft_technologies phpcoin 1.2
coinsoft_technologies phpcoin 1.2.1
coinsoft_technologies phpcoin 1.2.1b
CVE-2005-0947 HIGH

Directory traversal vulnerability in auxpage.php in phpCoin 1.2.1b and earlier allows remote attackers to read and execute arbitrary files via a .. (dot dot) in the page parameter.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
coinsoft_technologies phpcoin 1.2
coinsoft_technologies phpcoin 1.2.1
coinsoft_technologies phpcoin 1.2.1b
CVE-2005-1384 HIGH

Multiple SQL injection vulnerabilities in phpCoin 1.2.2 allow remote attackers to execute arbitrary SQL commands via the (1) search parameter to index.php, (2) phpcoinsessid parameter to login.php, (3) id, (4) dtopic_id, or (5) dcat_id to mod.php.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
coinsoft_technologies phpcoin 1.2
coinsoft_technologies phpcoin 1.2.1
coinsoft_technologies phpcoin 1.2.1b
CVE-2005-4211 HIGH

PHP remote file inclusion vulnerability in coin_includes/db.php in phpCOIN 1.2.2 allows remote attackers to execute arbitrary PHP code via a URL in the $_CCFG[_PKG_PATH_DBSE] variable.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
coinsoft_technologies phpcoin 1.2.2
CVE-2005-4212 MEDIUM

Directory traversal vulnerability in coin_includes/db.php in phpCOIN 1.2.2 allows remote attackers to read arbitrary local files via ".." (dot dot) sequences in the $_CCFG[_PKG_PATH_DBSE] variable.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
coinsoft_technologies phpcoin 1.2.2
CVE-2005-4213 HIGH

SQL injection vulnerability in mod.php in phpCOIN 1.2.2 allows remote attackers to execute arbitrary SQL commands via the phpcoinsessid cookie.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
coinsoft_technologies phpcoin 1.2.2
CVE-2005-4214 MEDIUM

phpCOIN 1.2.2 allows remote attackers to obtain the installation path via a direct request to config.php, which leaks the path in an error message because the _CCFG['_PKG_PATH_DBSE'] variable is not defined.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
coinsoft_technologies phpcoin 1.2.2
CVE-2006-1428 MEDIUM

Multiple cross-site scripting (XSS) vulnerabilities in phpCOIN 1.2.2 and earlier allow remote attackers to inject arbitrary web script or HTML via the fs parameter to (1) mod.php or (2) mod_print.php.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
coinsoft_technologies phpcoin 1.2.2
coinsoft_technologies phpcoin 1.2.1
coinsoft_technologies phpcoin 1.1.0
coinsoft_technologies phpcoin 1.1.1
coinsoft_technologies phpcoin 1.2.0
CVE-2006-2422 MEDIUM

phpCOIN 1.2.3 and earlier stores messages based upon e-mail addresses, which allows remote authenticated users to read messages for other users by adding the sender's e-mail address as an "additional contact".

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
coinsoft_technologies phpcoin 1.2.2
coinsoft_technologies phpcoin 1.2
coinsoft_technologies phpcoin 1.2.1
coinsoft_technologies phpcoin 1.2.1b