268501
|
- |
|
mozilla
|
firefox
|
Multiple cross-site scripting (XSS) vulnerabilities in Mozilla Firefox 3.0.1 through 3.0.3 allow remote attackers to inject arbitrary web script or HTML via an ftp:// URL for an HTML document within …
|
CWE-79
Cross-site Scripting
|
CVE-2008-4723
|
2008-10-24 13:00 |
2008-10-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
268502
|
- |
|
google
|
chrome
|
Multiple cross-site scripting (XSS) vulnerabilities in Google Chrome 0.2.149.30 allow remote attackers to inject arbitrary web script or HTML via an ftp:// URL for an HTML document within a (1) JPG, …
|
CWE-79
Cross-site Scripting
|
CVE-2008-4724
|
2008-10-24 13:00 |
2008-10-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
268503
|
- |
|
mplayer
|
mplayer
|
MPlayer, possibly 1.0rc1, allows remote attackers to cause a denial of service (SIGSEGV and application crash) via (1) a malformed MP3 file, as demonstrated by lol-mplayer.mp3; (2) a malformed Ogg Vo…
|
NVD-CWE-Other
|
CVE-2007-6718
|
2008-10-21 02:59 |
2008-10-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
268504
|
- |
|
ibm
|
zseries
|
The IPv6 Neighbor Discovery Protocol (NDP) implementation on IBM zSeries servers does not validate the origin of Neighbor Discovery messages, which allows remote attackers to cause a denial of servic…
|
CWE-20
Improper Input Validation
|
CVE-2008-4404
|
2008-10-4 00:07 |
2008-10-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
268505
|
- |
|
wsn_knowledge_base
|
wsn_knowledge_base
|
Multiple SQL injection vulnerabilities in WSN Knowledge Base 1.2.0 and earler allow remote attackers to execute arbitrary SQL commands via the (1) catid, (2) perpage, (3) ascdesc, and (4) orderlinks …
|
NVD-CWE-Other
|
CVE-2005-3939
|
2008-10-3 13:41 |
2005-12-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
268506
|
- |
|
phpalbum.net
|
phpalbum
|
Directory traversal vulnerability in main.php in PHPAlbum 0.2.3 and earlier allows remote attackers to read arbitrary files via the (1) cmd and (2) var1 parameters.
|
NVD-CWE-Other
|
CVE-2005-3948
|
2008-10-3 13:41 |
2005-12-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
268507
|
- |
|
bedeng_psp
|
bedeng_psp
|
SQL injection vulnerability in Bedeng PSP 1.1 allows remote attackers to execute arbitrary SQL commands via the cwhere parameter to (1) index.php and (2) download.php, or (3) ckode parameter to baca.…
|
NVD-CWE-Other
|
CVE-2005-3953
|
2008-10-3 13:41 |
2005-12-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
268508
|
- |
|
dmanews
|
dmanews
|
Multiple SQL injection vulnerabilities in index.php in DMANews 0.904 and 0.910 allow remote attackers to execute arbitrary SQL commands via the (1) id parameter in a comments action and the (2) sorto…
|
NVD-CWE-Other
|
CVE-2005-3956
|
2008-10-3 13:41 |
2005-12-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
268509
|
- |
|
iisprotect
|
iisprotect
|
iisPROTECT 2.1 and 2.2 allows remote attackers to bypass authentication via an HTTP request containing URL-encoded characters.
|
NVD-CWE-Other
|
CVE-2003-0317
|
2008-10-3 13:20 |
2003-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
268510
|
- |
|
phpnettoolpack
|
phpnettoolpack
|
PHPNetToolpack 0.1 relies on its environment's PATH to find and execute the traceroute program, which could allow local users to gain privileges by inserting a Trojan horse program into the search pa…
|
NVD-CWE-Other
|
CVE-2002-0470
|
2008-09-24 13:13 |
2002-08-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|