270001
|
- |
|
wordpress
|
wordpress
|
Cross-site scripting (XSS) vulnerability in WordPress before 2.6, SVN development versions only, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
|
CWE-79
Cross-site Scripting
|
CVE-2008-3233
|
2008-09-6 06:42 |
2008-07-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
270002
|
- |
|
jamroom
|
jamroom
|
Multiple unspecified vulnerabilities in JamRoom before 3.4.0 have unknown impact and attack vectors.
|
NVD-CWE-noinfo CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2008-3376
|
2008-09-6 06:42 |
2008-07-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
270003
|
- |
|
opendocman
|
opendocman
|
Cross-site scripting (XSS) vulnerability in index.php in OpenDocMan 1.2.5 allows remote attackers to inject arbitrary web script or HTML via the redirection parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2008-2788
|
2008-09-6 06:41 |
2008-06-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
270004
|
- |
|
exerocms
|
exero_cms
|
Multiple directory traversal vulnerabilities in Exero CMS 1.0.0 and 1.0.1 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the theme parameter to (1) custompa…
|
CWE-22
Path Traversal
|
CVE-2008-2840
|
2008-09-6 06:41 |
2008-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
270005
|
- |
|
webchamado
|
webchamado
|
SQL injection vulnerability in index.php in WebChamado 1.1 allows remote attackers to execute arbitrary SQL commands via the eml parameter. NOTE: the provenance of this information is unknown; the d…
|
CWE-89
SQL Injection
|
CVE-2008-2858
|
2008-09-6 06:41 |
2008-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
270006
|
- |
|
flicks_software
|
authentix
|
Cross-site scripting (XSS) vulnerability in editUser.asp in AuthentiX 6.3b1 Trial allows remote attackers to inject arbitrary web script or HTML via the username parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2008-1174
|
2008-09-6 06:37 |
2008-03-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
270007
|
- |
|
flicks_software
|
authentix
|
Cross-site scripting (XSS) vulnerability in AuthentiX 6.3b1 Trial allows remote attackers to inject arbitrary web script or HTML via the username parameter to aspAdmin/deleteUser.asp, a different vec…
|
CWE-79
Cross-site Scripting
|
CVE-2008-1175
|
2008-09-6 06:37 |
2008-03-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
270008
|
- |
|
microsoft
|
access jet
|
Unspecified vulnerability in Microsoft Access allows remote user-assisted attackers to execute arbitrary code via a crafted .MDB file, possibly related to Jet Engine (msjet40.dll). NOTE: this is pro…
|
NVD-CWE-noinfo
|
CVE-2008-1200
|
2008-09-6 06:37 |
2008-03-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
270009
|
- |
|
lagarde
|
storefront
|
SQL injection vulnerability in SearchResults.aspx in LaGarde StoreFront 6 before SP8 allows remote attackers to execute arbitrary SQL commands via the CategoryId parameter. NOTE: the provenance of t…
|
CWE-89
SQL Injection
|
CVE-2008-1341
|
2008-09-6 06:37 |
2008-03-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
270010
|
- |
|
polymita_technologies
|
bpm_suite collageportal
|
Multiple cross-site scripting (XSS) vulnerabilities in the search feature in Polymita BPM-Suite and CollagePortal allow remote attackers to inject arbitrary web script or HTML via the (1) _q and (2) …
|
CWE-79
Cross-site Scripting
|
CVE-2008-1342
|
2008-09-6 06:37 |
2008-03-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|