266021
|
- |
|
smarty
|
smarty
|
Multiple unspecified vulnerabilities in Smarty before 3.0.0 beta 6 have unknown impact and attack vectors.
|
NVD-CWE-noinfo
|
CVE-2009-5052
|
2011-02-15 14:00 |
2011-02-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
266022
|
- |
|
smarty
|
smarty
|
Unspecified vulnerability in Smarty before 3.0.0 beta 6 allows remote attackers to execute arbitrary PHP code by injecting this code into a cache file.
|
NVD-CWE-noinfo
|
CVE-2009-5053
|
2011-02-15 14:00 |
2011-02-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
266023
|
- |
|
smarty
|
smarty
|
Smarty before 3.0.0 beta 4 does not consider the umask value when setting the permissions of files, which might allow attackers to bypass intended access restrictions via standard filesystem operatio…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2009-5054
|
2011-02-15 14:00 |
2011-02-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
266024
|
- |
|
ibm
|
websphere_application_server
|
IBM WebSphere Application Server (WAS) 6.1.0.9, when the JAAS Login functionality is enabled, allows attackers to perform an internal application hashtable login by (1) not providing a password or (2…
|
CWE-20
Improper Input Validation
|
CVE-2008-7274
|
2011-02-15 14:00 |
2011-02-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
266025
|
- |
|
zikula
|
zikula_application_framework
|
Cross-site scripting (XSS) vulnerability in the Users module in Zikula before 1.2.5 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. NOTE: it is possible that …
|
CWE-79
Cross-site Scripting
|
CVE-2011-0911
|
2011-02-14 14:00 |
2011-02-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
266026
|
- |
|
ibm
|
lotus_domino
|
The Remote Console in IBM Lotus Domino, when a certain unsupported configuration involving UNC share pathnames is used, allows remote attackers to bypass authentication and execute arbitrary code via…
|
CWE-287
Improper Authentication
|
CVE-2011-0920
|
2011-02-14 14:00 |
2011-02-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
266027
|
- |
|
zikula
|
zikula_application_framework
|
Zikula before 1.3.1 uses the rand and srand PHP functions for random number generation, which makes it easier for remote attackers to defeat protection mechanisms based on randomization by predicting…
|
CWE-310
Cryptographic Issues
|
CVE-2010-4728
|
2011-02-14 14:00 |
2011-02-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
266028
|
- |
|
zikula
|
zikula_application_framework
|
Zikula before 1.2.3 does not use the authid protection mechanism for (1) the lostpassword form and (2) mailpasswd processing, which makes it easier for remote attackers to generate a flood of passwor…
|
CWE-352
Origin Validation Error
|
CVE-2010-4729
|
2011-02-14 14:00 |
2011-02-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
266029
|
- |
|
mediawiki
|
mediawiki
|
Multiple directory traversal vulnerabilities in (1) languages/Language.php and (2) includes/StubObject.php in MediaWiki 1.8.0 and other versions before 1.16.2, when running on Windows and possibly No…
|
CWE-22
Path Traversal
|
CVE-2011-0537
|
2011-02-12 15:46 |
2011-02-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
266030
|
- |
|
dovecot
|
dovecot
|
plugins/acl/acl-backend-vfile.c in Dovecot 1.2.x before 1.2.15 and 2.0.x before 2.0.5 interprets an ACL entry as a directive to add to the permissions granted by another ACL entry, instead of a direc…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2010-3706
|
2011-02-12 15:44 |
2010-10-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|