270881
|
- |
|
brekeke
|
pbx
|
Cross-site request forgery (CSRF) vulnerability in pbx/gate in Brekeke PBX 2.4.4.8 allows remote attackers to hijack the authentication of users for requests that change passwords via the pbxadmin.we…
|
CWE-352
Origin Validation Error
|
CVE-2010-2114
|
2010-06-1 13:00 |
2010-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
270882
|
- |
|
solarwinds
|
tftp_server
|
SolarWinds TFTP Server 10.4.0.10 allows remote attackers to cause a denial of service (no new connections) via a crafted read request.
|
CWE-20
Improper Input Validation
|
CVE-2010-2115
|
2010-06-1 13:00 |
2010-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
270883
|
- |
|
hp
|
mercury_testdirector_for_quality_center
|
Unspecified vulnerability in HP TestDirector for Quality Center 9.2 before Patch8 allows remote attackers to modify data via unknown vectors.
|
NVD-CWE-noinfo
|
CVE-2010-1959
|
2010-05-29 14:47 |
2010-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
270884
|
- |
|
sun
|
lightweight_availability_collection_tool
|
Race condition in the Sun Lightweight Availability Collection Tool 3.0 on Solaris 7 through 10 allows local users to overwrite arbitrary files via unspecified vectors.
|
CWE-362
Race Condition
|
CVE-2009-2314
|
2010-05-29 14:39 |
2009-07-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
270885
|
- |
|
go-oo
|
go-oo
|
Multiple heap-based buffer overflows in cppcanvas/source/mtfrenderer/emfplus.cxx in Go-oo 2.x and 3.x before 3.0.1, previously named ooo-build and related to OpenOffice.org (OOo), allow remote attack…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2009-2140
|
2010-05-29 14:38 |
2009-09-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
270886
|
- |
|
microsoft
|
asp.net
|
Microsoft ASP.NET 2.0 does not prevent setting the InnerHtml property on a control that inherits from HtmlContainerControl, which allows remote attackers to conduct cross-site scripting (XSS) attacks…
|
CWE-79
Cross-site Scripting
|
CVE-2010-2084
|
2010-05-28 13:00 |
2010-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
270887
|
- |
|
microsoft
|
.net_framework
|
The default configuration of ASP.NET in Microsoft .NET before 1.1 has a value of FALSE for the EnableViewStateMac property, which allows remote attackers to conduct cross-site scripting (XSS) attacks…
|
CWE-79
Cross-site Scripting
|
CVE-2010-2085
|
2010-05-28 13:00 |
2010-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
270888
|
- |
|
apache
|
myfaces
|
Apache MyFaces 1.1.7 and 1.2.8, as used in IBM WebSphere Application Server and other applications, does not properly handle an unencrypted view state, which allows remote attackers to conduct cross-…
|
CWE-79
Cross-site Scripting
|
CVE-2010-2086
|
2010-05-28 13:00 |
2010-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
270889
|
- |
|
microsoft
|
asp.net
|
ASP.NET in Microsoft .NET 3.5 does not properly handle an unencrypted view state, which allows remote attackers to conduct cross-site scripting (XSS) attacks against the form control via the __VIEWST…
|
CWE-79
Cross-site Scripting
|
CVE-2010-2088
|
2010-05-28 13:00 |
2010-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
270890
|
- |
|
cmsqlite
|
cmsqlite
|
SQL injection vulnerability in index.php in CMSQlite 1.2 and earlier allows remote attackers to execute arbitrary SQL commands via the c parameter.
|
CWE-89
SQL Injection
|
CVE-2010-2095
|
2010-05-28 13:00 |
2010-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|