267931
|
- |
|
nostatic
|
digitaldj
|
fest.pl in digitaldj 0.7.5 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/ddj_fest.tmp temporary file.
|
CWE-59
Link Following
|
CVE-2008-4948
|
2009-08-26 14:17 |
2008-11-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
267932
|
- |
|
fumitoshi_ukai
|
fml
|
mead.pl in fml 4.0.3 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/debugbuf temporary file.
|
CWE-59
Link Following
|
CVE-2008-4954
|
2009-08-26 14:17 |
2008-11-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
267933
|
- |
|
dov_grobgeld
|
impose\+
|
impose in impose+ 0.2 allows local users to overwrite arbitrary files via a symlink attack on (1) /tmp/*-tmp.ps and (2) /tmp/bboxx-* temporary files.
|
CWE-59
Link Following
|
CVE-2008-4960
|
2009-08-26 14:17 |
2008-11-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
267934
|
- |
|
adobe
|
coldfusion
|
Session fixation vulnerability in Adobe ColdFusion 8.0.1 and earlier allows remote attackers to hijack web sessions via unspecified vectors.
|
CWE-287
Improper Authentication
|
CVE-2009-1878
|
2009-08-26 13:00 |
2009-08-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
267935
|
- |
|
buildbot
|
buildbot
|
Cross-site scripting (XSS) vulnerability in the waterfall web status view (status/web/waterfall.py) in Buildbot 0.7.6 through 0.7.11p1 allows remote attackers to inject arbitrary web script or HTML v…
|
CWE-79
Cross-site Scripting
|
CVE-2009-2959
|
2009-08-26 02:30 |
2009-08-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
267936
|
- |
|
calimero.cms
|
calimero.cms
|
Cross-site scripting (XSS) vulnerability in index.php in Calimero.CMS 3.3 allows remote attackers to inject arbitrary web script or HTML via the id parameter in a calimero_webpage action.
|
CWE-79
Cross-site Scripting
|
CVE-2008-0749
|
2009-08-25 14:09 |
2008-02-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
267937
|
- |
|
ajsquare
|
free_polling_script
|
AJ Square Free Polling Script (AJPoll) allows remote attackers to bypass authentication and create new polls via a direct request to admin/include/newpoll.php, a different vector than CVE-2008-7045. …
|
CWE-287
Improper Authentication
|
CVE-2008-7046
|
2009-08-24 19:30 |
2009-08-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
267938
|
- |
|
wowraidmanager
|
wowraidmanager
|
The password_check function in auth/auth_phpbb3.php in WoW Raid Manager 3.5.1 before Patch 1, when using PHPBB3 authentication, (1) does not invoke the CheckPassword function with the required argume…
|
CWE-255
Credentials Management
|
CVE-2008-7050
|
2009-08-24 19:30 |
2009-08-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
267939
|
- |
|
cisco
|
ios_xr
|
Cisco IOS XR 3.8.1 and earlier allows remote attackers to cause a denial of service (process crash) via a long BGP UPDATE message, as demonstrated by a message with many AS numbers in the AS Path Att…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2009-1154
|
2009-08-22 02:30 |
2009-08-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
267940
|
- |
|
cisco
|
ios_xr
|
Cisco IOS XR 3.8.1 and earlier allows remote authenticated users to cause a denial of service (process crash) via vectors involving a BGP UPDATE message with many AS numbers prepended to the AS path.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2009-2056
|
2009-08-22 02:30 |
2009-08-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|