267811
|
- |
|
livestreet
|
livestreet
|
update/update_0.1.2_to_0.2.php in LiveStreet 0.2 does not require administrative authentication, which allows remote attackers to perform DROP TABLE operations via unspecified vectors.
|
CWE-287
Improper Authentication
|
CVE-2009-3261
|
2009-09-22 13:00 |
2009-09-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
267812
|
- |
|
livestreet
|
livestreet
|
Cross-site scripting (XSS) vulnerability in include/ajax/blogInfo.php in LiveStreet 0.2 allows remote attackers to inject arbitrary web script or HTML via the URI, as demonstrated by a SCRIPT element…
|
CWE-79
Cross-site Scripting
|
CVE-2009-3256
|
2009-09-21 13:00 |
2009-09-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
267813
|
- |
|
livestreet
|
livestreet
|
Cross-site scripting (XSS) vulnerability in LiveStreet 0.2 allows remote attackers to inject arbitrary web script or HTML via the header of the topic in a comment.
|
CWE-79
Cross-site Scripting
|
CVE-2009-3260
|
2009-09-21 13:00 |
2009-09-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
267814
|
- |
|
ibm
|
tivoli_identity_manager
|
Cross-site scripting (XSS) vulnerability in the Self Service UI (SSUI) in IBM Tivoli Identity Manager (ITIM) 5.0.0.5 allows remote authenticated users to inject arbitrary web script or HTML via the l…
|
CWE-79
Cross-site Scripting
|
CVE-2009-3262
|
2009-09-21 13:00 |
2009-09-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
267815
|
- |
|
ibm
|
tivoli_identity_manager
|
Per http://www-01.ibm.com/support/docview.wss?uid=swg1IZ54747
A fix is available
IBM Tivoli Identity Manager, ver 5.0, Interim Fix 5.0.0.6-TIV-TIM-IF0031
|
CWE-79
Cross-site Scripting
|
CVE-2009-3262
|
2009-09-21 13:00 |
2009-09-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
267816
|
- |
|
mozilla
|
bugzilla
|
token.cgi in Bugzilla 3.4rc1 through 3.4.1 places a password in a URL at the beginning of a login session that occurs immediately after a password reset, which allows context-dependent attackers to d…
|
CWE-255
Credentials Management
|
CVE-2009-3166
|
2009-09-19 14:32 |
2009-09-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
267817
|
- |
|
apple
|
mac_os_x mac_os_x_server java_1.4 java_1.5 java_1.6
|
Stack-based buffer overflow in the Java Web Start command launcher in Java for Mac OS X 10.5 before Update 5 allows attackers to execute arbitrary code or cause a denial of service (application crash…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2009-2205
|
2009-09-19 14:30 |
2009-09-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
267818
|
- |
|
intertwingly
|
planet planet_venus
|
Cross-site scripting (XSS) vulnerability in Planet 2.0 and Planet Venus allows remote attackers to inject arbitrary web script or HTML via the SRC attribute of an IMG element in a feed.
|
CWE-79
Cross-site Scripting
|
CVE-2009-2937
|
2009-09-18 19:30 |
2009-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
267819
|
- |
|
ohwada
|
xf-section
|
Cross-site scripting (XSS) vulnerability in the Happy Linux XF-Section module 1.12a for XOOPS allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
|
CWE-79
Cross-site Scripting
|
CVE-2009-3240
|
2009-09-18 19:30 |
2009-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
267820
|
- |
|
punbb
|
punbb
|
Cross-site request forgery (CSRF) vulnerability in PunBB before 1.2.17 allows remote attackers to hijack the authentication of unspecified users for requests related to a logout, probably a forced lo…
|
CWE-352
Origin Validation Error
|
CVE-2008-7241
|
2009-09-18 13:00 |
2009-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|