268121
|
- |
|
exerocms
|
exero_cms
|
Multiple directory traversal vulnerabilities in Exero CMS 1.0.0 and 1.0.1 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the theme parameter to (1) custompa…
|
CWE-22
Path Traversal
|
CVE-2008-2840
|
2008-09-6 06:41 |
2008-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
268122
|
- |
|
webchamado
|
webchamado
|
SQL injection vulnerability in index.php in WebChamado 1.1 allows remote attackers to execute arbitrary SQL commands via the eml parameter. NOTE: the provenance of this information is unknown; the d…
|
CWE-89
SQL Injection
|
CVE-2008-2858
|
2008-09-6 06:41 |
2008-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
268123
|
- |
|
flicks_software
|
authentix
|
Cross-site scripting (XSS) vulnerability in editUser.asp in AuthentiX 6.3b1 Trial allows remote attackers to inject arbitrary web script or HTML via the username parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2008-1174
|
2008-09-6 06:37 |
2008-03-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
268124
|
- |
|
flicks_software
|
authentix
|
Cross-site scripting (XSS) vulnerability in AuthentiX 6.3b1 Trial allows remote attackers to inject arbitrary web script or HTML via the username parameter to aspAdmin/deleteUser.asp, a different vec…
|
CWE-79
Cross-site Scripting
|
CVE-2008-1175
|
2008-09-6 06:37 |
2008-03-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
268125
|
- |
|
microsoft
|
access jet
|
Unspecified vulnerability in Microsoft Access allows remote user-assisted attackers to execute arbitrary code via a crafted .MDB file, possibly related to Jet Engine (msjet40.dll). NOTE: this is pro…
|
NVD-CWE-noinfo
|
CVE-2008-1200
|
2008-09-6 06:37 |
2008-03-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
268126
|
- |
|
lagarde
|
storefront
|
SQL injection vulnerability in SearchResults.aspx in LaGarde StoreFront 6 before SP8 allows remote attackers to execute arbitrary SQL commands via the CategoryId parameter. NOTE: the provenance of t…
|
CWE-89
SQL Injection
|
CVE-2008-1341
|
2008-09-6 06:37 |
2008-03-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
268127
|
- |
|
polymita_technologies
|
bpm_suite collageportal
|
Multiple cross-site scripting (XSS) vulnerabilities in the search feature in Polymita BPM-Suite and CollagePortal allow remote attackers to inject arbitrary web script or HTML via the (1) _q and (2) …
|
CWE-79
Cross-site Scripting
|
CVE-2008-1342
|
2008-09-6 06:37 |
2008-03-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
268128
|
- |
|
manageengine
|
supportcenter_plus
|
Cross-site scripting (XSS) vulnerability in SolutionSearch.do in ManageEngine SupportCenter Plus 7.0.0 allows remote attackers to inject arbitrary web script or HTML via the searchText parameter, a r…
|
CWE-79
Cross-site Scripting
|
CVE-2008-1432
|
2008-09-6 06:37 |
2008-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
268129
|
- |
|
paul_pelzl
|
wyrd
|
wyrd 1.4.3b allows local users to overwrite arbitrary files via a symlink attack on the wyrd-tmp.[USERID] temporary file.
|
CWE-59
Link Following
|
CVE-2008-0806
|
2008-09-6 06:36 |
2008-02-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
268130
|
- |
|
ikiwiki
|
ikiwiki
|
Cross-site scripting (XSS) vulnerability in the meta plugin in Ikiwiki before 1.1.47 allows remote attackers to inject arbitrary web script or HTML via meta tags.
|
CWE-79
Cross-site Scripting
|
CVE-2008-0808
|
2008-09-6 06:36 |
2008-02-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|