270231
|
- |
|
gallarific
|
gallarific
|
Gallarific Free Edition 1.1 does not require authentication for (1) photos.php, (2) comments.php, and (3) gallery.php in gadmin/, which allows remote attackers to edit objects via a direct request, d…
|
CWE-287
Improper Authentication
|
CVE-2008-1469
|
2011-07-25 13:00 |
2008-03-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
270232
|
- |
|
gallarific
|
gallarific
|
More information available at: http://www.securityfocus.com/bid/28163/info
|
CWE-287
Improper Authentication
|
CVE-2008-1469
|
2011-07-25 13:00 |
2008-03-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
270233
|
- |
|
linpha
|
linpha
|
Multiple cross-site scripting (XSS) vulnerabilities in LinPHA before 1.3.3 allow remote attackers to inject arbitrary web script or HTML via (1) ftp/index.php, (2) viewer.php, (3) functions/other.php…
|
CWE-79
Cross-site Scripting
|
CVE-2008-1487
|
2011-07-25 13:00 |
2008-03-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
270234
|
- |
|
netbsd
|
netbsd
|
The accept function in NetBSD-current before 20061023, NetBSD 3.0 and 3.0.1 before 20061024, and NetBSD 2.x before 20061029 allows local users to cause a denial of service (socket consumption) via an…
|
CWE-20
Improper Input Validation
|
CVE-2006-6653
|
2011-07-25 13:00 |
2006-12-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
270235
|
- |
|
netbsd
|
netbsd
|
This vulnerability is addressed in the following product updates:
NetBSD, NetBSD, current (10/23/2006)
NetBSD, NetBSD, 3.0 (10/24/2006)
NetBSD, NetBSD, 3.0.1 (10/24/2006)
NetBSD, NetBSD, 2.0 (10…
|
CWE-20
Improper Input Validation
|
CVE-2006-6653
|
2011-07-25 13:00 |
2006-12-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
270236
|
- |
|
web-app.net
|
webapp
|
Cross-site scripting (XSS) vulnerability in Web Automated Perl Portal (WebAPP) 0.9.9.4, and 0.9.9.3.4 Network Edition (NE) (aka WebAPP.NET), allows remote attackers to inject arbitrary web script or …
|
CWE-79
Cross-site Scripting
|
CVE-2006-6687
|
2011-07-25 13:00 |
2006-12-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
270237
|
- |
|
clamav
|
clamav
|
The cabd_find function in cabd.c of the libmspack library (mspack) for Clam AntiVirus (ClamAV) before 0.87.1 allows remote attackers to cause a denial of service (infinite loop) via a crafted CAB fil…
|
CWE-399
Resource Management Errors
|
CVE-2005-3501
|
2011-07-14 13:00 |
2005-11-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
270238
|
- |
|
php
|
php
|
The compress.bzip2:// URL wrapper provided by the bz2 extension in PHP before 4.4.7, and 5.x before 5.2.2, does not implement safemode or open_basedir checks, which allows remote attackers to read bz…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2007-1461
|
2011-07-13 13:00 |
2007-03-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
270239
|
- |
|
opera
|
opera_browser
|
The FTP protocol implementation in Opera 9.10 allows remote attackers to allows remote servers to force the client to connect to other servers, perform a proxied port scan, or obtain sensitive inform…
|
CWE-200
Information Exposure
|
CVE-2007-1563
|
2011-07-8 13:00 |
2007-03-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
270240
|
- |
|
wikkawiki
|
wikkawiki
|
The RecentChanges feature in WikkaWiki (Wikka Wiki) before 1.1.6.3 allows remote attackers to obtain the names, and possibly revision notes and dates, of private pages via RSS feeds.
|
CWE-200
Information Exposure
|
CVE-2007-2552
|
2011-06-16 13:00 |
2007-05-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|