266531
|
- |
|
phpmyadmin
|
phpmyadmin
|
phpMyAdmin before 2.11.5 accesses $_REQUEST to obtain some parameters instead of $_GET and $_POST, which allows attackers in the same domain to override certain variables and conduct SQL injection an…
|
CWE-89 CWE-352
SQL Injection Origin Validation Error
|
CVE-2008-1149
|
2017-08-8 10:29 |
2008-03-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
266532
|
- |
|
cisco
|
emergency_responder mobility_manager unified_communications_manager unified_presence
|
The Disaster Recovery Framework (DRF) master server in Cisco Unified Communications products, including Unified Communications Manager (CUCM) 5.x and 6.x, Unified Presence 1.x and 6.x, Emergency Resp…
|
CWE-287
Improper Authentication
|
CVE-2008-1154
|
2017-08-8 10:29 |
2008-04-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
266533
|
- |
|
cisco
|
network_admission_control
|
Cisco Network Admission Control (NAC) Appliance 3.5.x, 3.6.x before 3.6.4.4, 4.0.x before 4.0.6, and 4.1.x before 4.1.2 allows remote attackers to obtain the shared secret for the Clean Access Server…
|
CWE-200
Information Exposure
|
CVE-2008-1155
|
2017-08-8 10:29 |
2008-04-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
266534
|
- |
|
cisco
|
ciscoworks_internetwork_performance_monitor
|
Cisco CiscoWorks Internetwork Performance Monitor (IPM) 2.6 creates a process that executes a command shell and listens on a randomly chosen TCP port, which allows remote attackers to execute arbitra…
|
CWE-20
Improper Input Validation
|
CVE-2008-1157
|
2017-08-8 10:29 |
2008-03-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
266535
|
- |
|
cisco
|
unified_presence unified_presence_server
|
The Presence Engine (PE) service in Cisco Unified Presence before 6.0(1) allows remote attackers to cause a denial of service (core dump and service interruption) via malformed packets, aka Bug ID CS…
|
CWE-20
Improper Input Validation
|
CVE-2008-1158
|
2017-08-8 10:29 |
2008-05-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
266536
|
- |
|
flyspray
|
flyspray
|
Multiple cross-site scripting (XSS) vulnerabilities in Flyspray 0.9.9 through 0.9.9.4 allow remote attackers to inject arbitrary web script or HTML via (1) a forced SQL error message or (2) old_value…
|
CWE-79
Cross-site Scripting
|
CVE-2008-1165
|
2017-08-8 10:29 |
2008-03-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
266537
|
- |
|
sarg
|
squid_analysis_report_generator
|
Cross-site scripting (XSS) vulnerability in Squid Analysis Report Generator (Sarg) 2.2.3.1 allows remote attackers to inject arbitrary web script or HTML via the User-Agent header, which is not prope…
|
CWE-79
Cross-site Scripting
|
CVE-2008-1168
|
2017-08-8 10:29 |
2008-03-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
266538
|
- |
|
simm-comm
|
sci_photo_chat
|
Directory traversal vulnerability in the embedded HTTP server in SCI Photo Chat Server 3.4.9 and earlier allows remote attackers to read arbitrary files via a "..\" (dot dot backslash) or "../" (dot …
|
CWE-22
Path Traversal
|
CVE-2008-1169
|
2017-08-8 10:29 |
2008-03-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
266539
|
- |
|
centreon
|
centreon
|
Multiple cross-site scripting (XSS) vulnerabilities in include/common/javascript/color_picker.php in Centreon 1.4.2.3 and earlier allow remote attackers to inject arbitrary web script or HTML via the…
|
CWE-79
Cross-site Scripting
|
CVE-2008-1179
|
2017-08-8 10:29 |
2008-03-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
266540
|
- |
|
bsd_perimeter
|
pfsense
|
Cross-site scripting (XSS) vulnerability in BSD Perimeter pfSense before 1.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
|
CWE-79
Cross-site Scripting
|
CVE-2008-1182
|
2017-08-8 10:29 |
2008-03-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|