266591
|
- |
|
linpha
|
linpha
|
Multiple cross-site scripting (XSS) vulnerabilities in LinPHA before 1.3.4 might allow remote attackers to inject arbitrary web script or HTML via (1) new_images.php, (2) login.php, and unspecified v…
|
CWE-79
Cross-site Scripting
|
CVE-2008-6571
|
2009-04-1 02:30 |
2009-04-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
266592
|
- |
|
jax_scripts
|
jax_guestbook
|
Jax Guestbook 3.1 and 3.31 stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain IP addresses of users via a direct request to (1) …
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2005-4880
|
2009-04-1 02:30 |
2009-04-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
266593
|
- |
|
valgrind
|
valgrind
|
Untrusted search path vulnerability in valgrind before 3.4.0 allows local users to execute arbitrary programs via a Trojan horse .valgrindrc file in the current working directory, as demonstrated usi…
|
NVD-CWE-Other
|
CVE-2008-4865
|
2009-03-30 13:00 |
2008-11-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
266594
|
- |
|
alecwh
|
phpns
|
Unspecified vulnerability in phpns before 2.1.3 has unknown impact and attack vectors related to "activation permissions."
|
NVD-CWE-noinfo
|
CVE-2008-6546
|
2009-03-30 13:00 |
2009-03-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
266595
|
- |
|
moinmo
|
moinmoin
|
The password_checker function in config/multiconfig.py in MoinMoin 1.6.1 uses the cracklib and python-crack features even though they are not thread-safe, which allows remote attackers to cause a den…
|
NVD-CWE-noinfo
|
CVE-2008-6549
|
2009-03-30 13:00 |
2009-03-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
266596
|
- |
|
lukas_ruf
|
muttprint
|
muttprint in muttprint 0.72d allows local users to overwrite arbitrary files via a symlink attack on the /tmp/muttprint.log temporary file.
|
CWE-59
Link Following
|
CVE-2008-5368
|
2009-03-26 14:47 |
2008-12-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
266597
|
- |
|
drupal
|
print
|
Unspecified vulnerability in the Send by e-mail module in the "Printer, e-mail and PDF versions" module 5.x before 5.x-4.4 and 6.x before 6.x-1.4, a module for Drupal, allows remote attackers to send…
|
NVD-CWE-noinfo
|
CVE-2009-1037
|
2009-03-26 13:00 |
2009-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
266598
|
- |
|
sun
|
java_system_identity_manager
|
Sun Java System Identity Manager (IdM) 7.0 through 8.0 responds differently to failed use of the end-user question-based login feature depending on whether the user account exists, which allows remot…
|
CWE-200
Information Exposure
|
CVE-2009-1076
|
2009-03-26 00:30 |
2009-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
266599
|
- |
|
sun
|
java_system_identity_manager
|
Multiple cross-site scripting (XSS) vulnerabilities in Sun Java System Identity Manager (IdM) 7.0 through 8.0 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors, ak…
|
CWE-79
Cross-site Scripting
|
CVE-2009-1081
|
2009-03-26 00:30 |
2009-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
266600
|
- |
|
sun
|
java_system_identity_manager
|
Sun Java System Identity Manager (IdM) 7.0 through 8.0 allows remote authenticated users to gain privileges by submitting crafted commands to the Admin Console, as demonstrated by privileges for acco…
|
CWE-20
Improper Input Validation
|
CVE-2009-1082
|
2009-03-26 00:30 |
2009-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|