267181
|
- |
|
fad_solutions
|
drzes_hms
|
Multiple SQL injection vulnerabilities in DRZES HMS 3.2 allow remote attackers to execute arbitrary SQL commands via the (1) plan_id parameter to (a) domains.php, (b) viewusage.php, (c) pop_accounts.…
|
NVD-CWE-Other
|
CVE-2005-4366
|
2008-09-20 13:42 |
2005-12-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
267182
|
- |
|
asps
|
shopping_cart
|
Multiple SQL injection vulnerabilities in Absolute Shopping Package Solutions (ASPS) Shopping Cart Professional 2.9d and earlier, and Lite 2.1 and earlier, allow remote attackers to execute arbitrary…
|
NVD-CWE-Other
|
CVE-2005-4003
|
2008-09-20 13:41 |
2005-12-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
267183
|
- |
|
jax_calendar
|
jax_calendar
|
SQL injection vulnerability in jax_calendar.php in Jax Calendar 1.34 allows remote attackers to execute arbitrary SQL commands via the (1) cal_id parameter, and possibly the (2) Y and (3) m parameter…
|
NVD-CWE-Other
|
CVE-2005-4008
|
2008-09-20 13:41 |
2005-12-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
267184
|
- |
|
php_lite
|
calendar_express
|
Multiple SQL injection vulnerabilities in PHP Lite Calendar Express 2.2 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) cid and (2) catid parameters to (a) day.php, (…
|
NVD-CWE-Other
|
CVE-2005-4009
|
2008-09-20 13:41 |
2005-12-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
267185
|
- |
|
-
|
-
|
property.php in Widget Property 1.1.19 allows remote attackers to obtain the full server path via an invalid lang value, which leaks the path in the resulting error message.
|
NVD-CWE-Other
|
CVE-2005-4017
|
2008-09-20 13:41 |
2005-12-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
267186
|
- |
|
simplemedia
|
simplebbs
|
SQL injection vulnerability in SimpleBBS 1.1 allows remote attackers to execute arbitrary SQL commands via unspecified search module parameters.
|
CWE-89
SQL Injection
|
CVE-2005-4027
|
2008-09-20 13:41 |
2005-12-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
267187
|
- |
|
debian
|
python-dns
|
PyDNS (aka python-dns) before 2.3.1-4 in Debian GNU/Linux does not use random source ports or transaction IDs for DNS requests, which makes it easier for remote attackers to spoof DNS responses, a di…
|
CWE-16
Configuration
|
CVE-2008-4099
|
2008-09-19 13:00 |
2008-09-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
267188
|
- |
|
debian
|
python-dns
|
PyDNS (aka python-dns) before 2.3.1-5 in Debian GNU/Linux does not use random source ports for DNS requests and does not use random transaction IDs for DNS retries, which makes it easier for remote a…
|
CWE-16
Configuration
|
CVE-2008-4126
|
2008-09-19 13:00 |
2008-09-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
267189
|
- |
|
lxde
|
lightweight_x11_desktop_environment
|
src/main-win.c in GPicView 0.1.9 in Lightweight X11 Desktop Environment (LXDE) allows local users to overwrite arbitrary files via a symlink attack on the /tmp/rot.jpg temporary file.
|
CWE-59
Link Following
|
CVE-2008-3791
|
2008-09-17 14:35 |
2008-09-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
267190
|
- |
|
apple
|
iphone
|
Apple iPhone 2.0.2, in some configurations, allows physically proximate attackers to bypass intended access restrictions, and obtain sensitive information or make arbitrary use of the device, via an …
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2008-3876
|
2008-09-17 14:35 |
2008-09-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|