257471
|
- |
|
net2ftp
|
net2ftp
|
Multiple directory traversal vulnerabilities in the (a) "Unzip archive" and (b) "Upload files and archives" functionality in net2ftp 0.96 stable and 0.97 beta allow remote attackers to create, read, …
|
CWE-22
Path Traversal
|
CVE-2008-5275
|
2017-08-8 10:33 |
2008-11-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257472
|
- |
|
powerdns
|
powerdns
|
PowerDNS before 2.9.21.2 allows remote attackers to cause a denial of service (daemon crash) via a CH HINFO query.
|
NVD-CWE-noinfo CWE-16
Configuration
|
CVE-2008-5277
|
2017-08-8 10:33 |
2008-12-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257473
|
- |
|
wordpress
|
wordpress
|
Cross-site scripting (XSS) vulnerability in the self_link function in in the RSS Feed Generator (wp-includes/feed.php) for WordPress before 2.6.5 allows remote attackers to inject arbitrary web scrip…
|
CWE-79
Cross-site Scripting
|
CVE-2008-5278
|
2017-08-8 10:33 |
2008-11-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257474
|
- |
|
wordpress
|
wordpress
|
http://wordpress.org/development/2008/11/wordpress-265/
The security issue is an XSS exploit discovered by Jeremias Reith that fortunately only affects IP-based virtual servers running on Apache 2…
|
CWE-79
Cross-site Scripting
|
CVE-2008-5278
|
2017-08-8 10:33 |
2008-11-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257475
|
- |
|
gallery
|
gallery
|
Gallery 1.5.x before 1.5.10 and 1.6 before 1.6-RC3, when register_globals is enabled, allows remote attackers to bypass authentication and gain administrative via unspecified cookies. NOTE: some of …
|
CWE-287
Improper Authentication
|
CVE-2008-5296
|
2017-08-8 10:33 |
2008-12-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257476
|
- |
|
karakas-online
|
chm2pdf
|
chm2pdf 0.9 uses temporary files in directories with fixed names, which allows local users to cause a denial of service (chm2pdf failure) of other users by creating those directories ahead of time.
|
NVD-CWE-Other
|
CVE-2008-5298
|
2017-08-8 10:33 |
2008-12-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257477
|
- |
|
karakas-online
|
chm2pdf
|
chm2pdf 0.9 allows user-assisted local users to delete arbitrary files via a symlink attack on .chm files in the (1) /tmp/chm2pdf/work or (2) /tmp/chm2pdf/orig temporary directories.
|
CWE-59
Link Following
|
CVE-2008-5299
|
2017-08-8 10:33 |
2008-12-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257478
|
- |
|
dovecot
|
dovecot
|
Directory traversal vulnerability in the ManageSieve implementation in Dovecot 1.0.15, 1.1, and 1.2 allows remote attackers to read and modify arbitrary .sieve files via a ".." (dot dot) in a script …
|
CWE-22
Path Traversal
|
CVE-2008-5301
|
2017-08-8 10:33 |
2008-12-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257479
|
- |
|
twiki
|
twiki
|
Cross-site scripting (XSS) vulnerability in TWiki before 4.2.4 allows remote attackers to inject arbitrary web script or HTML via the %URLPARAM{}% variable.
|
CWE-79
Cross-site Scripting
|
CVE-2008-5304
|
2017-08-8 10:33 |
2008-12-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257480
|
- |
|
tiki
|
tikiwiki_cms\/groupware
|
Unspecified vulnerability in Tikiwiki before 2.2 has unknown impact and attack vectors related to "size of user-provided input," a different issue than CVE-2008-3653.
|
NVD-CWE-noinfo
|
CVE-2008-5318
|
2017-08-8 10:33 |
2008-12-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|