257531
|
- |
|
phpauction
|
phpauction
|
phpAuction 3.2, and possibly 3.3.0 GPL Basic edition, allows remote attackers to obtain configuration information via a direct request to phpinfo.php, which calls the phpinfo function.
|
CWE-200
Information Exposure
|
CVE-2008-6999
|
2017-08-17 10:29 |
2009-08-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257532
|
- |
|
phpauction
|
phpauction
|
PHP remote file inclusion vulnerability in index.php in PHPAuction 3.2 allows remote attackers to execute arbitrary PHP code via a URL in the lan parameter. NOTE: this might be related to CVE-2005-2…
|
CWE-94
Code Injection
|
CVE-2008-7000
|
2017-08-17 10:29 |
2009-08-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257533
|
- |
|
elog
|
elog
|
Buffer overflow in Electronic Logbook (ELOG) before 2.7.1 has unknown impact and attack vectors, possibly related to elog.c.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2008-7004
|
2017-08-17 10:29 |
2009-08-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257534
|
- |
|
hyperstop
|
web_host_directory
|
HyperStop Web Host Directory 1.2 allows remote attackers to bypass authentication and download a database backup via a direct request to admin/backup/db.
|
CWE-287
Improper Authentication
|
CVE-2008-7008
|
2017-08-17 10:29 |
2009-08-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257535
|
- |
|
accellion
|
secure_file_transfer_appliance
|
courier/1000@/api_error_email.html (aka "error reporting page") in Accellion File Transfer Appliance FTA_7_0_178, and possibly other versions before FTA_7_0_189, allows remote attackers to send spam …
|
NVD-CWE-noinfo
|
CVE-2008-7012
|
2017-08-17 10:29 |
2009-08-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257536
|
- |
|
luke_mewburn
|
tnftpd
|
tnftpd before 20080929 splits large command strings into multiple commands, which allows remote attackers to conduct cross-site request forgery (CSRF) attacks via unknown vectors, probably involving …
|
CWE-352
Origin Validation Error
|
CVE-2008-7016
|
2017-08-17 10:29 |
2009-08-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257537
|
- |
|
cacert
|
cacert
|
Cross-site scripting (XSS) vulnerability in analyse.php in CAcert 20080921, and possibly other versions before 20080928, allows remote attackers to inject arbitrary web script or HTML via the CN (Com…
|
CWE-79
Cross-site Scripting
|
CVE-2008-7017
|
2017-08-17 10:29 |
2009-08-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257538
|
- |
|
nashtech
|
easy_php_calendar
|
Cross-site scripting (XSS) vulnerability in NashTech Easy PHP Calendar 6.3.25 allows remote attackers to inject arbitrary web script or HTML via the Details field (descr parameter) in an Add New Even…
|
CWE-79
Cross-site Scripting
|
CVE-2008-7018
|
2017-08-17 10:29 |
2009-08-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257539
|
- |
|
mcafee
|
safeboot_device_encryption
|
McAfee SafeBoot Device Encryption 4 build 4750 and earlier stores pre-boot authentication passwords in the BIOS Keyboard buffer and does not clear this buffer after use, which allows local users to o…
|
CWE-310
Cryptographic Issues
|
CVE-2008-7020
|
2017-08-17 10:29 |
2009-08-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257540
|
- |
|
galore
|
com_simpleshop
|
SQL injection vulnerability in the Simple Shop Galore (com_simpleshop) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the section parameter in a section action to…
|
CWE-89
SQL Injection
|
CVE-2008-7033
|
2017-08-17 10:29 |
2009-08-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|