271011
|
- |
|
rivetcode
|
rivettracker
|
RivetTracker before 1.0 stores passwords in cleartext in config.php, which allows local users to discover passwords by reading config.php.
|
CWE-310
Cryptographic Issues
|
CVE-2008-7207
|
2009-09-12 01:30 |
2009-09-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
271012
|
- |
|
marc_gloor
|
screenie
|
screenie in screenie 1.30.0 allows local users to overwrite arbitrary files via a symlink attack on a /tmp/.screenie.##### temporary file.
|
CWE-59
Link Following
|
CVE-2008-5371
|
2009-09-11 14:29 |
2008-12-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
271013
|
- |
|
cmus
|
cmus
|
cmus-status-display in cmus 2.2.0 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/cmus-status temporary file.
|
CWE-59
Link Following
|
CVE-2008-5375
|
2009-09-11 14:29 |
2008-12-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
271014
|
- |
|
multi-website
|
multi_website
|
Cross-site scripting (XSS) vulnerability in Multi Website 1.5 allows remote attackers to inject arbitrary web script or HTML via the search parameter in a search action to the default URI.
|
CWE-79
Cross-site Scripting
|
CVE-2009-3162
|
2009-09-11 13:00 |
2009-09-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
271015
|
- |
|
openwebmail.acatysmoof
|
openwebmail
|
Multiple cross-site scripting (XSS) vulnerabilities in OpenWebMail before 2.53 (Stable) allow remote attackers to inject arbitrary web script or HTML via unknown vectors.
|
CWE-79
Cross-site Scripting
|
CVE-2008-7202
|
2009-09-11 13:00 |
2009-09-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
271016
|
- |
|
allenthusiast
|
reviewpost_php_pro
|
Cross-site scripting (XSS) vulnerability in showproduct.php in ReviewPost Pro vB3 allows remote attackers to inject arbitrary web script or HTML via the date parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2009-3147
|
2009-09-11 03:30 |
2009-09-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
271017
|
- |
|
mark_reinsfelder
|
metashell
|
Unspecified vulnerability in metashell before 0.03 has unknown impact and attack vectors related to a "PATH execution security flaw," possibly an untrusted search path vulnerability.
|
NVD-CWE-noinfo
|
CVE-2008-7196
|
2009-09-10 19:30 |
2009-09-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
271018
|
- |
|
g15tools
|
g15daemon
|
Multiple unspecified vulnerabilities in G15Daemon before 1.9.4 have unknown impact and attack vectors.
|
NVD-CWE-noinfo
|
CVE-2008-7197
|
2009-09-10 19:30 |
2009-09-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
271019
|
- |
|
alecwh
|
phpns
|
Multiple unspecified vulnerabilities in phpns before 2.1.1beta1 have unknown impact and attack vectors.
|
NVD-CWE-noinfo
|
CVE-2008-7198
|
2009-09-10 19:30 |
2009-09-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
271020
|
- |
|
phoenixcontact
|
fl_il_24_bk-pac
|
Phoenix Contact FL IL 24 BK-PAC allows remote attackers to cause a denial of service (hang) via (1) unspecified manipulations as demonstrated by a Nessus scan or (2) malformed input to TCP port 502.
|
NVD-CWE-noinfo
|
CVE-2008-7199
|
2009-09-10 19:30 |
2009-09-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|