258141
|
- |
|
nexusjnr
|
jbook
|
JBook stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file via a direct request to userids.mdb.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2008-6375
|
2017-08-17 10:29 |
2009-03-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258142
|
- |
|
nexusjnr
|
jbook
|
SQL injection vulnerability in main.asp in Jbook allows remote attackers to execute arbitrary SQL commands via the password (pass parameter).
|
CWE-89
SQL Injection
|
CVE-2008-6376
|
2017-08-17 10:29 |
2009-03-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258143
|
- |
|
drupal
|
storm
|
SQL injection vulnerability in SpeedTech Organization and Resource Manager (Storm) 5.x before 5.x-1.14 and 6.x before 6.x-1.18, a module for Drupal, allows remote authenticated users with storm proje…
|
CWE-89
SQL Injection
|
CVE-2008-6383
|
2017-08-17 10:29 |
2009-03-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258144
|
- |
|
drupal
|
storm
|
Per vendor advisory at: http://drupal.org/node/342246
"Versions Affected
* Versions of Storm for Drupal 5.x prior to 5.x-1.14
* Versions of Storm for Drupal 6.x prior to 6.x-1.18
Dr…
|
CWE-89
SQL Injection
|
CVE-2008-6383
|
2017-08-17 10:29 |
2009-03-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258145
|
- |
|
drupal
|
comment_mail
|
Multiple cross-site request forgery (CSRF) vulnerabilities in Comment Mail 5.x before 5.x-1.1, a module for Drupal, allow remote attackers to hijack the authentication of administrators.
|
CWE-352
Origin Validation Error
|
CVE-2008-6384
|
2017-08-17 10:29 |
2009-03-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258146
|
- |
|
w3matter
|
revsense
|
Cross-site scripting (XSS) vulnerability in index.php in W3matter RevSense 1.0 allows remote attackers to inject arbitrary web script or HTML via the section parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2008-6385
|
2017-08-17 10:29 |
2009-03-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258147
|
- |
|
1scripts
|
z1exchange
|
Cross-site scripting (XSS) vulnerability in showads.php in Z1Exchange 1.0 allows remote attackers to inject arbitrary web script or HTML via the id parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2008-6386
|
2017-08-17 10:29 |
2009-03-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258148
|
- |
|
nexusjnr
|
jbook
|
SQL injection vulnerability in main.asp in Jbook allows remote attackers to execute arbitrary SQL commands via the username (user parameter).
|
CWE-89
SQL Injection
|
CVE-2008-6391
|
2017-08-17 10:29 |
2009-03-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258149
|
- |
|
1scripts
|
z1exchange
|
SQL injection vulnerability in showads.php in Z1Exchange allows remote attackers to execute arbitrary SQL commands via the id parameter.
|
CWE-89
SQL Injection
|
CVE-2008-6392
|
2017-08-17 10:29 |
2009-03-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258150
|
- |
|
3com
|
wireless_8760_dual-radio
|
The web management interface in 3Com Wireless 8760 Dual Radio 11a/b/g PoE Access Point allows remote attackers to cause a denial of service (device crash) via a malformed HTTP POST request.
|
CWE-134
Use of Externally-Controlled Format String
|
CVE-2008-6395
|
2017-08-17 10:29 |
2009-03-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|