269481
|
- |
|
maianscriptworld
|
maian_cart
|
Cross-site scripting (XSS) vulnerability in index.php in Maian Cart 1.1 allows remote attackers to inject arbitrary web script or HTML via the keywords parameter in a search command. NOTE: the prove…
|
CWE-79
Cross-site Scripting
|
CVE-2008-1075
|
2008-09-6 06:36 |
2008-02-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
269482
|
- |
|
vocera_communications
|
vocera_communications_badge
|
Cisco Unified Wireless IP Phone 7921, when using Protected Extensible Authentication Protocol (PEAP), does not validate server certificates, which allows remote wireless access points to steal hashed…
|
CWE-200
Information Exposure
|
CVE-2008-1113
|
2008-09-6 06:36 |
2008-03-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
269483
|
- |
|
drupal
|
drupal
|
Cross-site scripting (XSS) vulnerability in Drupal 6.0 allows remote authenticated users to inject arbitrary web script or HTML via titles in content edit forms.
|
CWE-79
Cross-site Scripting
|
CVE-2008-1131
|
2008-09-6 06:36 |
2008-03-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
269484
|
- |
|
net_activity_viewer
|
net_activity_viewer
|
Untrusted search path vulnerability in src/mainwindow.c in Net Activity Viewer 0.2.1 allows local users with Net Activity Viewer privileges to execute arbitrary code via a malicious gksu program, whi…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2008-1132
|
2008-09-6 06:36 |
2008-03-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
269485
|
- |
|
small_axe_solutions
|
weblog
|
PHP remote file inclusion vulnerability in inc/linkbar.php in Small Axe Weblog 0.3.1 allows remote attackers to execute arbitrary PHP code via a URL in the ffile parameter, a different vector than CV…
|
CWE-94
Code Injection
|
CVE-2008-0442
|
2008-09-6 06:35 |
2008-01-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
269486
|
- |
|
endian
|
firewall
|
Cross-site scripting (XSS) vulnerability in vpnum/userslist.php in Endian Firewall 2.1.2 allows remote attackers to inject arbitrary web script or HTML via the psearch parameter. NOTE: the provenanc…
|
CWE-79
Cross-site Scripting
|
CVE-2008-0494
|
2008-09-6 06:35 |
2008-01-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
269487
|
- |
|
trixbox
|
trixbox
|
Multiple cross-site scripting (XSS) vulnerabilities in trixbox 2.4.2.0 allow remote attackers to inject arbitrary web script or HTML via the query string to index.php in (1) user/ or (2) maint/.
|
CWE-79
Cross-site Scripting
|
CVE-2008-0540
|
2008-09-6 06:35 |
2008-02-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
269488
|
- |
|
uniwin
|
ecart_professional
|
Cross-site scripting (XSS) vulnerability in Uniwin eCart Professional before 2.0.16 allows remote attackers to inject arbitrary web script or HTML via the rp parameter to cartView.asp and unspecified…
|
CWE-79
Cross-site Scripting
|
CVE-2008-0558
|
2008-09-6 06:35 |
2008-02-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
269489
|
- |
|
liferay
|
liferay_enterprise_portal
|
Cross-site request forgery (CSRF) vulnerability in service/impl/UserLocalServiceImpl.java in Liferay Portal 4.3.6 allows remote attackers to perform unspecified actions as unspecified authenticated u…
|
CWE-352
Origin Validation Error
|
CVE-2008-0563
|
2008-09-6 06:35 |
2008-02-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
269490
|
- |
|
xlight_ftp_server
|
xlight_ftp_server
|
The LDAP authentication feature in XLight FTP Server before 2.83, when used with some unspecified LDAP servers, does not check for blank passwords, which allows remote attackers to bypass intended ac…
|
CWE-255
Credentials Management
|
CVE-2008-0604
|
2008-09-6 06:35 |
2008-02-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|