268861
|
- |
|
php_lite
|
calendar_express
|
Multiple SQL injection vulnerabilities in PHP Lite Calendar Express 2.2 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) cid and (2) catid parameters to (a) day.php, (…
|
NVD-CWE-Other
|
CVE-2005-4009
|
2008-09-20 13:41 |
2005-12-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
268862
|
- |
|
-
|
-
|
property.php in Widget Property 1.1.19 allows remote attackers to obtain the full server path via an invalid lang value, which leaks the path in the resulting error message.
|
NVD-CWE-Other
|
CVE-2005-4017
|
2008-09-20 13:41 |
2005-12-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
268863
|
- |
|
simplemedia
|
simplebbs
|
SQL injection vulnerability in SimpleBBS 1.1 allows remote attackers to execute arbitrary SQL commands via unspecified search module parameters.
|
CWE-89
SQL Injection
|
CVE-2005-4027
|
2008-09-20 13:41 |
2005-12-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
268864
|
- |
|
debian
|
python-dns
|
PyDNS (aka python-dns) before 2.3.1-4 in Debian GNU/Linux does not use random source ports or transaction IDs for DNS requests, which makes it easier for remote attackers to spoof DNS responses, a di…
|
CWE-16
Configuration
|
CVE-2008-4099
|
2008-09-19 13:00 |
2008-09-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
268865
|
- |
|
debian
|
python-dns
|
PyDNS (aka python-dns) before 2.3.1-5 in Debian GNU/Linux does not use random source ports for DNS requests and does not use random transaction IDs for DNS retries, which makes it easier for remote a…
|
CWE-16
Configuration
|
CVE-2008-4126
|
2008-09-19 13:00 |
2008-09-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
268866
|
- |
|
lxde
|
lightweight_x11_desktop_environment
|
src/main-win.c in GPicView 0.1.9 in Lightweight X11 Desktop Environment (LXDE) allows local users to overwrite arbitrary files via a symlink attack on the /tmp/rot.jpg temporary file.
|
CWE-59
Link Following
|
CVE-2008-3791
|
2008-09-17 14:35 |
2008-09-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
268867
|
- |
|
apple
|
iphone
|
Apple iPhone 2.0.2, in some configurations, allows physically proximate attackers to bypass intended access restrictions, and obtain sensitive information or make arbitrary use of the device, via an …
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2008-3876
|
2008-09-17 14:35 |
2008-09-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
268868
|
- |
|
six_apart
|
movable_type
|
Cross-site scripting (XSS) vulnerability in Movable Type (MT) 4.x through 4.20, and 3.36 and earlier; Movable Type Enterprise 4.x through 4.20, and 1.54 and earlier; and Movable Type Community Soluti…
|
CWE-79
Cross-site Scripting
|
CVE-2008-4079
|
2008-09-16 00:14 |
2008-09-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
268869
|
- |
|
texmedia
|
million_pixel_script
|
SQL injection vulnerability in tops_top.php in Million Pixel Ad Script (Million Pixel Script) allows remote attackers to execute arbitrary SQL commands via the id_cat parameter.
|
CWE-89
SQL Injection
|
CVE-2008-4055
|
2008-09-12 13:00 |
2008-09-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
268870
|
- |
|
apple
|
itunes
|
Apple iTunes before 8.0 on Mac OS X 10.4.11, when iTunes Music Sharing is enabled but blocked by the host-based firewall, presents misleading information about firewall security, which might allow re…
|
CWE-200
Information Exposure
|
CVE-2008-3634
|
2008-09-11 13:00 |
2008-09-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|