264611
|
- |
|
mucommander
|
mucommander
|
muCommander before 0.8.2 stores credentials.xml with insecure permissions, which allows local users to obtain credentials.
|
CWE-255
Credentials Management
|
CVE-2008-1970
|
2017-08-8 10:30 |
2008-04-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
264612
|
- |
|
oicgroup
|
exponent_cms
|
Multiple cross-site scripting (XSS) vulnerabilities in the user account creation feature in Exponent CMS 0.96.6-GA20071003 and earlier, when the Allow Registration? configuration option is enabled, a…
|
CWE-79
Cross-site Scripting
|
CVE-2008-1972
|
2017-08-8 10:30 |
2008-04-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
264613
|
- |
|
oicgroup
|
exponent_cms
|
Patch Link: http://www.exponentcms.org/index.php?action=view&id=64&module=newsmodule&src=%40random44fe03276195
|
CWE-79
Cross-site Scripting
|
CVE-2008-1972
|
2017-08-8 10:30 |
2008-04-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
264614
|
- |
|
drupal
|
ubercart_module
|
Cross-site scripting (XSS) vulnerability in the Ubercart 5.x before 5.x-1.0 rc3 module for Drupal allows remote authenticated users to inject arbitrary web script or HTML via node titles related to u…
|
CWE-79
Cross-site Scripting
|
CVE-2008-1978
|
2017-08-8 10:30 |
2008-04-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
264615
|
- |
|
drupal
|
e-publish
|
Cross-site scripting (XSS) vulnerability in E-Publish 5.x before 5.x-1.1 and 6.x before 6.x-1.0 beta1, a Drupal module, allows remote attackers to inject arbitrary web script or HTML via unspecified …
|
CWE-79
Cross-site Scripting
|
CVE-2008-1980
|
2017-08-8 10:30 |
2008-04-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
264616
|
- |
|
anelectron
|
advanced_electron_forum
|
Cross-site scripting (XSS) vulnerability in Advanced Electron Forum (AEF) 1.0.6 allows remote attackers to inject arbitrary web script or HTML via the beg parameter in a members action to index.php.
|
CWE-79
Cross-site Scripting
|
CVE-2008-1983
|
2017-08-8 10:30 |
2008-04-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
264617
|
- |
|
digital_hive
|
digitalhive
|
Cross-site scripting (XSS) vulnerability in base.php in DigitalHive 2.0 RC2 allows remote attackers to inject arbitrary web script or HTML via the mt parameter, possibly related to membres.php.
|
CWE-79
Cross-site Scripting
|
CVE-2008-1985
|
2017-08-8 10:30 |
2008-04-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
264618
|
- |
|
pixel_motion
|
pixel_motion_blog
|
Cross-site scripting (XSS) vulnerability in liste_article.php in Blog Pixel Motion (aka PixelMotion) allows remote attackers to inject arbitrary web script or HTML via the jours parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2008-1986
|
2017-08-8 10:30 |
2008-04-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
264619
|
- |
|
encaps
|
encapsgallery
|
Cross-site scripting (XSS) vulnerability in search.php in EncapsGallery 2.0.2 allows remote attackers to inject arbitrary web script or HTML via the search parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2008-1987
|
2017-08-8 10:30 |
2008-04-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
264620
|
- |
|
encaps
|
encapsgallery
|
Unrestricted file upload vulnerability in the file_upload function in core/misc.class.php in EncapsGallery 2.0.2 allows remote authenticated administrators to upload and execute arbitrary PHP files b…
|
CWE-20
Improper Input Validation
|
CVE-2008-1988
|
2017-08-8 10:30 |
2008-04-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|