260521
|
- |
|
avaya
|
sip_enablement_services communication_manager
|
Unspecified vulnerability in the Web management interface in Avaya SIP Enablement Services (SES) 3.x and 4.0, as used with Avaya Communication Manager 3.1.x, allows remote authenticated users to exec…
|
NVD-CWE-noinfo
|
CVE-2008-6709
|
2017-08-17 10:29 |
2009-04-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260522
|
- |
|
avaya
|
communication_manager
|
Unspecified vulnerability in the Web administration interface in Avaya Communication Manager 3.1.x before CM 3.1.4 SP2 and 4.0.x before 4.0.3 SP1 allows remote authenticated administrators to gain ro…
|
NVD-CWE-noinfo
|
CVE-2008-6710
|
2017-08-17 10:29 |
2009-04-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260523
|
- |
|
avaya
|
communication_manager
|
Unspecified vulnerability in the Web administration interface in Avaya Communication Manager 3.1.x before CM 3.1.4 SP2 and 4.0.x before 4.0.3 SP1 allows remote authenticated users to execute arbitrar…
|
NVD-CWE-noinfo
|
CVE-2008-6711
|
2017-08-17 10:29 |
2009-04-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260524
|
- |
|
patrick_matthai
|
pnopaste
|
Cross-site scripting (XSS) vulnerability in index.pl in Perl Nopaste 1.0 allows remote attackers to inject arbitrary web script or HTML via the language parameter. NOTE: some of these details are ob…
|
CWE-79
Cross-site Scripting
|
CVE-2008-6724
|
2017-08-17 10:29 |
2009-04-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260525
|
- |
|
dotnetnuke
|
dotnetnuke
|
Cross-site scripting (XSS) vulnerability in the Language skin object in DotNetNuke before 4.8.4 allows remote attackers to inject arbitrary web script or HTML via "newly generated paths."
|
CWE-79
Cross-site Scripting
|
CVE-2008-6732
|
2017-08-17 10:29 |
2009-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260526
|
- |
|
dotnetnuke
|
dotnetnuke
|
Cross-site scripting (XSS) vulnerability in the error handling page in DotNetNuke 4.6.2 through 4.8.3 allows remote attackers to inject arbitrary web script or HTML via the querystring parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2008-6733
|
2017-08-17 10:29 |
2009-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260527
|
- |
|
ea
|
crysis
|
Crysis 1.21 and earlier allows remote attackers to obtain sensitive player information such as real IP addresses by sending a keyexchange packet without a previous join packet, which causes Crysis to…
|
CWE-200
Information Exposure
|
CVE-2008-6737
|
2017-08-17 10:29 |
2009-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260528
|
- |
|
cybozu
|
cybozu_dezie cybozu_garoon cybozu_office
|
Cross-site request forgery (CSRF) vulnerability in Cybozu Office 6, Cybozu Dezie before 6.0(1.0), and Cybozu Garoon 2.0.0 through 2.1.3 allows remote attackers to hijack the authentication of unspeci…
|
CWE-352
Origin Validation Error
|
CVE-2008-6744
|
2017-08-17 10:29 |
2009-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260529
|
- |
|
horde
|
turba_h3
|
Cross-site scripting (XSS) vulnerability in the contact display view in Turba Contact Manager H3 before 2.2.1 allows remote attackers to inject arbitrary web script or HTML via the contact name.
|
CWE-79
Cross-site Scripting
|
CVE-2008-6746
|
2017-08-17 10:29 |
2009-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260530
|
- |
|
dotproject
|
dotproject
|
dotProject before 2.1.2 does not properly restrict access to administrative pages, which allows remote attackers to gain privileges. NOTE: some of these details are obtained from third party informa…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2008-6747
|
2017-08-17 10:29 |
2009-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|