260581
|
- |
|
karen_stevenson yves_chedemois
|
cck
|
Multiple cross-site scripting (XSS) vulnerabilities in Drupal Content Construction Kit (CCK) 5.x through 5.x-1.8 allow remote authenticated users with "administer content" permissions to inject arbit…
|
CWE-79
Cross-site Scripting
|
CVE-2008-6972
|
2017-08-17 10:29 |
2009-08-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260582
|
- |
|
ibm
|
websphere_commerce
|
Multiple unspecified vulnerabilities in IBM WebSphere Commerce 6.0 before 6.0.0.7 have unknown impact and attack vectors.
|
NVD-CWE-noinfo
|
CVE-2008-6973
|
2017-08-17 10:29 |
2009-08-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260583
|
- |
|
parallels
|
plesk
|
Plesk 8.6.0, when short mail login names (SHORTNAMES) are enabled, allows remote attackers to bypass authentication and send spam e-mail via a message with (1) a base64-encoded username that begins w…
|
CWE-287
Improper Authentication
|
CVE-2008-6984
|
2017-08-17 10:29 |
2009-08-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260584
|
- |
|
ezonescripts
|
dating_website_script
|
Unrestricted file upload vulnerability in eZoneScripts Dating Website script allows remote attackers to execute arbitrary code via unknown vectors. NOTE: the provenance of this information is unknow…
|
NVD-CWE-Other
|
CVE-2008-6987
|
2017-08-17 10:29 |
2009-08-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260585
|
- |
|
phpauction
|
phpauction
|
phpAuction 3.2, and possibly 3.3.0 GPL Basic edition, allows remote attackers to obtain configuration information via a direct request to phpinfo.php, which calls the phpinfo function.
|
CWE-200
Information Exposure
|
CVE-2008-6999
|
2017-08-17 10:29 |
2009-08-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260586
|
- |
|
phpauction
|
phpauction
|
PHP remote file inclusion vulnerability in index.php in PHPAuction 3.2 allows remote attackers to execute arbitrary PHP code via a URL in the lan parameter. NOTE: this might be related to CVE-2005-2…
|
CWE-94
Code Injection
|
CVE-2008-7000
|
2017-08-17 10:29 |
2009-08-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260587
|
- |
|
elog
|
elog
|
Buffer overflow in Electronic Logbook (ELOG) before 2.7.1 has unknown impact and attack vectors, possibly related to elog.c.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2008-7004
|
2017-08-17 10:29 |
2009-08-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260588
|
- |
|
hyperstop
|
web_host_directory
|
HyperStop Web Host Directory 1.2 allows remote attackers to bypass authentication and download a database backup via a direct request to admin/backup/db.
|
CWE-287
Improper Authentication
|
CVE-2008-7008
|
2017-08-17 10:29 |
2009-08-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260589
|
- |
|
accellion
|
secure_file_transfer_appliance
|
courier/1000@/api_error_email.html (aka "error reporting page") in Accellion File Transfer Appliance FTA_7_0_178, and possibly other versions before FTA_7_0_189, allows remote attackers to send spam …
|
NVD-CWE-noinfo
|
CVE-2008-7012
|
2017-08-17 10:29 |
2009-08-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260590
|
- |
|
luke_mewburn
|
tnftpd
|
tnftpd before 20080929 splits large command strings into multiple commands, which allows remote attackers to conduct cross-site request forgery (CSRF) attacks via unknown vectors, probably involving …
|
CWE-352
Origin Validation Error
|
CVE-2008-7016
|
2017-08-17 10:29 |
2009-08-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|