256441
|
- |
|
xigla
|
absolute_poll_manager_xe
|
Xigla Software Absolute Poll Manager XE 4.1 allows remote attackers to bypass authentication and gain administrative access by setting a cookie to a certain value.
|
CWE-287
Improper Authentication
|
CVE-2008-6860
|
2017-09-29 10:33 |
2009-07-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256442
|
- |
|
xigla
|
absolute_newsletter
|
Xigla Software Absolute Newsletter 6.0 and 6.1 allows remote attackers to bypass authentication and gain administrative access by setting a cookie to a certain value.
|
CWE-287
Improper Authentication
|
CVE-2008-6861
|
2017-09-29 10:33 |
2009-07-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256443
|
- |
|
xigla
|
absolute_content_rotator
|
Absolute Content Rotator 6.0 allows remote attackers to bypass authentication and gain administrative access by setting a cookie to a certain value.
|
CWE-287
Improper Authentication
|
CVE-2008-6862
|
2017-09-29 10:33 |
2009-07-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256444
|
- |
|
xigla
|
absolute_form_processor.net
|
Xigla Software Absolute Form Processor .NET 4.0 allows remote attackers to bypass authentication and gain administrative access by setting a cookie to a certain value.
|
CWE-287
Improper Authentication
|
CVE-2008-6863
|
2017-09-29 10:33 |
2009-07-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256445
|
- |
|
xigla
|
absolute_live_support_.net
|
Xigla Software Absolute Live Support .NET 5.1 allows remote attackers to bypass authentication and gain administrative access by setting a cookie to a certain value.
|
CWE-287
Improper Authentication
|
CVE-2008-6864
|
2017-09-29 10:33 |
2009-07-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256446
|
- |
|
scripts_for_sites
|
ez_career
|
SQL injection vulnerability in content.php in Scripts For Sites (SFS) EZ Career allows remote attackers to execute arbitrary SQL commands via the topic parameter.
|
CWE-89
SQL Injection
|
CVE-2008-6867
|
2017-09-29 10:33 |
2009-07-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256447
|
- |
|
oramon
|
oramon
|
Oramon Oracle Database Monitoring Tool 2.0.1 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing credenti…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2008-6869
|
2017-09-29 10:33 |
2009-07-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256448
|
- |
|
merlix
|
educate_server
|
Merlix Educate Server allows remote attackers to bypass intended security restrictions and obtain sensitive information via a direct request to (1) config.asp and (2) users.asp.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2008-6870
|
2017-09-29 10:33 |
2009-07-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256449
|
- |
|
merlix
|
educate_server
|
Merlix Educate Server stores db.mdb under the web root with insufficient access control, which allows remote attackers to obtain unspecified sensitive information via a direct request.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2008-6871
|
2017-09-29 10:33 |
2009-07-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256450
|
- |
|
aspthai.net
|
aspthai_forums
|
ASPThai.NET ASPThai Forums 8.5 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for database…
|
CWE-200
Information Exposure
|
CVE-2008-6872
|
2017-09-29 10:33 |
2009-07-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|